Fine-Grained Access Control for Smart Healthcare Systems in the Internet of Things

被引:0
|
作者
Pal, Shantanu [1 ]
Hitchens, Michael [1 ]
Varadharajan, Vijay [2 ]
Rabehaja, Tahiry [1 ]
机构
[1] Department of Computing, Macquarie University, Sydney,NSW,2019, Australia
[2] Advanced Cyber Security Engineering Research Centre, University of Newcastle, NSW,2308, Australia
关键词
D O I
10.4108/eai.20-3-2018.154370
中图分类号
学科分类号
摘要
There has been tremendous growth in the application of the Internet of Things (IoT) in our daily lives. Yet with this growth has come numerous security concerns and privacy challenges for both the users and the systems. Smart devices have many uses in a healthcare system, e.g. collecting and reporting patient data and controlling the administration of treatment. In this paper, we address the specific security issue of access control for smart healthcare systems and the protection of smart things from unauthorised access in such large scale systems. Commonly used access control approaches e.g. Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC) and Capability-Based Access Control (CapBAC) do not, in isolation, provide a complete solution for securing access to IoT-enabled smart healthcare devices. They may, for example, require an overly-centralised solution or an unmanageably large policy base. We propose a novel access control architecture which improves policy management by reducing the required number of authentication policies in a large-scale healthcare system while providing fine-grained access control. The devised access control model employs attributes, roles and capabilities. We apply attributes for role membership assignment and in permission evaluation. Membership of roles grants capabilities. The capabilities which are issued may be parameterised based on attributes of the user and are then used to access specific services provided by things. We also provide a formal specification of the model and a description of its implementation and demonstrate its application through different use-case scenarios. The evaluation results of core functionality of our architecture are provided with the practical testbed experiments. © 2018. Shantanu Pal et al.
引用
收藏
相关论文
共 50 条
  • [21] Fine-grained multiagent systems for the Internet
    Nangsue, P
    Conry, SE
    INTERNATIONAL CONFERENCE ON MULTI-AGENT SYSTEMS, PROCEEDINGS, 1998, : 198 - 205
  • [22] Fine-Grained Access Control to Medical Records in Digital Healthcare Enterprises
    Khan, M. Fahim Ferdous
    Sakamura, Ken
    2015 INTERNATIONAL SYMPOSIUM ON NETWORKS, COMPUTERS AND COMMUNICATIONS (ISNCC 2015), 2015,
  • [23] A Data Aggregation Scheme with Fine-grained Access Control for the Smart Grid
    Wen, Mi
    Zhang, Xu
    Li, Hongwei
    Li, Jinguo
    2017 IEEE 86TH VEHICULAR TECHNOLOGY CONFERENCE (VTC-FALL), 2017,
  • [24] Fine-grained Context-aware Access Control for Smart Devices
    Baresi, Luciano
    Sadeghi, Mersedeh
    2018 8TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND INFORMATION TECHNOLOGY (CSIT), 2018, : 55 - 61
  • [25] Blockchain-IoT: A revolutionary model for secure data storage and fine-grained access control in internet of things
    Ullah, Zia
    Husnain, Ghassan
    Mohmand, Muhammad Ismail
    Qadir, Mansoor
    Alzahrani, Khalid J.
    Ghadi, Yazeed Yasin
    Alkahtani, Hend Khalid
    IET COMMUNICATIONS, 2024, 18 (19) : 1524 - 1540
  • [26] Fine-Grained Access Control for Microservices
    Nehme, Antonio
    Jesus, Vitor
    Mahbub, Khaled
    Abdallah, Ali
    FOUNDATIONS AND PRACTICE OF SECURITY, FPS 2018, 2019, 11358 : 285 - 300
  • [27] Fine-Grained Access Control for Electronic Health Record Systems
    Pham Thi Bach Hue
    Wohlgemuth, Sven
    Echizen, Isao
    Dong Thi Bich Thuy
    Nguyen Dinh Thu
    U- AND E-SERVICE, SCIENCE AND TECHNOLOGY, 2010, 124 : 31 - +
  • [28] On the facilitation of fine-grained access to distributed healthcare data
    Slaymaker, Mark
    Power, David
    Russell, Douglas
    Simpson, Andrew
    SECURE DATA MANAGEMENT, PROCEEDINGS, 2008, 5159 : 169 - 184
  • [29] Fine-Grained Access to Smart Building Energy Resources
    Lee, Eun-Kyu
    Chu, Peter
    Gadh, Rajit
    IEEE INTERNET COMPUTING, 2013, 17 (06) : 48 - 56
  • [30] Multidimensional data tight aggregation and fine-grained access control in smart grid
    Lang, Bo
    Wang, Jinmiao
    Cao, Zhenhai
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2018, 40 : 156 - 165