Aviso: para depositar documentos, por favor, inicia sesión e identifícate con tu cuenta de correo institucional de la UCM con el botón MI CUENTA UCM. No emplees la opción AUTENTICACIÓN CON CONTRASEÑA
 

Towards a GDPR-compliant cloud architecture with data privacy controlled through sticky policies

dc.contributor.authorCambronero, M. Emilia
dc.contributor.authorMartínez, Miguel A.
dc.contributor.authorLlana Díaz, Luis Fernando
dc.contributor.authorRodríguez, Ricardo J.
dc.contributor.authorRusso, Alejandro
dc.date.accessioned2024-12-11T11:31:22Z
dc.date.available2024-12-11T11:31:22Z
dc.date.issued2024-03-29
dc.description.abstractData privacy is one of the biggest challenges facing system architects at the system design stage. Especially when certain laws, such as the General Data Protection Regulation (GDPR), have to be complied with by cloud environments. In this article, we want to help cloud providers comply with the GDPR by proposing a GDPR-compliant cloud architecture. To do this, we use model-driven engineering techniques to design cloud architecture and analyze cloud interactions. In particular, we develop a complete framework, called MDCT, which includes a Unified Modeling Language profile that allows us to define specific cloud scenarios and profile validation to ensure that certain required properties are met. The validation process is implemented through the Object Constraint Language (OCL) rules, which allow us to describe the constraints in these models. To comply with many GDPR articles, the proposed cloud architecture considers data privacy and data tracking, enabling safe and secure data management and tracking in the context of the cloud. For this purpose, sticky policies associated with the data are incorporated to define permission for third parties to access the data and track instances of data access. As a result, a cloud architecture designed with MDCT contains a set of OCL rules to validate it as a GDPR-compliant cloud architecture. Our tool models key GDPR points such as user consent/withdrawal, the purpose of access, and data transparency and auditing, and considers data privacy and data tracking with the help of sticky policies.
dc.description.departmentDepto. de Sistemas Informáticos y Computación
dc.description.facultyFac. de Estudios Estadísticos
dc.description.refereedTRUE
dc.description.sponsorshipMinisterio de Ciencia y Educación
dc.description.sponsorshipUnión Europea
dc.description.sponsorshipComunidad de Madrid
dc.description.sponsorshipGobierno de Aragón
dc.description.statuspub
dc.identifier.citationCambronero ME, Martínez MA, Llana L, Rodríguez RJ, Russo A. 2024. Towards a GDPR-compliant cloud architecture with data privacy controlled through sticky policies. PeerJ Computer Science 10:e1898 https://doi.org/10.7717/peerj-cs.1898
dc.identifier.doi10.7717/peerj-cs.1898
dc.identifier.officialurlhttp://dx.doi.org/10.7717/peerj-cs.1898
dc.identifier.relatedurlhttps://peerj.com/articles/cs-1898/
dc.identifier.urihttps://hdl.handle.net/20.500.14352/112413
dc.journal.titlePeer J. Computer Science
dc.language.isoeng
dc.publisherPeerJ Publishing
dc.relation.projectIDPID2021-122215NB-C32
dc.relation.projectIDFORTE-CM, S2018/TCS-4314
dc.relation.projectIDPR65/19-22452
dc.rightsAttribution-NoDerivatives 4.0 Internationalen
dc.rights.accessRightsopen access
dc.rights.urihttp://creativecommons.org/licenses/by-nd/4.0/
dc.subject.cdu004
dc.subject.cdu004.056
dc.subject.cdu004.41
dc.subject.keywordGeneral data protection regulation
dc.subject.keywordData privacy
dc.subject.keywordCloud computing
dc.subject.keywordSticky policies
dc.subject.keywordData tracking
dc.subject.keywordUnified Modeling Language
dc.subject.keywordUML profiling
dc.subject.keywordModel validation
dc.subject.keywordObject Constraint Language
dc.subject.ucmInformática (Informática)
dc.subject.ucmSeguridad informática
dc.subject.unesco1203.17 Informática
dc.titleTowards a GDPR-compliant cloud architecture with data privacy controlled through sticky policies
dc.typejournal article
dc.type.hasVersionVoR
dspace.entity.typePublication
relation.isAuthorOfPublication680f556a-4f1b-4eda-9add-da2c9b24796a
relation.isAuthorOfPublication.latestForDiscovery680f556a-4f1b-4eda-9add-da2c9b24796a

Download

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Towards a GDPR
Size:
3.29 MB
Format:
Adobe Portable Document Format

Collections