Publication | Open Access
A Framework for Context Sensitive Risk-Based Access Control in Medical Information Systems
24
Citations
15
References
2015
Year
EngineeringInformation SecurityContext InformationHealthcare Information SecurityLogical Access ControlAccess ControlMedical InformationPublic HealthModel-driven SecurityHealth PolicyData PrivacyComputer ScienceData SecurityCryptographyMedical EthicsMedical PrivacyMedical Information SystemPatient SafetyMedicineHealth InformaticsEmergency MedicineMedical Information Systems
Since the access control environment has changed and the threat of insider information leakage has come to the fore, studies on risk-based access control models that decide access permissions dynamically have been conducted vigorously. Medical information systems should protect sensitive data such as medical information from insider threat and enable dynamic access control depending on the context such as life-threatening emergencies. In this paper, we suggest an approach and framework for context sensitive risk-based access control suitable for medical information systems. This approach categorizes context information, estimating and applying risk through context- and treatment-based permission profiling and specifications by expanding the eXtensible Access Control Markup Language (XACML) to apply risk. The proposed framework supports quick responses to medical situations and prevents unnecessary insider data access through dynamic access authorization decisions in accordance with the severity of the context and treatment.
| Year | Citations | |
|---|---|---|
Page 1
Page 1