Cloud computing is fast becoming the principal IT infrastructure facilitating, and often driving, the digital marketplace. According to one projection, the Worldwide Public Cloud Services Market will be worth USD 206.2 billion in 2019, up from 175.8 billion in 2018, a growth of 17.3 3 %. However, with a dearth of reassuring security arrangements, public authorities and companies are hesitant to entrust the storage and processing of sensitive data to external suppliers. PRISMACLOUD was set up to develop cryptographic solutions. The EU-funded project created a toolkit, alongside a portfolio of eight security enhanced cloud services. Together with the associated software, these enable end-to-end secure data services.

Gap in the clouds

PRISMACLOUD set out to fill a pronounced gap in the market for user-friendly and accessible security solutions. “Cloud computing is essentially a new form of IT outsourcing. And just as you would perform due diligence on any outsourcing company, so you need to fully trust cloud-based arrangements. Modern cryptography could reduce the reliance on trust alone by allowing control over data,” says Mr Thomas Loruenser, project coordinator. The solution combines different data protection approaches. “For example the core idea of one service is to distribute trust using encoding techniques across multiple clouds. In effect because data is fragmented no single part can reveal discernible, intelligible information to the storage provider”, says Loruenser. Moreover, because only a subset of the fragments is needed to reconstruct the data, the system is also resilient against single provider failures. As a proof of concept to demonstrate a measurable increase in service level security and privacy, PRISMACLOUD developed three case-studies based within the fields of SmartCity, e-Government, and e-Health. Project solutions were integrated into existing applications, as well as alongside new ones. By combining the pilots’ results with human-computer interaction research, PRISMACLOUD was able to identify further developments necessary for commercialisation, while better reflecting users’ needs. Generating recommendations for applications through the case studies also helps increase user acceptance of the technology.

Growing the digital single market

Access to more trustworthy cloud services will be a key enabler for European industry and for the European Cloud Strategy. One of PRISMACLOUD’s key advantages is that it can be mounted on top of existing cloud offerings, even those of less trusted lineage. The work done on data authenticity, based on digital signatures, is also relevant to digital identities’ (eIdas) regulations. Additionally, PRISMACLOUD’s enhancement of privacy directly supports the implementation of the General Data Protection Regulation (GDPR). PRISMACLOUD has succeeded in nudging some of its research results towards higher Technical Readiness Levels and its data privacy tools are already of interest to IBM. Furthermore, PRISMACLOUD’s methodology has been licensed to a start-up company which has already released its first product based on the technology. The team is further commercialising the project’s services, as well as continuing activities towards achieving standardisation of cloud security service levels and advanced digital signatures. However, as Loruenser says, “The technology has to adapt to new use cases, such as the Internet of things, which requires more advanced manipulation of encrypted and authenticated data. We also need security against potential quantum computer attacks in the future. We will be working in these areas.”

TRUSTEE - data pRivacy and cloUd Security clustEr Europe Wed, 10 Apr 2019 08:31:42 +0000

TRUSTEE (data pRivacy and cloUd Security clustEr Europe) is a network of 11 research projects funded by the European Union that was established within the Common Dissemination Booster initiative. The cluster is coordinated by CREDENTIAL, and furthermore subsumes the following projects: MUSA, PRISMACLOUD, SecureCloud, SERECA, SPECS, SUNFISH, SWITCH, TREDISEC, UNICORN, and WITDOM, which are all performing cutting-edge research and innovation in different domains of cloud security and privacy, ranging from secure and privacy-friendly authentication over encrypted and distributed solutions for data sharing and cloud storage to data integrity, authenticity, and availability.

The ambition of TRUSTEE is to consolidate the distributed and fragmented nature of currently ongoing European research initiatives and to serve as a central contact point which for software vendors, customers, research colleagues, and decision makers that are interested in leading-edge technologies and solutions.

Besides ready-to-use platforms, e.g., for data sharing, secure authentication, or SLA management, the projects have also developed a wide range of tools and components that can be integrated and re-used in other cloud applications. Below you can find a full service catalogue of projects involved in TRUSTEE.

Ready Platforms

TRUSTEE is currently providing more than a dozen platforms in six different categories, ranging from privacy-preserving identity management over secure data sharing to SLA management. More information can be found [here].

