SlideShare a Scribd company logo
RISK-AWARE INTEGRITY MANAGEMENT FRAMEWORK
FOR DISTRIBUTED HEALTHCARE SYSTEMS
Aastha Madaan
Research Fellow, WSL, IIIT-B
※ Research work done as a part of Work Package – 3 of the TRUMP Project [2]
Collaborative Healthcare Setup
Appointments/
Patient information
Pathology
Results
Treatment/Procedures/
Problem Lists
Nursing
Notes
EHR
TRUMP: REQUIREMENTS
o Collaborating & Heterogeneous Care
providers and receivers
2
 Self-Intervention for Chronic Illnesses
Multi-agency Care
Disjoint/distributed
agencies
Limited Resources
CHALLENGES
o Unit of Exchange of Health Information  EHRs  TRUMP Unit
Subjective
UtilityBounded
Validity
Interrelated
Utility
Divergent
Aggregation
TRUMP UNIT
Attributes
RecordId PName Age Sex Version_id
Data
Imported Worlds and Participation
Organization Treatment Person Person ……
…
Primary care
Provider
Therapy Physician Specialist ……
…
DISTRIBUTED KNOWLEDGE REPRESENTATION
FRAMEWORK
3
• Many Worlds on a Frame (MWF) Knowledge Representation framework proposed in [3], [5]
EHR UoD
Schema
AN EXAMPLE (1)
* Screenshots Source: MTech Students - TRUMP Project
AN EXAMPLE (2)
5
AN EXAMPLE (3)
6
AN EXAMPLE (4)
7
AN EXAMPLE (5)
8
AN EXAMPLE (6)
9
RISK-AWARE INTEGRITY MANAGEMENT
 Integrating “Trust” and “Risk” measures with earlier proposed
Credentials based Access Control (CBAC) [4]
 Flexible, bottom-up approach
 Associate policies based on user credentials
 Define Risk and Trust Measures
INTEGRATING TRAAC AND CBAC (1)
 Access control  Agnostic to actual end-users
 Zoned Policy Model [TRAAC]  Zoned Privilege Packages
11
share
deny
readu
reads
undefined
o Type of Requests  Read & Share
o Data Object Policy  Zones assigned
o Risk  Request & Trust  Requestor
o Types of Trust  Obligation & Sharing
Hospital X
Department
of Health
Health-care
Providers
Association
Role: Heart Specialist
Role: Secretary
Role: President
12
 TRAAC approach  Misses CONTEXT during Trust Update
 E.g in Which context was the particular violation made
 TRAAC+ CBAC  MWF captures the context of a given interaction
 Visibility of Policies  Critical to avoid unintentional violation
 TRAAC+CBAC  Policy viewed as a Data Element
 Credentials of a user  participation set
 Credentials  Privilege Package  View applicable policies
 Update of Sharing and Obligation based Trust
 Assignment of Sensitivity Category  Information
INTEGRATING TRAAC AND CBAC (2)
ASSOCIATING TRUST
 Trust  Probability with which a Privilege Package is entrusted to a world
 Privilege package  Assertion1, Assertion2, Assertion3,…., Assertionn
 Assertion  Set of role(Type, Location)
 Trust value  Aggregation of trust values associated with each role in a the
user’s participation set
 Trust across system elements
 User trust in system  Privacy of Information
 System trust in users  Authenticated information
 Trust between users  History of Events
 Evaluating trust  Risk Mitigation Strategy  Obligations to be performed in
a given domain
 Sharing Trust & Obligation Trust 13
ASSOCIATING RISK
 Risk  Probability with which a data-access is granted to a World
with a Stakeholder with a Privilege Package, P
 Assign  Sensitivity category to  Worlds
 Calculate  Loss sustained due to access
 Undesirable Events  Fake credentials of a user
Illegitimate access made by user
 Risk Score = Loss * Probability of Undesirable Events
 Risk Domain  Type and Location of a World
 Risk Mitigation Strategy ?
14
Allow
Deny
Access based
On Risk
CONCERNS
 Emergency Access  Bypassing Access Rules
 Patient  Owner of data or subject of data
 Modelling stakeholder as a data element answer this?
 Complex Information Flows  Involve Delegation
 Responsibility
 Update Trust
15
 Quantification of Risk and Trust
 Revocation of Privilege Packages  Boundary conditions
Risk & Trust
 Risk Mitigation Strategies and Obligation  Trust Delegation
 Visualization of Risk  Access granted to a stakeholder
REFERENCES
1. Burnett, C., Chen, L., Norman, T.~J. and Edwards, P. (2014). TRAAC: Trust and Risk Aware
Access Control. Proceedings of the 12th Annual Conference on Privacy, Security and Trust
(PST2014), Toronto, Canada.
2. Burnett, C., Edwards, P., Norman, T. J., Chen, L., Rahulamathavan, Y., Jaffray, M., & Pignotti,
E. (2013). TRUMP: A Trusted Mobile Platform for Self-management of Chronic Illness in
Rural Areas. In Trust and Trustworthy Computing (pp. 142-150). Springer Berlin Heidelberg.
3. Chinmay Jog, Sweety Agrawal, Srinath Srinivasa. Distributing a Trust Framework for
Utilitarian Data Exchanges in Inter-Organizational Collaborations. Proceedings of the Second
ACM iKDD Conference on Data Sciences (CoDS 2015), March 2015, Bangalore, India.
4. Sweety Agrawal, Chinmay Jog, Srinath Srinivasa. Integrity Management in a Trusted
Utilitarian Data Exchange Platform. Proceedings of the 13th International Conference on
Ontologies, Databases and Applications of Semantics (ODBASE 2014), Amantea, Italy,
October 2014.
5. Srinath Srinivasa, Sweety Agrawal, Chinmay Jog and Jayati Deshmukh. Characterizing Open
Utilitarian Knowledge. Proceedings of the First IKDD Conference on Data Sciences (CoDS
2014), New Delhi, India, March 2014.
16

