<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Risk Identi cation of Tailorable Context-aware Systems: a Case Study and Lessons Learned?</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Mohammad Zari Eslami</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Brahmananda Sapkota</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alireza Zarghami</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Eelco Vriezekolk</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Marten van Sinderen</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Roel Wieringa</string-name>
          <email>r.j.wieringag@utwente.nl</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Department of Electrical Engineering, Mathematics and Computer Science University of Twente -</institution>
          <country country="NL">The Netherlands</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>In this paper, we discuss possible risks posed by the application of tailorable context-aware systems in real-life practices. We use a tailorable context-aware system in the homecare domain as a case study to identify and analyse such risks. Next, we discuss which of these risks can be generalized to the use of tailorable context-aware system in other contexts than homecare. This would help the users of such systems to prevent the risks and guide the design and implementation of them.</p>
      </abstract>
      <kwd-group>
        <kwd>Risks</kwd>
        <kwd>Tailorable context-aware systems</kwd>
        <kwd>Homecare</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>
        A context-aware system adapts its behavior based on a model of the user's
current context [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Such a context model is usuallyinferred from data of sensors
in the environment of the user. If the adaptation is not only based on the context
model, but also on user-de ned preferences and requirements, we call this a
Tailorable Context-aware (TC) System [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ].
      </p>
      <p>The use of TC systems can bring important bene ts in many domains. Such
bene ts include easier to use, more useful and personalized services, as a
consequence of proper consideration of the user's context and preferences. However,
TC systems can also introduce new or increased risks for the person or
organization using these systems. Such risks arise from assumptions that are made
during the design, and which are typical for this type of systems, namely: the
context model properly re ects reality, the tailoring is done correctly, and the
provided service (e.g., in the form of advice or instructions) is used as intended.</p>
      <p>
        It is therefore important to do a risk assessment of a TC system in relation to
the environment in which it will be used. Such an assessment may deliver useful
results for the design of the system and its introduction in the environment. So
far, risk assessment of context-aware systems has mainly focused on privacy and
security aspects [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ], whereas other aspects such as availability and accountability
have received much less attention [
        <xref ref-type="bibr" rid="ref4 ref8">8, 4</xref>
        ].
? This work is part of the IOP GenCom U-Care project(http://ucare.ewi.utwente.nl),
sponsored by the Dutch Ministry of Economic A airs under contract IGC0816.
      </p>
      <p>The goal of this paper is to make a rst step towards introducing risk
assessment concerning the availability and accountability aspects, as part of a
requirements engineering approach for TC systems. As a case study, we use the design
of a TC system in the homecare domain, where the system aims at supporting
independent living of elderly people in their private environment.</p>
      <p>
        There is an emerging trend in industrialised countries for using IT-based
care services such as health monitoring and coaching and medication reminder
to support independent living of elderly [
        <xref ref-type="bibr" rid="ref1 ref11 ref16 ref3">1, 3, 11, 16</xref>
        ]. The use of these services
can have several bene ts such as improving the quality of care, quality of life of
elderly, saving time of healthcare professionals and responding to the shortage of
quali ed sta . The European Council recognises improvement of patient safety
as one of the bene ts of using eHealth systems [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. However, IT-based care
services can also introduce new types of risks.
      </p>
      <p>
        The concept of risk has been de ned di erently in di erent domains [
        <xref ref-type="bibr" rid="ref10 ref15 ref5">15, 10,
5</xref>
        ]. However, there is a common understanding that risk is a combination of the
likelihood that an incident will occur and the impact of that incident. In our
work, we are not concerned with the quanti cation of likehood nor of impact.
Therefore, based on this common understanding, we de ne risk for TC systems
as: the possibility of an undesirable outcome of an incident (related to the
operation and/or use of the system). More speci cally, we de ne availability risk as:
the possibility of an undesirable out due to the unavailability of the system or
its services; and accountability risk as: the possibility of an undesirable outcome
due to the fact that no accountable actor can be found. Since risk is de ned
in terms of undesirable outcomes, we assume that there are stakeholders which
su er the undesirable outcomes. What constitutes a risk is therefore
stakeholderdependent. If stakeholder goals and requirements would change, we may have to
repeat the risk assessment.