Primitives and Components

TRUSTEE is offering about 30 different components for different application scenarios within eight categories, including implementations of state-of-the-art cryptography, secure containers, or data authentication services. Find out more about our primitives [here].

For further information please do not hesitate to contact stephan[dot]krenn[at]ait[dot]ac[dot]at or any of the involved projects!

Impressions from Infosecurity Europe 2018 Tue, 09 Apr 2019 08:03:27 +0000

Mikroplan (MPL) and AIT presented the project results at the Infosecurity Europe. Infosecurity Europe is the region's number one information security event featuring Europe's largest and most comprehensive conference programme and over 400 exhibitors showcasing the most relevant information security solutions and products to 19,500+ information security professionals.

The stand was organized in a joint effort together with CREDENTIAL project, also a member of the TRUSTEE common dissemination cluster. In fact, besides the results, we were also promoting other H2020 project’s output, who are part of the dissemination cluster. It was a main target to generate awareness of the many innovations produced in the project and to bring project partners in contact with potential commercialization partners for exploitation beyond the consortium.

The overall outcome of the dissemination activity was very positive and we were able to establish more than 20 new contacts within security industry, which were interested in adoption of certain technologies or as a friendly customer.

Additionally, Thomas Lorünser (AIT) gave an oral presentation of the project’s result at the Cyber Innovation Showcase series stage. He presented the results achieved to interested industry people. The presentation raised some interesting discussions, specifically with governmental officials from Scandinavian countries who are involved in the development of a governmental cloud strategy.

PRISMACLOUD Contribution to ETSI Standards Fri, 29 Jun 2018 09:07:08 +0000 From March 2017 to February 2018, PRISMACLOUD contributed to ETSI TC CYBER STF529 (Specialist Task Force 529) with title “Attribute Based Encryption – Common protocol for data access control for Cloud, Mobile and IoT.” The outcome of the STF was the Technical Specification (TS) 103 532.

The work on PRISMACLOUD’s SECOSTOR tool directly influenced the STF529 work. In deliverable D4.3 - "Efficient Sharing-Based Storage Protocols for Mixed Adversaries", cryptographic access-control mechanisms are discussed where ABE is considered as a possible technique to encrypt", shares of sensitive data at the cloud provider which motivates the use of ABE for enhanced access control mechanisms to reduce the trust in cloud storage providers.

Cooperation with AGILE H2020 Project Tue, 12 Jun 2018 08:09:37 +0000 AGILE is a H2020 project producing software and hardware for a modular IoT gateway. AGILE supports cloud integration while addressing security concerns, everything on the basis of open source software hosted at GitHub (

After a first joint workshop where collaboration opportunities have been elaborated, the project partners AIT (PRISMACLOUD) and University of Passau (AGILE) teamed up to integrate a first PRISMACLOUD service into the AGILE open source framework.

In particular, the Secure Archiving Service Proxy (SAaaS) has been integrated into the AGILE gateway software such that it can be seamlessly deployed. The service has been “containerized” and is now available from the AGILE software repository for two different architectures:

Also, other services have been identified as interesting addons for the AGILE ecosystem, however, because of licence restrictions they could not be integrated right away.

More information about AGILE IOT project here:

Pushing the Boundaries for Secure & Privacy Friendly Cloud Services Tue, 22 May 2018 09:12:32 +0000 Place: Infosecurity Europe 2018 - Olympia London
Date: 07 Jun 2018, 12:55 - 13:20
Platform: Cyber Innovation Showcase

Our project coordinator Thomas Lorünser (AIT) will give a talk at Infosecurity Europe 2018 under the "Cyber Innovation Showcase"platform. He will present recent results and prototypes of the two EU funded projects PRISMACLOUD & CREDENTIAL developing novel secure and privacy friendly cloud services and identity management solutions.

The PRISMACLOUD research project is dedicated to enabling secure and trustworthy cloud-based services by improving and adopting novel tools from cryptographic research. The project brings novel concepts and methods to practical application to improve the security and privacy of cloud services.

CREDENTIAL is developing, testing and showcasing innovative cloud-based services for storing, managing, and sharing digital identity information and other highly critical personal data with a demonstrably higher level of security than other current solutions.

