Pseudonymization risk analysis in distributed systems

被引:6
|
作者
Neumann, Geoffrey K. [1 ]
Grace, Paul [1 ]
Burns, Daniel [1 ]
Surridge, Mike [1 ]
机构
[1] Univ Southampton, IT Innovat, Gamma House,Enterprise Rd, Southampton SO16 7NS, Hants, England
关键词
Privacy; Pseudonymization; Risk analysis; PRIVACY;
D O I
10.1186/s13174-018-0098-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In an era of big data, online services are becoming increasingly data-centric; they collect, process, analyze and anonymously disclose growing amounts of personal data in the form of pseudonymized data sets. It is crucial that such systems are engineered to both protect individual user (data subject) privacy and give back control of personal data to the user. In terms of pseudonymized data this means that unwanted individuals should not be able to deduce sensitive information about the user. However, the plethora of pseudonymization algorithms and tuneable parameters that currently exist make it difficult for a non expert developer (data controller) to understand and realise strong privacy guarantees. In this paper we propose a principled Model-Driven Engineering (MDE) framework to model data services in terms of their pseudonymization strategies and identify the risks to breaches of user privacy. A developer can explore alternative pseudonymization strategies to determine the effectiveness of their pseudonymization strategy in terms of quantifiable metrics: i) violations of privacy requirements for every user in the current data set; ii) the trade-off between conforming to these requirements and the usefulness of the data for its intended purposes. We demonstrate through an experimental evaluation that the information provided by the framework is useful, particularly in complex situations where privacy requirements are different for different users, and can inform decisions to optimize a chosen strategy in comparison to applying an off-the-shelf algorithm.
引用
收藏
页数:16
相关论文
共 50 条
  • [41] FORMAL TIMING ANALYSIS OF DISTRIBUTED SYSTEMS
    MALL, R
    PATNAIK, LM
    INTERNATIONAL JOURNAL OF PARALLEL PROGRAMMING, 1991, 20 (02) : 75 - 94
  • [42] Analysis and autonomous distributed control of super distributed energy systems
    Yasuda, K
    Ishii, T
    IEEE/PES TRANSMISSION AND DISTRIBUTION CONFERENCE AND EXHIBITION 2002: ASIA PACIFIC, VOLS 1-3, CONFERENCE PROCEEDINGS: NEW WAVE OF T&D TECHNOLOGY FROM ASIA PACIFIC, 2002, : 1628 - 1631
  • [43] Improving the protection of assets in open distributed systems by use of X-ifying risk analysis
    Frisinger, A
    TRUSTED INFORMATION: THE NEW DECADE CHALLENGE, 2001, 65 : 293 - 303
  • [44] Suitability of risk analysis methods for security assessment of large-scale distributed computer systems
    Djordjevic, I
    Scharf, E
    Raptis, D
    Gran, BA
    PROBABILISTIC SAFETY ASSESSMENT AND MANAGEMENT, VOL I AND II, PROCEEDINGS, 2002, : 1897 - 1902
  • [45] Risk modeling in distributed, large-scale systems
    Grabowski, M
    Merrick, JRW
    Harrald, JR
    Mazzuchi, TA
    van Dorp, JR
    IEEE TRANSACTIONS ON SYSTEMS MAN AND CYBERNETICS PART A-SYSTEMS AND HUMANS, 2000, 30 (06): : 651 - 660
  • [46] Determining and Sharing Risk Data in Distributed Interdependent Systems
    Burnap, Pete
    Cherdantseva, Yulia
    Blyth, Andrew
    Eden, Peter
    Jones, Kevin
    Soulsby, Hugh
    Stoddart, Kristan
    COMPUTER, 2017, 50 (04) : 72 - 79
  • [47] Security Risk Management Methodology for Distributed Ledger Systems
    Durakovskiy, Anatoly P.
    Gorbatov, Victor S.
    Dyatlov, Dmitriy A.
    Melnikov, Dmitriy A.
    BIOLOGICALLY INSPIRED COGNITIVE ARCHITECTURES 2021, 2022, 1032 : 96 - 112
  • [48] Cyber Security Risk Modeling in Distributed Information Systems
    Palko, Dmytro
    Babenko, Tetiana
    Bigdan, Andrii
    Kiktev, Nikolay
    Hutsol, Taras
    Kubon, Maciej
    Hnatiienko, Hryhorii
    Tabor, Sylwester
    Gorbovy, Oleg
    Borusiewicz, Andrzej
    APPLIED SCIENCES-BASEL, 2023, 13 (04):
  • [49] Impact of CyberShake on Risk Assessments for Distributed Infrastructure Systems
    Lee, Yajie
    Goulet, Christine
    Hu, Zhenghui
    Eguchi, Ronald T.
    LIFELINES 2022: 1971 SAN FERNANDO EARTHQUAKE AND LIFELINE INFRASTRUCTURE, 2022, : 869 - 879
  • [50] A Distributed Algorithm for Systemic Risk Mitigation in Financial Systems
    Li, Zhang
    Lin, Xiaojun
    Pollak, Ilya
    2013 IEEE GLOBAL CONFERENCE ON SIGNAL AND INFORMATION PROCESSING (GLOBALSIP), 2013, : 1137 - 1137