Conceptual framework for the security of mobile health applications on Android platform

Conceptual framework for the security of mobile health applications on Android platform
复制标题

DOI:
10.1016/j.tele.2018.03.005
复制
发表时间:
2018-08-01
影响因子:
8.5
通讯作者:
Albahri, A. S.
Albahri, A. S.
中科院分区:
管理学2区
文献类型:
--
作者:
Hussain, Muzammil;Zaidan, A. A.;Albahri, A. S.

文献摘要

被引文献

相似文献

移动的健康(mHealth)应用程序对于移动的设备的普通用户来说是容易访问的,并且尽管mHealth应用程序具有改善提供医疗保健服务的可用性、可负担性和有效性的潜力,但是它们处理敏感的医疗数据,并且因此也具有对其用户的安全性和隐私带来重大风险的潜力。应用程序的开发人员通常是未知的,用户不知道他们的数据是如何管理和使用的。这与由于移动的应用程序开发的缺陷或当前移动的操作系统的设计模糊性而出现的新威胁相结合。市场上有许多移动的操作系统,但Android平台获得了最高的人气。然而,Android的安全模型并不能完全保证用户数据的隐私和安全,包括移动健康应用程序的数据。尽管Android提供了权限和沙箱等安全机制,但mHealth应用程序仍然受到严重的隐私和安全问题的困扰。这些安全问题需要得到解决,以提高用户对移动健康应用程序的接受程度和医疗保健系统中移动健康应用程序的功效。因此,本文提出了一个概念框架,以提高与Android mHealth应用程序相关的医疗数据的安全性,以及保护其用户的隐私。根据文献审查,建议需要预定的安全框架,三个不同的和连续的阶段,其中每一个都在一个单独的部分。首先,讨论了第一阶段的设计过程,为移动健康应用程序开发一个安全框架,以确保敏感医疗数据的安全和隐私。第二阶段是讨论谁来实现一个原型的概念验证版本的框架的实施。最后,第三阶段结束时讨论了评估过程中的有效性和效率的建议框架。
Mobile Health (mHealth) applications are readily accessible to the average user of mobile devices, and despite the potential of mHealth applications to improve the availability, affordability and effectiveness of delivering healthcare services, they handle sensitive medical data, and as such, have also the potential to carry substantial risks to the security and privacy of their users. Developers of applications are usually unknown, and users are unaware of how their data are being managed and used. This is combined with the emergence of new threats due to the deficiency in mobile applications development or the design ambiguities of the current mobile operating systems. A number of mobile operating systems are available in the market, but the Android platform has gained the topmost popularity. However, Android security model is short of completely ensuring the privacy and security of users' data, including the data of mHealth applications. Despite the security mechanisms provided by Android such as permissions and sandboxing, mHealth applications are still plagued by serious privacy and security issues. These security issues need to be addressed in order to improve the acceptance of mHealth applications among users and the efficacy of mHealth applications in the healthcare systems. Thus, this paper presents a conceptual framework to improve the security of medical data associated with Android mHealth applications, as well as to protect the privacy of their users. Based on the literature review that suggested the need for the intended security framework, three-distinct and successive phases are presented, each of which is described in a separate section. First, discussed the design process of the first phase to develop a security framework for mHealth apps to ensure the security and privacy of sensitive medical data. The second phase is discussed who to achieve the implementation of a prototypic proof-of-concept version of the framework. Finally, the third phase ending discussed the evaluation process in terms of effectiveness and efficiency for the proposed framework.