      </p>
      <p>The rest of the paper is structured as follows. In Section 2, we describe our
research methodology and de ne the scope of the paper. In Section 3, we brie y
describe the case study with a TC system applied in homecare. In Section 4, we
present the results regarding the identi ed risk. Finally, in Section 5, we discuss
the lessons learned and conclude the paper.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Research Methodology</title>
      <p>
        The purpose of risk assessment is to gather necessary information so that
subsequent risk treatment decisions can be taken that are both e ective and e cient.
According to the ISO framework (ISO-31000), risk assessment consists of risk
identi cation, analysis and evaluation [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
      </p>
      <p>An essential step in risk identi cation is the identi cation of all stakeholders,
their goals and their interactions with the system. Any interaction (either
tailoring or using the system) that may lead to undesirable consequences for that
or another stakeholder will be listed as a risk. Thus, we execute the following to
reach the goal of the paper:
{ Identifying all stakeholders that use and interact with the system;
{ Describing the goals of stakeholders and their interactions with the system;
{ Identifying possible undesirable outcomes (risks) of these interactions;
{ Draw lessons learned for the general case of TC systems.</p>
      <p>
        One important assumption restricts the scope of the paper. We assume that
the TC system technically works as designed, i.e., risks due to malfunctioning
of internal components of the system (the risks caused by interactive
complexity [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]) are out of the scope of this paper. More speci cally, we are interested
only in risks arising from the interaction of stakeholders with the system.
3
      </p>
    </sec>
    <sec id="sec-3">
      <title>Description of the Case</title>
      <p>We performed our case study in a care-institution in the Netherlands. This
institution consists of residential blocks where elderly can live and receive care
services. We developed a tailorable IT-based homecare service platform to be
evaluated in this care institution. To analyse the existing situation, we
interviewed professional nurses who provide care services in this institution. The
purposes of the interviews was to gain insight in the commonly performed tasks
and the possible risks associated with these tasks.</p>
      <p>
        Providing Tailorable Context-Aware Homecare (TCH) services is one of the
required features of successful introduction of IT-based care services [
        <xref ref-type="bibr" rid="ref20 ref6">6, 20</xref>
        ]. Fig. 1
depicts a simple version of a TCH system. The motivation behind such system
is to support a care-giver to create a user-speci c service plan by using a
tailoring platform, which can be executed by a provisioning platform and satisfy the
individual needs and preference of a care-receiver. The detailed information on
creating the service plan using the tailoring platform and executing these service
plans by the provisioning platform are reported in our earlier works [
        <xref ref-type="bibr" rid="ref18 ref19">19, 18</xref>
        ].
      </p>
      <p>{ Care-receivers should be reminded to attach the blood pressure measurement
tool and measure the blood pressure themselves.
{ If the care-receivers ignore the reminder for attaching the measurement tool,
the second reminder should be sent after half an hour.
{ The message, number of its repetition and the modality can be personalized
based on individual requirements.</p>
      <p>{ If the measured value is high/low, the care-giver should be informed.
4</p>
    </sec>
    <sec id="sec-4">
      <title>Risk Assessment</title>
      <p>The type of the risks we are interested is caused by di erent stakeholders
participating in the homecare domain. To analyse these risks, we begin with the
identi cation of stakeholders in a homecare domain where care services are
provided both with and without using the TCH system. Then we identify a list of
possible risks in both situations, and their sources.
