Cybersecurity: ensuring security and privacy by design

Share

CEA-List's strength rests on a skillful combination of academic and scientific expertise, coupled with a deep understanding of real operational needs. This legitimacy allows it to design innovative, high-performing solutions matching the constant evolution of attackers' capabilities.

Patricia Mouy

Head of the Cybersecurity Program — CEA-List

A key part of digital transformation

Cybersecurity has become a major issue in digital transformation. It safeguards autonomy and peace in cyberspace. However, the now sprawling and decentralized perimeters of information processing systems create glaring asymmetries between the ease of attack and the difficulty of defense. Furthermore, the interconnections between the physical and digital worlds are generating new threats: so-called “kinetic” cyberattacks, which no longer aim to compromise virtual resources but rather physical assets. Added to these technical challenges are fundamental impacts on questions of sovereignty and the protection of private data within complex economic and geopolitical contexts.

To address this set of challenges, CEA-List spearheads collaborative initiatives to develop new technological tools. The institute is also an active contributor to national and European strategies in this field.

An innovative vision for cybersecurity

Only a hybrid human-machine approach to cybersecurity tasks will make it possible to overcome the immense challenge posed by cyber threats. The aim is to enhance the experts’ knowledge and judgment capabilities by equipping them with tools that multiply the effectiveness of their actions and their ability to act more efficiently across the entire attack-response cycle.

Equipped with these new capabilities, experts will work on system evaluation and auditing, as well as network monitoring and management. Their responsabilities will extend from the interfaces between these digital systems and the physical world to their evolution over time and to dependencies on suppliers. The tools developed by CEA-List, leveraging innovative automation, visualization, and analysis features, form the cornerstone of these capabilities.

In a world subject to constant cyber threats, the goal of CEA-List and its partners is to create a network of islands of trust, designed to store information securely or to serve as a command post in the event of attacks.

CEA-List’s work in cybersecurity thus aims to deliver:

  • software countermeasure solutions for protection against physical attacks, along with pre-silicon evaluation of their guarantees;
  • high-assurance tools for evaluating system robustness from the design stage onward;
  • monitoring capabilities encompassing both the digital and physical worlds;
  • communication orchestration and monitoring capabilities relying on ultra-lightweight probes and virtual network functions ensuring the security and resilience of communication networks;
  • advanced encryption solutions that guarantee the confidentiality of exchanged and processed data.

The challenge of smart distributed environments

Systems using distributed ledgers, neural networks, or even quantum computing are part of this new generation of fast-growing technologies. CEA-List is committed to developing techniques and tools to protect these types of systems, which are exposed to new forms of attack.

These same systems are also helping to build innovative cybersecurity approaches. CEA-List is exploring the use of innovative blockchains to provide proof of integrity, as well as homomorphic encryption of data allowing the exchange and processing of data without revealing it. The institute also researches AI to multiply its data-processing capabilities. In particular, our researchers are studying ways of using this technology to translate requirements expressed in natural language into mathematical language, in order to better addressing security aspects from the earliest stages of design.

CEA-List, a driving force in France's cybersecurity strategy

With its world-class expertise in cybersecurity, and through its positioning as a technological research institute, CEA-List acts as a trusted third party, capable of building relationships with major regulators such as ANSSI, leading industrial players (Thales, EDF, Siemens, etc.), academic stakeholders (ANR, etc.) and the startup ecosystem (Parsec, etc.).

It also takes care to meet CEA’s internal needs and, in particular, those related to its sovereign missions.

Cybersecurity is a discipline that blends mathematical theory with experimental approaches. On this second front, CEA-List boasts the resources needed to support its teams and partners using state-of-the-art tools and techniques.

 

Examples of CEA-List’s tools

  • BINSEC (formal binary code analysis for security)
  • Frama-C (program analysis)
  • Cingulata (garantees confidentiality by design through building applications capable of performing operations on encrypted data without decrypting it)
  • COGITO (a compiler that adds countermeasures to protect data and code running on an embedded system against physical side-channel attacks)
  • µArchiFI (pre-silicon RTL analysis of processors subjected to fault-injection attacks)
  • XanthOS (ensures, during the design of an OS kernel, functional safety and security properties by construction)
  • MAX (blockchain simulation and analysis)
  • SIGMO-IDS (detects attacks on communication links and provides an instant response through security countermeasures within networks)
  • NEON (an SDN, or *software defined network*, dedicated to heterogeneous networks but also addressing TSN, or *Time-Sensitive Networking*)

Other research areas addressed at CEA-List:

CEA-List is engaged in several French and European cybersecurity initiatives and projects.

 

Examples of notable projects (non-exhaustive list):

  • DefMal, on defense against malware,
  • Arsene, on the security of embedded systems,
  • Compromis, on the security of multimedia data,
  • SecureCompute, on the security of cloud data processing,
  • SecurEval, on software security evaluation,
  • SuperViz, on security supervision and orchestration,
  • REV, on vulnerability exploitation.

 

Campus Cyber: CEA-List is a partner of this flagship French cybersecurity hub. It contributes to the academic and research dimension and is involved in several projects such as:

  • SWHSec, for securing the Software Heritage archive;
  • Forward, on the contribution of formal methods to the security evaluation of hardware components;
  • Secubic, to strengthen the detection of vulnerabilities related to the software supply chain.

 

Numerous national projects:

  • EMASS— Efficient Memory Analysis for System SoftwareEMASS
  • Comemov — collaborative memory models for formal verification
  • RAR TwinSec — hardware security by design for embedded systems
  • Vedysec— dynamic verification of security properties
  • TAVA — towards the automation of vulnerability analyses

 

European projects:

  • Starlight, to strengthen the EU’s strategic autonomy in artificial intelligence (AI) for law enforcement agencies (LEAs).
  • TANGO, on a digital technology for secure and reliable data flows, ensuring data sovereignty, governance, and provenance for citizens, businesses, and public administrations in Europe.
  • ORQESTRA, for the development of practical and certifiable post-quantum cryptography solutions for military systems.
  • SecOpera , which aims to provide a comprehensive toolkit for security auditing and testing to identify security issues in open-source software and hardware.
  • KINAITICS, which explores new attack opportunities created by AI-based systems and develops innovative defense approaches to ensure their robustness and resilience against attacks.
  • And many others, such as MedSecurance (medical IoT), AInception (AI for cyberdefense), and Trumpet(data privacy and AI for healthcare)…
  • At the European strategic level, this involvement is reflected notably in participation in the European ECCO project (European Cybersecurity COmmunity), launched in 2022 by the European Cyber Security Organisation ECSO, to strengthen support for the cybersecurity community. The goal is to support the activities needed to develop, promote, coordinate, and organize the work of the cybersecurity skills community at both the European and national levels.

 

As well as National and international partnerships:

  • DGA (Direction Générale de l’Armement) — French defense procurement and technology agency
  • ANSSI (Agence Nationale de la Sécurité des Systèmes d’Information) — France’s national cybersecurity authority
  • Thales — aerospace, defense, and security electronics
  • InGroupe — secure digital identity solutions
  • Dawex — data exchange and data-marketplace technology
  • EDF — electricity generation and distribution (critical infrastructure)
  • Idemia — biometric identity and security technologies
  • Schneider Electric — industrial automation and energy management
  • RTE— French electricity transmission grid operator (critical infrastructure)