Maribor - Photo by Jernej Furman on Wikipedia Commons (modified)

The 15th IFIP Summer School on Privacy and Identity Management was originally planned to take place in Brno, Czech Republic. Due to the COVID-19 pandemic, it was ultimately held as a fully virtual event and was co-located with IFIP SEC 2020 and WISE 13.

The Summer School was a joint effort among IFIP Working Groups 9.2, 9.6/11.7 and 11.6, and Special Interest Group 9.2.2, in cooperation with the European Union cybersecurity competence network pilot projects CyberSec4Europe, SPARTA and CONCORDIA.

Proceedings

The revised selected papers were published by Springer in 2021 as volume 619 of the IFIP Advances in Information and Communication Technology series and can be found here.

Call For Papers

The 2020 Summer School welcomed interdisciplinary contributions in Privacy and Identity Management. Contributions combining anthropological, economic, ethical, historical, legal, media and communication, regulatory, sociological, surveillance, technical, philosophical, political and psychological perspectives were explicitly encouraged.

The Summer School also encouraged broader diversity, including contributions on fostering gender and cultural balance in cybersecurity research and policy, as well as tutorials and workshops aimed at raising awareness of these matters.

Submission and Review Process

The research paper presentations and workshops focused on involving students and encouraging the publication of high-quality, thorough research papers by students and young researchers. The Summer School used a three-phase process:

  • Authors first submitted an abstract of at most 2 pages. Submissions within the scope of the call were selected for presentation at the Summer School.
  • Authors of accepted abstracts submitted a full paper of up to 16 pages in Springer LNCS format before the Summer School. These versions appeared in unreviewed pre-proceedings.
  • Following the Summer School, authors had the opportunity to revise their papers based on the discussions at the event. The revised full papers were reviewed by members of the Programme Committee and could be accepted, conditionally accepted or rejected for inclusion in the Springer post-proceedings.

Submissions had to be in English and were submitted electronically. The original submission link is no longer active.

Possible Topics

Topics included, but were not limited to:

  • Technical and Organizational Measures for Privacy and Security
    • by-design and default mechanisms for privacy, value-sensitivity, ethics, human rights, impact and risk assessments, and data protection on the ground
    • data breach notification and its side effects
    • integration of privacy and security into agile development
    • privacy-enhancing technologies (PETs) and transparency-enhancing technologies (TETs)
    • privacy and identity management, including services, technologies, infrastructures, usability aspects, and legal and socio-economic aspects
    • privacy and security in citizens’ digital communications, online platforms, e-mail and instant messaging
    • usable privacy and security
  • Metrics, Standards, Ethics and Norms
    • complementarity and friction between data subject rights, security and privacy by design
    • compliance, overlaps and conflicts between cybersecurity and data protection norms, including the NIS Directive, GDPR, PSD2 and the upcoming ePrivacy Regulation
    • privacy and security evaluation, metrics, certifications, certification mechanisms, auditing experiences, standards and seals
    • privacy protection and confidentiality of communications by traditional providers and over-the-top media services
    • regulatory regimes and instruments, including ethical frameworks
  • Training and Education for Privacy and Security
    • awareness-raising, digital literacy and data infrastructure literacy
    • research ethics and approvals
    • social accountability
    • training and education methodologies and cyber ranges
  • Socio-technical Perspectives on Privacy and Data Protection
    • awareness, attitudes, skills and behaviour of citizens and organisations, including SMEs, regarding data privacy, surveillance and cybersecurity
    • integrative approaches for diversity, including gender, accessibility and economics
    • relations between privacy, public values and AI-based systems, and their global consequences for policy and society
    • socio-cultural practices, perspectives and (dis)trust concerning data-driven technologies and data capture and processing in areas such as health, smart cities, banking, media and education

Why should I submit?

Accepted papers received thorough discussions during the Summer School and gave students an opportunity to publish their work in the IFIP AICT series by Springer.

Students who participated in IFIP SEC throughout, presented their work and submitted a participation report could receive a course certificate corresponding to 3 ECTS credits at PhD level. Students whose papers were already at full submission length and of sufficient quality for a PhD seminar thesis could receive a certificate corresponding to 6 ECTS credits at PhD level.

Participants acting as opponents were assigned to a speaker in their session. The opponent opened the discussion after the presentation and prepared a three-page report reviewing the speaker’s full paper and relating it to other contributions at the conference.

Important Dates

All dates are AoE (anywhere on earth).

