Endre søk
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • apa.csl
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Engineering privacy by design: Lessons from the design and implementation of an identity wallet platform
Capgemini Germany, DEU.
Goethe University Frankfurt, DEU.
Karlstads universitet, Fakulteten för hälsa, natur- och teknikvetenskap (from 2013), Institutionen för matematik och datavetenskap (from 2013).ORCID-id: 0000-0001-6459-8409
Goethe University Frankfurt, DEU.
2019 (engelsk)Inngår i: Proceedings of the ACM Symposium on Applied Computing, Association for Computing Machinery (ACM), 2019, s. 1475-1483Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

Applying PbD principles to the design of a system is challenging. We provided our experience and lessons learnt from applying the LINDDUN as a privacy assessment framework in the design of the architecture for a cloud-based identity wallet platform. In this effort, we identified a need to improve LINDDUN in a number of cases, for which we proposed and documented concrete enhancements. We transform LINDDUN from a linear to an iterative process that requires adaptation, introduce the concept of “Constraints” and add a new step in the mitigation of threats. Further, we consider the mitigation strategies of LINDDUN too narrow, and propose other, more practicable ones. Finally, we not only identify further PETs for mitigating privacy threats, but also acknowledge the fact that some threats cannot be effectively mitigated with PETs alone. Thus, we introduce additional mitigation mechanisms besides PETs, introducing especially development guidelines and organizational measures. We demonstrate our enhancements with concrete examples, which could serve also other engineering projects following the PbD paradigm.

sted, utgiver, år, opplag, sider
Association for Computing Machinery (ACM), 2019. s. 1475-1483
Emneord [en]
Data flow diagram, Identity wallet, LINDDUN, Mitigation of risks, PbD, Privacy by design, Privacy risks, Privacy threat modelling, Concretes, Data flow analysis, Data flow graphs, Mathematical transformations, Data flow diagrams, Privacy threats, Risk assessment
HSV kategori
Forskningsprogram
Datavetenskap
Identifikatorer
URN: urn:nbn:se:kau:diva-72516DOI: 10.1145/3297280.3297429ISI: 000474685800206Scopus ID: 2-s2.0-85065644021ISBN: 978-1-4503-5933-7 (digital)OAI: oai:DiVA.org:kau-72516DiVA, id: diva2:1324219
Konferanse
34th Annual ACM Symposium on Applied Computing, SAC 2019, 8 April 2019 through 12 April 2019
Tilgjengelig fra: 2019-06-13 Laget: 2019-06-13 Sist oppdatert: 2020-12-10bibliografisk kontrollert

Open Access i DiVA

Fulltekst mangler i DiVA

Andre lenker

Forlagets fulltekstScopus

Person

Pulls, Tobias

Søk i DiVA

Av forfatter/redaktør
Pulls, Tobias
Av organisasjonen

Søk utenfor DiVA

GoogleGoogle Scholar

doi
isbn
urn-nbn

Altmetric

doi
isbn
urn-nbn
Totalt: 343 treff
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • apa.csl
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf