Pseudonymization risk analysis in distributed systems

被引:6
|
作者
Neumann, Geoffrey K. [1 ]
Grace, Paul [1 ]
Burns, Daniel [1 ]
Surridge, Mike [1 ]
机构
[1] Univ Southampton, IT Innovat, Gamma House,Enterprise Rd, Southampton SO16 7NS, Hants, England
关键词
Privacy; Pseudonymization; Risk analysis; PRIVACY;
D O I
10.1186/s13174-018-0098-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In an era of big data, online services are becoming increasingly data-centric; they collect, process, analyze and anonymously disclose growing amounts of personal data in the form of pseudonymized data sets. It is crucial that such systems are engineered to both protect individual user (data subject) privacy and give back control of personal data to the user. In terms of pseudonymized data this means that unwanted individuals should not be able to deduce sensitive information about the user. However, the plethora of pseudonymization algorithms and tuneable parameters that currently exist make it difficult for a non expert developer (data controller) to understand and realise strong privacy guarantees. In this paper we propose a principled Model-Driven Engineering (MDE) framework to model data services in terms of their pseudonymization strategies and identify the risks to breaches of user privacy. A developer can explore alternative pseudonymization strategies to determine the effectiveness of their pseudonymization strategy in terms of quantifiable metrics: i) violations of privacy requirements for every user in the current data set; ii) the trade-off between conforming to these requirements and the usefulness of the data for its intended purposes. We demonstrate through an experimental evaluation that the information provided by the framework is useful, particularly in complex situations where privacy requirements are different for different users, and can inform decisions to optimize a chosen strategy in comparison to applying an off-the-shelf algorithm.
引用
收藏
页数:16
相关论文
共 50 条
  • [31] STABILITY ANALYSIS OF SYSTEMS WITH DISTRIBUTED DELAY
    KARMARKAR, JS
    PROCEEDINGS OF THE INSTITUTION OF ELECTRICAL ENGINEERS-LONDON, 1970, 117 (07): : 1425 - +
  • [32] Peak cost analysis of distributed systems
    1600, Springer Verlag (8723):
  • [33] Experimental Analysis of Distributed Graph Systems
    Ammar, Khaled
    Ozsu, M. Tamer
    PROCEEDINGS OF THE VLDB ENDOWMENT, 2018, 11 (10): : 1151 - 1164
  • [34] Formal specification and analysis of distributed systems
    HENRIKAS PRANEVICIUS
    Journal of Intelligent Manufacturing, 1998, 9 : 559 - 569
  • [35] Heterogeneous analysis and verification for distributed systems
    Steffen, B
    Margaria, T
    Classen, A
    SOFTWARE-CONCEPTS AND TOOLS, 1996, 17 (01): : 13 - 25
  • [36] Quantitative static analysis of distributed systems
    Di Pierro, A
    Hankin, C
    Wiklicky, H
    JOURNAL OF FUNCTIONAL PROGRAMMING, 2005, 15 : 703 - 749
  • [37] Formal specification and analysis of distributed systems
    Pranevicius, H
    JOURNAL OF INTELLIGENT MANUFACTURING, 1998, 9 (06) : 559 - 569
  • [38] RELIABILITY-ANALYSIS IN DISTRIBUTED SYSTEMS
    RAGHAVENDRA, CS
    KUMAR, VKP
    HARIRI, S
    IEEE TRANSACTIONS ON COMPUTERS, 1988, 37 (03) : 352 - 358
  • [39] Peak Cost Analysis of Distributed Systems
    Albert, Elvira
    Correas, Jesus
    Roman-Diez, Guillermo
    STATIC ANALYSIS (SAS 2014), 2014, 8723 : 18 - 33
  • [40] The analysis of distributed systems with nonlocal damping
    Lei, Yongjun
    Friswell, Michael I.
    Adhikari, Sondipon
    SMART STRUCTURES AND MATERIALS 2006: DAMPING AND ISOLATION, 2006, 6169