Georgiadis Christos K, Mavridis Ioannis K, Pangalos George I
Informatics Laboratory, Computers Division, Faculty of Technology, Aristotle University of Thessaloniki, 54006, Thessaloniki, Greece.
Stud Health Technol Inform. 2002;90:184-8.
Healthcare environments are a representative case of collaborative environments since individuals (e.g. doctors) in many cases collaborate in order to provide care to patients in a more proficient way. At the same time modem healthcare institutions are increasingly interested in sharing access of their information resources in the networked environment. Healthcare applications over the Internet offer an attractive communication infrastructure at worldwide level but with a noticeably great factor of risk. Security has therefore become a major concern for healthcare applications over the Internet. However, although an adequate level of security can be relied upon digital certificates, if an appropriate security policy is used, additional security considerations are needed in order to deal efficiently with the above team-work concerns. The already known Hybrid Access Control security model supports and handles efficiently healthcare teams with active security capabilities and is capable to exploit the benefits of certificate technology. In this paper we present the way for encoding the appropriate authoritative information in various types of certificates, as well as the overall operational architecture of the implemented access control system for healthcare collaborative environments over the Internet. A pilot implementation of the proposed methodology in a major Greek hospital has shown the applicability of the proposals and the flexibility of the access control provided.
医疗环境是协作环境的典型代表,因为在很多情况下,个体(如医生)需要协作,以便更高效地为患者提供护理。与此同时,现代医疗机构越来越热衷于在网络环境中共享其信息资源的访问权限。基于互联网的医疗应用在全球范围内提供了一个有吸引力的通信基础设施,但风险因素也非常显著。因此,安全已成为基于互联网的医疗应用的主要关注点。然而,尽管依靠数字证书可以实现足够的安全级别,但如果使用适当的安全策略,则需要额外的安全考虑,以便有效地处理上述团队协作问题。已知的混合访问控制安全模型支持并有效地处理具有主动安全功能的医疗团队,并且能够利用证书技术的优势。在本文中,我们展示了在各种类型的证书中编码适当的权威信息的方法,以及为基于互联网的医疗协作环境实现的访问控制系统的整体操作架构。在希腊一家大型医院对所提出方法的试点实施表明了这些提议的适用性以及所提供访问控制的灵活性。