Federal grant · cooperative agreement (b)
NSF Safe-ose: Strengthening Critical Privacy Infrastructure -this Safety, Security, and Privacy of Open-source Ecosystems (safe-ose) Project Focuses on Improving a Critical Piece of Open-source Software Utilized by U.s. Government Agencies for National Security and Foreign Policy Purposes, by U.s.-based Companies and Organizations to Deliver Their Services, and by Individual Citizens of the U.s. to Bolster Their Privacy Online. the Project Will Focus on Transitioning the Software to a Stronger Form of Encryption, Ensuring That All Users of the Software Are Protected Against Evolving Threats Posed by Quantum Computing. the Project Will Also Resolve Vulnerabilities Posed by a Variety of Other Threats That Can Compromise the Safety, Security, or Privacy of the Software?s Users, Including Threats From Outside Governments, Potential Malicious Developers Who Might Try to Inject Compromised Code Into the Software?s Dependencies, and Insiders That Have Had Their Accounts Compromised Through Phishing Attacks, and More. This Safe-ose Project Addresses the Software?s (1) Potential Weakness to Decryption Caused by Its Use of Pre-quantum Encryption Algorithms and (2) Potential Weaknesses to Socio-technical Threats Like Supply-chain Attacks, Long- and Short-term Infiltration, Foreign Government Compromise, and Compromised Infrastructure. the Project Will (a) Convert Existing Threat Model Findings Into Concrete Security Implementation Measures; (B) Implement Supply Chain Resilience for Automated Dependency Management; (C) Provide a Reproducible Implementation of the Software; and (D) Integrate a Standardized Post-quantum Cryptographic Key Exchange Mechanism Into the Software. in Mitigating These Vulnerabilities, This Project Develops and Publicly Releases Analysis, Code, and Tools That Can Be Reviewed, Evaluated, and Reused by Software Developers. the Project Benefits Other Open-source Software Projects Facing Similar Challenges, and Will Be of Particular Use to Other Projects With Limited Resources. the Anticipated Outcomes of This Project Are the Use of the Software to Advance National Security and Foreign Policy Goals, to Deliver Company and Industry Services, and to Bolster Individuals' Online Privacy With Increased Safety, Security, and Privacy Measures. This Award Reflects NSF'S Statutory Mission and Has Been Deemed Worthy of Support Through Evaluation Using the Foundation's Intellectual Merit and Broader Impacts Review Criteria.- Subawards Are Not Planned for This Award.
Committed
$0
Loading…
Everything here is this single award's whole record — signed, amended, paid — not a fiscal-year slice. The by-year charts elsewhere split an award across the years it was committed; this page keeps it whole.
Committed is what the government has legally promised on this award so far. Contracts can also carry a ceiling — the maximum if every option is exercised. Unspent ceiling is headroom, not money owed.
The cash actually disbursed against this award. The gap from committed is the disbursement pipeline: promised, not yet cashed.
Each transaction is a signing event — an action that created or changed the award, dated the day it was signed — not a payment. Negative amounts are real: money de-committed at closeout or renegotiation.
One bar, the award’s whole arithmetic: paid out, then committed, not yet paid, then unspent ceiling.