Department of Computer Science, Norwegian University of Science and Technology (NTNU), NO-7491 Trondheim, Norway.
Sensors (Basel). 2019 Oct 6;19(19):4318. doi: 10.3390/s19194318.
Privacy has long been an important issue for IT systems that handle personal information, and is further aggravated as technology for collecting and analyzing massive amounts of data is becoming increasingly effective. There are methods to help practitioners analyze the privacy implications of a system during the design time. However, this is still a difficult task, especially when dealing with Internet of Things scenarios. The problem of privacy can become even more unmanageable with the introduction of overspecifications during the system development life cycle. In this paper, we carried out a controlled experiment with students performing an analysis of privacy implications using two different methods. One method aims at reducing the impact of overspecifications through the application of a goal-oriented analysis. The other method does not involve a goal-oriented analysis and is used as a control. Our initial findings show that conducting a goal-oriented analysis early during design time can have a positive impact over the privacy friendliness of the resulting system.
隐私一直是处理个人信息的 IT 系统的一个重要问题,随着收集和分析大量数据的技术变得越来越有效,这个问题进一步加剧了。有一些方法可以帮助从业者在设计时分析系统的隐私影响。然而,这仍然是一项艰巨的任务,特别是在处理物联网场景时。随着系统开发生命周期中过度规范的引入,隐私问题可能会变得更加难以处理。在本文中,我们通过让学生使用两种不同的方法来分析隐私影响,进行了一项对照实验。一种方法旨在通过应用面向目标的分析来减少过度规范的影响。另一种方法不涉及面向目标的分析,用作对照。我们的初步发现表明,在设计时尽早进行面向目标的分析可以对产生的系统的隐私友好性产生积极影响。