Parametric information flow control in ehealth

Parametric information flow control in ehealth
复制标题

电子卫生中的参数信息流控制

DOI:
10.1109/healthcom.2015.7454481
复制
发表时间:
2015
期刊:
2015 17th International Conference on E-health Networking, Application & Services (HealthCom)
影响因子:
--
通讯作者:
Sanjiva Prasad
Sanjiva Prasad
中科院分区:
--
文献类型:
--
作者:
Chandrika Bhardwaj;Sanjiva Prasad

文献摘要

被引文献

相似文献

我们研究的问题,执行信息流控制(IFC)在电子医疗系统中,以验证安全的信息流通过程序。IFC机制允许用户控制敏感信息的发布和传播,使得机密信息在与其他合法主体协作时不会被非预期主体观察到。我们正式的参数化的安全类所需的安全策略规范在典型的电子健康系统在医院和使用静态类型检查检测系统中的安全策略违规行为。使用参数化的安全类格的主要优点是在声明策略时更精确,增强了可用性,并减少了创建安全标记时的开销。
We study the problem of enforcing information flow control (IFC) in ehealth systems to verify secure flow of information through programs. IFC mechanisms allow users to control the release and propagation of sensitive information so that confidential information is not observable to unintended principals while collaborating with other legitimate principals. We formalise the parametrised security classes that are required for security policy specification in typical e-health systems in a hospital and use static type checking for detecting security policy violations in the system. The key advantage of using the parametrised security class lattice is greater precision in stating policies, enhanced usability and a reduced overhead in creating security tags.