Modelling privacy-aware trust negotiations

被引:8
|
作者
Rios, Ruben [1 ]
Fernandez-Gago, Carmen [1 ]
Lopez, Javier [1 ]
机构
[1] Univ Malaga, Network Informat & Comp Secur NICS Lab, Malaga, Spain
基金
欧盟地平线“2020”;
关键词
Secure Software Engineering; Requirements Engineering; Goal-Oriented Modelling; Trust; Privacy; Policy; TROPOS METHODOLOGY; SECURE TROPOS; REQUIREMENTS; SYSTEM;
D O I
10.1016/j.cose.2017.09.015
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Trust negotiations are mechanisms that enable interaction between previously unknown users. After exchanging various pieces of potentially sensitive information, the participants of a negotiation can decide whether or not to trust one another. Therefore, trust negotiations bring about threats to personal privacy if not carefully considered. This paper presents a framework for representing trust negotiations in the early phases of the Software Development Life Cycle (SDLC). The framework can help software engineers to determine the most suitable policies for the system by detecting conflicts between privacy and trust requirements. More precisely, we extend the SI* modelling language and provide a set of predicates for defining trust and privacy policies and a set of rules for describing the dynamics of the system based on the established policies. The formal representation of the model facilitates its automatic verification. The framework has been validated in a distributed social network scenario for connecting drivers with potential passengers willing to share a journey. (C) 2017 Elsevier Ltd. All rights reserved.
引用
收藏
页码:773 / 789
页数:17
相关论文
共 50 条
  • [1] Privacy-Aware Trust Negotiation
    Rios, Ruben
    Fernandez-Gago, Carmen
    Lopez, Javier
    [J]. SECURITY AND TRUST MANAGEMENT, STM 2016, 2016, 9871 : 98 - 105
  • [2] Understanding trust in privacy-aware video surveillance systems
    Rashwan, Hatem A.
    Solanas, Agusti
    Puig, Domenec
    Martinez-Balleste, Antoni
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2016, 15 (03) : 225 - 234
  • [3] Understanding trust in privacy-aware video surveillance systems
    Hatem A. Rashwan
    Agusti Solanas
    Domènec Puig
    Antoni Martínez-Ballesté
    [J]. International Journal of Information Security, 2016, 15 : 225 - 234
  • [4] Cloud service evaluation model based on trust and privacy-aware
    Wang, Yubiao
    Wen, Junhao
    Wang, Xibin
    Zhou, Wei
    [J]. OPTIK, 2017, 134 : 269 - 279
  • [5] Privacy-aware access control with trust management in web service
    Li, Min
    Sun, Xiaoxun
    Wang, Hua
    Zhang, Yanchun
    Zhang, Ji
    [J]. WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2011, 14 (04): : 407 - 430
  • [6] User modelling for privacy-aware self-disclosure
    Ben Salem, Rim
    Aimeur, Esma
    Hage, Hicham
    [J]. 2023 20TH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST, PST, 2023, : 44 - 51
  • [7] Privacy-aware access control with trust management in web service
    Min Li
    Xiaoxun Sun
    Hua Wang
    Yanchun Zhang
    Ji Zhang
    [J]. World Wide Web, 2011, 14 : 407 - 430
  • [8] Privacy-Aware Wrappers
    Jafer, Yasser
    Matwin, Stan
    Sokolova, Marina
    [J]. ADVANCES IN ARTIFICIAL INTELLIGENCE (AI 2015), 2015, 9091 : 130 - 138
  • [9] Privacy-Aware Folksonomies
    Heidinger, Clemens
    Buchmann, Erik
    Huber, Matthias
    Boehm, Klemens
    Mueller-Quade, Joern
    [J]. RESEARCH AND ADVANCED TECHNOLOGY FOR DIGITAL LIBRARIES, 2010, 6273 : 156 - 167
  • [10] TRIMS, a privacy-aware trust and reputation model for identity management systems
    Gomez Marmol, Felix
    Girao, Joao
    Martinez Perez, Gregorio
    [J]. COMPUTER NETWORKS, 2010, 54 (16) : 2899 - 2912