{"title":"通过彩色Petri网(CPN)建模评估ISO 14441基于角色的访问控制(RBAC)限制模式下的隐私要求","authors":"M. Carvalho, Paulo Bandiera-Paiva","doi":"10.1109/CCST.2017.8167833","DOIUrl":null,"url":null,"abstract":"Objective: This article objective is to model authorization process from role-based access control (RBAC) using restrict mode features (separation of duties (SoD) implementation) via Colored Petri Nets (CPN) simulations to map security concerns or limitations of this access control while addressing ISO 14441 requirements for Electronic Health Records (EHR) systems. Method: We have mapped the two separation of duties access control resources from RBAC (static and dynamic) according with National Institute of Standards and Technology (NIST) documentation into a representative process flow using Petri Net formalism. The test scenario included two different physician roles with access permission grants labeled as in conflict if used altogether. Then, we have implemented this flow into a Colored Petri Net simulator (CPN Tools) in order to check RBAC SoD capability to address ISO 14441 privacy requirements to segregate conflicted grants from authenticated users on a general EHR system. The simulations considered conflicts either from a single user or from two users accessing shared patient's private EHR. Conclusion: Colored tokens on Petri Nets models simulating RBAC authorization are useful to demonstrate security policy conflicts during access control authorization process. Tested ISO 14441 privacy demands could be addressed only by including RBAC's dynamic SoD property.","PeriodicalId":371622,"journal":{"name":"2017 International Carnahan Conference on Security Technology (ICCST)","volume":"8 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":"{\"title\":\"Evaluating ISO 14441 privacy requirements on role based access control (RBAC) restrict mode via Colored Petri Nets (CPN) modeling\",\"authors\":\"M. Carvalho, Paulo Bandiera-Paiva\",\"doi\":\"10.1109/CCST.2017.8167833\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Objective: This article objective is to model authorization process from role-based access control (RBAC) using restrict mode features (separation of duties (SoD) implementation) via Colored Petri Nets (CPN) simulations to map security concerns or limitations of this access control while addressing ISO 14441 requirements for Electronic Health Records (EHR) systems. Method: We have mapped the two separation of duties access control resources from RBAC (static and dynamic) according with National Institute of Standards and Technology (NIST) documentation into a representative process flow using Petri Net formalism. The test scenario included two different physician roles with access permission grants labeled as in conflict if used altogether. Then, we have implemented this flow into a Colored Petri Net simulator (CPN Tools) in order to check RBAC SoD capability to address ISO 14441 privacy requirements to segregate conflicted grants from authenticated users on a general EHR system. The simulations considered conflicts either from a single user or from two users accessing shared patient's private EHR. Conclusion: Colored tokens on Petri Nets models simulating RBAC authorization are useful to demonstrate security policy conflicts during access control authorization process. Tested ISO 14441 privacy demands could be addressed only by including RBAC's dynamic SoD property.\",\"PeriodicalId\":371622,\"journal\":{\"name\":\"2017 International Carnahan Conference on Security Technology (ICCST)\",\"volume\":\"8 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2017-10-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"7\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2017 International Carnahan Conference on Security Technology (ICCST)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/CCST.2017.8167833\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 International Carnahan Conference on Security Technology (ICCST)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CCST.2017.8167833","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Evaluating ISO 14441 privacy requirements on role based access control (RBAC) restrict mode via Colored Petri Nets (CPN) modeling
Objective: This article objective is to model authorization process from role-based access control (RBAC) using restrict mode features (separation of duties (SoD) implementation) via Colored Petri Nets (CPN) simulations to map security concerns or limitations of this access control while addressing ISO 14441 requirements for Electronic Health Records (EHR) systems. Method: We have mapped the two separation of duties access control resources from RBAC (static and dynamic) according with National Institute of Standards and Technology (NIST) documentation into a representative process flow using Petri Net formalism. The test scenario included two different physician roles with access permission grants labeled as in conflict if used altogether. Then, we have implemented this flow into a Colored Petri Net simulator (CPN Tools) in order to check RBAC SoD capability to address ISO 14441 privacy requirements to segregate conflicted grants from authenticated users on a general EHR system. The simulations considered conflicts either from a single user or from two users accessing shared patient's private EHR. Conclusion: Colored tokens on Petri Nets models simulating RBAC authorization are useful to demonstrate security policy conflicts during access control authorization process. Tested ISO 14441 privacy demands could be addressed only by including RBAC's dynamic SoD property.