More Related Content

Viewers also liked

Trabajo de deporte actividad 3.1
Trabajo de deporte   actividad 3.1Trabajo de deporte   actividad 3.1
Trabajo de deporte actividad 3.1
gilmaperalta
 
Deporte en Boyacá
Deporte en BoyacáDeporte en Boyacá
Deporte en Boyacá
Melissa_delri
 
cumpleaños normal florencia
cumpleaños normal florenciacumpleaños normal florencia
cumpleaños normal florencia
camilodiazaz
 
Xiomara .
Xiomara .Xiomara .
Constanza roura
Constanza rouraConstanza roura
Constanza roura
ejemplo12
 
Deber exame 1
Deber exame 1Deber exame 1
Deber exame 1
ESTEFANIA Perez
 

Viewers also liked (6)

Trabajo de deporte actividad 3.1
Trabajo de deporte   actividad 3.1Trabajo de deporte   actividad 3.1
Trabajo de deporte actividad 3.1
 
Deporte en Boyacá
Deporte en BoyacáDeporte en Boyacá
Deporte en Boyacá
 
cumpleaños normal florencia
cumpleaños normal florenciacumpleaños normal florencia
cumpleaños normal florencia
 
Xiomara .
Xiomara .Xiomara .
Xiomara .
 
Constanza roura
Constanza rouraConstanza roura
Constanza roura
 
Deber exame 1
Deber exame 1Deber exame 1
Deber exame 1
 

Similar to Risk and Credentials based Access Control

Provider Aware Anonymization Algorithm for Preserving M - Privacy
Provider Aware Anonymization Algorithm for Preserving M - PrivacyProvider Aware Anonymization Algorithm for Preserving M - Privacy
Provider Aware Anonymization Algorithm for Preserving M - Privacy
IJERA Editor
 
IRJET - Blockchain for Medical Data Access and Permission Management
IRJET - Blockchain for Medical Data Access and Permission ManagementIRJET - Blockchain for Medical Data Access and Permission Management
IRJET - Blockchain for Medical Data Access and Permission Management
IRJET Journal
 
Information Security using Cryptography and Image Processing
Information Security using Cryptography and Image ProcessingInformation Security using Cryptography and Image Processing
Information Security using Cryptography and Image Processing
ijsrd.com
 
A review on anonymization techniques for privacy preserving data publishing
A review on anonymization techniques for privacy preserving data publishingA review on anonymization techniques for privacy preserving data publishing
A review on anonymization techniques for privacy preserving data publishing
eSAT Journals
 
Possible Solution for Managing the Worlds Personal Genetic Data - DNA Guide, ...
Possible Solution for Managing the Worlds Personal Genetic Data - DNA Guide, ...Possible Solution for Managing the Worlds Personal Genetic Data - DNA Guide, ...
Possible Solution for Managing the Worlds Personal Genetic Data - DNA Guide, ...
DNA Compass
 
Ijarcet vol-2-issue-4-1393-1397
Ijarcet vol-2-issue-4-1393-1397Ijarcet vol-2-issue-4-1393-1397
Ijarcet vol-2-issue-4-1393-1397
Editor IJARCET
 
m-Privacy for Collaborative Data Publishing
m-Privacy for Collaborative Data Publishingm-Privacy for Collaborative Data Publishing
m-Privacy for Collaborative Data Publishing
Migrant Systems
 
Cp34550555
Cp34550555Cp34550555
Cp34550555
IJERA Editor
 
An Empirical Study on Mushroom Disease Diagnosis:A Data Mining Approach
An Empirical Study on Mushroom Disease Diagnosis:A Data Mining ApproachAn Empirical Study on Mushroom Disease Diagnosis:A Data Mining Approach
An Empirical Study on Mushroom Disease Diagnosis:A Data Mining Approach
IRJET Journal
 
Predicting disease from several symptoms using machine learning approach.
Predicting disease from several symptoms using machine learning approach.Predicting disease from several symptoms using machine learning approach.
Predicting disease from several symptoms using machine learning approach.
IRJET Journal
 
