Skip to main content

Showing 1–16 of 16 results for author: Grünewald, E

Searching in archive cs. Search in all archives.
.
  1. arXiv:2505.13153  [pdf, ps, other

    cs.DC cs.CR cs.SE

    Prink: $k_s$-Anonymization for Streaming Data in Apache Flink

    Authors: Philip Groneberg, Saskia Nuñez von Voigt, Thomas Janke, Louis Loechel, Karl Wolf, Elias Grünewald, Frank Pallas

    Abstract: In this paper, we present Prink, a novel and practically applicable concept and fully implemented prototype for ks-anonymizing data streams in real-world application architectures. Building upon the pre-existing, yet rudimentary CASTLE scheme, Prink for the first time introduces semantics-aware ks-anonymization of non-numerical (such as categorical or hierarchically generalizable) streaming data i… ▽ More

    Submitted 19 May, 2025; originally announced May 2025.

    Comments: accepted for ARES 2025

  2. arXiv:2406.09960  [pdf, other

    cs.SE

    Extending Business Process Management for Regulatory Transparency

    Authors: Jannis Kiesel, Elias Grünewald

    Abstract: Ever-increasingly complex business processes are enabled by loosely coupled cloud-native systems. In such fast-paced development environments, data controllers face the challenge of capturing and updating all personal data processing activities due to considerable communication overhead between development teams and data protection staff. To date, established business process management methods ge… ▽ More

    Submitted 14 June, 2024; originally announced June 2024.

    Comments: Preprint, accepted to the BPM Forum 2024

  3. arXiv:2404.05598  [pdf, other

    cs.CR cs.CY cs.DC cs.SE

    Hook-in Privacy Techniques for gRPC-based Microservice Communication

    Authors: Louis Loechel, Siar-Remzi Akbayin, Elias Grünewald, Jannis Kiesel, Inga Strelnikova, Thomas Janke, Frank Pallas

    Abstract: gRPC is at the heart of modern distributed system architectures. Based on HTTP/2 and Protocol Buffers, it provides highly performant, standardized, and polyglot communication across loosely coupled microservices and is increasingly preferred over REST- or GraphQL-based service APIs in practice. Despite its widespread adoption, gRPC lacks any advanced privacy techniques beyond transport encryption… ▽ More

    Submitted 8 April, 2024; originally announced April 2024.

    Comments: 15 pages, accepted for the ICWE, International Conference on Web Engineering, 2024, research paper

  4. arXiv:2309.00382  [pdf, other

    cs.CY cs.CR cs.SE cs.SI

    Towards Cross-Provider Analysis of Transparency Information for Data Protection

    Authors: Elias Grünewald, Johannes M. Halkenhäußer, Nicola Leschke, Frank Pallas

    Abstract: Transparency and accountability are indispensable principles for modern data protection, from both, legal and technical viewpoints. Regulations such as the GDPR, therefore, require specific transparency information to be provided including, e.g., purpose specifications, storage periods, or legal bases for personal data processing. However, it has repeatedly been shown that all too often, this info… ▽ More

    Submitted 5 September, 2023; v1 submitted 1 September, 2023; originally announced September 2023.

    Comments: technical report

  5. arXiv:2306.02496  [pdf, other

    cs.DC cs.CR cs.CY cs.SE

    Hawk: DevOps-driven Transparency and Accountability in Cloud Native Systems

    Authors: Elias Grünewald, Jannis Kiesel, Siar-Remzi Akbayin, Frank Pallas

    Abstract: Transparency is one of the most important principles of modern privacy regulations, such as the GDPR or CCPA. To be compliant with such regulatory frameworks, data controllers must provide data subjects with precise information about the collection, processing, storage, and transfer of personal data. To do so, respective facts and details must be compiled and always kept up to date. In traditional… ▽ More

    Submitted 4 June, 2023; originally announced June 2023.

