{"title":"Integrated Modeling and Analysis of Attribute Based Access Control Policies and Workflows in Healthcare","authors":"Sandeep Lakkaraju, Dianxiang Xu","doi":"10.1109/TSA.2014.15","DOIUrl":null,"url":null,"abstract":"Healthcare information systems deal with sensitive data across complex workflows. They often allow various stakeholders from different environments to access data across organizational boundaries. This elevates the risk of exposing sensitive healthcare information to unauthorized personnel. To prevent unwanted access to sensitive information, healthcare organizations need to adopt effective workflows and access control mechanisms. This research addresses this issue by developing a methodology for integrated modeling and analysis of organizational workflows and attribute-based access control policies. This methodology can help identify workflow activities that are not being protected by access control policies and improve existing access control policies. In addition to subjects, resources, and actions, our methodology introduces 'environment' as a new element to workflow activity. This allows more contextual information to be associated with workflow activity for access control analysis.","PeriodicalId":127413,"journal":{"name":"2014 International Conference on Trustworthy Systems and their Applications","volume":"45 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-06-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 International Conference on Trustworthy Systems and their Applications","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/TSA.2014.15","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
Healthcare information systems deal with sensitive data across complex workflows. They often allow various stakeholders from different environments to access data across organizational boundaries. This elevates the risk of exposing sensitive healthcare information to unauthorized personnel. To prevent unwanted access to sensitive information, healthcare organizations need to adopt effective workflows and access control mechanisms. This research addresses this issue by developing a methodology for integrated modeling and analysis of organizational workflows and attribute-based access control policies. This methodology can help identify workflow activities that are not being protected by access control policies and improve existing access control policies. In addition to subjects, resources, and actions, our methodology introduces 'environment' as a new element to workflow activity. This allows more contextual information to be associated with workflow activity for access control analysis.