Title :
A secure RBAC mobile agent access control model for healthcare institutions
Author :
Santos-Pereira, Catia ; Augusto, Alexandre B. ; Cruz-Correia, Ricardo ; Correia, Manuel Eduardo
Author_Institution :
Center for Res. in Health Technol. & Inf. Syst. - CINTESIS, Univ. of Porto, Porto, Portugal
Abstract :
In medical organizations, healthcare providers need to have fast access to patients´ medical information in order to make accurate diagnoses as well as to provide appropriate treatments. Efficient healthcare is thus highly dependent on doctors being provided with access to patients´ medical information at the right time and place. However it frequently happens that critical pieces of pertinent information end up not being used because they are located in information systems that do not inter-operate in a timely manner. Unfortunately the standard operational mode for many healthcare applications, and even healthcare institutions, is to be managed and operated as isolated islands that do not share information in an efficient manner. There are many reasons that contribute to this grim state of affairs, but what interests us the most is the lack of enforceable security policies for systems interoperability and data exchange and the existence of many heterogeneous legacy systems that are almost impossible to directly include into any reasonable secure interoperable workflow. In this paper we propose a RBAC mobile agent access control model supported by a specially managed public key infrastructure for mobile agent´s strong authentication and access control. Our aim is to create the right means for doctors to be provided with timely accurate information, which would be otherwise inaccessible, by the means of strongly authenticated mobile agents capable of securely bridging otherwise isolated institutional eHealth domains and legacy applications.
Keywords :
access control; electronic data interchange; health care; medical information systems; mobile agents; open systems; security of data; RBAC mobile agent access control model; authentication control; data exchange; healthcare provider; institutional eHealth domain application; institutional eHealth legacy application; interoperability; medical organization; patient medical information system; public key infrastructure management; role-based access control; security policy; Access control; Authentication; Clinical diagnosis; Hospitals; Information systems; Mobile agents; Authentication; Health Information Systems (HIS); Information Security; Interoperability; Mobile agent; Role-Based Access Control (RBAC);
Conference_Titel :
Computer-Based Medical Systems (CBMS), 2013 IEEE 26th International Symposium on
Conference_Location :
Porto
DOI :
10.1109/CBMS.2013.6627814