首页> 外文会议>International Symposium on Networks, Computers and Communications >Fine-grained access control to medical records in digital healthcare enterprises
【24h】

Fine-grained access control to medical records in digital healthcare enterprises

机译:数字医疗企业对病历的细粒度访问控制

获取原文

摘要

Adopting IT as an integral part of business and operation is certainly making the healthcare industry more efficient and cost-effective. With the widespread digitalization of personal health information, coupled with big data revolution and advanced analytics, security and privacy related to medical data - especially ensuring authorized access thereto - is facing a huge challenge. In this paper, we argue that a fine-grained approach is needed for developing access control mechanisms contingent upon various environmental and application-dependent contexts along with provision for secure delegation of access-control rights. In particular, we propose a context-sensitive approach to access control, building on conventional discretionary access control (DAC) and role-based access control (RBAC) models. Taking a holistic view to access control, we effectively address the precursory authentication part as well. The eTRON architecture - which advocates use of tamper-resistant chips equipped with functions for mutual authentication and encrypted communication - is used for authentication and implementing the DAC-based delegation of access-control rights. For realizing the authorization and access decision, we used the RBAC model and implemented context verification on top of it. Our approach closely follows regulatory and technical standards of the healthcare domain. Evaluation of the proposed system in terms of various security and performance showed promising results.
机译:将IT作为业务和运营的有机组成部分无疑将使医疗保健行业更加高效和经济高效。随着个人健康信息的广泛数字化,再加上大数据革命和先进的分析技术,与医疗数据相关的安全性和隐私(尤其是确保对其的授权访问)正面临着巨大的挑战。在本文中,我们认为需要一种细粒度的方法来开发依赖于各种环境和依赖于应用程序的上下文的访问控制机制,以及对访问控制权进行安全委派的规定。特别是,我们提出了一种基于上下文的访问控制方法,该方法基于常规的自由访问控制(DAC)和基于角色的访问控制(RBAC)模型。从访问控制的整体角度来看,我们也有效地解决了先验身份验证部分。 eTRON架构提倡使用具有互认证和加密通信功能的防篡改芯片,该架构用于认证和实现基于DAC的访问控制权委派。为了实现授权和访问决策,我们使用了RBAC模型并在其之上实施了上下文验证。我们的方法严格遵循医疗保健领域的法规和技术标准。对所提出系统的各种安全性和性能进行评估显示出可喜的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号