Privacy by Evidence: A Methodology to develop privacy-friendly software applications

被引:4
|
作者
Barbosa, Pedro [1 ]
Brito, Andrey [1 ]
Almeida, Hyggo [1 ]
机构
[1] Univ Fed Campina Grande, Comp & Syst Dept, Campina Grande, Paraiba, Brazil
关键词
Methodology; Process risk; Privacy-enhancing technologies;
D O I
10.1016/j.ins.2019.09.040
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In an increasingly connected world, a diversity of data is collected from the environment and its inhabitants. Because of the richness of the information, privacy becomes an important requirement. Although there are principles and rules, there is still a lack of methodologies to guide the integration of privacy guidelines into the development process. Methodologies like the Privacy by Design (PbD) are still vague and leave many open questions on how to apply them in practice. In this work we propose a new concept, called Privacy by Evidence (PbE), in the form of a software development methodology to provide privacy-awareness. Given the difficulty in providing total privacy in many applications, we propose to document the mitigations in form of evidences of privacy, aiming to increase the confidence of the project. To validate its effectiveness, PbE has been used during the development of four case studies: a smart metering application; a people counting and monitoring application; an energy efficiency monitoring system; and a two factor authentication system. For these applications, the teams were able to provide seven, five, five, and four evidences of privacy, respectively, and we conclude that PbE can be effective in helping to understand and address the privacy protection needs when developing software. (C) 2019 Elsevier Inc. All rights reserved.
引用
收藏
页码:294 / 310
页数:17
相关论文
共 50 条
  • [21] Cell-based privacy-friendly roadpricing
    Garcia, Flavio D.
    Verheul, Eric R.
    Jacobs, Bart
    COMPUTERS & MATHEMATICS WITH APPLICATIONS, 2013, 65 (05) : 774 - 785
  • [22] File Fragmentation in the Wild: a Privacy-Friendly Approach
    van der Meer, Vincent
    Jonker, Hugo
    Dols, Guy
    van Beek, Harm
    van den Bos, Jeroen
    van Eekelen, Marko
    2019 IEEE INTERNATIONAL WORKSHOP ON INFORMATION FORENSICS AND SECURITY (WIFS), 2019,
  • [23] PACCo: Privacy-friendly Access Control with Context
    Put, Andreas
    De Decker, Bart
    SECRYPT: PROCEEDINGS OF THE 13TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS - VOL. 4, 2016, : 159 - 170
  • [24] Privacy-friendly Photo Capturing and Sharing System
    Zhang, Lan
    Liu, Kebin
    Li, Xiang-Yang
    Liu, Cihang
    Ding, Xuan
    Liu, Yunhao
    UBICOMP'16: PROCEEDINGS OF THE 2016 ACM INTERNATIONAL JOINT CONFERENCE ON PERVASIVE AND UBIQUITOUS COMPUTING, 2016, : 524 - 534
  • [25] Privacy-friendly machine learning - Part 2: Privacy attacks and privacy-preserving machine learning
    Stock J.
    Petersen T.
    Behrendt C.-A.
    Federrath H.
    Kreutzburg T.
    Informatik Spektrum, 2022, 45 (3) : 137 - 145
  • [26] Ethical aspects in eHealth - design of a privacy-friendly system
    Milutinovic, Milica
    De Decker, Bart
    JOURNAL OF INFORMATION COMMUNICATION & ETHICS IN SOCIETY, 2016, 14 (01): : 49 - 69
  • [27] Privacy-Friendly Decentralized Data Aggregation For Mobile Crowdsensing
    Wang, Xudong
    Ying, Chenhao
    Luo, Yuan
    2020 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2020,
  • [28] Privacy-friendly Blockchain based Data Trading and Tracking
    Wu, Zhenan
    Zheng, Han
    Zhang, Lan
    Li, Xiang-Yang
    5TH INTERNATIONAL CONFERENCE ON BIG DATA COMPUTING AND COMMUNICATIONS (BIGCOM 2019), 2019, : 240 - 244
  • [29] Privacy-Friendly Appliance Load Scheduling in Smart Grids
    Rottondi, Cristina
    Verticale, Giacomo
    2013 IEEE INTERNATIONAL CONFERENCE ON SMART GRID COMMUNICATIONS (SMARTGRIDCOMM), 2013, : 420 - 425
  • [30] Privacy-Friendly Electronic Traffic Pricing via Commits
    de Jonge, Wiebren
    Jacobs, Bart
    FORMAL ASPECTS IN SECURITY AND TRUST, 2009, 5491 : 143 - +