首页> 外文会议>International conference on future data and security engineering >An Enhancement of the Rew-XAC Model for Workflow Data Access Control in Healthcare
【24h】

An Enhancement of the Rew-XAC Model for Workflow Data Access Control in Healthcare

机译:用于医疗保健工作流数据访问控制的Rew-XAC模型的增强

获取原文

摘要

The Rew-XAC model, based on Extensible Access Control Markup Language (XACML) 3.0, has been developed to solve the problem in the case that requests receive "Not Applicable " responses from the policy decision point (PDP). According to the most applicable policy that has the best score computed by a fuzzy function, the Rew-XAC model carried out rewriting the request. However, an important issue not addressed yet in the Rew-XAC model is that there has more than one policy with the same highest fuzzy value. In this paper, we propose an enhancement that assigns a union operator for all resource filter expressions produced from the related modules in the Rew-XAC model for each selected policy to the rewritten request. Besides, we demonstrate the potential of our model through analyzing the complex security requirements for a case study in the healthcare domain, and then propose a mechanism integrated with the proposed model to support access control for workflow data. We also perform an experiment using the dataset of policies in the case study to verify the feasibility of our approach in the healthcare domain that needs the data-protection rigorously complying with the regulations.
机译:已经开发了基于可扩展访问控制标记语言(XACML)3.0的Rew-XAC模型,以解决请求从策略决策点(PDP)收到“不适用”响应的情况下的问题。根据具有通过模糊函数计算出的最佳分数的最适用策略,Rew-XAC模型进行了重写请求。但是,Rew-XAC模型中尚未解决的一个重要问题是,存在多个具有相同最高模糊值的策略。在本文中,我们提出了一项增强功能,该功能为Rew-XAC模型中的每个选定策略向重写请求分配了从Rew-XAC模型中的相关模块生成的所有资源过滤器表达式的并运算符。此外,我们通过分析医疗领域中案例研究的复杂安全要求来证明我们模型的潜力,然后提出一种与提出的模型集成的机制来支持工作流数据的访问控制。我们还使用案例研究中的策略数据集进行了实验,以验证我们的方法在需要严格遵守法规数据保护的医疗保健领域的可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号