DocumentCode
2604738
Title
Reconciling IHE-ATNA profile with a posteriori contextual access and usage control policy in healthcare environment
Author
Azkia, Hanieh ; Cuppens-Boulahia, Nora ; Cuppens, Frédéric ; Coatrieux, Gouenou
Author_Institution
IT/Telecom Bretagne, Cesson Sevigne, France
fYear
2010
fDate
23-25 Aug. 2010
Firstpage
197
Lastpage
203
Abstract
Traditional access control mechanisms prevent illegal access by controlling access right before executing an action; they belong to a class of a priori security solutions and, from this point of view, they have some limitations, like inflexibility in unanticipated circumstances. By contrast, a posteriori mechanisms enforce policies not by preventing unauthorized access, but rather by deterring it. Such access control needs evidence to prove violations. Evidence is derived from one or several log records, which trace each user´s actions. Efficiency of violation detection mostly depends on the compliance of log records with the access control policy. In order to develop an efficient method for finding these violations, we propose restructuring log records according to a security policy model. We illustrate our methodology by applying it to the healthcare domain, taking care of the IHE (Integrating the healthcare enterprise) framework, particularly its basic security profile, ATNA (Audit Trail and Node Authentication). This profile defines log records established on the analysis of common health practice scenarios. We analyze and establish how ATNA log records can be refined in order to be integrated into an a posteriori access and usage control process, based on an expressive and contextual security policy like the OrBAC policy.
Keywords
authorisation; health care; medical information systems; records management; ATNA log record; IHE-ATNA profile; access control mechanism; audit trail; contextual access; healthcare enterprise integration framework; healthcare environment; illegal access; node authentication; security policy model; usage control policy; violation detection; Access control; Context; Medical services; Organizations; Radiology; Standards organizations; Access control model; Audit; IHE-ATNA;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Assurance and Security (IAS), 2010 Sixth International Conference on
Conference_Location
Atlanta, GA
Print_ISBN
978-1-4244-7407-3
Type
conf
DOI
10.1109/ISIAS.2010.5604060
Filename
5604060
Link To Document