安全数据共享基础设施:临床数据实施。

IF 2.5 Q2 HEALTH CARE SCIENCES & SERVICES JAMIA Open Pub Date : 2024-05-15 eCollection Date: 2024-07-01 DOI:10.1093/jamiaopen/ooae040
Joanna F DeFranco, Joshua Roberts, David Ferraiolo, D Chris Compton
{"title":"安全数据共享基础设施:临床数据实施。","authors":"Joanna F DeFranco, Joshua Roberts, David Ferraiolo, D Chris Compton","doi":"10.1093/jamiaopen/ooae040","DOIUrl":null,"url":null,"abstract":"<p><strong>Objective: </strong>To address database interoperability challenges to improve collaboration among disparate organizations.</p><p><strong>Materials and methods: </strong>We developed a lightweight system to allow broad but well-controlled data sharing while preserving local data protection policies. We used 2 NIST-developed technologies-Next-generation Database Access Control (NDAC) and the Data Block Matrix (DBM)-to create a proof-of-concept system called the Secure Federated Data Sharing System (SFDS). NDAC controls access to database resources down to the field level based on attributes assigned to users. The DBM manages and shares authoritative user-attribute assignments across a federation of organizations, implemented using a modified open-source permissioned blockchain, to manage and share authoritative user-attribute assignments across a federation of organizations. We used synthetic data to demonstrate a clinical research data-sharing use case using the SFDS.</p><p><strong>Results: </strong>We demonstrated, through consent, the onboarding of previously unknown users into NDAC via assignments to their DBM-validated attributes, allowing those users policy-preserving access to local database resources. The SFDS main system components-NDAC and DBM-also showed excellent performance metrics.</p><p><strong>Discussion: </strong>The SFDS provides a generic data-sharing infrastructure that effectively and securely achieves data-sharing objectives. It is completely transparent to the otherwise normal business operations of participating organizations. It requires no changes to database management systems or existing methods of authenticating and authorizing local user access to local resources.</p><p><strong>Conclusion: </strong>This efficiency, flexibility of deployment, and granularity of control make this new infrastructure solution practical for meeting the data-sharing and protection objectives of the clinical research community.</p>","PeriodicalId":36278,"journal":{"name":"JAMIA Open","volume":"7 2","pages":"ooae040"},"PeriodicalIF":2.5000,"publicationDate":"2024-05-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://www.ncbi.nlm.nih.gov/pmc/articles/PMC11095973/pdf/","citationCount":"0","resultStr":"{\"title\":\"An infrastructure for secure data sharing: a clinical data implementation.\",\"authors\":\"Joanna F DeFranco, Joshua Roberts, David Ferraiolo, D Chris Compton\",\"doi\":\"10.1093/jamiaopen/ooae040\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<p><strong>Objective: </strong>To address database interoperability challenges to improve collaboration among disparate organizations.</p><p><strong>Materials and methods: </strong>We developed a lightweight system to allow broad but well-controlled data sharing while preserving local data protection policies. We used 2 NIST-developed technologies-Next-generation Database Access Control (NDAC) and the Data Block Matrix (DBM)-to create a proof-of-concept system called the Secure Federated Data Sharing System (SFDS). NDAC controls access to database resources down to the field level based on attributes assigned to users. The DBM manages and shares authoritative user-attribute assignments across a federation of organizations, implemented using a modified open-source permissioned blockchain, to manage and share authoritative user-attribute assignments across a federation of organizations. We used synthetic data to demonstrate a clinical research data-sharing use case using the SFDS.</p><p><strong>Results: </strong>We demonstrated, through consent, the onboarding of previously unknown users into NDAC via assignments to their DBM-validated attributes, allowing those users policy-preserving access to local database resources. The SFDS main system components-NDAC and DBM-also showed excellent performance metrics.</p><p><strong>Discussion: </strong>The SFDS provides a generic data-sharing infrastructure that effectively and securely achieves data-sharing objectives. It is completely transparent to the otherwise normal business operations of participating organizations. It requires no changes to database management systems or existing methods of authenticating and authorizing local user access to local resources.</p><p><strong>Conclusion: </strong>This efficiency, flexibility of deployment, and granularity of control make this new infrastructure solution practical for meeting the data-sharing and protection objectives of the clinical research community.</p>\",\"PeriodicalId\":36278,\"journal\":{\"name\":\"JAMIA Open\",\"volume\":\"7 2\",\"pages\":\"ooae040\"},\"PeriodicalIF\":2.5000,\"publicationDate\":\"2024-05-15\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://www.ncbi.nlm.nih.gov/pmc/articles/PMC11095973/pdf/\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"JAMIA Open\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1093/jamiaopen/ooae040\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"2024/7/1 0:00:00\",\"PubModel\":\"eCollection\",\"JCR\":\"Q2\",\"JCRName\":\"HEALTH CARE SCIENCES & SERVICES\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"JAMIA Open","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1093/jamiaopen/ooae040","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"2024/7/1 0:00:00","PubModel":"eCollection","JCR":"Q2","JCRName":"HEALTH CARE SCIENCES & SERVICES","Score":null,"Total":0}
引用次数: 0

