Skip to main content

Showing 1–18 of 18 results for author: Pallas, F

.
  1. arXiv:2407.04470  [pdf, other

    cs.CY

    How to Drill Into Silos: Creating a Free-to-Use Dataset of Data Subject Access Packages

    Authors: Nicola Leschke, Daniela Pöhn, Frank Pallas

    Abstract: The European Union's General Data Protection Regulation (GDPR) strengthened several rights for individuals (data subjects). One of these is the data subjects' right to access their personal data being collected by services (data controllers), complemented with a new right to data portability. Based on these, data controllers are obliged to provide respective data and allow data subjects to use the… ▽ More

    Submitted 5 July, 2024; originally announced July 2024.

    Comments: Submitted Manuscript. The Version of record can be found at https://link.springer.com/conference/apf

  2. arXiv:2405.01097  [pdf, other

    cs.CY cs.CL cs.HC cs.IR cs.SE

    Silencing the Risk, Not the Whistle: A Semi-automated Text Sanitization Tool for Mitigating the Risk of Whistleblower Re-Identification

    Authors: Dimitri Staufer, Frank Pallas, Bettina Berendt

    Abstract: Whistleblowing is essential for ensuring transparency and accountability in both public and private sectors. However, (potential) whistleblowers often fear or face retaliation, even when reporting anonymously. The specific content of their disclosures and their distinct writing style may re-identify them as the source. Legal measures, such as the EU WBD, are limited in their scope and effectivenes… ▽ More

    Submitted 2 May, 2024; originally announced May 2024.

    Comments: Accepted for publication at the ACM Conference on Fairness, Accountability, and Transparency 2024 (ACM FAccT'24). This is a preprint manuscript (authors' own version before final copy-editing)

    ACM Class: H.3; K.4; H.5; K.5; D.2; J.4

  3. arXiv:2404.05598  [pdf, other

    cs.CR cs.CY cs.DC cs.SE

    Hook-in Privacy Techniques for gRPC-based Microservice Communication

    Authors: Louis Loechel, Siar-Remzi Akbayin, Elias Grünewald, Jannis Kiesel, Inga Strelnikova, Thomas Janke, Frank Pallas

    Abstract: gRPC is at the heart of modern distributed system architectures. Based on HTTP/2 and Protocol Buffers, it provides highly performant, standardized, and polyglot communication across loosely coupled microservices and is increasingly preferred over REST- or GraphQL-based service APIs in practice. Despite its widespread adoption, gRPC lacks any advanced privacy techniques beyond transport encryption… ▽ More

    Submitted 8 April, 2024; originally announced April 2024.

    Comments: 15 pages, accepted for the ICWE, International Conference on Web Engineering, 2024, research paper

  4. arXiv:2404.03442  [pdf, ps, other

    cs.CR cs.CY cs.SE

    Privacy Engineering From Principles to Practice: A Roadmap

    Authors: Frank Pallas, Katharina Koerner, Isabel Barberá, Jaap-Henk Hoepman, Meiko Jensen, Nandita Rao Narla, Nikita Samarin, Max-R. Ulbricht, Isabel Wagner, Kim Wuyts, Christian Zimmermann

    Abstract: Privacy engineering is gaining momentum in industry and academia alike. So far, manifold low-level primitives and higher-level methods and strategies have successfully been established. Still, fostering adoption in real-world information systems calls for additional aspects to be consciously considered in research and practice.

    Submitted 4 April, 2024; originally announced April 2024.

    ACM Class: K.5.0; H.1.0; D.2.1; D.2.2

    Journal ref: IEEE Security & Privacy, volume 22, issue 2, March-April 2024

  5. arXiv:2309.00382  [pdf, other

    cs.CY cs.CR cs.SE cs.SI

    Towards Cross-Provider Analysis of Transparency Information for Data Protection

    Authors: Elias Grünewald, Johannes M. Halkenhäußer, Nicola Leschke, Frank Pallas

    Abstract: Transparency and accountability are indispensable principles for modern data protection, from both, legal and technical viewpoints. Regulations such as the GDPR, therefore, require specific transparency information to be provided including, e.g., purpose specifications, storage periods, or legal bases for personal data processing. However, it has repeatedly been shown that all too often, this info… ▽ More

    Submitted 5 September, 2023; v1 submitted 1 September, 2023; originally announced September 2023.

    Comments: technical report

  6. arXiv:2306.02496  [pdf, other

    cs.DC cs.CR cs.CY cs.SE

    Hawk: DevOps-driven Transparency and Accountability in Cloud Native Systems

    Authors: Elias Grünewald, Jannis Kiesel, Siar-Remzi Akbayin, Frank Pallas

    Abstract: Transparency is one of the most important principles of modern privacy regulations, such as the GDPR or CCPA. To be compliant with such regulatory frameworks, data controllers must provide data subjects with precise information about the collection, processing, storage, and transfer of personal data. To do so, respective facts and details must be compiled and always kept up to date. In traditional… ▽ More

    Submitted 4 June, 2023; originally announced June 2023.