4.1</p>
      <sec id="sec-4-1">
        <title>Identi cation of Stakeholders</title>
        <p>The homecare domain is complex and involves various stakeholders with diverse
interests (e.g., insurance companies, government, etc.). Excluding the
stakeholders that fall outside the scope of the TCH system, we identi ed care-givers,
care-receivers and care centers as three main types of stakeholders.</p>
        <p>Anyone involved in providing care to the elderly (care-receivers), is
considered a care-giver. Those who can provide care or interact with elderly include:
professional nurses, informal care-givers and physicians. In this work, we
consider only professional nurses as the care-givers, because: a) care-receivers spend
most of their time with processional nurses while receiving care services in
comparison to other care-givers, and b) Professional nurses are the main care-givers
who interact with the TCH system to de ne service plans for care-receivers.</p>
        <p>Care centers are institutions who pay for the care-givers and provide
facilities to take care of the care-receivers. Care centers de ne medical protocols
providing guidelines for taking care of care-receivers, which should comply with
the national medical protocols de ned by the government. When carrying out
homecare tasks, care-givers must follow these medical protocols.</p>
        <p>As shown in Fig. 2, after introduction of the TCH system, four new types of
stakeholders appear in the homecare domain. These new types of stakeholders are
IT specialists, third-party service providers, infrastructure providers and hackers.</p>
        <p>An IT specialist is a person who can install, test, operate and maintain the
TCH system. IT specialists are responsible for de ning the treatment patterns
based on existing medical protocols and care-givers recommendations and re
ning them based on operational experiences and test results. Third-party service
providers own and manage services (such as blood pressure measurement,
location determination and medication dispensing services) which can be used and
composed by the TCH system to provide desired services to the care-receivers.
These providers are located outside the care center and their services are
accessible to other services through the Internet. Infrastructure providers are
responsible for providing the necessary infra services to realise the TCH system such
as the Internet and power supply. Hackers are individuals or organizations who
break into the TCH system and its network and violate its function.</p>
        <p>Pharmacy
Physician
Informal
Care-giver</p>
        <p>Professional</p>
        <p>Nurses</p>
        <p>Hackers</p>
        <p>IT Specialists</p>
        <p>TCH
System</p>
        <p>&gt;</p>
        <p>Third-party
Service Providers</p>
        <p>Care Centers</p>
        <p>Interact
Care-receivers
Infrastructure</p>
        <p>Providers
One of the bene ts of a TCH system, compared to the current way of
providing services, is the mitigation of existing risks that stakeholders, mainly
carereceivers and care-givers, are already dealing with. We identify these existing
risks and discuss whether the proposed TCH system can indeed mitigate them.
We also identify new risks that might be introduced due to use of a TCH system.
Existing Risks We interviewed care-givers to identify the common tasks
generally performed in the homecare domain. Based on the result of these interviews,
we identi ed the risks in the current situation and determined whether these can
possibly be decreased using a TCH system.</p>
        <p>
          { Forgetting to Treat Patients: The care-givers usually follow a routine
schedule in providing care services based on the medical protocols and
doctors advice, for example measuring blood pressure every morning right after
the care-receiver wakes up. However, it is likely that a care-giver forgets to
measure blood pressure for a speci c care-receiver or measures it late which
might result in unreliable readings. A TCH system can be used to remind a
care-receiver to attach the measurement tool whenever it is required.
{ Observation Error: The care-givers give reports about the situation of
the care-receivers to the doctors, family members, pharmacy, etc., based on
which the authorised stakeholders take appropriate actions. For example,
a doctor can prescribe new medication based on the current situation of
the care-receivers, then the pharmacy can provide it, and the care-giver
can give the medicine to the care-receivers. However, while measuring the
care-receivers vital signs such as blood pressure, the care-givers can make
mistakes in reading/writing of values, which can a ect the diagnosis made
by the doctor. A TCH system can automatically create a correct report
based on the measured data which is accessible by a doctor.
{ Action Error: The care-givers can make a mistake in providing care services
to the care-receivers. For example, a care-giver can provide a wrong medicine
to a care-receiver. A TCH system can be used to provide medication through
a digital dispenser lled with medicine by a pharmacy based on doctor's
prescription. We should take to account that there is still the possibility of
the pharmacy making a mistake when lling the medicine dispenser.
