Data minimisation in communication protocols: a formal analysis framework and application to identity management

被引:4
|
作者
Veeningen, Meilof [1 ]
de Weger, Benne [1 ]
Zannone, Nicola [1 ]
机构
[1] Eindhoven Univ Technol, NL-5600 MB Eindhoven, Netherlands
关键词
Privacy; Identity management; Formal methods; Data minimisation; Detectability; Associability; AUTOMATED VERIFICATION; ZERO-KNOWLEDGE; PRIVACY; SECURITY; REQUIREMENTS; SECRECY;
D O I
10.1007/s10207-014-0235-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the growing amount of personal information exchanged over the Internet, privacy is becoming more and more a concern for users. One of the key principles in protecting privacy is data minimisation. This principle requires that only the minimum amount of information necessary to accomplish a certain goal is collected and processed. "Privacy-enhancing" communication protocols have been proposed to guarantee data minimisation in a wide range of applications. However, currently, there is no satisfactory way to assess and compare the privacy they offer in a precise way: existing analyses are either too informal and high level or specific for one particular system. In this work, we propose a general formal framework to analyse and compare communication protocols with respect to privacy by dataminimisation. Privacy requirements are formalised independent of a particular protocol in terms of the knowledge of (coalitions of) actors in a three-layer model of personal information. These requirements are then verified automatically for particular protocols by computing this knowledge from a description of their communication. We validate our framework in an identity management (IdM) case study. As IdM systems are used more and more to satisfy the increasing need for reliable online identification and authentication, privacy is becoming an increasingly critical issue. We use our framework to analyse and compare four identity management systems. Finally, we discuss the completeness and (re)usability of the proposed framework.
引用
收藏
页码:529 / 569
页数:41
相关论文
共 50 条
  • [31] Management of the master data lifecycle: a framework for analysis
    Ofner, Martin Hubert
    Straub, Kevin
    Otto, Boris
    Oesterle, Hubert
    JOURNAL OF ENTERPRISE INFORMATION MANAGEMENT, 2013, 26 (04) : 472 - +
  • [32] The HiveDB image data management and analysis framework
    Muehlboeck, J-Sebastian
    Westman, Eric
    Simmons, Andrew
    FRONTIERS IN NEUROINFORMATICS, 2014, 7
  • [33] General Identity Management Model for Big Data Analysis
    Gao, Feng
    Zhang, Feng
    Xia, Junjie
    Ma, Zheng
    2016 18TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATIONS TECHNOLOGY (ICACT) - INFORMATION AND COMMUNICATIONS FOR SAFE AND SECURE LIFE, 2016, : 197 - 200
  • [34] Formal policy framework and ICT tools for research data management in academic institutions in Ghana
    Arthur, Beatrice
    van der Walt, Thomas
    Arthur, Collins
    Imoro, Osman
    Kodua-Ntim, Kwame
    INFORMATION DEVELOPMENT, 2024,
  • [35] A State Estimation Based Framework for Control and Management of Data Communication Networks
    Abbas, Ghularn
    Nagar, Atulya K.
    Tawfik, Hissam
    Goulermas, J. Y.
    DFMA 2008: FIRST INTERNATIONAL CONFERENCE ON DISTRIBUTED FRAMEWORKS & APPLICATIONS, PROCEEDINGS, 2008, : 194 - +
  • [36] A formal framework for modeling and analysis of system-level dynamic power management
    Yardi, S
    Channakeshava, K
    Hsiao, MS
    Martin, TL
    Ha, DS
    2005 IEEE INTERNATIONAL CONFERENCE ON COMPUTER DESIGN: VLSI IN COMPUTERS & PROCESSORS, PROCEEDINGS, 2005, : 119 - 126
  • [37] Floating Point Arithmetic Protocols for Constructing Secure Data Analysis Application
    Liu, Yun-Ching
    Chiang, Yi-Ting
    Hsu, Tsan-Sheng
    Liau, Churn-Jung
    Wang, Da-Wei
    17TH INTERNATIONAL CONFERENCE IN KNOWLEDGE BASED AND INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS - KES2013, 2013, 22 : 152 - 161
  • [38] MacSim - A framework for MAC and LAC Protocols analysis on 3G mobile communication systems
    Barbosa, LHR
    Mateus, GR
    PROCEEDINGS OF THE IASTED INTERNATIONAL CONFERENCE ON WIRELESS AND OPTICAL COMMUNICATIONS, 2002, : 486 - 492
  • [39] APPLICATION OF STATISTICAL COMMUNICATION THEORY TO ANALYSIS OF GEOMAGNETIC DATA
    KOTICK, BJ
    TRANSACTIONS-AMERICAN GEOPHYSICAL UNION, 1968, 49 (01): : 134 - &
  • [40] A Framework for the Application of Decision Trees to the Analysis of SNPs Data
    Fiaschi, Linda
    Garibaldi, Jonathan M.
    Krasnogor, Natalio
    CIBCB: 2009 IEEE SYMPOSIUM ON COMPUTATIONAL INTELLIGENCE IN BIOINFORMATICS AND COMPUTATIONAL BIOLOGY, 2009, : 106 - 113