RSL-IL4Privacy: a domain-specific language for the rigorous specification of privacy policies

被引:0
|
作者
João Caramujo
Alberto Rodrigues da Silva
Shaghayegh Monfared
André Ribeiro
Pável Calado
Travis Breaux
机构
[1] Universidade de Lisboa,INESC
[2] Carnegie Mellon University,ID, Instituto Superior Técnico
来源
Requirements Engineering | 2019年 / 24卷
关键词
Privacy policy; Privacy requirement; Domain-specific language; RSL-IL4Privacy; Eddy;
D O I
暂无
中图分类号
学科分类号
摘要
Mobile and web applications that manage users’ personal information require developers to align their software design with privacy requirements commonly described in privacy policies. These policies are often the sole means to enforce accountability on that data protection. We propose the RSL-IL4Privacy, a domain-specific language for specifying privacy policies that can be simultaneously manipulated by computers and authored and analyzed by humans. In addition, RSL-IL4Privacy can be used as an intermediate language to support model-to-model transformations from and into other related languages. RSL-IL4Privacy provides policy authors with means to define a privacy policy as a set of declarative statements with explicit relationships to services, data recipients, private data types and enforcement mechanisms. The RSL-IL4Privacy is defined with different technologies for supporting distinct levels of formality, namely support for multiple modes of presenting privacy requirements, including tabular, graphical and textual representations, to increase integration with a wider variety of authoring and analyzing practices. We apply this language to support the analysis and comparison of policies from Facebook, LinkedIn, Twitter, Dropbox and IMDb. We discuss with further detail the application of this approach to the Twitter policy by presenting several examples with multiple representations. Finally, we discuss how RSL-IL4Privacy can improve the quality of privacy policies and also identifies threats to validity.
引用
收藏
页码:1 / 26
页数:25
相关论文
共 26 条
  • [1] RSL-IL4Privacy: a domain-specific language for the rigorous specification of privacy policies
    Caramujo, Joao
    da Silva, Alberto Rodrigues
    Monfared, Shaghayegh
    Ribeiro, Andre
    Calado, Pavel
    Breaux, Travis
    [J]. REQUIREMENTS ENGINEERING, 2019, 24 (01) : 1 - 26
  • [2] A domain-specific language for the specification of UCON policies
    Reina Quintero, Antonia M.
    Martinez Perez, Salvador
    Jesus Varela-Vaca, Angel
    Gomez Lopez, Maria Teresa
    Cabot, Jordi
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 64
  • [3] Is the Privacy Paradox a Domain-Specific Phenomenon
    Hirschprung, Ron S.
    [J]. COMPUTERS, 2023, 12 (08)
  • [4] Specification and Refinement of Domain-Specific ECA Policies
    Romeikat, Raphael
    Bauer, Bernhard
    [J]. ADVANCED INFORMATION SYSTEMS ENGINEERING WORKSHOPS, 2011, 83 : 197 - 206
  • [5] Improving the Specification and Analysis of Privacy Policies The RSLingo4Privacy Approach
    da Silva, Alberto Rodrigues
    Caramujo, Joao
    Monfared, Shaghayegh
    Calado, Pavel
    Breaux, Travis
    [J]. PROCEEDINGS OF THE 18TH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS, VOL 1 (ICEIS), 2016, : 336 - 347
  • [6] RSLingo4Privacy Studio A Tool to Improve the Specification and Analysis of Privacy Policies
    Ribeiro, Andre
    da Silva, Alberto Rodrigues
    [J]. ICEIS: PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS - VOL 2, 2017, : 52 - 63
  • [7] HAPI: A domain-specific language for the declaration of access policies
    Ramos, Vinicius Juliao
    Holmquist, Alexander
    Pereira, Fernando Magno Quintao
    [J]. JOURNAL OF COMPUTER LANGUAGES, 2022, 72
  • [8] Enforcing Exception Handling Policies with a Domain-Specific Language
    Barbosa, Eiji Adachi
    Garcia, Alessandro
    Robillard, Martin P.
    Jakobus, Benjamin
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2016, 42 (06) : 559 - 584
  • [9] Hapi: A Domain-Specific Language for the Declaration of Access Policies
    Juliao, Vinicius
    Holmquist, Alexander
    Correa Junior, Flavio Lucio
    Oliveira Santos, Celso Junio S.
    Quintao Pereira, Fernando M.
    [J]. 25TH BRAZILIAN SYMPOSIUM ON PROGRAMMING LANGUAGES, SBLP 2021, 2021, : 9 - 16
  • [10] A Domain-Specific Language for the Specification of Gesture-based Applications
    Viana, Daniel Leite
    de Medeiros Santos, Andre Luis
    [J]. PROCEEDINGS OF THE 21ST BRAZILIAN SYMPOSIUM ON PROGRAMMING LANGUAGES (SBLP 2017), 2017,