Title :
Reconciling IHE-ATNA profile with a posteriori contextual access and usage control policy in healthcare environment
Author :
Azkia, Hanieh ; Cuppens-Boulahia, Nora ; Cuppens, Frédéric ; Coatrieux, Gouenou
Author_Institution :
IT/Telecom Bretagne, Cesson Sevigne, France
Abstract :
Traditional access control mechanisms prevent illegal access by controlling access right before executing an action; they belong to a class of a priori security solutions and, from this point of view, they have some limitations, like inflexibility in unanticipated circumstances. By contrast, a posteriori mechanisms enforce policies not by preventing unauthorized access, but rather by deterring it. Such access control needs evidence to prove violations. Evidence is derived from one or several log records, which trace each user´s actions. Efficiency of violation detection mostly depends on the compliance of log records with the access control policy. In order to develop an efficient method for finding these violations, we propose restructuring log records according to a security policy model. We illustrate our methodology by applying it to the healthcare domain, taking care of the IHE (Integrating the healthcare enterprise) framework, particularly its basic security profile, ATNA (Audit Trail and Node Authentication). This profile defines log records established on the analysis of common health practice scenarios. We analyze and establish how ATNA log records can be refined in order to be integrated into an a posteriori access and usage control process, based on an expressive and contextual security policy like the OrBAC policy.
Keywords :
authorisation; health care; medical information systems; records management; ATNA log record; IHE-ATNA profile; access control mechanism; audit trail; contextual access; healthcare enterprise integration framework; healthcare environment; illegal access; node authentication; security policy model; usage control policy; violation detection; Access control; Context; Medical services; Organizations; Radiology; Standards organizations; Access control model; Audit; IHE-ATNA;
Conference_Titel :
Information Assurance and Security (IAS), 2010 Sixth International Conference on
Conference_Location :
Atlanta, GA
Print_ISBN :
978-1-4244-7407-3
DOI :
10.1109/ISIAS.2010.5604060