Fine-Grained Access Control for Smart Healthcare Systems in the Internet of Things

被引:0
|
作者
Pal, Shantanu [1 ]
Hitchens, Michael [1 ]
Varadharajan, Vijay [2 ]
Rabehaja, Tahiry [1 ]
机构
[1] Department of Computing, Macquarie University, Sydney,NSW,2019, Australia
[2] Advanced Cyber Security Engineering Research Centre, University of Newcastle, NSW,2308, Australia
关键词
D O I
10.4108/eai.20-3-2018.154370
中图分类号
学科分类号
摘要
There has been tremendous growth in the application of the Internet of Things (IoT) in our daily lives. Yet with this growth has come numerous security concerns and privacy challenges for both the users and the systems. Smart devices have many uses in a healthcare system, e.g. collecting and reporting patient data and controlling the administration of treatment. In this paper, we address the specific security issue of access control for smart healthcare systems and the protection of smart things from unauthorised access in such large scale systems. Commonly used access control approaches e.g. Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC) and Capability-Based Access Control (CapBAC) do not, in isolation, provide a complete solution for securing access to IoT-enabled smart healthcare devices. They may, for example, require an overly-centralised solution or an unmanageably large policy base. We propose a novel access control architecture which improves policy management by reducing the required number of authentication policies in a large-scale healthcare system while providing fine-grained access control. The devised access control model employs attributes, roles and capabilities. We apply attributes for role membership assignment and in permission evaluation. Membership of roles grants capabilities. The capabilities which are issued may be parameterised based on attributes of the user and are then used to access specific services provided by things. We also provide a formal specification of the model and a description of its implementation and demonstrate its application through different use-case scenarios. The evaluation results of core functionality of our architecture are provided with the practical testbed experiments. © 2018. Shantanu Pal et al.
引用
收藏
相关论文
共 50 条
  • [31] A Fine-Grained and Dynamic Access Control Model for Smart Home in Cloud Environment
    Xie, Pengshou
    Zhang, Pengyun
    Feng, Tao
    Zhang, Minghu
    Li, Xiaoye
    Qi, Linge
    International Journal of Network Security, 2023, 25 (06) : 970 - 982
  • [32] Flexible and Fine-Grained Access Control for EHR in Blockchain-Assisted E-Healthcare Systems
    Chen, Dajiang
    Zhang, Li
    Liao, Zeyu
    Dai, Hong-Ning
    Zhang, Ning
    Shen, Xuemin
    Pang, Minghui
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (06) : 10992 - 11007
  • [33] Privacy-Aware Efficient Fine-Grained Data Access Control in Internet of Medical Things Based Fog computing
    Wang, Xiaofan
    Wang, Lei
    Li, Yujun
    Gai, Keke
    IEEE ACCESS, 2018, 6 : 47657 - 47665
  • [34] Fine-Grained Encryption for Search and Rescue Operation on Internet of Things
    Li, Depeng
    Sampalli, Srinivas
    Aung, Zeyar
    Williams, John
    Sanchez, Abel
    2014 ASIA-PACIFIC WORLD CONGRESS ON COMPUTER SCIENCE AND ENGINEERING (APWC ON CSE), 2014,
  • [35] Efficient and Fine-Grained Sharing of Signed Healthcare Data in Smart Healthcare
    Liu, Jianghua
    Xu, Lei
    Gu, Bruce
    Cui, Lei
    Zhu, Fei
    NETWORK AND SYSTEM SECURITY, NSS 2022, 2022, 13787 : 443 - 458
  • [36] Towards a fine-grained access control for Cloud
    Msahli, Mounira
    Chen, Xiuzhen
    Serhrouchni, Ahmed
    2014 IEEE 11TH INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE), 2014, : 286 - 291
  • [37] Delegatable access control for fine-grained XML
    Wu, J
    Seberry, J
    Mu, Y
    Ruan, C
    11TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS WORKSHOPS, VOL II, PROCEEDINGS,, 2005, : 270 - 274
  • [38] Fine-grained Access Control to Web Databases
    Roichman, Alex
    Gudes, Ehud
    SACMAT'07: PROCEEDINGS OF THE 12TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2007, : 31 - 40
  • [39] Fine-grained integration of access control policies
    Rao, Prathima
    Lin, Dan
    Bertino, Elisa
    Li, Ninghui
    Lobo, Jorge
    COMPUTERS & SECURITY, 2011, 30 (2-3) : 91 - 107
  • [40] A Fine-Grained Image Access Control Model
    Al Bouna, Bechara
    Chbeir, Richard
    Gabillon, Alban
    Capolsini, Patrick
    8TH INTERNATIONAL CONFERENCE ON SIGNAL IMAGE TECHNOLOGY & INTERNET BASED SYSTEMS (SITIS 2012), 2012, : 603 - 612