An enhancement of the Role-Based Access Control model to facilitate information access management in context of team collaboration and workflow

被引:32
|
作者
Le, Xuan Hung [1 ]
Doll, Terry [1 ]
Barbosu, Monica [1 ]
Luque, Amneris [1 ]
Wang, Dongwen [1 ]
机构
[1] Univ Rochester, Med Ctr, Rochester, NY 14642 USA
关键词
Access control; Computation model; Information management; Computer supported cooperative work; Workflow; Medical education; ELECTRONIC PATIENT RECORD; MEDICAL-RECORDS; AWARE ACCESS; HEALTH; CARE; SYSTEM; SUPPORT; DESIGN; NETWORKS; OVERLOAD;
D O I
10.1016/j.jbi.2012.06.001
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Although information access control models have been developed and applied to various applications, few of the previous works have addressed the issue of managing information access in the combined context of team collaboration and workflow. To facilitate this requirement, we have enhanced the Role-Based Access Control (RBAC) model through formulating universal constraints, defining bridging entities and contributing attributes, extending access permissions to include workflow contexts, synthesizing a role-based access delegation model to target on specific objects, and developing domain ontologies as instantiations of the general model to particular applications. We have successfully applied this model to the New York State HIV Clinical Education Initiative (CEI) project to address the specific needs of information management in collaborative processes. An initial evaluation has shown this model achieved a high level of agreement with an existing system when applied to 4576 cases (kappa = 0.801). Comparing to a reference standard, the sensitivity and specificity of the enhanced RBAC model were at the level of 97-100%. These results indicate that the enhanced RBAC model can be effectively used for information access management in context of team collaboration and workflow to coordinate clinical education programs. Future research is required to incrementally develop additional types of universal constraints, to further investigate how the workflow context and access delegation can be enriched to support the various needs on information access management in collaborative processes, and to examine the generalizability of the enhanced RBAC model for other applications in clinical education, biomedical research, and patient care. (C)12 Elsevier Inc. All rights reserved.
引用
收藏
页码:1084 / 1107
页数:24
相关论文
共 50 条
  • [1] A Role-Based Workflow Access Control Model
    Zhang Wen-dong
    Zhang Kai-ji
    [J]. PROCEEDINGS OF THE FIRST INTERNATIONAL WORKSHOP ON EDUCATION TECHNOLOGY AND COMPUTER SCIENCE, VOL II, 2009, : 1136 - 1139
  • [2] An improved Role-based workflow Access Control Model
    Zhao, Hui
    Fang, Zhiyi
    Xu, Peng
    Zhao, Lianyu
    Liu, Jin
    Wang, Tianyang
    [J]. PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: NEW GENERATIONS, 2008, : 551 - 556
  • [3] The application of role-based access control in workflow management systems
    Liu, JX
    Sun, LX
    [J]. 2004 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN & CYBERNETICS, VOLS 1-7, 2004, : 5492 - 5496
  • [4] The application research of role-based access control model in workflow management system
    Wang, BY
    Zhang, SM
    Xia, XD
    [J]. GRID AND COOPERATIVE COMPUTING, PT 2, 2004, 3033 : 1034 - 1037
  • [5] A role-based access control model for information mediation
    Yang, L
    Ege, RK
    Ezenwoye, O
    Kharma, Q
    [J]. PROCEEDINGS OF THE 2004 IEEE INTERNATIONAL CONFERENCE ON INFORMATION REUSE AND INTEGRATION (IRI-2004), 2004, : 277 - 282
  • [6] The research on role-based access control mechanism for workflow management system
    Wang, BY
    Zhang, SM
    [J]. GRID AND COOPERATIVE COMPUTING GCC 2004, PROCEEDINGS, 2004, 3251 : 729 - 736
  • [7] Spatial context in role-based access control
    Zhang, Hong
    He, Yeping
    Shi, Zhiguo
    [J]. INFORMATION SECURITY AND CRYPTOLOGY - ICISC 2006, PROCEEDINGS, 2006, 4296 : 166 - 178
  • [8] Extending role-based access control model with context for grid applications
    Cheng, Yanfen
    Yao, Hanbing
    [J]. DCABES 2007 PROCEEDINGS, VOLS I AND II, 2007, : 650 - 654
  • [9] Rights management for role-based access control
    Bouwman, Bart
    Mauw, Sjouke
    Petkovic, Milan
    [J]. 2008 5TH IEEE CONSUMER COMMUNICATIONS AND NETWORKING CONFERENCE, VOLS 1-3, 2008, : 1085 - +
  • [10] Extended role-based access control model supporting authorization for collaboration environment
    Liu, TT
    Zhang, YL
    Wang, HF
    [J]. Proceedings of the International Conference on Mechanical Engineering and Mechanics 2005, Vols 1 and 2, 2005, : 1238 - 1243