{ Overlooking the Medical Protocols: Nurses should follow the medical
protocols in providing care services, and are examined yearly to prove that
they still recall them. However, a care-giver may overlook these protocols and
make a wrong decision. A TCH system ensures the conformance of medical
protocols, because those protocols are embodied in the treatment patterns.
{ Con ict in Medication/Treatment: Care-receivers typically use
multiple medications which are prescribed by di erent specialists. A doctor may
prescribe a medicine without considering other prescribed medications that
can have negative e ects at other diseases/medicines. It is also common that
for a speci c disease, a doctors prescribes a new medicine, which has better
e ect, but without stopping the previously prescribed medicines. It is also
possible to have con ict in treatment. For example, a care-receiver can use
advise or treatment from di erent professionals, such as a family doctor,
hospital doctor and physiotherapist, which may in itself be correct, but not
optimal if used in combination. This risk can be easily detected by a TCH
system, if there are prede ned rules for con icting medicines/treatments.
Risks of Using the TCH System One of the key motivations for replacing
manual activities with automatic IT-based systems is human error reduction.
However, many practical experiences shows that in reality, automation may
produce new sources and types of errors [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ]. This is also true when a TCH system
is used in providing personalized IT-based homecare services. We identify the
following risks for each stakeholder that interacts with the TCH system.
{ Care-givers:
        </p>
        <p>Wrong Con guration: Setting the wrong values for the con guration
parameters, e.g., setting higher/lower values for the threshold of blood pressure.
Con icting Service Plans: Creating con icting service plans. An elderly
usually su er from a combination of diseases and hence, a care-giver may
ignore the suggestion from the system and potentially create con icting
service plans for the same care-receiver. For example, in a service plan
a care-receiver is asked to take his blood pressure at 8:00 AM while in
another service plan he is asked to take a walk at the same time.
Missing Service Plan: Forgetting to create a service plan for a care-receiver.
Too Little Information: The face-to-face communication will be decreased,
so care-giver's knowledge about care-receivers' situation will be limited.
{ Care-receivers:</p>
        <p>Cheating with the System: Lying to the system whenever a con rmation is
needed, for example, a care-receiver may lie about taking the medicine.
Increased Loneliness: Feeling lonely is a common issue among elderly people.</p>
        <p>This could get worse by using a TCH system.
{ IT Specialists:</p>
        <p>Inappropriate Treatment Patterns: Translating the medical protocols to
treatment patterns incorrectly or providing incomplete patterns. The
possibility of occurring this risk is very low, because this a one-time activity
(with minor changes per year) and the incompleteness or incorrectness
of the patterns can be detected easily during a testing phase.
{ Third-party Service Providers:</p>
        <p>Service Failures: Services provided by the third-party service providers may
not function or function improperly. These services such as the blood
pressure measurement service are outside the control of TCH system.
{ Infrastructure Providers:</p>
        <p>Data/Power Network Failures: The data/power network may go down.
{ Hackers:</p>
        <p>Malicious Action: The care-receiver data or con gured service plans may be
altered/stolen. In fact, we do not consider hackers as new source of risk,
since thieves can do the similar damage in the existing situation.
5</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>Discussion and Conclusions</title>
      <p>Context-awareness is becoming an important aspect of any information system.
We all can imagine what new features such a system can have: selection of
tting services and adapting system behavior and providing services tailored
to users' needs and preferences. However, such a context-aware system can raise
new risks because of unpredictable behavior. To the best of our knowledge, there
is a limited amount of research and information regarding what new risks and
challenges such a system can pose to its users. In this paper, we assume that the
context-aware system can perceive and process context information accurately
and in-time. In other words, we are only interested in undesired outcomes arising
from the interaction of the user/services with a context-aware system.</p>
      <p>
        In order to discuss the risks of TC systems, we need to clarify our
understanding of context and context-awareness. In the literature, there are a number
of de nitions for context, however it is still di cult to say what information is
context information and what is not. In this paper, we do not provide a new
de nition of context-awareness, but analyse context-aware systems and identify
their potential risks. We consider context as any information that can be used
to adapt the response of a system and add value to provided services for target
users. A context-aware system mainly performs context-triggered actions in the
form of 'If-then' rules to specify how the system should be adapted [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. We
discuss further the facts that can be generalised to any TC system.
