The rapid proliferation of Application Programming Interfaces (APIs) enhances data exchange. Still, it introduces significant privacy and security risks, especially in the Internet of Things (IoT), where APIs often lack mechanisms to manage privacy and security, leading to vulnerabilities. Hippocratic Databases (HDBs) provide mechanisms, e.g., purpose-based access, to control database use. However, to effectively manage data access to the HDB, proper API design is crucial. This paper proposes a conceptual framework for a Hippocratic API (HAPI), revising traditional API design aiming to protect data subjects’ rights and enhance security. By embedding data protection and ethical standards into API operations, HAPIs rectify inadequacies in consent mechanisms and mitigate privacy risks. We identify non-functional requirements, design objectives, and techniques through extensive research of recent literature, informed by the ethical principles of the GDPR, ISO/IEC 27001, and HDBs. We present our findings by knowledge graphs, providing a comprehensive conceptual view of the relevant design knowledge.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Conceptual Framework for Designing Hippocratic APIs

  • Sarmad Rezayat,
  • Gerrit Burmester,
  • Hui Ma,
  • Sven Hartmann

摘要

The rapid proliferation of Application Programming Interfaces (APIs) enhances data exchange. Still, it introduces significant privacy and security risks, especially in the Internet of Things (IoT), where APIs often lack mechanisms to manage privacy and security, leading to vulnerabilities. Hippocratic Databases (HDBs) provide mechanisms, e.g., purpose-based access, to control database use. However, to effectively manage data access to the HDB, proper API design is crucial. This paper proposes a conceptual framework for a Hippocratic API (HAPI), revising traditional API design aiming to protect data subjects’ rights and enhance security. By embedding data protection and ethical standards into API operations, HAPIs rectify inadequacies in consent mechanisms and mitigate privacy risks. We identify non-functional requirements, design objectives, and techniques through extensive research of recent literature, informed by the ethical principles of the GDPR, ISO/IEC 27001, and HDBs. We present our findings by knowledge graphs, providing a comprehensive conceptual view of the relevant design knowledge.