首页> 外文会议>2011 IEEE 13th International Conference on e-Health Networking, Applications and Services >A standard-driven communication protocol for disconnected clinics in rural areas
【24h】

A standard-driven communication protocol for disconnected clinics in rural areas

机译:针对农村地区断开诊所的标准驱动通信协议

获取原文

摘要

The importance of the Electronic Health Record (EHR), which stores all healthcare-related data belonging to a patient, has been recognized in recent years by governments, institutions, and industry. Initiatives like Integrating the Healthcare Enterprise (IHE) have been developed for the definition of standard methodologies for secure and interoperable EHR exchanges among clinics and hospitals. Using the requisites specified by these initiatives, many large-scale projects have been set up to enable healthcare professionals to handle patients' EHRs. Applications deployed in these settings are often considered safety-critical, thus ensuring such security properties as confidentiality, authentication, and authorization is crucial for their success. In this paper, we propose a communication protocol, based on the IHE specifications, for authenticating healthcare professionals and assuring patients' safety in settings where no network connection is available, such as in rural areas of some developing countries. We define a specific threat model, driven by the experience of use cases covered by international projects, and prove that an intruder cannot cause damages to the safety of patients and their data by performing any of the attacks falling within this threat model. To demonstrate the feasibility and effectiveness of our protocol, we have fully implemented it.
机译:近年来,电子病历(EHR)的重要性已得到政府,机构和行业的认可,该病历存储着属于患者的所有医疗保健相关数据。已经开发了诸如整合医疗保健企业(IHE)之类的举措,以定义用于在诊所和医院之间进行安全且可互操作的EHR交换的标准方法。使用这些计划指定的条件,已经建立了许多大型项目,以使医疗保健专业人员能够处理患者的EHR。在这些设置中部署的应用程序通常被认为对安全性至关重要,因此确保诸如机密性,身份验证和授权之类的安全性对于它们的成功至关重要。在本文中,我们提出了一种基于IHE规范的通信协议,用于在没有网络连接的环境中(例如在某些发展中国家的农村地区)对医疗保健专业人员进行身份验证并确保患者的安全。我们根据国际项目涉及的使用案例的经验来定义特定的威胁模型,并证明入侵者不会通过执行属于该威胁模型的任何攻击来对患者及其数据的安全造成损害。为了证明我们协议的可行性和有效性,我们已经完全实施了它。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号