Towards a Secure and GDPR-compliant Fog-to-Cloud Platform

被引:4
作者
Crompton, Shirley [1 ]
Jensen, Jens [2 ]
机构
[1] UKRI Sci & Technol Facil Council, Daresbury Lab, Dept Comp Sci, Data Sci & Technol Grp, Daresbury, England
[2] UKRI Sci & Technol Facil Council, Rutherford Appleton Lab, Dept Comp Sci, Data Sci & Technol Grp, Chilton, England
来源
2018 IEEE/ACM INTERNATIONAL CONFERENCE ON UTILITY AND CLOUD COMPUTING COMPANION (UCC COMPANION) | 2018年
关键词
mF2c; security; privacy; trust; fog-to-cloud; IoT; IaaS; INTERNET;
D O I
10.1109/UCC-Companion.2018.00071
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The mF2C project is building an open, secure and decentralized management platform for coordinating resource sharing between connected devices in the fog-to-cloud (F2C) environment. Safeguarding information security and privacy in mF2C is a considerable challenge given the heterogeneous and autonomous nature of devices spanning the F2C spectrum. The recently introduced General Data Protection Regulation (GDPR) raised the stake further by defining stringent security and privacy requirements on the processing of personal information. IaaS and PaaS providers falling in scope must demonstrate that they have implemented reasonable security mechanisms to ensure compliance or face significant financial penalties. In this paper, we present a prototype JAVA-based security library that addresses some of the data security and privacy requirements of mF2C and GDPR. The prototype employs a PKI-based trust model to facilitate authentication and authorization. It uses policy to ensure data privacy and cryptography to deliver data confidentiality, integrity and non-repudiation. We also outline plans to enhance the mF2C security infrastructure with data protection functionalities from the security library and to leverage blockchain technology to augment mF2C security and data protection capabilities.
引用
收藏
页码:296 / 301
页数:6
相关论文
共 12 条
  • [1] Crompton S., MF2C SECURITY LIB
  • [2] Efficient Data Tagging for Managing Privacy in the Internet of Things
    Evans, David
    Eyers, David M.
    [J]. 2012 IEEE INTERNATIONAL CONFERENCE ON GREEN COMPUTING AND COMMUNICATIONS, CONFERENCE ON INTERNET OF THINGS, AND CONFERENCE ON CYBER, PHYSICAL AND SOCIAL COMPUTING (GREENCOM 2012), 2012, : 244 - 248
  • [3] Kahvazadeh S., 2017, IEEE FUT TECHN C VAN
  • [4] Kahvazadeh S., 2018, 3 INT THINGS CIOT C
  • [5] Kahvazadeh Sarang., 2017, Proceedings of the 4th Workshop on CrossCloud Infrastructures Platforms, P2
  • [6] Security, privacy and trust in Internet of Things: The road ahead
    Sicari, S.
    Rizzardi, A.
    Grieco, L. A.
    Coen-Porisini, A.
    [J]. COMPUTER NETWORKS, 2015, 76 : 146 - 164
  • [7] Tattersall E., INTERNET OF THINGIES
  • [8] The mF2C project, 2017, D3 1 SEC PRIV ASP MF
  • [9] The mF2C project, 2017, D2 6 MF2C ARCH IT1
  • [10] The mF2C project, 2017, D2 4 SEC PRIV REQ FE