UPB Logo
Contact
  • Deutsch
  • English
    • Open Page "Studies"
      • Open Page "Prospective students"
      • Eltern
    • Students
    • International students & prospective students
    • School & teachers
    • Open Page "Teaching"
      • Open Page "Profile"
      • Academic Mission Statement
      • Digitalization & E-Learning
      • Open Source
      • Open Page "Teaching"
      • Competence-Oriented Education
      • Exam design
      • Organizing Courses
      • Course Evaluations
      • General Education Requirements
      • Lecture series on sustainability
    • AI in teaching
      • Open Page "Digital Teaching"
      • Digital Teaching
      • Digital learning rooms
      • Digital test formats
      • Digital test formats
      • Digital tools
      • FAQs
      • Open Page "Qualification and service"
      • Higher Education Development Unit
      • Writing Center
      • Internal Professional Development and Further Education
      • Interdisciplinary Cooperation to Improve Quality in Teacher Education (PLAZ)
      • Faculty-Specific Initiatives
      • Internationally Focused Academics
      • Open Page "Educational innovations"
      • Teaching Awards at UPB
      • Fellowship
      • Best-Practices Teaching Symposium
      • Teaching Projects
      • E-Learning Label
      • Open Page "Teaching research networks"
      • DH.NRW
      • Foundation for Innovation in Higher Education
      • Centre for Higher Mathematics Education (khdm)
      • Academic quality
    • Open Page "Research"
      • Open Page "Research profile"
      • Key research areas
      • Interdisciplinary research institutes
      • Research in the faculties
      • Collaborative Research Centres
      • Graduate Programmes and Schools
      • DFG Research Units
      • DFG Priority Programmes
      • ERC Grants
      • Leibniz Prize Winners
      • Heinz Maier Leibnitz Prize Winners
      • Open Page "Academic career"
      • Early career stages
      • Professorship at Paderborn University
      • Job portal
      • University as an employer
      • Open Page "Research funding and services"
      • Funding and application advice
      • Legal advice in research and development
      • Ethics Committee
      • Research Information at UPB
      • Research data management
      • Publication Service of the University Library
      • Open Access Portal
      • Inventions & patents
      • Start-ups and entrepreneurship
      • Network for Interdisciplinary Research
      • Internal grants (Committee for Research and Junior Academics)
      • Open Page "Research culture"
      • Research-Oriented Standards on Gender Equality
      • Gender & Diversity Consulting
      • Ethics committee
      • Good Research Practice
      • Human Resources Strategy for Researchers
    • Open Page "Transfer"
    • Creating together
    • Innovating together
    • Reflecting together
    • Contacts
    • Open Page "International"
    • International Profile
    • International Campus
    • Open Page "University"
      • Open Page "About us"
      • Mission Statement
      • History
      • Important Personalities and Pioneers
      • University Society
      • Alumni
      • Unishop
      • Open Page "Our organisation"
      • University Executive Board
      • Advisory Board
      • Senate
      • Faculties
      • Central University Administration
      • Central research institutes
      • Central operating units
      • Agencies and authorised representatives
      • Anlauf- und Beratungsstellen
      • Universitätskommissionen
      • Open Page "Working at UPB"
      • Vacancies
      • Equality, Compatibility and Diversity
      • Welcome Services
      • Personnel development
      • Scientific career paths
      • Dual Career Service
      • Healthy university
      • Social, sporting and cultural activities
    • Maps & directions
    • Open Page "Faculties"
    • Faculty of Arts and Humanities
    • Faculty of Business Administration and Economics
    • Faculty of Science
    • Faculty of Mechanical Engineering
    • Faculty of Computer Science, Electrical Engineering and Mathematics
  • Press
Creating trustworthy IT systems using cryptography
Creating trustworthy IT systems using cryptography
Contact
  1. Paderborn University
Back to the news list

Se­cur­ity solu­tions for the com­put­ing of the fu­ture

24.04.2023  |  Research

A contribution from Press release

Share post on:

  • Share on Instagram
  • Teilen auf Twitter
  • Teilen auf Facebook
  • Teilen auf Xing
  • Teilen auf LinkedIn
  • Teilen über E-Mail
  • Link kopieren

