Security and Privacy Preserving GDPR-Compliant Scheme Resisting in Rendering False Data
Mou Dutta, Subhasish Dhal · 2024
The protection of personal data has grown to be a top priority around the world. The General Data Protection Regulation (GDPR) enables the data subjects (DS) to get back the control of their personal information, which is usually managed and processed by Service Providers (SP). Therefore, it is to check whether a service by SP is GDPR compliant. Manual verification is not feasible as a lot of data are being generated over time by a DS. An automated process may help. We explored a recent such automated tool, which allows the SP to provide requested data to a User (U) only if the DS has the consent for this transaction. However, a malicious SP can alter the data as the correctness of the received data is not being verified. In this paper, we have addressed this problem and proposed a GDPR compliant scheme that ensures the correctness of the received data. We simulate our proposed scheme using the well-known Automated Verification of Internet Security Protocols and Application (AVISPA) verification tool, which illustrates that the proposed scheme is safe. We compare the performance of our proposed scheme with the existing scheme to ensure its acceptance in real life.