A Risk-aware Access Control Model for Biomedical Research Platforms

被引:1
|
作者
Badji, Radja [1 ]
Dankar, Fida K. [1 ]
机构
[1] UAEU, Coll Informat Technol, Al Ain, U Arab Emirates
关键词
Privacy Preserving Data Sharing; Privacy Risk; Access Control Models; FRAMEWORK;
D O I
10.5220/0006608403220328
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Data sharing and collaboration are important success factors for modern biomedical research. As biomedical data contains sensitive information, any mechanism that governs biomedical data sharing should protect subjects' privacy while providing high-utility data in an efficient and prompt manner. The use of biomedical data for research has been studied extensively from the legal aspect. Several regulations control its use and sharing to limit privacy risks. However, current sharing mechanisms can be a barrier to the research community needs. Going through the IRB process is time consuming and will become a bottleneck for the intensive data need of the biomedical research community. Alternatively, creating a universal de-identified research sub-dataset accessible through honest-broker-systems will not satisfy all research use-cases, as stringent de-identification methods can reduce data utility. A risk-aware access control model is a good alternative toward making data more available. In such a model, data requests are evaluated against their incurred privacy risks, and are granted access after the application of appropriate protection levels. In this paper, we describe a formal risk-aware model that will be used in the access control layer and describe the different risk components that can be combined to provide a decision against a data access request.
引用
收藏
页码:322 / 328
页数:7
相关论文
共 50 条
  • [1] XACML and Risk-Aware Access Control
    Chen, Liang
    Gasparini, Luca
    Norman, Timothy J.
    [J]. WOSIS: PROCEEDINGS OF THE 10TH INTERNATIONAL WORKSHOP ON SECURITY IN INFORMATION SYSTEMS, 2013, : 66 - 75
  • [2] Adaptive risk-aware access control model for Internet of Things
    Rath, Annanda Thavymony
    Colin, Jean-Noel
    [J]. 2017 INTERNATIONAL WORKSHOP ON SECURE INTERNET OF THINGS (SIOT 2017), 2017, : 40 - 49
  • [3] A Framework for Risk-Aware Role Based Access Control
    Bijon, Khalid Zaman
    Krishnan, Ram
    Sandhu, Ravi
    [J]. 2013 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2013, : 462 - 469
  • [4] Anomalies Correlation for Risk-Aware Access Control Enhancement
    Evina, Pierrette Annie
    Ayachi, Faten Labbene
    Jaidi, Faouzi
    Bouhoula, Adel
    [J]. PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON EVALUATION OF NOVEL APPROACHES TO SOFTWARE ENGINEERING, 2018, : 299 - 304
  • [5] Risk-Aware Control
    Sanger, Terence D.
    [J]. NEURAL COMPUTATION, 2014, 26 (12) : 2669 - 2691
  • [6] Risk-Aware Model-Based Control
    Yu, Chen
    Rosendo, Andre
    [J]. FRONTIERS IN ROBOTICS AND AI, 2021, 8
  • [7] A Risk-Aware Access Control Framework for Cyber-Physical Systems
    Akhuseyinoglu, Nuray Baltaci
    Joshi, James
    [J]. 2017 IEEE 3RD INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (CIC), 2017, : 349 - 358
  • [8] Towards Risk-aware Access Control Framework for Healthcare Information Sharing
    Abomhara, Mohamed
    Koien, Geir M.
    Oleshchuk, Vladimir A.
    Hamid, Mohamed
    [J]. ICISSP: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2018, : 312 - 321
  • [9] Risk-Aware Control and Games in Engineering
    Barreiro-Gomez, Julian
    Tembine, Hamidou
    Stella, Leonardo
    Bauso, Dario
    Colaneri, Patrizio
    [J]. 2020 59TH IEEE CONFERENCE ON DECISION AND CONTROL (CDC), 2020, : 3860 - 3870
  • [10] Risk-Aware Model Predictive Control Enabled by Bayesian Learning
    Li, Yingke
    Lin, Yifan
    Zhou, Enlu
    Zhang, Fumin
    [J]. 2022 AMERICAN CONTROL CONFERENCE, ACC, 2022, : 108 - 113