Chen Baozhan, Qiao Siyuan, Zhao Jie, Liu Dongqing, Shi Xiaobing, Lyu Minzhao, Chen Haotian, Lu Huimin, Zhai Yunkai
National Engineering Laboratory for Internet Medical Systems and Application and the National Telemedicine Center of ChinaFirst Affiliated Hospital of Zhengzhou University Zhengzhou 450052 China.
Strategic Investment and Ecological Cooperation DepartmentQi An Xin Technology Group Inc. Beijing 100032 China.
IEEE Internet Things J. 2020 Nov 30;8(13):10248-10263. doi: 10.1109/JIOT.2020.3041042. eCollection 2021 Jul 1.
The key features of 5G network (i.e., high bandwidth, low latency, and high concurrency) along with the capability of supporting big data platforms with high mobility make it valuable in coping with emerging medical needs, such as COVID-19 and future healthcare challenges. However, enforcing the security aspect of a 5G-based smart healthcare system that hosts critical data and services is becoming more urgent and critical. Passive security mechanisms (e.g., data encryption and isolation) used in legacy medical platforms cannot provide sufficient protection for a healthcare system that is deployed in a distributed manner and fail to meet the need for data/service sharing across "cloud-edge-terminal" in the 5G era. In this article, we propose a security awareness and protection system that leverages zero-trust architecture for a 5G-based smart medical platform. Driven by the four key dimensions of 5G smart healthcare including "subject" (i.e., users, terminals, and applications), "object" (i.e., data, platforms, and services), "behavior," and "environment," our system constructs trustable dynamic access control models and achieves real-time network security situational awareness, continuous identity authentication, analysis of access behavior, and fine-grained access control. The proposed security system is implemented and tested thoroughly at industrial-grade, which proves that it satisfies the needs of active defense and end-to-end security enforcement of data, users, and services involved in a 5G-based smart medical system.
5G网络的关键特性(即高带宽、低延迟和高并发)以及支持具有高移动性的大数据平台的能力,使其在应对诸如新冠疫情和未来医疗挑战等新出现的医疗需求方面具有重要价值。然而,强化基于5G的智能医疗系统的安全方面变得愈发紧迫和关键,因为该系统承载着关键数据和服务。传统医疗平台中使用的被动安全机制(如数据加密和隔离)无法为以分布式方式部署的医疗系统提供足够保护,也无法满足5G时代跨“云-边-端”进行数据/服务共享的需求。在本文中,我们提出了一种安全意识与保护系统,该系统为基于5G的智能医疗平台利用零信任架构。受5G智能医疗的四个关键维度(包括“主体”(即用户、终端和应用程序)、“客体”(即数据、平台和服务)、“行为”和“环境”)驱动,我们的系统构建了可信的动态访问控制模型,并实现了实时网络安全态势感知、持续身份认证、访问行为分析和细粒度访问控制。所提出的安全系统在工业级进行了全面实现和测试,这证明它满足了基于5G的智能医疗系统中数据、用户和服务的主动防御和端到端安全强化的需求。