MOSAICrOWN
Multi-Owner data Sharing for Analytics and Integration respecting Confidentiality and Owner control
MOSAICrOWN was a Horizon 2020 Research and Innovation Action that developed practical methods for sharing and analysing data contributed by independent owners without giving up confidentiality, privacy, or control. The project combined policy-based governance, encryption-based protection, and data sanitisation to support selective disclosure and collaborative computation in digital data markets.
The University of Bergamo participated in the consortium together with the University of Milan (coordinator), EMC Information Systems International, Mastercard Europe, SAP, and ERCIM.
Project Information
- Programme: Horizon 2020, Research and Innovation Action
- Grant agreement: 825333
- Duration: 1 January 2019–31 December 2021
- EU contribution: €3,203,750
- Coordinator: University of Milan
Research and Results
MOSAICrOWN addressed four complementary aspects of privacy-aware data markets:
- a data-governance framework and policy language through which owners could express and enforce access and usage restrictions;
- data wrapping and encryption-based techniques for selective access, secure storage, and controlled query execution;
- sanitisation techniques—including anonymisation and differential privacy—to balance disclosure risk and analytical utility;
- scalable collaborative computation over data originating from multiple owners, including distributed anonymisation of large datasets.
The project validated these components through industrial use cases and made several academic results available as open-source software. The MOSAICrOWN GitHub organisation maintains the most relevant repositories, including the policy engine, secure query optimisation, AESMix encryption tools, and the distributed Mondrian anonymisation tool, which supports k-anonymity and ℓ-diversity using Apache Spark.
Deliverables
The European Commission catalogues 21 public MOSAICrOWN deliverables. They include reports and software releases covering:
- the metadata model, policy language, policy engine, and final data-governance framework;
- preliminary and final encryption-based protection tools;
- privacy metrics, disclosure-risk assessment, data sanitisation, and collaborative computation;
- use-case requirements, prototypes, and final evaluation;
- the project's data-management plan.
The complete catalog, with downloadable reports and tools, is available on the CORDIS results page. The final project report summarises the resulting architecture, techniques, and industrial evaluation.
Project Publications
- Multi-Provider Secure Processing of Sensors Data
- Securing Resources in Decentralized Cloud Storage
- Dynamic Allocation for Resource Protection in Decentralized Cloud Storage
- Scalable Distributed Data Anonymization
- Artifact: Scalable Distributed Data Anonymization
- SEApp: Bringing Mandatory Access Control to Android Apps
- I Told You Tomorrow: Practical Time-Locked Secrets using Smart Contracts
- Multi-Dimensional Indexes for Point and Range Queries on Outsourced Encrypted Data
- Scalable Distributed Data Anonymization for Large Datasets