Technology brief on the secure distributed processing of information requiring protection
Companies hold large amounts of information that must be protected to ensure that it remains confidential, unchanged and available at all times. While there are good solutions for storage and transmission, protecting information during processing can be challenging, particularly when several parties are working together, such as on digital platforms. This technology brief sets out the requirements for the secure distributed processing of information requiring protection, proposes a suitable target architecture, and provides recommendations for related development and procurement projects.
Many communication and collaboration platforms involve the distributed processing of information requiring protection. From a security perspective, this gives rise to specific strategic, technical and organisational requirements.
Based on these requirements, the technology brief proposes a target architecture designed for the secure distributed processing of information requiring protection. The basic idea is to store information that requires protection in one location only – and make it accessible via secure end devices and communication channels. In particular, this helps prevent uncontrolled copying of information requiring protection, which would otherwise mean that each individual copy would also have to be protected. This makes it easier to manage security requirements and ensure that they are met.
For synchronous voice and video communication, the target architecture provides for transparent end-to-end (E2E) encryption. When cryptographically protecting the information, the key management system must be designed in a way that prevents third parties from viewing or manipulating the information. If processing takes place in data centres that are not operated by the organisation or company itself, homomorphic encryption methods, confidential computing or both must also be used to ensure that the operator cannot view or manipulate the data.
The target architecture is recommended as a basis for assessment in both development and procurement projects.
The technology brief on processing information requiring protection explains in detail why centralised storage and controlled access are essential and which aspects must be considered.
