Textdokument
Requirements Engineering of the Cryptography within the Application Landscape of the German Banking Industry
Lade...
Volltext URI
Dokumententyp
Dateien
Zusatzinformation
Datum
2021
Autor:innen
Zeitschriftentitel
ISSN der Zeitschrift
Bandtitel
Quelle
Verlag
Gesellschaft für Informatik, Bonn
Zusammenfassung
The standardization of PQC is going to be the beginning of an enormous effort by the industry incorporating new cryptography into the current application l landscape. Moreover, the German federal office for information security (BSI3) recommends that applications with high security requirements should assume that in 2030 a cryptanalytic relevant quantum computer will exist. This suggests that early migration considerations are quintessential now. The German banking industry is heavily reliant upon cryptography. A natural question is therefore: What requirements does the application landscape of the German banking industry impose on cryptography and which PQC schemes meet these requirements. We attempt to answer this question by closely reviewing the application and cryptography landscape of the German banking industry in accordance with a classical requirements engineering (RE) process that is being taught by the IREB Foundation Level course4, which we assume to be the most pervasive in the industry. We describe how this methodology was applied in the project QuantumLeap5 and present an overview of the cryptography being used in the German banking industry together with promising PQC replacement candidates.