Privacy by Evidence: A Methodology to develop privacy-friendly software applications

被引:4
|
作者
Barbosa, Pedro [1 ]
Brito, Andrey [1 ]
Almeida, Hyggo [1 ]
机构
[1] Univ Fed Campina Grande, Comp & Syst Dept, Campina Grande, Paraiba, Brazil
关键词
Methodology; Process risk; Privacy-enhancing technologies;
D O I
10.1016/j.ins.2019.09.040
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In an increasingly connected world, a diversity of data is collected from the environment and its inhabitants. Because of the richness of the information, privacy becomes an important requirement. Although there are principles and rules, there is still a lack of methodologies to guide the integration of privacy guidelines into the development process. Methodologies like the Privacy by Design (PbD) are still vague and leave many open questions on how to apply them in practice. In this work we propose a new concept, called Privacy by Evidence (PbE), in the form of a software development methodology to provide privacy-awareness. Given the difficulty in providing total privacy in many applications, we propose to document the mitigations in form of evidences of privacy, aiming to increase the confidence of the project. To validate its effectiveness, PbE has been used during the development of four case studies: a smart metering application; a people counting and monitoring application; an energy efficiency monitoring system; and a two factor authentication system. For these applications, the teams were able to provide seven, five, five, and four evidences of privacy, respectively, and we conclude that PbE can be effective in helping to understand and address the privacy protection needs when developing software. (C) 2019 Elsevier Inc. All rights reserved.
引用
收藏
页码:294 / 310
页数:17
相关论文
共 50 条
  • [41] Finding Similar Mobile Consumers with a Privacy-Friendly Geosocial Design
    Provost, Foster
    Martens, David
    Murray, Alan
    INFORMATION SYSTEMS RESEARCH, 2015, 26 (02) : 243 - 265
  • [42] A Blockchain-based Privacy-friendly Renewable Energy Community
    Cejka, Stephan
    Zeilinger, Franz
    Veseli, Argjenta
    Holzleitner, Marie-Theres
    Stefan, Mark
    PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON SMART CITIES AND GREEN ICT SYSTEMS (SMARTGREENS), 2020, : 95 - 103
  • [43] Designing privacy-friendly digital whiteboards for mediation of clinical progress
    Gjaere, Erlend Andreas
    Lillebo, Borge
    BMC MEDICAL INFORMATICS AND DECISION MAKING, 2014, 14
  • [44] Combining personalised communications services with privacy-friendly identity management
    Dumortier, J
    JOURNAL OF THE COMMUNICATIONS NETWORK, 2005, 4 : 142 - 146
  • [45] Efficient, Verifiable, Secure, and Privacy-Friendly Computations for the Smart Grid
    Borges, Fabio
    Volk, Florian
    Muehlhaeuser, Max
    2015 IEEE POWER & ENERGY SOCIETY INNOVATIVE SMART GRID TECHNOLOGIES CONFERENCE (ISGT), 2015,
  • [46] ORGs for scalable, robust, privacy-friendly client cloud computing
    Hewitt, Carl
    IEEE INTERNET COMPUTING, 2008, 12 (05) : 96 - 99
  • [47] Privacy-Friendly Cloud Audits with Somewhat Homomorphic and Searchable Encryption
    Lopez, Jose M.
    Ruebsamen, Thomas
    Westhoff, Dirk
    2014 14TH INTERNATIONAL CONFERENCE ON INNOVATIONS FOR COMMUNITY SERVICES (I4CS), 2014, : 95 - 103
  • [48] Privacy-Friendly Mobility Analytics using Aggregate Location Data
    Pyrgelis, Apostolos
    De Cristofaro, Emiliano
    Ross, Gordon J.
    24TH ACM SIGSPATIAL INTERNATIONAL CONFERENCE ON ADVANCES IN GEOGRAPHIC INFORMATION SYSTEMS (ACM SIGSPATIAL GIS 2016), 2016,
  • [49] Privacy-Friendly Datasets of Synthetic Fingerprints for Evaluation of Biometric Algorithms
    Makrushin, Andrey
    Mannam, Venkata Srinath
    Dittmann, Jana
    APPLIED SCIENCES-BASEL, 2023, 13 (18):
  • [50] Efficient, Verifiable, Secure, and Privacy-Friendly Computations for the Smart Grid
    Borges, Fabio
    Volk, Florian
    Muhlhauser, Max
    2015 IEEE POWER & ENERGY SOCIETY INNOVATIVE SMART GRID TECHNOLOGIES CONFERENCE (ISGT), 2015,