Deliverable D4.4: Research and Development Roadmap 2
Total Page:16
File Type:pdf, Size:1020Kb
Proposal No. 830929 Project start: February 1, 2019 Call H2020-SU-ICT-03-2018 Project duration: 42 months D4.4 Research and Development Roadmap 2 Document Identification Due date 31 January 2021 Submission date 29 January 2021 Revision 3.0 Related WP WP4 Dissemination Public Level Lead FORTH Lead Author Evangelos Markatos Participant (FORTH) Contributing AIT, Atos, ATOS, Related D4.1, D4.3 Beneficiaries BBVA, CNR, Deliverables Dawex, DTU, ENG, FORTH, ISGS, JAMK KUL, NTNU, POLITO, SIE, SINTEF, TDL, UCY, UM, UMA, UMU, UNITN, UPRC CyberSec4Europe D4.4 Research and Development Roadmap 2 Abstract: This is the second of a sequence of three research and development roadmaps of the CyberSec4Europe project. The goal of this roadmap is to identify major research challenges in the verticals of the project, and to explain what is at stake and what can go wrong if problems are left unsolved. The verticals studied are: (i) Open Banking, (ii) Supply Chain Security Assurance, (iii) Privacy-Preserving Identity Management, (iv) Incident Reporting, (v) Maritime Transport, (vi) Medical Data Exchange, and (vii) Smart Cities. For each vertical we identify the research challenges that need to be addressed and group them according to time in three phases: short term (12 months), medium term (until the end of the project), and long term (beyond the end of the project). To emphasize the European nature of these roadmaps, each vertical clearly demonstrates how it can contribute to dimensions with significant European impact including European Digital Sovereignty, the COVID-19 pandemic, and the European Green Deal. Finally, a SWOT (Strengths, Weaknesses, Opportunities and Threats) Analysis clearly demonstrates how Europe can approach the research in each area, what are the hurdles in the way, what are the strengths that can be exploited, and what can be expected at the end. This document is issued within the CyberSec4Europe project. This project has received funding from the European Union's Horizon 2020 Programme under grant agreement no. 830929. This document and its content are the property of the CyberSec4Europe Consortium. All rights relevant to this document are determined by the applicable laws. Access to this document does not grant any right or license to the document or its contents. This document and its contents are not to be used or treated in any manner inconsistent with the rights or interests of the CyberSec4Europe Consortium and are not to be disclosed externally without prior written consent from the CyberSec4Europe Partners. Each CyberSec4Europe Partner may use this document in conformity with the CyberSec4Europe Consortium Grant Agreement provisions and the Consortium Agreement. The information in this document is provided as is, and no warranty is given or implied that the information is fit for any particular purpose. Anyone using the information does so at their own sole risk and liability. ii CyberSec4Europe D4.4: Research and Development Roadmap 2 Executive Summary In the context of the CyberSec4Europe project, we publish a yearly research and development roadmap. Unlike other similar road mapping activities, which may aim to cover all (or most) aspects of cybersecurity, our roadmaps aim to explore emerging threats and to prioritise research directions, mainly in the areas of the seven verticals that have been identified in the project: (i) open banking, (ii) supply-chain security assurance, (iii) privacy-preserving identity management, (iv) incident reporting, (v) maritime transport, (vi) medical data exchange, and (vii) smart cities. Our first roadmap (Deliverable D4.3) was published in 2020 and focused on landscaping the research areas of the verticals and establishing the most important priorities [Markatos 2020]. This document, the second roadmap in the series, focuses on 1. updating the research priorities, introducing any new research topics, and possibly readjusting the ranking of existing ones 2. providing a SWOT analysis that builds on strengths and addresses shortcomings: o what are the strengths of Europe in these verticals? o what are the weaknesses? o what (global) opportunities may exist? o what threats should we be careful of? 3. explaining how the chosen research priorities interact with the important dimensions of European policies in 2020-2021 as they relate to: o the European Digital Sovereignty, o the new reality imposed by COVID-19, and o the Green Deal. How to read this document To provide a uniform approach to the roadmap, each vertical is covered in one section starting from section 3 all the way to section 9. In the interests of homogeneity, subsections are structured as follows: • Subsections1 *.1 provide the big picture of the vertical. • Subsections *.2 provide an overview. • Subsections *.3 describe what is at stake for each vertical. • Subsections *.4 describe the attackers. • Subsections *.5 describe the research challenges and provide background information. More specifically: o Subsections *.5.1 describe the state of the art for each vertical and subsections *5.2 indicate the final goal; o Subsections *.5.3 provide a SWOT analysis; o Subsections *.5.4 explain how each vertical contributes to European Digital Sovereignty; o Subsections *.5.5 describe the interactions with COVID-19; o Subsections *5.6 describe the interactions with the Green Deal; and o The remaining subsections of *.5 describe the research challenges. 