Privacy by Evidence: A Methodology to develop privacy-friendly software applications

被引:4
|
作者
Barbosa, Pedro [1 ]
Brito, Andrey [1 ]
Almeida, Hyggo [1 ]
机构
[1] Univ Fed Campina Grande, Comp & Syst Dept, Campina Grande, Paraiba, Brazil
关键词
Methodology; Process risk; Privacy-enhancing technologies;
D O I
10.1016/j.ins.2019.09.040
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In an increasingly connected world, a diversity of data is collected from the environment and its inhabitants. Because of the richness of the information, privacy becomes an important requirement. Although there are principles and rules, there is still a lack of methodologies to guide the integration of privacy guidelines into the development process. Methodologies like the Privacy by Design (PbD) are still vague and leave many open questions on how to apply them in practice. In this work we propose a new concept, called Privacy by Evidence (PbE), in the form of a software development methodology to provide privacy-awareness. Given the difficulty in providing total privacy in many applications, we propose to document the mitigations in form of evidences of privacy, aiming to increase the confidence of the project. To validate its effectiveness, PbE has been used during the development of four case studies: a smart metering application; a people counting and monitoring application; an energy efficiency monitoring system; and a two factor authentication system. For these applications, the teams were able to provide seven, five, five, and four evidences of privacy, respectively, and we conclude that PbE can be effective in helping to understand and address the privacy protection needs when developing software. (C) 2019 Elsevier Inc. All rights reserved.
引用
收藏
页码:294 / 310
页数:17
相关论文
共 50 条
  • [1] Speranza: Usable, privacy-friendly software signing
    Merrill, Kelsey
    Newman, Zachary
    Torres-Arias, Santiago
    Sollins, Karen R.
    PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023, 2023, : 3388 - 3402
  • [2] An Embedded Platform for Privacy-Friendly Road Charging Applications
    Balasch, Josep
    Verbauwhede, Ingrid
    Preneel, Bart
    2010 DESIGN, AUTOMATION & TEST IN EUROPE (DATE 2010), 2010, : 867 - 872
  • [3] Privacy-Friendly Smart Environments
    Armac, Ibrahim
    Panchenko, Andriy
    Pettau, Marcel
    Retkowitz, Daniel
    THIRD INTERNATIONAL CONFERENCE ON NEXT GENERATION MOBILE APPLICATIONS, SERVICES, AND TECHNOLOGIES, PROCEEDINGS, 2009, : 425 - 431
  • [4] Privacy-Friendly Identity Management in eGovernment
    Huysmans, Xavier
    FUTURE OF IDENTITY IN THE INFORMATION SOCIETY, 2008, : 245 - 258
  • [5] Privacy-Friendly Delivery Plan Recommender
    Jaha, Albana
    Jaha, Dardana
    Pincay, Jhonny
    Teran, Luis
    Portmann, Edy
    2021 EIGHT INTERNATIONAL CONFERENCE ON EDEMOCRACY & EGOVERNMENT (ICEDEG), 2021, : 146 - 151
  • [6] Privacy-Friendly and Trustworthy Technology for Society
    Anton Fedosov
    Aurelia Tamò-Larrieux
    Christoph Lutz
    Eduard Fosch-Villaronga
    Anto Čartolovni
    Digital Society, 2025, 4 (1):
  • [7] Towards Privacy-Friendly Smart Products
    Garcia, Kimberly
    Zihlmann, Zaira
    Mayer, Simon
    Tamo-Larrieux, Aurelia
    Hooss, Johannes
    2021 18TH INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2021,
  • [8] Privacy-Friendly Incentives and Their Application to Wikipedia
    Camenisch, Jan
    Gross, Thomas
    Hladky, Peter
    Hoertnagl, Christian
    POLICIES AND RESEARCH IN IDENTITY MANAGEMENT, 2010, 343 : 113 - +
  • [9] An Advanced, Privacy-Friendly Loyalty System
    Milutinovic, Milica
    Dacosta, Italo
    Put, Andreas
    De Decker, Bart
    PRIVACY AND IDENTITY MANAGEMENT FOR EMERGING SERVICES AND TECHNOLOGIES, 2014, 421 : 128 - 138
  • [10] BioID: A Privacy-Friendly Identity Document
    Balli, Fatih
    Durak, F. Betul
    Vaudenay, Serge
    SECURITY AND TRUST MANAGEMENT, STM 2019, 2019, 11738 : 53 - 70