电子健康记录访问权授权的分布式方法

M. F. F. Khan, K. Sakamura
{"title":"电子健康记录访问权授权的分布式方法","authors":"M. F. F. Khan, K. Sakamura","doi":"10.1109/ICEIC49074.2020.9051092","DOIUrl":null,"url":null,"abstract":"Delegation of access rights to patients' health records is an important feature for eHealth systems. Often considered an add-on to legacy access control systems, most of the existing delegation schemes are extension of the widely used role-based access control mechanism. However, when it comes to handling patient data in healthcare applications, a growing body of international technical standards, and national and regional healthcare regulations have been suggesting use of individual discretion as the basis, or at least a critical component, of access control. Along this line of access-control strategy, we are of the view that delegation is intrinsically discretionary, and it should be implemented in a way that directly translates user discretion as much as possible. In this paper, we propose a distributed system for delegation management that enables a patient to securely delegate access rights to her health records to someone she trusts. We implemented this discretionary approach using our eTRON enterprise security architecture, cryptographically assuring the authorization of any delegation.","PeriodicalId":271345,"journal":{"name":"2020 International Conference on Electronics, Information, and Communication (ICEIC)","volume":"52 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"A Distributed Approach to Delegation of Access Rights for Electronic Health Records\",\"authors\":\"M. F. F. Khan, K. Sakamura\",\"doi\":\"10.1109/ICEIC49074.2020.9051092\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Delegation of access rights to patients' health records is an important feature for eHealth systems. Often considered an add-on to legacy access control systems, most of the existing delegation schemes are extension of the widely used role-based access control mechanism. However, when it comes to handling patient data in healthcare applications, a growing body of international technical standards, and national and regional healthcare regulations have been suggesting use of individual discretion as the basis, or at least a critical component, of access control. Along this line of access-control strategy, we are of the view that delegation is intrinsically discretionary, and it should be implemented in a way that directly translates user discretion as much as possible. In this paper, we propose a distributed system for delegation management that enables a patient to securely delegate access rights to her health records to someone she trusts. We implemented this discretionary approach using our eTRON enterprise security architecture, cryptographically assuring the authorization of any delegation.\",\"PeriodicalId\":271345,\"journal\":{\"name\":\"2020 International Conference on Electronics, Information, and Communication (ICEIC)\",\"volume\":\"52 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-01-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2020 International Conference on Electronics, Information, and Communication (ICEIC)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICEIC49074.2020.9051092\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 International Conference on Electronics, Information, and Communication (ICEIC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICEIC49074.2020.9051092","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

对患者健康记录的访问权的授权是电子卫生系统的一个重要特征。通常被认为是遗留访问控制系统的附加组件,大多数现有的授权方案是对广泛使用的基于角色的访问控制机制的扩展。然而,当涉及到在医疗保健应用程序中处理患者数据时,越来越多的国际技术标准以及国家和地区医疗保健法规都建议使用个人自由裁量权作为访问控制的基础,或者至少是一个关键组成部分。沿着这条访问控制策略的路线,我们认为授权本质上是自由裁量的,它应该以一种尽可能直接转换用户自由裁量权的方式实现。在本文中,我们提出了一个用于委托管理的分布式系统,该系统使患者能够安全地将其健康记录的访问权委托给她信任的人。我们使用我们的eTRON企业安全架构实现了这种自由裁量的方法,以加密方式确保任何委托的授权。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A Distributed Approach to Delegation of Access Rights for Electronic Health Records
Delegation of access rights to patients' health records is an important feature for eHealth systems. Often considered an add-on to legacy access control systems, most of the existing delegation schemes are extension of the widely used role-based access control mechanism. However, when it comes to handling patient data in healthcare applications, a growing body of international technical standards, and national and regional healthcare regulations have been suggesting use of individual discretion as the basis, or at least a critical component, of access control. Along this line of access-control strategy, we are of the view that delegation is intrinsically discretionary, and it should be implemented in a way that directly translates user discretion as much as possible. In this paper, we propose a distributed system for delegation management that enables a patient to securely delegate access rights to her health records to someone she trusts. We implemented this discretionary approach using our eTRON enterprise security architecture, cryptographically assuring the authorization of any delegation.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信