Guiding the implementation of data privacy with microservices

被引:0
|
作者
Antunes, Pedro [1 ]
Guimaraes, Nuno [2 ]
机构
[1] Univ Lisbon, Fac Sci, LaSIGE, Campo Grande, P-1749016 Lisbon, Portugal
[2] Univ Inst Lisbon, ISCTE, Ave Forcas Armadas, P-1649026 Lisbon, Portugal
关键词
Privacy by design; Microservices; Data privacy implementation; Decision framework; DESIGN; CLOUD; CHALLENGES; SECURITY; MODEL;
D O I
10.1007/s10207-024-00907-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Privacy by design is nowadays recognized as essential in bringing data privacy into software systems. However, developers still face many challenges in reconciling privacy and software requirements and implementing privacy protections in software systems. One emerging trend is the adoption of microservices architectures-they bring in some qualities that can benefit privacy by design. The main goal of this study is to adapt privacy by design to the qualities brought by microservices. The main focus is at the architectural level, where the main structural decisions are made. A systematic literature review is adopted to identify a set of privacy models that underscore significant differences in software systems' protection using microservices. From the literature review, a decision framework is developed. The decision framework provides guidance and supports design decisions in implementing data privacy using microservices. The framework helps select and integrate different privacy models. An illustration of using the framework, which considers the design of an electronic voting system, is provided. This study contributes to closing the gap between regulation and implementation through design, where decisions related to data privacy are integrated with decisions on architecting systems using microservices.
引用
收藏
页数:18
相关论文
共 50 条
  • [1] Privacy Data Envelope: Concept and Implementation
    Ghorbel, Mahmoud
    Aghasaryan, Armen
    Betge-Brezetz, Stephane
    Dupont, Marie-Pascale
    Kamga, Guy-Bertrand
    Piekarec, Sophie
    [J]. 2011 NINTH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST, 2011, : 55 - 62
  • [2] The civic transformation of data privacy implementation in Europe
    Mizarhi-Borohovich, Inbar
    Newman, Abraham
    Sivan-Sevilla, Ido
    [J]. WEST EUROPEAN POLITICS, 2024, 47 (03) : 671 - 700
  • [3] Analysis and Implementation of Microservices Using Docker
    Sharma, Keshav
    Verma, Anshul
    Verma, Pradeepika
    [J]. ADVANCED NETWORK TECHNOLOGIES AND INTELLIGENT COMPUTING, ANTIC 2022, PT I, 2023, 1797 : 413 - 421
  • [4] Mapping and evaluating national data flows: transparency, privacy, and guiding infrastructural transformation
    Zhang, Joe
    Morley, Jess
    Gallifant, Jack
    Oddy, Chris
    Teo, James T.
    Ashrafian, Hutan
    Delaney, Brendan
    Darzi, Ara
    [J]. LANCET DIGITAL HEALTH, 2023, 5 (10): : 737 - 748
  • [5] Analysing Privacy-Preserving Constraints in Microservices Architecture
    Vistbakka, Inna
    Troubitsyna, Elena
    [J]. 2020 IEEE 44TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2020), 2020, : 1089 - 1090
  • [6] Ephemeral Data Handling in Microservices
    Giallorenzo, Saverio
    Montesi, Fabrizio
    Safinal, Larisa
    Zingaro, Stefano Pio
    [J]. 2019 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING (IEEE SCC 2019), 2019, : 234 - 236
  • [7] An Implementation of Microservices Based Architecture for Remote Laboratories
    Moussa, Mohammed
    Benachenhou, Abdelhalim
    Belghit, Smail
    Benattia, Abderrahmane Adda
    Boumehdi, Abderrahmane
    [J]. CROSS REALITY AND DATA SCIENCE IN ENGINEERING, 2021, 1231 : 154 - 161
  • [8] Design and Implementation of a Decentralized Message Bus for Microservices
    Kookarinrat, Pakorn
    Temtanapat, Yaowadee
    [J]. 2016 13TH INTERNATIONAL JOINT CONFERENCE ON COMPUTER SCIENCE AND SOFTWARE ENGINEERING (JCSSE), 2016, : 183 - 188
  • [9] An Architecture and Implementation of Automatic Network Slicing for Microservices
    Minami, Yuki
    Taniguchi, Atsushi
    Kawabata, Taichi
    Sakaida, Norio
    Shimano, Katsuhiro
    [J]. NOMS 2018 - 2018 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2018,
  • [10] Privacy in implementation
    Gradwohl, Ronen
    [J]. SOCIAL CHOICE AND WELFARE, 2018, 50 (03) : 547 - 580