Skip to main navigation Skip to search Skip to main content

A Case Study in Access Control Requirements for a Health Information System

  • MP Evered
  • , SF Bogeholz

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

We present a detailed examination of the access constraints for a small real-world Health Information System with the aim of achieving minimal access rights for each of the involved principals. We show that, even for such a relatively simple system, the resulting constraints are very complex and cannot be expressed easily or clearly using the static per-method access control lists generally supported by component-based software. We derive general requirements for the expressiveness of access constraints and propose criteria for a more suitable access control mechanism in the context of component-based systems. We describe a two-level mechanism which can fulfil these criteria.
Original languageEnglish
Title of host publicationProceedings of the Second Australasian Information Security Workshop (AISW2004) - Conferences in Research and Practice in Information Technology, Vol. 32
Editors Hogan, J, Montague, P, Purvis, M, Steketee, C
Place of PublicationDunedin, New Zealand
PublisherAustralian Computer Society (ACS)
Pages53-61
ISBN (Print)1920682147
Publication statusPublished - 2004
EventAISW 2004: Second Australasian Information Security Workshop - Dunedin, New Zealand
Duration: 31 Jan 2004 → …

Conference

ConferenceAISW 2004: Second Australasian Information Security Workshop
CityDunedin, New Zealand
Period31/01/04 → …

Keywords

  • Computer Software

Fingerprint

Dive into the research topics of 'A Case Study in Access Control Requirements for a Health Information System'. Together they form a unique fingerprint.

Cite this