Proposing hierarchy-similarity based access control framework: A multilevel Electronic Health Record data sharing approach for interoperable environment

Interoperability in healthcare environment deals with sharing of patient’s Electronic Health Records (EHR) with fellow professionals in inter as well as intra departments or organizations. Healthcare environment experiences frequent shifting of doctors, paramedical staff in inter as well as intra de...

Full description

Bibliographic Details
Main Authors: Shalini Bhartiya, Deepti Mehrotra, Anup Girdhar
Format: Article
Language:English
Published: Elsevier 2017-10-01
Series:Journal of King Saud University: Computer and Information Sciences
Subjects:
Online Access:http://www.sciencedirect.com/science/article/pii/S1319157815001147
id doaj-b62a737ce09b4d1b9d4b52cf5e19fc3c
record_format Article
spelling doaj-b62a737ce09b4d1b9d4b52cf5e19fc3c2020-11-24T23:03:43ZengElsevierJournal of King Saud University: Computer and Information Sciences1319-15782017-10-0129450551910.1016/j.jksuci.2015.08.005Proposing hierarchy-similarity based access control framework: A multilevel Electronic Health Record data sharing approach for interoperable environmentShalini Bhartiya0Deepti Mehrotra1Anup Girdhar2Amity School of Engineering and Technology, Amity University, Uttar Pradesh Sector 125, Noida, U.P., IndiaAmity School of Engineering and Technology, Amity University, Uttar Pradesh Sector 125, Noida, U.P., IndiaSedulity Solutions, 310 Suneja Towers-II, Janakpuri, New Delhi, IndiaInteroperability in healthcare environment deals with sharing of patient’s Electronic Health Records (EHR) with fellow professionals in inter as well as intra departments or organizations. Healthcare environment experiences frequent shifting of doctors, paramedical staff in inter as well as intra departments or hospitals. The system exhibits dynamic attributes of users and resources managed through access control policies defined for that environment. Rules obtained on merging of such policies often generate policy-conflicts thereby resulting in undue data leakages to unintended users. This paper proposes an access control framework that applies a Hierarchy Similarity Analyzer (HSA) on the policies need to be merged. It calculates a Security_Level (SL) and assigns it to the users sharing data. The SL determines the authorized amount of data that can be shared on successful collaboration of two policies. The proposed framework allows integration of independent policies and identifies the possible policy-conflicts arising due to attribute disparities in defined rules. The framework is implemented on XACML policies and compared with other access models designed using centralized and decentralized approaches. Conditional constraints and properties are defined that generate policy-conflicts as prevalent in the policies.http://www.sciencedirect.com/science/article/pii/S1319157815001147Access control policiesElectronic Health Records (EHR)Hierarchical Similarity Analyzer (HSA)Interoperable healthcare environmentSecurity
collection DOAJ
language English
format Article
sources DOAJ
author Shalini Bhartiya
Deepti Mehrotra
Anup Girdhar
spellingShingle Shalini Bhartiya
Deepti Mehrotra
Anup Girdhar
Proposing hierarchy-similarity based access control framework: A multilevel Electronic Health Record data sharing approach for interoperable environment
Journal of King Saud University: Computer and Information Sciences
Access control policies
Electronic Health Records (EHR)
Hierarchical Similarity Analyzer (HSA)
Interoperable healthcare environment
Security
author_facet Shalini Bhartiya
Deepti Mehrotra
Anup Girdhar
author_sort Shalini Bhartiya
title Proposing hierarchy-similarity based access control framework: A multilevel Electronic Health Record data sharing approach for interoperable environment
title_short Proposing hierarchy-similarity based access control framework: A multilevel Electronic Health Record data sharing approach for interoperable environment
title_full Proposing hierarchy-similarity based access control framework: A multilevel Electronic Health Record data sharing approach for interoperable environment
title_fullStr Proposing hierarchy-similarity based access control framework: A multilevel Electronic Health Record data sharing approach for interoperable environment
title_full_unstemmed Proposing hierarchy-similarity based access control framework: A multilevel Electronic Health Record data sharing approach for interoperable environment
title_sort proposing hierarchy-similarity based access control framework: a multilevel electronic health record data sharing approach for interoperable environment
publisher Elsevier
series Journal of King Saud University: Computer and Information Sciences
issn 1319-1578
publishDate 2017-10-01
description Interoperability in healthcare environment deals with sharing of patient’s Electronic Health Records (EHR) with fellow professionals in inter as well as intra departments or organizations. Healthcare environment experiences frequent shifting of doctors, paramedical staff in inter as well as intra departments or hospitals. The system exhibits dynamic attributes of users and resources managed through access control policies defined for that environment. Rules obtained on merging of such policies often generate policy-conflicts thereby resulting in undue data leakages to unintended users. This paper proposes an access control framework that applies a Hierarchy Similarity Analyzer (HSA) on the policies need to be merged. It calculates a Security_Level (SL) and assigns it to the users sharing data. The SL determines the authorized amount of data that can be shared on successful collaboration of two policies. The proposed framework allows integration of independent policies and identifies the possible policy-conflicts arising due to attribute disparities in defined rules. The framework is implemented on XACML policies and compared with other access models designed using centralized and decentralized approaches. Conditional constraints and properties are defined that generate policy-conflicts as prevalent in the policies.
topic Access control policies
Electronic Health Records (EHR)
Hierarchical Similarity Analyzer (HSA)
Interoperable healthcare environment
Security
url http://www.sciencedirect.com/science/article/pii/S1319157815001147
work_keys_str_mv AT shalinibhartiya proposinghierarchysimilaritybasedaccesscontrolframeworkamultilevelelectronichealthrecorddatasharingapproachforinteroperableenvironment
AT deeptimehrotra proposinghierarchysimilaritybasedaccesscontrolframeworkamultilevelelectronichealthrecorddatasharingapproachforinteroperableenvironment
AT anupgirdhar proposinghierarchysimilaritybasedaccesscontrolframeworkamultilevelelectronichealthrecorddatasharingapproachforinteroperableenvironment
_version_ 1725632521123659776