Roadmap Timeline
-
2029
-
2022
-
2024
-
2025
-
2026
-
2027
-
2029
-
2030
Trustworthy Software
2021-2029
Problem description
Overall challenge: gain trust in the security of software, either by construction or by validation. Security here is taken to mean that the software respects the confidentiality, integrity, and availability of data to be protected.
Research aspect: Trust in software can be obtained either by construction or by validation. We propose to explore both directions. We will integrate security in a model-driven software engineering process, thereby giving substance to the security-by-design concept. We will, in particular, develop formal methods with high guarantees of security properties. In terms of validation, we shall develop analysis techniques for precise models of software behavior. This will enable the efficient detection of malware. In the long term, this could also provide new, more automated software security certification procedures.
Industrial demand: Strong in many sectors, including banking, finance, transportation, energy, health.
Social aspect: Increase the confidence that end users have in the digital economy. Guarantee the protection of privacy.
Industrial demand: Strong in many sectors, including banking, finance, transportation, energy, health.
Social aspect: Increase the confidence that end users have in the digital economy. Guarantee the protection of privacy.
Final goal: A comprehensive collection of theories, techniques and tools that can enhance the trust we have in the security of our software.
Benefits for EU: Win a competitive edge in other industrial sectors by an increase in software productivity, security and certification.
Domain (JRC Taxonomy): Assurance, audit and certification. Software and hardware Security Engineering. Theoretical foundations.
Sector (JRC Taxonomy): Defense, Energy, Financial, Health, Nuclear, Transportation, Space.
Relation to emerging technologies: The emergence of quantum computing will raise additional questions of how to construct and validate software systems. Techniques developed for classical Trustworthy Software will need to be reviewed in light of this emerging paradigm.
Benefits for EU: Win a competitive edge in other industrial sectors by an increase in software productivity, security and certification.
Domain (JRC Taxonomy): Assurance, audit and certification. Software and hardware Security Engineering. Theoretical foundations.
Sector (JRC Taxonomy): Defense, Energy, Financial, Health, Nuclear, Transportation, Space.
Relation to emerging technologies: The emergence of quantum computing will raise additional questions of how to construct and validate software systems. Techniques developed for classical Trustworthy Software will need to be reviewed in light of this emerging paradigm.