E-Health systems logically demand a sufficiently fine-grained authorization policy for access control. The access to medical information should not be just role-based but should also include the contextual condition of the role to access data. In this paper, we present a mechanism to extend the standard role-based access control to incorporate contextual information for making access control decisions in e-health application. We present an architecture consisting of authorisation and context infrastructure that work cooperatively to grant access rights based on context-aware authorization policies and context information.
History
Chapter number
9
Pagination
68-77
ISSN
1865-0929
eISSN
1865-0937
ISBN-13
9783642026324
Language
eng
Notes
Third International Conference, ISA 2009 Seoul, Korea, June 25-27, 2009 Proceedings
Publication classification
B1 Book chapter
Copyright notice
2009, Springer-Verlag Berlin
Extent
16
Editor/Contributor(s)
Park J, Zhan J, Lee C, Wang G, Kim TH, Yeo SS
Publisher
Springer
Place of publication
Berlin, Germany
Title of book
Advances in information security and its application
Series
Communications in computer and informationscience ; v. 36