A secure and flexible e-Health access control system with provisions for emergency access overrides and delegation of access privileges

M. F. F. Khan, K. Sakamura
{"title":"A secure and flexible e-Health access control system with provisions for emergency access overrides and delegation of access privileges","authors":"M. F. F. Khan, K. Sakamura","doi":"10.1109/ICACT.2016.7423463","DOIUrl":null,"url":null,"abstract":"Protecting electronic health records (EHR) from unauthorized access and data breaches has been a great challenge for healthcare organizations in recent times. Controlling access to EHR demands a delicate balance between security and flexibility: There are emergency cases where the default access control policy must be circumvented in order to save patients' life - and cases where management of access control rights needs to be delegated to some trusted parties. Therefore, e-Health access control systems must be robust and flexible at the same time. Conventional general-purpose access control schemes like role-based access control (RBAC) and its derivatives emphasize mainly on the robustness of the access control mechanism, and treat flexibility issues like emergency access overrides and delegation management as addenda. However, in order to comply with the care first principle of the healthcare domain, an ideal e-Health access control system should consider such flexibility issues from the ground up. Recognizing these special requirements mandated by the very nature of the healthcare profession, in this paper, we propose a secure and flexible access control system for e-Health. The user-role and object-operation mappings in our proposed system lend themselves to the RBAC model, and we implemented context verification atop this layer in order for the system to make access decision responsive to emergency incidents. For managing delegation of access control rights, we developed a secure mechanism for creation, transfer and verification of a delegation token, presentation of which to the access control system enables a delegatee to access a delegator's EHR. Every access request in our system is preceded by mandatory user authentication which we implemented using eTRON tamper-resistant cards. Security and performance analysis of the proposed system showed promising results for achieving the desired level of balance between security and flexibility required for an e-Health access control system.","PeriodicalId":125854,"journal":{"name":"2016 18th International Conference on Advanced Communication Technology (ICACT)","volume":"17 8","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-03-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 18th International Conference on Advanced Communication Technology (ICACT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICACT.2016.7423463","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9

Abstract

Protecting electronic health records (EHR) from unauthorized access and data breaches has been a great challenge for healthcare organizations in recent times. Controlling access to EHR demands a delicate balance between security and flexibility: There are emergency cases where the default access control policy must be circumvented in order to save patients' life - and cases where management of access control rights needs to be delegated to some trusted parties. Therefore, e-Health access control systems must be robust and flexible at the same time. Conventional general-purpose access control schemes like role-based access control (RBAC) and its derivatives emphasize mainly on the robustness of the access control mechanism, and treat flexibility issues like emergency access overrides and delegation management as addenda. However, in order to comply with the care first principle of the healthcare domain, an ideal e-Health access control system should consider such flexibility issues from the ground up. Recognizing these special requirements mandated by the very nature of the healthcare profession, in this paper, we propose a secure and flexible access control system for e-Health. The user-role and object-operation mappings in our proposed system lend themselves to the RBAC model, and we implemented context verification atop this layer in order for the system to make access decision responsive to emergency incidents. For managing delegation of access control rights, we developed a secure mechanism for creation, transfer and verification of a delegation token, presentation of which to the access control system enables a delegatee to access a delegator's EHR. Every access request in our system is preceded by mandatory user authentication which we implemented using eTRON tamper-resistant cards. Security and performance analysis of the proposed system showed promising results for achieving the desired level of balance between security and flexibility required for an e-Health access control system.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
安全灵活的电子保健访问控制系统,提供紧急访问权限和访问权限授权
近年来,保护电子健康记录(EHR)免受未经授权的访问和数据泄露一直是医疗保健组织面临的巨大挑战。控制对EHR的访问需要在安全性和灵活性之间取得微妙的平衡:在某些紧急情况下,为了挽救患者的生命,必须绕过默认访问控制策略——在某些情况下,访问控制权限的管理需要委托给一些受信任的方。因此,电子卫生访问控制系统必须同时具有鲁棒性和灵活性。传统的通用访问控制方案,如基于角色的访问控制(RBAC)及其衍生方案,主要强调访问控制机制的鲁棒性,而将紧急访问覆盖和委托管理等灵活性问题作为补充。然而,为了遵守医疗保健领域的护理第一原则,理想的电子健康访问控制系统应该从头开始考虑这种灵活性问题。鉴于医疗保健行业的特殊性,本文提出了一种安全灵活的电子医疗访问控制系统。我们提出的系统中的用户角色和对象操作映射适合RBAC模型,并且我们在该层之上实现了上下文验证,以便系统对紧急事件做出响应的访问决策。为了管理访问控制权限的委托,我们开发了一种安全机制,用于创建、传输和验证委托令牌,将其呈现给访问控制系统使被委托者能够访问委托者的EHR。在我们的系统中的每个访问请求之前,我们使用eTRON防篡改卡实现了强制用户身份验证。对所提议系统的安全性和性能分析显示,在实现电子卫生访问控制系统所需的安全性和灵活性之间的预期平衡水平方面取得了有希望的结果。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
DNSNA: DNS name autoconfiguration for Internet of Things devices A novel multi-carrier waveform with high spectral efficiency: Semi-orthogonal frequency division multiplexing Adaptive spectral co-clustering for multiview data Efficient Doppler mitigation for high-speed rail communications Supply and demand management system based on consumption pattern analysis and tariff for cost minimization
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1