Secure cloud computing is key for business success and end-user adoption of federated and decentralized cloud services and thus essential to stimulate the growth of the European Digital Single Market. RestAssured will provide solutions to specific technical concerns of data protection in the cloud (such as geo-location restrictions on personal data), which are imposed by the dynamic, multi-stakeholder and decentralized nature of federated cloud systems. These concerns mean that privacy and security by design approaches will no longer be sufficient, due to uncertainty at design time of how the cloud and privacy requirements may dynamically evolve and change at run time. To this end, RestAssured provides novel mechanisms and cloud architectures for the runtime detection, prediction and prevention of data protection violations.
RestAssured will assure the protection of sensitive business and citizen data in the cloud by combining four pillars of innovation: (1) combination of fully homomorphic encryption to process data without decryption with cloud enablement of SGX hardware for protected data processing, (2) sticky policies for decentralized data lifecycle management, (3) models@runtime for data protection assurance, and (4) automated risk management for run-time data protection. The applicability and usefulness of the RestAssured solutions will be demonstrated through three use cases driven by project partners and involving other stakeholders from outside the consortium; High-Performance Computing for commercial enterprises; Pay As You Drive usage-based insurance; and self-directed Social care for vulnerable adults and social care providers. The main impact of RestAssured will be to enable the free and seamless movement of data within the EU, whilst assuring conformance to data protection regulations, such as the EU Data Protection Directive and its successor the General Data Protection Regulation.
Research and Innovation Action
01.01.2017 – 31.12.2019
Adaptant will lead the High-Performance Computing (HPC) and Usage-based insurance (UBI) end-user use-cases, working towards making both of these areas GDPR-ready. Owing to the cross-disciplinary reach and diversity of the use cases, contributions will be made to the overall project architecture, testbed, and methodology. Technical contributions will focus principally on the secure cloud data processing and execution environment, as well as decentralized data lifecycle management. Adaptant will finally contribute to the exploitation of project results, innovation management, and standardization activities.