Requirements elicitation for secure and interoperable cross-border health data exchange: the KONFIDO study

被引:2
|
作者
Natsiavas, Pantelis [1 ]
Kakalou, Christine [1 ]
Votis, Konstantinos [2 ]
Tzovaras, Dimitrios [2 ]
Maglaveras, Nicos [3 ]
Koutkias, Vassilis [1 ]
机构
[1] Ctr Res & Technol Hellas, Inst Appl Biosci, Thessaloniki, Greece
[2] Ctr Res & Technol Hellas, Informat Technol Inst, Thessaloniki, Greece
[3] Northwestern Univ, McCormick Sch Engn & Appl Sci, Dept Ind Engn & Management Sci, Evanston, IL USA
关键词
medical information systems; systems analysis; formal specification; open systems; security of data; cloud computing; cryptography; secure cross-border health data exchange; interoperable cross-border health data exchange; KONFIDO study; requirements elicitation approach; KONFIDO project; authors; requirement elicitation; end-user goals; main business processes; security risks; threats; defining requirements; elaborated business processes; OPENNCP;
D O I
10.1049/iet-sen.2018.5292
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
In this study, the requirements elicitation approach employed in the context of the KONFIDO project is presented. KONFIDO introduces a technical paradigm for secure and interoperable cross-border health data exchange by leveraging novel approaches and cutting-edge technologies, such as homomorphic encryption and blockchains. Being a key part of the overall user requirements engineering methodology, requirements elicitation focused on producing high-level, end-user goals following a systematic procedure. First, the main business processes were identified based on the project's pilot scenarios. These business processes were the subject of a threat analysis, which identified the respective assets and a list of security risks/threats. Threats were further elaborated, considering the outcome of relevant projects and applicable best practices/standards. As a result, a set of user goals were identified and analysed in detail. Finally, a meta-analysis of the produced goals against the employed information sources was applied, highlighting the importance of standards as a guide for defining requirements, as well as the complexity concerning the interdependencies among the elaborated business processes, assets, threats, and user goals. As the deployment of the technical solution may be cloud-based, implications and challenges imposed by the adoption of cloud computing in this setting are also presented.
引用
收藏
页码:203 / 212
页数:10
相关论文
共 50 条
  • [1] Secure Cross-border Exchange of Health Related Data: the KONFIDO Approach
    Diamantopoulos, Sotiris
    Karamitros, Dimitris
    Romano, Luigi
    Coppolino, Luigi
    Koutkias, Vassilis
    Votis, Kostas
    Stan, Oana
    Campegiani, Paolo
    Martinez, David Mari
    Nalin, Marco
    Baroni, Ilaria
    Clemente, Fabrizio
    Faiella, Giuliana
    Mesaritakis, Charis
    Grivas, Evangelos
    Rasmussen, Janne
    MedCom, Jan Petersen
    Cano, Isaac
    Puigdomenech, Elisa
    Gelenbe, Erol
    Dumortier, Jos
    Voss-KnudeVoronkov, Maja
    2019 15TH EUROPEAN DEPENDABLE COMPUTING CONFERENCE (EDCC 2019), 2019, : 73 - 74
  • [2] Comprehensive user requirements engineering methodology for secure and interoperable health data exchange
    Natsiavas, Pantelis
    Rasmussen, Janne
    Voss-Knude, Maja
    Votis, Kostas
    Coppolino, Luigi
    Campegiani, Paolo
    Cano, Isaac
    Mari, David
    Faiella, Giuliana
    Clemente, Fabrizio
    Nalin, Marco
    Grivas, Evangelos
    Stan, Oana
    Gelenbe, Erol
    Dumortier, Jos
    Petersen, Jan
    Tzovaras, Dimitrios
    Romano, Luigi
    Komnios, Ioannis
    Koutkias, Vassilis
    BMC MEDICAL INFORMATICS AND DECISION MAKING, 2018, 18
  • [3] Comprehensive user requirements engineering methodology for secure and interoperable health data exchange
    Pantelis Natsiavas
    Janne Rasmussen
    Maja Voss-Knude
    Κostas Votis
    Luigi Coppolino
    Paolo Campegiani
    Isaac Cano
    David Marí
    Giuliana Faiella
    Fabrizio Clemente
    Marco Nalin
    Evangelos Grivas
    Oana Stan
    Erol Gelenbe
    Jos Dumortier
    Jan Petersen
    Dimitrios Tzovaras
    Luigi Romano
    Ioannis Komnios
    Vassilis Koutkias
    BMC Medical Informatics and Decision Making, 18
  • [4] The European cross-border health data exchange roadmap: Case study in the Italian setting
    Nalin, Marco
    Baroni, Ilaria
    Faiella, Giuliana
    Romano, Maria
    Matrisciano, Flavia
    Gelenbe, Erol
    Mari Martinez, David
    Dumortier, Jos
    Natsiavas, Pantelis
    Votis, Kostas
    Koutkias, Vassilis
    Tzovaras, Dimitrios
    Clemente, Fabrizio
    JOURNAL OF BIOMEDICAL INFORMATICS, 2019, 94
  • [5] Building an Ethical Framework for Cross-Border Applications: The KONFIDO Project
    Faiella, G.
    Komnios, I.
    Voss-Knude, M.
    Cano, I.
    Duquenoy, P.
    Nalin, M.
    Baroni, I.
    Matrisciano, F.
    Clemente, F.
    SECURITY IN COMPUTER AND INFORMATION SCIENCES, EURO-CYBERSEC 2018, 2018, 821 : 38 - 45
  • [6] The European Cross-Border Health Data Exchange: Focus on Clinically Relevant Data
    Palojoki, Sari
    Vakkuri, Anne
    Vuokko, Riikka
    PUBLIC HEALTH AND INFORMATICS, PROCEEDINGS OF MIE 2021, 2021, 281 : 442 - 446
  • [7] KONFIDO: An OpenNCP-Based Secure eHealth Data Exchange System
    Staffa, Mariacarla
    Coppolino, Luigi
    Sgaglione, Luigi
    Gelenbe, Erol
    Komnios, Ioannis
    Grivas, Evangelos
    Stan, Oana
    Castaldo, Luigi
    SECURITY IN COMPUTER AND INFORMATION SCIENCES, EURO-CYBERSEC 2018, 2018, 821 : 11 - 27
  • [8] Privacy policies, cross-border health data and the GDPR
    Mulder, T.
    Tudorica, M.
    INFORMATION & COMMUNICATIONS TECHNOLOGY LAW, 2019, 28 (03) : 261 - 274
  • [9] Intraday herding on a cross-border exchange
    Andrikopoulos, Panagiotis
    Kallinterakis, Vasileios
    Leite Ferreira, Mario Pedro
    Verousis, Thanos
    INTERNATIONAL REVIEW OF FINANCIAL ANALYSIS, 2017, 53 : 25 - 36
  • [10] CROSS-BORDER DATA COMPARISONS
    OJALA, M
    ONLINE, 1994, 18 (03): : 105 - 107