首页> 外文会议>International Conference on Connected Health: Applications, Systems and Engineering Technologies >Implementing Informed Consent as Information-Flow Policies for Secure Analytics on eHealth Data: Principles and Practices
【24h】

Implementing Informed Consent as Information-Flow Policies for Secure Analytics on eHealth Data: Principles and Practices

机译:在eHealth数据上实施知情同意作为安全分析的信息流策略:原则和实践

获取原文

摘要

Wearable and ambient cyber-physical systems coupled with big-data health analytics promise continuous individual health monitoring and customized medical interventions. However, health workers and medical researchers are bound by strict security and privacy conventions that make it difficult to take advantage of emerging data streams. In this paper, we propose a security and privacy architecture for the analytics back-end in medical cyber-physical systems. Our approach is motivated by three principles: users behave mostly rational, informed consent are security policies, and deep revocation of granted rights. We propose implementing these principles using a novel combination of information-flow control with attested programs for data declassification in combination with auditing and credential-based access control. Our implementation relies on fine-grained encapsulation of data sets and processing components inside virtual-machine containers. We therefore evaluate our ability to host concurrent Linux containers, and observe that 70 instances can be easily accommodated on commodity hardware.
机译:可穿戴和环境网络物理系统与大数据健康分析相结合,承诺持续的个人健康监测和定制医疗干预措施。然而,卫生工作者和医学研究人员受到严格的安全和隐私公约的约束,这使得难以利用新兴数据流。在本文中,我们向医疗网络 - 物理系统中的分析后端提出了安全性和隐私架构。我们的方法是三个原则的动机:用户行为主要是理性,知情同意是安全政策,深度撤销授予权利。我们建议使用信息流控制的新组合实施这些原则,该原则与已证明的数据解码计划结合审计和凭证的访问控制。我们的实现依赖于虚拟机容器内的数据集和处理组件的细粒度封装。因此,我们评估我们托管并发Linux容器的能力,并观察到70个实例可以轻松容纳在商品硬件上。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号