@inproceedings{9c5748d54b4f41a18bd6e022b4a20580,
title = "Identifying privacy risks in distributed data services: A model-driven approach",
abstract = "Online services are becoming increasingly data-centric; they collect, process, analyze and anonymously disclose growing amounts of personal data. It is crucial that such systems are engineered in a privacy-aware manner in order to satisfy both the privacy requirements of the user, and the legal privacy regulations that the system operates under. How can system developers be better supported to create privacy-aware systems and help them to understand and identify privacy risks? Model-Driven Engineering (MDE) offers a principled approach to engineer systems software. The capture of shared domain knowledge in models and corresponding tool support can increase the developers' understanding. In this paper, we argue for the application of MDE approaches to engineer privacy-aware systems. We present a general purpose privacy model and methodology that can be used to analyse and identify privacy risks in systems that comprise both access control and data pseudonymization enforcement technologies. We evaluate this method using a case-study based approach and show how the model can be applied to engineer privacy-aware systems and privacy policies that reduce the risk of unintended disclosure.",
keywords = "Cloud, Model-driven engineering, Privacy, Risk",
author = "Paul Grace and Daniel Burns and Geoffrey Neumann and Brian Pickering and Panos Melas and Mike Surridge",
note = "{\textcopyright} 2018 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works. ; 38th IEEE International Conference on Distributed Computing Systems, ICDCS 2018 ; Conference date: 02-07-2018 Through 05-07-2018",
year = "2018",
month = jul,
day = "23",
doi = "10.1109/ICDCS.2018.00157",
language = "English",
isbn = "978-1-5386-6872-6",
series = "Proceedings - International Conference on Distributed Computing Systems",
publisher = "IEEE",
pages = "1513--1518",
booktitle = "Proceedings - 2018 IEEE 38th International Conference on Distributed Computing Systems, ICDCS 2018",
address = "United States",
}