Security Analysis of Standards-Driven Communication Protocols for Healthcare Scenarios

被引:4
|
作者
Masi, Massimiliano [1 ,2 ]
Pugliese, Rosario [2 ]
Tiezzi, Francesco [3 ]
机构
[1] Tiani Spirit GmbH, A-1110 Vienna, Austria
[2] Univ Florence, I-50134 Florence, Italy
[3] IMT Adv Studies Lucca, I-55100 Lucca, Italy
关键词
Healthcare applications; Electronic Health Records; Medical records storage and retrieval; Data security; Authentication; Model checking;
D O I
10.1007/s10916-012-9843-1
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
The importance of the Electronic Health Record (EHR), that stores all healthcare-related data belonging to a patient, has been recognised in recent years by governments, institutions and industry. Initiatives like the Integrating the Healthcare Enterprise (IHE) have been developed for the definition of standard methodologies for secure and interoperable EHR exchanges among clinics and hospitals. Using the requisites specified by these initiatives, many large scale projects have been set up for enabling healthcare professionals to handle patients' EHRs. The success of applications developed in these contexts crucially depends on ensuring such security properties as confidentiality, authentication, and authorization. In this paper, we first propose a communication protocol, based on the IHE specifications, for authenticating healthcare professionals and assuring patients' safety. By means of a formal analysis carried out by using the specification language COWS and the model checker CMC, we reveal a security flaw in the protocol thus demonstrating that to simply adopt the international standards does not guarantee the absence of such type of flaws. We then propose how to emend the IHE specifications and modify the protocol accordingly. Finally, we show how to tailor our protocol for application to more critical scenarios with no assumptions on the communication channels. To demonstrate feasibility and effectiveness of our protocols we have fully implemented them.
引用
收藏
页码:3695 / 3711
页数:17
相关论文
共 50 条
  • [1] Security Analysis of Standards-Driven Communication Protocols for Healthcare Scenarios
    Massimiliano Masi
    Rosario Pugliese
    Francesco Tiezzi
    [J]. Journal of Medical Systems, 2012, 36 : 3695 - 3711
  • [2] A Methodology for Standards-Driven Metamodel Fusion
    Pataricza, Andras
    Goenczy, Laszlo
    Koevi, Andras
    Szatmari, Zoltan
    [J]. MODEL AND DATA ENGINEERING, 2011, 6918 : 270 - 277
  • [3] STATELINE - THE SEARCH FOR A STANDARDS-DRIVEN UTOPIA
    PIPHO, C
    [J]. PHI DELTA KAPPAN, 1995, 77 (03) : 198 - 199
  • [4] A standards-driven open architecture for learning systems
    Anido, L
    Llamas, M
    Fernández, MJ
    Rodríguez, J
    Caeiro, M
    Santos, J
    [J]. IEEE INTERNATIONAL CONFERENCE ON ADVANCED LEARNING TECHNOLOGIES, PROCEEDINGS, 2001, : 3 - 4
  • [5] Analysis of Security Protocols for Mobile Healthcare
    Mohammad Wazid
    Sherali Zeadally
    Ashok Kumar Das
    Vanga Odelu
    [J]. Journal of Medical Systems, 2016, 40
  • [6] Analysis of Security Protocols for Mobile Healthcare
    Wazid, Mohammad
    Zeadally, Sherali
    Das, Ashok Kumar
    Odelu, Vanga
    [J]. JOURNAL OF MEDICAL SYSTEMS, 2016, 40 (11)
  • [7] Standards-driven Metamodel to Increase Retrievability of Heterogeneous Services
    Garriga, Martin
    Flores, Andres
    [J]. SAC '19: PROCEEDINGS OF THE 34TH ACM/SIGAPP SYMPOSIUM ON APPLIED COMPUTING, 2019, : 2507 - 2514
  • [8] Mission impossible: inclusive teaching in a standards-driven system
    Williams-Brown, Zeta
    Hodkinson, Alan
    Jopling, Michael
    [J]. EDUCATION 3-13, 2023,
  • [9] Security Analysis of Drone Communication Protocols
    Bunse, Christian
    Plotz, Sebastian
    [J]. ENGINEERING SECURE SOFTWARE AND SYSTEMS, ESSOS 2018, 2018, 10953 : 96 - 107
  • [10] Robbing Peter to pay Paul: the price of standards-driven education
    Ingleby, Ewan
    [J]. RESEARCH IN POST-COMPULSORY EDUCATION, 2010, 15 (04) : 427 - 440