Activity-oriented access control to ubiquitous hospital information and services

  • Le, Xuan Hung
  • Lee, Sungyoung
  • Lee, Young-Koo
  • Lee, Heejo
  • Khalid, Murad
  • 외 1명
Citations

WEB OF SCIENCE

24
Citations

SCOPUS

33

초록

In hospital information systems, protecting the confidentiality of health information, whilst at the same time allowing authorized physicians to access it conveniently, is a crucial requirement. The need to deliver health information at the point-of-care is a primary factor to increase healthcare quality and cost efficiency. However, current systems require considerable coordination effort of hospital professionals to locate relevant documents to support a specific activity. This paper presents a flexible and dynamic access control model, Activity-Oriented Access Control (AOAC), which is based on user activity to authorize access permissions. A user is allowed to perform an activity if he/she holds a number of satisfactory attributes (i.e. roles, assignments, etc.) under a specified condition (e.g. time, location). Results of AOAC implementation in a realistic healthcare scenario have shown to meet two important requirements: protecting confidentiality of health information by denying an unauthorized access, and allowing physicians to conveniently browse medical data at the point-of-care. Furthermore, the average execution time was 0.078 s which allows AOAC to work in real-time. (C) 2010 Published by Elsevier Inc.

키워드

Access controlUbiquitous hospital information system and servicesSecurityHuman activity
제목
Activity-oriented access control to ubiquitous hospital information and services
저자
Le, Xuan HungLee, SungyoungLee, Young-KooLee, HeejoKhalid, MuradSankar, Ravi
DOI
10.1016/j.ins.2010.04.020
발행일
2010-08-15
유형
Article
저널명
Information Sciences
180
16
페이지
2979 ~ 2990