Survey on Medical Data Sharing Systems with NTRU
Survey on Medical Data Sharing Systems with NTRUSurvey on Medical Data Sharing Systems with NTRU
Survey on Medical Data Sharing Systems with NTRU
IRJET Journal
 
DEADLINE FRIDAY 492021 BY 0800 PM ESTINSTRUCTIONS Res
DEADLINE FRIDAY 492021 BY 0800 PM ESTINSTRUCTIONS ResDEADLINE FRIDAY 492021 BY 0800 PM ESTINSTRUCTIONS Res
DEADLINE FRIDAY 492021 BY 0800 PM ESTINSTRUCTIONS Res
LinaCovington707
 
Framework architecture for improving
Framework architecture for improvingFramework architecture for improving
Framework architecture for improving
IJMIT JOURNAL
 
Jennifer DiscussionThe use of electronic health records (EHR) i.docx
Jennifer DiscussionThe use of electronic health records (EHR) i.docxJennifer DiscussionThe use of electronic health records (EHR) i.docx
Jennifer DiscussionThe use of electronic health records (EHR) i.docx
LaticiaGrissomzz
 
Paper id 37201535
Paper id 37201535Paper id 37201535
Paper id 37201535
IJRAT
 
Framework Architecture for Improving Healthcare Information Systems using Age...
Framework Architecture for Improving Healthcare Information Systems using Age...Framework Architecture for Improving Healthcare Information Systems using Age...
Framework Architecture for Improving Healthcare Information Systems using Age...
IJMIT JOURNAL
 
The Case Study of an Early Warning Models for the Telecare Patients in Taiwan
The Case Study of an Early Warning Models for the Telecare Patients in TaiwanThe Case Study of an Early Warning Models for the Telecare Patients in Taiwan
The Case Study of an Early Warning Models for the Telecare Patients in Taiwan
IJERA Editor
 
Andrew Roberts - Mobile Health Apps for Improved Patient Engagement and Educa...
Andrew Roberts - Mobile Health Apps for Improved Patient Engagement and Educa...Andrew Roberts - Mobile Health Apps for Improved Patient Engagement and Educa...
Andrew Roberts - Mobile Health Apps for Improved Patient Engagement and Educa...
itnewsafrica
 
Ijricit 01-005 pscsv - patient self-driven multi-stage confidentiality safegu...
Ijricit 01-005 pscsv - patient self-driven multi-stage confidentiality safegu...Ijricit 01-005 pscsv - patient self-driven multi-stage confidentiality safegu...
Ijricit 01-005 pscsv - patient self-driven multi-stage confidentiality safegu...
Ijripublishers Ijri
 
Implementing The Affordable Care Act Essay
Implementing The Affordable Care Act EssayImplementing The Affordable Care Act Essay
Implementing The Affordable Care Act Essay
Michelle Love
 

Similar to Risk and Credentials based Access Control (20)

Provider Aware Anonymization Algorithm for Preserving M - Privacy
Provider Aware Anonymization Algorithm for Preserving M - PrivacyProvider Aware Anonymization Algorithm for Preserving M - Privacy
Provider Aware Anonymization Algorithm for Preserving M - Privacy
 
IRJET - Blockchain for Medical Data Access and Permission Management
IRJET - Blockchain for Medical Data Access and Permission ManagementIRJET - Blockchain for Medical Data Access and Permission Management
IRJET - Blockchain for Medical Data Access and Permission Management
 
Information Security using Cryptography and Image Processing
Information Security using Cryptography and Image ProcessingInformation Security using Cryptography and Image Processing
Information Security using Cryptography and Image Processing
 
A review on anonymization techniques for privacy preserving data publishing
A review on anonymization techniques for privacy preserving data publishingA review on anonymization techniques for privacy preserving data publishing
A review on anonymization techniques for privacy preserving data publishing
 
Possible Solution for Managing the Worlds Personal Genetic Data - DNA Guide, ...
Possible Solution for Managing the Worlds Personal Genetic Data - DNA Guide, ...Possible Solution for Managing the Worlds Personal Genetic Data - DNA Guide, ...
Possible Solution for Managing the Worlds Personal Genetic Data - DNA Guide, ...
 
Ijarcet vol-2-issue-4-1393-1397
Ijarcet vol-2-issue-4-1393-1397Ijarcet vol-2-issue-4-1393-1397
Ijarcet vol-2-issue-4-1393-1397
 
m-Privacy for Collaborative Data Publishing
m-Privacy for Collaborative Data Publishingm-Privacy for Collaborative Data Publishing
m-Privacy for Collaborative Data Publishing
 
Cp34550555
Cp34550555Cp34550555
Cp34550555
 
An Empirical Study on Mushroom Disease Diagnosis:A Data Mining Approach
An Empirical Study on Mushroom Disease Diagnosis:A Data Mining ApproachAn Empirical Study on Mushroom Disease Diagnosis:A Data Mining Approach
An Empirical Study on Mushroom Disease Diagnosis:A Data Mining Approach
 
Predicting disease from several symptoms using machine learning approach.
Predicting disease from several symptoms using machine learning approach.Predicting disease from several symptoms using machine learning approach.
Predicting disease from several symptoms using machine learning approach.
 
