Title :
Representation of mental health application access policy in a monotonic model
Author :
Calvelli, Claudio ; Varadharajan, Vijay
Author_Institution :
Hewlett-Packard Lab., Bristol, UK
Abstract :
The access policy to patients´ records in a mental health hospital has only a verbal specification, and many formal systems fail to represent all the aspects of this problem. This paper uses an extension of SPM, which can represent revocation and conditional tickets, to model part of this access policy. Even with our extension, SPM still remains a monotonic model, where rights can be removed only in very special cases, and this makes it impossible to represent all the aspects of the problem. Other than to serve as an example for the extensions previously proposed by the authors (1993), this paper also helps to separate aspects of this access control policy which are inherently monotonic from parts which are defined in a non-monotonic way, but can still be represented in a monotonic model
Keywords :
medical administrative data processing; security of data; SPM; access policy; data security; mental health application access policy; mental health hospital; monotonic model; patients´ records; Access control; Authentication; Guidelines; Hospitals; Permission; Scanning probe microscopy; System testing;
Conference_Titel :
Computer Security Applications Conference, 1993. Proceedings., Ninth Annual
Conference_Location :
Orlando, FL
Print_ISBN :
0-8186-4330-7
DOI :
10.1109/CSAC.1993.315439