Towards a GDPR-compliant cloud architecture with data privacy controlled through sticky policies
Resumen: Data privacy is one of the biggest challenges facing system architects at the system design stage. Especially when certain laws, such as the General Data Protection Regulation (GDPR), have to be complied with by cloud environments. In this article, we want to help cloud providers comply with the GDPR by proposing a GDPR-compliant cloud architecture. To do this, we use model-driven engineering techniques to design cloud architecture and analyze cloud interactions. In particular, we develop a complete framework, called MDCT, which includes a Unified Modeling Language profile that allows us to define specific cloud scenarios and profile validation to ensure that certain required properties are met. The validation process is implemented through the Object Constraint Language (OCL) rules, which allow us to describe the constraints in these models. To comply with many GDPR articles, the proposed cloud architecture considers data privacy and data tracking, enabling safe and secure data management and tracking in the context of the cloud. For this purpose, sticky policies associated with the data are incorporated to define permission for third parties to access the data and track instances of data access. As a result, a cloud architecture designed with MDCT contains a set of OCL rules to validate it as a GDPR-compliant cloud architecture. Our tool models key GDPR points such as user consent/withdrawal, the purpose of access, and data transparency and auditing, and considers data privacy and data tracking with the help of sticky policies.
Idioma: Inglés
DOI: 10.7717/peerj-cs.1898
Año: 2024
Publicado en: PeerJ Computer Science 10 (2024), e1898 [44 pp.]
ISSN: 2376-5992

Factor impacto JCR: 2.5 (2024)
Categ. JCR: COMPUTER SCIENCE, THEORY & METHODS rank: 56 / 147 = 0.381 (2024) - Q2 - T2
Categ. JCR: COMPUTER SCIENCE, ARTIFICIAL INTELLIGENCE rank: 116 / 204 = 0.569 (2024) - Q3 - T2
Categ. JCR: COMPUTER SCIENCE, INFORMATION SYSTEMS rank: 142 / 258 = 0.55 (2024) - Q3 - T2

Factor impacto CITESCORE: 7.1 - Computer Science (all) (Q1)

Factor impacto SCIMAGO: 0.719 - Computer Science (miscellaneous) (Q1)

Financiación: info:eu-repo/grantAgreement/ES/DGA/T21-23R
Financiación: info:eu-repo/grantAgreement/ES/MICINN-AEI-FEDER/PID2021-PID2021-122215NB-C32
Tipo y forma: Artículo (Versión definitiva)
Área (Departamento): Área Lenguajes y Sistemas Inf. (Dpto. Informát.Ingenie.Sistms.)

Creative Commons Debe reconocer adecuadamente la autoría, proporcionar un enlace a la licencia e indicar si se han realizado cambios. Puede hacerlo de cualquier manera razonable, pero no de una manera que sugiera que tiene el apoyo del licenciador o lo recibe por el uso que hace.


Exportado de SIDERAL (2026-02-17-20:22:19)


Visitas y descargas

Este artículo se encuentra en las siguientes colecciones:
Artículos > Artículos por área > Lenguajes y Sistemas Informáticos



 Registro creado el 2024-04-24, última modificación el 2026-02-17


Versión publicada:
 PDF
Valore este documento:

Rate this document:
1
2
3
 
(Sin ninguna reseña)