• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

一种用于连接健康信息系统的安全架构。

A security architecture for interconnecting health information systems.

作者信息

Gritzalis Dimitris, Lambrinoudakis Costas

机构信息

Department of Informatics, Athens University of Economics and Business, 76 Patission Street, Athens GR-10434, Greece.

出版信息

Int J Med Inform. 2004 Mar 31;73(3):305-9. doi: 10.1016/j.ijmedinf.2003.12.011.

DOI:10.1016/j.ijmedinf.2003.12.011
PMID:15066563
Abstract

Several hereditary and other chronic diseases necessitate continuous and complicated health care procedures, typically offered in different, often distant, health care units. Inevitably, the medical records of patients suffering from such diseases become complex, grow in size very fast and are scattered all over the units involved in the care process, hindering communication of information between health care professionals. Web-based electronic medical records have been recently proposed as the solution to the above problem, facilitating the interconnection of the health care units in the sense that health care professionals can now access the complete medical record of the patient, even if it is distributed in several remote units. However, by allowing users to access information from virtually anywhere, the universe of ineligible people who may attempt to harm the system is dramatically expanded, thus severely complicating the design and implementation of a secure environment. This paper presents a security architecture that has been mainly designed for providing authentication and authorization services in web-based distributed systems. The architecture has been based on a role-based access scheme and on the implementation of an intelligent security agent per site (i.e. health care unit). This intelligent security agent: (a). authenticates the users, local or remote, that can access the local resources; (b). assigns, through temporary certificates, access privileges to the authenticated users in accordance to their role; and (c). communicates to other sites (through the respective security agents) information about the local users that may need to access information stored in other sites, as well as about local resources that can be accessed remotely.

摘要

几种遗传性疾病和其他慢性疾病需要持续且复杂的医疗保健程序,这些程序通常由不同的、往往距离较远的医疗保健单位提供。不可避免地,患有此类疾病的患者的病历变得复杂,规模增长迅速,且分散在参与护理过程的各个单位,这阻碍了医疗保健专业人员之间的信息交流。基于网络的电子病历最近被提议作为解决上述问题的方案,从医疗保健单位相互连接的意义上来说,它便于医疗保健专业人员现在能够访问患者的完整病历,即使该病历分布在几个远程单位。然而,通过允许用户几乎在任何地方访问信息,可能试图破坏系统的不合格人员范围大幅扩大,从而使安全环境的设计和实施严重复杂化。本文提出了一种主要为基于网络的分布式系统提供认证和授权服务而设计的安全架构。该架构基于基于角色的访问方案,并在每个站点(即医疗保健单位)实施智能安全代理。这种智能安全代理:(a). 对可以访问本地资源的本地或远程用户进行认证;(b). 通过临时证书根据认证用户的角色为其分配访问权限;以及(c). 向其他站点(通过各自的安全代理)传达有关可能需要访问存储在其他站点的信息的本地用户以及可以远程访问的本地资源的信息。

相似文献

1
A security architecture for interconnecting health information systems.一种用于连接健康信息系统的安全架构。
Int J Med Inform. 2004 Mar 31;73(3):305-9. doi: 10.1016/j.ijmedinf.2003.12.011.
2
A cross-platform model for secure Electronic Health Record communication.一种用于安全电子健康记录通信的跨平台模型。
Int J Med Inform. 2004 Mar 31;73(3):291-5. doi: 10.1016/j.ijmedinf.2003.12.012.
3
Access control based on attribute certificates for medical intranet applications.基于属性证书的医疗内部网应用访问控制。
J Med Internet Res. 2001 Jan-Mar;3(1):E9. doi: 10.2196/jmir.3.1.e9.
4
A remote data access architecture for home-monitoring health-care applications.一种用于家庭监测医疗保健应用的远程数据访问架构。
Med Eng Phys. 2007 Mar;29(2):199-204. doi: 10.1016/j.medengphy.2006.03.002. Epub 2006 Apr 18.
5
Purposes of health identification cards and role of a secure access platform (Be-Health) in Belgium.比利时健康识别卡的用途及安全访问平台(Be-Health)的作用。
Int J Med Inform. 2007 Feb-Mar;76(2-3):84-8. doi: 10.1016/j.ijmedinf.2006.10.003. Epub 2006 Nov 28.
6
The need for security--a clinical view.安全需求——临床视角
Int J Biomed Comput. 1994 Feb;35 Suppl:189-94.
7
Secure interoperability of patient data cards in health networks.健康网络中患者数据卡的安全互操作性。
Stud Health Technol Inform. 2000;77:1059-68.
8
Access and privacy rights using web security standards to increase patient empowerment.利用网络安全标准保障访问和隐私权,增强患者自主权。
Stud Health Technol Inform. 2008;137:275-85.
9
Web-based secure access from multiple patient repositories.基于网络的来自多个患者资料库的安全访问。
Int J Med Inform. 2008 Apr;77(4):242-8. doi: 10.1016/j.ijmedinf.2007.06.001. Epub 2007 Aug 2.
10
Intranet health clinic: Web-based medical support services employing XML.企业内部网健康诊所:采用XML的基于网络的医疗支持服务。
Stud Health Technol Inform. 2000;77:1112-6.

引用本文的文献

1
A Scoping Review of Integrated Blockchain-Cloud (BcC) Architecture for Healthcare: Applications, Challenges and Solutions.综合区块链-云 (BcC) 架构在医疗保健中的应用、挑战与解决方案:综述
Sensors (Basel). 2021 May 28;21(11):3753. doi: 10.3390/s21113753.
2
Information Security Risk Assessment in Hospitals.医院中的信息安全风险评估
Open Med Inform J. 2017 Sep 14;11:37-43. doi: 10.2174/1874431101711010037. eCollection 2017.
3
A security framework for nationwide health information exchange based on telehealth strategy.基于远程医疗战略的全国性健康信息交换安全框架。
J Med Syst. 2015 May;39(5):51. doi: 10.1007/s10916-015-0235-1. Epub 2015 Mar 3.
4
An enhanced security solution for electronic medical records based on AES hybrid technique with SOAP/XML and SHA-1.一种基于AES混合技术与SOAP/XML和SHA-1的电子病历增强安全解决方案。
J Med Syst. 2013 Oct;37(5):9971. doi: 10.1007/s10916-013-9971-2. Epub 2013 Sep 14.
5
Application of portable CDA for secure clinical-document exchange.便携式 CDA 在安全临床文档交换中的应用。
J Med Syst. 2010 Aug;34(4):531-9. doi: 10.1007/s10916-009-9266-9. Epub 2009 Feb 25.
6
Biometrics for electronic health records.电子健康记录的生物识别技术。
J Med Syst. 2010 Oct;34(5):975-83. doi: 10.1007/s10916-009-9313-6. Epub 2009 Jun 2.
7
Security and access of health research data.健康研究数据的安全性与获取
J Med Syst. 2007 Apr;31(2):103-7. doi: 10.1007/s10916-006-9035-y.
8
Personal health record systems and their security protection.个人健康记录系统及其安全保护。
J Med Syst. 2006 Aug;30(4):309-15. doi: 10.1007/s10916-006-9019-y.