Institute of Intelligence Applications, Yunnan University of Finance and Economics, Kunming, 650021, China.
School of Business, Yunnan University of Finance and Economics, Kunming, 650021, China.
BMC Med Inform Decis Mak. 2024 Sep 16;24(1):260. doi: 10.1186/s12911-024-02638-5.
Graded diagnosis and treatment, referral, and expert consultations between medical institutions all require cross domain access to patient medical information to support doctors' treatment decisions, leading to an increase in cross domain access among various medical institutions within the medical consortium. However, patient medical information is sensitive and private, and it is essential to control doctors' cross domain access to reduce the risk of leakage. Access control is a continuous and long-term process, and it first requires verification of the legitimacy of user identities, while utilizing control policies for selection and management. After verifying user identity and access permissions, it is also necessary to monitor unauthorized operations. Therefore, the content of access control includes authentication, implementation of control policies, and security auditing. Unlike the existing focus on authentication and control strategy implementation in access control, this article focuses on the control based on access log security auditing for doctors who have obtained authorization to access medical resources. This paper designs a blockchain based doctor intelligent cross domain access log recording system, which is used to record, query and analyze the cross domain access behavior of doctors after authorization. Through DBSCAN clustering analysis of doctors' cross domain access logs, we find the abnormal phenomenon of cross domain access, and build a penalty function to dynamically control doctors' cross domain access process, so as to reduce the risk of Data breach. Finally, through comparative analysis and experiments, it is shown that the proposed cross domain access control model for medical consortia based on DBSCAN and penalty function has good control effect on the cross domain access behavior of doctors in various medical institutions of the medical consortia, and has certain feasibility for the cross domain access control of doctors.
分级诊疗、医疗机构间转诊、专家会诊等都需要跨域访问患者医疗信息,以支持医生的治疗决策,这导致医疗联合体内部各医疗机构之间的跨域访问需求不断增加。然而,患者医疗信息敏感且私密,必须控制医生的跨域访问,以降低信息泄露风险。访问控制是一个持续且长期的过程,首先需要验证用户身份的合法性,同时利用控制策略进行选择和管理。在验证用户身份和访问权限后,还需要监控未经授权的操作。因此,访问控制的内容包括认证、控制策略的实施和安全审计。与现有的访问控制中对认证和控制策略实施的关注不同,本文重点关注对已获得授权访问医疗资源的医生的基于访问日志的安全审计的控制。本文设计了一个基于区块链的医生智能跨域访问日志记录系统,用于记录、查询和分析医生授权后的跨域访问行为。通过对医生跨域访问日志进行 DBSCAN 聚类分析,发现了跨域访问的异常现象,并构建了一个惩罚函数来动态控制医生的跨域访问过程,从而降低数据泄露的风险。最后,通过对比分析和实验表明,所提出的基于 DBSCAN 和惩罚函数的医疗联合体医生跨域访问控制模型对医疗联合体中各医疗机构医生的跨域访问行为具有较好的控制效果,对医生的跨域访问控制具有一定的可行性。