Score
Designs and produces socio-technical system requirements by eliciting and translating stakeholder goals, business barriers, and governance constraints into concrete technical specifications, protocols, and requirements artifacts. Covers both functional and non‑functional concerns—privacy-by-design data governance, service classes for latency and reliability, and edge–cloud partitioning—so implementers can build or analyze the resulting system designs.
This study addresses the challenge of privacy communication in human–robot collaboration systems within Industry 5.0, where sensitive data monitoring raises significant privacy concerns that are often obscured by technical complexity, leading to mistrust and resistance among non-technical stakeholders. To bridge this gap, the authors propose a novel conceptual framework that integrates Privacy by Design principles with large language models (LLMs), leveraging LLMs for the first time in the requirements engineering process to automatically generate natural-language privacy reports tailored for non-technical audiences from representative human–robot monitoring scenarios. Evaluation across two industrial use cases demonstrates that the approach substantially enhances the comprehensibility of privacy information and supports informed decision-making, thereby addressing a critical accessibility gap in existing privacy communication mechanisms.
This work addresses the lack of reproducible evaluation methodologies in decentralized identity (DI) and self-sovereign identity (SSI) systems, which stems from the failure to translate their core security and privacy principles into explicit functional requirements. For the first time, this study systematically operationalizes SSI principles through requirements engineering and formal modeling techniques, yielding a verifiable set of functional requirements and a comprehensive functional model that spans common use cases. The resulting requirements specification and formal model establish a foundational framework for DI/SSI system evaluation, thereby filling a critical gap in the current landscape and providing a rigorous basis for future system development and reproducible assessments.
This study addresses a critical gap in Privacy by Design (PbD) requirements engineering: the absence of an effective evaluation mechanism grounded in organizational objectives, which often leads to a misalignment between selected PbD methods and actual organizational goals. To bridge this gap, the authors propose a novel goal-oriented evaluation framework that shifts away from traditional process-centric paradigms by positioning organizational goals as a central dimension for assessing PbD approaches. Through an iterative process involving literature review, interviews with practitioners, and empirical validation, the framework was developed and refined. The research demonstrates the feasibility and practical utility of this approach, offering both theoretical grounding and actionable guidance for selecting, tailoring, and developing PbD methods aligned with organizational priorities.
This study addresses the persistent gap between citizen engagement and requirements engineering (RE) in large-scale socio-technical software systems within the public sector. To bridge this gap, we systematically integrate participatory civic platforms into the entire RE lifecycle—elicitation, negotiation, and validation—thereby proposing the first “Civic Platform–Requirements Engineering” (CP-RE) integration framework tailored for public-sector contexts. Methodologically, we combine participatory design, requirements negotiation modeling, multi-stakeholder traceability analysis, and qualitative case study research to develop an extensible conceptual model. Our key contributions include: (1) articulating the structural role of civic platforms in RE processes; (2) identifying their governance advantages, implementation risks, and contextual adaptation pathways; and (3) establishing a theoretical and methodological foundation for democratic, transparent, and inclusive governance of public software systems.
In software design, paradigm-implied semantic expectations—such as data abstraction consistency and feedback-control closed-loop behavior—are often left implicit, leading to design deviations and verification challenges. To address this, we introduce the concept of *design obligations*: explicit, logically formalizable, and verifiable specifications that codify such implicit constraints inherent to design paradigms. Leveraging formal modeling and paradigm semantics analysis, we establish two obligation frameworks—one for data-abstraction-based systems and another for feedback-driven adaptive systems—precisely capturing their core semantic requirements. We demonstrate that common design flaws stem from obligation violations and show how these obligations enable rigorous compliance verification and pedagogical application. This work bridges the semantic gap between design intent and implementation, providing both theoretical foundations and a methodological framework for paradigm-driven design assurance.
This study addresses the challenge of transforming stakeholder requirements into product requirements in software-driven automotive systems. Leveraging a dataset of 8,082 stakeholder requirements and 5,870 product requirements provided by Infineon, the research employs a hybrid methodology integrating structural statistics, decision modeling, traceability mining, textual analysis, and hardware-software linkage to systematically analyze the requirement refinement process. It reveals, for the first time, that requirement complexity primarily stems from ambiguous architectural scope and missing contextual information rather than linguistic redundancy. The work establishes a classification framework for mapping stakeholder to product requirements, identifies systematic differences across abstraction levels, and proposes key improvements in requirement validation, deviation management, and contextual tooling to support efficient and reusable automotive development.
In multi-stakeholder platforms, software architecture decisions often implicitly entrench conflicting requirements without systematic support for mapping governance principles to technical design. This work proposes the first governance-architecture alignment framework, explicitly linking five core governance principles to the space of architectural decisions, thereby rendering implicit governance stances identifiable and contestable. The framework also exposes how default technical choices can obscure underlying value commitments. Feasibility is preliminarily demonstrated through a constructive case study of a pig-farming knowledge platform in Rwanda. Future work will employ pre- and post-intervention user judgment studies to evaluate the framework’s impact on actual governance outcomes.
This work addresses the practical adoption barriers of Privacy-Enhancing Technologies (PETs), which stem from their technical complexity and the fragmentation among engineering, legal, and business perspectives. To bridge these disciplinary divides, the paper innovatively integrates multidisciplinary viewpoints into a systematic requirements engineering framework. By formally modeling and specifying the diverse needs of developers, integrators, and adopters, the proposed approach effectively aligns cross-domain concerns. The resulting requirements engineering–driven framework not only fills a critical gap in multidisciplinary collaboration for PET deployment but also substantially enhances the efficiency and regulatory compliance of integrating PETs into software systems.
研究探讨了在旧系统现代化过程中,仅依赖以利益相关者为中心的需求工程方法的局限性,并提出需要结合不确定性意识、迭代和基于证据的方法来解决新旧系统功能映射问题。
This work addresses the challenge of aligning real-world data processing practices in distributed systems with the purpose limitation principle under the General Data Protection Regulation (GDPR). To this end, it introduces the first formal framework that integrates multiparty session types with GDPR compliance. The approach models data processing purposes as structured interaction protocols among participants, employing a process calculus enriched with private data semantics to capture system behavior. A novel type system is developed to enforce subject reduction and purpose fidelity, ensuring that runtime execution strictly adheres to declared purposes. Formal verification guarantees alignment between stated purposes and actual behavior. The framework’s effectiveness is demonstrated through its application to a healthcare system case study, offering an engineering-oriented theoretical foundation for privacy-by-design.