A method to implement fine-grained access control for personal health records through standard relational database queries

被引:20
|
作者
Sujansky, Walter V. [1 ]
Faus, Sam A. [1 ]
Stone, Ethan [2 ]
Brennan, Patricia Flatley [3 ]
机构
[1] Sujansky & Associates LLC, San Carlos, CA USA
[2] Corman Technol Inc, Santa Rosa, CA USA
[3] Univ Wisconsin Madison, Sch Nursing, Madison, WI USA
关键词
Personal health record; Access control; Security; Relational database; SQL; XACML;
D O I
10.1016/j.jbi.2010.08.001
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Online personal health records (PHRs) enable patients to access, manage, and share certain of their own health information electronically. This capability creates the need for precise access-controls mechanisms that restrict the sharing of data to that intended by the patient. The authors describe the design and implementation of an access-control mechanism for PHR repositories that is modeled on the eXtensible Access Control Markup Language (XACML) standard, but intended to reduce the cognitive and computational complexity of XACML. The authors implemented the mechanism entirely in a relational database system using ANSI-standard SQL statements. Based on a set of access-control rules encoded as relational table rows, the mechanism determines via a single SQL query whether a user who accesses patient data from a specific application is authorized to perform a requested operation on a specified data object. Testing of this query on a moderately large database has demonstrated execution times consistently below 100 ms. The authors include the details of the implementation, including algorithms, examples, and a test database as Supplementary materials. (C) 2010 Elsevier Inc. All rights reserved.
引用
收藏
页码:S46 / S50
页数:5
相关论文
共 50 条
  • [1] HealthPass: Fine-grained Access Control to Portable Personal Health Records
    Steele, Robert
    Min, Kyongho
    [J]. 2010 24TH IEEE INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2010, : 1012 - 1019
  • [2] Fine-grained Access Control for Personal Health Records in Cloud Computing
    Li, Wei
    Ni, Wei
    Liu, Dongxi
    Liu, Ren Ping
    Wang, Peishun
    Luo, Shoushan
    [J]. 2017 IEEE 85TH VEHICULAR TECHNOLOGY CONFERENCE (VTC SPRING), 2017,
  • [3] Unified Fine-Grained Access Control for Personal Health Records in Cloud Computing
    Li, Wei
    Liu, Bonnie M.
    Liu, Dongxi
    Liu, Ren Ping
    Wang, Peishun
    Luo, Shoushan
    Ni, Wei
    [J]. IEEE JOURNAL OF BIOMEDICAL AND HEALTH INFORMATICS, 2019, 23 (03) : 1278 - 1289
  • [4] Efficient Fine-Grained Access Control for Secure Personal Health Records in Cloud Computing
    He, Kai
    Weng, Jian
    Liu, Joseph K.
    Zhou, Wanlei
    Liu, Jia-Nan
    [J]. NETWORK AND SYSTEM SECURITY, (NSS 2016), 2016, 9955 : 65 - 79
  • [5] A searchable personal health records framework with fine-grained access control in cloud-fog computing
    Sun, Jin
    Wang, Xiaojing
    Wang, Shangping
    Ren, Lili
    [J]. PLOS ONE, 2018, 13 (11):
  • [6] A fine-grained access control model for relational databases
    Shi, Jie
    Zhu, Hong
    [J]. JOURNAL OF ZHEJIANG UNIVERSITY-SCIENCE C-COMPUTERS & ELECTRONICS, 2010, 11 (08): : 575 - 586
  • [8] A fine-grained access control model for relational databases
    Jie Shi
    Hong Zhu
    [J]. Journal of Zhejiang University SCIENCE C, 2010, 11 : 575 - 586
  • [9] Fine-grained access control for database management systems
    Zhu, Hong
    Lue, Kevin
    [J]. DATA MANAGEMENT: DATA, DATA EVERYWHERE, PROCEEDINGS, 2007, 4587 : 215 - +
  • [10] Fine-Grained Spatial Access Control in Spatial Database
    Chen Zhen
    Chen Rongguo
    Xie Jiong
    [J]. ADVANCED TECHNOLOGY IN TEACHING - PROCEEDINGS OF THE 2009 3RD INTERNATIONAL CONFERENCE ON TEACHING AND COMPUTATIONAL SCIENCE (WTCS 2009), VOL 2: EDUCATION, PSYCHOLOGY AND COMPUTER SCIENCE, 2012, 117 : 823 - 830