一个访问控制模型,便于在EHR系统中管理患者隐私

M. Sicuranza, A. Esposito
{"title":"一个访问控制模型,便于在EHR系统中管理患者隐私","authors":"M. Sicuranza, A. Esposito","doi":"10.1109/ICITST.2013.6750243","DOIUrl":null,"url":null,"abstract":"In EHR systems most of the data are confidential concerning the health of a patient, so it is necessary to provide a mechanism for access control. This has to ensure not only the confidentiality and integrity of the data, but also to allow the definition of security policies which reflect the need for privacy of the health care organization that manages the data; of the patient, who the documents refer to; and finally of international and national directives and norms. In literature there are several access control models, each of which responds just partially to the need for patient privacy. In this paper an innovative access control model is defined. It meets the main features that have to be satisfied by an EHR. Our proposal is an advanced access control model that combines several access control models known in the literature. It adds the characteristics of modularity and easiness in the management of access policies, focusing attention on privacy and patient's consent (patient privacy centric). The model provides the ability to define and to realize fine-grained access policies, which can be defined independently by both healthcare organizations and by patients. Our model is Attribute-based, multi-level, modular and with a dynamic and temporal management of the users' lists.","PeriodicalId":246884,"journal":{"name":"8th International Conference for Internet Technology and Secured Transactions (ICITST-2013)","volume":"9 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"15","resultStr":"{\"title\":\"An access control model for easy management of patient privacy in EHR systems\",\"authors\":\"M. Sicuranza, A. Esposito\",\"doi\":\"10.1109/ICITST.2013.6750243\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In EHR systems most of the data are confidential concerning the health of a patient, so it is necessary to provide a mechanism for access control. This has to ensure not only the confidentiality and integrity of the data, but also to allow the definition of security policies which reflect the need for privacy of the health care organization that manages the data; of the patient, who the documents refer to; and finally of international and national directives and norms. In literature there are several access control models, each of which responds just partially to the need for patient privacy. In this paper an innovative access control model is defined. It meets the main features that have to be satisfied by an EHR. Our proposal is an advanced access control model that combines several access control models known in the literature. It adds the characteristics of modularity and easiness in the management of access policies, focusing attention on privacy and patient's consent (patient privacy centric). The model provides the ability to define and to realize fine-grained access policies, which can be defined independently by both healthcare organizations and by patients. Our model is Attribute-based, multi-level, modular and with a dynamic and temporal management of the users' lists.\",\"PeriodicalId\":246884,\"journal\":{\"name\":\"8th International Conference for Internet Technology and Secured Transactions (ICITST-2013)\",\"volume\":\"9 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2013-12-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"15\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"8th International Conference for Internet Technology and Secured Transactions (ICITST-2013)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICITST.2013.6750243\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"8th International Conference for Internet Technology and Secured Transactions (ICITST-2013)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICITST.2013.6750243","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 15

摘要

EHR系统的大部分数据是保密的有关病人的健康,所以有必要提供访问控制机制。这不仅要确保数据的机密性和完整性,而且要允许定义安全政策,以反映管理数据的卫生保健组织对隐私的需求;病人的文件参考;最后是国际和国家的指令和规范。在文学上有几种访问控制模型,其中每个响应只是部分病人隐私的需要。本文定义了一种新颖的访问控制模型。会议的主要特点是由EHR满意。我们的建议是一种高级访问控制模型,它结合了文献中已知的几种访问控制模型。它增加了模块化的特点和从容的访问策略的管理,重点关注隐私和病人的同意(病人隐私中心)。该模型提供了定义和实现细粒度访问策略的能力,这些策略可以由医疗保健组织和患者独立定义。我们的模型是基于属性的、多层次的、模块化的,并具有对用户列表的动态和临时管理。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
An access control model for easy management of patient privacy in EHR systems
In EHR systems most of the data are confidential concerning the health of a patient, so it is necessary to provide a mechanism for access control. This has to ensure not only the confidentiality and integrity of the data, but also to allow the definition of security policies which reflect the need for privacy of the health care organization that manages the data; of the patient, who the documents refer to; and finally of international and national directives and norms. In literature there are several access control models, each of which responds just partially to the need for patient privacy. In this paper an innovative access control model is defined. It meets the main features that have to be satisfied by an EHR. Our proposal is an advanced access control model that combines several access control models known in the literature. It adds the characteristics of modularity and easiness in the management of access policies, focusing attention on privacy and patient's consent (patient privacy centric). The model provides the ability to define and to realize fine-grained access policies, which can be defined independently by both healthcare organizations and by patients. Our model is Attribute-based, multi-level, modular and with a dynamic and temporal management of the users' lists.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信