1 When we write *.1 we mean subsections 3.1, 4.1, 5.1 etc. until subsection 9.1. When we write *.2 we mean subsections 3.2, 4.2, 5.2, … 9.2, and so on and so forth. iii CyberSec4Europe D4.4 Research and Development Roadmap 2 • Subsections *.6 describe the mapping of the challenges to the big picture. • Subsections *.7 describe the methods and tools for the research challenges. • Subsections *.8 provide the roadmap for each vertical. Each roadmap is structured in three phases: o Short-term, o Medium-term, and o Long-term, • Finally, subsections *.9 provide a summary of each vertical. To place this work in context, Section 10 provides progress with respect to work reported in the first Roadmap (D4.3 [Markatos 2020]. Finally, section 11 surveys roadmaps (or similar research priorities documents) that were published in 2020 including ENISA2’s annual cybersecurity prioritisation document [ENISA 2020B], Europol’s annual publication IOCTA (Internet Organized Threat Assessment), which lists the evolution of the threats in cybercrime [EUROPOL 2020], JRC3’s Digital Anchor, SPARTA’s Roadmap, etc. We hope that this document will be a useful tool for people who are interested in studying and understanding (i) the importance and (ii) the European dimensions of the research challenges in the vertical areas of the project. 2 ENISA is the European Network and Information Security Agency 3 JRC is the Joint Research Centre (of the European Commission) iv CyberSec4Europe D4.4: Research and Development Roadmap 2 Document information Contributors Name Partner Cristina Alcaraz UMA Ahmad Amro NTNU Marco Angelini ENG Elias Athanasopoulos UCY Jorge Bernal UMU Karin Bernsmed SINTEF Panagiotis Bountakas UPRC Vanesa Gil Laredo BBVA Laura Colombini ISGS Said Daoudagh CNR Jérémy Decis DAWEX Christos Douligeris UPRC Carmen Fernández Gago UMA Jesús García UMU Vasileios Gkioulos NTNU David Goodman TDL Christos Grigoriadis UPRC Alba Hita UMU Marko Hölbl UM Wouter Joosen KUL Elma Kalogeraki UPRC Prabhakaran Kasinathan SIE Georgios Kavalieratos NTNU Marko Kompara UM Panagiotis Kotzanikolaou UPRC Stephan Krenn AIT Alberto Lluch Lafuente DTU Antonio Lioy POLITO Eda Marchetti CNR Evangelos Markatos FORTH Per Håkon Meland SINTEF Vincenzo Napolitano ENG Aida Omerovic SINTEF Jani Päijänen JAMK Spyros Papastergiou UPRC Ivan Pashchenko UNITN Juan Carlos Pérez Baún Atos Salvador Perez UMU Rodrigo Roman UMA Michael Salmony TDL Vincenzo Savarino ENG Antonio Skarmeta UMU Rafael Torres UMU v CyberSec4Europe D4.4 Research and Development Roadmap 2 Martin Wimmer SIE Ricarda Weber SIE Christos Xenakis UPRC Susana González Zarzosa Atos Reviewers Name Partner Elias Athanasopoulos UCY Sandro Luigi Fiore UNITN Javier Lopez UMA Kai Rannenberg GUF Ahad Niknia GUF History Version Date Authors Comment 0.01 October 10th 2020 Evangelos Markatos Table of Contents 0.02 October 22th 2020 Rafael Torres and Jesus García Section 5 0.03 October 22th 2020 Alba Hita and Salvador Perez Section 9 0.04 November 4th 2020 Marko Kompara Section 5 0.05 November 4th 2020 Stephan Krenn Section 5 1.0 December 16th 2020 Evangelos Markatos (based on input First version for high-level from all partners) review 2.0 January 15th 2021 Evangelos Markatos (based on input Second version addresses from all partners) the comments of the reviewers 3.0 January 28th 2021 Evangelos Markatos Third version addresses the comments of the PC vi CyberSec4Europe D4.4: Research and Development Roadmap 2 Short Table of Contents: Executive Summary ................................................................................................................................... iii 1 Introduction ...................................................................................................................................... 1 2 Context and Methodology ............................................................................................................... 3 3 Open Banking .................................................................................................................................. 11 4 Supply Chain Security Assurance...................................................................................................