Ilmu Komputer & AI editorial
Open AccessOA2026
Designing a GDPR-Compliant Security Architecture for Remote Elderly Care Systems: A Privacy-by-Design Approach
The Secure Edge Gateway (SEG) framework integrates edge-layer pseudonymisation, zero-interaction usability, and STRIDE-based threat validation for IoMT elderly care.
Md. Rahid Parvez; Mikael Soini· 2026· DOI 10.48550/arXiv.2607.13122
The core problem
IoMT-based remote elderly care systems continuously generate sensitive health data, yet existing security architectures have not simultaneously addressed three interdependent challenges: GDPR-compliant edge-layer pseudonymisation, elderly-specific zero-interaction usability as a binding architectural constraint, and integrated STRIDE-based threat validation within a single unified design. This tripartite gap motivates the Secure Edge Gateway (SEG) framework, an integrated IoMT security architecture for elderly care designed to resolve all three dimensions simultaneously. The work is positioned at the intersection of privacy-by-design regulation (GDPR Articles 25 and 32) and practical, resource-constrained IoT deployment for a vulnerable population.
Innovation
Published benchmarks confirm that MQTT consumes 6–8% less energy than HTTP in comparable IoT deployments, and edge processing achieves sub-50 ms response latency versus 200–700 ms for cloud-only systems. The SEG framework's simulation-based validation demonstrates that GDPR compliance mechanisms (pseudonymisation, encryption, access control) do not introduce prohibitive overhead. The STRIDE threat modelling across all six categories and attack tree analysis identified no unmitigated high-risk threats within the defined scope. GDPR compliance mapping covered nine regulatory obligations, and the DPIA under Article 35 was completed, confirming that the architecture meets privacy-by-design requirements.
IoMT-based remote elderly care systems continuously generate sensitive health data, yet existing security architectures have not simultaneously addressed three interdependent challenges: GDPR-compliant edge-layer pseudonymisation, elderly-specific zero-interaction usability as a binding architectural constraint, and integrated STRIDE-based threat validation within a single unified design. This tripartite gap motivates the Secure Edge Gateway (SEG) framework, an integrated IoMT security architecture for elderly care designed to resolve all three dimensions simultaneously. The work is positioned at the intersection of privacy-by-design regulation (GDPR Articles 25 and 32) and practical, resource-constrained IoT deployment for a vulnerable population.
The SEG framework is built around an ESP32-WROOM-32 residential gateway that enforces multiple security layers before any network transmission. Key mechanisms include:
Why it matters
The results demonstrate that GDPR compliance and operational efficiency are complementary—not competing—objectives in resource-constrained IoMT deployments for elderly care. The SEG framework resolves the tripartite gap by integrating edge-layer pseudonymisation, zero-interaction usability (critical for elderly users who may have limited technical proficiency), and STRIDE-based threat validation into a single architecture. The use of an ESP32-WROOM-32 gateway shows that robust security can be implemented on low-cost, low-power hardware. The sub-50 ms edge latency supports real-time monitoring and alerting, which is essential for elderly care scenarios. The framework's alignment with GDPR Articles 25 and 32 provides a regulatory blueprint for similar IoMT systems. Future work may involve physical deployment and long-term field validation.
Who should read this
CS practitioners and researchers
Opening member content…