Privacy and security are crucial for using Electronic Patient Records (EHRs) within healthcare systems, as clinical data is sensitive. In response to this, several access control approaches have been recently developed to limit access to sensitive information. This paper presents a novel human-centric access control model, Behavioral-Based Access Control (BBAC), inspired by the Internet of Behavior paradigm. The proposed model implements behavioral modeling, allowing privacy-preserving data sharing based on user behaviors in complex healthcare environments. The model enhances security and privacy in distributed healthcare systems by adjusting access permissions according to user behavior, location, and time, as evaluated in a simulated scenario. The proposed model uses the XACML policy language to implement BBAC, which determines whether to allow or deny user access requests. This approach enables personalized and secure access control by analyzing user behavioral patterns and adjusting permissions accordingly. The ability to regulate access based on individual user behavior represents a shift towards more adaptive and tailored security mechanisms and discusses its dynamic potential for future research.

Behavioral and human-centric access control model in XACML reference architecture: design and implementation of EHR case study

Marchetti E.
2024

Abstract

Privacy and security are crucial for using Electronic Patient Records (EHRs) within healthcare systems, as clinical data is sensitive. In response to this, several access control approaches have been recently developed to limit access to sensitive information. This paper presents a novel human-centric access control model, Behavioral-Based Access Control (BBAC), inspired by the Internet of Behavior paradigm. The proposed model implements behavioral modeling, allowing privacy-preserving data sharing based on user behaviors in complex healthcare environments. The model enhances security and privacy in distributed healthcare systems by adjusting access permissions according to user behavior, location, and time, as evaluated in a simulated scenario. The proposed model uses the XACML policy language to implement BBAC, which determines whether to allow or deny user access requests. This approach enables personalized and secure access control by analyzing user behavioral patterns and adjusting permissions accordingly. The ability to regulate access based on individual user behavior represents a shift towards more adaptive and tailored security mechanisms and discusses its dynamic potential for future research.
2024
Istituto di Scienza e Tecnologie dell'Informazione "Alessandro Faedo" - ISTI
9783031638503
9783031638510
Health 5.0
Human-centric
Security
Access control
User behavior
Internet of Behavior
XACML
File in questo prodotto:
File Dimensione Formato  
Pagine da 978-3-031-63851-0 (1).pdf

solo utenti autorizzati

Descrizione: Behavioral and Human-Centric Access Control Model in XACML Reference Architecture: Design and Implementation of EHR Case Study
Tipologia: Versione Editoriale (PDF)
Licenza: NON PUBBLICO - Accesso privato/ristretto
Dimensione 1.91 MB
Formato Adobe PDF
1.91 MB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/513519
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact