Masoud Barati
Privacy-Aware Cloud Auditing for GDPR Compliance Verification in Online Healthcare
Barati, Masoud; Aujla, Gagangeet Singh; Llanos, Jose Tomas; Duodu, Kwabena Adu; Rana, Omer F.; Carr, Madeline; Rajan, Rajiv
Authors
Dr Gagangeet Aujla gagangeet.s.aujla@durham.ac.uk
Associate Professor in Computer Science
Jose Tomas Llanos
Kwabena Adu Duodu
Omer F. Rana
Madeline Carr
Rajiv Rajan
Abstract
Emerging multi-tenant cloud computing ecosystems allow multiple applications to share virtualised pool of computing and networking resources. As a result such ecosystems are becoming increasingly prone to data privacy concerns (personal data leakages and unauthorised access). While cloud computing providers support robust security and privacy mechanisms (e.g, public key cryptography, firewalls, virtual private networks, among many others), they lack mechanisms and frameworks to monitor, audit and verify these data privacy concerns. The emergence of data protection regulations around the world, such as General Data Protection Regulation (GDPR) in Europe and the Data Protection Act (DPA) in the UK, further emphasise the need to overcome these privacy limitations. A novel technique for monitoring, auditing and verifying the operations carried out on a users personal data in cloud computing ecosystems is proposed. Our research methodology leverages distributed ledger technologies (e.g., Blockchain, Smart Contracts) for developing an immutable recording technique, which transparently logs, monitors and verifies the operations carried out on user data. Using a healthcare pharmacy scenario and extensive real-world experiments, we validate the feasibility of the proposed technique. The proposed work handles a large pool of requests (> 13K) ensuring minimal latency (approx. 50-60 ms) and overheads for three different service packages varied with respect to the number of actors and operations).
Citation
Barati, M., Aujla, G. S., Llanos, J. T., Duodu, K. A., Rana, O. F., Carr, M., & Rajan, R. (2022). Privacy-Aware Cloud Auditing for GDPR Compliance Verification in Online Healthcare. IEEE Transactions on Industrial Informatics, 18(7), 4808-4819. https://doi.org/10.1109/tii.2021.3100152
Journal Article Type | Article |
---|---|
Acceptance Date | Jul 27, 2021 |
Online Publication Date | Jul 27, 2021 |
Publication Date | 2022-07 |
Deposit Date | Sep 10, 2021 |
Publicly Available Date | Sep 10, 2021 |
Journal | IEEE Transactions on Industrial Informatics |
Print ISSN | 1551-3203 |
Electronic ISSN | 1941-0050 |
Publisher | Institute of Electrical and Electronics Engineers |
Peer Reviewed | Peer Reviewed |
Volume | 18 |
Issue | 7 |
Pages | 4808-4819 |
DOI | https://doi.org/10.1109/tii.2021.3100152 |
Public URL | https://durham-repository.worktribe.com/output/1234958 |
Files
Accepted Journal Article
(1.6 Mb)
PDF
Copyright Statement
© 2021 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.
You might also like
Uncovering hidden and complex relations of pandemic dynamics using an AI driven system
(2024)
Journal Article
Trusted Explainable AI for 6G-Enabled Edge Cloud Ecosystem
(2023)
Journal Article
Compliance Checking of Cloud Providers: Design and Implementation
(2023)
Journal Article
Downloadable Citations
About Durham Research Online (DRO)
Administrator e-mail: dro.admin@durham.ac.uk
This application uses the following open-source libraries:
SheetJS Community Edition
Apache License Version 2.0 (http://www.apache.org/licenses/)
PDF.js
Apache License Version 2.0 (http://www.apache.org/licenses/)
Font Awesome
SIL OFL 1.1 (http://scripts.sil.org/OFL)
MIT License (http://opensource.org/licenses/mit-license.html)
CC BY 3.0 ( http://creativecommons.org/licenses/by/3.0/)
Powered by Worktribe © 2025
Advanced Search