SlideShare ist ein Scribd-Unternehmen logo
1 von 16
RISK-AWARE INTEGRITY MANAGEMENT FRAMEWORK
FOR DISTRIBUTED HEALTHCARE SYSTEMS
Aastha Madaan
Research Fellow, WSL, IIIT-B
※ Research work done as a part of Work Package – 3 of the TRUMP Project [2]
Collaborative Healthcare Setup
Appointments/
Patient information
Pathology
Results
Treatment/Procedures/
Problem Lists
Nursing
Notes
EHR
TRUMP: REQUIREMENTS
o Collaborating & Heterogeneous Care
providers and receivers
2
 Self-Intervention for Chronic Illnesses
Multi-agency Care
Disjoint/distributed
agencies
Limited Resources
CHALLENGES
o Unit of Exchange of Health Information  EHRs  TRUMP Unit
Subjective
UtilityBounded
Validity
Interrelated
Utility
Divergent
Aggregation
TRUMP UNIT
Attributes
RecordId PName Age Sex Version_id
Data
Imported Worlds and Participation
Organization Treatment Person Person ……
…
Primary care
Provider
Therapy Physician Specialist ……
…
DISTRIBUTED KNOWLEDGE REPRESENTATION
FRAMEWORK
3
• Many Worlds on a Frame (MWF) Knowledge Representation framework proposed in [3], [5]
EHR UoD
Schema
AN EXAMPLE (1)
* Screenshots Source: MTech Students - TRUMP Project
AN EXAMPLE (2)
5
AN EXAMPLE (3)
6
AN EXAMPLE (4)
7
AN EXAMPLE (5)
8
AN EXAMPLE (6)
9
RISK-AWARE INTEGRITY MANAGEMENT
 Integrating “Trust” and “Risk” measures with earlier proposed
Credentials based Access Control (CBAC) [4]
 Flexible, bottom-up approach
 Associate policies based on user credentials
 Define Risk and Trust Measures
INTEGRATING TRAAC AND CBAC (1)
 Access control  Agnostic to actual end-users
 Zoned Policy Model [TRAAC]  Zoned Privilege Packages
11
share
deny
readu
reads
undefined
o Type of Requests  Read & Share
o Data Object Policy  Zones assigned
o Risk  Request & Trust  Requestor
o Types of Trust  Obligation & Sharing
Hospital X
Department
of Health
Health-care
Providers
Association
Role: Heart Specialist
Role: Secretary
Role: President
12
 TRAAC approach  Misses CONTEXT during Trust Update
 E.g in Which context was the particular violation made
 TRAAC+ CBAC  MWF captures the context of a given interaction
 Visibility of Policies  Critical to avoid unintentional violation
 TRAAC+CBAC  Policy viewed as a Data Element
 Credentials of a user  participation set
 Credentials  Privilege Package  View applicable policies
 Update of Sharing and Obligation based Trust
 Assignment of Sensitivity Category  Information
INTEGRATING TRAAC AND CBAC (2)
ASSOCIATING TRUST
 Trust  Probability with which a Privilege Package is entrusted to a world
 Privilege package  Assertion1, Assertion2, Assertion3,…., Assertionn
 Assertion  Set of role(Type, Location)
 Trust value  Aggregation of trust values associated with each role in a the
user’s participation set
 Trust across system elements
 User trust in system  Privacy of Information
 System trust in users  Authenticated information
 Trust between users  History of Events
 Evaluating trust  Risk Mitigation Strategy  Obligations to be performed in
a given domain
 Sharing Trust & Obligation Trust 13
ASSOCIATING RISK
 Risk  Probability with which a data-access is granted to a World
with a Stakeholder with a Privilege Package, P
 Assign  Sensitivity category to  Worlds
 Calculate  Loss sustained due to access
 Undesirable Events  Fake credentials of a user
Illegitimate access made by user
 Risk Score = Loss * Probability of Undesirable Events
 Risk Domain  Type and Location of a World
 Risk Mitigation Strategy ?
14
Allow
Deny
Access based
On Risk
CONCERNS
 Emergency Access  Bypassing Access Rules
 Patient  Owner of data or subject of data
 Modelling stakeholder as a data element answer this?
 Complex Information Flows  Involve Delegation
 Responsibility
 Update Trust
15
 Quantification of Risk and Trust
 Revocation of Privilege Packages  Boundary conditions
Risk & Trust
 Risk Mitigation Strategies and Obligation  Trust Delegation
 Visualization of Risk  Access granted to a stakeholder
REFERENCES
1. Burnett, C., Chen, L., Norman, T.~J. and Edwards, P. (2014). TRAAC: Trust and Risk Aware
Access Control. Proceedings of the 12th Annual Conference on Privacy, Security and Trust
(PST2014), Toronto, Canada.
2. Burnett, C., Edwards, P., Norman, T. J., Chen, L., Rahulamathavan, Y., Jaffray, M., & Pignotti,
E. (2013). TRUMP: A Trusted Mobile Platform for Self-management of Chronic Illness in
Rural Areas. In Trust and Trustworthy Computing (pp. 142-150). Springer Berlin Heidelberg.
3. Chinmay Jog, Sweety Agrawal, Srinath Srinivasa. Distributing a Trust Framework for
Utilitarian Data Exchanges in Inter-Organizational Collaborations. Proceedings of the Second
ACM iKDD Conference on Data Sciences (CoDS 2015), March 2015, Bangalore, India.
4. Sweety Agrawal, Chinmay Jog, Srinath Srinivasa. Integrity Management in a Trusted
Utilitarian Data Exchange Platform. Proceedings of the 13th International Conference on
Ontologies, Databases and Applications of Semantics (ODBASE 2014), Amantea, Italy,
October 2014.
5. Srinath Srinivasa, Sweety Agrawal, Chinmay Jog and Jayati Deshmukh. Characterizing Open
Utilitarian Knowledge. Proceedings of the First IKDD Conference on Data Sciences (CoDS
2014), New Delhi, India, March 2014.
16

