Pangalos G, Khair M, Bozios L
Faculty of Technology, General Department, Aristotelian University, Thessaloniki, Greece.
J Med Syst. 1994 Aug;18(4):159-71. doi: 10.1007/BF00996700.
A methodology for the enhancement of database security in a hospital environment is presented in this paper which is based on both the discretionary and the mandatory database security policies. In this way the advantages of both approaches are combined to enhance medical database security. An appropriate classification of the different types of users according to their different needs and roles and a User Role Definition Hierarchy has been used. The experience obtained from the experimental implementation of the proposed methodology in a major general hospital is briefly discussed. The implementation has shown that the combined discretionary and mandatory security enforcement effectively limits the unauthorized access to the medical database, without severely restricting the capabilities of the system.
本文提出了一种在医院环境中增强数据库安全性的方法,该方法基于自主和强制数据库安全策略。通过这种方式,将两种方法的优点结合起来以增强医疗数据库的安全性。根据不同用户的不同需求和角色对其进行了适当分类,并使用了用户角色定义层次结构。简要讨论了在一家大型综合医院对所提出方法进行实验实施所获得的经验。实施表明,自主和强制安全实施相结合有效地限制了对医疗数据库的未经授权访问,而不会严重限制系统的功能。