Security Protection Profile on Smart Card System Using ISO 15408 Case Study: Indonesia Health Insurance Agency

被引:0
|
作者
Setyoko, Yoso Adi [1 ]
Yasirandi, Rahmat [1 ]
机构
[1] Telkom Univ, Sch Comp, Bandung, West Java, Indonesia
关键词
BP[!text type='JS']JS[!/text; smart card; ISO; 15408; 15446; security evaluation;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Indonesia Health Assurance Agency also called BPJS is the most important part of the Indonesian people as a health insurance agency. BPJS want to improve the quality of healthcare by applying information technology. One way to improve the quality of service BPJS is implementing smart card technology. this new system, BPJS smart card system, is consisted of two part, there are a smart card and smart card reader. Beside it can be searching BPJS members faster and easier than before (offline system), every card member has a temporary storage enough to save nominal of their own insurance premium. Therefore, smart card system needs security requirements to make sure data in every card member is still secure and confidential when implementing this smart card technology. With that problem, this research creates security design proposal from Protection Profile document by evaluating smart card system of BPJS using Common Criteria Framework (ISO 15408). And then this methodology research is using (ISO 15446) to guide the development of Protection Profile document. Common Criteria Framework for the security of smart card make security design becomes more systematic. This research is consisting of 3 steps, first analyzing threats, second designing security objectives, the last designing security function requirements. Threats assessment and analysis in this research has result 10 threats. From previous step then designed 12 points security objectives. At third step, the security functional requirements need to be analyzed and founded, has 36 security functional requirements from 12 points security objectives before. Prototype has built based on all of security functional requirements that already recommended. The evaluate result shows that all of system use case has been tested according system functional requirement.
引用
收藏
页码:425 / 428
页数:4
相关论文
共 11 条
  • [1] Development of Protection Profile and Security Target for Indonesia Electronic ID Card's (KTP-el) Card Reader Based on Common Criteria V3.1:2012/SNI ISO/IEC 15408:2014
    Aminanto, Muhamad Erza
    Sutikno, Sarwono
    2014 International Conference of Advanced Informatics: Concept, Theory and Application (ICAICTA), 2014, : 1 - 6
  • [2] Network security system for health and medical information using smart IC card
    Kanai, Y
    Yachida, M
    Yoshikawa, H
    Yamaguchi, M
    Ohyama, N
    MEDICAL IMAGING 1998 - PACS DESIGN AND EVALUATION: ENGINEERING AND CLINICAL ISSUES, 1998, 3339 : 23 - 30
  • [3] E-health Card Information System: Case Study Health Insurance Fund of Montenegro
    Ivanovic, Andrija
    Rakovic, Predrag
    2019 8TH MEDITERRANEAN CONFERENCE ON EMBEDDED COMPUTING (MECO), 2019, : 695 - 699
  • [4] Strengthening Existing Internet of Things System Security: Case Study of Improved Security Structure in Smart Health
    Chang, Chih-Wei
    Hung, Wei-Hsi
    SENSORS AND MATERIALS, 2021, 33 (04) : 1257 - 1272
  • [5] The Assessment of Information Security Management Process Capability using ISO/IEC 33072:2016 (Case Study in Statistics Indonesia)
    Rimawati, Yeni
    Sutikno, Sarwono
    PROCEEDINGS OF 2016 INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY SYSTEMS AND INNOVATION (ICITSI), 2016,
  • [6] Estimating heterogeneous policy impacts using causal machine learning: a case study of health insurance reform in Indonesia
    Kreif, Noemi
    DiazOrdaz, Karla
    Moreno-Serra, Rodrigo
    Mirelman, Andrew
    Hidayat, Taufik
    Suhrcke, Marc
    HEALTH SERVICES AND OUTCOMES RESEARCH METHODOLOGY, 2022, 22 (02) : 192 - 227
  • [7] Estimating heterogeneous policy impacts using causal machine learning: a case study of health insurance reform in Indonesia
    Noemi Kreif
    Karla DiazOrdaz
    Rodrigo Moreno-Serra
    Andrew Mirelman
    Taufik Hidayat
    Marc Suhrcke
    Health Services and Outcomes Research Methodology, 2022, 22 : 192 - 227
  • [8] Enhanced Information Security Management System Framework Design Using ISO 27001 And Zachman Framework A Study Case of XYZ Company
    Aginsa, Andre
    Edward, Ian Yosef Matheus
    Shalannanda, Wervyan
    2016 2ND INTERNATIONAL CONFERENCE ON WIRELESS AND TELEMATICS (ICWT), 2016, : 62 - 66
  • [9] Using smart card data to develop origin-destination matrix-based business analytics for bus rapid transit systems: case study of Jakarta, Indonesia
    Wasesa, Meditya
    Afrianto, Mochammad Agus
    Ramadhan, Fakhri Ihsan
    Sunitiyoso, Yos
    Nuraeni, Shimaditya
    Putro, Utomo Sarjono
    Hastuti, Sri
    JOURNAL OF MANAGEMENT ANALYTICS, 2024, 11 (03) : 471 - 494
  • [10] Designing Recommendations and Road Map of Governance for Quality Management System of Online SKCK Based on Information Security Using ISO 9001: 2015 and ISO 27001: 2013 (Case Study: Ditintelkam Polda ABC)
    Putra, Prima Pringgo
    Arman, Arry Akhmad
    Edward, Ian Joseph Matheus
    Shalannanda, Wervyan
    PROCEEDING OF 14TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATION SYSTEMS, SERVICES, AND APPLICATIONS (TSSA), 2020,