首页> 外文会议>Information Security and Privacy >A Novel Use of RBAC to Protect Privacy in Distributed Health Care Information Systems
【24h】

A Novel Use of RBAC to Protect Privacy in Distributed Health Care Information Systems

机译:RBAC在分布式医疗信息系统中保护隐私的一种新颖用法

获取原文

摘要

This paper examines the access control requirements of distributed health care information networks. Since the electronic sharing of an individual's personal health information requires their informed consent, health care information networks need an access control framework that can capture and enforce individual access policies tailored to the specific circumstances of each consumer. Role Based Access Control (RBAC) is examined as a candidate access control framework. While it is well suited to the task in many regards, we identify a number of shortcomings, particularly in the range of access policy expression types that it can support. For efficiency and comprehensibility, access policies that grant access to a broad range of entities whilst explicitly denying it to subgroups of those entities need to be supported in health information networks. We argue that RBAC does not support policies of this type with sufficient flexibility and propose a novel adaptation of RBAC principles to address this shortcoming. We also describe a prototype distributed medical information system that embodies the improved RBAC model.
机译:本文研究了分布式医疗信息网络的访问控制要求。由于个人的个人健康信息的电子共享需要他们的知情同意,因此医疗保健信息网络需要访问控制框架,该框架可以捕获并执行针对每个消费者的特定情况量身定制的个人访问策略。基于角色的访问控制(RBAC)被视为候选访问控制框架。尽管它在很多方面都非常适合该任务,但是我们发现了许多缺点,特别是在它可以支持的访问策略表达类型范围内。为了提高效率和可理解性,需要在健康信息网络中支持授予访问范围广泛的实体,同时明确拒绝这些实体的子组访问的访问策略。我们认为RBAC不能以足够的灵活性支持这种类型的政策,因此建议对RBAC原则进行新颖的修改以解决这一缺点。我们还描述了体现改进的RBAC模型的原型分布式医疗信息系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号