Survey on Medical Data Sharing Systems with NTRU
Survey on Medical Data Sharing Systems with NTRUSurvey on Medical Data Sharing Systems with NTRU
Survey on Medical Data Sharing Systems with NTRU
 
DEADLINE FRIDAY 492021 BY 0800 PM ESTINSTRUCTIONS Res
DEADLINE FRIDAY 492021 BY 0800 PM ESTINSTRUCTIONS ResDEADLINE FRIDAY 492021 BY 0800 PM ESTINSTRUCTIONS Res
DEADLINE FRIDAY 492021 BY 0800 PM ESTINSTRUCTIONS Res
 
Framework architecture for improving
Framework architecture for improvingFramework architecture for improving
Framework architecture for improving
 
Jennifer DiscussionThe use of electronic health records (EHR) i.docx
Jennifer DiscussionThe use of electronic health records (EHR) i.docxJennifer DiscussionThe use of electronic health records (EHR) i.docx
Jennifer DiscussionThe use of electronic health records (EHR) i.docx
 
Paper id 37201535
Paper id 37201535Paper id 37201535
Paper id 37201535
 
Framework Architecture for Improving Healthcare Information Systems using Age...
Framework Architecture for Improving Healthcare Information Systems using Age...Framework Architecture for Improving Healthcare Information Systems using Age...
Framework Architecture for Improving Healthcare Information Systems using Age...
 
The Case Study of an Early Warning Models for the Telecare Patients in Taiwan
The Case Study of an Early Warning Models for the Telecare Patients in TaiwanThe Case Study of an Early Warning Models for the Telecare Patients in Taiwan
The Case Study of an Early Warning Models for the Telecare Patients in Taiwan
 
Andrew Roberts - Mobile Health Apps for Improved Patient Engagement and Educa...
Andrew Roberts - Mobile Health Apps for Improved Patient Engagement and Educa...Andrew Roberts - Mobile Health Apps for Improved Patient Engagement and Educa...
Andrew Roberts - Mobile Health Apps for Improved Patient Engagement and Educa...
 
Ijricit 01-005 pscsv - patient self-driven multi-stage confidentiality safegu...
Ijricit 01-005 pscsv - patient self-driven multi-stage confidentiality safegu...Ijricit 01-005 pscsv - patient self-driven multi-stage confidentiality safegu...
Ijricit 01-005 pscsv - patient self-driven multi-stage confidentiality safegu...
 
Implementing The Affordable Care Act Essay
Implementing The Affordable Care Act EssayImplementing The Affordable Care Act Essay
Implementing The Affordable Care Act Essay
 

More from Aastha Madaan

Components of openEHR based EHRs
Components of openEHR based EHRsComponents of openEHR based EHRs
Components of openEHR based EHRs
Aastha Madaan
 
Promise of web science
Promise of web sciencePromise of web science
Promise of web science
Aastha Madaan
 
Web Page Segmentation for Querying Healthcare Repository
Web Page Segmentation for Querying Healthcare RepositoryWeb Page Segmentation for Querying Healthcare Repository
Web Page Segmentation for Querying Healthcare Repository
Aastha Madaan
 
Domain-specific Multi-stage Query Language for Medical Document Repositories
Domain-specific Multi-stage Query Language for Medical Document RepositoriesDomain-specific Multi-stage Query Language for Medical Document Repositories
Domain-specific Multi-stage Query Language for Medical Document Repositories
Aastha Madaan
 
A Quasi Relational Query Language for Persistent Standardized EHRs: Using NoS...
A Quasi Relational Query Language for Persistent Standardized EHRs: Using NoS...A Quasi Relational Query Language for Persistent Standardized EHRs: Using NoS...
A Quasi Relational Query Language for Persistent Standardized EHRs: Using NoS...
Aastha Madaan
 
Observlets
Observlets Observlets
Observlets
Aastha Madaan
 
IoT Observatory
IoT ObservatoryIoT Observatory
IoT Observatory
Aastha Madaan
 

More from Aastha Madaan (7)

Components of openEHR based EHRs
Components of openEHR based EHRsComponents of openEHR based EHRs
Components of openEHR based EHRs
 
Promise of web science
Promise of web sciencePromise of web science
Promise of web science
 
Web Page Segmentation for Querying Healthcare Repository
Web Page Segmentation for Querying Healthcare RepositoryWeb Page Segmentation for Querying Healthcare Repository
Web Page Segmentation for Querying Healthcare Repository
 
Domain-specific Multi-stage Query Language for Medical Document Repositories
Domain-specific Multi-stage Query Language for Medical Document RepositoriesDomain-specific Multi-stage Query Language for Medical Document Repositories
Domain-specific Multi-stage Query Language for Medical Document Repositories
 
A Quasi Relational Query Language for Persistent Standardized EHRs: Using NoS...
A Quasi Relational Query Language for Persistent Standardized EHRs: Using NoS...A Quasi Relational Query Language for Persistent Standardized EHRs: Using NoS...
A Quasi Relational Query Language for Persistent Standardized EHRs: Using NoS...
 
