Visible to the public Access Control Policy Combination from Similarity Analysis for Secure Privacy-Preserved EHR Systems

TitleAccess Control Policy Combination from Similarity Analysis for Secure Privacy-Preserved EHR Systems
Publication TypeConference Paper
Year of Publication2017
AuthorsRezaeibagha, F., Mu, Y.
Conference Name2017 IEEE Trustcom/BigDataSE/ICESS
Date Publishedaug
ISBN Number978-1-5090-4906-6
KeywordsAccess Control, access control policy combination, authorisation, Collaboration, computer network, cryptography, data privacy, Data security, distributed processing, Distributed Systems, electronic health record, electronic health records, electronic healthcare systems, Health Care, hospitals, large scale healthcare system, patients privacy, policy-based governance, privacy, pubcrawl, secure integrated systems, secure privacy-preserved EHR systems, security, Security Policies Analysis, similarity analysis, XACML, XACML policies
Abstract

In distributed systems, there is often a need to combine the heterogeneous access control policies to offer more comprehensive services to users in the local or national level. A large scale healthcare system is usually distributed in a computer network and might require sophisticated access control policies to protect the system. Therefore, the need for integrating the electronic healthcare systems might be important to provide a comprehensive care for patients while preserving patients' privacy and data security. However, there are major impediments in healthcare systems concerning not well-defined and flexible access control policy implementations, hindering the progress towards secure integrated systems. In this paper, we introduce an access control policy combination framework for EHR systems that preserves patients' privacy and ensures data security. We achieve our goal through an access control mechanism which handles multiple access control policies through a similarity analysis phase. In that phase, we evaluate different XACML policies to decide whether or not a policy combination is applicable. We have provided a case study to show the applicability of our proposed approach based on XACML. Our study results can be applied to the electronic health record (EHR) access control policy, which fosters interoperability and scalability among healthcare providers while preserving patients' privacy and data security.

URLhttps://ieeexplore.ieee.org/document/8029465/
DOI10.1109/Trustcom/BigDataSE/ICESS.2017.262
Citation Keyrezaeibagha_access_2017