Murdoch University Research Repository

Welcome to the Murdoch University Research Repository

The Murdoch University Research Repository is an open access digital collection of research
created by Murdoch University staff, researchers and postgraduate students.

Learn more

Access control policy combination from similarity analysis for secure Privacy-preserved EHR systems

Rezaeibagha, F. and Mu, Y. (2017) Access control policy combination from similarity analysis for secure Privacy-preserved EHR systems. In: 2017 IEEE Trustcom/BigDataSE/ICESS, 1 - 4 Aug. 2017, Sydney, NSW

Link to Published Version: https://doi.org/10.1109/Trustcom/BigDataSE/ICESS.2...
*Subscription may be required

Abstract

In distributed systems, there is often a need to combine the heterogeneous access control policies to offer more comprehensive services to users in the local or national level. A large scale healthcare system is usually distributed in a computer network and might require sophisticated access control policies to protect the system. Therefore, the need for integrating the electronic healthcare systems might be important to provide a comprehensive care for patients while preserving patients' privacy and data security. However, there are major impediments in healthcare systems concerning not well-defined and flexible access control policy implementations, hindering the progress towards secure integrated systems. In this paper, we introduce an access control policy combination framework for EHR systems that preserves patients' privacy and ensures data security. We achieve our goal through an access control mechanism which handles multiple access control policies through a similarity analysis phase. In that phase, we evaluate different XACML policies to decide whether or not a policy combination is applicable. We have provided a case study to show the applicability of our proposed approach based on XACML. Our study results can be applied to the electronic health record (EHR) access control policy, which fosters interoperability and scalability among healthcare providers while preserving patients' privacy and data security.

Item Type: Conference Paper
URI: http://researchrepository.murdoch.edu.au/id/eprint/54660
Item Control Page Item Control Page