Georgiadis Christos K, Mavridis Ioannis K, Pangalos George I
Informatics Laboratory, Computers Division, Faculty of Technology, Aristotle University of Thessaloniki, Egnatia Str., 54006 Thessaloniki, Greece.
Int J Med Inform. 2003 Jul;70(2-3):161-71. doi: 10.1016/s1386-5056(03)00031-5.
Healthcare environments are a representative case of collaborative environments since individuals (e.g. doctors) in many cases collaborate in order to provide care to patients in a more proficient way. At the same time modern healthcare institutions are increasingly interested in sharing access of their information resources in the networked environment. Healthcare applications over the Internet offer an attractive communication infrastructure at worldwide level but with a noticeably great factor of risk. Security has, therefore, become a major concern. However, although an adequate level of security can be relied upon digital certificates, if an appropriate security model is used, additional security considerations are needed in order to deal efficiently with the above team-work concerns. The already known Hybrid Access Control (HAC) security model supports and handles efficiently healthcare teams with active security capabilities and is capable to exploit the benefits of certificate technology. In this paper we present the way for encoding the appropriate authoritative information in various types of certificates, as well as the overall operational architecture of the implemented access control system for healthcare collaborative environments over the Internet. A pilot implementation of the proposed methodology in a major Greek hospital has shown the applicability of the proposals and the flexibility of the access control provided.
医疗环境是协作环境的一个典型例子,因为在很多情况下,个体(如医生)会相互协作,以便更高效地为患者提供护理。同时,现代医疗机构越来越热衷于在网络环境中共享其信息资源的访问权限。基于互联网的医疗应用在全球范围内提供了一个有吸引力的通信基础设施,但风险因素也非常显著。因此,安全已成为一个主要问题。然而,尽管依靠数字证书可以实现足够的安全级别,但如果使用合适的安全模型,还需要额外的安全考量,以便有效地处理上述团队协作问题。已知的混合访问控制(HAC)安全模型支持并能高效处理具备主动安全功能的医疗团队,并且能够利用证书技术的优势。在本文中,我们介绍了在各种类型证书中编码适当权威信息的方法,以及为基于互联网的医疗协作环境所实现的访问控制系统的整体操作架构。在希腊一家大型医院对所提方法进行的试点实施,证明了这些提议的适用性以及所提供访问控制的灵活性。