GDPR Compliance Verification in Internet of Things

被引:28
作者
Barati, Masoud [1 ]
Rana, Omer [1 ]
Petri, Ioan [2 ]
Theodorakopoulos, George [1 ]
机构
[1] Cardiff Univ, Sch Comp Sci & Informat, Cardiff CF24 3AA, Wales
[2] Cardiff Univ, Sch Engn, Cardiff CF10 3AT, Wales
基金
英国工程与自然科学研究理事会;
关键词
Blockchain-based auditing; business processes; general data protection regulation; Internet of Things; user privacy; BLOCKCHAIN; CHALLENGES; PRIVACY;
D O I
10.1109/ACCESS.2020.3005509
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Data privacy in Internet of Things (IoT) applications remains a major concern of regulation bodies. The introduction of the European General Data Protection Regulation (GDPR) enables users to control how their data is accessed and processed, requiring consent from users before any data manipulation is carried out on their (personal) data by smart devices or cloud-hosted services. Blockchains provide the benefits of a distributed and immutable ledger recording digital transactions across a global network of peer nodes. Blockchain support for tracking of operations carried out by an IoT-based system provides greater confidence to a user that the IoT device is not infringing user privacy (as the Blockchain can be audited to verify which operation was carried out, by which actor). A formal model (following the privacy-by-design approach) is proposed for supporting GDPR compliance checking for smart devices. The privacy requirements of such applications are related to GDPR obligations of device (and software systems) operators (such as user consent, data protection, right to forget etc). Three smart contracts are proposed as a practical solution to support automated verification of operations carried out by devices on user data, in accordance with GDPR rules. We evaluate the performance and scalability costs of our approach using a Blockchain test network.
引用
收藏
页码:119697 / 119709
页数:13
相关论文
共 42 条
[1]   A Study on Security and Privacy Guidelines, Countermeasures, Threats: IoT Data at Rest Perspective [J].
Abdulghani, Hezam Akram ;
Nijdam, Niels Alexander ;
Cohen, Anastasija ;
Konstantas, Dimitri .
SYMMETRY-BASEL, 2019, 11 (06)
[2]  
Al-Said Taimur, 2015, International Journal of High Performance Computing and Networking, V8, P222
[3]   EclipseloT: A secure and adaptive hub for the Internet of Things [J].
Anthi, Eirini ;
Ahmad, Shazaib ;
Rana, Omer ;
Theodorakopoulos, George ;
Burnap, Pete .
COMPUTERS & SECURITY, 2018, 78 :477-490
[4]   Enhancing User Privacy in IoT: Integration of GDPR and Blockchain [J].
Barati, Masoud ;
Rana, Omer .
BLOCKCHAIN AND TRUSTWORTHY SYSTEMS, BLOCKSYS 2019, 2020, 1156 :322-335
[5]  
Barati M, 2019, INT CONF UTIL CLOUD, P133, DOI 10.1145/3344341.3368812
[6]   Privacy-Aware Cloud Ecosystems and GDPR Compliance [J].
Barati, Masoud ;
Rana, Omer ;
Theodorakopoulos, George ;
Burnap, Peter .
2019 7TH INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD (FICLOUD 2019), 2019, :117-124
[7]   On Purpose and by Necessity: Compliance Under the GDPR [J].
Basin, David ;
Debois, Soren ;
Hildebrandt, Thomas .
FINANCIAL CRYPTOGRAPHY AND DATA SECURITY, FC 2018, 2018, 10957 :20-37
[8]   Towards Better Availability and Accountability for IoT Updates by means of a Blockchain [J].
Boudguiga, Aymen ;
Bouzerna, Nabil ;
Granboulan, Louis ;
Olivereau, Alexis ;
Quesnel, Flavien ;
Roger, Anthony ;
Sirdey, Renaud .
2017 2ND IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW), 2017, :50-58
[9]   The state-of-the-art in container technologies: Application, orchestration and security [J].
Casalicchio, Emiliano ;
Iannucci, Stefano .
CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2020, 32 (17)
[10]   Building accountability into the Internet of Things: the IoT Databox model [J].
Crabtree A. ;
Lodge T. ;
Colley J. ;
Greenhalgh C. ;
Glover K. ;
Haddadi H. ;
Amar Y. ;
Mortier R. ;
Li Q. ;
Moore J. ;
Wang L. ;
Yadav P. ;
Zhao J. ;
Brown A. ;
Urquhart L. ;
McAuley D. .
Journal of Reliable Intelligent Environments, 2018, 4 (01) :39-55