Fortress klein.png

Fully Optimized Root of Trust for Robust Embedded Secure Systems

(2025 - 2028)

Funded by: EU HORIZON-CL3-2024-CS-01-02
Duration: 09/2025 - 08/2028  (3 years)
Contact at ESSEC: Prof. Dr. Michael Hutter

The foundation of modern cybersecurity lies in the secure boot process, ensuring only trusted and authenticated software runs on a device. By validating code integrity through cryptographic signatures, secure boot upholds the Confidentiality, Integrity, and Availability triad, acting as the first line of defence against tampering, malware, and unauthorized changes. Currently, secure boot relies on traditional cryptographic algorithms like RSA. However, the advent of quantum computing threatens these systems, as quantum algorithms like Shor’s could break them, necessitating a transition to Post-Quantum Cryptography. The European Union and relevant agencies, such as ANSSI and BSI, advocate for a Post-Quantum/Traditional (PQ/T) hybrid cryptographic model, combining quantum-resistant algorithms with traditional cryptography for added resilience. Implementing quantum-safe secure boot remains challenging due to the performance, scalability, and compliance trade-offs of PQ/T solutions. However, to date there seems no significant progress has been made in this domain. FORTRESS aims to address these challenges by developing a scalable and efficient hybrid secure boot architecture. It will design a flexible Root of Trust, integrating both traditional and post-quantum algorithms while exploring trade-offs between security, performance, and cost. The project will focus on hardware-software co-design principles, enabling diverse platforms - embedded systems, edge devices, and Critical National Infrastructure - to transition to quantum-resistant architectures seamlessly. Additionally, the project will engage industry stakeholders to align with regulatory and standardization efforts, ensuring practical deployment and maximum impact. By developing a critical building block for a wide range of applications, FORTRESS will safeguard Europe’s digital infrastructure, fostering resilience and leadership in the post-quantum era.

Project Partners

EU eng klein.jpg     logo_pqshield_3.png       logo_cyberhive_3.png

 

    logo_eurescom_3.png      logo_eshard_3.png     Codasip_3.png.jpg