Cargando…

An Event Driven Hybrid Identity Management Approach to Privacy Enhanced e-Health

Credential-based authorization offers interesting advantages for ubiquitous scenarios involving limited devices such as sensors and personal mobile equipment: the verification can be done locally; it offers a more reduced computational cost than its competitors for issuing, storing, and verification...

Descripción completa

Detalles Bibliográficos
Autores principales: Sánchez-Guerrero, Rosa, Almenárez, Florina, Díaz-Sánchez, Daniel, Marín, Andrés, Arias, Patricia, Sanvido, Fabio
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Molecular Diversity Preservation International (MDPI) 2012
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3386733/
https://www.ncbi.nlm.nih.gov/pubmed/22778634
http://dx.doi.org/10.3390/s120506129
_version_ 1782237014088744960
author Sánchez-Guerrero, Rosa
Almenárez, Florina
Díaz-Sánchez, Daniel
Marín, Andrés
Arias, Patricia
Sanvido, Fabio
author_facet Sánchez-Guerrero, Rosa
Almenárez, Florina
Díaz-Sánchez, Daniel
Marín, Andrés
Arias, Patricia
Sanvido, Fabio
author_sort Sánchez-Guerrero, Rosa
collection PubMed
description Credential-based authorization offers interesting advantages for ubiquitous scenarios involving limited devices such as sensors and personal mobile equipment: the verification can be done locally; it offers a more reduced computational cost than its competitors for issuing, storing, and verification; and it naturally supports rights delegation. The main drawback is the revocation of rights. Revocation requires handling potentially large revocation lists, or using protocols to check the revocation status, bringing extra communication costs not acceptable for sensors and other limited devices. Moreover, the effective revocation consent—considered as a privacy rule in sensitive scenarios—has not been fully addressed. This paper proposes an event-based mechanism empowering a new concept, the sleepyhead credentials, which allows to substitute time constraints and explicit revocation by activating and deactivating authorization rights according to events. Our approach is to integrate this concept in IdM systems in a hybrid model supporting delegation, which can be an interesting alternative for scenarios where revocation of consent and user privacy are critical. The delegation includes a SAML compliant protocol, which we have validated through a proof-of-concept implementation. This article also explains the mathematical model describing the event-based model and offers estimations of the overhead introduced by the system. The paper focus on health care scenarios, where we show the flexibility of the proposed event-based user consent revocation mechanism.
format Online
Article
Text
id pubmed-3386733
institution National Center for Biotechnology Information
language English
publishDate 2012
publisher Molecular Diversity Preservation International (MDPI)
record_format MEDLINE/PubMed
spelling pubmed-33867332012-07-09 An Event Driven Hybrid Identity Management Approach to Privacy Enhanced e-Health Sánchez-Guerrero, Rosa Almenárez, Florina Díaz-Sánchez, Daniel Marín, Andrés Arias, Patricia Sanvido, Fabio Sensors (Basel) Article Credential-based authorization offers interesting advantages for ubiquitous scenarios involving limited devices such as sensors and personal mobile equipment: the verification can be done locally; it offers a more reduced computational cost than its competitors for issuing, storing, and verification; and it naturally supports rights delegation. The main drawback is the revocation of rights. Revocation requires handling potentially large revocation lists, or using protocols to check the revocation status, bringing extra communication costs not acceptable for sensors and other limited devices. Moreover, the effective revocation consent—considered as a privacy rule in sensitive scenarios—has not been fully addressed. This paper proposes an event-based mechanism empowering a new concept, the sleepyhead credentials, which allows to substitute time constraints and explicit revocation by activating and deactivating authorization rights according to events. Our approach is to integrate this concept in IdM systems in a hybrid model supporting delegation, which can be an interesting alternative for scenarios where revocation of consent and user privacy are critical. The delegation includes a SAML compliant protocol, which we have validated through a proof-of-concept implementation. This article also explains the mathematical model describing the event-based model and offers estimations of the overhead introduced by the system. The paper focus on health care scenarios, where we show the flexibility of the proposed event-based user consent revocation mechanism. Molecular Diversity Preservation International (MDPI) 2012-05-10 /pmc/articles/PMC3386733/ /pubmed/22778634 http://dx.doi.org/10.3390/s120506129 Text en © 2012 by the authors; licensee MDPI, Basel, Switzerland This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution license (http://creativecommons.org/licenses/by/3.0/).
spellingShingle Article
Sánchez-Guerrero, Rosa
Almenárez, Florina
Díaz-Sánchez, Daniel
Marín, Andrés
Arias, Patricia
Sanvido, Fabio
An Event Driven Hybrid Identity Management Approach to Privacy Enhanced e-Health
title An Event Driven Hybrid Identity Management Approach to Privacy Enhanced e-Health
title_full An Event Driven Hybrid Identity Management Approach to Privacy Enhanced e-Health
title_fullStr An Event Driven Hybrid Identity Management Approach to Privacy Enhanced e-Health
title_full_unstemmed An Event Driven Hybrid Identity Management Approach to Privacy Enhanced e-Health
title_short An Event Driven Hybrid Identity Management Approach to Privacy Enhanced e-Health
title_sort event driven hybrid identity management approach to privacy enhanced e-health
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3386733/
https://www.ncbi.nlm.nih.gov/pubmed/22778634
http://dx.doi.org/10.3390/s120506129
work_keys_str_mv AT sanchezguerrerorosa aneventdrivenhybrididentitymanagementapproachtoprivacyenhancedehealth
AT almenarezflorina aneventdrivenhybrididentitymanagementapproachtoprivacyenhancedehealth
AT diazsanchezdaniel aneventdrivenhybrididentitymanagementapproachtoprivacyenhancedehealth
AT marinandres aneventdrivenhybrididentitymanagementapproachtoprivacyenhancedehealth
AT ariaspatricia aneventdrivenhybrididentitymanagementapproachtoprivacyenhancedehealth
AT sanvidofabio aneventdrivenhybrididentitymanagementapproachtoprivacyenhancedehealth
AT sanchezguerrerorosa eventdrivenhybrididentitymanagementapproachtoprivacyenhancedehealth
AT almenarezflorina eventdrivenhybrididentitymanagementapproachtoprivacyenhancedehealth
AT diazsanchezdaniel eventdrivenhybrididentitymanagementapproachtoprivacyenhancedehealth
AT marinandres eventdrivenhybrididentitymanagementapproachtoprivacyenhancedehealth
AT ariaspatricia eventdrivenhybrididentitymanagementapproachtoprivacyenhancedehealth
AT sanvidofabio eventdrivenhybrididentitymanagementapproachtoprivacyenhancedehealth