Model-Checking the Implementation of Consent
- ,
- Daniel Le Métayer
- ,
- INSA Lyon
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-reviewOpen access
Publication Information
Output type
Research Output:
Conference Article in Proceeding or Book/Report chapter
Article in proceedings
Peer-reviewOriginal language
EnglishPages from-to (Number of pages)
Pages 253-271Publication milestones
- Published - 26/11/2024
Publication status
Published - 26/11/2024
Volume
15280Publisher
Springer, United States, GermanyPublication IDs
- Scopus: 85210860440
Host publication title
Model-Checking the Implementation of ConsentAbstract
Privacy policies define the terms under which personal data may be collected and processed by data controllers. The General Data Protection Regulation (GDPR) imposes requirements on these policies that are often difficult to implement. Difficulties arise in particular due to the heterogeneity of existing systems (e.g., the Internet of Things (IoT), web technology, etc.). In this paper, we propose a method to refine high level GDPR privacy requirements for informed consent into low-level computational models. The method is aimed at software developers implementing systems that require consent management. We mechanize our models in TLA+ and use model-checking to prove that the low-level computational models implement the high-level privacy requirements; TLA+ has been used by software engineers in companies such as Microsoft or Amazon. We demonstrate our method in two real world scenarios: an implementation of cookie banners and a IoT system communicating via Bluetooth low energy.
Publication metrics
PlumX, opens in new tab
Captures
8
Access to documents
Related Event
Title
International Conference on Software Engineering and Formal Methods
Event type
ConferenceDegree of recognition
International eventDate
04/11/2024 - 08/11/2024Location
PortugalAveiroPortugal
