Information Security and Cryptography

Information Security:
Information Security addresses foundations, methods, and tools for building trustworthy computing systems that remain secure in the presence of malicious adversaries. Research at INSAIT develops and applies methods for specifying, analyzing, and enforcing security policies in complex computing environments. Our research includes:
- formal methods for the specification, verification, and automated analysis of security protocols and software systems;
- foundations and mechanisms for authentication, authorization, access control, and secure digital identity;
- methods and tools for improving the security and privacy of software, distributed systems, and networked infrastructures;
- the construction, deployment, and maintenance of such systems.
Faculty involved in this research area: Prof. David Basin
Cryptography:
Cryptography studies the fundamental principles underlying secure communication and computation. It takes a mathematical approach to the design of secure protocols: desired security properties are specified in formal models and protocols are proven to satisfy these properties under well-established computational hardness assumptions. Research at INSAIT develops cryptographic protocols and analyzes their security in realistic models with a focus on the following directions:
- fundamental cryptographic primitives such as digital signatures and encryption schemes with improved efficiency, functionality and security guarantees;
- zero-knowledge proofs that allow one party to prove the validity of a statement without revealing any additional information beyond its correctness;
- post-quantum primitives that remain secure against adversaries equipped with quantum computers.
Faculty involved in this research area: Dr. Michael Reichle