SIEVE_CUI_Guide_v1.pdf
PDF 100 KB Posted
- Attached to
- Securing Information for Encrypted Verification and Evaluation (SIEVE) Federal contract opportunity
- Solicitation number
- HR001119S0076
About this file
This document provides a Controlled Unclassified Information (CUI) guide for the Securing Information for Encrypted Verification and Evaluation (SIEVE) program. The guide defines CUI for the program as technical information with military or space application related to research and engineering data, computer software, vulnerabilities in military systems, APIs, user interfaces, and assembled systems incorporating CUI. It identifies safeguarding requirements for CTI including restrictions on foreign release and marking requirements. The guide specifies that program management information, interaction and collaboration details, evaluation and assessment information will not be CTI unless including CUI. It also lists technical areas including zero-knowledge proof construction and evaluation that will not produce CTI. The related federal contract opportunity posting seeks innovative research proposals in zero-knowledge proofs for complex DoD capabilities under the SIEVE broad agency announcement, to be evaluated through scientific review and using FAR procedures.
CUI Guide
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| HR001119S0076-Amendment-01.pdf | ||
| HR001119S0076.pdf | ||
| SIEVE_BAA_Attachment_Proposal_Summary_Chart_Template.pptx | PPTX presentation | |
| SIEVE_BAA_proposal_LoE_table_template_SkillSets.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Distribution Statement A: Approved for Public Release, Distribution Unlimited
Controlled Unclassified Information Guide
Program: Securing Information for Encrypted Verification and Evaluation
(SIEVE)
Program Manager: Dr. Joshua Baron
Program Security Officer: Denice Holden
Date: June 25, 2019
Version: 1.0
SIEVE CUI Guide
Version 1.0 Page 2 of 4
1 Background The SIEVE program will use zero knowledge proofs to enable the verification of capabilities relevant to the Department of Defense without revealing the sensitive details associated with those capabilities. SIEVE will accomplish this goal by dramatically increasing the expressivity of problem statements for which zero knowledge proofs can be constructed; SIEVE will also focus on increasing the efficiency of zero knowledge proof technology to enable large, complex proof statements (e.g., billions of gates or more, where the statement natively consists of probabilistic, indeterminate-branching conditions).
2 Purpose This guide identifies those aspects of the program that performers must handle as Controlled Technical Information (CTI). Questions concerning the content and interpretation of this guide and/or recommendations for changes due to current conditions, progress made in program research, scientific technological developments, advances in state of the art, or other factors should be directed to the DARPA Program Manager. All users of this guide are encouraged to assist in improving its currency and adequacy.
No changes are approved until DARPA issues an official modification and updates this guide.
3 Definition of Controlled Technical Information for the Program DoD considers “technical information” to be technical data or computer software, as those terms are defined in Defense Federal Acquisition Regulation Supplement clause 252.227-7013, "Rights in Technical Data - Noncommercial Items" (48 CFR 252.227-7013). Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software code. Note that such technical information may or may not be controlled (i.e., CTI), depending on whether it has military or space application.
Controlled Technical Information (CTI) is defined as technical information with military or space application that is subject to controls on its access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. CTI is to be marked with one of the distribution statements B through F, in accordance with Department of Defense Instruction 5230.24, "Distribution Statements on Technical Documents." The term CTI does not apply to information that is lawfully publicly available without restrictions.
The SIEVE program may provide zero knowledge proofs for the existence of certain computer system vulnerabilities. Such a proof will be considered CTI or classified only if the vulnerability itself is considered CTI or classified. For the SIEVE program, such a vulnerability is considered at least CTI only if identified with a specific military system. For example, the existence of a specific Windows XP vulnerability is not CTI. The fact that a specific military system X uses Windows XP and would be susceptible to that specific vulnerability would be at least CTI.
The application programming interfaces (APIs) user interfaces, and assembled systems will constitute CTI if the APIs user interfaces, or assembled systems directly incorporate material from CUI or CTI sources.
The evaluation planning, performance results, and user observation or testing results based on CUI transition partner data will also constitute CUI. The datasets and other materials prepared for SIEVE will constitute CTI if they directly incorporate material from CUI or CTI sources. In addition, datasets or other information received from transition partners will constitute CTI if the originator of the dataset or the SIEVE PM designates it as such.
4 Safeguarding CTI The Contractor shall not release CTI to anyone outside the Contractor’s organization or to a Foreign National, regardless of medium (e.g. file, tape, and document), pertaining to any part of this contract or any
Version 1.0 Page 3 of 4 program related to this contract, unless DARPA has provided prior written approval. Please submit requests for release of CTI to both the SIEVE Program Manager and Program Security Officer.
