临床数据管理中以人为中心的可视化访问控制

S. Fahl, M. Harbach, Matthew Smith
{"title":"临床数据管理中以人为中心的可视化访问控制","authors":"S. Fahl, M. Harbach, Matthew Smith","doi":"10.1109/DEST.2012.6227927","DOIUrl":null,"url":null,"abstract":"This paper introduces a novel human-centric, visual, and context-aware access control (AC) system for distributed clinical data management and health information systems. Human-centricity in this context means that medical staff should be able to configure AC rules, both in a timesaving and reliable manner. Since medical data often include meta information about a patient, it is essential that an AC system only grants access requests that meet the patient's intent. Hence, it is desirable that a patient be included in the AC process. To cater for the strong security needs in the medical domain, both the AC policy creation by medical staff as well as the patient-interaction feature need to be supervised by governing policies. While traditional AC systems such as role-based access control offer sufficient security in theory, they lack in comfort and flexibility. This property does not fulfil the requirements of flexible and distributed environments. Distributed medical institutions could enormously benefit from the opportunity of dynamic AC configuration at an end-user level while adhering to legal, ethical or other privacy requirements. Hence, this paper presents a human-centric visual AC model for medical data, addressing usability, information security and patient interaction. To demonstrate our approach, an integration with the DCM4CHE open source system is presented.","PeriodicalId":320291,"journal":{"name":"2012 6th IEEE International Conference on Digital Ecosystems and Technologies (DEST)","volume":"149 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-06-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Human-centric visual access control for clinical data management\",\"authors\":\"S. Fahl, M. Harbach, Matthew Smith\",\"doi\":\"10.1109/DEST.2012.6227927\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This paper introduces a novel human-centric, visual, and context-aware access control (AC) system for distributed clinical data management and health information systems. Human-centricity in this context means that medical staff should be able to configure AC rules, both in a timesaving and reliable manner. Since medical data often include meta information about a patient, it is essential that an AC system only grants access requests that meet the patient's intent. Hence, it is desirable that a patient be included in the AC process. To cater for the strong security needs in the medical domain, both the AC policy creation by medical staff as well as the patient-interaction feature need to be supervised by governing policies. While traditional AC systems such as role-based access control offer sufficient security in theory, they lack in comfort and flexibility. This property does not fulfil the requirements of flexible and distributed environments. Distributed medical institutions could enormously benefit from the opportunity of dynamic AC configuration at an end-user level while adhering to legal, ethical or other privacy requirements. Hence, this paper presents a human-centric visual AC model for medical data, addressing usability, information security and patient interaction. To demonstrate our approach, an integration with the DCM4CHE open source system is presented.\",\"PeriodicalId\":320291,\"journal\":{\"name\":\"2012 6th IEEE International Conference on Digital Ecosystems and Technologies (DEST)\",\"volume\":\"149 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2012-06-18\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2012 6th IEEE International Conference on Digital Ecosystems and Technologies (DEST)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/DEST.2012.6227927\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2012 6th IEEE International Conference on Digital Ecosystems and Technologies (DEST)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/DEST.2012.6227927","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

本文介绍了一种用于分布式临床数据管理和卫生信息系统的新型以人为本、可视化和上下文感知的访问控制系统。在这种情况下,以人为中心意味着医务人员应该能够以节省时间和可靠的方式配置交流规则。由于医疗数据通常包含有关患者的元信息,因此AC系统必须仅授予符合患者意图的访问请求。因此,患者被纳入AC过程是可取的。为了满足医疗领域的强安全性需求,医务人员创建的AC策略以及患者交互功能都需要由治理策略进行监督。传统的交流系统,如基于角色的访问控制,理论上提供了足够的安全性,但缺乏舒适性和灵活性。此属性不能满足灵活和分布式环境的要求。分布式医疗机构可以在遵守法律、道德或其他隐私要求的同时,从最终用户级别的动态交流配置中获益良多。因此,本文提出了一个以人为中心的医疗数据可视化交流模型,解决可用性、信息安全和患者交互问题。为了演示我们的方法,介绍了与DCM4CHE开源系统的集成。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Human-centric visual access control for clinical data management
This paper introduces a novel human-centric, visual, and context-aware access control (AC) system for distributed clinical data management and health information systems. Human-centricity in this context means that medical staff should be able to configure AC rules, both in a timesaving and reliable manner. Since medical data often include meta information about a patient, it is essential that an AC system only grants access requests that meet the patient's intent. Hence, it is desirable that a patient be included in the AC process. To cater for the strong security needs in the medical domain, both the AC policy creation by medical staff as well as the patient-interaction feature need to be supervised by governing policies. While traditional AC systems such as role-based access control offer sufficient security in theory, they lack in comfort and flexibility. This property does not fulfil the requirements of flexible and distributed environments. Distributed medical institutions could enormously benefit from the opportunity of dynamic AC configuration at an end-user level while adhering to legal, ethical or other privacy requirements. Hence, this paper presents a human-centric visual AC model for medical data, addressing usability, information security and patient interaction. To demonstrate our approach, an integration with the DCM4CHE open source system is presented.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
A digital ecosystem view on cloud computing GPU-based Cloud computing for comparing the structure of protein binding sites An essay on the emerging political economy and the future of the social media Complex environment evolution: Challenges with semantic service infrastructures A Customer Relationship Management ecosystem that utilizes multiple sources and types of information conjointly
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1