Observlets
Observlets Observlets
Observlets
 
IoT Observatory
IoT ObservatoryIoT Observatory
IoT Observatory
 

Recently uploaded

Assessment of ear, Eye, Nose, and-Throat.pptx
Assessment of ear, Eye, Nose, and-Throat.pptxAssessment of ear, Eye, Nose, and-Throat.pptx
Assessment of ear, Eye, Nose, and-Throat.pptx
Rommel Luis III Israel
 
The crucial role of mathematics in ai development.pptx
The crucial role of mathematics in ai development.pptxThe crucial role of mathematics in ai development.pptx
The crucial role of mathematics in ai development.pptx
priyabhojwani1200
 
2024 Media Preferences of Older Adults: Consumer Survey and Marketing Implica...
2024 Media Preferences of Older Adults: Consumer Survey and Marketing Implica...2024 Media Preferences of Older Adults: Consumer Survey and Marketing Implica...
2024 Media Preferences of Older Adults: Consumer Survey and Marketing Implica...
Media Logic
 
Test bank advanced health assessment and differential diagnosis essentials fo...
Test bank advanced health assessment and differential diagnosis essentials fo...Test bank advanced health assessment and differential diagnosis essentials fo...
Test bank advanced health assessment and differential diagnosis essentials fo...
rightmanforbloodline
 
Psychological Safety as a Foundation for Improvement 12-06-24.pdf
Psychological Safety as a Foundation for Improvement 12-06-24.pdfPsychological Safety as a Foundation for Improvement 12-06-24.pdf
Psychological Safety as a Foundation for Improvement 12-06-24.pdf
Healthcare Improvement Support
 
Discover the Perfect Way to Relax - Malayali Kerala Spa Ajman
Discover the Perfect Way to Relax - Malayali Kerala Spa AjmanDiscover the Perfect Way to Relax - Malayali Kerala Spa Ajman
Discover the Perfect Way to Relax - Malayali Kerala Spa Ajman
Malayali Kerala Spa Ajman
 
𝔹hopal Call Girls 7023059433 High Profile Independent Escorts 𝔹hopal
𝔹hopal Call Girls 7023059433 High Profile Independent Escorts 𝔹hopal𝔹hopal Call Girls 7023059433 High Profile Independent Escorts 𝔹hopal
𝔹hopal Call Girls 7023059433 High Profile Independent Escorts 𝔹hopal
garge6804
 
Faridkot ℂ𝕒𝕝𝕝 𝔾𝕚𝕣𝕝𝕤 7742996321 ℂ𝕒𝕝𝕝 𝔾𝕚𝕣𝕝𝕤 Faridkot
Faridkot ℂ𝕒𝕝𝕝 𝔾𝕚𝕣𝕝𝕤 7742996321 ℂ𝕒𝕝𝕝 𝔾𝕚𝕣𝕝𝕤 FaridkotFaridkot ℂ𝕒𝕝𝕝 𝔾𝕚𝕣𝕝𝕤 7742996321 ℂ𝕒𝕝𝕝 𝔾𝕚𝕣𝕝𝕤 Faridkot
Faridkot ℂ𝕒𝕝𝕝 𝔾𝕚𝕣𝕝𝕤 7742996321 ℂ𝕒𝕝𝕝 𝔾𝕚𝕣𝕝𝕤 Faridkot
varun0kumar00
 
THE SPECIAL SENCES- Unlocking the Wonders of the Special Senses: Sight, Sound...
THE SPECIAL SENCES- Unlocking the Wonders of the Special Senses: Sight, Sound...THE SPECIAL SENCES- Unlocking the Wonders of the Special Senses: Sight, Sound...
THE SPECIAL SENCES- Unlocking the Wonders of the Special Senses: Sight, Sound...
Nursing Mastery
 
STERILIZATION AND DISINFECTION PRACTICES IN HOSPITAL.pptx
STERILIZATION AND DISINFECTION PRACTICES IN HOSPITAL.pptxSTERILIZATION AND DISINFECTION PRACTICES IN HOSPITAL.pptx
STERILIZATION AND DISINFECTION PRACTICES IN HOSPITAL.pptx
Ritikachoudhary69
 
GORDON'S 11 FUNCTIONAL PATTERN-Health Assessment.pptx
GORDON'S 11 FUNCTIONAL PATTERN-Health Assessment.pptxGORDON'S 11 FUNCTIONAL PATTERN-Health Assessment.pptx
GORDON'S 11 FUNCTIONAL PATTERN-Health Assessment.pptx
Rommel Luis III Israel
 
05 CLINICAL AUDIT-ORTHO done at a peripheral.pptx
05 CLINICAL AUDIT-ORTHO done at a peripheral.pptx05 CLINICAL AUDIT-ORTHO done at a peripheral.pptx
05 CLINICAL AUDIT-ORTHO done at a peripheral.pptx
Santhosh Raj
 
Medicard presentation for companies 2024
Medicard presentation for companies 2024Medicard presentation for companies 2024
Medicard presentation for companies 2024
FrancescaAlainaDeGuz
 
