Blobel Bernd, Pharow Peter
eHealth Competence Center, University of Regensburg Medical Center, Germany.
Stud Health Technol Inform. 2006;121:307-16.
State of the Art methodologies for establishing requirements and solutions to securing applications are based on narrative descriptions about the use of available system, sometimes also dedicated to system components. Even nowadays new developments to ruling application security services by the use of predicate logic suffer from being administered manually. Therefore, security and privacy requirements cannot be properly met resulting in restrictions and fears for allowing the use of sensitive data and functions. Because of the sensitivity of personal health information and especially of genetic data with its wider implications beyond the original subject of care, weaknesses in guaranteeing fine-grained security and privacy rules lead to less acceptance or even the avoidance of essential information transfer and use. To overcome the problem, security and privacy have to become properties of the architectural components of the respective health information system. Embedding security into the systems architecture allows for negotiating and enforcing any security and privacy services related to principals, their roles, their relationships, further contextual information as well as other regulations summarized in formally modeled policies. The paper introduces the evolving paradigm of the model-driven architecture, first time also comprehensively deployed for security and privacy services in bio-genetic and health information systems.
用于确定应用程序安全需求和解决方案的最新方法基于对可用系统使用情况的叙述性描述,有时也涉及系统组件。即使在当今,通过使用谓词逻辑来管理应用程序安全服务的新发展仍需手动进行。因此,安全和隐私需求无法得到妥善满足,导致在允许使用敏感数据和功能方面受到限制并引发担忧。由于个人健康信息的敏感性,尤其是遗传数据的敏感性及其对原始护理对象之外的更广泛影响,在保证细粒度安全和隐私规则方面的弱点导致对基本信息传输和使用的接受度降低甚至避免。为克服这一问题,安全和隐私必须成为相应健康信息系统架构组件的属性。将安全嵌入系统架构允许就与主体、其角色、其关系、进一步的上下文信息以及正式建模策略中总结的其他规则相关的任何安全和隐私服务进行协商和执行。本文介绍了模型驱动架构不断发展的范式,该范式首次全面应用于生物遗传和健康信息系统中的安全和隐私服务。