5.1
      </p>
      <sec id="sec-5-1">
        <title>What Can Go Wrong in TC Systems?</title>
        <p>Since we are interested only in risks arising from the interaction with the
tailorable context-aware system, to be able to generalize the identi ed risks, rst we
should identify the main type of stakeholders who interact with the system. We
also discuss why they are the source of risks. Generalizing from our case study,
four types of stakeholders interact with the tailorable context-aware systems:
Developer (IT specialists in the case study): Designs and implements the system.</p>
        <p>Because of lack of domain knowledge, the developer can be the source of risks.
However, since a developer's action is not a frequent one, the impact of such
a risk is relatively low. Once the risk is identi ed, it can be xed and the
probability of occurring the same risk again remains low.</p>
        <p>Con gurator (Care-givers in the case study): Has enough domain knowledge
and con gures the system parameters and creates new services to satisfy
individual needs. Because of lack of IT knowledge, the con gurator can be
the source of risks. Since he uses the system frequently, the possibility of
same risks occurring repetitively is high.</p>
        <p>End-user (Care-receivers in the case study): Is a target user and bene ts from
the output of the system. Because of the lack of knowledge or interest about
the system, the end-user can be the source of risks. Even though an end-user
has higher rate of interaction with the system, since he usually performs the
same type of actions (such as con rmation of receiving a message/service),
possibility of same risks occurring repetitively is relatively low.</p>
        <p>Third-party Service Provider (Third-party providers in the case study):
Provides third-party services (services outside of the control of the system).
Because of the lack of amenability, the third-party service provider can be a
source of risks. Since his services have a higher rate of interaction with the
system, the possibility of same risks occurring repetitively is relatively high.
Based on the fact that the con gurator and third-party service provider are the
main sources of risks, we limit the types of risks which are caused by them.
Looking at the list of risks we identi ed for the homecare domain, in the following
we generalize risks which can occur in any tailorable context-aware systems.
Wrong Con guration Values: This type of risks occurs due to the tailorability
of the system. It is important to consider what can be tailored and what
not. This risk happens when a user puts a con guration value which is not
in the context model. For example, suppose that the location of a
carereceiver is modeled as only inside home and outside home. A care-giver may
insert a value at park as the location value. This type of risks can easily be
prevented by limiting the possible con guration values, e.g., by checking the
value against the model, decreasing the likelihood of this type of risk.
Con ict in a Task with Multiple Context Information: This type of risks occurs
due to bad reasoning of the system regarding a task with multiple context
information. The system should decide what to do based on context
information, however there will be a con ict if there are two di erent actions for
di erent context information. For example, a reminder should be sent to a
care-receiver mobile phone when he is outside home and based on another
reasoning he should not receive any reminder message on his phone when he
is with somebody. So if he is outside home and is accompanied by somebody,
there will be a con ict on sending the reminder message. Since this con ict
occurs in one task (for example sending a reminder), a context-aware
system can be designed in a way to detect such a con icts and inform user in
advance. This type of risks can be prevented by prioritizing the rules.
Con ict of Di erent Tasks: This type of risks occur because of performing
different tasks which are in con ict. For example, one task is to attach a blood
pressure measurement tool and the other task is to take a walk outside. Since
this risk occurs in di erent tasks, it is di cult to detect and prevent it.