Sunscreens, IP-I, Dr. M.N.CHISHTI, Asst Prof. Dept of Pharmaceutics, YBCCPA
Sunscreens, IP-I, Dr. M.N.CHISHTI, Asst Prof. Dept of Pharmaceutics, YBCCPASunscreens, IP-I, Dr. M.N.CHISHTI, Asst Prof. Dept of Pharmaceutics, YBCCPA
Sunscreens, IP-I, Dr. M.N.CHISHTI, Asst Prof. Dept of Pharmaceutics, YBCCPA
ssuser555edf
 
Simple Steps to Make Her Choose You Every Day
Simple Steps to Make Her Choose You Every DaySimple Steps to Make Her Choose You Every Day
Simple Steps to Make Her Choose You Every Day
Lucas Smith
 
Hyderabad Call Girls 7023059433 High Profile Escorts Service Hyderabad
Hyderabad Call Girls 7023059433 High Profile Escorts Service HyderabadHyderabad Call Girls 7023059433 High Profile Escorts Service Hyderabad
Hyderabad Call Girls 7023059433 High Profile Escorts Service Hyderabad
garge6804
 
1比1制作(uofm毕业证书)美国密歇根大学毕业证学位证书原版一模一样
1比1制作(uofm毕业证书)美国密歇根大学毕业证学位证书原版一模一样1比1制作(uofm毕业证书)美国密歇根大学毕业证学位证书原版一模一样
1比1制作(uofm毕业证书)美国密歇根大学毕业证学位证书原版一模一样
5sj7jxf7
 
一比一原版布里斯托大学毕业证(Bristol毕业证书)学历如何办理
一比一原版布里斯托大学毕业证(Bristol毕业证书)学历如何办理一比一原版布里斯托大学毕业证(Bristol毕业证书)学历如何办理
一比一原版布里斯托大学毕业证(Bristol毕业证书)学历如何办理
obowu
 
HEALTH ASSESSMENT IN NURSING USING THE NURSING PROCESSpptx
HEALTH ASSESSMENT IN NURSING USING THE NURSING PROCESSpptxHEALTH ASSESSMENT IN NURSING USING THE NURSING PROCESSpptx
HEALTH ASSESSMENT IN NURSING USING THE NURSING PROCESSpptx
Rommel Luis III Israel
 
Health Tech Market Intelligence Prelim Questions -
Health Tech Market Intelligence Prelim Questions -Health Tech Market Intelligence Prelim Questions -
Health Tech Market Intelligence Prelim Questions -
Gokul Rangarajan
 

Recently uploaded (20)

Assessment of ear, Eye, Nose, and-Throat.pptx
Assessment of ear, Eye, Nose, and-Throat.pptxAssessment of ear, Eye, Nose, and-Throat.pptx
Assessment of ear, Eye, Nose, and-Throat.pptx
 
The crucial role of mathematics in ai development.pptx
The crucial role of mathematics in ai development.pptxThe crucial role of mathematics in ai development.pptx
The crucial role of mathematics in ai development.pptx
 
2024 Media Preferences of Older Adults: Consumer Survey and Marketing Implica...
2024 Media Preferences of Older Adults: Consumer Survey and Marketing Implica...2024 Media Preferences of Older Adults: Consumer Survey and Marketing Implica...
2024 Media Preferences of Older Adults: Consumer Survey and Marketing Implica...
 
Test bank advanced health assessment and differential diagnosis essentials fo...
Test bank advanced health assessment and differential diagnosis essentials fo...Test bank advanced health assessment and differential diagnosis essentials fo...
Test bank advanced health assessment and differential diagnosis essentials fo...
 
Psychological Safety as a Foundation for Improvement 12-06-24.pdf
Psychological Safety as a Foundation for Improvement 12-06-24.pdfPsychological Safety as a Foundation for Improvement 12-06-24.pdf
Psychological Safety as a Foundation for Improvement 12-06-24.pdf
 
Discover the Perfect Way to Relax - Malayali Kerala Spa Ajman
Discover the Perfect Way to Relax - Malayali Kerala Spa AjmanDiscover the Perfect Way to Relax - Malayali Kerala Spa Ajman
Discover the Perfect Way to Relax - Malayali Kerala Spa Ajman
 
𝔹hopal Call Girls 7023059433 High Profile Independent Escorts 𝔹hopal
𝔹hopal Call Girls 7023059433 High Profile Independent Escorts 𝔹hopal𝔹hopal Call Girls 7023059433 High Profile Independent Escorts 𝔹hopal
𝔹hopal Call Girls 7023059433 High Profile Independent Escorts 𝔹hopal
 
