Privacy by Evidence: A Methodology to develop privacy-friendly software applications

被引:4
|
作者
Barbosa, Pedro [1 ]
Brito, Andrey [1 ]
Almeida, Hyggo [1 ]
机构
[1] Univ Fed Campina Grande, Comp & Syst Dept, Campina Grande, Paraiba, Brazil
关键词
Methodology; Process risk; Privacy-enhancing technologies;
D O I
10.1016/j.ins.2019.09.040
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In an increasingly connected world, a diversity of data is collected from the environment and its inhabitants. Because of the richness of the information, privacy becomes an important requirement. Although there are principles and rules, there is still a lack of methodologies to guide the integration of privacy guidelines into the development process. Methodologies like the Privacy by Design (PbD) are still vague and leave many open questions on how to apply them in practice. In this work we propose a new concept, called Privacy by Evidence (PbE), in the form of a software development methodology to provide privacy-awareness. Given the difficulty in providing total privacy in many applications, we propose to document the mitigations in form of evidences of privacy, aiming to increase the confidence of the project. To validate its effectiveness, PbE has been used during the development of four case studies: a smart metering application; a people counting and monitoring application; an energy efficiency monitoring system; and a two factor authentication system. For these applications, the teams were able to provide seven, five, five, and four evidences of privacy, respectively, and we conclude that PbE can be effective in helping to understand and address the privacy protection needs when developing software. (C) 2019 Elsevier Inc. All rights reserved.
引用
收藏
页码:294 / 310
页数:17
相关论文
共 50 条
  • [31] Secure and Privacy-Friendly Public Key Generation and Certification
    Borges, Fabio
    Martucci, Leonardo A.
    Beato, Filipe
    Muehlhaeuser, Max
    2014 IEEE 13TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM), 2014, : 114 - 121
  • [32] PRISM: Privacy-friendly Routing In Suspicious MANETs (and VANETs)
    El Defrawy, Karim
    Tsudik, Gene
    16TH IEEE INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS: ICNP'08, 2008, : 258 - 267
  • [33] Privacy-friendly synchronized ultralightweight authentication protocols in the storm
    Avoine, Gildas
    Carpent, Xavier
    Martin, Benjamin
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2012, 35 (02) : 826 - 843
  • [34] PriMSED - Privacy-Friendly Measurement of Smart Entertainment Devices
    Ghiglieri, Marco
    2015 12TH ANNUAL IEEE CONSUMER COMMUNICATIONS AND NETWORKING CONFERENCE, 2015, : 65 - 70
  • [35] Practical Group-Signatures with Privacy-Friendly Openings
    Krenn, Stephan
    Samelin, Kai
    Striecks, Christoph
    14TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2019), 2019,
  • [36] Secure and Privacy-Friendly Storage and Data Processing in the Cloud
    Chiaro, Pasquale
    Fischer-Hubner, Simone
    Gross, Thomas
    Krenn, Stephan
    Loruenser, Thomas
    Martinez Garci, Ana Isabel
    Migliavacca, Andrea
    Rannenberg, Kai
    Slamanig, Daniel
    Striecks, Christoph
    Zanini, Alberto
    PRIVACY AND IDENTITY MANAGEMENT: THE SMART REVOLUTION, 2018, 526 : 153 - 169
  • [37] An SDN Architecture for Privacy-Friendly Network-Assisted DASH
    Kleinrouweler, Jan Willem
    Cabrero, Sergio
    Cesar, Pablo
    ACM TRANSACTIONS ON MULTIMEDIA COMPUTING COMMUNICATIONS AND APPLICATIONS, 2017, 13 (03)
  • [38] Privacy-Friendly Energy-Metering via Homomorphic Encryption
    Garcia, Flavio D.
    Jacobs, Bart
    SECURITY AND TRUST MANAGEMENT, 2011, 6710 : 226 - 238
  • [39] A Decisional Attack to Privacy-friendly Data Aggregation in Smart Grids
    Rottondi, Cristina
    Savi, Marco
    Polenghi, Daniele
    Verticale, Giacomo
    Krauss, Christoph
    2013 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2013, : 2616 - 2621
  • [40] Privacy-friendly Distributed Algorithm for Energy Management in Smart Grids
    Brettschneider, Daniel
    Scheerhorn, Alfred
    Hoelker, Daniel
    Roer, Peter
    Toenjes, Ralf
    2015 INTERNATIONAL CONFERENCE ON NETWORKED SYSTEMS (NETSYS), 2015,