4.2 Article

RSL-IL4Privacy: a domain-specific language for the rigorous specification of privacy policies

期刊

REQUIREMENTS ENGINEERING
卷 24, 期 1, 页码 1-26

出版社

SPRINGER
DOI: 10.1007/s00766-018-0305-2

关键词

Privacy policy; Privacy requirement; Domain-specific language; RSL-IL4Privacy; Eddy

资金

  1. national funds under FCT [UID/CEC/50021/2013, EXCL/EEI-ESS/0257/2012, CMUP-EPB/TIC/0053/2013, TT-MDD-Mindbury/2014]
  2. Fundação para a Ciência e a Tecnologia [CMUP-EPB/TIC/0053/2013] Funding Source: FCT

向作者/读者索取更多资源

Mobile and web applications that manage users' personal information require developers to align their software design with privacy requirements commonly described in privacy policies. These policies are often the sole means to enforce accountability on that data protection. We propose the RSL-IL4Privacy, a domain-specific language for specifying privacy policies that can be simultaneously manipulated by computers and authored and analyzed by humans. In addition, RSL-IL4Privacy can be used as an intermediate language to support model-to-model transformations from and into other related languages. RSL-IL4Privacy provides policy authors with means to define a privacy policy as a set of declarative statements with explicit relationships to services, data recipients, private data types and enforcement mechanisms. The RSL-IL4Privacy is defined with different technologies for supporting distinct levels of formality, namely support for multiple modes of presenting privacy requirements, including tabular, graphical and textual representations, to increase integration with a wider variety of authoring and analyzing practices. We apply this language to support the analysis and comparison of policies from Facebook, LinkedIn, Twitter, Dropbox and IMDb. We discuss with further detail the application of this approach to the Twitter policy by presenting several examples with multiple representations. Finally, we discuss how RSL-IL4Privacy can improve the quality of privacy policies and also identifies threats to validity.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.2
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据