{"id":1352,"date":"2016-10-20T15:10:02","date_gmt":"2016-10-20T15:10:02","guid":{"rendered":"https:\/\/prismacloud.eu\/?page_id=1352"},"modified":"2018-06-08T14:19:29","modified_gmt":"2018-06-08T14:19:29","slug":"services","status":"publish","type":"page","link":"https:\/\/prismacloud.eu\/services\/","title":{"rendered":"Secure Cloud Services"},"content":{"rendered":"<div id=\"pl-1352\"  class=\"panel-layout\" ><div id=\"pg-1352-0\"  class=\"panel-grid panel-no-style\" ><div id=\"pgc-1352-0-0\"  class=\"panel-grid-cell\" ><div id=\"panel-1352-0-0-0\" class=\"so-panel widget widget_black-studio-tinymce widget_black_studio_tinymce panel-first-child panel-last-child\" data-index=\"0\" ><div class=\"panel-widget-style panel-widget-style-for-1352-0-0-0\" ><div class=\"textwidget\"><h2 style=\"text-align: justify;\">PRISMACLOUD Services<\/h2>\n<p style=\"text-align: justify;\">In PRISMACLOUD a protfolio of novel security and\/or privacy enhanced services has been developed. Based on the PRISMACLOUD\u00a0<a href=\"https:\/\/prismacloud.eu\/architecture\/\">Architecture<\/a> a service can be seen as customization of one particular cryptographic tool (or several particular tools)\u00a0 PRISMACLOUD toolbox for one specific from the application scenario. It provides a set of features which has been identified as particularly useful for a broader class of applications scenarios the service is targeting.<\/p>\n<h3 style=\"text-align: justify;\"><em><strong>Secure Archiving Service (SAaaS)<br \/>\n<\/strong><\/em><\/h3>\n<p style=\"text-align: justify;\">The PRISMACLOUD secure archiving service is a generic infrastructure service which can easily be integrated into cloud based backup scenarios while providing a demonstrable higher level of data privacy and availability than current cloud-based archiving solutions. The delivery model for this service is IaaS.<\/p>\n<table>\n<tbody>\n<tr>\n<td><\/td>\n<td style=\"width: 60%;\"><img class=\"wp-image-2903 aligncenter\" src=\"https:\/\/prismacloud.eu\/wp-content\/uploads\/2018\/06\/SA_after_cropped.png\" alt=\"\" width=\"500\" height=\"200\" \/><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><\/td>\n<td style=\"text-align: center;\"><strong>Figure SAaaS<\/strong>: Files get split into multiple parts on the users\u2019 device. The parts get sent to multiple cloud service providers. As with SAaaS, the availability can be increased if not all parts of the data are needed for reconstruction and the cloud service provider no longer has to be trusted w.r.t. confidentiality.<\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h3 style=\"text-align: justify;\"><em><strong>Data Sharing Service (DSaaS)<br \/>\n<\/strong><\/em><\/h3>\n<p style=\"text-align: justify;\">The PRISMACLOUD data sharing service allows multiple parties to securely store data in a cloud-of-clouds network such that no single storage node learns plaintext data, while still enabling the owner to share the data with other users of the system, i.e., the data sharing service supports secure collaboration without the need to trust one single storage provider. The delivery model of this service is IaaS.<\/p>\n<table>\n<tbody>\n<tr>\n<td><\/td>\n<td style=\"width: 60%;\"><img class=\"aligncenter wp-image-2953\" src=\"https:\/\/prismacloud.eu\/wp-content\/uploads\/2018\/06\/data-sharing.png\" alt=\"\" width=\"500\" height=\"302\" \/><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><\/td>\n<td style=\"text-align: center;\"><strong>Figure\u00a0DSaaS<em style=\"text-align: justify; font-family: inherit; font-size: inherit;\">:\u00a0<\/em><\/strong><span style=\"font-family: inherit; font-size: inherit;\">Files selected for archiving get split and then distributed to multiple cloud service providers.\u00a0<\/span><span style=\"font-family: inherit; font-size: inherit;\">The user no longer has to trust the cloud service provider w.r.t. confidentiality.\u00a0<\/span><span style=\"font-family: inherit; font-size: inherit;\">The availability of the data can be increased if not all parts of the data are needed for reconstruction.\u00a0<\/span><span style=\"font-family: inherit; font-size: inherit;\">The proxy nature of the service allows legacy applications to use SAaaS.