GDPR Compliance Verification in Internet of Things

被引:25
作者
Barati, Masoud [1 ]
Rana, Omer [1 ]
Petri, Ioan [2 ]
Theodorakopoulos, George [1 ]
机构
[1] Cardiff Univ, Sch Comp Sci & Informat, Cardiff CF24 3AA, Wales
[2] Cardiff Univ, Sch Engn, Cardiff CF10 3AT, Wales
来源
IEEE ACCESS | 2020年 / 8卷
基金
英国工程与自然科学研究理事会;
关键词
Blockchain-based auditing; business processes; general data protection regulation; Internet of Things; user privacy; BLOCKCHAIN; CHALLENGES; PRIVACY;
D O I
10.1109/ACCESS.2020.3005509
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Data privacy in Internet of Things (IoT) applications remains a major concern of regulation bodies. The introduction of the European General Data Protection Regulation (GDPR) enables users to control how their data is accessed and processed, requiring consent from users before any data manipulation is carried out on their (personal) data by smart devices or cloud-hosted services. Blockchains provide the benefits of a distributed and immutable ledger recording digital transactions across a global network of peer nodes. Blockchain support for tracking of operations carried out by an IoT-based system provides greater confidence to a user that the IoT device is not infringing user privacy (as the Blockchain can be audited to verify which operation was carried out, by which actor). A formal model (following the privacy-by-design approach) is proposed for supporting GDPR compliance checking for smart devices. The privacy requirements of such applications are related to GDPR obligations of device (and software systems) operators (such as user consent, data protection, right to forget etc). Three smart contracts are proposed as a practical solution to support automated verification of operations carried out by devices on user data, in accordance with GDPR rules. We evaluate the performance and scalability costs of our approach using a Blockchain test network.
引用
收藏
页码:119697 / 119709
页数:13
相关论文
共 42 条
  • [1] A Study on Security and Privacy Guidelines, Countermeasures, Threats: IoT Data at Rest Perspective
    Abdulghani, Hezam Akram
    Nijdam, Niels Alexander
    Cohen, Anastasija
    Konstantas, Dimitri
    [J]. SYMMETRY-BASEL, 2019, 11 (06):
  • [2] Al-Said Taimur, 2015, International Journal of High Performance Computing and Networking, V8, P222
  • [3] [Anonymous], 2018, P 15 INT JOINT C E B
  • [4] EclipseloT: A secure and adaptive hub for the Internet of Things
    Anthi, Eirini
    Ahmad, Shazaib
    Rana, Omer
    Theodorakopoulos, George
    Burnap, Pete
    [J]. COMPUTERS & SECURITY, 2018, 78 : 477 - 490
  • [5] Barati M., 2019, P 12 IEEE ACM INT C, P133, DOI DOI 10.1145/3344341.3368812
  • [6] Enhancing User Privacy in IoT: Integration of GDPR and Blockchain
    Barati, Masoud
    Rana, Omer
    [J]. BLOCKCHAIN AND TRUSTWORTHY SYSTEMS, BLOCKSYS 2019, 2020, 1156 : 322 - 335
  • [7] Privacy-Aware Cloud Ecosystems and GDPR Compliance
    Barati, Masoud
    Rana, Omer
    Theodorakopoulos, George
    Burnap, Peter
    [J]. 2019 7TH INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD (FICLOUD 2019), 2019, : 117 - 124
  • [8] On Purpose and by Necessity: Compliance Under the GDPR
    Basin, David
    Debois, Soren
    Hildebrandt, Thomas
    [J]. FINANCIAL CRYPTOGRAPHY AND DATA SECURITY, FC 2018, 2018, 10957 : 20 - 37
  • [9] Towards Better Availability and Accountability for IoT Updates by means of a Blockchain
    Boudguiga, Aymen
    Bouzerna, Nabil
    Granboulan, Louis
    Olivereau, Alexis
    Quesnel, Flavien
    Roger, Anthony
    Sirdey, Renaud
    [J]. 2017 2ND IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW), 2017, : 50 - 58
  • [10] The state-of-the-art in container technologies: Application, orchestration and security
    Casalicchio, Emiliano
    Iannucci, Stefano
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2020, 32 (17)