Incorporating privacy requirements into the system design process - The PriS conceptual framework

被引:13
|
作者
Kavakli, Evangelia
Kalloniatis, Christos [1 ]
Loucopoulos, Pericles
Gritzalis, Stefanos
机构
[1] Univ Aegean, Dept Cultural Technol & Commun, Mitilini, Greece
[2] Univ Manchester, Sch Informat, Manchester, Lancs, England
[3] Univ Aegean, Dept Informat & Commun Syst Engn, Samos, Greece
关键词
privacy; systems software;
D O I
10.1108/10662240610656483
中图分类号
F [经济];
学科分类号
02 ;
摘要
Purpose - To present a new methodology for incorporating privacy requirements into the system design process called PriS, and describe its applicability in the e-VOTE system for presenting methodology's way-of-working. Design/methodology/approach - PriS is a requirement engineering methodology focused on privacy issues. It provides a set of concepts for modelling privacy requirements (anonymity, pseudonymity, unlinkability and unobservability) in the organisation domain and a systematic way-of-working for translating these requirements into system models. The conceptual model used in PriS is based on the Enterprise Knowledge Development (EKD) framework. PriS models privacy requirements as a special type of goal. Findings - Based on the analysis of a number of well-known privacy-enhancing technologies as well as of existing security requirement engineering methodologies, this paper pinpoints the gap between system design methodologies and technological solutions. To this end, PriS is suggested, with a view to providing a methodological framework for matching privacy-related requirements with the proper implementation techniques. Originality/value - This paper proposes a new methodology for addressing privacy requirements during the design process. It guides developers to choose the most appropriate implementation techniques for realising the identified privacy issues. PriS methodology has a high degree of applicability on Internet systems that wish to provide services that ensure users privacy, such as anonymous browsing, untraceable transactions, etc.
引用
收藏
页码:140 / 158
页数:19
相关论文
共 50 条
  • [41] A Privacy-Aware Conceptual Framework for Coordination
    Elahi, Haroon
    Wang, Guojun
    Zhang, Wei
    2017 15TH IEEE INTERNATIONAL SYMPOSIUM ON PARALLEL AND DISTRIBUTED PROCESSING WITH APPLICATIONS AND 2017 16TH IEEE INTERNATIONAL CONFERENCE ON UBIQUITOUS COMPUTING AND COMMUNICATIONS (ISPA/IUCC 2017), 2017, : 190 - 197
  • [42] Company information privacy orientation: a conceptual framework
    Greenaway, Kathleen E.
    Chan, Yolande E.
    Crossler, Robert E.
    INFORMATION SYSTEMS JOURNAL, 2015, 25 (06) : 579 - 606
  • [43] A Framework for Privacy and Security Requirements Analysis and Conflict Resolution for Supporting GDPR Compliance Through Privacy-by-Design
    Alkubaisy, Duaa
    Piras, Luca
    Al-Obeidallah, Mohammed Ghazi
    Cox, Karl
    Mouratidis, Haralambos
    EVALUATION OF NOVEL APPROACHES TO SOFTWARE ENGINEERING (ENASE 2021), 2022, 1556 : 67 - 87
  • [44] Framework for Requirements-Driven system Design Automation
    Cardei, Ionut
    Fonoage, Mihai
    Shankar, Ravi
    2007 1ST ANNUAL IEEE SYSTEMS CONFERENCE, 2007, : 211 - +
  • [45] Incorporating sustainability into software projects: a conceptual framework
    Khalifeh, Amin
    Farrell, Peter
    Alrousan, Mohammad
    Alwardat, Shaima
    Faisal, Masar
    INTERNATIONAL JOURNAL OF MANAGING PROJECTS IN BUSINESS, 2020, 13 (06) : 1339 - 1361
  • [46] Dealing with privacy issues during the system design process
    Kalloniatis, C
    Kavakli, E
    Gritzalis, S
    2005 IEEE International Symposium on Signal Processing and Information Technology (ISSPIT), Vols 1 and 2, 2005, : 546 - 551
  • [47] A CONCEPTUAL PRIVACY FRAMEWORK FOR PRIVACY-AWARE IOT HEALTH APPLICATIONS
    Thinakaran, Kavenesh
    Dhillon, Jaspaljeet Singh
    Gunasekaran, Saraswathy Shamini
    Chen, Lim Fung
    PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON COMPUTING AND INFORMATICS: EMBRACING ECO-FRIENDLY COMPUTING, 2017, : 175 - 183
  • [48] Shield privacy: A conceptual framework for information privacy and data access controls
    Centre for Extended Enterprises and Business Intelligence, Curtin University of Technology, Perth, WA, Australia
    WSEAS Trans. Comput., 2006, 6 (1375-1382):
  • [49] Experiences in the Development and Usage of a Privacy Requirements Framework
    Oliver, Ian
    2016 IEEE 24TH INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE), 2016, : 293 - 302
  • [50] User requirements and conceptual design of the ITER Electron Cyclotron Control System
    Carannante, Giuseppe
    Cavinato, Mario
    Gandini, Franco
    Granucci, Gustavo
    Henderson, Mark
    Purohit, Dharmesh
    Saibene, Gabriella
    Sartori, Filippo
    Sozzi, Carlo
    FUSION ENGINEERING AND DESIGN, 2015, 96-97 : 420 - 424