Third-parties Service Failure: Service Oriented Architecture (SOA) is becoming
popular for designing IT-based systems. A SOA-based context-aware system
may utilize services o ered by di erent providers. There are usually Service
Level Agreements (SLAs) among the partners to assure the availability of the
services. However, in some domains like homecare, which is a safety critical
domain, relying on the SLAs may not fully compensate the risks that occur.</p>
        <p>The accountability aspects are mainly concerned with identifying the source
of the risks and ultimately making that source responsible. Unlike in existing
de nitions, we treated the accountability as a means of identifying the source
of risks (identifying where and how it can be xed). This treatment is realistic
because in the homecare domain, regardless of who is making a mistake, the care
center is accountable for any risks that arise to its customers.</p>
        <p>The risks due to wrong con guration values may lead to unavailability of
desired services because the wrong con guration values may cause the system to
behave di erently. This kind of risk can also be classi ed as the accountability
aspects, because the source of the risk can be traced back.</p>
        <p>The risks due to con ict of di erent tasks and the con ict in a task with
multiple context information may lead to providing undesired services, which
can be considered as unavailability of the desired services. It might be di cult
to exactly identify the source of risk and hence the accountability, because risk
occurs when a newly created task con icts with the existing one which might
have been con gured by a di erent con gurator.</p>
        <p>The risk due to third-parties service failure will lead to unavailability of
desired services. The source of the risk can be identi ed only in terms of service
providers, and accountability aspect should be considered in SLAs.
5.2</p>
      </sec>
      <sec id="sec-5-2">
        <title>What More is Needed?</title>
        <p>We have performed a rst assessment of risks of TC systems in general, and of
homecare systems in particular. This has led to a classi cation of availability and
accountability risks. This is new regarding the current risk assessment literature
of context-aware systems, which is mainly about security and privacy risks.</p>
        <p>There are some limitations to this study. We have done only one case study
and even in this study, we may not have found all available risks. We have
interviewed the care-givers about the tasks they perform, and then identi ed
the list of possible risks while they perform their tasks. However, there is a
possibility that the interviewees have forgotten important tasks and accordingly
important risks. Based on their explanation, we have listed possible risks and
there is a possibility that those risks are not real risks. In other cases, other
risks may exist too, that are not present in our investigated case. Despite these
limitations, we can still claim that we have found a list of possible risks. We
intend to do more case studies in the near future to identify the importance of
the risks as well as the completeness and correctness of the list of identi ed risks.</p>
        <p>Another aspect of future work is to further con rm and elaborate the risks
that we found for homecare systems. In addition, we would like to extend this
assessment towards requirements engineering, by incorporating the risk assessment
as a rst step in a requirements engineering process for homecare systems.</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1. Amigo:
          <article-title>Ambient intelligence for the networked home environment project (</article-title>
          <year>2008</year>
          ), available at: http://www.hitechprojects.com/euprojects/amigo
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Baldauf</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dustdar</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rosenberg</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          :
          <article-title>A Survey on Context-aware Systems</article-title>
          .
          <source>IJAHUC 2</source>
          (
          <issue>4</issue>
          ),
          <volume>263</volume>
          {
          <fpage>277</fpage>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Batet</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          , et al.:
          <article-title>Knowledge-driven Delivery of Home Care Services</article-title>
          . JIIS pp.
          <volume>1</volume>
          {
          <issue>36</issue>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Bellotti</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Edwards</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          :
          <article-title>Intelligibility and Accountability: Human Considerations in Context Aware Systems</article-title>
          .
          <source>HCI 16</source>
          ,
          <issue>193</issue>
          {
          <fpage>212</fpage>
          (
          <year>2001</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Du</surname>
            <given-names>us</given-names>
          </string-name>
          , J.,
          <string-name>
            <surname>Brown</surname>
          </string-name>
          , S.,
          <string-name>
            <surname>Fernicola</surname>
          </string-name>
          , N.:
          <article-title>Glossary for Chemists of Terms Used in Toxicology</article-title>
          .
          <source>Intl. Union of Pure and Applied Chemistry</source>
          <volume>65</volume>
          ,
          <year>2003</year>
          {
          <volume>2122</volume>
          (
          <year>1993</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <given-names>European</given-names>
            <surname>Commission</surname>
          </string-name>
          :
          <article-title>Ageing well in the information society - an i2010 initiative - action plan on info</article-title>
          .
          <source>and comm. tech. and ageing. Tech. rep.</source>
          ,
          <source>EU (Jun</source>
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Hong</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Suh</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kim</surname>
            ,
            <given-names>S.J.</given-names>
          </string-name>
          :
          <article-title>Context-aware Systems: A Literature Review and Classi cation</article-title>
          .
