Enforcing context-awareness and privacy-by-design in the specification of information systems

Conference Paper (2018)
Author(s)

Boris Shishkov (Interdisciplinary Institute for Collaboration and Research on Enterprise Systems and Technology (IICREST), Bulgarian Academy of Sciences)

M Marijn (TU Delft - Information and Communication Technology)

Department
Engineering, Systems and Services
Copyright
© 2018 Boris Shishkov, M.F.W.H.A. Janssen
DOI related publication
https://doi.org/10.1007/978-3-319-78428-1_5
More Info
expand_more
Publication Year
2018
Language
English
Copyright
© 2018 Boris Shishkov, M.F.W.H.A. Janssen
Department
Engineering, Systems and Services
Bibliographical Note
Green Open Access added to TU Delft Institutional Repository ‘You share, we take care!’ – Taverne project https://www.openaccess.nl/en/you-share-we-take-care Otherwise as indicated in the copyright section: the publisher is the copyright holder of this work and the author uses the Dutch legislation to make this work public.@en
Volume number
309
Pages (from-to)
87-111
ISBN (print)
9783319784274
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

Networked physical devices, vehicles, home appliances, and other items embedded with electronics, software, sensors, actuators, and connectivity, allow for run-time acquisition of user data. This in turn can enable information systems which capture the “current” user state and act accordingly. The use of this data would result in context-aware applications that get fueled by user data (and environmental data) to adapt their behavior. Yet the use of data is often restricted by privacy regulations and norms; for example, the location of a person cannot be shared without given consent. In this paper we propose a design approach that allows for weaving context-awareness and privacy-by-design into the specification of information systems. This is to be done since the very early stages of the software development, while the enterprise needs are captured (and understood) and the software features are specified on that basis. In addition to taking into account context-awareness and privacy-sensitivity these two aspects will be balanced, especially if they are conflicting. The presented approach extends the “Software Derived from Business Components” (SDBC) approach. We partially demonstrate our proposed way of modeling, by means of a case example featuring land border security. Our proposed way of modeling would allow developers to smoothly reflect context and privacy features in the application design, supported by methodological guidelines that span over the enterprise modeling and software specification. Those features are captured as technology-independent societal demands and are in the end reflected in technology-specific (software) solutions. Traceability between the two is possible as well as re-use of modeling constructs.

Files

Shishkov_Janssen2018_Chapter_E... (pdf)
(pdf | 2.1 Mb)
- Embargo expired in 20-09-2018
License info not available