【24h】

Towards a Secure and GDPR-Compliant Fog-to-Cloud Platform

机译:朝着一个符合安全和符合GDPR的迷雾到云平台

获取原文

摘要

The mF2C project is building an open, secure and decentralized management platform for coordinating resource sharing between connected devices in the fog-to-cloud (F2C) environment. Safeguarding information security and privacy in mF2C is a considerable challenge given the heterogeneous and autonomous nature of devices spanning the F2C spectrum. The recently introduced General Data Protection Regulation (GDPR) raised the stake further by defining stringent security and privacy requirements on the processing of personal information. IaaS and PaaS providers falling in scope must demonstrate that they have implemented reasonable security mechanisms to ensure compliance or face significant financial penalties. In this paper, we present a prototype JAVA-based security library that addresses some of the data security and privacy requirements of mF2C and GDPR. The prototype employs a PKI-based trust model to facilitate authentication and authorization. It uses policy to ensure data privacy and cryptography to deliver data confidentiality, integrity and non-repudiation. We also outline plans to enhance the mF2C security infrastructure with data protection functionalities from the security library and to leverage blockchain technology to augment mF2C security and data protection capabilities.
机译:MF2C项目正在构建一个开放式,安全和分散的管理平台,用于协调雾到云(F2C)环境中的连接设备之间的资源共享。鉴于跨越F2C谱的设备的异构和自主性,保障信息安全和隐私是一个相当大的挑战。最近引入的一般数据保护规则(GDPR)通过定义关于处理个人信息的严格安全性和隐私要求,进一步提出了股权。 IAAS和PAAS提供者落在范围内,必须证明他们已经实施了合理的安全机制,以确保合规或面临重大的经济处罚。在本文中,我们提出了一种基于原型的Java的安全库,用于解决MF2C和GDP的一些数据安全性和隐私要求。原型采用基于PKI的信任模型,以促进身份验证和授权。它使用策略来确保数据隐私和加密,以提供数据机密性,完整性和非拒绝。我们还概述计划以安全库的数据保护功能增强MF2C安全基础架构,并利用SlockChain技术来增强MF2C安全性和数据保护功能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号