首页> 外文会议>International Conference on Advanced Information Networking and Applications >A Context-Aware Security Model for a Combination of Attribute-Based Access Control and Attribute-Based Encryption in the Healthcare Domain
【24h】

A Context-Aware Security Model for a Combination of Attribute-Based Access Control and Attribute-Based Encryption in the Healthcare Domain

机译:用于在医疗域中基于属性的访问控制和基于属性的加密组合的上下文感知安全模型

获取原文

摘要

The need of a trusted environment in which only authorized users are permitted to access a system was of imperative importance since the early days of cloud computing. Even nowadays, a lot of users seem to be reluctant to store their personal data in the cloud and specifically the data related to bank accounts and the health care domain. Our goal is to enhance the access control mechanisms that can be used in the healthcare domain for enhancing the security and privacy of EHR systems. In this work, we present a context-aware security model which consists of classes and properties that can serve as background knowledge for creating and enforcing access control rules for electronic health records (EHR). We consider two different layers of authorization control based on the current context: (i) the Attribute Based Access Control (ABAC) layer which permits or denies access and/or editing rights to (encrypted) EHRs; and (ii) the Attribute Based Encryption (ABE) layer which handles the way sensitive data should be decrypted.
机译:只允许授权用户访问系统的可信环境的需要是自云计算早期以来的势在必行的重要性。即使如今,大量用户似乎不愿意在云中存储他们的个人数据,具体是与银行账户和医疗领域相关的数据。我们的目标是增强可以在医疗领域中使用的访问控制机制,以提高EHR系统的安全性和隐私。在这项工作中,我们提出了一种上下文感知安全模型,它由类和属性组成,该类和属性可以作为创建和强制电子健康记录(EHR)的访问控制规则的背景知识。我们根据当前上下文考虑两个不同的授权控件层:(i)基于属性的访问控制(ABAC)层,其允许或拒绝访问和/或编辑权限(加密)EHRS; (ii)应该解密处理敏感数据方式的基于属性的加密(ABE)层。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号