Weitere ähnliche Inhalte

Andere mochten auch

Andere mochten auch (6)

Trabajo de deporte actividad 3.1
Trabajo de deporte   actividad 3.1Trabajo de deporte   actividad 3.1
Trabajo de deporte actividad 3.1
 
Deporte en Boyacá
Deporte en BoyacáDeporte en Boyacá
Deporte en Boyacá
 
cumpleaños normal florencia
cumpleaños normal florenciacumpleaños normal florencia
cumpleaños normal florencia
 
Xiomara .
Xiomara .Xiomara .
Xiomara .
 
Constanza roura
Constanza rouraConstanza roura
Constanza roura
 
Deber exame 1
Deber exame 1Deber exame 1
Deber exame 1
 

Ähnlich wie Risk and Credentials based Access Control

Provider Aware Anonymization Algorithm for Preserving M - Privacy
Provider Aware Anonymization Algorithm for Preserving M - PrivacyProvider Aware Anonymization Algorithm for Preserving M - Privacy
Provider Aware Anonymization Algorithm for Preserving M - PrivacyIJERA Editor
 
IRJET - Blockchain for Medical Data Access and Permission Management
IRJET - Blockchain for Medical Data Access and Permission ManagementIRJET - Blockchain for Medical Data Access and Permission Management
IRJET - Blockchain for Medical Data Access and Permission ManagementIRJET Journal
 
Information Security using Cryptography and Image Processing
Information Security using Cryptography and Image ProcessingInformation Security using Cryptography and Image Processing
Information Security using Cryptography and Image Processingijsrd.com
 
A review on anonymization techniques for privacy preserving data publishing
A review on anonymization techniques for privacy preserving data publishingA review on anonymization techniques for privacy preserving data publishing
A review on anonymization techniques for privacy preserving data publishingeSAT Journals
 
Possible Solution for Managing the Worlds Personal Genetic Data - DNA Guide, ...
Possible Solution for Managing the Worlds Personal Genetic Data - DNA Guide, ...Possible Solution for Managing the Worlds Personal Genetic Data - DNA Guide, ...
Possible Solution for Managing the Worlds Personal Genetic Data - DNA Guide, ...DNA Compass
 
Ijarcet vol-2-issue-4-1393-1397
Ijarcet vol-2-issue-4-1393-1397Ijarcet vol-2-issue-4-1393-1397
Ijarcet vol-2-issue-4-1393-1397Editor IJARCET
 
m-Privacy for Collaborative Data Publishing
m-Privacy for Collaborative Data Publishingm-Privacy for Collaborative Data Publishing
m-Privacy for Collaborative Data PublishingMigrant Systems
 
