DocumentCode
680226
Title
SIM: A smartphone-based identity management framework and its application to Arkansas trauma image repository
Author
Mengjun Xie ; Topaloglu, Umit ; Powell, T. ; Chao Peng ; Jiang Bian
Author_Institution
Dept. of Comput. Sci., Univ. of Arkansas at Little Rock, Little Rock, AR, USA
fYear
2013
fDate
18-21 Dec. 2013
Firstpage
53
Lastpage
60
Abstract
Secure and convenient user identity management is particularly important to the success of EMR, EHR, and PHR systems. Unfortunately, widely-used identity management mechanisms that solely rely on username/password are inadequate to meet the strong security and privacy requirements for protecting sensitive user information and medical data. Two-factor authentication approaches that are more convenient and user friendly than existing solutions have been given top priority in the healthcare sector where the majority of healthcare practitioners and patients are not tech-savvy. In this paper, we present a smartphone-based identity management framework-SIM-to enhance the security and usability of user identity management in healthcare information systems. SIM leverages the popularity and computational power of smartphone. Within the SIM framework, a person employs a smartphone to centrally store and manage her identity credentials and authenticates herself to healthcare applications using two-factor authentication without typing any identity credentials. Moreover, SIM provides patients with a patient-controlled authorization mechanism to help patients manage the accesses to their PHRs in a secure and convenient manner. Using an existing EMR system-Arkansas Trauma Image Repository-as an example, we demonstrate that SIM can be applied to a real-world healthcare information system to enhance its protection of user credentials and sensitive information.
Keywords
cryptographic protocols; data protection; electronic health records; health care; human computer interaction; information retrieval; security of data; smart phones; telemedicine; Arkansas Trauma Image Repository application; EHR systems; EMR systems; PHR access management; PHR systems; SIM framework; central identity credential management; central identity credential storage; convenient user identity management; healthcare applications; healthcare information systems; healthcare sector; identity credential authentication; identity management mechanisms; medical data protection; patient-controlled authorization mechanism; privacy requirements; real-world healthcare information system; security requirements; smartphone computational power; smartphone-based identity management framework; two-factor authentication approaches; user credential protection; user friendly; user identity management security; user identity management usability; user information protection; username-password authentication approaches; Authentication; Browsers; Hospitals; Malware; Servers;
fLanguage
English
Publisher
ieee
Conference_Titel
Bioinformatics and Biomedicine (BIBM), 2013 IEEE International Conference on
Conference_Location
Shanghai
Type
conf
DOI
10.1109/BIBM.2013.6732600
Filename
6732600
Link To Document