Formal specification of role-based security policies for clinical information systems

  • Authors:
  • Karsten Sohr;Michael Drouineaud;Gail-Joon Ahn

  • Affiliations:
  • Universität Bremen, Bielefeld, Germany;Universität Bremen, Bielefeld, Germany;University of North Carolina at Charlotte Charlotte, NC

  • Venue:
  • Proceedings of the 2005 ACM symposium on Applied computing
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Many healthcare organizations have transited from their old and disparate business models based on ink and paper to a new, consolidated ones based on electronic patient records. There are significant demands on secure mechanisms for collaboration and data sharing among clinicians, patients and researchers through clinical information systems. In order to fulfil the high demands of data protection in such systems, we believe that access control policies play an important role to reduce the risks to confidentiality, integrity, and availability of medical data. In this paper, we attempt to formally specify access control policies in clinical information systems which are highly dynamic and complex environments. We leverage characteristics of temporal linear first-order logic to cope with dynamic access control policies in clinical information systems.