Access control based on roles and groups: Case study Building a secure Smart Hospital using BPMS

被引:0
|
作者
Asma, Daassa [1 ]
Mohsen, Machhout [2 ]
Ghannouchi, Sonia Ayachi [3 ,4 ]
Taoufik, Aguili [5 ]
机构
[1] Univ Tunis El Manar, Fac Sci Monastir, Elect & Microelect Lab, Natl Engn Sch Tunis, Tunis, Tunisia
[2] Univ Monastir, Elect & Microelect Lab, Fac Sci, Monastir, Tunisia
[3] Univ Sousse, ISG Sousse, Sousse, Tunisia
[4] Univ Mannouba, RIADI Lab, ENSI, Mannouba, Tunisia
[5] Univ Tunis El Manar, Dept Informat & Commun Technol, SYSCOM Lab, Natl Engn Sch Tunis, Tunis, Tunisia
关键词
Process Security; Process Management (BPM); SecureBPMN; smart hospital; access control; SYSTEM;
D O I
10.1109/ATSIP62566.2024.10638848
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
In today's e-health applications, controlling access to patients' medical information is a real concern. In particular, the control of access has been identified as one of the requirements for the security of these systems. In a BPMS, this security requirement is not adequately addressed: it is represented by a simple actor filter where a task is performed by a particular user. However, to ensure the confidentiality of the data used in each task, this is not sufficient. This research paper explores the idea of integrating an access control filter into a BPMS, specifically the Bonita BPMS. A case study is performed for the validation of this idea. More specifically, the COVID-19 healthcare process of a Tunisian hospital is taken into account, for which we have been able to apply the proposed solution by implementing this process in Bonita and providing real-time access control based on groups and roles. This article explores the access control in a BPMS for smart hospitals. We address the problem of access control of personal information of patients and doctors by using a BPMS systems, in the Intelligent assistance system for a COVID-19 crisis unit (SMART2C).
引用
收藏
页码:306 / 311
页数:6
相关论文
共 50 条
  • [21] Decentralised Access Control Framework using Blockchain: Smart Farming Case
    Noor, Normaizeerah Mohd
    Razali, Noor Afiza Mat
    Sham, Sharifah Nabila S. Azli
    Ishak, Khairul Khalil
    Wook, Muslihah
    Hasbullah, Nor Asiakin
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (05) : 566 - 579
  • [22] Access Control Attacks against IoT Smart Devices: A Case Study
    Philip, Sumesh J.
    Amisha, Fnu
    Kamesh, Fnu
    2024 INTERNATIONAL CONFERENCE ON SMART APPLICATIONS, COMMUNICATIONS AND NETWORKING, SMARTNETS-2024, 2024,
  • [23] A Case Study for a Secure and Robust Geo-fencing and Access Control Framework
    Rahimi, Hossein
    Maimaiti, Tuerxun
    Zincir-Heywood, A. Nur
    2014 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (NOMS), 2014,
  • [24] Case Study: Using Smart Cards with PKI to Implement Data Access Control for Health Information Systems
    Watts, Jewel
    Yu, Huiming
    Yuan, Xiaohong
    IEEE SOUTHEASTCON 2010: ENERGIZING OUR FUTURE, 2010, : 163 - 167
  • [25] Entitlement-Based Access Control for Smart Cities Using Blockchain
    Sabrina, Fariza
    Jang-Jaccard, Julian
    SENSORS, 2021, 21 (16)
  • [26] Fingerprint-based access control using smart cards in IPTV
    Eun-A Jun
    Hyun Sook Rhee
    Jeom Goo Kim
    Seok Won Jung
    Dong Hoon Lee
    Multimedia Tools and Applications, 2014, 73 : 647 - 661
  • [27] Fingerprint-based access control using smart cards in IPTV
    Jun, Eun-A
    Rhee, Hyun Sook
    Kim, Jeom Goo
    Jung, Seok Won
    Lee, Dong Hoon
    MULTIMEDIA TOOLS AND APPLICATIONS, 2014, 73 (02) : 647 - 661
  • [28] Attribute-based data access control scheme with secure revocation in fog computing for smart grid
    Wu, Zhiwei
    Shi, Run-hua
    Li, Kunchang
    Yang, Yifan
    Cluster Computing, 2022, 25 (06) : 3899 - 3913
  • [29] An Efficient and Secure Revocation-Enabled Attribute-Based Access Control for eHealth in Smart Society
    Khan, Shahzad
    Iqbal, Waseem
    Waheed, Abdul
    Mehmood, Gulzar
    Khan, Shawal
    Zareei, Mahdi
    Biswal, Rajesh Roshan
    SENSORS, 2022, 22 (01)
  • [30] Secure Data-Centric Access Control for Smart Grid Services Based on Publish/Subscribe Systems
    Duan, Li
    Liu, Dongxi
    Zhang, Yang
    Chen, Shiping
    Liu, Ren Ping
    Cheng, Bo
    Chen, Junliang
    ACM TRANSACTIONS ON INTERNET TECHNOLOGY, 2016, 16 (04)