通信学报 ›› 2015, Vol. 36 ›› Issue (12): 190-199.doi: 10.11959/j.issn.1000-436x.2015328

• 数据安全 • 上一篇    下一篇

面向医疗大数据的风险自适应的访问控制模型

惠榛,李昊,张敏,冯登国   

  1. 中国科学院 软件研究所,北京 100080
  • 出版日期:2015-12-25 发布日期:2017-07-17
  • 基金资助:
    国家自然科学基金资助项目

Risk-adaptive access control model for big data in healthcare

Zhen HUI,Hao LI,Min ZHANG,Deng-guo FENG   

  1. Institute of Software,Chinese Academy of Sciences,Beijing 100080,China
  • Online:2015-12-25 Published:2017-07-17
  • Supported by:
    The National Natural Science Foundation of China

摘要:

面对医疗大数据,策略制定者难以预测医生的访问需求,进而制定准确的访问控制策略。针对上述问题,提出一种基于风险的访问控制模型,能够适应性地调整医生的访问能力,保护患者隐私。该模型通过分析医生的访问历史,使用信息熵和EM算法量化医生侵犯隐私造成的风险。利用量化的风险,监测和控制对于医疗记录的过度访问以及特殊情况下的访问请求。实验结果表明,该模型是有效的,并且相比于其他模型能更为准确地进行访问控制。

关键词: 风险访问控制, 大数据, 隐私, 自适应

Abstract:

While dealing with the big data in healthcare,it was difficult for a policy maker to foresee what information a doctor may need,even to make an accurate access control policy.To deal with it,a risk-based access control model that regulates doctors’ access rights adaptively was proposed to protect patient privacy.This model analyzed the history of access,applies the EM algorithm and the information entropy technique to quantify the risk of privacy violation.Using the quantified risk,the model can detect and control the over-accessing and exceptional accessing of patients’ data.Experimental results show that this model is effective and more accurate than other models.

Key words: risk-based access control, big data, privacy, adaptive

No Suggested Reading articles found!