    Comments: preprint, accepted for the 16th IEEE International Conference on Cloud Computing 2023, IEEE Cloud 2023

  6. arXiv:2305.15006  [pdf, other

    cs.CY cs.AI

    A Human-in-the-Loop Approach for Information Extraction from Privacy Policies under Data Scarcity

    Authors: Michael Gebauer, Faraz Maschhur, Nicola Leschke, Elias Grünewald, Frank Pallas

    Abstract: Machine-readable representations of privacy policies are door openers for a broad variety of novel privacy-enhancing and, in particular, transparency-enhancing technologies (TETs). In order to generate such representations, transparency information needs to be extracted from written privacy policies. However, respective manual annotation and extraction processes are laborious and require expert kn… ▽ More

    Submitted 31 May, 2023; v1 submitted 24 May, 2023; originally announced May 2023.

    Comments: Accepted for 2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&P)

  7. arXiv:2305.03471  [pdf, other

    cs.CY

    Streamlining personal data access requests: From obstructive procedures to automated web workflows

    Authors: Nicola Leschke, Florian Kirsten, Frank Pallas, Elias Grünewald

    Abstract: Transparency and data portability are two core principles of modern privacy legislations such as the GDPR. From the regulatory perspective, providing individuals (data subjects) with access to their data is a main building block for implementing these. Different from other privacy principles and respective regulatory provisions, however, this right to data access has so far only seen marginal tech… ▽ More

    Submitted 5 May, 2023; originally announced May 2023.

    Comments: Accepted for publication at the 23rd International Conference on Web Engineering (ICWE 2023) to appear in https://link.springer.com/book/9783031344459. This is a preprint manuscript (authors' own version before final copy-editing)

  8. arXiv:2302.10991  [pdf, other

    cs.SE cs.CR cs.CY

    Enabling Versatile Privacy Interfaces Using Machine-Readable Transparency Information

    Authors: Elias Grünewald, Johannes M. Halkenhäußer, Nicola Leschke, Johanna Washington, Cristina Paupini, Frank Pallas

    Abstract: Transparency regarding the processing of personal data in online services is a necessary precondition for informed decisions on whether or not to share personal data. In this paper, we argue that privacy interfaces shall incorporate the context of display, personal preferences, and individual competences of data subjects following the principles of universal design and usable privacy. Doing so req… ▽ More

    Submitted 17 April, 2023; v1 submitted 21 February, 2023; originally announced February 2023.

    Comments: Preprint, accepted to the Privacy Symposium 2023 https://privacysymposium.org/

  9. Scalable Discovery and Continuous Inventory of Personal Data at Rest in Cloud Native Systems

    Authors: Elias Grünewald, Leonard Schurbert

    Abstract: Cloud native systems are processing large amounts of personal data through numerous and possibly multi-paradigmatic data stores (e.g., relational and non-relational databases). From a privacy engineering perspective, a core challenge is to keep track of all exact locations, where personal data is being stored, as required by regulatory frameworks such as the European General Data Protection Regula… ▽ More

    Submitted 9 September, 2022; originally announced September 2022.

    Comments: Preprint of 2022-09-09 before final copy-editing of an accepted peer-reviewed paper to appear in the Proceedings of the 20th International Conference on Service-Oriented Computing ICSOC 2022

  10. arXiv:2206.11641  [pdf, other

    cs.CR cs.DC

    Advancing Blockchain-based Federated Learning through Verifiable Off-chain Computations

    Authors: Jonathan Heiss, Elias Grünewald, Nikolas Haimerl, Stefan Schulte, Stefan Tai

    Abstract: Federated learning may be subject to both global aggregation attacks and distributed poisoning attacks. Blockchain technology along with incentive and penalty mechanisms have been suggested to counter these. In this paper, we explore verifiable off-chain computations using zero-knowledge proofs as an alternative to incentive and penalty mechanisms in blockchain-based federated learning. In our sol… ▽ More

    Submitted 23 June, 2022; originally announced June 2022.

  11. arXiv:2203.09903  [pdf, ps, other

    cs.CR cs.CY cs.DC cs.SE

    Configurable Per-Query Data Minimization for Privacy-Compliant Web APIs

    Authors: Frank Pallas, David Hartmann, Paul Heinrich, Josefine Kipke, Elias Grünewald

    Abstract: The purpose of regulatory data minimization obligations is to limit personal data to the absolute minimum necessary for a given context. Beyond the initial data collection, storage, and processing, data minimization is also required for subsequent data releases, as it is the case when data are provided using query-capable Web APIs. Data-providing Web APIs, however, typically lack sophisticated dat… ▽ More

    Submitted 18 March, 2022; originally announced March 2022.

