Gritzalis S, Gritzalis D, Moulinos C, Iliadis J
Department of Information and Communication Systems, University of Aegean, Athens, Greece.
Med Inform Internet Med. 2001 Jan-Mar;26(1):49-72.
In this paper we describe a pilot architecture aiming at protecting Web-based medical applications through the development of a virtual private medical network. The basic technology, which is utilized by this integrated architecture, is the Trusted Third Party (TTP). In specific, a TTP is used to generate, distribute, and revoke digital certificates to/from medical practitioners and healthcare organizations wishing to communicate in a secure way. Digital certificates and digital signatures are, in particular, used to provide peer and data origin authentication and access control functionalities. We also propose a logical Public Key Infrastructure (PKI) architecture, which is robust, scalable, and based on standards. This architecture aims at supporting large-scale healthcare applications. It supports openness, scalability, flexibility and extensibility, and can be integrated with existing TTP schemes and infrastructures offering transparency and adequate security. Finally, it is demonstrated that the proposed architecture enjoys all desirable usability characteristics, and meets the set of criteria, which constitutes an applicable framework for the development of trusted medical services over the Web.
在本文中,我们描述了一种试点架构,旨在通过开发虚拟专用医疗网络来保护基于网络的医疗应用程序。这种集成架构所采用的基本技术是可信第三方(TTP)。具体而言,TTP用于向希望以安全方式进行通信的医生和医疗保健组织生成、分发和撤销数字证书。特别是,数字证书和数字签名用于提供对等方和数据来源认证以及访问控制功能。我们还提出了一种逻辑公钥基础设施(PKI)架构,它强大、可扩展且基于标准。该架构旨在支持大规模医疗保健应用程序。它支持开放性、可扩展性、灵活性和可扩展性,并且可以与现有的TTP方案和基础设施集成,提供透明度和足够的安全性。最后,证明了所提出的架构具有所有理想的可用性特征,并且符合一组标准,这些标准构成了在网络上开发可信医疗服务的适用框架。