Features of mathematical rationale for a complex datа security system of a medical enterprise

H.T. Samoylenko, Yu.Yu. Yurchenko
{"title":"Features of mathematical rationale for a complex datа security system of a medical enterprise","authors":"H.T. Samoylenko, Yu.Yu. Yurchenko","doi":"10.34121/1028-9763-2023-4-51-57","DOIUrl":null,"url":null,"abstract":"The article is dedicated to the analysis of data protection issues, particularly personal data, in medical institutions of various ownership forms. The necessity of implementing comprehensive data security systems is justified by the Bell-LaPadula model, which is considered a foundation for the development of a complex data security system within the enterprise. The Bell-LaPadula model represents an access control system based on a hierarchical data access structure. How-ever, using a rigid hierarchical approach when building an information infrastructure of an en-terprise based on this model, taking into account different levels of information confidentiality, might not account for the possibility of insider intervention at higher levels. The article analyz-es the key aspects of this model, including assigning special security levels to all participants in data processing and to documents containing the protected data. To ensure security and access regulation based on an adapted model, individual access levels that correspond to each user’s responsibilities and confidentiality level are proposed for them. After implementing a compre-hensive system for protecting confidential data and assigning special security levels to all par-ticipants in the processing of protected data and documents, a clear differentiation of ownership rights to information of different values emerged. This facilitates further expansion of the circle of employees with access to this information, reduces access time, and forms informational and analytical reports on access control system performance. The use of the hierarchical Bell-LaPadula access model allows for effective control over access to the information system and ensures overall enterprise security.","PeriodicalId":473328,"journal":{"name":"Matematičeskie mašiny i sistemy","volume":"70 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Matematičeskie mašiny i sistemy","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.34121/1028-9763-2023-4-51-57","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The article is dedicated to the analysis of data protection issues, particularly personal data, in medical institutions of various ownership forms. The necessity of implementing comprehensive data security systems is justified by the Bell-LaPadula model, which is considered a foundation for the development of a complex data security system within the enterprise. The Bell-LaPadula model represents an access control system based on a hierarchical data access structure. How-ever, using a rigid hierarchical approach when building an information infrastructure of an en-terprise based on this model, taking into account different levels of information confidentiality, might not account for the possibility of insider intervention at higher levels. The article analyz-es the key aspects of this model, including assigning special security levels to all participants in data processing and to documents containing the protected data. To ensure security and access regulation based on an adapted model, individual access levels that correspond to each user’s responsibilities and confidentiality level are proposed for them. After implementing a compre-hensive system for protecting confidential data and assigning special security levels to all par-ticipants in the processing of protected data and documents, a clear differentiation of ownership rights to information of different values emerged. This facilitates further expansion of the circle of employees with access to this information, reduces access time, and forms informational and analytical reports on access control system performance. The use of the hierarchical Bell-LaPadula access model allows for effective control over access to the information system and ensures overall enterprise security.
某医疗企业复杂数据安全系统的数学原理特征
本文致力于分析各种所有制形式的医疗机构中的数据保护问题,特别是个人数据。Bell-LaPadula模型证明了实现综合数据安全系统的必要性,该模型被认为是在企业内开发复杂数据安全系统的基础。Bell-LaPadula模型代表了一个基于分层数据访问结构的访问控制系统。然而,在基于该模型构建企业的信息基础设施时,使用严格的分层方法,考虑到不同级别的信息机密性,可能无法考虑更高级别内部人员干预的可能性。本文分析了该模型的关键方面,包括为数据处理中的所有参与者和包含受保护数据的文档分配特殊的安全级别。为了确保基于适应模型的安全性和访问规则,为每个用户提出了对应于每个用户的职责和保密级别的单独访问级别。在实施了一套全面的保护机密数据的制度,并为所有处理受保护数据和文件的参与者分配了特殊的安全级别后,不同价值的信息的所有权出现了明显的区分。这样可以进一步扩大访问这些信息的员工圈子,减少访问时间,并形成对门禁系统性能的信息性和分析性报告。使用分层的Bell-LaPadula访问模型可以有效地控制对信息系统的访问,并确保整个企业的安全性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信