Uppsats

Engineering Consent-Aware Service Orchestration at the Edge : A Privacy-Driven Approach for Software-Defined Vehicles

Magister-uppsats

Blekinge Tekniska Högskola/Institutionen för programvaruteknik

Publicerad: 2026

Språk: Engelska

Sammanfattning

Background Modern vehicles are increasingly software-defined and data-intensive, requiring compliance with privacy regulations such as the General Data Protection Regulation (GDPR). Current enforcement mechanisms remain heavily cloud-centric and struggle to translate privacy obligations—particularly consent withdrawal—into actionable technical controls when vehicles operate offline or with intermittent connectivity. Objectives This thesis investigates how consent-aware privacy enforcement can be realized through lightweight orchestration logic deployed directly at the vehicle edge. The goal is to demonstrate how system-level privacy control can be preserved without continuous backend connectivity by unifying consent collection, policy enforcement, and dynamic orchestration within a cohesive edge-native framework. Methods The study follows a Design Science Research (DSR) methodology, which involves iterative construction and evaluation of a consent-aware orchestration framework. The artifact integrates a lightweight orchestration platform (KubeEdge), local consent-state management, and audit-capable logging. The evaluation followed a mixed-methods approach using a Raspberry Pi~5 testbed, combining controlled deployment experiments, log-based analysis, and stakeholder validation sessions with developers and Data Protection Officers. Results Findings confirm both feasibility and verifiable traceability. Feasibility (RQ1): The system reliably deployed and executed services on constrained hardware, enforcing consent changes locally in 100 % of offline scenarios with a near-instantaneous response from the user’s perspective. Traceability (RQ2): Audit-log inspection showed that all consent transitions were captured with complete metadata, enabling reconstruction of the entire lifecycle even when events occurred locally and synchronized later. Conclusions The results demonstrate that consent-aware orchestration at the edge is technically viable and capable of maintaining compliance transparency under intermittent connectivity. Embedding enforcement directly into the orchestration layer operationalizes regulatory intent through autonomous and locally enforceable mechanisms, positioning privacy obligations as a built-in property of distributed systems.

Information

Lärosäte / institution
Blekinge Tekniska Högskola/Institutionen för programvaruteknik
Publiceringsdatum
2026
Uppsatstyp
Magister-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.