ESCUDO-CLOUD
Enforceable Security in the Cloud to Uphold Data Ownership
ESCUDO-CLOUD was a Horizon 2020 Research and Innovation Action focused on making data owners first-class citizens of cloud environments. It developed deployable techniques that let owners retain control over outsourced data while still using cloud storage, processing, sharing, and multi-provider services.
The University of Bergamo participated in the consortium coordinated by the University of Milan. The consortium also included British Telecommunications, EMC, IBM Research, SAP, the Technical University of Darmstadt, and Wellness Telecom.
Project Information
- Programme: Horizon 2020, Research and Innovation Action
- Grant agreement: 644579
- Duration: 1 January 2015–31 December 2017
- Total cost: €4,822,750
- EU contribution: €3,827,000
- Coordinator: University of Milan
Research and Results
ESCUDO-CLOUD organised its work around four technical goals:
- self-protecting data, including protection at rest, key management, private retrieval, and query execution over encrypted data;
- selective and secure information sharing, with owner-defined access restrictions and integrity guarantees for collaborative processing;
- security assessment and requirement-based threat analysis;
- multi-cloud and federated-cloud protection, including security metrics, provider selection, and the use of multiple providers to strengthen security.
The project produced prototypes for real industrial use cases and integrated results into cloud and database platforms. Its final report highlights open-source academic results as well as technology transferred into OpenStack, SAP HANA, BT services, and partner-specific cloud solutions.
Deliverables
The European Commission catalogues 22 public ESCUDO-CLOUD deliverables. They cover:
- use-case requirements, research alignment, prototypes, and final evaluation;
- data and access protection, key management, and integrity verification;
- selective access, secure information sharing, private multi-user queries, and security testing;
- security metrics and protection techniques for multi-cloud and federated environments;
- preliminary and final software tools implementing the project's protection mechanisms.
The complete catalog and downloadable material are available on the CORDIS results page. The final project report describes the objectives, deployed results, and exploitation by the project partners.
Project Publications
- AppPolicyModules: Mandatory Access Control for Third-Party Apps
- DockerPolicyModules: Mandatory Access Control for Docker Containers
- An SELinux-based Intent manager for Android
- Policy Specialization to Support Domain Isolation
- SeSQLite: Security Enhanced SQLite
- Extending Mandatory Access Control Policies in Android
- Access Control Management for Secure Cloud Storage
- Mix&Slice: Efficient Access Revocation in the Cloud
- Managing Data Sharing in OpenStack Swift with Over-Encryption
- Distributed Shuffle Index in the Cloud: Implementation and Evaluation
- Distributed Shuffle Index: Analysis and Implementation in an Industrial Testbed
- EncSwift and Key Management: An Integrated Approach in an Industrial Setting
- Protecting Resources and Regulating Access in Cloud-Based Object Storage