A virtual PHR authorization system

M. Poulymenopoulou, F. Malamateniou, G. Vassilacopoulos
{"title":"A virtual PHR authorization system","authors":"M. Poulymenopoulou, F. Malamateniou, G. Vassilacopoulos","doi":"10.1109/BHI.2014.6864307","DOIUrl":null,"url":null,"abstract":"Cloud computing and Internet of things (IOT) technologies can support a new generation of PHR systems which are provided as cloud services that contain patient data (health and social) from various sources, including automatically transmitted data from Internet connected devices of patient living space (e.g. medical devices connected to patients at home care). In this paper, the virtual PHR concept is introduced as an entity on the network consisted of (a) a non-healthcare component containing health and social information collected by either the patient or non-healthcare providers, (b) a medical device component containing health information transmitted from Internet connected medical devices and (c) a healthcare professional component containing information stored into various healthcare information systems. The PHR concept is based on the patient-centered model dictating that patients are the owners of their information. Hence, patients are empowered to authorize other subjects to access it that introduces specific security challenges which are further accentuated by the fact that diverse local security policies may need to be reconciled. The PHR authorization system proposed here is based on a combination of role-based and attribute-based access control (RABAC) and supports patient-specified authorization policies of various granularity levels subject to constraints imposed by the security policies of the various health and social care providers involved. To this end, an ontology of granular security concepts is built to aid in semantically matching diverse authorization requests and to enable semantic rule reasoning on whether a requested access should be permitted or denied.","PeriodicalId":177948,"journal":{"name":"IEEE-EMBS International Conference on Biomedical and Health Informatics (BHI)","volume":"22 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE-EMBS International Conference on Biomedical and Health Informatics (BHI)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/BHI.2014.6864307","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

Abstract

Cloud computing and Internet of things (IOT) technologies can support a new generation of PHR systems which are provided as cloud services that contain patient data (health and social) from various sources, including automatically transmitted data from Internet connected devices of patient living space (e.g. medical devices connected to patients at home care). In this paper, the virtual PHR concept is introduced as an entity on the network consisted of (a) a non-healthcare component containing health and social information collected by either the patient or non-healthcare providers, (b) a medical device component containing health information transmitted from Internet connected medical devices and (c) a healthcare professional component containing information stored into various healthcare information systems. The PHR concept is based on the patient-centered model dictating that patients are the owners of their information. Hence, patients are empowered to authorize other subjects to access it that introduces specific security challenges which are further accentuated by the fact that diverse local security policies may need to be reconciled. The PHR authorization system proposed here is based on a combination of role-based and attribute-based access control (RABAC) and supports patient-specified authorization policies of various granularity levels subject to constraints imposed by the security policies of the various health and social care providers involved. To this end, an ontology of granular security concepts is built to aid in semantically matching diverse authorization requests and to enable semantic rule reasoning on whether a requested access should be permitted or denied.
虚拟PHR授权系统
云计算和物联网(IOT)技术可以支持新一代PHR系统,这些系统作为云服务提供,包含来自各种来源的患者数据(健康和社会),包括从患者生活空间的互联网连接设备(例如连接到家庭护理患者的医疗设备)自动传输的数据。在本文中,虚拟PHR概念被介绍为网络上的一个实体,它由(a)包含由患者或非医疗保健提供者收集的健康和社会信息的非医疗保健组件,(b)包含从连接互联网的医疗设备传输的健康信息的医疗设备组件和(c)包含存储在各种医疗保健信息系统中的信息的医疗保健专业组件组成。PHR概念基于以患者为中心的模型,该模型规定患者是其信息的所有者。因此,患者有权授权其他受试者访问它,这引入了特定的安全挑战,而不同的本地安全政策可能需要协调,这进一步加剧了这一挑战。这里提出的PHR授权系统基于基于角色和基于属性的访问控制(RABAC)的组合,并支持患者指定的各种粒度级别的授权策略,但要遵守所涉及的各种健康和社会护理提供者的安全策略所施加的约束。为此,构建了一个细粒度安全概念本体,以帮助在语义上匹配不同的授权请求,并支持关于是否应该允许或拒绝请求的访问的语义规则推理。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信