Data minimisation in communication protocols: a formal analysis framework and application to identity management

被引:4
|
作者
Veeningen, Meilof [1 ]
de Weger, Benne [1 ]
Zannone, Nicola [1 ]
机构
[1] Eindhoven Univ Technol, NL-5600 MB Eindhoven, Netherlands
关键词
Privacy; Identity management; Formal methods; Data minimisation; Detectability; Associability; AUTOMATED VERIFICATION; ZERO-KNOWLEDGE; PRIVACY; SECURITY; REQUIREMENTS; SECRECY;
D O I
10.1007/s10207-014-0235-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the growing amount of personal information exchanged over the Internet, privacy is becoming more and more a concern for users. One of the key principles in protecting privacy is data minimisation. This principle requires that only the minimum amount of information necessary to accomplish a certain goal is collected and processed. "Privacy-enhancing" communication protocols have been proposed to guarantee data minimisation in a wide range of applications. However, currently, there is no satisfactory way to assess and compare the privacy they offer in a precise way: existing analyses are either too informal and high level or specific for one particular system. In this work, we propose a general formal framework to analyse and compare communication protocols with respect to privacy by dataminimisation. Privacy requirements are formalised independent of a particular protocol in terms of the knowledge of (coalitions of) actors in a three-layer model of personal information. These requirements are then verified automatically for particular protocols by computing this knowledge from a description of their communication. We validate our framework in an identity management (IdM) case study. As IdM systems are used more and more to satisfy the increasing need for reliable online identification and authentication, privacy is becoming an increasingly critical issue. We use our framework to analyse and compare four identity management systems. Finally, we discuss the completeness and (re)usability of the proposed framework.
引用
收藏
页码:529 / 569
页数:41
相关论文
共 50 条
  • [41] Pyxis: An integrated analysis, visualization and data management framework
    Peterson, T
    Montoya, L
    Farmer, A
    Wenes, G
    Hall, V
    Glass, K
    Colbaugh, R
    8TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL IX, PROCEEDINGS: COMPUTER SCIENCE AND ENGINEERING: I, 2004, : 194 - 198
  • [42] Researches on the Analysis Framework of Application Layer Communication Protocol Based on SQLite
    Xu, Wenyuan
    Li, Hao
    Xu, Weifeng
    HUMAN CENTERED COMPUTING, HCC 2017, 2018, 10745 : 150 - 157
  • [43] SPICE: A new framework for data mining based on probability logic and formal concept analysis
    Jiang, Liying
    Deogun, Jitender
    FUNDAMENTA INFORMATICAE, 2007, 78 (04) : 467 - 485
  • [44] A communication placement framework with unified dependence and data-flow analysis
    Kennedy, K
    Sethi, A
    3RD INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING, PROCEEDINGS, 1996, : 201 - 208
  • [45] The Application of Data Mining Techniques for Financial Risk Management: A classification framework
    Saeed, Tariq
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2020, 20 (08): : 84 - 93
  • [46] Personal Data Management: An Architectural Framework for Personal Cloud Mobile Application
    Wang, Sheng-Wen
    Chang, Shuchih Ernest
    2014 INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE, ELECTRONICS AND ELECTRICAL ENGINEERING (ISEEE), VOLS 1-3, 2014, : 785 - 789
  • [47] Optimization of Data Communication on Air Control Device Based on Internet of Things with Application of HTTP and MQTT Protocols
    Luthfi, F.
    Juanda, E. A.
    Kustiawan, I.
    INTERNATIONAL SYMPOSIUM ON MATERIALS AND ELECTRICAL ENGINEERING (ISMEE) 2017, 2018, 384
  • [48] Analysis of the possibility of SysML and BPMN application in formal data acquisition system description
    Cwikla, G.
    Gwiazda, A.
    Banas, W.
    Monica, Z.
    Foit, K.
    MODTECH INTERNATIONAL CONFERENCE - MODERN TECHNOLOGIES IN INDUSTRIAL ENGINEERING V, 2017, 227
  • [49] Formal callability and its relevance and application to interprocedural data-flow analysis
    Knoop, J
    1998 INTERNATIONAL CONFERENCE ON COMPUTER LANGUAGES, PROCEEDINGS, 1998, : 252 - 261
  • [50] Application of big data analysis and visualization technology in news communication
    Yang J.
    Jin H.
    Comput.-Aided Des. Appl., 2020, Special Issue 2 (134-144): : 134 - 144