کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
517379 867448 2010 5 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
A method to implement fine-grained access control for personal health records through standard relational database queries
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر نرم افزارهای علوم کامپیوتر
پیش نمایش صفحه اول مقاله
A method to implement fine-grained access control for personal health records through standard relational database queries
چکیده انگلیسی

Online personal health records (PHRs) enable patients to access, manage, and share certain of their own health information electronically. This capability creates the need for precise access-controls mechanisms that restrict the sharing of data to that intended by the patient. The authors describe the design and implementation of an access-control mechanism for PHR repositories that is modeled on the eXtensible Access Control Markup Language (XACML) standard, but intended to reduce the cognitive and computational complexity of XACML. The authors implemented the mechanism entirely in a relational database system using ANSI-standard SQL statements. Based on a set of access-control rules encoded as relational table rows, the mechanism determines via a single SQL query whether a user who accesses patient data from a specific application is authorized to perform a requested operation on a specified data object. Testing of this query on a moderately large database has demonstrated execution times consistently below 100 ms. The authors include the details of the implementation, including algorithms, examples, and a test database as Supplementary materials.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Journal of Biomedical Informatics - Volume 43, Issue 5, Supplement, October 2010, Pages S46–S50
نویسندگان
, , , ,