• DocumentCode
    2124547
  • Title

    Credential Based Hybrid Access Control Methodology for Shared Electronic Health Records

  • Author

    Dagdee, Nirmal ; VIjaywargiya, Ruchi

  • Author_Institution
    S.D. Bansal Coll. of Technol., Indore
  • fYear
    2009
  • fDate
    3-5 April 2009
  • Firstpage
    624
  • Lastpage
    628
  • Abstract
    Various credential based approaches have been proposed for realizing access control on shared data sources. These approaches use various types of credentials like identity certificates, attribute certificates, authorization certificate etc. The access control policies and mechanisms required in EHR must not only ensure that sensitive patient data is accessible to the authorized personnel only, but also ascertain that it is immediately available when needed in life-critical situations. The approaches based on identity credentials entail prior user registration whereas the attribute or authorization certificate based approaches incur considerable delay in fetching the appropriate certificates for granting access to shared data. Therefore these approaches are not suitable to handle immediate access required by an unknown competent user in critical situation. In this paper, we have proposed a hybrid access control methodology that not only enables immediate and open access to critical information by competent users but also provides fine grained access control on domain confined data. In this methodology, access control policy for EHR is defined using various types of credentials. Use of different types of credentials simplifies the specification of access control policy required to address the varied requirements of EHR. Credentials are supposed to be acquired independently by the user from appropriate Credential Issuing Authority and have been realized as digital certificates.
  • Keywords
    authorisation; medical information systems; attribute certificate; authorization certificate; credential based hybrid access control methodology; credential issuing authority; digital certificates; life-critical situations; shared data sources; shared electronic health records; user registration; Access control; Accidents; Authorization; Computer science; Data engineering; Delay; Health information management; Hospitals; Internet; Personnel; access control; certificate; credential;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Management and Engineering, 2009. ICIME '09. International Conference on
  • Conference_Location
    Kuala Lumpur
  • Print_ISBN
    978-0-7695-3595-1
  • Type

    conf

  • DOI
    10.1109/ICIME.2009.84
  • Filename
    5077109