首页> 美国卫生研究院文献>Computational and Mathematical Methods in Medicine >A Framework for Context Sensitive Risk-Based Access Control in Medical Information Systems
【2h】

A Framework for Context Sensitive Risk-Based Access Control in Medical Information Systems

机译:医疗信息系统中基于上下文敏感风险的访问控制的框架

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Since the access control environment has changed and the threat of insider information leakage has come to the fore, studies on risk-based access control models that decide access permissions dynamically have been conducted vigorously. Medical information systems should protect sensitive data such as medical information from insider threat and enable dynamic access control depending on the context such as life-threatening emergencies. In this paper, we suggest an approach and framework for context sensitive risk-based access control suitable for medical information systems. This approach categorizes context information, estimating and applying risk through context- and treatment-based permission profiling and specifications by expanding the eXtensible Access Control Markup Language (XACML) to apply risk. The proposed framework supports quick responses to medical situations and prevents unnecessary insider data access through dynamic access authorization decisions in accordance with the severity of the context and treatment.
机译:由于访问控制环境已发生变化,内部信息泄露的威胁已迫在眉睫,因此对基于风险的访问控制模型进行了动态研究,这些模型动态地决定了访问权限。医疗信息系统应保护诸如医疗信息之类的敏感数据免受内部威胁,并根据情况(如危及生命的紧急情况)进行动态访问控制。在本文中,我们建议一种适用于医学信息系统的基于上下文的基于风险的访问控制方法和框架。该方法通过扩展可扩展的访问控制标记语言(XACML)来应用风险,从而对上下文信息进行分类,通过基于上下文和处理的权限配置文件和规范来估计和应用风险。所提出的框架支持对医疗情况的快速响应,并根据情况和治疗的严重性通过动态访问授权决策来防止不必要的内部数据访问。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号