【24h】

An Attributable Role-Based Access Control for Healthcare

机译:基于角色的基于角色的医疗保健访问控制

获取原文
获取原文并翻译 | 示例

摘要

Role Based Access Control (RBAC) has the potential for reducing the complexity and total cost of security administration. Even though RBAC implementations aim on administrating large scale systems, they have a shortcoming in common. They do not allow to define attributable roles and permissions. But such roles are very common in our thoughts and language. When we say "attending physician of patient x", we mean a role attending physician with all associated permissions to fulfill the treatment of patient x. Because the resulting permissions only differ in the restriction to a particular patient, it is desirable that attributes like "patient x" are used in roles and permissions to restrict the rights to access only data related to that patient. This paper shows how attributes can be applied to RBAC, in order to reduce the total number of role- and permission-objects in security administration.
机译:基于角色的访问控制(RBAC)具有降低安全性管理的复杂性和总成本的潜力。尽管RBAC实施旨在管理大型系统,但它们也有一个共同的缺点。它们不允许定义可归因的角色和权限。但是这种角色在我们的思想和语言中非常普遍。当我们说“患者x的主治医师”时,是指具有所有相关权限以实现患者x的治疗的主治医师角色。因为所产生的权限仅在对特定患者的限制方面有所不同,所以希望在角色和权限中使用“患者x”之类的属性来限制仅访问与该患者有关的数据的权限。本文展示了如何将属性应用于RBAC,以减少安全管理中角色和权限对象的总数。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号