Formalising Requirements for a Biobank Case Study Using a Logic for Consent and Revocation
Abstract
In this paper we focus on formalising privacy requirements for the Oxford Radcliffe Biobank (ORB) case study that has emerged within the EnCoRe project. We express the requirements using a logic designed for reasoning about the dynamics of privacy and specifically for capturing the lifecycle of consent and revocation (C&R) controls that a user may invoke. We demonstrate how to tackle ambiguities uncovered in the formalisation and to bridge the gap between user requirements for personal data privacy and system level policy languages effectively.
Domains
Computer Science [cs]Origin | Files produced by the author(s) |
---|
Loading...