Abstract
We present a detailed examination of the access constraints for a small real-world Health Information System with the aim of achieving minimal access rights for each of the involved principals. We show that, even for such a relatively simple system, the resulting constraints are very complex and cannot be expressed easily or clearly using the static per-method access control lists generally supported by component-based software. We derive general requirements for the expressiveness of access constraints and propose criteria for a more suitable access control mechanism in the context of component-based systems. We describe a two-level mechanism which can fulfil these criteria.
| Original language | English |
|---|---|
| Title of host publication | Proceedings of the Second Australasian Information Security Workshop (AISW2004) - Conferences in Research and Practice in Information Technology, Vol. 32 |
| Editors | Hogan, J, Montague, P, Purvis, M, Steketee, C |
| Place of Publication | Dunedin, New Zealand |
| Publisher | Australian Computer Society (ACS) |
| Pages | 53-61 |
| ISBN (Print) | 1920682147 |
| Publication status | Published - 2004 |
| Event | AISW 2004: Second Australasian Information Security Workshop - Dunedin, New Zealand Duration: 31 Jan 2004 → … |
Conference
| Conference | AISW 2004: Second Australasian Information Security Workshop |
|---|---|
| City | Dunedin, New Zealand |
| Period | 31/01/04 → … |
Keywords
- Computer Software
Fingerprint
Dive into the research topics of 'A Case Study in Access Control Requirements for a Health Information System'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver