Title :
Spatio temporal emergency role based access control (STEM-RBAC): A time and location aware role based access control model with a break the glass mechanism
Author :
Georgakakis, Emmanouil ; Nikolidakis, Stefanos A. ; Vergados, Dimitrios D. ; Douligeris, Christos
Author_Institution :
Dept. of Inf., Univ. of Piraeus, Piraeus, Greece
fDate :
June 28 2011-July 1 2011
Abstract :
The ever-increasing use of information systems and networks in every aspect of our lives has made possible the transfer of data to a wide range of different users and applications. In recent years, several architectures and models have been proposed in order to limit access to resources and ensure that data are available only to authorized users, programs or processes. These models in most cases are not dynamic and the permissions assigned to users are granted based on a static policy. A mechanism that will allow exception access to data, for example to medical information, in case of an emergency is needed. In current systems, emergency access techniques are not well defined and are used in an ad hoc manner on top of the access control mechanisms implemented without using parameters such as time, location or hierarchy of the actors involved in the system. In this paper, we present a model that provides both a normal access control based on roles and also a mechanism that is used in order to provide exception access to data in case of an emergency. The proposed emergency access mechanism is time aware and takes into account the mobility and location of users, also it grants exception access with a controlled manner in case of an emergency utilizing role hierarchies.
Keywords :
authorisation; information retrieval; medical information systems; mobile computing; spatiotemporal phenomena; STEM-RBAC; ad hoc manner; data transfer; emergency access technique; glass mechanism; location aware role based access control model; medical information; spatiotemporal emergency role based access control; Access control; Break The Glass; Electronic Healthcare Record; Emergency Access; Spatio Temporal RBAC;
Conference_Titel :
Computers and Communications (ISCC), 2011 IEEE Symposium on
Conference_Location :
Kerkyra
Print_ISBN :
978-1-4577-0680-6
Electronic_ISBN :
1530-1346
DOI :
10.1109/ISCC.2011.5983932