首页> 外文会议>IEEE Region 10 Conference >A smartcard-based framework for delegation management in healthcare Access Control systems
【24h】

A smartcard-based framework for delegation management in healthcare Access Control systems

机译:基于智能卡的医疗访问控制系统中的委派管理框架

获取原文

摘要

A comprehensive access control system must provide a well-designed mechanism for delegation of access-control rights. In order to achieve a balance between security and flexibility, delegation of access privileges is necessary in one way or another for any kind of enterprise; for healthcare systems in particular, the ability to delegate access privileges is crucially important as it can directly impact the quality and timeliness of care and consequently saving a patient's life. Most of the existing access control models - for healthcare or otherwise - propose a delegation framework based on Role-based Access Control (RBAC). However, we argue that delegation should be treated in a discretionary manner, and hence a Discretionary Access Control or DAC-based approach would be more appropriate, as delegation is intuitively discretionary in nature - and many statutory healthcare regulations explicitly consider patients as the owner of their data. In this paper, we explain the design and implementation of a discretionary framework for managing delegation of access privileges in a healthcare scenario. The proposed framework is implemented using the eTRON cyber security architecture that is based on usage of public key infrastructure (PKI) and tamper-resistant devices like smartcards. Analysis of our proposed framework ascertains that it is secure against various attacks, and can be a robust delegation component of any standard access control system for healthcare.
机译:一个完善的访问控制系统必须提供一种设计良好的机制来委派访问控制权。为了在安全性和灵活性之间取得平衡,对于任何类型的企业,都必须以一种或另一种方式委派访问特权。特别是对于医疗保健系统,授予访问权限的权限至关重要,因为它可以直接影响护理的质量和及时性,从而挽救患者的生命。对于医疗保健或其他方面,大多数现有的访问控制模型都提出了基于基于角色的访问控制(RBAC)的委派框架。但是,我们认为应该以自由裁量的方式对待委派,因此,由于委派本质上是直觉上的自由裁量权,因此基于自由访问控制或基于DAC的方法将更为合适-许多法定医疗法规明确将患者视为患者的所有者。他们的数据。在本文中,我们解释了在医疗保健场景中用于管理访问权限委派的全权框架的设计和实现。所提出的框架是使用eTRON网络安全架构实现的,该架构基于公钥基础结构(PKI)和防篡改设备(如智能卡)的使用。通过对我们提出的框架进行分析,可以确定它在抵御各种攻击方面是安全的,并且可以成为任何标准医疗保健访问控制系统的强大委派组件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号