Norwegian version of this page

Security in Internet Governance and Networks: Analysing the Law (SIGNAL)

SIGNAL is a project on the legal aspects of internet security hosted at the Norwegian Research Center for Computers and Law (NRCCL). SIGNAL examines changes in legal frameworks for internet security by focusing on established, new and proposed legal security requirements – at both international and national levels – directed at critical internet infrastructure (CII) and cloud computing.

Illustrative picture.

Internet Security: what are its legal requirements? The SIGNAL project aims to focus its research on legal frameworks of different security aspects, such as encryption, cybercrime and privacy by design. Image author: Yuri Samoilov. Used under CC terms.

About the Project

Ensuring internet security is a growing concern. The security of the internet depends not only on technological factors but also on an adequate legal framework. Therefore, the SIGNAL project scrutinizes legal requirements for such security.

Cybercrime

One set of requirements examined by the project concerns the prevention of cybercrime. Criminal laws play a significant role in combatting cybercrime at the national level, but there is also an international convention on cybercrime (the so-called Budapest Convention of 2001) which shapes the national rules.

An important remit of the project is to assess the extent to which the Budapest Convention is sufficiently “up-to-date” in relation to technological developments. 

Encryption

Another focus is legal rules for use of cryptography. Encryption is an important enabler of internet security, but it can also be a tool for cybercrime, and this dual potential raises vexing issues.

Amongst the questions discussed in the project are the extent to which police should be given access to unencrypted or decrypted data sent over the internet, and what limitations human rights law impose on such access.

Illustrative picture
SIGNAL focuses on legal aspects of internet security. Image author: unknown. Used under CC.

The role of IGOs

At the international level, there is no single intergovernmental organization with a mandate to ensure all aspects of internet security. Instead, there are several organizations with overlapping but distinct policy frameworks. Some of these organizations, however, are moving to increase their security mandates.

The project investigates the possible effects of their increasing influence in the field. 

Privacy

The security focus of the project is complemented by privacy-focused research. Particularly relevant for SIGNAL are attempts to introduce legal incentives to develop privacy-enhancing technologies and "privacy by design". Such incentives have been largely absent from legislation on privacy and data protection.

However, the new EU regulation on data protection contains new provisions on data protection by design and default, which require a detailed analysis.

Project objectives

The primary objective is to enhance understanding of the regulatory framework for internet security by critically analyzing established and proposed legal security requirements directed at critical internet infrastructure (CII) and cloud computing services.

The secondary objective is to assess critically:

  1. the degree to which the relevant legal security requirements take sensible account of internet development;
  2. the degree to which these requirements impact upon governance of CII and cloud computing services;
  3. the extent to which intergovernmental organisations are exercising and able to exercise increasing influence on such governance;
  4. the degree to which the above legal security requirements engender fragmentation of the internet.

Project management and execution

The project is formally led by Professor Lee A. Bygrave, with the assistance of Professor Tobias Mahler.

The bulk of research will be conducted by three doctoral research fellows, each of whom will work primarily on one of the main research prongs (apart from that dealing with privacy-enhancing technologies (PETs)), with input and guidance from Bygrave and Mahler. Bygrave is taking the lead in research on PETs (a prong of research that will not form the main part of a PhD).

Project funding

SIGNAL is funded by the Norwegian Research Council and UNINETT Norid AS, with support from the University of Oslo.

Project plan and organisation

The project will run for five years, starting on 1 January 2016. In addition to research, the project will involve holding three symposiums and a concluding conference. The first symposium will be held in September/October 2017; the second in May/June 2018; the third in May/June 2019. The final conference will be held in September/October 2020.

See a more detailed plan.

 

Tags: signal, NRCCL, encryption, privacy by design, privacy-enhancing technology, cybercrime, IGO, China, USA, Brazil, Russia
Published Feb. 22, 2016 1:14 PM - Last modified Oct. 19, 2017 2:11 PM