CloudSEEP: Secure Encrypted Processing

CloudSEEP1 technologies comprise state-of-the-art privacy-preserving tools and advanced encrypted processing algorithms to securely process private signals and data (techniques commonly known as Signal Processing in the Encrypted Domain). These algorithms allow to build secure solutions for unreliable environments through a set of core operations. Since it is a software solution, it is easily virtualizable and scalable, so it is possible to apply it in the cloud to take advantage of all its advantages without compromising the confidentiality of sensitive data, even during its processing.

Encrypted processing of sensitive data in Cloud environments with full privacy guarantees through advanced cryptographic primitives

Currently, oursourced environments like Cloud computing suffer from trust issues that hold back their full wide-spread adoption when dealing with sensitive data:

  • There are many Cloud applications in which service providers must process clients’ personal, private or confidential data
  • Clients may be reluctant to access Cloud resources due to privacy constraints and data sensitivity
  • Traditional approaches like encrypting communications are not enough for protecting these data
  • It is customary to keep private what should be private

By applying CloudSEEP’s state-of-the-art privacy-preserving techniques to these data for operating on them (a.k.a. Signal Processing in the Encrypted Domain), we achieve the highest level of privacy and confidentiality, featuring:

  • User-Control: using of client-managed and revokable keys that the server will never gain access to.
  • Full privacy guarantee: concealing of data during all their life-cycle: data never leave their encrypted state while they are processed at the Cloud, with no possible access from any unauthorized third party, or even by the provider itself.
  • Leveraging a new class of secure services: cloud services are seamlessly provided on the encrypted data, and results will also be encrypted, only viewable by the owner of those data.
  • Seamless integration: the underlying technology does not require any specific or dedicated hardware element. A middleware layer transparetly provides all the encryption, blind encrypted operation and client-side decryption.

Generic architecture

This figure represents the high-level architecture needed to apply CloudSEEP technology to the Cloud.

The middleware layer provides full protection for the data in the Cloud, and leverages encrypted services with no extra hardware requirements and providing a dedicated API for encrypted operations.


