...
首页> 外文期刊>International Journal of Information Security >Deployment of a posteriori access control using IHE ATNA
【24h】

Deployment of a posteriori access control using IHE ATNA

机译:使用IHE ATNA部署后验访问控制

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

In healthcare information management, privacy and confidentiality are two major concerns usually satisfied by access control means. Traditional access control mechanisms prevent illegal access by controlling access right before executing an action. They have some limitations like inflexibility in unanticipated circumstances (e.g., emergency). Recently, a posteriori access control has been proposed to complete a priori protection for a more effective and flexible solution. It controls the access by deterring user from having unauthorized access. To be deployed, a posteriori access control needs evidence to prove the users' violations. In this paper, we show how log records defined by the Integrating the Healthcare Enterprise-Audit Trail and Node Authentication (ATNA) profile can be used to deploy an a posteriori access control system. To develop an efficient method for finding violations, we propose a framework that customizes ATNA log records according to a contextual security policy like the Organization-Based Access Control. Experiments we conducted are also presented.
机译:在医疗保健信息管理中,隐私和机密性是访问控制手段通常可以满足的两个主要问题。传统的访问控制机制通过在执行操作之前控制访问权限来防止非法访问。它们具有一些局限性,例如在意外情况下(例如紧急情况)缺乏灵活性。最近,已经提出了后验访问控制以完成对更有效和灵活解决方案的先验保护。它通过阻止用户进行未经授权的访问来控制访问。要部署,后验访问控制需要证据来证明用户的违规行为。在本文中,我们展示了如何通过集成医疗保健企业-审计跟踪和节点身份验证(ATNA)配置文件定义的日志记录可用于部署后验访问控制系统。为了开发一种发现违规的有效方法,我们提出了一个框架,该框架根据上下文安全策略(如基于组织的访问控制)自定义ATNA日志记录。还介绍了我们进行的实验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号