Role-based Access Control Solution for GraphQL-based Fast Healthcare Interoperability Resources Health Application Programming Interface

Mohammed S. Baihan
{"title":"Role-based Access Control Solution for GraphQL-based Fast Healthcare Interoperability Resources Health Application Programming Interface","authors":"Mohammed S. Baihan","doi":"10.1109/HealthCom54947.2022.9982782","DOIUrl":null,"url":null,"abstract":"Recently, GraphQL, a query language for Application Programming Interface (API), attracts many organizations and implementers in different domains, including healthcare informatic, to utilize it as an alternative to Representational State Transfer (REST) API. It is believed that GraphQL overcomes some issues of REST API. Moreover, GraphQL is known for its security issues as identified by OWASP organization, specifically Broken Object Level Authorization (BOLA) and Broken Function Level Authorization (BFLA) which are basically access control related issues. Furthermore, to the best of our knowledge there is no solution exists, in the academia or industry, to protect GraphQL-based Fast Healthcare Interoperability Resources (FHIR) API against BOLA and BFLA. In this paper, we present a Role-based Access Control (RBAC) solution to intercept all FHIR GraphQL requests to prevent related BOLA and BFLA vulnerabilities. To prove our work, we have implemented the RBAC solution as a server interceptor based on the HAPI FHIR reference implementation. Moreover, our evaluation showed that the suggested solution introduced minimal overhead.","PeriodicalId":202664,"journal":{"name":"2022 IEEE International Conference on E-health Networking, Application & Services (HealthCom)","volume":"30 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-10-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE International Conference on E-health Networking, Application & Services (HealthCom)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/HealthCom54947.2022.9982782","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Recently, GraphQL, a query language for Application Programming Interface (API), attracts many organizations and implementers in different domains, including healthcare informatic, to utilize it as an alternative to Representational State Transfer (REST) API. It is believed that GraphQL overcomes some issues of REST API. Moreover, GraphQL is known for its security issues as identified by OWASP organization, specifically Broken Object Level Authorization (BOLA) and Broken Function Level Authorization (BFLA) which are basically access control related issues. Furthermore, to the best of our knowledge there is no solution exists, in the academia or industry, to protect GraphQL-based Fast Healthcare Interoperability Resources (FHIR) API against BOLA and BFLA. In this paper, we present a Role-based Access Control (RBAC) solution to intercept all FHIR GraphQL requests to prevent related BOLA and BFLA vulnerabilities. To prove our work, we have implemented the RBAC solution as a server interceptor based on the HAPI FHIR reference implementation. Moreover, our evaluation showed that the suggested solution introduced minimal overhead.
基于graphql的快速医疗保健互操作性资源健康应用程序编程接口的基于角色的访问控制解决方案
最近,GraphQL(一种应用程序编程接口(API)的查询语言)吸引了包括医疗保健信息在内的不同领域的许多组织和实现者,将其用作Representational State Transfer (REST) API的替代方案。人们相信GraphQL克服了REST API的一些问题。此外,GraphQL还因其OWASP组织确定的安全问题而闻名,特别是损坏的对象级别授权(BOLA)和损坏的功能级别授权(BFLA),它们基本上是与访问控制相关的问题。此外,据我们所知,学术界或业界都没有解决方案可以保护基于graphql的快速医疗保健互操作性资源(FHIR) API免受BOLA和BFLA的侵害。在本文中,我们提出了一个基于角色的访问控制(RBAC)解决方案来拦截所有FHIR GraphQL请求,以防止相关的BOLA和BFLA漏洞。为了证明我们的工作,我们在HAPI FHIR参考实现的基础上实现了RBAC解决方案作为服务器拦截器。此外,我们的评估表明,建议的解决方案引入了最小的开销。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信