SGAC: A Multi-Layered Access Control Model with Conflict Resolution Strategy

被引:3
|
作者
Nghi Huynh [1 ,2 ]
Frappier, Marc [1 ]
Pooda, Herman [1 ]
Mammar, Amel [3 ]
Laleau, Regine [2 ]
机构
[1] Univ Sherbrooke, Dept Informat, GRIF, Sherbrooke, PQ, Canada
[2] Univ Paris Est Creteil, LACL, Val De Marne, France
[3] Univ Paris Saclay, CNRS, Telecom SudParis, SAMOVAR, Evry, France
来源
COMPUTER JOURNAL | 2019年 / 62卷 / 12期
基金
加拿大自然科学与工程研究理事会;
关键词
Healthcare; access control; consent management; formal model; verification; Alloy; ProB; POLICIES;
D O I
10.1093/comjnl/bxz039
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
This paper presents SGAC (Solution de Gestion Automatisee du Consentement / automated consent management solution), a new healthcare access control model and its support tool, which manages patient wishes regarding access to their electronic health records (EHR). This paper also presents the verification of access control policies for SGAC using two first-order-logic model checkers based on distinct technologies, Alloy and ProB. The development of SGAC has been achieved within the scope of a project with the University of Sherbrooke Hospital (CHUS), and thus has been adapted to take into account regional laws and regulations applicable in Quebec and Canada, as they set bounds to patient wishes: for safety reasons, under strictly defined contexts, patient consent can be overriden to protect his/her life (break-the-glass rules). Since patient wishes and those regulations can be in conflict, SGAC provides a mechanism to address this problem based on priority, specificity and modality. In order to protect patient privacy while ensuring effective caregiving in safety-critical situations, we check four types of properties: accessibility, availability, contextuality and rule effectivity. We conducted performance tests comparison: implementation of SGAC versus an implementation of another access control model, XACML, and property verification with Alloy versus ProB. The performance results show that SGAC performs better than XACML and that ProB outperforms Alloy by two order of magnitude thanks to its programmable approach to constraint solving.
引用
收藏
页码:1707 / 1733
页数:27
相关论文
共 50 条
  • [1] Refactoring Multi-Layered Access Control Policies Through (De)Composition
    Casalino, Matteo Maria
    Thion, Romuald
    2013 9TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2013, : 243 - 250
  • [2] Error control in multi-layered stacks
    Zorzi, M
    Rao, RR
    GLOBECOM 97 - IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, CONFERENCE RECORD, VOLS 1-3, 1997, : 1413 - 1418
  • [3] A multi-layered general agent model
    Costantini, Stefania
    Tocchio, Arianna
    Toni, Francesca
    Tsintza, Panagiota
    AI(ASTERISK)IA 2007: ARTIFICIAL INTELLIGENCE AND HUMAN-ORIENTED COMPUTING, 2007, 4733 : 121 - +
  • [4] Quantum control of a model qubit based on a multi-layered quantum dot
    Ferron, Alejandro
    Serra, Pablo
    Osenda, Omar
    JOURNAL OF APPLIED PHYSICS, 2013, 113 (13)
  • [5] High Resolution Technology for Multi-Layered Electrochromic Display
    Okada, Yoshinori
    Yashiro, Tohru
    Naijoh, Yoshihisa
    Hirano, Shigenobu
    Kim, SukChan
    Tsuji, Kazuaki
    Takahashi, Hiroyuki
    Fujimura, Koh
    Kondoh, Hitoshi
    IDW/AD '12: PROCEEDINGS OF THE INTERNATIONAL DISPLAY WORKSHOPS, PT 1, 2012, 19 : 641 - 644
  • [6] Study of convergence configuration strategy in multi-layered network
    Wang, Zhi-Wen
    Xia, Qin
    Li, Zeng-Zhi
    Li, Ping-Jun
    Xiaoxing Weixing Jisuanji Xitong/Mini-Micro Systems, 2001, 22 (12):
  • [7] A multi-layered control architecture of intelligent Agent
    Kong, Lianfang
    Xiao, Lei
    2007 IEEE INTERNATIONAL CONFERENCE ON CONTROL AND AUTOMATION, VOLS 1-7, 2007, : 2042 - +
  • [8] Approach of mechanics model of multi-layered barrels
    Zhang, Yue
    Fan, Xinmin
    Kong, Deren
    Dandao Xuebao/Journal of Ballistics, 1998, 10 (03): : 20 - 24
  • [9] A multi-layered database model for mobile environment
    Madria, SK
    Fu, YJ
    Bhowmick, S
    MOBILE DATA MANAGEMENT, PROCEEDINGS, 2003, 2574 : 381 - 385
  • [10] Model Suites For Multi-Layered Database Modelling
    Thalheim, Bernhard
    INFORMATION MODELLING AND KNOWLEDGE BASES XXI, 2010, 206 : 116 - 134