摘要

目的解决数据库互操作性难题,改善不同组织之间的协作:我们开发了一个轻量级系统,允许广泛但控制良好的数据共享,同时保留本地数据保护策略。我们利用 NIST 开发的两项技术--下一代数据库访问控制(NDAC)和数据块矩阵(DBM)--创建了一个概念验证系统,名为安全联合数据共享系统(SFDS)。NDAC 根据分配给用户的属性控制对数据库资源的访问,直至字段级。DBM 在组织联盟中管理和共享权威的用户属性分配,使用修改过的开源许可区块链实现,在组织联盟中管理和共享权威的用户属性分配。我们使用合成数据演示了使用 SFDS 的临床研究数据共享用例:结果:我们通过同意演示了通过对其经 DBM 验证的属性进行分配,将以前未知的用户加入 NDAC,允许这些用户以政策保护的方式访问本地数据库资源。SFDS 的主要系统组件--NDAC 和 DBM 也显示出卓越的性能指标:SFDS 提供了一种通用数据共享基础架构,可有效、安全地实现数据共享目标。它对参与组织的正常业务运作完全透明。它无需更改数据库管理系统或现有的本地用户访问本地资源的验证和授权方法:这种高效、灵活的部署和细粒度的控制使这种新的基础架构解决方案成为实现临床研究界数据共享和保护目标的实用工具。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
An infrastructure for secure data sharing: a clinical data implementation.

Objective: To address database interoperability challenges to improve collaboration among disparate organizations.

Materials and methods: We developed a lightweight system to allow broad but well-controlled data sharing while preserving local data protection policies. We used 2 NIST-developed technologies-Next-generation Database Access Control (NDAC) and the Data Block Matrix (DBM)-to create a proof-of-concept system called the Secure Federated Data Sharing System (SFDS). NDAC controls access to database resources down to the field level based on attributes assigned to users. The DBM manages and shares authoritative user-attribute assignments across a federation of organizations, implemented using a modified open-source permissioned blockchain, to manage and share authoritative user-attribute assignments across a federation of organizations. We used synthetic data to demonstrate a clinical research data-sharing use case using the SFDS.

Results: We demonstrated, through consent, the onboarding of previously unknown users into NDAC via assignments to their DBM-validated attributes, allowing those users policy-preserving access to local database resources. The SFDS main system components-NDAC and DBM-also showed excellent performance metrics.

Discussion: The SFDS provides a generic data-sharing infrastructure that effectively and securely achieves data-sharing objectives. It is completely transparent to the otherwise normal business operations of participating organizations. It requires no changes to database management systems or existing methods of authenticating and authorizing local user access to local resources.

Conclusion: This efficiency, flexibility of deployment, and granularity of control make this new infrastructure solution practical for meeting the data-sharing and protection objectives of the clinical research community.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
JAMIA Open
JAMIA Open Medicine-Health Informatics
CiteScore
4.10
自引率
4.80%
发文量
102
审稿时长
16 weeks
期刊最新文献
Aligning prediction models with clinical information needs: infant sepsis case study. Semantic enrichment of Pomeranian health study data using LOINC and WHO-FIC terminology mapping principles. Exploring beyond diagnoses in electronic health records to improve discovery: a review of the phenome-wide association study. Toward digital caregiving network interventions for children with medical complexity living in socioeconomically disadvantaged neighborhoods. Transforming appeal decisions: machine learning triage for hospital admission denials.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1