首页> 外文期刊>Transforming Government: People, Process and Policy >Protecting privacy in system design: the electronic voting case
【24h】

Protecting privacy in system design: the electronic voting case

机译:在系统设计中保护隐私:电子投票箱

获取原文
获取原文并翻译 | 示例
       

摘要

Purpose – The purpose of the paper is to present Privacy Safeguard (PriS) a formal security requirements engineering methodology which, incorporates privacy requirements in the system design process and to demonstrate its applicability in an e-voting case. Design/methodology/approach – PriS provides a methodological framework for addressing privacy-related issues during system development. It provides a set of concepts for formally expressing privacy requirements (authentication, authorisation, identification, data protection, anonymity, pseudonymity, unlinkability and unobservability) and a systematic way-of-working for translating these requirements into system models. The main activities of the PriS way-of-working are: elicit privacy-related goals, analyse the impact of privacy goals on processes, model affected processes using privacy process patterns and identify the technique(s) that best support/implement the above-process patterns. Findings – Analysis of a number of well known privacy-enhancing technologies, as well as of existing security requirement engineering methodologies, pinpoints the gap between system design methodologies and technological solutions. To this end, PriS provides an integrated approach for matching privacy-related requirements to proper implementation techniques. Experimentation with the e-voting case suggests that PriS has a high degree of applicability on internet systems that wish to provide services that ensure users privacy, such as anonymous browsing, untraceable transactions, etc. Originality/value – The paper proposes a new methodology for addressing privacy requirements during the design process. Instead of prescribing a single solution, PriS guides developers to choose the most appropriate implementation techniques for realizing the identified privacy issues. In addition, due to its formal definition it facilitates control of the accuracy and precision of the results and enables the development of automated tools for assisting its application.
机译:目的–本文的目的是为隐私保护(PriS)提供一种正式的安全需求工程方法,该方法将隐私需求纳入系统设计过程中,并展示其在电子投票案例中的适用性。设计/方法/方法– PriS提供了一种方法框架,用于解决系统开发过程中与隐私相关的问题。它提供了一组概念,用于正式表达隐私要求(身份验证,授权,标识,数据保护,匿名性,假名,不可链接性和不可观察性),以及将这些要求转换为系统模型的系统工作方式。 PriS工作方式的主要活动是:得出与隐私相关的目标,分析隐私目标对流程的影响,使用隐私流程模式对受影响的流程进行建模,并确定最能支持/实现上述目的的技术-过程模式。调查结果–分析许多众所周知的增强隐私的技术以及现有的安全需求工程方法论,以找出系统设计方法论与技术解决方案之间的差距。为此,PriS提供了一种集成方法,可将与隐私相关的要求与适当的实施技术相匹配。对电子投票案例的实验表明,PriS在希望提供可确保用户隐私的服务的Internet系统上具有高度适用性,例如匿名浏览,无法追踪的交易等。原创性/价值–本文提出了一种新的方法来在设计过程中解决隐私要求。 PriS无需制定单一解决方案,而是指导开发人员选择最合适的实施技术来实现已识别的隐私问题。此外,由于其形式上的定义,它有助于控制结果的准确性和精确度,并能够开发用于辅助其应用的自动化工具。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号