SovereignEdge: A Context-Aware Cryptographic Architecture for Data Sovereignty in Mobile Edge–Fog–Cloud IoT Data Spaces

Shuwen Liu, George C. Polyzos · 2025

Existing three-tier IoT systems focus on real-time analytics and context-aware processing across Edge, Fog, and Cloud layers but often overlook data sovereignty in cross-organizational Data Space scenarios. This paper introduces SovereignEdge, a context-aware cryptographic framework that extends ciphertext-embedded policies to a distributed multi-authority model, letting mobile Edge data owners define detailed access rules before data goes to Fog or Cloud layers. SovereignEdge features a multi-tier key management system with multiple Fog-based Attribute Authorities operating under a trust root, supporting dynamic policy updates, attribute revocation, and secret sharing without requiring re-encryption of historical data. To prevent forged contextual claims on constrained Edge devices, SovereignEdge uses a verifiable attribute mechanism that reduces unauthorized decryption. It merges robust cryptographic enforcement and data-space-based auditing. This approach supports cross-domain auditing, efficient attribute revocation, and regulatory compliance, and it follows Data Space principles. Experimental results show that SovereignEdge preserves data sovereignty and enables privacy-preserving collaboration across heterogeneous Edge–Fog–Cloud environments.

Read the paper · More papers on PaperTik