    Comments: preprint, accepted for the 16th IEEE International Conference on Cloud Computing 2023, IEEE Cloud 2023

  7. arXiv:2305.15006  [pdf, other

    cs.CY cs.AI

    A Human-in-the-Loop Approach for Information Extraction from Privacy Policies under Data Scarcity

    Authors: Michael Gebauer, Faraz Maschhur, Nicola Leschke, Elias Grünewald, Frank Pallas

    Abstract: Machine-readable representations of privacy policies are door openers for a broad variety of novel privacy-enhancing and, in particular, transparency-enhancing technologies (TETs). In order to generate such representations, transparency information needs to be extracted from written privacy policies. However, respective manual annotation and extraction processes are laborious and require expert kn… ▽ More

    Submitted 31 May, 2023; v1 submitted 24 May, 2023; originally announced May 2023.

    Comments: Accepted for 2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&P)

  8. arXiv:2305.03471  [pdf, other

    cs.CY

    Streamlining personal data access requests: From obstructive procedures to automated web workflows

    Authors: Nicola Leschke, Florian Kirsten, Frank Pallas, Elias Grünewald

    Abstract: Transparency and data portability are two core principles of modern privacy legislations such as the GDPR. From the regulatory perspective, providing individuals (data subjects) with access to their data is a main building block for implementing these. Different from other privacy principles and respective regulatory provisions, however, this right to data access has so far only seen marginal tech… ▽ More

    Submitted 5 May, 2023; originally announced May 2023.

    Comments: Accepted for publication at the 23rd International Conference on Web Engineering (ICWE 2023) to appear in https://link.springer.com/book/9783031344459. This is a preprint manuscript (authors' own version before final copy-editing)

  9. arXiv:2302.10991  [pdf, other

    cs.SE cs.CR cs.CY

    Enabling Versatile Privacy Interfaces Using Machine-Readable Transparency Information

    Authors: Elias Grünewald, Johannes M. Halkenhäußer, Nicola Leschke, Johanna Washington, Cristina Paupini, Frank Pallas

    Abstract: Transparency regarding the processing of personal data in online services is a necessary precondition for informed decisions on whether or not to share personal data. In this paper, we argue that privacy interfaces shall incorporate the context of display, personal preferences, and individual competences of data subjects following the principles of universal design and usable privacy. Doing so req… ▽ More

    Submitted 17 April, 2023; v1 submitted 21 February, 2023; originally announced February 2023.

    Comments: Preprint, accepted to the Privacy Symposium 2023 https://privacysymposium.org/

  10. arXiv:2209.09584  [pdf, other

    cs.CR

    Non-Disclosing Credential On-chaining for Blockchain-based Decentralized Applications

    Authors: Jonathan Heiss, Robert Muth, Frank Pallas, Stefan Tai

    Abstract: Many service systems rely on verifiable identity-related information of their users. Manipulation and unwanted exposure of this privacy-relevant information, however, must at the same time be prevented and avoided. Peer-to-peer blockchain-based decentralization with a smart contract-based execution model and verifiable off-chain computations leveraging zero-knowledge proofs promise to provide the… ▽ More

    Submitted 20 September, 2022; originally announced September 2022.

  11. arXiv:2203.09903  [pdf, ps, other

    cs.CR cs.CY cs.DC cs.SE

    Configurable Per-Query Data Minimization for Privacy-Compliant Web APIs

    Authors: Frank Pallas, David Hartmann, Paul Heinrich, Josefine Kipke, Elias Grünewald

    Abstract: The purpose of regulatory data minimization obligations is to limit personal data to the absolute minimum necessary for a given context. Beyond the initial data collection, storage, and processing, data minimization is also required for subsequent data releases, as it is the case when data are provided using query-capable Web APIs. Data-providing Web APIs, however, typically lack sophisticated dat… ▽ More

    Submitted 18 March, 2022; originally announced March 2022.

    Comments: Preprint version (2022-03-18) This version of the contribution has been accepted for publication at the 22nd International Conference on Web Engineering (ICWE 2022), Bari, Italy

  12. arXiv:2201.06350  [pdf, other

    cond-mat.mes-hall physics.acc-ph physics.ins-det

    Megahertz-rate Ultrafast X-ray Scattering and Holographic Imaging at the European XFEL

    Authors: Nanna Zhou Hagström, Michael Schneider, Nico Kerber, Alexander Yaroslavtsev, Erick Burgos Parra, Marijan Beg, Martin Lang, Christian M. Günther, Boris Seng, Fabian Kammerbauer, Horia Popescu, Matteo Pancaldi, Kumar Neeraj, Debanjan Polley, Rahul Jangid, Stjepan B. Hrkac, Sheena K. K. Patel, Sergei Ovcharenko, Diego Turenne, Dmitriy Ksenzov, Christine Boeglin, Igor Pronin, Marina Baidakova, Clemens von Korff Schmising, Martin Borchert , et al. (75 additional authors not shown)

    Abstract: The advent of X-ray free-electron lasers (XFELs) has revolutionized fundamental science, from atomic to condensed matter physics, from chemistry to biology, giving researchers access to X-rays with unprecedented brightness, coherence, and pulse duration. All XFEL facilities built until recently provided X-ray pulses at a relatively low repetition rate, with limited data statistics. Here, we presen… ▽ More

    Submitted 20 January, 2022; v1 submitted 17 January, 2022; originally announced January 2022.

