Digital Security
Comment
Stakeholder Type
GESDA
4.4.1 Privacy and Security. 2026
Photo: 4.4.1 Privacy and Security. 2026

Topic

Digital Security

Anticipation Committee Chair:

Linus Gasser

Lead Engineer, Center for Digital Trust (C4DT)

EPFL

Digital Security

The world of the 21st century is increasingly reliant on digital technologies, creating a slew of challenges for tasks, processes, institutions and individuals that require privacy, transparency and security in all their various forms. A number of mathematical and technical innovations, such as zero-knowledge proofs, trusted execution environments, homomorphic encryption and advances in formal verification are improving the prospects of creating effective digital-security measures.

The world of the 21st century is increasingly reliant on digital technologies, creating a slew of challenges for tasks, processes, institutions and individuals that require privacy, transparency and security in all their various forms. A number of mathematical and technical innovations, such as zero-knowledge proofs, trusted execution environments, homomorphic encryption and advances in formal verification are improving the prospects of creating effective digital-security measures.

However, the practice of digital security still faces a range of theoretical and practical challenges in the face of numerous emerging forms of computing and communication. At the heart of these challenges is AI, which is dramatically increasing the capabilities of both defenders and attackers in cybersecurity. At the same time, the “internet of things” is extending its web through every aspect of human society, from transport and industry to healthcare and entertainment. By some estimates, there will be 100 billion devices connected to this network by 2050.1 That raises a host of security issues on a scale never before seen. Next-generation telecommunications networks based on 6G technologies will also need to be secured, as will biological information. Then there is the health, financial and personal data stored in the cloud that must be processed without revealing its content. And if that were not enough, the next decade will see quantum computing coming online with the computational power to crush some existing encryption systems. Securing these systems will be a significant task and developing the mathematical foundations to guarantee this security will be even tougher.

KEY TAKEAWAYS

Thanks to increases in private, institutional and governmental activities in the digital sphere, there is a growing need for reliable and practical digital-security solutions. Privacy and security are fundamental to democracy, economic activity, communications and healthcare delivery, but there is also a need for transparency in these activities, depending on the context. Researchers are developing a range of solutions for establishing, protecting and verifying digital identity, with a growing use of biometric data offering particular challenges and opportunities. Novel encryption technologies are coming onto the market, although technological progress is necessarily slow here, and the prospect of emerging quantum-computing systems able to challenge some of the most widely used encryption methods is creating some legitimate concern about whether encryption can stay ahead of encryption-breaking operations. Many of these concerns might be allayed through development of better and more wide-ranging Formal verification protocols, which provide reliable mathematical modelling of real-world capabilities and scenarios.

Topic:

Anticipation Potential

Digital Security

Sub-Fields:

Privacy and security
Digital identity
Novel encryption technologies
Formal verification
Digital identity and Privacy and security are very much under the spotlight today. Research in these areas is expected to see significant developments in the coming five years. Formal verification technology breakthroughs are further away and will be less transformative. Digital identity is the area with the highest scope for action, highlighting the need for coordinated international involvement.

Anticipatory Impact:

Three fundamental questions guide GESDA’s mission and drive its work: Who are we, as humans? How can we all live together? How can we ensure the well-being of humankind and the sustainable future of our planet? We asked researchers from the field to anticipate what impact future breakthroughs could have on each of these dimensions. This wheel summarises their opinions when considering each of these questions, with a higher score indicating high anticipated impact, and vice versa.

  • Anticipated impact on who we are as humans
  • Anticipated impact on how we will all live together
  • Anticipated impact on the well-being of humankind and sustainable future of our planet

Privacy and security

Issues of privacy and security now affect all citizens, as well as state-level operations. The pervasive use of digital technology means that, for an equitable society, personal data and communications have to be encrypted in ways that allow transactions and access to services such as welfare payments, healthcare and voting facilities, as well as private web-browsing, messaging and mobile-phone use.

Future Horizons:

×××

5-yearhorizon

AI cybercrimes change focus of security

AI is used to encourage people to use IT systems without employing proper security measures. A handful of spectacular cybercrimes demonstrate the role of AI in exploiting weaknesses in conventional security systems. The issue focuses the global security community on whether and how to control AI as well as how to balance citizens’ rights with public safety.

