Skip to main content
QUICK REVIEW

[Paper Review] A Core Ontology for Privacy Requirements Engineering

Mohamad Gharib, John Mylopoulos|arXiv (Cornell University)|Nov 30, 2018
Privacy, Security, and Data Protection4 citations
TL;DR

This paper introduces COPri, a core ontology for privacy requirements engineering that extends prior work through systematic literature review and refinement of privacy concepts. It enables modeling privacy requirements in socio-technical contexts by integrating technical, social, and organizational dimensions, validated via competency queries and expert evaluation, offering a reusable foundation for privacy-aware system design.

ABSTRACT

Nowadays, most companies need to collect, store, and manage personal information in order to deliver their services. Accordingly, privacy has emerged as a key concern for these companies since they need to comply with privacy laws and regulations. To deal with them properly, such privacy concerns should be considered since the early phases of system design. Ontologies have proven to be a key factor for elaborating high-quality requirements models. However, most existing work deals with privacy as a special case of security requirements, thereby missing essential traits of this family of requirements. In this paper, we introduce COPri, a Core Ontology for Privacy requirements engineering that adopts and extends our previous work on privacy requirements engineering ontology that has been mined through a systematic literature review. Additionally, we implement, validate and then evaluate our ontology.

Motivation & Objective

  • To address the lack of a unified, expressive ontology for privacy requirements that captures both technical and socio-technical aspects.
  • To overcome the limitation of treating privacy as a subset of security requirements, which overlooks key privacy-specific concepts like anonymity and unlinkability.
  • To provide a formal, reusable framework for system designers to elicit, model, and reason about privacy requirements from early system design phases.
  • To validate the ontology’s expressiveness and correctness using real-world case studies and competency questions.
  • To support future automation of privacy policy derivation through a goal-oriented framework grounded in the ontology.

Proposed method

  • The ontology was extended and refined based on a systematic literature review of existing privacy requirements models.
  • Core concepts such as personal information, privacy goals, purpose of use, need-to-use, and sensitivity levels were formalized in OWL using Protégé.
  • An Ambient-Assisted Living (AAL) system was used as a real-world case study to instantiate and validate the ontology.
  • Competency Questions (CQs) were defined and used to query the ontology instance, assessing its ability to answer domain-specific privacy queries.
  • The ontology was evaluated for common pitfalls using automated tools, lexical semantics experts, and privacy/security researchers.
  • Future work includes developing a goal-oriented framework for automated derivation of privacy policies from requirements models.

Experimental results

Research questions

  • RQ1How can a core ontology be designed to capture the full spectrum of privacy requirements beyond traditional security concerns?
  • RQ2To what extent can the COPri ontology model privacy requirements in socio-technical systems, including organizational and human factors?
  • RQ3Can the ontology effectively answer competency questions derived from real-world privacy use cases?
  • RQ4How can privacy-specific concepts like pseudonymity, unlinkability, and unobservability be formally represented and distinguished from confidentiality?
  • RQ5What are the key challenges in refining and validating a privacy ontology across diverse domains?

Key findings

  • The COPri ontology successfully models privacy requirements across technical, social, and organizational dimensions, demonstrating its expressiveness in a real-world AAL case study.
  • The ontology was validated through a set of competency questions, confirming its ability to capture and retrieve detailed privacy-relevant knowledge from the instance model.
  • Expert evaluation and tool-based analysis revealed that COPri avoids common ontology pitfalls such as ambiguity, redundancy, and poor modularity.
  • The ontology distinguishes critical privacy concepts like anonymity, pseudonymity, and unlinkability from confidentiality, addressing a key limitation in prior work.
  • The integration of sensitivity levels and purpose-of-use properties enables more nuanced modeling of privacy requirements based on context and data usage.
  • The study identifies the need for further refinement of properties like Need-to-Use (NtU) and Purpose-of-Use (PoU) to support automated policy derivation.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.