A Clark-Wilson and ANSI role-based access control model

被引:7
|
作者
Tsegaye, Tamir [1 ]
Flowerday, Stephen [1 ]
机构
[1] Rhodes Univ, Dept Informat Syst, Grahamstown, South Africa
关键词
Access control; Role-based access control; Attribute-based access control; Clark-Wilson; Security; Privacy; Electronic health record; ELECTRONIC HEALTH RECORDS; SECURITY; PRIVACY; SYSTEMS; FRAMEWORK; ADOPTION; ISSUES;
D O I
10.1108/ICS-08-2019-0100
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose An electronic health record (EHR) enables clinicians to access and share patient information electronically and has the ultimate goal of improving the delivery of healthcare. However, this can create security and privacy risks to patient information. This paper aims to present a model for securing the EHR based on role-based access control (RBAC), attribute-based access control (ABAC) and the Clark-Wilson model. Design/methodology/approach A systematic literature review was conducted which resulted in the collection of secondary data that was used as the content analysis sample. Using the MAXQDA software program, the secondary data was analysed quantitatively using content analysis, resulting in 2,856 tags, which informed the discussion. An expert review was conducted to evaluate the proposed model using an evaluation framework. Findings The study found that a combination of RBAC, ABAC and the Clark-Wilson model may be used to secure the EHR. While RBAC is applicable to healthcare, as roles are linked to an organisation's structure, its lack of dynamic authorisation is addressed by ABAC. Additionally, key concepts of the Clark-Wilson model such as well-formed transactions, authentication, separation of duties and auditing can be used to secure the EHR. Originality/value Although previous studies have been based on a combination of RBAC and ABAC, this study also uses key concepts of the Clark-Wilson model for securing the EHR. Countries implementing the EHR can use the model proposed by this study to help secure the EHR while also providing EHR access in a medical emergency.
引用
收藏
页码:373 / 395
页数:23
相关论文
共 50 条
  • [41] Study of Role-based Access Control
    Cao Yonghui
    EBM 2010: INTERNATIONAL CONFERENCE ON ENGINEERING AND BUSINESS MANAGEMENT, VOLS 1-8, 2010, : 5209 - 5212
  • [42] Migrating to role-based access control
    Brooks, K
    FOURTH ACM WORKSHOP ON ROLE-BASED ACCESS CONTROL, PROCEEDINGS, 1999, : 71 - 81
  • [43] A Purpose-Involved Role-Based Access Control Model
    Wang, Yingjie
    Zhou, Zhihong
    Li, Jianhua
    FOUNDATIONS OF INTELLIGENT SYSTEMS (ISKE 2013), 2014, 277 : 1119 - 1131
  • [44] Detecting and Resolving Misconfigurations in Role-Based Access Control
    Mukkamala, Ravi
    Kamisetty, Vishnu
    Yedugani, Pawankumar
    INFORMATION SYSTEMS SECURITY, PROCEEDINGS, 2009, 5905 : 318 - 325
  • [45] A generalized temporal and spatial role-based access control model
    Chen H.-C.
    Wang S.-J.
    Wen J.-H.
    Huang Y.-F.
    Chen C.-W.
    Journal of Networks, 2010, 5 (08) : 912 - 920
  • [46] Hierarchical Role-Based Access Control with Homomorphic Encryption for Database as a Service
    Hingwe, Kamlesh Kumar
    Bhanu, S. Mary Saira
    PROCEEDINGS OF INTERNATIONAL CONFERENCE ON ICT FOR SUSTAINABLE DEVELOPMENT ICT4SD 2015, VOL 2, 2016, 409 : 437 - 448
  • [47] Consistency maintenance for constraint in role-based access control model
    Wei-li Han
    Gang Chen
    Jian-wei Yin
    Jin-xiang Dong
    Journal of Zhejiang University-SCIENCE A, 2002, 3 (3): : 292 - 297
  • [48] An improved administration method on role-based access control in the enterprise environment
    Oh, S
    Park, S
    JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2001, 17 (06) : 921 - 944
  • [49] Severity Level of Permissions in Role-Based Access Control
    Belim, S. V.
    Bogachenko, N. F.
    Kabanov, A. N.
    2018 12TH INTERNATIONAL IEEE SCIENTIFIC AND TECHNICAL CONFERENCE ON DYNAMICS OF SYSTEMS, MECHANISMS AND MACHINES (DYNAMICS), 2018,
  • [50] Universally Composable Cryptographic Role-Based Access Control
    Liu, Bin
    Warinschi, Bogdan
    PROVABLE SECURITY, (PROVSEC 2016), 2016, 10005 : 61 - 80