A Clark-Wilson and ANSI role-based access control model

被引:7
|
作者
Tsegaye, Tamir [1 ]
Flowerday, Stephen [1 ]
机构
[1] Rhodes Univ, Dept Informat Syst, Grahamstown, South Africa
关键词
Access control; Role-based access control; Attribute-based access control; Clark-Wilson; Security; Privacy; Electronic health record; ELECTRONIC HEALTH RECORDS; SECURITY; PRIVACY; SYSTEMS; FRAMEWORK; ADOPTION; ISSUES;
D O I
10.1108/ICS-08-2019-0100
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose An electronic health record (EHR) enables clinicians to access and share patient information electronically and has the ultimate goal of improving the delivery of healthcare. However, this can create security and privacy risks to patient information. This paper aims to present a model for securing the EHR based on role-based access control (RBAC), attribute-based access control (ABAC) and the Clark-Wilson model. Design/methodology/approach A systematic literature review was conducted which resulted in the collection of secondary data that was used as the content analysis sample. Using the MAXQDA software program, the secondary data was analysed quantitatively using content analysis, resulting in 2,856 tags, which informed the discussion. An expert review was conducted to evaluate the proposed model using an evaluation framework. Findings The study found that a combination of RBAC, ABAC and the Clark-Wilson model may be used to secure the EHR. While RBAC is applicable to healthcare, as roles are linked to an organisation's structure, its lack of dynamic authorisation is addressed by ABAC. Additionally, key concepts of the Clark-Wilson model such as well-formed transactions, authentication, separation of duties and auditing can be used to secure the EHR. Originality/value Although previous studies have been based on a combination of RBAC and ABAC, this study also uses key concepts of the Clark-Wilson model for securing the EHR. Countries implementing the EHR can use the model proposed by this study to help secure the EHR while also providing EHR access in a medical emergency.
引用
收藏
页码:373 / 395
页数:23
相关论文
共 50 条
  • [21] Securing the Web of Things with Role-Based Access Control
    Barka, Ezedine
    Mathew, Sujith Samuel
    Atif, Yacine
    CODES, CRYPTOLOGY, AND INFORMATION SECURITY, C2SI 2015, 2015, 9084 : 14 - 26
  • [22] Privacy-Aware Role-Based Access Control
    Ni, Qun
    Bertino, Elisa
    Lobo, Jorge
    Calo, Seraphin B.
    IEEE SECURITY & PRIVACY, 2009, 7 (04) : 35 - 43
  • [23] Secure databases: An analysis of Clark-Wilson model in a database environment
    Ge, XC
    Polack, F
    Laleau, R
    ADVANCED INFORMATION SYSTEMS ENGINEERING, PROCEEDINGS, 2004, 3084 : 234 - 247
  • [24] User authentication using Blockchain based smart contract in role-based access control
    Kamboj, Priyanka
    Khare, Shivang
    Pal, Sujata
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2021, 14 (05) : 2961 - 2976
  • [25] Evaluation of an Enhanced Role-Based Access Control model to manage information access in collaborative processes for a statewide clinical education program
    Le, Xuan Hung
    Doll, Terry
    Barbosu, Monica
    Luque, Amneris
    Wang, Dongwen
    JOURNAL OF BIOMEDICAL INFORMATICS, 2014, 50 : 184 - 195
  • [26] An improved Role-based workflow Access Control Model
    Zhao, Hui
    Fang, Zhiyi
    Xu, Peng
    Zhao, Lianyu
    Liu, Jin
    Wang, Tianyang
    PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: NEW GENERATIONS, 2008, : 551 - 556
  • [27] A generalized temporal role-based access control model
    Joshi, JBD
    Bertino, E
    Latif, U
    Ghafoor, A
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2005, 17 (01) : 4 - 23
  • [28] Parameterized Role-Based Access Control Policies for XML Documents
    Mueldner, Tomasz
    Leighton, Gregory
    Miziolek, Jan Krzysztof
    INFORMATION SECURITY JOURNAL, 2009, 18 (06): : 282 - 296
  • [29] On Automated Role-Based Access Control Assessment in Enterprise Systems
    Walker, Andrew
    Svacina, Jan
    Simmons, Johnathan
    Cerny, Tomas
    INFORMATION SCIENCE AND APPLICATIONS, 2020, 621 : 375 - 385
  • [30] THE PRIVACY-AWARE ACCESS CONTROL SYSTEM USING ATTRIBUTE-AND ROLE-BASED ACCESS CONTROL IN PRIVATE CLOUD
    Mon, Ei Ei
    Naing, Thinn Thu
    2011 4TH IEEE INTERNATIONAL CONFERENCE ON BROADBAND NETWORK AND MULTIMEDIA TECHNOLOGY (4TH IEEE IC-BNMT2011), 2011, : 447 - 451