A System for Semantic-Based Access Control

被引:2
|
作者
Amato, Flora [1 ]
Mazzocca, Nicola [1 ]
De Pietro, Giuseppe
Esposito, Massimo
机构
[1] Univ Naples Federico II, Dipartimento Ingn Elettr & Tecnol Informaz, Naples, Italy
关键词
component; Role-based Access Control; Access Control Policy; Ontology; Electronic Health Record; Rule-based Formalism; ELECTRONIC HEALTH RECORDS; MANAGEMENT; MODEL;
D O I
10.1109/3PGCIC.2013.74
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security and privacy of patient's medical data has more than ever become a critical factor in healthcare and, therefore, has a strong influence on the development of Electronic Health Record (EHR) systems. One of the most challenging aspects regards the possibility of specifying fine-grained access control restrictions over EHRs, not only at a document level but also on their specific sections. In order to face this issue, the paper proposes a semantic-based system aimed at supporting the definition of fine-grained access control policies on EHRs. This system relies on a role-based authorization model, encoded in terms of a formal ontology, and a set of access control restrictions defined as "if-then rules", in order to assign to healthcare workers the necessary privileges to carry out a task on specific EHR sections. A prototype implementation has been realized, by offering simple and intuitive interfaces to the security administrators for writing access control policies and restrictions.
引用
收藏
页码:442 / 446
页数:5
相关论文
共 50 条
  • [1] A Temporal Semantic-Based Access Control Model
    Ravari, Ali Noorollahi
    Amini, Morteza
    Jalili, Rasool
    [J]. ADVANCES IN COMPUTER SCIENCE AND ENGINEERING, 2008, 6 : 559 - 568
  • [2] A semantic-based access control mechanism for distributed systems
    Sadeghi, Mersedeh
    Sartor, Luca
    Rossi, Matteo
    [J]. 36TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2021, 2021, : 1864 - 1873
  • [3] A Semantic-based Access Control Approach for Systems of Systems
    Sadeghi, Mersedeh
    Sartor, Luca
    Rossi, Matteo
    [J]. APPLIED COMPUTING REVIEW, 2021, 21 (04): : 5 - 19
  • [4] Handling Context in a Semantic-based Access Control Framework
    Ehsan, Moussa A.
    Amini, Morteza
    Jalili, Rasool
    [J]. 2009 INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS: WAINA, VOLS 1 AND 2, 2009, : 103 - 108
  • [5] Semantic-based Obligation for Context-Based Access Control
    Al-Wahah, Mouiad
    Saaudi, Ahmed
    Farkas, Csilla
    [J]. PROCEEDINGS OF THE 16TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS, VOL 2: SECRYPT, 2019, : 535 - 540
  • [6] Semantic-based role matching and dynamic inspection for smart access control
    Xin Su
    Yiming Liu
    Yuanzhe Geng
    Yihang Yang
    Dongmin Choi
    [J]. Multimedia Tools and Applications, 2018, 77 : 18545 - 18562
  • [7] Semantic-based role matching and dynamic inspection for smart access control
    Su, Xin
    Liu, Yiming
    Geng, Yuanzhe
    Yang, Yihang
    Choi, Dongmin
    [J]. MULTIMEDIA TOOLS AND APPLICATIONS, 2018, 77 (14) : 18545 - 18562
  • [8] A Semantic-Based Access Control for Ensuring Data Security in Cloud Computing
    Auxilia, M.
    Raja, K.
    [J]. 2012 INTERNATIONAL CONFERENCE ON RADAR, COMMUNICATION AND COMPUTING (ICRCC), 2012, : 171 - 175
  • [9] Semantic-based data access services on the grid
    Huang, H
    Shi, ZZ
    Cheng, Y
    Qiu, LR
    He, XX
    [J]. PROCEEDINGS OF THE 8TH JOINT CONFERENCE ON INFORMATION SCIENCES, VOLS 1-3, 2005, : 1554 - 1557
  • [10] Semantic-Based Access to Composite Mobile Services
    Yang, Xu
    Bouguettaya, Athman
    Liu, Xumin
    [J]. INTERNATIONAL JOURNAL OF WEB SERVICES RESEARCH, 2011, 8 (03) : 70 - 100