Event Deadline
Abstracts Deadline: 15 Jun 2020 23:59 (AoE)
Acceptance Decision: Not later than 05 Jul 2020 (AoE)
Full Draft Paper: 14 Sep 2020 23:59 (AoE)
Summer School: 20-23 Sep 2020
Full Paper: 17 Oct 2020 23:59 (AoE)
Reviews: 25 Nov 2020 (AoE)
Camera Ready: 15 Dec 2020 (AoE)

Program

Because of the COVID-19 pandemic, the 2020 Summer School was held entirely online and was co-located with IFIP SEC 2020 and WISE 13. The original conference programme interleaved sessions from all three events. The programme below contains only the sessions of the IFIP Summer School on Privacy and Identity Management. The complete integrated programme is available on the IFIP SEC 2020 website.

All times are Central European Summer Time (CEST).

IFIP Summer School 2020 Programme at a Glance

Monday, September 21, 2020

Time IFIP Summer School
10:30-12:00 Session 1 - Pattern and models
Chair: Stefan Schiffner

Introduction to the Summer School

Michael Toth
Influence of “Dark Patterns” on Opting-out in Cookie Banner Design

Ahad Niknia and Sebastian Pape
A Serious Game on the GDPR, and Privacy and Security Awareness
16:00-17:30 Session 2 - Societal Impact
Chair: Michael Friedewald

Thao Ngo, Ina Rentemeister and Nicole Krämer
What is the Role of Control over Personal Information for Privacy Cynicism and Personal Data Disclosure?

Samuel Wairimu
e-Health as a target in Cyberwar: Expecting the worst

Fredrik Heiding
The ethics of ethical hacking - abstract

Tuesday, September 22, 2020

Time IFIP Summer School
11:00-12:00 Session 3 - Applications of differential privacy
Chair: Stefan Schiffner

Héber H. Arcolezi, Jean-François Couchot, Béchara Al Bouna and Xiaokui Xiao
Combination of differential privacy mechanisms for continuous collection of mobile data

Peter Franke, Michael Kreutzer and Hervais Simo Fhom
Privacy-preserving IDS for In-Car-Networks with Local Differential Privacy
13:00-14:30 Session 4 - Electronic payments
Chair: Stephan Krenn

Danaja Fabcic
Security in e-payments: two-factor authentication under PSD2 and GDPR

Frédéric Tronnier
Privacy in Payment in the Age of Central Bank Digital Currency

Peter Hamm
An Evaluation of the Trust Assumptions and Privacy Guarantees of Electronic Payment Systems
16:00-17:30 Session 5 - Human Factors and Education
Chair: Robin Pierce

Lejla Islami, Simone Fischer-Hübner, Eunice Naa Korkoi Hammond and Jan Eloff
Analysing drivers’ preferences for privacy enhancing car-to-car communication systems

Marvin Priedigkeit, Andreas Weich and Ina Schiering
Learning Analytics and Privacy - Respecting Privacy in Digital Learning Scenarios

Wednesday, September 23, 2020

Time IFIP Summer School
10:00-11:30 Session 6 - Identity Protection
Chair: Stephan Krenn

Tamara Stefanovic and Silvia Ghilezan
Preserving Privacy in Caller ID applications

Anne Steinbrueck
“Identity management by design” with a technical Mediator under the GDPR

Shirin Kalantari
Open about the open-rate? State of email tracking and its effects on user’s privacy
12:00-13:30 Session 7 - Tutorial & Lecture
Chair: Stefan Schiffner

Sandra Schmitz and Stefan Schiffner
Don’t Tell Them now (or at all) - End User Notification Duties under GDPR and NIS Directive

Marit Hansen, Data Protection Supervisor Schleswig-Holstein, ULD, Kiel, Germany
Privacy-Enhancing Technologies - where are we after 25 years?
14:00-15:30 Session 8 - Privacy Friendly Data Sharing
Chair: Michael Friedewald

Michael Pleger and Ina Schiering
Privacy Respecting Data Sharing and Communication in mHealth: A Case Study

Karl Koch, Stephan Krenn, Donato Pellegrino and Sebastian Ramacher
Privacy-preserving Analytics for Data Markets

Next steps and farewell

Keynote Speaker

Marit Hansen

ULD, State Data Protection Authority of Schleswig-Holstein, Germany

Privacy-Enhancing Technologies - where are we after 25 years?

