首页> 外文会议>2016 IEEE First Conference on Connected Health: Applications, Systems and Engineering Technologies >Implementing Informed Consent as Information-Flow Policies for Secure Analytics on eHealth Data: Principles and Practices
【24h】

Implementing Informed Consent as Information-Flow Policies for Secure Analytics on eHealth Data: Principles and Practices

机译:实施知情同意作为信息流策略,以对eHealth数据进行安全分析:原则和实践

获取原文
获取原文并翻译 | 示例

摘要

Wearable and ambient cyber-physical systems coupled with big-data health analytics promise continuous individual health monitoring and customized medical interventions. However, health workers and medical researchers are bound by strict security and privacy conventions that make it difficult to take advantage of emerging data streams. In this paper, we propose a security and privacy architecture for the analytics back-end in medical cyber-physical systems. Our approach is motivated by three principles: users behave mostly rational, informed consent are security policies, and deep revocation of granted rights. We propose implementing these principles using a novel combination of information-flow control with attested programs for data declassification in combination with auditing and credential-based access control. Our implementation relies on fine-grained encapsulation of data sets and processing components inside virtual-machine containers. We therefore evaluate our ability to host concurrent Linux containers, and observe that 70 instances can be easily accommodated on commodity hardware.
机译:可穿戴的环境网络物理系统与大数据健康分析相结合,可以实现连续的个人健康监测和定制的医疗干预。但是,卫生工作者和医学研究人员受到严格的安全性和隐私约定的约束,这使利用新兴数据流变得困难。在本文中,我们为医疗网络物理系统的分析后端提出了一种安全和隐私体系结构。我们的方法受以下三个原则激励:用户的行为主要是理性的,知情同意是安全策略,以及对已授予权利的深度撤销。我们建议使用新颖的信息流控制与经验证的程序进行数据解密的组合,再结合审核和基于凭证的访问控制,来实现这些原则。我们的实现依赖于虚拟机容器内数据集和处理组件的细粒度封装。因此,我们评估了托管并发Linux容器的能力,并观察到70个实例可以轻松容纳在商用硬件上。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号