Search papers, labs, and topics across Lattice.
This paper introduces the Secure Edge Gateway (SEG) framework, which addresses the simultaneous challenges of GDPR-compliant pseudonymisation, usability for the elderly, and integrated threat validation in remote elderly care systems. By employing a combination of MAC address whitelisting, cryptographic pseudonymisation, and AES-128-CBC encryption, the SEG framework ensures compliance with GDPR while maintaining operational efficiency. The findings reveal that GDPR compliance can coexist with improved performance metrics, such as reduced energy consumption and lower response latency compared to traditional cloud-only systems.
GDPR compliance and operational efficiency can be achieved simultaneously in elderly care IoMT systems, challenging the notion that they are mutually exclusive.
IoMT-based remote elderly care systems generate continuous streams of sensitive health data, yet existing security architectures have not simultaneously addressed three interdependent challenges: GDPR-compliant edge-layer pseudonymisation, elderly-specific zero-interaction usability as a binding architectural constraint, and integrated STRIDE-based threat validation within a single unified design. This paper presents the Secure Edge Gateway (SEG) framework - a software-simulation-validated integrated IoMT security architecture for elderly care designed to resolve all three dimensions of this tripartite gap simultaneously. An ESP32-WROOM-32 residential gateway enforces MAC address whitelisting, HMAC-SHA256 cryptographic pseudonymisation before any network transmission, AES-128-CBC payload encryption, and TLS 1.3 transport security, in compliance with GDPR Articles 25 and 32. The framework is validated through software-based simulation, full STRIDE threat modelling across all six categories, attack tree analysis, GDPR compliance mapping across nine regulatory obligations, and a Data Protection Impact Assessment (DPIA) under Article 35. Published benchmarks confirm MQTT consumes 6-8% less energy than HTTP in comparable IoT deployments, and edge processing achieves sub-50 ms response latency versus 200-700 ms for cloud-only systems. The results demonstrate that GDPR compliance and operational efficiency are complementary - not competing - objectives in resource-constrained IoMT deployments for elderly care.