Towards a Secure and GDPR-compliant Fog-to-Cloud Platform

被引:4
|
作者
Crompton, Shirley [1 ]
Jensen, Jens [2 ]
机构
[1] UKRI Sci & Technol Facil Council, Daresbury Lab, Dept Comp Sci, Data Sci & Technol Grp, Daresbury, England
[2] UKRI Sci & Technol Facil Council, Rutherford Appleton Lab, Dept Comp Sci, Data Sci & Technol Grp, Chilton, England
关键词
mF2c; security; privacy; trust; fog-to-cloud; IoT; IaaS; INTERNET;
D O I
10.1109/UCC-Companion.2018.00071
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The mF2C project is building an open, secure and decentralized management platform for coordinating resource sharing between connected devices in the fog-to-cloud (F2C) environment. Safeguarding information security and privacy in mF2C is a considerable challenge given the heterogeneous and autonomous nature of devices spanning the F2C spectrum. The recently introduced General Data Protection Regulation (GDPR) raised the stake further by defining stringent security and privacy requirements on the processing of personal information. IaaS and PaaS providers falling in scope must demonstrate that they have implemented reasonable security mechanisms to ensure compliance or face significant financial penalties. In this paper, we present a prototype JAVA-based security library that addresses some of the data security and privacy requirements of mF2C and GDPR. The prototype employs a PKI-based trust model to facilitate authentication and authorization. It uses policy to ensure data privacy and cryptography to deliver data confidentiality, integrity and non-repudiation. We also outline plans to enhance the mF2C security infrastructure with data protection functionalities from the security library and to leverage blockchain technology to augment mF2C security and data protection capabilities.
引用
收藏
页码:296 / 301
页数:6
相关论文
共 50 条
  • [21] Moving towards Smart Cities: A Selection of Middleware for Fog-to-Cloud Services
    Bangui, Hind
    Rakrak, Said
    Raghay, Said
    Buhnova, Barbora
    APPLIED SCIENCES-BASEL, 2018, 8 (11):
  • [22] A GDPR-compliant Ecosystem for Speech Recognition with Transfer, Federated, and Evolutionary Learning
    Jiang, Di
    Tan, Conghui
    Peng, Jinhua
    Chen, Chaotao
    Wu, Xueyang
    Zhao, Weiwei
    Song, Yuanfeng
    Tong, Yongxin
    Liu, Chang
    Xu, Qian
    Yang, Qiang
    Deng, Li
    ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2021, 12 (03)
  • [23] How to Make Privacy Policies both GDPR-Compliant and Usable
    Renaud, Karen
    Shepherd, Lynsay A.
    2018 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA), 2018,
  • [24] Development of GDPR-Compliant Software Document Management System for HR Department
    Goncalves, Emanuel
    Teixeira, Paulo
    Silva, Joaquim P.
    2020 15TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI'2020), 2020,
  • [25] The smashHitCore Ontology for GDPR-Compliant Sensor Data Sharing in Smart Cities
    Kurteva, Anelia
    Chhetri, Tek Raj
    Tauqeer, Amar
    Hilscher, Rainer
    Fensel, Anna
    Nagorny, Kevin
    Correia, Ana
    Zilverberg, Albert
    Schestakov, Stefan
    Funke, Thorben
    Demidova, Elena
    SENSORS, 2023, 23 (13)
  • [26] GDPR-Compliant Personal Data Management: A Blockchain-Based Solution
    Nguyen Binh Truong
    Sun, Kai
    Lee, Gyu Myoung
    Guo, Yike
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 1746 - 1761
  • [27] Implementing and evaluating a GDPR-compliant open-source SIEM solution
    Vazao, Ana Paula
    Santos, Leonel
    Costa, Rogerio Luis de C.
    Rabadao, Carlos
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2023, 75
  • [28] Privacy-preserving public auditing for secure data storage in fog-to-cloud computing
    Tian, Hui
    Nan, Fulin
    Chang, Chin-Chen
    Huang, Yongfeng
    Lu, Jing
    Du, Yongqian
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2019, 127 : 59 - 69
  • [29] Speed Kit: A Polyglot & GDPR-Compliant Approach For Caching Personalized Content
    Wingerath, Wolfram
    Gessert, Felix
    Witt, Erik
    Kuhlmann, Hannes
    Bucklers, Florian
    Wollmer, Benjamin
    Ritter, Norbert
    2020 IEEE 36TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE 2020), 2020, : 1603 - 1608
  • [30] GDPR-Compliant Data Breach Detection: Leveraging Semantic Web and Blockchain
    Ansar, Kainat
    Ahmed, Mansoor
    Khalid, Muhammad Irfan
    Helfert, Markus
    GOOD PRACTICES AND NEW PERSPECTIVES IN INFORMATION SYSTEMS AND TECHNOLOGIES, VOL 6, WORLDCIST 2024, 2024, 990 : 3 - 11