首页> 外文会议>International conference on information systems >An Activity Theory Approach to Specification of Access Control Policies in Transitive Health Workflows
【24h】

An Activity Theory Approach to Specification of Access Control Policies in Transitive Health Workflows

机译:传递卫生工作流中访问控制策略规范的活动理论方法

获取原文

摘要

Access control models are implemented to mitigate the risks of unauthorized access in Electronic Health Records (EHRs). These models provide authorization with the help of security policies, wherein the protected resource is governed by one or more policies that exactly specify what attributes a requester needs to fulfill in order to obtain access. However, due to the increasing complexity of current healthcare system, defining and implementing policies are becoming more and more difficult. In this research-in-progress paper, we present an Activity Theory driven methodology to formalize access control policies that can be used in enforcing patient's privacy consent in a healthcare setting. In order to account for the transitivity in health workflows, we extend the Activity Theory to include "organizational interconnectedness" within the health workflows.
机译:实施访问控制模型以减轻电子病历(EHR)中未经授权访问的风险。这些模型在安全策略的帮助下提供授权,其中受保护的资源由一个或多个策略控制,这些策略精确地指定了请求者需要实现哪些属性才能获得访问权限。但是,由于当前医疗保健系统的复杂性越来越高,因此定义和实施策略变得越来越困难。在这篇进行中的研究论文中,我们提出了一种由活动理论驱动的方法,用于规范访问控制策略,该策略可用于在医疗机构中执行患者的隐私同意。为了说明健康工作流程中的可传递性,我们将活动理论扩展为在健康工作流程中包括“组织互连性”。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号