10-yearhorizon

Augmented reality redraws privacy boundaries

Malicious state-level cyber-activity becomes so damaging for privacy and security that it forces an expansion of the definition of cyberwarfare. That lowers barriers to conventional war while raising the stakes for digital diplomacy. Growing activity in the metaverse focuses security research onto the challenges of privacy and safety in immersive environments. Awareness-raising about abuse of data-sharing causes individuals to take more control of their personal data, as well as protect themselves with more use of multifactor authentication.

25-yearhorizon

Tension grows between the digital haves and have-nots

Countries with secure digital infrastructures experience significant growth in their knowledge-based economies, often at the expense of digital privacy. But countries without this capability suffer economic hardship, and the division dramatically redraws the global balance of power.

This requires a vast technological infrastructure that is not only efficient and secure, but also — depending on the context — private yet transparent. At issue is the confidentiality, integrity and availability of information as well as related concerns over authenticity, accountability and reliability. There is also the inevitable trade-off between privacy and system functionality that individuals must navigate, which often brings into focus tensions between the way people think about privacy and the way they act.2

New technologies are also raising security and privacy issues. Video analysis can reveal an individual’s identity and location but also the people they meet, their mood and even certain medical conditions. The transmission and storage of biometric data requires the implementation of new protocols, and the increasing prevalence and accessibility of a wide range of biology-based data (such as genomic information, healthcare data and access protocols for laboratory samples of weaponisable pathogens) means that “cyberbiosecurity” is an emerging research topic of significant importance. AI is also changing this landscape,3 not least because of its pattern-recognition capabilities and the potential it offers to automate many tracking processes.

Privacy and security - Anticipation Scores

The Anticipation Potential of a research field is determined by the capacity for impactful action in the present, considering possible future transformative breakthroughs in a field over a 25-year outlook. A field with a high Anticipation Potential, therefore, combines the potential range of future transformative possibilities engendered by a research area with a wide field of opportunities for action in the present. We asked researchers in the field to anticipate:

  1. The uncertainty related to future science breakthroughs in the field
  2. The transformative effect anticipated breakthroughs may have on research and society
  3. The scope for action in the present in relation to anticipated breakthroughs.

This chart represents a summary of their responses to each of these elements, which when combined, provide the Anticipation Potential for the topic. See methodology for more information.

Digital identity

One of the most difficult digital-security problems is to create ways for establishing digital identities that are useful in a wide range of applications but remain secure.

Future Horizons:

×××

5-yearhorizon

AI identity theft threatens democracy

State-sponsored AI cybercrime combines the data from multiple security leaks to produce convincing patchworked identities for large-scale fraud. This theft occurs on such a large scale that it threatens banking systems, healthcare and even democracy. Passwords become a rarely used means of authentication, replaced by passwordless approaches. Autonomous agents trade on their owner’s behalf using networks of verifiable trust that occasionally, through unpredictable herding behaviour, create runs on certain types of goods, leading to shortages and profiteering. Encryption protocols such as PGP and SPKI flourish.

10-yearhorizon

The notion of personal identity mutates

The notion of one identity per person begins to change with the legitimate use of multiple IDs. This creates diverse social landscapes, with the opportunity to segment an online existence to share different parts of life with different groups of people. A new breed of security attack via the internet of things, particularly medical devices, poses a life-threatening risk for millions of people.

25-yearhorizon

Establishing and protecting identity becomes routine

Identity-authenticating technology is developed in ways that allow even young children and technology-disadvantaged individuals to establish and protect their identities.

This will mean consideration of indirect insecurities, such as LGBTQ+ people being unwillingly identified because of data-sharing leading to openly targeted advertising,4 doxing5 or even physical attacks. Identity security relies on data policies and software routines as well as on “unlinkability”6 and secure hardware implementations such as “secure enclaves”. It is likely that unlinkability will allow people to maintain several legitimate identities simultaneously, for example. Multifactor authentication is used now, but its importance is likely to grow, with distributed and independent issuers of factors making identity theft much harder than it is today.

Reliable means of establishing identity will be key as autonomous agents begin to augment people in certain decision-making scenarios. These agents will need their own identities that are securely linked to their owners. This kind of distributed decision-making raises broader issues about the way human identity will evolve in future. What’s more, establishing the identity of machines is an important issue for the “internet of things”,7 which consists of devices with limited power, network and computational ability. Identity in this context will have to be established by methods that do not rely on strong encryption, network connections and so on. Ensuring that these mechanisms are secure and fit for purpose is an ongoing area of study.

