IPTM: An Integrated Privacy Threat Modelling Framework for Wearable Health Devices Combining STRIDE, LINDDUN, and Privacy Impact Assessment — A Design-Science Proposal and Evaluation Protocol.

  • Unique Paper ID: 206664
  • Volume: 13
  • Issue: 2
  • PageNo: 2476-2481
  • Abstract:
  • Wearable health devices (WHDs) sit at the intersection of security threat modelling, privacy threat modelling, and regulatory compliance assessment, yet a companion review of the literature finds no published, empirically validated method that integrates STRIDE, LINDDUN, and Privacy Impact Assessment (PIA) into a single workflow for this domain. This paper proposes the Integrated Privacy Threat Modelling (IPTM) framework to close that gap. IPTM is a design-science artefact comprising four components: a unified data-flow representation capable of treating continuous biometric telemetry as a first-class modelling object; a threat-elicitation layer that runs STRIDE and LINDDUN categories against this representation in parallel rather than sequentially; an explicit GDPR Article 22 automated-decisionmaking threat category bridging the technical and regulatory layers; and a tiered PIA-compliance scoring module that maps elicited threats directly onto specific GDPR articles. Following the principles of design-science research, we specify IPTM’s architecture and worked threat-elicitation procedure in full, and we specify a concrete, falsifiable evaluation protocol — a representative WHD use case, an expert-evaluation procedure, a comparative threat-coverage metric against the three standalone frameworks, and defined usability and compliance-mapping outcome measures — by which IPTM’s central claims should be tested. Consistent with its current design-stage status, no expert evaluation or comparative threat-coverage result is reported in this paper; we close with a candid assessment of which IPTM components are well supported by precedent in the literature and which rest on an as-yet-untested integration assumption.

Copyright & License

Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.

BibTeX

@article{206664,
        author = {CHINONSO JOB and ONWE, FESTUS CHIJIOKE and OKORO FAVOUR NGOZI and NDUBUISI MATTHEW UHUO and NWOJIJI TITUS UCHENNA},
        title = {IPTM: An Integrated Privacy Threat Modelling Framework for Wearable Health Devices Combining STRIDE, LINDDUN, and Privacy Impact Assessment — A Design-Science Proposal and Evaluation Protocol.},
        journal = {International Journal of Innovative Research in Technology},
        year = {2026},
        volume = {13},
        number = {2},
        pages = {2476-2481},
        issn = {2349-6002},
        url = {https://ijirt.org/article?manuscript=206664},
        abstract = {Wearable health devices (WHDs) sit at the intersection of security threat modelling, privacy threat modelling, and regulatory compliance assessment, yet a companion review of the literature finds no published, empirically validated method that integrates STRIDE, LINDDUN, and Privacy Impact Assessment (PIA) into a single workflow for this domain. This paper proposes the Integrated Privacy Threat Modelling (IPTM) framework to close that gap. IPTM is a design-science artefact comprising four components: a unified data-flow representation capable of treating continuous biometric telemetry as a first-class modelling object; a threat-elicitation layer that runs STRIDE and LINDDUN categories against this representation in parallel rather than sequentially; an explicit GDPR Article 22 automated-decisionmaking threat category bridging the technical and regulatory layers; and a tiered PIA-compliance scoring module that maps elicited threats directly onto specific GDPR articles. Following the principles of design-science research, we specify IPTM’s architecture and worked threat-elicitation procedure in full, and we specify a concrete, falsifiable evaluation protocol — a representative WHD use case, an expert-evaluation procedure, a comparative threat-coverage metric against the three standalone frameworks, and defined usability and compliance-mapping outcome measures — by which IPTM’s central claims should be tested. Consistent with its current design-stage status, no expert evaluation or comparative threat-coverage result is reported in this paper; we close with a candid assessment of which IPTM components are well supported by precedent in the literature and which rest on an as-yet-untested integration assumption.},
        keywords = {Privacy threat modelling, LINDDUN, STRIDE, Privacy Impact Assessment, wearable health devices, GDPR, design science research, health IoT.},
        month = {July},
        }

Cite This Article

JOB, C., & CHIJIOKE, O. F., & NGOZI, O. F., & UHUO, N. M., & UCHENNA, N. T. (2026). IPTM: An Integrated Privacy Threat Modelling Framework for Wearable Health Devices Combining STRIDE, LINDDUN, and Privacy Impact Assessment — A Design-Science Proposal and Evaluation Protocol.. International Journal of Innovative Research in Technology (IJIRT). https://doi.org/doi.org/10.64643/IJIRTV13I2-206664-459

Related Articles