Access Control for Multi-tenancy in Cloud-based Health Information Systems

被引:3
|
作者
Anwar, Mohd [1 ]
Imran, Ashiq [1 ]
机构
[1] North Carolina A&T State Univ, Dept Comp Sci, Greensboro, NC 27401 USA
关键词
multitenancy; health cloud; access control; ontological model; openstack; HIPAA; SERVICE;
D O I
10.1109/CSCloud.2015.95
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud technology can be used to support cost-effective, scalable, and well-managed healthcare information systems. However, cloud computing, particularly multitenancy, introduces privacy and security issues related to personal health information (PHI). In this paper, we designed ontological models for healthcare workflow and multi-tenancy, and then applied HIPAA requirements on the models to generate HIPAA-compliant access control policies. We used Semantic Web Rule Language (SWRL) to represent access control policies as rules, and we verified the rules with an OWL-DL reasoner. Additionally, we implemented HIPAA security rules through access control policies in a cloud-based simulated healthcare environment. More specifically, we investigated access control policy specification and enforcement for cloud based healthcare information systems using an open source cloud platform, OpenStack. The results manifest HIPAA compliance through authorization policies that are capable of addressing vulnerabilities of multi-tenancy.
引用
收藏
页码:104 / 110
页数:7
相关论文
共 50 条
  • [1] Multi-tenancy access control strategy for cloud services
    Zou, Maoyang
    He, Jia
    Wu, Qian
    PROCEEDINGS OF 2016 10TH INTERNATIONAL CONFERENCE ON SOFTWARE, KNOWLEDGE, INFORMATION MANAGEMENT & APPLICATIONS (SKIMA), 2016, : 258 - 261
  • [2] Design Role-Based Multi-Tenancy Access Control Scheme for Cloud Services
    Yang, Shin-Jer
    Lai, Pei-Ci
    Lin, Jyhjong
    2013 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), 2013, : 273 - 279
  • [3] An Attribute-Role Based Access Control Mechanism for Multi-tenancy Cloud Environment
    Lo, Nai Wei
    Yang, Ta Chih
    Guo, Ming Huang
    WIRELESS PERSONAL COMMUNICATIONS, 2015, 84 (03) : 2119 - 2134
  • [4] An Attribute-Role Based Access Control Mechanism for Multi-tenancy Cloud Environment
    Nai Wei Lo
    Ta Chih Yang
    Ming Huang Guo
    Wireless Personal Communications, 2015, 84 : 2119 - 2134
  • [5] Design Issues of Role-Based Multi-Tenancy Access Control in Cloud Computing Services
    Yang, Shin-Jer
    Lai, Pei-Ci
    Lin, Jyhjong
    JOURNAL OF INTERNET TECHNOLOGY, 2017, 18 (06): : 1407 - 1417
  • [6] XBAC: A Unified Access Control Model for Heterogeneous Multi-Tenancy Cloud Environments
    Ayache, Meryeme
    Gawanmeh, Amjad
    Al-Karaki, Jamal N.
    2019 15TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE (IWCMC), 2019, : 1872 - 1878
  • [7] Multi-Tenancy in Cloud Computing
    AlJahdali, Hussain
    Albatli, Abdulaziz
    Garraghan, Peter
    Townend, Paul
    Lau, Lydia
    Xu, Jie
    2014 IEEE 8TH INTERNATIONAL SYMPOSIUM ON SERVICE ORIENTED SYSTEM ENGINEERING (SOSE), 2014, : 344 - 351
  • [8] Security in Multi-Tenancy Cloud
    Jasti, Amarnath
    Shah, Payal
    Nagaraj, Rajeev
    Pendse, Ravi
    44TH ANNUAL 2010 IEEE INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY, 2010, : 35 - 41
  • [9] MULTI-TENANCY IN BUSINESS SUPPORT SYSTEMS CLOUD DEPLOYMENTS
    Dragan, Ioan
    Zota, Razvan Daniel
    INTERNATIONAL CONFERENCE ON INFORMATICS IN ECONOMY, IE 2016: EDUCATION, RESEARCH & BUSINESS TECHNOLOGIES, 2016, : 32 - 37
  • [10] Introducing Network Multi-tenancy for Cloud-based Enterprise Resource Planning: An IoT Application
    Tiwary, Mayank
    Kumar, Sunil
    Agrawal, Pankaj Kumar
    Puthal, Deepak
    Rodrigues, Joel J. P. C.
    Sahoo, Kshira Sagar
    Sahoo, Bibhudatta
    2018 IEEE 27TH INTERNATIONAL SYMPOSIUM ON INDUSTRIAL ELECTRONICS (ISIE), 2018, : 1263 - 1269