SecureCloud (690111)

  https://cordis.europa.eu/project/id/690111

  Horizon 2020 (2014-2020)

  Secure Big Data Processing in Untrusted Clouds

  Cloud Computing, including security aspects (EUB-1-2015)

  operating systems  ·  computer processors  ·  big data  ·  electric power transmission  ·  data processing

  2016-01-01 Start Date (YY-MM-DD)

  2018-12-31 End Date (YY-MM-DD)

  € 2,285,377 Total Cost


  Description

SecureCloud addresses the confidentiality, integrity and availability of applications executed in the cloud. Data at rest or in transit on the network is already nowadays protected by encryption. The main problem that we face is how to ensure the confidentiality of data while being processed. Our approach is based on upcoming hardware extensions of commodity CPUs like Intel's Secure Guard Extensions (SGX). By the help of these hardware extensions, we reduce the trusted computing base dramatically by excluding from it the millions of lines of source code of the cloud stack, operating systems and hypervisor. This permits us to ensure the confidentiality of computations even if the computers are under a different administrative control (like a cloud provider) or there is no physical security of the computers. Moreover, we ensure the confidentiality even if attackers would take control of the cloud stack, the hypervisor or the operating systems. As long as the hardware extensions of the CPU can be trusted, we can ensure the confidentiality of the computations. SecureCloud focuses on ensuring the confidential and dependable processing of Big Data. To keep the trusted computing base small, we use the concept of microservices: only the application logic that processes data (e.g., operators) is protected while all functionality that, e.g., shuffles and stores encrypted data is outside the trusted computing base. By monitoring the microservices, we can restart services that run on compromised hosts. We will evaluate and demonstrate our approach in the context of smart grids. In this use case context, we need to run across a physically distributed computing infrastructure with no or little physical security and partly untrusted administrators. We need to process large volumes of data and this big data processing would benefit by partial offloading into the cloud. In SecureCloud, we will show how to do this in a secure fashion even if clouds are untrusted.


  Complicit Organisations

1 Israeli organisation participates in SecureCloud.

Country Organisation (ID) VAT Number Role Activity Type Total Cost EC Contribution Net EC Contribution
Italy SYNC LAB SRL (968797007) IT07952560634 participant PRC € 201,250 € 201,250 € 201,250
Switzerland CLOUDSIGMA AG (969018264) CHE115204434MWST participant PRC € 248,750 € 0 € 0
United Kingdom IMPERIAL COLLEGE OF SCIENCE TECHNOLOGY AND MEDICINE (999993468) GB649926678 participant HES € 499,252 € 499,252 € 499,252
Switzerland UNIVERSITE DE NEUCHATEL (999870181) CHE115251043TVA participant HES € 537,000 € 0 € 0
Denmark CHOCOLATE CLOUD APS (934064120) DK35865756 participant PRC € 199,500 € 199,500 € 199,500
Israel THE ISRAEL ELECTRIC CORPORATION LIMITED (998827237) IL520000472 participant PRC € 100,000 € 100,000 € 100,000
Germany TECHNISCHE UNIVERSITAET DRESDEN (999897729) DE188369991 coordinator HES € 499,624 € 499,624 € 499,624