This document describes a threat model for RDF and SPARQL.

Introduction

This document describes a threat model for RDF. As you can probably tell, it is very much work-in-progress. In this document, we use the visual languaged proposed in [[threat-modeling-guide]]. below present a global view of the threat model, which is explained step-by-step in the following sections.

See description in the caption.
Global view of the threat model. See .

Data Flow Description

See description in the caption.
Simple data exchange
TODO description of
See description in the caption.
Data integration
TODO description of
See description in the caption.
SPARQL-based processing
TODO description of

Dictionary

E1 Data Owner
TODO
E2 End User
TODO
E3 Developer
TODO
C1 Data Provider, C3 Data Provider 2
TODO
C2 Application
TODO
S1 Graph, S2 Graph, S3 Graph
TODO NB: should this says "dataset" instead? (noting that it could be either an RDF Graph or an RDF Dataset)
P1 Serialize, P4 Serialize
TODO
P2 Parse
TODO
P3 Process
TODO
P5 Query
TODO
P6 Update
TODO
P7 Client
TODO
P8 Query/Update
TODO

Stakeholders

TODO

Threats

TODO import here threats from various "Security & Privacy Considerations" sections