    Comments: Preprint version (2022-03-18) This version of the contribution has been accepted for publication at the 22nd International Conference on Web Engineering (ICWE 2022), Bari, Italy

  12. Datensouveränität für Verbraucher:innen: Technische Ansätze durch KI-basierte Transparenz und Auskunft im Kontext der DSGVO

    Authors: Elias Grünewald, Frank Pallas

    Abstract: A sufficient level of data sovereignty is extremely difficult for consumers in practice. The EU General Data Protection Regulation guarantees comprehensive data subject rights, which must be implemented by responsible controllers through technical and organizational measures. Traditional approaches, such as the provision of lengthy data protection declarations or the downloading of raw personal da… ▽ More

    Submitted 7 December, 2021; originally announced December 2021.

    Comments: In German, appears in "Schriften der Verbraucherinformatik 2021". Original publication: https://pub.h-brs.de/frontdoor/index/index/docId/6021

  13. RedCASTLE: Practically Applicable $k_s$-Anonymity for IoT Streaming Data at the Edge in Node-RED

    Authors: Frank Pallas, Julian Legler, Niklas Amslgruber, Elias Grünewald

    Abstract: In this paper, we present RedCASTLE, a practically applicable solution for Edge-based $k_s$-anonymization of IoT streaming data in Node-RED. RedCASTLE builds upon a pre-existing, rudimentary implementation of the CASTLE algorithm and significantly extends it with functionalities indispensable for real-world IoT scenarios. In addition, RedCASTLE provides an abstraction layer for smoothly integratin… ▽ More

    Submitted 29 October, 2021; originally announced October 2021.

    Comments: Accepted for publication as regular research paper for the "8th International Workshop on Middleware and Applications for the Internet of Things". This is a preprint manuscript (authors' own version before final copy-editing)

  14. Cloud Native Privacy Engineering through DevPrivOps

    Authors: Elias Grünewald

    Abstract: Cloud native information systems engineering enables scalable and resilient service infrastructures for all major online offerings. These are built following agile development practices. At the same time, a growing demand for privacy-friendly services is articulated by societal norms and policy through effective legislative frameworks. In this paper, we identify the conceptual dimensions of cloud… ▽ More

    Submitted 1 December, 2021; v1 submitted 2 August, 2021; originally announced August 2021.

    Comments: preprint version (2021-12-01), accepted for the Post-Proceedings at the 16th IFIP Summer School on Privacy and Identity Management 2021

  15. TIRA: An OpenAPI Extension and Toolbox for GDPR Transparency in RESTful Architectures

    Authors: Elias Grünewald, Paul Wille, Frank Pallas, Maria C. Borges, Max-R. Ulbricht

    Abstract: Transparency - the provision of information about what personal data is collected for which purposes, how long it is stored, or to which parties it is transferred - is one of the core privacy principles underlying regulations such as the GDPR. Technical approaches for implementing transparency in practice are, however, only rarely considered. In this paper, we present a novel approach for doing so… ▽ More

    Submitted 10 June, 2021; originally announced June 2021.

    Comments: Accepted for publication at the 2021 International Workshop on Privacy Engineering (IWPE'21). This is a preprint manuscript (authors' own version before final copy-editing)

  16. arXiv:2012.10431  [pdf, other

    cs.CY cs.CR cs.FL cs.SE

    TILT: A GDPR-Aligned Transparency Information Language and Toolkit for Practical Privacy Engineering

    Authors: Elias Grünewald, Frank Pallas

    Abstract: In this paper, we present TILT, a transparency information language and toolkit explicitly designed to represent and process transparency information in line with the requirements of the GDPR and allowing for a more automated and adaptive use of such information than established, legalese data protection policies do. We provide a detailed analysis of transparency obligations from the GDPR to ide… ▽ More

    Submitted 18 December, 2020; originally announced December 2020.

    Comments: Accepted for publication at the ACM Conference on Fairness, Accountability, and Transparency 2021 (ACM FAccT'21). This is a preprint manuscript (authors' own version before final copy-editing)

    ACM Class: H.3; K.5; K.4; H.5; D.2; E.2