<\/span><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h3><em style=\"text-align: justify;\"><strong>Selective Authentic Exchange Service<\/strong><\/em><\/h3>\n<p style=\"text-align: justify;\">This service enables users to move their authentic documents to a cloud service and then delegate the selective sharing of parts of these documents to another party, while maintaining the authenticity of the selected parts. The other party can then verify the authenticity of the received data. The delivery model of this service is PaaS.<\/p>\n<table>\n<tbody>\n<tr>\n<td><\/td>\n<td style=\"width: 60%;\"><img class=\"aligncenter wp-image-2920\" src=\"https:\/\/prismacloud.eu\/wp-content\/uploads\/2018\/06\/SAEcropped.png\" alt=\"\" width=\"500\" height=\"205\" \/><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><\/td>\n<td style=\"text-align: center;\"><strong>Figure<\/strong>: Documents which were uploaded to the service can be redacted without invalidating the original signature of the document. Allowing the user to redact signed documents allows them to only share necessary information without sharing too much. On the flipside, the data consumer can be sure that the data they received were based on a signed document.<\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h3 style=\"text-align: justify;\"><em><strong>Privacy Enhancing ID Management Service<\/strong><\/em><\/h3>\n<p style=\"text-align: justify;\">This service offers the capability of a privacy enhanced identity management. In particular, it allows users to store their attribute credentials obtained from some entity (e.g, a service provider or an authority) in this component and to realize a selective attribute disclosure functionality. The delivery model of this service is PaaS.<\/p>\n<table>\n<tbody>\n<tr>\n<td><\/td>\n<td style=\"width: 60%;\"><img class=\"aligncenter wp-image-2900\" src=\"https:\/\/prismacloud.eu\/wp-content\/uploads\/2018\/06\/PIDM_after_cropped.png\" alt=\"\" width=\"500\" height=\"230\" \/><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><\/td>\n<td style=\"text-align: center;\"><strong>Figure<\/strong>: Users are granted certain rights depending on the group they belong to. The service provider does not need to identify the users by ID to be sure they have the rights for certain actions. Increases trust of the user in privacy protection without impeding the service.<\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h3 style=\"text-align: justify;\"><em><strong>Verifiable Statistics Service<\/strong><\/em><\/h3>\n<p style=\"text-align: justify;\">This service provides the functionality to delegate the computation of verifiable statistics on authenticated data in a secure way. The computations have the feature of being public verifiability, i.e., any verifier can check whether an outsourced computation has been performed correctly, or not. The delivery model for this service is PaaS.<\/p>\n<table>\n<tbody>\n<tr>\n<td><\/td>\n<td style=\"width: 60%;\"><img src=\"https:\/\/prismacloud.eu\/wp-content\/uploads\/2018\/06\/VC_after_cropped.png\" \/><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><\/td>\n<td style=\"text-align: center;\"><strong>Figure<\/strong>:\u00a0The data producer sends signed data to the cloud. The cloud service consumer is then able to retrieve the result of a computation on the original data, which will still have a valid signature, thus proving the result was calculated using the input data. The cloud service consumer can validate their results without breaching the privacy of the data producer.<\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h3 style=\"text-align: justify;\"><em><strong>Infrastructure Auditing Service<\/strong><\/em><\/h3>\n<p style=\"text-align: justify;\">The infrastructure auditing service offers the capability to certify and prove properties of the topology of a cloud infrastructure without disclosing sensitive information about the actual infrastructure\u2019s blueprint. The delivery model associated to this service is IaaS.