Title :
SIM: A smartphone-based identity management framework and its application to Arkansas trauma image repository
Author :
Mengjun Xie ; Topaloglu, Umit ; Powell, T. ; Chao Peng ; Jiang Bian
Author_Institution :
Dept. of Comput. Sci., Univ. of Arkansas at Little Rock, Little Rock, AR, USA
Abstract :
Secure and convenient user identity management is particularly important to the success of EMR, EHR, and PHR systems. Unfortunately, widely-used identity management mechanisms that solely rely on username/password are inadequate to meet the strong security and privacy requirements for protecting sensitive user information and medical data. Two-factor authentication approaches that are more convenient and user friendly than existing solutions have been given top priority in the healthcare sector where the majority of healthcare practitioners and patients are not tech-savvy. In this paper, we present a smartphone-based identity management framework-SIM-to enhance the security and usability of user identity management in healthcare information systems. SIM leverages the popularity and computational power of smartphone. Within the SIM framework, a person employs a smartphone to centrally store and manage her identity credentials and authenticates herself to healthcare applications using two-factor authentication without typing any identity credentials. Moreover, SIM provides patients with a patient-controlled authorization mechanism to help patients manage the accesses to their PHRs in a secure and convenient manner. Using an existing EMR system-Arkansas Trauma Image Repository-as an example, we demonstrate that SIM can be applied to a real-world healthcare information system to enhance its protection of user credentials and sensitive information.
Keywords :
cryptographic protocols; data protection; electronic health records; health care; human computer interaction; information retrieval; security of data; smart phones; telemedicine; Arkansas Trauma Image Repository application; EHR systems; EMR systems; PHR access management; PHR systems; SIM framework; central identity credential management; central identity credential storage; convenient user identity management; healthcare applications; healthcare information systems; healthcare sector; identity credential authentication; identity management mechanisms; medical data protection; patient-controlled authorization mechanism; privacy requirements; real-world healthcare information system; security requirements; smartphone computational power; smartphone-based identity management framework; two-factor authentication approaches; user credential protection; user friendly; user identity management security; user identity management usability; user information protection; username-password authentication approaches; Authentication; Browsers; Hospitals; Malware; Servers;
Conference_Titel :
Bioinformatics and Biomedicine (BIBM), 2013 IEEE International Conference on
Conference_Location :
Shanghai
DOI :
10.1109/BIBM.2013.6732600