...
首页> 外文期刊>Journal of computer security >Behavior-based access control for distributed healthcare systems
【24h】

Behavior-based access control for distributed healthcare systems

机译:分布式医疗系统基于行为的访问控制

获取原文
获取原文并翻译 | 示例
           

摘要

Sensitivity of clinical data and strict rules regarding data sharing have caused privacy and security to be critical requirements for using patient profiles in distributed healthcare systems. The amalgamation of new information technology with traditional healthcare workflows for sharing patient profiles has made the whole system vulnerable to privacy and security breaches. Standardization organizations are developing specifications to satisfy the required privacy and security requirements. In this paper we present a novel access control model compliant with healthcare standards based on a framework designed for data and service interoperability in the healthcare domain. The proposed model for customizable access control captures the dynamic behavior of the user and determines access rights accordingly. The model is generic and flexible in the sense that an access control engine dynamically receives security effective parameters from the subject user, and identifies the privilege level in accessing data using different specialized components within the engine. Standard data representation formats and ontologies are used to make the model compatible with different healthcare systems. The access control engine employs an approach to follow the user's behavior and navigates among engine components to provide the user's privilege to access a resource. A simulation environment is implemented to evaluate and test the proposed model.
机译:临床数据的敏感性和有关数据共享的严格规则已导致隐私和安全性成为在分布式医疗保健系统中使用患者资料的关键要求。新信息技术与传统医疗保健工作流程的融合(用于共享患者资料)使整个系统容易受到隐私和安全漏洞的侵害。标准化组织正在制定规范,以满足所需的隐私和安全要求。在本文中,我们基于为医疗保健领域的数据和服务互操作性设计的框架,提出了一种符合医疗保健标准的新颖访问控制模型。所提出的可自定义访问控制模型捕获了用户的动态行为,并相应地确定了访问权限。从访问控制引擎动态地从目标用户接收安全有效参数的角度出发,该模型是通用且灵活的,并且使用引擎内的不同专用组件来标识访问数据时的特权级别。标准的数据表示格式和本体用于使模型与不同的医疗系统兼容。访问控制引擎采用一种方法来跟踪用户的行为,并在引擎组件之间导航以提供用户访问资源的特权。实现了仿真环境以评估和测试所提出的模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号