Encrypted Spaces is a new architecture designed for collaborative applications where all data is encrypted and operations are cryptographically verifiable, ensuring privacy even on untrusted servers [1, 2].
The system allows centralized cloud servers to store data but only access what users explicitly expose. This prevents servers from seeing plaintext user data, addressing risks such as data exposure, loss of control, and self-censorship that commonly occur with traditional cloud setups [1, 2].
Within an encrypted space, the server acts as a centralized data store but is not trusted with the actual content. Users share persistent data encrypted end-to-end, with an application data schema defining which parts of the encrypted data the server may view to support advanced queries [1, 2].
To ensure server honesty, users verify cryptographic proofs that validate correct behavior and data integrity. The system enforces membership rules, access controls, encryption, and key management to maintain security and privacy [1, 2].
Participants in an encrypted space know exactly who can read or modify data, and all changes are cryptographically attributed to their authors. This provides auditability and accountability within the collaborative environment [1, 2].
Encrypted Spaces aim to enable developers to build trustworthy collaborative applications without having to manage complex cryptographic operations themselves. The architecture shields both users and developers from low-level encryption details while working securely on untrusted servers [1, 2].