首页> 外文会议>International Conference on Advanced Communication Technology >A Secure and Flexible e-Health Access Control System with Provisions for Emergency Access Overrides and Delegation of Access Privileges
【24h】

A Secure and Flexible e-Health Access Control System with Provisions for Emergency Access Overrides and Delegation of Access Privileges

机译:安全且灵活的电子健康访问控制系统,具有用于紧急访问覆盖和访问权限委派的规定

获取原文

摘要

Protecting electronic health records (EHR) from unauthorized access and data breaches has been a great challenge for healthcare organizations in recent times. Controlling access to EHR demands a delicate balance between security and flexibility: There are emergency cases where the default access control policy must be circumvented in order to save patients' life - and cases where management of access control rights needs to be delegated to some trusted parties. Therefore, e-Health access control systems must be robust and flexible at the same time. Conventional general-purpose access control schemes like role-based access control (RBAC) and its derivatives emphasize mainly on the robustness of the access control mechanism, and treat flexibility issues like emergency access overrides and delegation management as addenda. However, in order to comply with the care first principle of the healthcare domain, an ideal e-Health access control system should consider such flexibility issues from the ground up. Recognizing these special requirements mandated by the very nature of the healthcare profession, in this paper, we propose a secure and flexible access control system for e-Health. The userrole and object-operation mappings in our proposed system lend themselves to the RBAC model, and we implemented context verification atop this layer in order for the system to make access decision responsive to emergency incidents. For managing delegation of access control rights, we developed a secure mechanism for creation, transfer and verification of a delegation token, presentation of which to the access control system enables a delegatee to access a delegator's EHR. Every access request in our system is preceded by mandatory user authentication which we implemented using eTRON tamper-resistant cards. Security and performance analysis of the proposed system showed promising results for achieving the desired level of balance between security and flexibility required for an e-Health access control system.
机译:保护电子卫生记录(EHR)从未经授权的访问和数据泄露中对医疗组织来说是一个巨大的挑战。控制访问EHR的访问要求安全性和灵活性之间的微妙平衡:必须避免默认访问控制策略的紧急情况,以便拯救患者的生命和访问控制权的管理需要授权给一些可信任的缔约方。因此,电子健康访问控制系统必须同时坚固且灵活。传统的通用访问控制方案,如基于角色的访问控制(RBAC)及其衍生物主要强调了访问控制机制的稳健性,并处理紧急访问覆盖和委派管理等灵活性问题作为附加物。但是,为了遵守医疗领域的护理第一原理,理想的电子健康访问控制系统应考虑从头开始的这种灵活性问题。在本文中,认识到由医疗保健专业的本质要求的这些特殊要求,我们提出了一种安全灵活的电子健康检修控制系统。我们提出的系统中的Userrole和对象映射为RBAC模型提供了借助RBAC模型,并且我们在该图层中实现了上下文验证,以便系统响应于紧急事件的访问决策。为了管理访问控制权限的委派,我们开发了一个安全的机制,用于创建,传输和验证委托令牌,呈现到访问控制系统的呈现使得代表人能够访问委托人的EHR。我们系统中的每一个访问请求都是由我们使用etron防篡改卡实现的强制性用户身份验证。建议系统的安全性和性能分析表明,在电子卫生访问控制系统所需的安全性和灵活性之间实现所需的平衡水平。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号