Your browser doesn't support javascript.
loading
A cross domain access control model for medical consortium based on DBSCAN and penalty function.
Yao, Chuanjia; Jiang, Rong; Wu, Bin; Li, Pinghui; Wang, Chenguang.
Afiliação
  • Yao C; Institute of Intelligence Applications, Yunnan University of Finance and Economics, Kunming, 650021, China.
  • Jiang R; School of Business, Yunnan University of Finance and Economics, Kunming, 650021, China.
  • Wu B; Yunnan Key Laboratory of Service Computing, Kunming, 650021, China.
  • Li P; Institute of Intelligence Applications, Yunnan University of Finance and Economics, Kunming, 650021, China.
  • Wang C; School of Business, Yunnan University of Finance and Economics, Kunming, 650021, China.
BMC Med Inform Decis Mak ; 24(1): 260, 2024 Sep 16.
Article em En | MEDLINE | ID: mdl-39285411
ABSTRACT

BACKGROUND:

Graded diagnosis and treatment, referral, and expert consultations between medical institutions all require cross domain access to patient medical information to support doctors' treatment decisions, leading to an increase in cross domain access among various medical institutions within the medical consortium. However, patient medical information is sensitive and private, and it is essential to control doctors' cross domain access to reduce the risk of leakage. Access control is a continuous and long-term process, and it first requires verification of the legitimacy of user identities, while utilizing control policies for selection and management. After verifying user identity and access permissions, it is also necessary to monitor unauthorized operations. Therefore, the content of access control includes authentication, implementation of control policies, and security auditing. Unlike the existing focus on authentication and control strategy implementation in access control, this article focuses on the control based on access log security auditing for doctors who have obtained authorization to access medical resources. This paper designs a blockchain based doctor intelligent cross domain access log recording system, which is used to record, query and analyze the cross domain access behavior of doctors after authorization. Through DBSCAN clustering analysis of doctors' cross domain access logs, we find the abnormal phenomenon of cross domain access, and build a penalty function to dynamically control doctors' cross domain access process, so as to reduce the risk of Data breach. Finally, through comparative analysis and experiments, it is shown that the proposed cross domain access control model for medical consortia based on DBSCAN and penalty function has good control effect on the cross domain access behavior of doctors in various medical institutions of the medical consortia, and has certain feasibility for the cross domain access control of doctors.
Assuntos
Palavras-chave

Texto completo: 1 Coleções: 01-internacional Base de dados: MEDLINE Assunto principal: Segurança Computacional Limite: Humans Idioma: En Revista: BMC Med Inform Decis Mak Assunto da revista: INFORMATICA MEDICA Ano de publicação: 2024 Tipo de documento: Article País de afiliação: China País de publicação: Reino Unido

Texto completo: 1 Coleções: 01-internacional Base de dados: MEDLINE Assunto principal: Segurança Computacional Limite: Humans Idioma: En Revista: BMC Med Inform Decis Mak Assunto da revista: INFORMATICA MEDICA Ano de publicação: 2024 Tipo de documento: Article País de afiliação: China País de publicação: Reino Unido