Creating trustworthy IT systems using cryptography

Banking, emails, shopping: increasing volumes of data are being collected, processed and stored online. The challenge of ensuring that they are securely encrypted is similarly increasing, because in the future, quantum computers will be able to crack current encryptions. There is a need for solutions to enable trustworthy IT systems, both now and in the years to come. The Collaborative Research Center (CRC) ‘CROSSING’ (Cryptography-Based Security Solutions: Enabling Trust in New and Next Generation Computing Environments) sees researchers working to develop cryptography-based security solutions that will be able to withstand even high-performance quantum computers. This joint project is a collaboration between TU Darmstadt, Paderborn University, the University of Duisburg-Essen, the University of Regensburg, and the Fraunhofer Institute for Secure Information Technology (SIT) in Darmstadt. More than 65 researchers from the fields of quantum physics, cryptography, system security and software engineering are working together in an interdisciplinary collaboration to develop new security solutions that create trust in the current and next generation of computing environments. Last year, the CRC – which has been funded by the German Research Foundation (DFG) since 2014 – was extended for a third term until 2026 with ten million euros of funding.

Prof. Dr. Eric Bodden of the Heinz Nixdorf Institute and Department of Computer Science at Paderborn University is heading the ‘Secure Integration of Cryptographic Software’ sub-project under the CRC’s ‘Engineering’ section. With his team, he is developing methods and technologies to enable encryption technology to be securely integrated into various applications. This means that even people who are not experts in the field should be able to correctly use cryptographic processes.

Improved information security: freely available platform for developers
 

During the first two funding phases, the CRC researchers have already managed to develop secure encryption and signature processes to combat quantum attacks. But although cryptography offers a variety of solutions to protect sensitive data, implementing it poses some challenges. Software developers are therefore having to tackle issues relating to the choice, composition and integration of cryptographic components. Among other things, this creates a danger of insecure combinations.

To overcome this hurdle, Prof. Bodden and his team are tackling the objective of assisting developers using automation tools. The researchers have designed various software development and analysis techniques to achieve this. The tools are being made freely accessible to all via the intelligent open-source platform ‘CogniCrypt’, developed jointly by the CRC researchers. In doing so, they are seeking to help application developers choose suitable cryptographic components, as well as incorporate them securely into their software to prevent vulnerabilities and errors from the outset.

Avoid security loopholes right from the start
 

To raise awareness of the proper way of dealing with these security solutions, the researchers have documented some cryptography regulations. This is because if any elements within an application are not executed in a specific way, security loopholes quickly arise that can cause considerable damage.

The researchers have followed the ‘allowlisting’ approach in this: ‘“allowlisting” is a form of application control that reduces malicious security attacks by only allowing correct cryptography to be executed’, explains Michael Schlichtig, a researcher in the ‘Secure Software Engineering’ research group at the Heinz Nixdorf Institute. Researchers consider this as offering a major advantage over ‘denylisting’, which prohibits executions based on known threats: ‘If I need to list all potential threats, it is very easy to overlook something, making the solution insecure. “Allowlisting”, on the other hand, allows us to ensure that only the secure use of cryptography is permitted’, Schlichtig explains.

In this third and final phase of funding, the researchers in the various project groups are currently working to combine their research findings as optimally as possible, so that the newly developed cryptography-based security solutions are easy but also effective for IT developers, administrators and end users to employ.

Photo (Paderborn University, Jennifer Bounoua): Trustworthy IT systems: the Collaborative Research Center (CRC) ‘CROSSING’ brings together more than 65 researchers from the fields of quantum physics, cryptography, system security and software engineering to develop cryptography-based security solutions.
Download (4 MB)

Contact

business-card image

Prof. Dr. Eric Bodden

Secure Software Engineering / Heinz Nixdorf Institut

Write email +49 5251 60-6563
More about the person
business-card image

Michael Schlichtig

Secure Software Engineering / Heinz Nixdorf Institut

Write email +49 5251 60-6580
More about the person
Universität Paderborn

Warburger Str. 100
33098 Paderborn
Germany

Phone University

+49 5251 60-0
Quick links
  • Cafeteria
  • Online application
  • Library
  • PAUL
  • PANDA
Social networks
Legal notice
  • Imprint
  • Data privacy
  • Whistleblower system
  • Accessibility Declaration