          <source>Expert Syst. Appl</source>
          .
          <volume>36</volume>
          (
          <issue>4</issue>
          ),
          <volume>8509</volume>
          {
          <fpage>8522</fpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Hussein</surname>
          </string-name>
          , M.,
          <string-name>
            <surname>Han</surname>
            ,
            <given-names>J</given-names>
          </string-name>
          .,
          <string-name>
            <surname>Colman</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Context-Aware Adaptive Software Systems: A System-Context Relationships Oriented Survey</article-title>
          .
          <source>Tech. rep. (</source>
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9. ISO:
          <article-title>Risk management { principles and guidelines</article-title>
          .
          <source>Intl. Std</source>
          .
          <volume>31000</volume>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10. ISO/IEC: IT {
          <article-title>Security Techniques { Guidelines for the Management of IT Security { Part 1: Concepts and Models for IT Security</article-title>
          . Intl. Std.
          <volume>13335</volume>
          -
          <fpage>1</fpage>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Korhonen</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Parkka</surname>
            , J., Van Gils,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Health Monitoring in the Home of the Future</article-title>
          .
          <source>Engineering in Medicine and Biology Magazine</source>
          , IEEE
          <volume>22</volume>
          (
          <issue>3</issue>
          ),
          <volume>66</volume>
          {
          <fpage>73</fpage>
          (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Leveson</surname>
            ,
            <given-names>N.G.</given-names>
          </string-name>
          : Engineering a Safer World: Systems Thinking Applied to Safety, p.
          <fpage>4</fpage>
          . To be published by MIT Press in Fall (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Schilit</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Adams</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Want</surname>
          </string-name>
          , R.:
          <article-title>Context-aware Computing Applications</article-title>
          .
          <source>In: Workshop on Mobile Computing Systems and Applications</source>
          . pp.
          <volume>85</volume>
          {
          <issue>90</issue>
          (
          <year>1994</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <article-title>The Council of The European Union: Council Conclusions on a Safe and E cient Healthcare through eHealth</article-title>
          .
          <source>In: O cial Journal of EU (December</source>
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <article-title>United Nations International Strategy for Disaster Reduction UN-ISDR: Terminology on disaster risk reduction</article-title>
          .
          <source>Geneva (May</source>
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>White</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          , et al.:
          <article-title>Improving Healthcare Quality through Distributed Diagnosis and Home Healthcare</article-title>
          .
          <source>In: Transdisciplinary Conference on D2H2</source>
          . pp.
          <volume>168</volume>
          {
          <issue>172</issue>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Wiener</surname>
            ,
            <given-names>E.L.</given-names>
          </string-name>
          :
          <article-title>Cockpit Automation</article-title>
          . In:
          <article-title>Human factors in aviation, Academic Press series in cognition and perception</article-title>
          . pp.
          <volume>433</volume>
          {
          <issue>461</issue>
          (
          <year>1988</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>Zarghami</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          , et al.:
          <article-title>Dynamic Homecare Service Provisioning Architecture</article-title>
          .
          <source>In: IEEE Conf. on SOCA</source>
          . pp.
          <volume>213</volume>
          {
          <issue>220</issue>
          (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <given-names>Zari</given-names>
            <surname>Eslami</surname>
          </string-name>
          ,
          <string-name>
            <surname>M.</surname>
          </string-name>
          , et al.:
          <article-title>Flexible Homecare Application Personalization and Integration Using Pattern-based Service Tailoring</article-title>
          . In: CIT. pp.
          <volume>467</volume>
          {
          <issue>474</issue>
          (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20.
          <string-name>
            <given-names>Zari</given-names>
            <surname>Eslami</surname>
          </string-name>
          , M.,
          <string-name>
            <surname>van Sinderen</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Flexible Home Care Automation</article-title>
          .
          <source>In: IEEE 3rd Intl. Conf. on PervasiveHealth</source>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>