Skip to main content
Go to the home page of the European Commission (opens in new window)
English English
CORDIS - EU research results
CORDIS

CIPHRA

Project description

Pioneering cybersecurity technology huge headache for hackers

As the world becomes increasingly interconnected, data and its acquisition have become more weaponised than ever before - and thus more valuable for resale on the black market, with personal and global impact. Passwords and their encrypted keys are the primary way of identifying valid users. Because encryption keys are stored together with the database of passwords, it is quite easy for hackers to access both. The EU-funded CIPHRA project has delivered a pioneering solution, a hardware device that plugs into the user device and generates a new password key on request. Since the keys are not stored in the databases with the encrypted passwords, it is very difficult for hackers to gain access to them - and the one is useless without the other. This encryption solution could be a revolution in cybersecurity.

Objective

The story of data breaches across industries with national, regional, and often global impact is a never-ending one. The
exposure of huge amounts of personal information and identities continues to be a major problem without a solution in sight
(see sample on the left of recent breaches to tech giants). At the nexus of the world of cyber security and cyber-crime is the
paramount issue of password and encryption key storage – the security measures in place to prevent hacking, and the
capabilities of the illegal hackers to hack into storage sites and decipher encrypted messages.Authentico has invented
CIPHRA which is a hardware dependent cryptographic processor that ensures that passwords and encryption keys are
essentially impossible to steal even if a database is hacked into. CIPHRA protects the cryptographic infrastructure by
securely processing passwords, and generating unclonable encryption keys from authentication requests using a technology
called PUF (physically unclonable functions). Authentico´s solution stands to be a major alternative to traditional key storage
methods. The keys are always present in the device, by generating the key on request. Information, such as password
hashes, can be inputted, but never read out or extracted. Even weak passwords cannot be broken because the generated
outputs are useless for an attacker and the database of encrypted and hashed passwords is useless without the key. This is
a far better solution than current approaches because the company’s secret keys are never stored anywhere, at any time,
making it extremely difficult for any malicious insider or outside hacker to ever gain access to them.

Programme(s)

Multi-annual funding programmes that define the EU’s priorities for research and innovation.

Topic(s)

Calls for proposals are divided into topics. A topic defines a specific subject or area for which applicants can submit proposals. The description of a topic comprises its specific scope and the expected impact of the funded project.

Funding Scheme

Funding scheme (or “Type of Action”) inside a programme with common features. It specifies: the scope of what is funded; the reimbursement rate; specific evaluation criteria to qualify for funding; and the use of simplified forms of costs like lump sums.

SME-1 - SME instrument phase 1

See all projects funded under this funding scheme

Call for proposal

Procedure for inviting applicants to submit project proposals, with the aim of receiving EU funding.

(opens in new window) H2020-EIC-SMEInst-2018-2020

See all projects funded under this call

Coordinator

AUTHENTICO TECHNOLOGIES AB
Net EU contribution

Net EU financial contribution. The sum of money that the participant receives, deducted by the EU contribution to its linked third party. It considers the distribution of the EU financial contribution between direct beneficiaries of the project and other types of participants, like third-party participants.

€ 50 000,00
Address
FRAMNAS 3
47537 GOTEBORG
Sweden

See on map

SME

The organization defined itself as SME (small and medium-sized enterprise) at the time the Grant Agreement was signed.

Yes
Region
Södra Sverige Västsverige Västra Götalands län
Activity type
Private for-profit entities (excluding Higher or Secondary Education Establishments)
Links
Total cost

The total costs incurred by this organisation to participate in the project, including direct and indirect costs. This amount is a subset of the overall project budget.

€ 71 429,00
My booklet 0 0