Model-Based Privacy Analysis in Industrial Ecosystems

被引:12
|
作者
Ahmadian, Amir Shayan [1 ]
Strueber, Daniel [1 ]
Riediger, Volker [1 ]
Juerjens, Jan [1 ,2 ]
机构
[1] Univ Koblenz Landau, Inst Software Technol, Koblenz, Germany
[2] Fraunhofer Inst Software & Syst Engn ISST, Dortmund, Germany
基金
欧盟地平线“2020”;
关键词
REQUIREMENTS;
D O I
10.1007/978-3-319-61482-3_13
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Article 25 of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing and the free movement of personal data, refers to data protection by design and by default. Privacy and data protection by design implies that IT systems need to be adapted or focused to technically support privacy and data protection. To this end, we need to verify whether security and privacy are supported by a system, or any change in the design of the system is required. In this paper, we provide a model-based privacy analysis approach to analyze IT systems that provide IT services to service customers. An IT service may rely on different enterprises to process the data that is provided by service customers. Therefore, our approach is modular in the sense that it analyzes the system design of each enterprise individually. The approach is based on the four privacy fundamental elements, namely purpose, visibility, granularity, and retention. We present an implementation of the approach based on the CARiSMA tool. To evaluate our approach, we apply it to an industrial case study.
引用
收藏
页码:215 / 231
页数:17
相关论文
共 50 条
  • [1] Extending Model-Based Privacy Analysis for the Industrial Data Space by Exploiting Privacy Level Agreements
    Ahmadian, Amir Shayan
    Juerjens, Jan
    Strueber, Daniel
    [J]. 33RD ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, 2018, : 1142 - 1149
  • [2] Supporting Privacy Impact Assessment by Model-Based Privacy Analysis
    Ahmadian, Amir Shayan
    Strueber, Daniel
    Riediger, Volker
    Juerjens, Jan
    [J]. 33RD ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, 2018, : 1467 - 1474
  • [3] Model-Based Privacy and Security Analysis with CARiSMA
    Ahmadian, Amir Shayan
    Peldszus, Sven
    Ramadan, Qusai
    Juerjens, Jan
    [J]. ESEC/FSE 2017: PROCEEDINGS OF THE 2017 11TH JOINT MEETING ON FOUNDATIONS OF SOFTWARE ENGINEERING, 2017, : 989 - 993
  • [4] A model-based analysis of tunability in privacy services
    Lundin, Reine
    Lindskog, Stefan
    Brunstrom, Anna
    [J]. FUTURE OF IDENTITY IN THE INFORMATION SOCIETY, 2008, : 343 - 356
  • [5] Supporting Model-based Privacy Analysis by Exploiting Privacy Level Agreements
    Ahmadian, Amir Shayan
    Juerjens, Jan
    [J]. 2016 8TH IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM 2016), 2016, : 360 - 365
  • [6] A Model-Based Privacy Compliance Checker
    Pearson, Siani
    Allison, Damien
    [J]. INTERNATIONAL JOURNAL OF E-BUSINESS RESEARCH, 2009, 5 (02) : 63 - 83
  • [7] Robustness analysis of privacy-preserving model-based recommendation schemes
    Bilge, Alper
    Gunes, Ihsan
    Polat, Huseyin
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2014, 41 (08) : 3671 - 3681
  • [8] MODEL-BASED CONTROL OF INDUSTRIAL MANIPULATORS - AN EXPERIMENTAL-ANALYSIS
    LEAHY, MB
    [J]. JOURNAL OF ROBOTIC SYSTEMS, 1990, 7 (05): : 741 - 758
  • [9] Model-based Electrical Energy Analysis of Industrial Automation Systems
    Beck, A.
    Jazdi, N.
    [J]. PROCEEDINGS OF 2010 IEEE INTERNATIONAL CONFERENCE ON AUTOMATION, QUALITY AND TESTING, ROBOTICS (AQTR 2010), VOLS. 1-3, 2010,
  • [10] Robustness analysis of industrial emergency plans: a model-based methodology
    Karagiannis, G. M.
    Piatyszek, E.
    Flaus, J. M.
    [J]. RISK ANALYSIS VII: SIMULATION AND HAZARD MITIGATION & BROWNFIELDS V: PREVENTION, ASSESSMENT, REHABILITATION AND DEVELOPMENT OF BROWNFIELD SITES, 2010, : PI93 - PI104