Privacy-Aware Cloud Auditing for GDPR Compliance Verification in Online Healthcare

Privacy-Aware Cloud Auditing for GDPR Compliance Verification in Online Healthcare
复制标题

DOI:
10.1109/tii.2021.3100152
复制
发表时间:
2022-07-01
影响因子:
12.3
通讯作者:
Ranjan, Rajiv
Ranjan, Rajiv
中科院分区:
计算机科学1区
文献类型:
--
作者:
Barati, Masoud;Aujla, Gagangeet Singh;Ranjan, Rajiv

文献摘要

被引文献

相似文献

新兴的多租户云计算生态系统允许多个应用程序共享虚拟化的计算和网络资源池。因此,这些生态系统越来越容易受到数据隐私问题的影响(个人数据泄露和未经授权的访问)。虽然云计算提供商支持鲁棒的安全和隐私机制(例如,公钥加密、防火墙和虚拟专用网络等),它们缺乏监控、审计和验证这些数据隐私问题的机制和框架。世界各地数据保护法规的出现,如欧洲的《通用数据保护条例》和英国的《数据保护法》,进一步强调需要克服这些隐私限制。在这篇文章中,提出了一种新的技术,用于监视、审计和验证在云计算生态系统中对用户个人数据进行的操作。我们的研究方法利用分布式账本技术(例如,区块链和智能合约),用于开发不可变的记录技术,透明地记录、监控和验证对用户数据进行的操作。使用医疗药房的情况下,广泛的现实世界的实验,我们验证了所提出的技术的可行性。拟议的工作处理大量的请求(> 13 K),确保最小的延迟(约50-60毫秒)和开销为三个不同的服务包不同的演员和操作的数量。
Emerging multitenant cloud computing ecosystems allow multiple applications to share virtualized pool of computing and networking resources. As a result, such ecosystems are becoming increasingly prone to data privacy concerns (personal data leakages and unauthorized access). While cloud computing providers support robust security and privacy mechanisms (e.g., public key cryptography, firewalls, and virtual private networks, among many others), they lack mechanisms and frameworks to monitor, audit, and verify these data privacy concerns. The emergence of data protection regulations around the world, such as General Data Protection Regulation in Europe and the Data Protection Act in the U.K., further emphasizes the need to overcome these privacy limitations. In this article, a novel technique for monitoring, auditing, and verifying the operations carried out on a user's personal data in cloud computing ecosystems is proposed. Our research methodology leverages distributed ledger technologies (e.g., blockchain and smart contracts) for developing an immutable recording technique, which transparently logs, monitors, and verifies the operations carried out on user data. Using a healthcare pharmacy scenario and extensive real-world experiments, we validate the feasibility of the proposed technique. The proposed work handles a large pool of requests (>13K) ensuring minimal latency (approximate to 50-60 ms) and overheads for three different service packages varied with respect to the number of actors and operations.