Tutorial

Sandra Schmitz and Stefan Schiffner
Don’t Tell Them now (or at all) - End User Notification Duties under GDPR and NIS Directive

Committees

General Chair

  • Stephan Krenn (🇦🇹 AIT Austrian Institute of Technology)

Programme Chairs

  • Michael Friedewald (🇩🇪 Fraunhofer ISI)
  • Stefan Schiffner (🇱🇺 University of Luxembourg)

Organizing Committee

  • Gloria González Fuster (🇧🇪 Vrije Universiteit Brussel)
  • Váshek Matyáš (🇨🇿 Masaryk University)

Steering Committee

  • Jan Camenisch (🇨🇭 Dfinity)
  • Marit Hansen (🇩🇪 ULD)
  • Anja Lehmann (🇨🇭 IBM Research – Zürich)
  • Ronald Leenes (🇳🇱 Tilburg University)
  • Simone Fischer-Hübner (🇸🇪 Karlstad University)
  • Diane Whitehouse (🇬🇧 The Castlegate Consultancy)
  • Charles Raab (🇬🇧 University of Edinburgh)
  • Kai Rannenberg (🇩🇪 Goethe University Frankfurt)

Programme Committee

  • Florian Adamsky (🇩🇪 University of Applied Sciences Hof)
  • Daniel Bachlechner (🇦🇹 Fraunhofer Austria)
  • Felix Bieker (🇩🇪 Independent Centre for Privacy Protection Schleswig-Holstein)
  • Mauro Brignoli (🇮🇹 Vitrociset S.p.A.)
  • Sonja Buchegger (🇸🇪 KTH Royal Institute of Technology)
  • Sébastien Canard (🇫🇷 Orange Labs)
  • Pavel Čeleda (🇨🇿 Masaryk University)
  • Josep Domingo-Ferrer (🇪🇸 Universitat Rovira i Virgili)
  • Orhan Ermiş (🇫🇷 Eurecom)
  • Simone Fischer-Hübner (🇸🇪 Karlstad University)
  • Pedro Freitas (🇵🇹 University of Minho)
  • Michael Friedewald (🇩🇪 Fraunhofer ISI)
  • Lothar Fritsch (🇸🇪 Karlstad University)
  • Gloria González Fuster (🇧🇪 Vrije Universiteit Brussel)
  • Jan Hajný (🇨🇿 Brno University of Technology)
  • Dominik Herrmann (🇩🇪 University of Bamberg)
  • Meiko Jensen (🇩🇪 Kiel University of Applied Sciences)
  • Stefan Katzenbeisser (🇩🇪 University of Passau)
  • Kai Kimppa (🇫🇮 University of Turku)
  • Stephan Krenn (🇦🇹 AIT Austrian Institute of Technology)
  • Eva Lievens (🇧🇪 Ghent University)
  • Lukáš Malina (🇨🇿 Brno University of Technology)
  • Ninja Marnau (🇩🇪 CISPA Helmholtz Center for Information Security)
  • Váshek Matyáš (🇨🇿 Masaryk University)
  • Joachim Meyer (🇮🇱 Tel Aviv University)
  • Andreas Nautsch (🇫🇷 Eurecom)
  • Sebastian Pape (🇩🇪 Goethe University Frankfurt)
  • Aljosa Pasic (🇪🇸 Atos Research & Innovation)
  • Robin Pierce (🇳🇱 Tilburg University)
  • Jo Pierson (🇧🇪 Vrije Universiteit Brussel)
  • Tobias Pulls (🇸🇪 Karlstad University)
  • Kjetil Rommetveit (🇳🇴 University of Bergen)
  • Arnold Roosendaal (🇳🇱 The Privacy Company)
  • Ina Schiering (🇩🇪 Ostfalia University of Applied Sciences)
  • Stefan Schiffner (🇱🇺 University of Luxembourg)
  • Valerie Verdoodt (🇬🇧 London School of Economics)
  • Diane Whitehouse (🇬🇧 The Castlegate Consultancy)
  • Marc van Lieshout (🇳🇱 Radboud University)
  • Simone van der Hof (🇳🇱 Leiden University)
  • Rose-Mharie Åhlfeldt (🇸🇪 University of Skövde)
  • Melek Önen (🇫🇷 Eurecom)

Venue

The Summer School was originally planned for Brno, Czech Republic. Following changes caused by the COVID-19 pandemic, it was co-located with IFIP SEC 2020 in Maribor, Slovenia, and ultimately held as a fully virtual event.

Registration

The 2020 event was online only. Registration for the co-located events was handled through the IFIP SEC 2020 registration system.

Registration type Early registration
until 15 Aug 2020
Late registration
until 15 Sep 2020
IFIP Summer School - presenting author (online) 100 € 150 €
Attendee online - not presenting author 100 € 150 €

For Summer School presenting authors, the fee included attendance at the online sessions of IFIP SEC 2020, WISE 13 and the IFIP Summer School, as well as the Summer School post-proceedings published by Springer. For non-presenting online attendees, the fee included attendance at the online sessions of all three co-located events.

Registration to this event is no longer possible.

Organizers

In cooperation with

IFIP

Supporters

The 15th IFIP Summer School was held in cooperation with the European Union’s cybersecurity competence network pilot projects CyberSec4Europe, SPARTA and CONCORDIA.

CyberSec4Europe SPARTA CONCORDIA