Standardized access control mechanisms for protecting ISO 13606-based electronic health record systems

Jorge Calvillo-Arbizu, Isabel Roman-Martinez, Laura M. Roa-Romero
{"title":"Standardized access control mechanisms for protecting ISO 13606-based electronic health record systems","authors":"Jorge Calvillo-Arbizu, Isabel Roman-Martinez, Laura M. Roa-Romero","doi":"10.1109/BHI.2014.6864421","DOIUrl":null,"url":null,"abstract":"EHR systems have acquired a primary role in the technological revolution of healthcare services and the improvement of quality and efficiency of care. Although EHR application is more and more extended, the protection of EHR data against unauthorized intruders continues being a major concern. EHR standards provide authorization requirements flexible enough to be addressed for different technological implementations, and so EHR solutions often develop ad-hoc access control schemes. Although there are wide-known general-purpose mechanisms to enforce access control policies, their application rate to the access control of EHR systems (by satisfying standard requirements) is low. In this work an XACML-based access control mechanism is presented that includes mandatory principles of the ISO 13606 family of standards. This makes use of semantic technologies to boost interoperability by defining attributes as ontology classes and policies as rules. The decision making process is automatically performed by an inference engine based on policies and sensitivity level of EHR extracts from ISO 13606-4. Finally, this work discusses the potential of combining security requirements of EHR standards with wide-known access control schemas.","PeriodicalId":177948,"journal":{"name":"IEEE-EMBS International Conference on Biomedical and Health Informatics (BHI)","volume":"153 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE-EMBS International Conference on Biomedical and Health Informatics (BHI)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/BHI.2014.6864421","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9

Abstract

EHR systems have acquired a primary role in the technological revolution of healthcare services and the improvement of quality and efficiency of care. Although EHR application is more and more extended, the protection of EHR data against unauthorized intruders continues being a major concern. EHR standards provide authorization requirements flexible enough to be addressed for different technological implementations, and so EHR solutions often develop ad-hoc access control schemes. Although there are wide-known general-purpose mechanisms to enforce access control policies, their application rate to the access control of EHR systems (by satisfying standard requirements) is low. In this work an XACML-based access control mechanism is presented that includes mandatory principles of the ISO 13606 family of standards. This makes use of semantic technologies to boost interoperability by defining attributes as ontology classes and policies as rules. The decision making process is automatically performed by an inference engine based on policies and sensitivity level of EHR extracts from ISO 13606-4. Finally, this work discusses the potential of combining security requirements of EHR standards with wide-known access control schemas.
用于保护基于ISO 13606的电子健康记录系统的标准化访问控制机制
电子病历系统在医疗保健服务的技术革命和提高护理质量和效率方面发挥了主要作用。尽管电子病历应用越来越广泛,但如何保护电子病历数据免受未经授权的入侵者的侵害仍然是一个主要问题。EHR标准提供了足够灵活的授权需求,可以针对不同的技术实现进行处理,因此EHR解决方案经常开发临时访问控制方案。尽管有一些众所周知的通用机制来实施访问控制策略,但它们在EHR系统访问控制中的应用比率(通过满足标准需求)很低。在这项工作中,提出了一种基于xacml的访问控制机制,该机制包括ISO 13606系列标准的强制原则。这利用语义技术通过将属性定义为本体类和将策略定义为规则来提高互操作性。决策过程由推理引擎根据ISO 13606-4中EHR提取的策略和灵敏度级别自动执行。最后,本文讨论了将EHR标准的安全需求与广为人知的访问控制模式相结合的可能性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信