{"title":"GDPR Compliant Audit Log Management System with Blockchain: GDPR Uyumlu Denetim Günlüğü Yönetim Sistemi","authors":"Ulaş Aslan, Baha Şen","doi":"10.1109/UYMS54260.2021.9659700","DOIUrl":null,"url":null,"abstract":"Audit log files can contain both personal data and system actions. Therefore, storing audit log files in accordance with the General Data Protection Regulation (GDPR) has become a legal obligation. In this paper, we propose a GDPR-compliant log storage system called Solid Log Chain (SLC). The goal of Solid Log Chain is to store audit logs and ensure the confidentiality and immutability of log data while meeting GDPR obligations. We have developed SLC by combining existing technologies with blockchain and using it in innovative ways. We have developed a data structure that allows only personal data to be deleted without destroying data integrity. Solid Log Chain is intended to be an alternative to expensive hardware-based solutions. We describe the design concept and architecture of the SLC and evaluate its performance in terms of latency and payload size.","PeriodicalId":287667,"journal":{"name":"2021 15th Turkish National Software Engineering Symposium (UYMS)","volume":"144 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-11-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 15th Turkish National Software Engineering Symposium (UYMS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/UYMS54260.2021.9659700","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
Audit log files can contain both personal data and system actions. Therefore, storing audit log files in accordance with the General Data Protection Regulation (GDPR) has become a legal obligation. In this paper, we propose a GDPR-compliant log storage system called Solid Log Chain (SLC). The goal of Solid Log Chain is to store audit logs and ensure the confidentiality and immutability of log data while meeting GDPR obligations. We have developed SLC by combining existing technologies with blockchain and using it in innovative ways. We have developed a data structure that allows only personal data to be deleted without destroying data integrity. Solid Log Chain is intended to be an alternative to expensive hardware-based solutions. We describe the design concept and architecture of the SLC and evaluate its performance in terms of latency and payload size.