课题基金 / 基金详情

TC: Medium: Collaborative Research: Experience-Based Access Management (EBAM) for Hospital Information Technology

TC: Medium: Collaborative Research: Experience-Based Access Management (EBAM) for Hospital Information Technology
TC:媒介:协作研究:医院信息技术的基于经验的访问管理(EBAM)
批准号:
0964087
负责人:
David Liebovitz
金额:
$39.98万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-04-01 至 2015-03-31

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
企业身份和访问管理(IAM)作为一个需要在变化和发展的基础上持续执行的过程,一直没有得到足够的重视。特别是,对于IAM如何利用企业长期积累的经验,几乎没有正式的支持。该项目正在开发一种称为基于经验的访问管理(EBAM)的IAM生命周期模型,该模型提供了一组模型、技术和工具,以调和“理想”访问模型(由高级企业、专业和法律标准判断)与“强制”访问控制(特定于可操作的IAM系统)之间的差异。EBAM支持系统的主要组成部分是“预期”访问模型,该模型用于表示基于从访问日志和其他操作信息收集的理想模型和强制模型之间的差异。该项目正在开发和验证一种实现预期模型的方法,该方法基于使用概率信息通知访问规则的设计。该项目侧重于医院信息系统的EBAM,因为这是一类特别重要的企业系统,它们提出了各种有趣的挑战,但也为其他类型的企业IAM系统中的类似问题提供了潜在的见解。该团队由网络安全、生物医学信息学方面的专家和一名在大型医院系统中担任首席医疗信息官的医生组成。该项目将展示临床经验分析如何能够在一家有代表性的医院解决理想访问控制模式和强制访问控制模式之间的差距。
英文摘要
Insufficient attention has been given to enterprise Identity and Access Management (IAM) as a process that needs to be carried out on a continuing basis in the presence of change and evolution. In particular, there is little formal support for how IAM can exploit experience the enterprise collects over time. This project is developing a lifecycle model of IAM called Experience Based Access Management (EBAM) that provides a set of models, techniques, and tools to reconcile differences between the "ideal" access model, as judged by high-level enterprise, professional, and legal standards, and the "enforced" access control, specific to the operational IAM system. The principal component of an EBAM support system is an "expected" access model that is used to represent differences between the ideal and enforced models based on information collected from access logs and other operational information. The project is developing and validating an approach to the expected model based on using probabilistic information to inform the design of access rules. The project focuses on EBAM for hospital information systems since these are an especially important class of enterprise systems that present diverse and interesting challenges but also provide potential insight into similar issues in other types of enterprise IAM systems. The team consists of specialists in cyber security, biomedical informatics, and a physician who serves as chief medical information officer within a major hospital system. The project will demonstrate how analysis of clinical experience can address gaps between ideal and enforced access control models in a representative hospital.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金