Cargando…

Access Control based on Attribute Certificates for Medical Intranet Applications

BACKGROUND: Clinical information systems frequently use intranet and Internet technologies. However these technologies have emphasized sharing and not security, despite the sensitive and private nature of much health information. Digital certificates (electronic documents which recognize an entity o...

Descripción completa

Detalles Bibliográficos
Autores principales: Mavridis, Ioannis, Georgiadis, Christos, Pangalos, George, Khair, Marie
Formato: Texto
Lenguaje:English
Publicado: Gunther Eysenbach 2001
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1761880/
https://www.ncbi.nlm.nih.gov/pubmed/11720951
http://dx.doi.org/10.2196/jmir.3.1.e9
_version_ 1782131502830583808
author Mavridis, Ioannis
Georgiadis, Christos
Pangalos, George
Khair, Marie
author_facet Mavridis, Ioannis
Georgiadis, Christos
Pangalos, George
Khair, Marie
author_sort Mavridis, Ioannis
collection PubMed
description BACKGROUND: Clinical information systems frequently use intranet and Internet technologies. However these technologies have emphasized sharing and not security, despite the sensitive and private nature of much health information. Digital certificates (electronic documents which recognize an entity or its attributes) can be used to control access in clinical intranet applications. OBJECTIVES: To outline the need for access control in distributed clinical database systems, to describe the use of digital certificates and security policies, and to propose the architecture for a system using digital certificates, cryptography and security policy to control access to clinical intranet applications. METHODS: We have previously developed a security policy, DIMEDAC (Distributed Medical Database Access Control), which is compatible with emerging public key and privilege management infrastructure. In our implementation approach we propose the use of digital certificates, to be used in conjunction with DIMEDAC. RESULTS: Our proposed access control system consists of two phases: the ways users gain their security credentials; and how these credentials are used to access medical data. Three types of digital certificates are used: identity certificates for authentication; attribute certificates for authorization; and access-rule certificates for propagation of access control policy. Once a user is identified and authenticated, subsequent access decisions are based on a combination of identity and attribute certificates, with access-rule certificates providing the policy framework. CONCLUSIONS: Access control in clinical intranet applications can be successfully and securely managed through the use of digital certificates and the DIMEDAC security policy.
format Text
id pubmed-1761880
institution National Center for Biotechnology Information
language English
publishDate 2001
publisher Gunther Eysenbach
record_format MEDLINE/PubMed
spelling pubmed-17618802007-01-03 Access Control based on Attribute Certificates for Medical Intranet Applications Mavridis, Ioannis Georgiadis, Christos Pangalos, George Khair, Marie J Med Internet Res Original Paper BACKGROUND: Clinical information systems frequently use intranet and Internet technologies. However these technologies have emphasized sharing and not security, despite the sensitive and private nature of much health information. Digital certificates (electronic documents which recognize an entity or its attributes) can be used to control access in clinical intranet applications. OBJECTIVES: To outline the need for access control in distributed clinical database systems, to describe the use of digital certificates and security policies, and to propose the architecture for a system using digital certificates, cryptography and security policy to control access to clinical intranet applications. METHODS: We have previously developed a security policy, DIMEDAC (Distributed Medical Database Access Control), which is compatible with emerging public key and privilege management infrastructure. In our implementation approach we propose the use of digital certificates, to be used in conjunction with DIMEDAC. RESULTS: Our proposed access control system consists of two phases: the ways users gain their security credentials; and how these credentials are used to access medical data. Three types of digital certificates are used: identity certificates for authentication; attribute certificates for authorization; and access-rule certificates for propagation of access control policy. Once a user is identified and authenticated, subsequent access decisions are based on a combination of identity and attribute certificates, with access-rule certificates providing the policy framework. CONCLUSIONS: Access control in clinical intranet applications can be successfully and securely managed through the use of digital certificates and the DIMEDAC security policy. Gunther Eysenbach 2001-03-17 /pmc/articles/PMC1761880/ /pubmed/11720951 http://dx.doi.org/10.2196/jmir.3.1.e9 Text en © Ioannis Mavridis, Christos Georgiadis, George Pangalos, Marie Khair. Originally published in the Journal of Medical Internet Research (http://www.jmir.org), 17.3.2001. Except where otherwise noted, articles published in the Journal of Medical Internet Research are distributed under the terms of the Creative Commons Attribution License (http://www.creativecommons.org/licenses/by/2.0/), which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited, including full bibliographic details and the URL (see "please cite as" above), and this statement is included.
spellingShingle Original Paper
Mavridis, Ioannis
Georgiadis, Christos
Pangalos, George
Khair, Marie
Access Control based on Attribute Certificates for Medical Intranet Applications
title Access Control based on Attribute Certificates for Medical Intranet Applications
title_full Access Control based on Attribute Certificates for Medical Intranet Applications
title_fullStr Access Control based on Attribute Certificates for Medical Intranet Applications
title_full_unstemmed Access Control based on Attribute Certificates for Medical Intranet Applications
title_short Access Control based on Attribute Certificates for Medical Intranet Applications
title_sort access control based on attribute certificates for medical intranet applications
topic Original Paper
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1761880/
https://www.ncbi.nlm.nih.gov/pubmed/11720951
http://dx.doi.org/10.2196/jmir.3.1.e9
work_keys_str_mv AT mavridisioannis accesscontrolbasedonattributecertificatesformedicalintranetapplications
AT georgiadischristos accesscontrolbasedonattributecertificatesformedicalintranetapplications
AT pangalosgeorge accesscontrolbasedonattributecertificatesformedicalintranetapplications
AT khairmarie accesscontrolbasedonattributecertificatesformedicalintranetapplications