Sabiá: an authentication, authorization, and user data delivery architecture based on user consent for health information systems in Brazil

被引:0
|
作者
de Paiva Marques Carvalho T. [1 ,2 ]
de Paiva J.C. [1 ,2 ]
de Medeiros Valentim R.A. [1 ]
Silva C.B.P. [2 ]
de Lima D.F. [1 ]
Silva E.C. [1 ]
机构
[1] Laboratory for Technological Innovation in Healthcare (LAIS), Federal University of Rio Grande do Norte (UFRN), R. Dr. Nilo Bezerra Ramalho, 1692 - Tirol, Natal, 59015-300, RN
[2] Federal Institute of Rio Grande do Norte (IFRN), R. Dr. Nilo Bezerra Ramalho, 1692 - Tirol, Natal, 59015-300, RN
关键词
Authentication; Authorization; Health information systems; Interoperability; User consent;
D O I
10.1007/s42600-020-00058-8
中图分类号
学科分类号
摘要
Purpose: Health information systems in Brazil have been designed and developed in a heterogeneous manner based on local regional characteristics, resulting in a lack of health information integrity. In this context, the Brazilian Ministry of Health pointed out the need for interoperability solutions of health information systems, noting the importance of integration with national databases and alignment with Brazilian data protection laws. Therefore, this paper presents Sabiá, a platform for authentication, authorization, and data delivery based on user consent for health information systems in Brazil. Methods: Sabiá’s architecture is designed to achieve the following requirements: (R1) Provide a Federated Identity; (R2) Be a Federated Resource Manager; (R3) Collect user data from different information systems; and (R4) Deliver user data to systems based on user consent. Sabiá consists of three main components: (1) Sabiá Authorization Server, responsible for implementing Open Authentication; (2) Sabiá Collector, responsible for collecting data from different information systems; and (3) Sabiá Resource Server, responsible for delivering data previously authorized by the user to the systems. Results: After analyzing historical data, R4 functionality was selected to be submitted to performance testing because it is the process that most affects overall system performance. The tests aimed at analyzing Sabiá’s behavior in the heaviest scenario based on historical data. Conclusion: The results showed no flaws and indicated system stability and consistency, in which the user perceives a system reaction instantaneous, whose response time averages remained below 100 ms. © 2020, Sociedade Brasileira de Engenharia Biomedica.
引用
收藏
页码:197 / 202
页数:5
相关论文
共 50 条
  • [1] Authentication and Authorization of End User in Microservice Architecture
    He, Xiuyu
    Yang, Xudong
    2017 INTERNATIONAL CONFERENCE ON CLOUD TECHNOLOGY AND COMMUNICATION ENGINEERING (CTCE2017), 2017, 910
  • [2] A UPnP extension for enabling user authentication and authorization in pervasive systems
    Sales T.
    Sales L.
    Almeida H.
    Perkusich A.
    Journal of the Brazilian Computer Society, 2010, 16 (04) : 261 - 277
  • [3] A Security Architecture Based on User Authentication of Bluetooth
    Xin, Yu
    Ting, Yan
    2009 INTERNATIONAL FORUM ON INFORMATION TECHNOLOGY AND APPLICATIONS, VOL 3, PROCEEDINGS, 2009, : 627 - +
  • [4] The need and practice of user authentication and TTP services in distributed health information systems
    Blobel, B
    Pharow, P
    TRUSTED INFORMATION: THE NEW DECADE CHALLENGE, 2001, 65 : 61 - 76
  • [5] A Private User Data Protection Mechanism in TrustZone Architecture Based on Identity Authentication
    Bo Zhao
    Yu Xiao
    Yuqing Huang
    Xiaoyu Cui
    Tsinghua Science and Technology, 2017, (02) : 218 - 225
  • [6] A Private User Data Protection Mechanism in TrustZone Architecture Based on Identity Authentication
    Zhao, Bo
    Xiao, Yu
    Huang, Yuqing
    Cui, Xiaoyu
    TSINGHUA SCIENCE AND TECHNOLOGY, 2017, 22 (02) : 218 - 225
  • [7] A Private User Data Protection Mechanism in TrustZone Architecture Based on Identity Authentication
    Bo Zhao
    Yu Xiao
    Yuqing Huang
    Xiaoyu Cui
    Tsinghua Science and Technology, 2017, 22 (02) : 218 - 225
  • [8] Design and Evaluation of an Architecture for Ubiquitous User Authentication based on Identity Management Systems
    Barisch, Marc
    TRUSTCOM 2011: 2011 INTERNATIONAL JOINT CONFERENCE OF IEEE TRUSTCOM-11/IEEE ICESS-11/FCST-11, 2011, : 863 - 872
  • [9] User preferences for adaptive user interfaces in health information systems
    Mahboubeh Eslami
    Mohammad Firoozabadi
    Elaheh Homayounvala
    Universal Access in the Information Society, 2018, 17 : 875 - 883
  • [10] User preferences for adaptive user interfaces in health information systems
    Eslami, Mahboubeh
    Firoozabadi, Mohammad
    Homayounvala, Elaheh
    UNIVERSAL ACCESS IN THE INFORMATION SOCIETY, 2018, 17 (04) : 875 - 883