A UML Profile for Privacy Enforcement

被引:4
作者
Canovas Izquierdo, Javier Luis [1 ]
Salas, Julian [1 ]
机构
[1] Univ Oberta Catalunya UOC, Internet Interdisciplinary Inst IN3, Barcelona, Spain
来源
SOFTWARE TECHNOLOGIES: APPLICATIONS AND FOUNDATIONS | 2018年 / 11176卷
关键词
UML; UML-profile; Privacy;
D O I
10.1007/978-3-030-04771-9_46
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Nowadays most software applications have to deal with personal data, specially with the emergence of Web-based applications, where user profile information has become one of their main assets. Due to regulation laws and to protect the privacy of users, customers and companies; most of this information is considered private, and therefore convenient ways to gather, process and store them have to be proposed. A common problem when modeling software systems is the lack of support to specify how to enforce privacy concerns in data models. Current approaches for modeling privacy cover high-level privacy aspects to describe what should be done with the data (e.g., elements to be private) instead of how to do it (e.g., which privacy enhancing technology to use); or propose access control policies, which may cover privacy only partially. In this paper we propose a profile to define and enforce privacy concerns in UML class diagrams. Models annotated with our profile can be used in model-driven methodologies to generate privacy-aware applications.
引用
收藏
页码:609 / 616
页数:8
相关论文
共 17 条
[1]   Model-Based Privacy and Security Analysis with CARiSMA [J].
Ahmadian, Amir Shayan ;
Peldszus, Sven ;
Ramadan, Qusai ;
Juerjens, Jan .
ESEC/FSE 2017: PROCEEDINGS OF THE 2017 11TH JOINT MEETING ON FOUNDATIONS OF SOFTWARE ENGINEERING, 2017, :989-993
[2]   Model-Based Privacy Analysis in Industrial Ecosystems [J].
Ahmadian, Amir Shayan ;
Strueber, Daniel ;
Riediger, Volker ;
Juerjens, Jan .
MODELLING FOUNDATIONS AND APPLICATIONS, ECMFA 2017, 2017, 10376 :215-231
[3]   Metamodel for Privacy Policies within SOA [J].
Allison, David S. ;
El Yamany, Hany F. ;
Capretz, Miriam A. M. .
2009 ICSE WORKSHOP ON SOFTWARE ENGINEERING FOR SECURE SYSTEMS, 2009, :40-46
[4]   A UML Profile for Privacy-Aware Data Lifecycle Models [J].
Alshammari, Majed ;
Simpson, Andrew .
COMPUTER SECURITY, 2017, 2018, 10683 :189-209
[5]  
[Anonymous], 2005, EXTENSIBLE ACCESS CO
[6]  
[Anonymous], 2010, The Unified Modeling Language(UML)
[7]   Towards a UML Profile for Privacy-Aware Applications [J].
Basso, Tania ;
Montecchi, Leonardo ;
Moraes, Regina ;
Jino, Mario ;
Bondavalli, Andrea .
CIT/IUCC/DASC/PICOM 2015 IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION TECHNOLOGY - UBIQUITOUS COMPUTING AND COMMUNICATIONS - DEPENDABLE, AUTONOMIC AND SECURE COMPUTING - PERVASIVE INTELLIGENCE AND COMPUTING, 2015, :371-378
[8]  
Busch M., 2016, Evaluating Engineering: An Approach for the Development of Secure Web Applications
[9]  
Damianou N, 2001, LECT NOTES COMPUT SC, V1995, P18
[10]  
Hoepman JH, 2014, IFIP ADV INF COMM TE, V428, P446