Contractor information systems shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171. “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations”. DARPA can provide guidance on how to implement 800-171 controls.
CTI is to be marked “DISTRIBUTION C. Distribution authorized to U.S. Government agencies and their contractor; Critical Technology; December 2017. Other requests for this document shall be referred to DARPA, I2O.”, in accordance with Department of Defense Instruction 5230.24, "Distribution Statements on Technical Documents."
Material that does not contain CUI does not require marking. The lack of distribution statement does not automatically approve the information for public release. DARPA unclassified information must be reviewed for public release IAW with the performer’s contract.
5 Aspects of the Program that Will Not Involve CTI
5.1 Program Management
• Information and materials related to program schedules, meeting plans, programmatic goals and intentions, research directions, strategic challenges and gaps, instructions, status updates, and other such program management information and materials, whether created by DARPA or performers, will not constitute CTI unless they include material deemed to be CUI as noted in Section 3 of this guide.
• Non-CTI SIEVE management information and material may be shared with any program participant, U.S. government representative, or other authorized individual or group by any means of communication, including in-person discussion, telephone communication, electronic message, electronic or hardcopy document, or electronic sharing medium.
5.2 Interaction and Collaboration
• Frequent and extensive interaction and collaboration among performers is a crucial program activity. Information and materials related to SIEVE research, development, software and system details, data preparation, algorithm performance, strategic objectives, and other such SIEVE technical information and materials, whether created by DARPA or performers, will not constitute CTI unless they include material deemed to be CUI as noted in Section 3 of this guide.
• Non-CTI SIEVE interaction and collaboration information and material may be shared with any program participant, U.S. government representative, or other authorized individual or group by any means of communication, including in-person discussion, telephone communication, electronic message, electronic or hardcopy document, or electronic sharing medium. When at all possible, encryption of data at rest and in motion is highly encouraged.
5.3 Evaluation and Assessment
• Information and materials related to SIEVE evaluation or assessment planning, execution, or results, whether created by DARPA or performers, will not constitute CTI unless they include material deemed to be CUI as noted in Section 3 of this guide.
Version 1.0 Page 4 of 4
• Non-CTI SIEVE evaluation and assessment information and material may be shared with any program participant, U.S. government representative, or other authorized individual or group by any means of communication, including in-person discussion, telephone communication, electronic message, electronic or hardcopy document, or electronic sharing medium. When at all possible, encryption of data at rest and in motion is highly encouraged.
The following work products are not CTI, either individually or in combination with other non-CTI SIEVE-developed technologies, provided they are not solely intended to be used on a specific military system:
5.4 TA1: ZK Statement Construction
• Techniques, documentation, security analysis and/or proofs, formats, protocols, and software to encode problem statements into intermediate representations (IRs), including the underlying primitives to do so.
5.5 TA2: ZK Proof Generation Compilers
• Techniques, documentation, security analysis and/or proofs, formats, protocols, and software to generate zero knowledge proofs from IR-encoded problem statements.
• Techniques, documentation, security analysis and/or proofs, formats, protocols, and software to manipulate IR-encoded problem statements to enable more efficient zero knowledge proofs.
5.6 TA3: Post Quantum ZK
• Techniques, documentation, security analysis and/or proofs, formats, protocols, and software to create zero knowledge proofs that are secure in plausibly post-quantum hardness settings
5.7 Test and Evaluation
• Techniques, documentation (to include security analyses), protocols, and software to perform test and evaluation of SIEVE technologies:
• Data obtained by T&E performers regarding proof performance and/or realism unless identified as
CTI by the source of that data
6 Publication All performers must follow the publication guidelines outlined in their contract. Performers requiring pre-publication review must submit any request through DARPA’s DISTAR Process.
| 1 Background |
| 2 Purpose |
| 3 Definition of Controlled Technical Information for the Program |
| 4 Safeguarding CTI |
| 5 Aspects of the Program that Will Not Involve CTI |
| 5.1 Program Management |
| 5.2 Interaction and Collaboration |
| 5.3 Evaluation and Assessment |
| 5.4 TA1: ZK Statement Construction |
| 5.5 TA2: ZK Proof Generation Compilers |
| 5.6 TA3: Post Quantum ZK |
| 5.7 Test and Evaluation |
6 Publication
File details come from the government source that posted it. Updated .