Skip to main navigation Skip to search Skip to main content

NSF-Safe-OSE: Strengthening HDF5 for Science, Industry, and National Security Applications

Project: Research

Abstract & Details

Description

Award ID: 2534078

This project enhances the safety, security, and privacy of the Hierarchical Data Format version 5 (HDF5), a widely used data management system critical in scientific research, industry, healthcare, finance, and national security. Given HDF5s role in handling large, complex datasets across various applications, vulnerabilities within its infrastructure pose significant risks. This project systematically identifies and addresses these vulnerabilities, creating safer data management solutions to advance scientific discovery, protect national security interests, and support economic growth. By enhancing HDF5s robustness, the initiative seeks to strengthen U.S. leadership in scientific and technological innovation, thereby providing lasting competitive advantages in data management. The enhanced HDF5 infrastructure will particularly benefit national laboratories, healthcare providers, educational institutions, and industries that rely on secure and reliable data systems. Through community engagement and rigorous safety practices, the project directly contributes to national health, prosperity, and security by strengthening the foundational data technologies that underpin modern scientific, industrial, and societal infrastructures. This project addresses critical safety, security, and privacy (SSP) vulnerabilities within HDF5 through comprehensive audit and mitigation phases. The audit systematically investigates seven vulnerability categories, including file format, library-level issues, extensions, toolchain dependencies, operational usage, privacy leaks, and supply chain risks. It utilizes static and dynamic analysis tools, threat modeling, and community-driven bug discovery initiatives to identify vulnerabilities. Mitigation activities follow two parallel tracks: Track A enhances the core HDF5 library and file format through code refactoring, input validation, buffer overflow resolutions, and the introduction of secure-by-default behaviors. Track B secures the broader ecosystem by standardizing safer development templates, hardening extensions, and interfaces, and ensuring robust distribution practices through signed packages and reproducible builds. Key deliverables include updated, hardened software releases, comprehensive security playbooks, enhanced plugin management frameworks, and strategies for migrating critical modules to memory-safe languages. The projects structured community engagement ensures continuous input and adoption of best practices, significantly strengthening the security posture of HDF5 and its extensive user base across many sectors. This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.

NSF Program Director: Florence Rabanal
StatusActive
Effective start/end date10/01/2509/30/27

Funding

  • (Safe-OSE) NSF Safety, Security, and Privacy of Open-Source Ecosystems: $1,500,000.00

Active Fiscal Year

  • FY2027
  • FY2026

Start Fiscal Year

  • FY2026

TIP Programs

  • (Safe-OSE) NSF Safety, Security, and Privacy of Open-Source Ecosystems

Key Technology Areas

  • Data and Cybersecurity
  • (confidence score: 100%)

Technology Foci

  • Data Privacy
  • (confidence score: 99%)
  • Data Management / Databases
  • (confidence score: 100%)
  • Cyber-security
  • (confidence score: 94%)

Congressional District at Award

  • District n. 13 of Illinois

Current Congressional District

  • District n. 13 of Illinois

United States

  • Illinois

Core Based Statistical Area (CBSA)

  • Champaign-Urbana, IL

County

  • County: Champaign, IL

Fingerprint

Explore the research topics touched on by this project. These labels are generated based on the underlying awards/grants. Together they form a unique fingerprint. Learn more about Elsevier's Fingerprint Engine here: https://beta.elsevier.com/products/elsevier-fingerprint-engine