Managing Break-The-Glass using Situation-oriented authorizations
2014
Abstract
The patient's life is a redline in Healthcare environments. Whenever it comes to danger, such environments reject static authorizations . A common problem "Break The Glass" is known as the act of breaking the static authorization in order to reach the required permission. Healthcare environment is full of different contexts and situations that require the authorizations to be dynamic. Dynamic Authorization is a concept of giving the choice to E-Health authorization system to choose the most suitable permission by considering one's situation. This paper aims at preventing the matter of modifying the policy to make authorizations dynamic. It introduces a simple solution to provide Dynamic Authorization by orienting the authorization system decision using situations. Situations, which are calculated using Complex Event Processing, are integrated to XACML architecture. A Healthcare example proves the efficiency of our approach.
References (16)
- Asaf Adi and Opher Etzion. Amit -the situation manager. The VLDB Journal The International Journal on Very Large Data Bases, 13(2):177-203, September 2003.
- Balana - The Open-Source Xacml V3.0 Implementation, http://xacmlinfo.org/, August 2012.
- Achim D Brucker and Helmut Petritsch. Extending access control models with break-glass. In SACMAT '09: Proceedings of the 14th ACM symposium on Access control models and technologies, pages 197-206, Stresa, Italy, 2009. ACM Request Permissions.
- Barbara Carminati, Elena Ferrari, and Michele Guglielmi. Secure informa- tion sharing on support of emergency management. Privacy, security, risk and trust (passat), 2011 ieee third international conference on and 2011 ieee third international conference on social computing (socialcom), pages 988-995, 2011.
- G Eysenbach. What is e-health? Journal of Medical Internet Research, 3(2):e20, 2001.
- Ana Ferreira, Luis Antunes, David W Chadwick, and Ricardo Correia. Grounding information security in healthcare. International Journal of Med- ical Informatics, 79(4):268-283, April 2010.
- Junzhe Hu and Alfred Weaver. A Dynamic, Context-Aware Security Infras- tructure for Distributed Healthcare Applications. In Proc. 1st Workshop on Pervasive Privacy Security, Privacy, and Trust (PSPT), Boston, MA, USA, 2004.
- Romain Laborde, Michel Kamel, Francois Barrere, and Abdelmalek Benzekri. A secure collaborative web based environment for virtual organizations. In
- Srdjan Marinovic, Robert Craven, Jiefei Ma, and Naranker Dulay. Rumpole: A Flexible Break-glass Access Control Model. In the 16th ACM symposium, page 73, New York, New York, USA, 2011. ACM Press.
- G Ma, K Wu, T Zhang, and W Li. A Flexible Policy-Based Access Control Model for Workflow. Przegląd Elektrotechniczny, 2012.
- Barzan Mozafari, Kai Zeng, and Carlo Zaniolo. High-performance com- plex event processing over XML streams. In Proceedings of the 2012 ACM SIGMOD International Conference on Management of Data, pages 253-264, Scottsdale, Arizona, USA, May 2012. ACM Request Permissions.
- Thierry Sans, Fréderic CUPPENS, and Nora Cuppens-Boulahia. A Flex- ible and Distributed Architecture to Enforce Dynamic Access Control. In IFIP International Federation for Information Processing, pages 183-195-195.
- SSH + 08] Matthew A Scholl, Kevin M Stine, Joan Hash, Pauline Bowen, L Arnold John- son, Carla Dancy Smith, and Daniel I Steinberg. An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule. An Introductory Resource Guide for Implement- ing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, October 2008.
- Sigrid Schefer-Wenzl and Mark Strembeck. Generic support for RBAC break- glass policies in process-aware information systems. Proceedings of the 28th Annual ACM Symposium on Applied Computing, pages 1441-1446, 2013.
- eXtensible Access Control Markup Language (XACML) Version 3.0. OA- SIS Standard http://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os- en.html, 22January 2013.
- Juan Ye, Simon Dobson, and Susan McKeever. Situation identification tech- niques in pervasive computing: A review. Pervasive and Mobile Computing, 8(1):36-66, February 2012.