Digital identity - Anticipation Scores

The Anticipation Potential of a research field is determined by the capacity for impactful action in the present, considering possible future transformative breakthroughs in a field over a 25-year outlook. A field with a high Anticipation Potential, therefore, combines the potential range of future transformative possibilities engendered by a research area with a wide field of opportunities for action in the present. We asked researchers in the field to anticipate:

  1. The uncertainty related to future science breakthroughs in the field
  2. The transformative effect anticipated breakthroughs may have on research and society
  3. The scope for action in the present in relation to anticipated breakthroughs.

This chart represents a summary of their responses to each of these elements, which when combined, provide the Anticipation Potential for the topic. See methodology for more information.

Novel encryption technologies

The science of hiding information by encrypting it to prevent unauthorised access faces a wide range of new challenges. Among the most significant is the advent of big data, stored in the cloud, that needs to be processed securely.

Future Horizons:

×××

5-yearhorizon

Secure cloud search revolutionises healthcare research

Homomorphic encryption techniques allow researchers to process data stored in the cloud without revealing its content. This leads to significant advances in fields such as genomics where data privacy is a key concern. However, other security weaknesses that allow malicious users to access the data via well-known shortcomings threaten to undermine the potential. Basic-level data, such as DNS traffic, is routinely encrypted.

10-yearhorizon

Post-quantum encryption widely adopted

A relatively small number of quantum computers become capable of breaking public-key encryption. This forces the widespread adoption of post-quantum encryption, although some of the adopted encryption methods are likely to be broken. Simple, lightweight cryptography gains in popularity, but the environments that adopt a hybrid approach, using two or more encryption systems with very different characteristics, are the most secure against attack.

25-yearhorizon

Genome security improves

Homomorphic techniques allow the risk posed by a given nucleic-acid sequence to be assessed without the whole sequence being read, protecting IP while facilitating trade and transfer of biological materials.

This has led to much work on homomorphic encryption8, which allows encrypted information to be searched and processed while remaining encrypted. Applications include healthcare, banking, voting, genome encryption and beyond. Zero-knowledge proofs allow data verification without revealing anything about the data itself 9and have applications in healthcare, electronic identity systems, arms verification and so on. Another challenge comes from quantum-computing systems, which are soon expected to become capable of breaking many public-key cryptographic systems that are in widespread use for communication, financial transactions and the like. The US National Institute of Standards and Technology is coordinating efforts to develop post-quantum cryptographic standards that will be immune to quantum attack.10 But much work needs to be done to make sure they are safe.

The “internet of things” is a network expected to connect over 40 billion devices by 2025,11 but there are significant challenges in achieving this securely. These devices operate with lower power and with limited computational resources, which limits the data processing they can do. Ongoing research for securing the internet of things focuses on blockchains, physically unclonable functions and post-quantum cryptography. Many of these techniques require improvements, such as error-detection routines and practical, user-friendly hardware interfaces. Device-independent cryptography, where users can test a device’s security for themselves, removing any reliance on manufacturer-issued assurances, remains an important goal.

Novel encryption technologies - Anticipation Scores

The Anticipation Potential of a research field is determined by the capacity for impactful action in the present, considering possible future transformative breakthroughs in a field over a 25-year outlook. A field with a high Anticipation Potential, therefore, combines the potential range of future transformative possibilities engendered by a research area with a wide field of opportunities for action in the present. We asked researchers in the field to anticipate:

  1. The uncertainty related to future science breakthroughs in the field
  2. The transformative effect anticipated breakthroughs may have on research and society
  3. The scope for action in the present in relation to anticipated breakthroughs.

This chart represents a summary of their responses to each of these elements, which when combined, provide the Anticipation Potential for the topic. See methodology for more information.

Formal verification

A crucial component of modern security systems is the task of proving their correctness with respect to a specification, a process known as formal verification. This requires accurate mathematical modelling of hardware designs, along with their envisaged operations, and then an exhaustive, systematic check of all model states in a way that can offer evidence of security.

Future Horizons:

×××

5-yearhorizon

Formal verification becomes more visible

The trend towards demanding explanations for how AI makes decisions also drives wider demand for verifiable security, and observation of “ceremony” in processes such as key generation. AI accelerates the testing and verification of software and hardware systems, but relatively few companies or organisations have this capacity, creating a threat of monopoly.

10-yearhorizon

Verification methods for biological systems spark debates

Formal verification methods for biological systems emerge that allow a full analysis of the capability of synthetic organisms before they are made and released into the environment.