    Comments: 13 pages, 5 figures. Supplementary Information as ancillary file

    Journal ref: J. Synchrotron Rad. (2022), 29

  13. Datensouveränität für Verbraucher:innen: Technische Ansätze durch KI-basierte Transparenz und Auskunft im Kontext der DSGVO

    Authors: Elias Grünewald, Frank Pallas

    Abstract: A sufficient level of data sovereignty is extremely difficult for consumers in practice. The EU General Data Protection Regulation guarantees comprehensive data subject rights, which must be implemented by responsible controllers through technical and organizational measures. Traditional approaches, such as the provision of lengthy data protection declarations or the downloading of raw personal da… ▽ More

    Submitted 7 December, 2021; originally announced December 2021.

    Comments: In German, appears in "Schriften der Verbraucherinformatik 2021". Original publication: https://pub.h-brs.de/frontdoor/index/index/docId/6021

  14. RedCASTLE: Practically Applicable $k_s$-Anonymity for IoT Streaming Data at the Edge in Node-RED

    Authors: Frank Pallas, Julian Legler, Niklas Amslgruber, Elias Grünewald

    Abstract: In this paper, we present RedCASTLE, a practically applicable solution for Edge-based $k_s$-anonymization of IoT streaming data in Node-RED. RedCASTLE builds upon a pre-existing, rudimentary implementation of the CASTLE algorithm and significantly extends it with functionalities indispensable for real-world IoT scenarios. In addition, RedCASTLE provides an abstraction layer for smoothly integratin… ▽ More

    Submitted 29 October, 2021; originally announced October 2021.

    Comments: Accepted for publication as regular research paper for the "8th International Workshop on Middleware and Applications for the Internet of Things". This is a preprint manuscript (authors' own version before final copy-editing)

  15. arXiv:2110.15150  [pdf, ps, other

    cs.CR

    Messaging with Purpose Limitation -- Privacy-Compliant Publish-Subscribe Systems

    Authors: Karl Wolf, Frank Pallas, Stefan Tai

    Abstract: Purpose limitation is an important privacy principle to ensure that personal data may only be used for the declared purposes it was originally collected for. Ensuring compliance with respective privacy regulations like the GDPR, which codify purpose limitation as an obligation, consequently, is a major challenge in real-world enterprise systems. Technical solutions under the umbrella of purpose-ba… ▽ More

    Submitted 28 October, 2021; originally announced October 2021.

    ACM Class: C.2.4; H.4.0; K.5.0

  16. TIRA: An OpenAPI Extension and Toolbox for GDPR Transparency in RESTful Architectures

    Authors: Elias Grünewald, Paul Wille, Frank Pallas, Maria C. Borges, Max-R. Ulbricht

    Abstract: Transparency - the provision of information about what personal data is collected for which purposes, how long it is stored, or to which parties it is transferred - is one of the core privacy principles underlying regulations such as the GDPR. Technical approaches for implementing transparency in practice are, however, only rarely considered. In this paper, we present a novel approach for doing so… ▽ More

    Submitted 10 June, 2021; originally announced June 2021.

    Comments: Accepted for publication at the 2021 International Workshop on Privacy Engineering (IWPE'21). This is a preprint manuscript (authors' own version before final copy-editing)

  17. arXiv:2012.10431  [pdf, other

    cs.CY cs.CR cs.FL cs.SE

    TILT: A GDPR-Aligned Transparency Information Language and Toolkit for Practical Privacy Engineering

    Authors: Elias Grünewald, Frank Pallas

    Abstract: In this paper, we present TILT, a transparency information language and toolkit explicitly designed to represent and process transparency information in line with the requirements of the GDPR and allowing for a more automated and adaptive use of such information than established, legalese data protection policies do. We provide a detailed analysis of transparency obligations from the GDPR to ide… ▽ More

    Submitted 18 December, 2020; originally announced December 2020.

    Comments: Accepted for publication at the ACM Conference on Fairness, Accountability, and Transparency 2021 (ACM FAccT'21). This is a preprint manuscript (authors' own version before final copy-editing)

    ACM Class: H.3; K.5; K.4; H.5; D.2; E.2

  18. Fog Computing as Privacy Enabler

    Authors: Frank Pallas, Philip Raschke, David Bermbach

    Abstract: Despite broad discussions on privacy challenges arising from fog computing, the authors argue that privacy and security requirements might actually drive the adoption of fog computing. They present four patterns of fog computing fostering data privacy and the security of business secrets, complementing existing cryptographic approaches. Their practical application is illuminated on the basis of th… ▽ More

    Submitted 13 March, 2020; v1 submitted 9 October, 2019; originally announced October 2019.

    Comments: Preprint, accepted for publication in IEEE Internet Computing. This is the authors' own version before final copy-editing by IEEE