An Empirical Study on Mushroom Disease Diagnosis:A Data Mining Approach
An Empirical Study on Mushroom Disease Diagnosis:A Data Mining ApproachAn Empirical Study on Mushroom Disease Diagnosis:A Data Mining Approach
An Empirical Study on Mushroom Disease Diagnosis:A Data Mining ApproachIRJET Journal
 
Predicting disease from several symptoms using machine learning approach.
Predicting disease from several symptoms using machine learning approach.Predicting disease from several symptoms using machine learning approach.
Predicting disease from several symptoms using machine learning approach.IRJET Journal
 
Survey on Medical Data Sharing Systems with NTRU
Survey on Medical Data Sharing Systems with NTRUSurvey on Medical Data Sharing Systems with NTRU
Survey on Medical Data Sharing Systems with NTRUIRJET Journal
 
DEADLINE FRIDAY 492021 BY 0800 PM ESTINSTRUCTIONS Res
DEADLINE FRIDAY 492021 BY 0800 PM ESTINSTRUCTIONS ResDEADLINE FRIDAY 492021 BY 0800 PM ESTINSTRUCTIONS Res
DEADLINE FRIDAY 492021 BY 0800 PM ESTINSTRUCTIONS ResLinaCovington707
 
Framework architecture for improving
Framework architecture for improvingFramework architecture for improving
Framework architecture for improvingIJMIT JOURNAL
 
Jennifer DiscussionThe use of electronic health records (EHR) i.docx
Jennifer DiscussionThe use of electronic health records (EHR) i.docxJennifer DiscussionThe use of electronic health records (EHR) i.docx
Jennifer DiscussionThe use of electronic health records (EHR) i.docxLaticiaGrissomzz
 
Paper id 37201535
Paper id 37201535Paper id 37201535
Paper id 37201535IJRAT
 
Framework Architecture for Improving Healthcare Information Systems using Age...
Framework Architecture for Improving Healthcare Information Systems using Age...Framework Architecture for Improving Healthcare Information Systems using Age...
Framework Architecture for Improving Healthcare Information Systems using Age...IJMIT JOURNAL
 
The Case Study of an Early Warning Models for the Telecare Patients in Taiwan
The Case Study of an Early Warning Models for the Telecare Patients in TaiwanThe Case Study of an Early Warning Models for the Telecare Patients in Taiwan
The Case Study of an Early Warning Models for the Telecare Patients in TaiwanIJERA Editor
 
Andrew Roberts - Mobile Health Apps for Improved Patient Engagement and Educa...
Andrew Roberts - Mobile Health Apps for Improved Patient Engagement and Educa...Andrew Roberts - Mobile Health Apps for Improved Patient Engagement and Educa...
Andrew Roberts - Mobile Health Apps for Improved Patient Engagement and Educa...itnewsafrica
 
Ijricit 01-005 pscsv - patient self-driven multi-stage confidentiality safegu...
Ijricit 01-005 pscsv - patient self-driven multi-stage confidentiality safegu...Ijricit 01-005 pscsv - patient self-driven multi-stage confidentiality safegu...
Ijricit 01-005 pscsv - patient self-driven multi-stage confidentiality safegu...Ijripublishers Ijri
 
Implementing The Affordable Care Act Essay
Implementing The Affordable Care Act EssayImplementing The Affordable Care Act Essay
Implementing The Affordable Care Act EssayMichelle Love
 

Ähnlich wie Risk and Credentials based Access Control (20)

Provider Aware Anonymization Algorithm for Preserving M - Privacy
Provider Aware Anonymization Algorithm for Preserving M - PrivacyProvider Aware Anonymization Algorithm for Preserving M - Privacy
Provider Aware Anonymization Algorithm for Preserving M - Privacy
 
IRJET - Blockchain for Medical Data Access and Permission Management
IRJET - Blockchain for Medical Data Access and Permission ManagementIRJET - Blockchain for Medical Data Access and Permission Management
IRJET - Blockchain for Medical Data Access and Permission Management
 
Information Security using Cryptography and Image Processing
Information Security using Cryptography and Image ProcessingInformation Security using Cryptography and Image Processing
Information Security using Cryptography and Image Processing
 
