Motta Gustavo H M B, Furuie Sergio S
Department of Informatics, Federal University of Paraiba, João Pessoa PB 58059-900, Brazil.
IEEE Trans Inf Technol Biomed. 2003 Sep;7(3):202-7. doi: 10.1109/titb.2003.816562.
The design of proper models for authorization and access control for electronic patient record (EPR) is essential to a wide scale use of EPR in large health organizations. In this paper, we propose a contextual role-based access control authorization model aiming to increase the patient privacy and the confidentiality of patient data, whereas being flexible enough to consider specific cases. This model regulates user's access to EPR based on organizational roles. It supports a role-tree hierarchy with authorization inheritance; positive and negative authorizations; static and dynamic separation of duties based on weak and strong role conflicts. Contextual authorizations use environmental information available at access time, like user/patient relationship, in order to decide whether a user is allowed to access an EPR resource. This enables the specification of a more flexible and precise authorization policy, where permission is granted or denied according to the right and the need of the user to carry out a particular job function.
为电子病历(EPR)设计合适的授权和访问控制模型对于大型医疗机构广泛使用EPR至关重要。在本文中,我们提出了一种基于上下文角色的访问控制授权模型,旨在增强患者隐私和患者数据的保密性,同时足够灵活以考虑特定情况。该模型基于组织角色来规范用户对EPR的访问。它支持具有授权继承的角色树层次结构;正向和负向授权;基于弱角色冲突和强角色冲突的静态和动态职责分离。上下文授权使用访问时可用的环境信息,如用户/患者关系,以决定用户是否被允许访问EPR资源。这使得能够制定更灵活、精确的授权策略,根据用户执行特定工作职能的权利和需求授予或拒绝权限。