• DocumentCode
    2604738
  • Title

    Reconciling IHE-ATNA profile with a posteriori contextual access and usage control policy in healthcare environment

  • Author

    Azkia, Hanieh ; Cuppens-Boulahia, Nora ; Cuppens, Frédéric ; Coatrieux, Gouenou

  • Author_Institution
    IT/Telecom Bretagne, Cesson Sevigne, France
  • fYear
    2010
  • fDate
    23-25 Aug. 2010
  • Firstpage
    197
  • Lastpage
    203
  • Abstract
    Traditional access control mechanisms prevent illegal access by controlling access right before executing an action; they belong to a class of a priori security solutions and, from this point of view, they have some limitations, like inflexibility in unanticipated circumstances. By contrast, a posteriori mechanisms enforce policies not by preventing unauthorized access, but rather by deterring it. Such access control needs evidence to prove violations. Evidence is derived from one or several log records, which trace each user´s actions. Efficiency of violation detection mostly depends on the compliance of log records with the access control policy. In order to develop an efficient method for finding these violations, we propose restructuring log records according to a security policy model. We illustrate our methodology by applying it to the healthcare domain, taking care of the IHE (Integrating the healthcare enterprise) framework, particularly its basic security profile, ATNA (Audit Trail and Node Authentication). This profile defines log records established on the analysis of common health practice scenarios. We analyze and establish how ATNA log records can be refined in order to be integrated into an a posteriori access and usage control process, based on an expressive and contextual security policy like the OrBAC policy.
  • Keywords
    authorisation; health care; medical information systems; records management; ATNA log record; IHE-ATNA profile; access control mechanism; audit trail; contextual access; healthcare enterprise integration framework; healthcare environment; illegal access; node authentication; security policy model; usage control policy; violation detection; Access control; Context; Medical services; Organizations; Radiology; Standards organizations; Access control model; Audit; IHE-ATNA;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance and Security (IAS), 2010 Sixth International Conference on
  • Conference_Location
    Atlanta, GA
  • Print_ISBN
    978-1-4244-7407-3
  • Type

    conf

  • DOI
    10.1109/ISIAS.2010.5604060
  • Filename
    5604060