A review on anonymization techniques for privacy preserving data publishing
A review on anonymization techniques for privacy preserving data publishingA review on anonymization techniques for privacy preserving data publishing
A review on anonymization techniques for privacy preserving data publishing
 
Possible Solution for Managing the Worlds Personal Genetic Data - DNA Guide, ...
Possible Solution for Managing the Worlds Personal Genetic Data - DNA Guide, ...Possible Solution for Managing the Worlds Personal Genetic Data - DNA Guide, ...
Possible Solution for Managing the Worlds Personal Genetic Data - DNA Guide, ...
 
Ijarcet vol-2-issue-4-1393-1397
Ijarcet vol-2-issue-4-1393-1397Ijarcet vol-2-issue-4-1393-1397
Ijarcet vol-2-issue-4-1393-1397
 
m-Privacy for Collaborative Data Publishing
m-Privacy for Collaborative Data Publishingm-Privacy for Collaborative Data Publishing
m-Privacy for Collaborative Data Publishing
 
Cp34550555
Cp34550555Cp34550555
Cp34550555
 
An Empirical Study on Mushroom Disease Diagnosis:A Data Mining Approach
An Empirical Study on Mushroom Disease Diagnosis:A Data Mining ApproachAn Empirical Study on Mushroom Disease Diagnosis:A Data Mining Approach
An Empirical Study on Mushroom Disease Diagnosis:A Data Mining Approach
 
Predicting disease from several symptoms using machine learning approach.
Predicting disease from several symptoms using machine learning approach.Predicting disease from several symptoms using machine learning approach.
Predicting disease from several symptoms using machine learning approach.
 
Survey on Medical Data Sharing Systems with NTRU
Survey on Medical Data Sharing Systems with NTRUSurvey on Medical Data Sharing Systems with NTRU
Survey on Medical Data Sharing Systems with NTRU
 
DEADLINE FRIDAY 492021 BY 0800 PM ESTINSTRUCTIONS Res
DEADLINE FRIDAY 492021 BY 0800 PM ESTINSTRUCTIONS ResDEADLINE FRIDAY 492021 BY 0800 PM ESTINSTRUCTIONS Res
DEADLINE FRIDAY 492021 BY 0800 PM ESTINSTRUCTIONS Res
 
Framework architecture for improving
Framework architecture for improvingFramework architecture for improving
Framework architecture for improving
 
Jennifer DiscussionThe use of electronic health records (EHR) i.docx
Jennifer DiscussionThe use of electronic health records (EHR) i.docxJennifer DiscussionThe use of electronic health records (EHR) i.docx
Jennifer DiscussionThe use of electronic health records (EHR) i.docx
 
Paper id 37201535
Paper id 37201535Paper id 37201535
Paper id 37201535
 
Framework Architecture for Improving Healthcare Information Systems using Age...
Framework Architecture for Improving Healthcare Information Systems using Age...Framework Architecture for Improving Healthcare Information Systems using Age...
Framework Architecture for Improving Healthcare Information Systems using Age...
 
The Case Study of an Early Warning Models for the Telecare Patients in Taiwan
The Case Study of an Early Warning Models for the Telecare Patients in TaiwanThe Case Study of an Early Warning Models for the Telecare Patients in Taiwan
The Case Study of an Early Warning Models for the Telecare Patients in Taiwan
 
Andrew Roberts - Mobile Health Apps for Improved Patient Engagement and Educa...
Andrew Roberts - Mobile Health Apps for Improved Patient Engagement and Educa...Andrew Roberts - Mobile Health Apps for Improved Patient Engagement and Educa...
Andrew Roberts - Mobile Health Apps for Improved Patient Engagement and Educa...
 
Ijricit 01-005 pscsv - patient self-driven multi-stage confidentiality safegu...
Ijricit 01-005 pscsv - patient self-driven multi-stage confidentiality safegu...Ijricit 01-005 pscsv - patient self-driven multi-stage confidentiality safegu...
Ijricit 01-005 pscsv - patient self-driven multi-stage confidentiality safegu...
 