<\/p>\n<table>\n<tbody>\n<tr>\n<td><\/td>\n<td style=\"width: 60%;\"><img class=\"aligncenter wp-image-2892\" src=\"https:\/\/prismacloud.eu\/wp-content\/uploads\/2018\/06\/IA_after_1cta.jpg\" alt=\"\" width=\"500\" height=\"375\" \/><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><\/td>\n<td style=\"text-align: center;\"><strong>Figure<\/strong>:\u00a0An auditor creates a certifi cate based on a graph representation of the infrastructure of a cloud service provider. The cloud service consumer can then send a challenge request to the cloud service, which can only be fulfilled if the cloud service upholds the requirement. The cloud service provider no longer needs to grant access to their infrastructure in order to prove that they uphold the requirements.<\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3 style=\"text-align: justify;\"><em><strong>Encryption Proxy Service<\/strong><\/em><\/h3>\n<p style=\"text-align: justify;\">The service supports moving legacy applications to the cloud by encrypting sensitive information identified within HTTP traffic in a format and\/or order preserving way. The delivery model associated to this service is SaaS.<\/p>\n<table>\n<tbody>\n<tr>\n<td><\/td>\n<td style=\"width: 60%;\"><img class=\"aligncenter wp-image-2923\" src=\"https:\/\/prismacloud.eu\/wp-content\/uploads\/2018\/06\/EP_after_cropped.png\" alt=\"\" width=\"500\" height=\"198\" \/><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><\/td>\n<td style=\"text-align: center;\"><strong>Figure<\/strong>: The data producer sends unencrypted data to the encryption service, which encrypts the data in either an order or format preserving manner and then sends it to the cloud service provider.\u00a0When requesting data from the proxy, the request is modifi ed by the proxy to work on the encrypted data, retrieves the requested data from the server and then sends the decrypted data to the cloud service consumer.<\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h3 style=\"text-align: justify;\"><em><strong>Anonymization Service<\/strong><\/em><\/h3>\n<p style=\"text-align: justify;\">This service enables users to anonymize large data sets, and in particular database tables. The service allows users to identify private and sensitive information in the data sets and produce an anonymized version of the data set. The delivery model associated to this service is SaaS.<\/p>\n<table>\n<tbody>\n<tr>\n<td><\/td>\n<td style=\"width: 60%;\"><img class=\"aligncenter wp-image-2909\" src=\"https:\/\/prismacloud.eu\/wp-content\/uploads\/2018\/06\/AP_after_cropped.png\" alt=\"\" width=\"500\" height=\"202\" \/><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><\/td>\n<td style=\"text-align: center;\"><strong>Figure<\/strong>: Plain data stored in a legacy database is analyzed and is obscured enough so no connections between the datasets and the user can be made. The user\u2019s privacy is protected while the cloud service consumer can still make calculations on the obscured data.<\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<\/div><\/div><\/div><\/div><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>PRISMACLOUD Services In PRISMACLOUD a protfolio of novel security and\/or privacy enhanced services has been developed. Based on the PRISMACLOUD\u00a0Architecture a service can be seen as customization of one particular cryptographic tool (or several particular tools)\u00a0 PRISMACLOUD toolbox for one specific from the application scenario. It provides a set of features which has been identified [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"template-pc-home.php","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/prismacloud.eu\/wp-json\/wp\/v2\/pages\/1352"}],"collection":[{"href":"https:\/\/prismacloud.eu\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/prismacloud.eu\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/prismacloud.eu\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/prismacloud.eu\/wp-json\/wp\/v2\/comments?post=1352"}],"version-history":[{"count":122,"href":"https:\/\/prismacloud.eu\/wp-json\/wp\/v2\/pages\/1352\/revisions"}],"predecessor-version":[{"id":3001,"href":"https:\/\/prismacloud.eu\/wp-json\/wp\/v2\/pages\/1352\/revisions\/3001"}],"wp:attachment":[{"href":"https:\/\/prismacloud.eu\/wp-json\/wp\/v2\/media?parent=1352"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}