Faridkot ℂ𝕒𝕝𝕝 𝔾𝕚𝕣𝕝𝕤 7742996321 ℂ𝕒𝕝𝕝 𝔾𝕚𝕣𝕝𝕤 Faridkot
Faridkot ℂ𝕒𝕝𝕝 𝔾𝕚𝕣𝕝𝕤 7742996321 ℂ𝕒𝕝𝕝 𝔾𝕚𝕣𝕝𝕤 FaridkotFaridkot ℂ𝕒𝕝𝕝 𝔾𝕚𝕣𝕝𝕤 7742996321 ℂ𝕒𝕝𝕝 𝔾𝕚𝕣𝕝𝕤 Faridkot
Faridkot ℂ𝕒𝕝𝕝 𝔾𝕚𝕣𝕝𝕤 7742996321 ℂ𝕒𝕝𝕝 𝔾𝕚𝕣𝕝𝕤 Faridkot
 
THE SPECIAL SENCES- Unlocking the Wonders of the Special Senses: Sight, Sound...
THE SPECIAL SENCES- Unlocking the Wonders of the Special Senses: Sight, Sound...THE SPECIAL SENCES- Unlocking the Wonders of the Special Senses: Sight, Sound...
THE SPECIAL SENCES- Unlocking the Wonders of the Special Senses: Sight, Sound...
 
STERILIZATION AND DISINFECTION PRACTICES IN HOSPITAL.pptx
STERILIZATION AND DISINFECTION PRACTICES IN HOSPITAL.pptxSTERILIZATION AND DISINFECTION PRACTICES IN HOSPITAL.pptx
STERILIZATION AND DISINFECTION PRACTICES IN HOSPITAL.pptx
 
GORDON'S 11 FUNCTIONAL PATTERN-Health Assessment.pptx
GORDON'S 11 FUNCTIONAL PATTERN-Health Assessment.pptxGORDON'S 11 FUNCTIONAL PATTERN-Health Assessment.pptx
GORDON'S 11 FUNCTIONAL PATTERN-Health Assessment.pptx
 
05 CLINICAL AUDIT-ORTHO done at a peripheral.pptx
05 CLINICAL AUDIT-ORTHO done at a peripheral.pptx05 CLINICAL AUDIT-ORTHO done at a peripheral.pptx
05 CLINICAL AUDIT-ORTHO done at a peripheral.pptx
 
Medicard presentation for companies 2024
Medicard presentation for companies 2024Medicard presentation for companies 2024
Medicard presentation for companies 2024
 
Sunscreens, IP-I, Dr. M.N.CHISHTI, Asst Prof. Dept of Pharmaceutics, YBCCPA
Sunscreens, IP-I, Dr. M.N.CHISHTI, Asst Prof. Dept of Pharmaceutics, YBCCPASunscreens, IP-I, Dr. M.N.CHISHTI, Asst Prof. Dept of Pharmaceutics, YBCCPA
Sunscreens, IP-I, Dr. M.N.CHISHTI, Asst Prof. Dept of Pharmaceutics, YBCCPA
 
Simple Steps to Make Her Choose You Every Day
Simple Steps to Make Her Choose You Every DaySimple Steps to Make Her Choose You Every Day
Simple Steps to Make Her Choose You Every Day
 
Hyderabad Call Girls 7023059433 High Profile Escorts Service Hyderabad
Hyderabad Call Girls 7023059433 High Profile Escorts Service HyderabadHyderabad Call Girls 7023059433 High Profile Escorts Service Hyderabad
Hyderabad Call Girls 7023059433 High Profile Escorts Service Hyderabad
 
1比1制作(uofm毕业证书)美国密歇根大学毕业证学位证书原版一模一样
1比1制作(uofm毕业证书)美国密歇根大学毕业证学位证书原版一模一样1比1制作(uofm毕业证书)美国密歇根大学毕业证学位证书原版一模一样
1比1制作(uofm毕业证书)美国密歇根大学毕业证学位证书原版一模一样
 
一比一原版布里斯托大学毕业证(Bristol毕业证书)学历如何办理
一比一原版布里斯托大学毕业证(Bristol毕业证书)学历如何办理一比一原版布里斯托大学毕业证(Bristol毕业证书)学历如何办理
一比一原版布里斯托大学毕业证(Bristol毕业证书)学历如何办理
 
HEALTH ASSESSMENT IN NURSING USING THE NURSING PROCESSpptx
HEALTH ASSESSMENT IN NURSING USING THE NURSING PROCESSpptxHEALTH ASSESSMENT IN NURSING USING THE NURSING PROCESSpptx
HEALTH ASSESSMENT IN NURSING USING THE NURSING PROCESSpptx
 
Health Tech Market Intelligence Prelim Questions -
Health Tech Market Intelligence Prelim Questions -Health Tech Market Intelligence Prelim Questions -
Health Tech Market Intelligence Prelim Questions -
 

