论文标题

隐私工程符合软件工程。关于工程隐私的挑战bydesign

Privacy Engineering Meets Software Engineering. On the Challenges of Engineering Privacy ByDesign

论文作者

Kostova, Blagovesta, Gürses, Seda, Troncoso, Carmela

论文摘要

当前的软件开发在很大程度上取决于服务体系结构的使用以及敏捷的迭代开发方法设计,实施和部署系统。这些实践导致由多个服务组成的系统,这些服务引入了新的数据流和不断发展的设计,以避开单个设计师的控制。学术隐私工程文献通常会抽象这种软件生产条件,以获得可推广的结果。然而,通过对文献的系统研究,我们表明,提出的解决方案不可避免地会对软件架构,开发方法和设计人员控制范围进行假设,这些解决方案与当前实践不一致。这些未对准可能会构成野外隐私工程解决方案的障碍。具体而言,我们确定了研究人员采用的方法设计和评估隐私增强技术的重要局限性,这些技术涉及有关隐私工程方法的建议。基于我们的分析,我们描述了与实践重新调整研究所需的研究和行动,这些变化为学术隐私的运营提供了前提,导致共同的软件工程实践。

Current day software development relies heavily on the use of service architectures and on agile iterative development methods to design, implement, and deploy systems. These practices result in systems made up of multiple services that introduce new data flows and evolving designs that escape the control of a single designer. Academic privacy engineering literature typically abstracts away such conditions of software production in order to achieve generalizable results. Yet, through a systematic study of the literature, we show that proposed solutions inevitably make assumptions about software architectures, development methods and scope of designer control that are misaligned with current practices. These misalignments are likely to pose an obstacle to operationalizing privacy engineering solutions in the wild. Specifically, we identify important limitations in the approaches that researchers take to design and evaluate privacy enhancing technologies which ripple to proposals for privacy engineering methodologies. Based on our analysis, we delineate research and actions needed to re-align research with practice, changes that serve a precondition for the operationalization of academic privacy results in common software engineering practices.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源