论文标题
设计一个严肃的游戏:教开发人员将隐私嵌入软件系统中
Designing a Serious Game: Teaching Developers to Embed Privacy into Software Systems
论文作者
论文摘要
当用户与他们互动时,软件应用程序将继续挑战用户隐私。存在隐私惯例(例如数据最小化(DM),设计(PBD)的隐私(PBD)或一般数据保护法规(GDPR))和相关的“隐私工程”方法,并为开发人员提供了明确的说明,以使开发人员将隐私在开发的软件系统中实施,以保留用户隐私。但是,这些实践和方法论尚不在软件开发社区中的普遍做法。以前没有研究重点是开发“教育”干预措施,例如认真的游戏来增强软件开发人员的编码行为。因此,本研究建议将游戏设计框架作为软件开发人员改进(安全)编码行为的教育工具,以便他们可以开发人们可以使用的保护隐私的软件应用程序。提出的框架的要素被整合到游戏应用程序方案中,该场景通过动机来增强软件开发人员的编码行为。拟议的工作不仅可以开发隐私的软件系统,而且还可以帮助软件开发社区将隐私指南和工程方法付诸实践。
Software applications continue to challenge user privacy when users interact with them. Privacy practices (e.g. Data Minimisation (DM), Privacy by Design (PbD) or General Data Protection Regulation (GDPR)) and related "privacy engineering" methodologies exist and provide clear instructions for developers to implement privacy into software systems they develop that preserve user privacy. However, those practices and methodologies are not yet a common practice in the software development community. There has been no previous research focused on developing "educational" interventions such as serious games to enhance software developers' coding behaviour. Therefore, this research proposes a game design framework as an educational tool for software developers to improve (secure) coding behaviour, so they can develop privacy-preserving software applications that people can use. The elements of the proposed framework were incorporated into a gaming application scenario that enhances the software developers' coding behaviour through their motivation. The proposed work not only enables the development of privacy-preserving software systems but also helping the software development community to put privacy guidelines and engineering methodologies into practice.