Risk and Credentials based Access Control

  • 1. RISK-AWARE INTEGRITY MANAGEMENT FRAMEWORK FOR DISTRIBUTED HEALTHCARE SYSTEMS Aastha Madaan Research Fellow, WSL, IIIT-B ※ Research work done as a part of Work Package – 3 of the TRUMP Project [2] Collaborative Healthcare Setup Appointments/ Patient information Pathology Results Treatment/Procedures/ Problem Lists Nursing Notes EHR
  • 2. TRUMP: REQUIREMENTS o Collaborating & Heterogeneous Care providers and receivers 2  Self-Intervention for Chronic Illnesses Multi-agency Care Disjoint/distributed agencies Limited Resources CHALLENGES o Unit of Exchange of Health Information  EHRs  TRUMP Unit Subjective UtilityBounded Validity Interrelated Utility Divergent Aggregation
  • 3. TRUMP UNIT Attributes RecordId PName Age Sex Version_id Data Imported Worlds and Participation Organization Treatment Person Person …… … Primary care Provider Therapy Physician Specialist …… … DISTRIBUTED KNOWLEDGE REPRESENTATION FRAMEWORK 3 • Many Worlds on a Frame (MWF) Knowledge Representation framework proposed in [3], [5] EHR UoD Schema
  • 4. AN EXAMPLE (1) * Screenshots Source: MTech Students - TRUMP Project
  • 10. RISK-AWARE INTEGRITY MANAGEMENT  Integrating “Trust” and “Risk” measures with earlier proposed Credentials based Access Control (CBAC) [4]  Flexible, bottom-up approach  Associate policies based on user credentials  Define Risk and Trust Measures
  • 11. INTEGRATING TRAAC AND CBAC (1)  Access control  Agnostic to actual end-users  Zoned Policy Model [TRAAC]  Zoned Privilege Packages 11 share deny readu reads undefined o Type of Requests  Read & Share o Data Object Policy  Zones assigned o Risk  Request & Trust  Requestor o Types of Trust  Obligation & Sharing Hospital X Department of Health Health-care Providers Association Role: Heart Specialist Role: Secretary Role: President
  • 12. 12  TRAAC approach  Misses CONTEXT during Trust Update  E.g in Which context was the particular violation made  TRAAC+ CBAC  MWF captures the context of a given interaction  Visibility of Policies  Critical to avoid unintentional violation  TRAAC+CBAC  Policy viewed as a Data Element  Credentials of a user  participation set  Credentials  Privilege Package  View applicable policies  Update of Sharing and Obligation based Trust  Assignment of Sensitivity Category  Information INTEGRATING TRAAC AND CBAC (2)
  • 13. ASSOCIATING TRUST  Trust  Probability with which a Privilege Package is entrusted to a world  Privilege package  Assertion1, Assertion2, Assertion3,…., Assertionn  Assertion  Set of role(Type, Location)  Trust value  Aggregation of trust values associated with each role in a the user’s participation set  Trust across system elements  User trust in system  Privacy of Information  System trust in users  Authenticated information  Trust between users  History of Events  Evaluating trust  Risk Mitigation Strategy  Obligations to be performed in a given domain  Sharing Trust & Obligation Trust 13
  • 14. ASSOCIATING RISK  Risk  Probability with which a data-access is granted to a World with a Stakeholder with a Privilege Package, P  Assign  Sensitivity category to  Worlds  Calculate  Loss sustained due to access  Undesirable Events  Fake credentials of a user Illegitimate access made by user  Risk Score = Loss * Probability of Undesirable Events  Risk Domain  Type and Location of a World  Risk Mitigation Strategy ? 14 Allow Deny Access based On Risk
  • 15. CONCERNS  Emergency Access  Bypassing Access Rules  Patient  Owner of data or subject of data  Modelling stakeholder as a data element answer this?  Complex Information Flows  Involve Delegation  Responsibility  Update Trust 15  Quantification of Risk and Trust  Revocation of Privilege Packages  Boundary conditions Risk & Trust  Risk Mitigation Strategies and Obligation  Trust Delegation  Visualization of Risk  Access granted to a stakeholder
  • 16. REFERENCES 1. Burnett, C., Chen, L., Norman, T.~J. and Edwards, P. (2014). TRAAC: Trust and Risk Aware Access Control. Proceedings of the 12th Annual Conference on Privacy, Security and Trust (PST2014), Toronto, Canada. 2. Burnett, C., Edwards, P., Norman, T. J., Chen, L., Rahulamathavan, Y., Jaffray, M., & Pignotti, E. (2013). TRUMP: A Trusted Mobile Platform for Self-management of Chronic Illness in Rural Areas. In Trust and Trustworthy Computing (pp. 142-150). Springer Berlin Heidelberg. 3. Chinmay Jog, Sweety Agrawal, Srinath Srinivasa. Distributing a Trust Framework for Utilitarian Data Exchanges in Inter-Organizational Collaborations. Proceedings of the Second ACM iKDD Conference on Data Sciences (CoDS 2015), March 2015, Bangalore, India. 4. Sweety Agrawal, Chinmay Jog, Srinath Srinivasa. Integrity Management in a Trusted Utilitarian Data Exchange Platform. Proceedings of the 13th International Conference on Ontologies, Databases and Applications of Semantics (ODBASE 2014), Amantea, Italy, October 2014. 5. Srinath Srinivasa, Sweety Agrawal, Chinmay Jog and Jayati Deshmukh. Characterizing Open Utilitarian Knowledge. Proceedings of the First IKDD Conference on Data Sciences (CoDS 2014), New Delhi, India, March 2014. 16