Towards a Secure and GDPR-compliant Fog-to-Cloud Platform

被引:4
|
作者
Crompton, Shirley [1 ]
Jensen, Jens [2 ]
机构
[1] UKRI Sci & Technol Facil Council, Daresbury Lab, Dept Comp Sci, Data Sci & Technol Grp, Daresbury, England
[2] UKRI Sci & Technol Facil Council, Rutherford Appleton Lab, Dept Comp Sci, Data Sci & Technol Grp, Chilton, England
关键词
mF2c; security; privacy; trust; fog-to-cloud; IoT; IaaS; INTERNET;
D O I
10.1109/UCC-Companion.2018.00071
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The mF2C project is building an open, secure and decentralized management platform for coordinating resource sharing between connected devices in the fog-to-cloud (F2C) environment. Safeguarding information security and privacy in mF2C is a considerable challenge given the heterogeneous and autonomous nature of devices spanning the F2C spectrum. The recently introduced General Data Protection Regulation (GDPR) raised the stake further by defining stringent security and privacy requirements on the processing of personal information. IaaS and PaaS providers falling in scope must demonstrate that they have implemented reasonable security mechanisms to ensure compliance or face significant financial penalties. In this paper, we present a prototype JAVA-based security library that addresses some of the data security and privacy requirements of mF2C and GDPR. The prototype employs a PKI-based trust model to facilitate authentication and authorization. It uses policy to ensure data privacy and cryptography to deliver data confidentiality, integrity and non-repudiation. We also outline plans to enhance the mF2C security infrastructure with data protection functionalities from the security library and to leverage blockchain technology to augment mF2C security and data protection capabilities.
引用
收藏
页码:296 / 301
页数:6
相关论文
共 50 条
  • [1] GDPR-Compliant Use of Blockchain for Secure Usage Logs
    Zieglmeier, Valentin
    Daiqui, Gabriel Loyola
    PROCEEDINGS OF EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING (EASE 2021), 2021, : 313 - 320
  • [2] Towards a GDPR-compliant cloud architecture with data privacy controlled through sticky policies
    Cambronero, M. Emilia
    Martinez, Miguel A.
    Llana, Luis
    Rodriguez, Ricardo J.
    Russo, Alejandro
    PEERJ COMPUTER SCIENCE, 2024, 10
  • [3] AMNESIA: A Technical Solution towards GDPR-compliant Machine Learning
    Stach, Christoph
    Giebler, Corinna
    Wagner, Manuela
    Weber, Christian
    Mitschang, Bernhard
    ICISSP: PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2020, : 21 - 32
  • [4] Towards GDPR-compliant data processing in modern SIEM systems
    Menges, Florian
    Latzo, Tobias
    Vielberth, Manfred
    Sobola, Sabine
    Poehls, Henrich C.
    Taubmann, Benjamin
    Koestler, Johannes
    Puchta, Alexander
    Freiling, Felix
    Reiser, Hans P.
    Pernul, Guenther
    COMPUTERS & SECURITY, 2021, 103 (103)
  • [5] Towards a GDPR-Compliant Blockchain-Based COVID Vaccination Passport
    Haque, A. K. M. Bahalul
    Naqvi, Bilal
    Islam, A. K. M. Najmul
    Hyrynsalmi, Sami
    APPLIED SCIENCES-BASEL, 2021, 11 (13):
  • [6] Lightweight Blockchain-based Platform for GDPR-Compliant Personal Data Management
    Dauden-Esmel, Cristofol
    Castella-Roca, Jordi
    Viejo, Alexandre
    Domingo-Ferrer, Josep
    2021 IEEE 5TH INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY (ICCSP), 2021, : 68 - 73
  • [7] Implementing GDPR-Compliant Surveys Using Blockchain
    Goncalves, Ricardo Martins
    da Silva, Miguel Mira
    da Cunha, Paulo
    FUTURE INTERNET, 2023, 15 (04)
  • [8] Designing a GDPR-Compliant and Usable Privacy Dashboard
    Raschke, Philip
    Kuepper, Axel
    Drozd, Olha
    Kirrane, Sabrina
    PRIVACY AND IDENTITY MANAGEMENT: THE SMART REVOLUTION, 2018, 526 : 221 - 236
  • [9] Modelling GDPR-Compliant Explanations for Trustworthy AI
    Sovrano, Francesco
    Vitali, Fabio
    Palmirani, Monica
    ELECTRONIC GOVERNMENT AND THE INFORMATION SYSTEMS PERSPECTIVE, EGOVIS 2020, 2020, 12394 : 219 - 233
  • [10] Pseudonymisation in the context of GDPR-compliant medical research
    Basdekis, Ioannis
    Kloukinas, Christos
    Agostinho, Carlos
    Vezakis, Ioannis
    Pimenta, Andreia
    Gallo, Luigi
    2023 19TH INTERNATIONAL CONFERENCE ON THE DESIGN OF RELIABLE COMMUNICATION NETWORKS, DRCN, 2023,