25-yearhorizon

Quantum computing introduces new challenges for verification

The challenge of verifying quantum software using quantum techniques drives new research into formal verification based on the laws of physics themselves.

While formal verification is an essential part of the development process, in practice it is often applied in retrospect, which makes the task significantly harder. Simpler user interfaces and better techniques could help to change that. That’s particularly important for mobile computing and cloud computing, which have spurred the use of formal verification at earlier stages in associated platform development.

Other new types of computing introduce their own challenges for formal verification. The “internet of things”, for instance, connects a wide variety of devices together and to the internet using a variety of different technologies, communications protocols and security standards, rendering each one vulnerable to attack — especially since they are often installed by non-security experts.12 6G communications networks, which are being designed as open and programmable by multiple stakeholders, may be vulnerable to attack in ways that 5G networks are not.13

Because of the trend towards ever-larger and more complex networks and systems, formal analysis is becoming more difficult, and AI — in particular, its pattern-identification capabilities — will play an increasingly important role in formal verification routines. However, low-end devices are likely to benefit from advances in local verifiability and public verifiability protocols, which will be of particular use in small and medium-sized countries where traditional certification is not affordable and tools for trustworthy certification (and suitably qualified personnel) are not available.

Formal verification - Anticipation Scores

The Anticipation Potential of a research field is determined by the capacity for impactful action in the present, considering possible future transformative breakthroughs in a field over a 25-year outlook. A field with a high Anticipation Potential, therefore, combines the potential range of future transformative possibilities engendered by a research area with a wide field of opportunities for action in the present. We asked researchers in the field to anticipate:

  1. The uncertainty related to future science breakthroughs in the field
  2. The transformative effect anticipated breakthroughs may have on research and society
  3. The scope for action in the present in relation to anticipated breakthroughs.

This chart represents a summary of their responses to each of these elements, which when combined, provide the Anticipation Potential for the topic. See methodology for more information.

Citations

Topic brief

  1. A. Haroon et al.. Constraints in the IoT: The World in 2020 and Beyond http://dx.doi.org/10.14569/IJACSA.2016.071133

4.4.1 Privacy and security

  1. J. Colnago et al.. Is There a Reverse Privacy Paradox? An Exploratory Analysis of Gaps Between Privacy Perspectives and Privacy-Seeking Behaviors https://ssrn.com/abstract=4607259
  2. A. Habbal et all.. Risk and Security Management (AI TRiSM): Frameworks, applications, challenges and future research directions https://doi.org/10.1016/j.eswa.2023.122442

4.4.2 Digital identity

  1. E. Bouma-Sims et al.. Exploring the Privacy Experiences of Closeted Users of Online Dating Services in the US https://doi.org/10.56553/popets-2024-0046
  2. J.M. MacAllister. The Doxing Dilemma: Seeking a Remedy for the Malicious Publication of Personal Information https://ir.lawnet.fordham.edu/flr/vol85/iss5/21
  3. A. Hassanpour et al.. The Impact of Linkability On Privacy Leakage https://doi.org/10.1145/3625007.3627832
  4. K.Y. Lam and Chi-Hung Chi. Identity in the Internet-of-Things (IoT): New Challenges and Opportunities https://doi.org/10.1007/978-3-319-50011-9_2

4.4.3 Novel encryption technologies

  1. M. Alloghani et al.. A Systematic Review on the Status and Progress of Homomorphic Encryption Technologies https://doi.org/10.1016/j.jisa.2019.102362
  2. L. Zhou et al.. Leveraging Zero Knowledge Proofs for Blockchain-Based Identity Sharing https://doi.org/10.1016/j.jisa.2023.103678
  3. NIST Computer Security Resource Center. Post-Quantum Cryptography https://csrc.nist.gov/projects/post-quantum-cryptography
  4. Dell. Internet of Things and Data Placement https://infohub.delltechnologies.com/en-us/l/edge-to-core-and-the-internet-of-things-2/internet-of-things-and-data-placement/

4.4.4 Formal verification

  1. K. Hofer-Schmitz and B. Stojanović. Towards formal verification of IoT protocols: A Review https://doi.org/10.1016/j.comnet.2020.107233
  2. A. Kalla et al.. A survey on the use of blockchain for future 6G: Technical aspects, use cases, challenges and research directions https://doi.org/10.1016/j.jii.2022.100404