Learning Outcomes:

  1. Learn about leading edge security topics for cloud computing
  2. See new products and services available to protect your data
  3. Understand novel cryptographic tools and concepts for security
  4. Get in contact with potential partners for commercialisation of new solutions
  5. See innovations for GDPR friendly identity management
Hosting and Service Providers Summit 2018 Mon, 21 May 2018 08:16:28 +0000

Picture: Vogel IT-Akademie / © Marko's Photography [1]

Hosting & Service Provider Summit 2018
Frankfurt, Germany, May 16 – 18, 2018

Henrich C. Pöhls (UNI PASSAU) gave a keynote with the title “Cryptography – for a new generation of secure Cloud services”[2] at the seventh hosting and service provider summit. This event for German speaking cloud service providers and “adjacent businesses” was organised for the seventh time by Vogel IT and was visited by around 120 business strategists, CEOs, CTOs, and other key people in the cloud and hosting business. In the keynote Henrich C. Pöhls presented the gains of redactable signature schemes and secret sharing schemes and the opportunities from the resulting security and privacy increases.


[2] Original German title: “Kryptographie – die neue Generation sicherer Cloud-Services?”


]]> Concertation Meeting Fri, 18 May 2018 07:23:44 +0000 The concertation meeting on April 26th in Brussels had the goal to take stock of the current R&I landscape and to identify common themes and challenges for clustering activities. With a strong EC presence, it was a great opportunity to discuss with other projects, get noticed and provide input for the future research landscape within cybersecurity.

Daniel Slamanig (AIT) gave a PRISMACLOUD lighting talk in the break-out session “Foundation technical methods and risk management for trustworthy systems”. The main idea of this meeting was to bring projects in cybersecurity together and find collaboration opportunities. Daniel had the chance to discuss with many other interesting projects such as PANORAMIX, FENTEC and CREDENTIAL, get informed about the future strategy of the EC and discuss with other experts the future landscape of cybersecurity research.

Developing the IT security solutions of tomorrow Thu, 03 May 2018 13:08:45 +0000


Date: 5 - 7 June 2018
Place: Olympia London | Stand X141

At Infosecurity Europe 2018, AIT is showcasing its portfolio of cryptographic solutions for the cloud. Developed over recent years together with industry partners like Atos, IBM, Interoute and Etra, these solutions are driven by the increased need for security and data protection in the cloud.

A live demo of the FragmentiX secure multi-cloud storage appliance based on Archistar technology will be shown alongside the CREDENTIAL-NGPID privacy preserving identity management solution. Both solutions have been built to maximise security and privacy, and can substantially increase GDPR compliance for business customers.

What’s more, AIT helps customers to design cybersecurity solutions for cloud, IoT, big data and Blockchain through the application of next generation cryptography in a seamless manner.

ISO SC27 meeting in Wuhan, China Fri, 27 Apr 2018 10:24:06 +0000 In the week from 16 to 20 April 2018, PRISMACLOUD attended the 26th meeting of the ISO SC27 "IT-Security Techniques" in Wuhan, China. We are having two active liaisons with SC27 working groups WG2 "Cryptography and Security Mechanisms" and WG4 "Security Controls and Services", and this was the fourth ISO meeting we were attending.

In WG4, the standard ISO/IEC 19086-4 "Cloud SLA - Security and Privacy", to which we already contributed objectives covering our newly developed services (integrity protection of data in motion, anonymous and pseudonymous authentication support, and data minimisation cryptographic controls) was propagated to "Draft International Standard" level and thus will likely be published at the upcoming 27th meeting in Norway in autumn. Although PRISMACLOUD will be over then, at least two of our project partners have already established channels through their respective national bodies (i.e. Austria and Germany) and intend to continue the PRISMACLOUD mission beyond project end. We would like to thank Thomas Länger (UNIL) and Henrich C. Pöhls from (UNI PASSAU) for their support.

In WG2 we were particularly successful in Wuhan: Together with the CREDENTIAL H2020 project, we managed to secure enough international support to kick off a new "work item" for a standard covering the cryptographic technology of "redactable signatures", one of the technologies we employ to minimize unnecessary dispersion of private data. We have been working towards this goal for the last 1,5 years and now also provide one of the rapporteurs of this upcoming standard.

Beyond the mentioned activities, we could again link up and network with excellent researchers from all over the world. And visiting the metropolitan area of Wuhan, a 20 million inhabitants megacity that generates about 20% of the Chinese GDP (particularly in optical technology) was also an interesting adventure and a pleasure.
