• DocumentCode
    680226
  • Title

    SIM: A smartphone-based identity management framework and its application to Arkansas trauma image repository

  • Author

    Mengjun Xie ; Topaloglu, Umit ; Powell, T. ; Chao Peng ; Jiang Bian

  • Author_Institution
    Dept. of Comput. Sci., Univ. of Arkansas at Little Rock, Little Rock, AR, USA
  • fYear
    2013
  • fDate
    18-21 Dec. 2013
  • Firstpage
    53
  • Lastpage
    60
  • Abstract
    Secure and convenient user identity management is particularly important to the success of EMR, EHR, and PHR systems. Unfortunately, widely-used identity management mechanisms that solely rely on username/password are inadequate to meet the strong security and privacy requirements for protecting sensitive user information and medical data. Two-factor authentication approaches that are more convenient and user friendly than existing solutions have been given top priority in the healthcare sector where the majority of healthcare practitioners and patients are not tech-savvy. In this paper, we present a smartphone-based identity management framework-SIM-to enhance the security and usability of user identity management in healthcare information systems. SIM leverages the popularity and computational power of smartphone. Within the SIM framework, a person employs a smartphone to centrally store and manage her identity credentials and authenticates herself to healthcare applications using two-factor authentication without typing any identity credentials. Moreover, SIM provides patients with a patient-controlled authorization mechanism to help patients manage the accesses to their PHRs in a secure and convenient manner. Using an existing EMR system-Arkansas Trauma Image Repository-as an example, we demonstrate that SIM can be applied to a real-world healthcare information system to enhance its protection of user credentials and sensitive information.
  • Keywords
    cryptographic protocols; data protection; electronic health records; health care; human computer interaction; information retrieval; security of data; smart phones; telemedicine; Arkansas Trauma Image Repository application; EHR systems; EMR systems; PHR access management; PHR systems; SIM framework; central identity credential management; central identity credential storage; convenient user identity management; healthcare applications; healthcare information systems; healthcare sector; identity credential authentication; identity management mechanisms; medical data protection; patient-controlled authorization mechanism; privacy requirements; real-world healthcare information system; security requirements; smartphone computational power; smartphone-based identity management framework; two-factor authentication approaches; user credential protection; user friendly; user identity management security; user identity management usability; user information protection; username-password authentication approaches; Authentication; Browsers; Hospitals; Malware; Servers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Bioinformatics and Biomedicine (BIBM), 2013 IEEE International Conference on
  • Conference_Location
    Shanghai
  • Type

    conf

  • DOI
    10.1109/BIBM.2013.6732600
  • Filename
    6732600