• DocumentCode
    2754578
  • Title

    Spatio temporal emergency role based access control (STEM-RBAC): A time and location aware role based access control model with a break the glass mechanism

  • Author

    Georgakakis, Emmanouil ; Nikolidakis, Stefanos A. ; Vergados, Dimitrios D. ; Douligeris, Christos

  • Author_Institution
    Dept. of Inf., Univ. of Piraeus, Piraeus, Greece
  • fYear
    2011
  • fDate
    June 28 2011-July 1 2011
  • Firstpage
    764
  • Lastpage
    770
  • Abstract
    The ever-increasing use of information systems and networks in every aspect of our lives has made possible the transfer of data to a wide range of different users and applications. In recent years, several architectures and models have been proposed in order to limit access to resources and ensure that data are available only to authorized users, programs or processes. These models in most cases are not dynamic and the permissions assigned to users are granted based on a static policy. A mechanism that will allow exception access to data, for example to medical information, in case of an emergency is needed. In current systems, emergency access techniques are not well defined and are used in an ad hoc manner on top of the access control mechanisms implemented without using parameters such as time, location or hierarchy of the actors involved in the system. In this paper, we present a model that provides both a normal access control based on roles and also a mechanism that is used in order to provide exception access to data in case of an emergency. The proposed emergency access mechanism is time aware and takes into account the mobility and location of users, also it grants exception access with a controlled manner in case of an emergency utilizing role hierarchies.
  • Keywords
    authorisation; information retrieval; medical information systems; mobile computing; spatiotemporal phenomena; STEM-RBAC; ad hoc manner; data transfer; emergency access technique; glass mechanism; location aware role based access control model; medical information; spatiotemporal emergency role based access control; Access control; Break The Glass; Electronic Healthcare Record; Emergency Access; Spatio Temporal RBAC;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computers and Communications (ISCC), 2011 IEEE Symposium on
  • Conference_Location
    Kerkyra
  • ISSN
    1530-1346
  • Print_ISBN
    978-1-4577-0680-6
  • Electronic_ISBN
    1530-1346
  • Type

    conf

  • DOI
    10.1109/ISCC.2011.5983932
  • Filename
    5983932