首页> 外文会议>International Conference on Information Assurance and Security >Reconciling IHE-ATNA profile with a posteriori contextual access and usage control policy in healthcare environment
【24h】

Reconciling IHE-ATNA profile with a posteriori contextual access and usage control policy in healthcare environment

机译:在医疗环境中重新调整IHE-ATNA简档,并在医疗环境中进行后验语文访问和使用控制政策

获取原文

摘要

Traditional access control mechanisms prevent illegal access by controlling access right before executing an action; they belong to a class of a priori security solutions and, from this point of view, they have some limitations, like inflexibility in unanticipated circumstances. By contrast, a posteriori mechanisms enforce policies not by preventing unauthorized access, but rather by deterring it. Such access control needs evidence to prove violations. Evidence is derived from one or several log records, which trace each user's actions. Efficiency of violation detection mostly depends on the compliance of log records with the access control policy. In order to develop an efficient method for finding these violations, we propose restructuring log records according to a security policy model. We illustrate our methodology by applying it to the healthcare domain, taking care of the IHE (Integrating the healthcare enterprise) framework, particularly its basic security profile, ATNA (Audit Trail and Node Authentication). This profile defines log records established on the analysis of common health practice scenarios. We analyze and establish how ATNA log records can be refined in order to be integrated into an a posteriori access and usage control process, based on an expressive and contextual security policy like the OrBAC policy.
机译:传统的访问控制机制防止在执行动作之前通过控制访问来防止非法访问;它们属于一类先验的安全解决方案,并且从这个角度来看,它们有一些限制,如在意外情况下的不灵活性。相比之下,后验机制不是通过防止未经授权的访问来实施策略,而是通过阻止它来实现策略。这种访问控制需要证据证明违规行为。证据来自一个或多个日志记录,它跟踪每个用户的操作。违规检测效率主要取决于日志记录与访问控制策略的符合。为了开发有效的方法来查找这些违规行为,我们提出根据安全策略模型重组日志记录。我们通过将其应用于医疗领域,照顾IHE(整合医疗保健企业)框架,特别是其基本安全配置文件,ATNA(审计跟踪和节点认证)来说明我们的方法。此配置文件定义了在分析常见健康实践方案上建立的日志记录。我们分析并建立如何改进ATNA日志记录,以便基于ORBAC策略等表达和上下文安全策略集成到后验和使用控制过程中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号