Implementing The Affordable Care Act Essay
Implementing The Affordable Care Act EssayImplementing The Affordable Care Act Essay
Implementing The Affordable Care Act Essay
 

Mehr von Aastha Madaan

Components of openEHR based EHRs
Components of openEHR based EHRsComponents of openEHR based EHRs
Components of openEHR based EHRsAastha Madaan
 
Promise of web science
Promise of web sciencePromise of web science
Promise of web scienceAastha Madaan
 
Web Page Segmentation for Querying Healthcare Repository
Web Page Segmentation for Querying Healthcare RepositoryWeb Page Segmentation for Querying Healthcare Repository
Web Page Segmentation for Querying Healthcare RepositoryAastha Madaan
 
Domain-specific Multi-stage Query Language for Medical Document Repositories
Domain-specific Multi-stage Query Language for Medical Document RepositoriesDomain-specific Multi-stage Query Language for Medical Document Repositories
Domain-specific Multi-stage Query Language for Medical Document RepositoriesAastha Madaan
 
A Quasi Relational Query Language for Persistent Standardized EHRs: Using NoS...
A Quasi Relational Query Language for Persistent Standardized EHRs: Using NoS...A Quasi Relational Query Language for Persistent Standardized EHRs: Using NoS...
A Quasi Relational Query Language for Persistent Standardized EHRs: Using NoS...Aastha Madaan
 

Mehr von Aastha Madaan (7)

Components of openEHR based EHRs
Components of openEHR based EHRsComponents of openEHR based EHRs
Components of openEHR based EHRs
 
Promise of web science
Promise of web sciencePromise of web science
Promise of web science
 
Web Page Segmentation for Querying Healthcare Repository
Web Page Segmentation for Querying Healthcare RepositoryWeb Page Segmentation for Querying Healthcare Repository
Web Page Segmentation for Querying Healthcare Repository
 
Domain-specific Multi-stage Query Language for Medical Document Repositories
Domain-specific Multi-stage Query Language for Medical Document RepositoriesDomain-specific Multi-stage Query Language for Medical Document Repositories
Domain-specific Multi-stage Query Language for Medical Document Repositories
 
A Quasi Relational Query Language for Persistent Standardized EHRs: Using NoS...
A Quasi Relational Query Language for Persistent Standardized EHRs: Using NoS...A Quasi Relational Query Language for Persistent Standardized EHRs: Using NoS...
A Quasi Relational Query Language for Persistent Standardized EHRs: Using NoS...
 
Observlets
Observlets Observlets
Observlets
 
IoT Observatory
IoT ObservatoryIoT Observatory
IoT Observatory
 

Kürzlich hochgeladen

VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near MeVIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Memriyagarg453
 
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF ...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF  ...❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF  ...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF ...Gfnyt.com
 
❤️♀️@ Jaipur Call Girls ❤️♀️@ Meghna Jaipur Call Girls Number CRTHNR Call G...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Meghna Jaipur Call Girls Number CRTHNR   Call G...❤️♀️@ Jaipur Call Girls ❤️♀️@ Meghna Jaipur Call Girls Number CRTHNR   Call G...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Meghna Jaipur Call Girls Number CRTHNR Call G...Gfnyt.com
 
Krishnagiri call girls Tamil aunty 7877702510
Krishnagiri call girls Tamil aunty 7877702510Krishnagiri call girls Tamil aunty 7877702510
Krishnagiri call girls Tamil aunty 7877702510Vipesco
 
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591adityaroy0215
 
(Ajay) Call Girls in Dehradun- 8854095900 Escorts Service 50% Off with Cash O...
(Ajay) Call Girls in Dehradun- 8854095900 Escorts Service 50% Off with Cash O...(Ajay) Call Girls in Dehradun- 8854095900 Escorts Service 50% Off with Cash O...
(Ajay) Call Girls in Dehradun- 8854095900 Escorts Service 50% Off with Cash O...indiancallgirl4rent
 
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetbhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
Call Girls Service In Goa 💋 9316020077💋 Goa Call Girls By Russian Call Girl...
Call Girls Service In Goa  💋 9316020077💋 Goa Call Girls  By Russian Call Girl...Call Girls Service In Goa  💋 9316020077💋 Goa Call Girls  By Russian Call Girl...
Call Girls Service In Goa 💋 9316020077💋 Goa Call Girls By Russian Call Girl...russian goa call girl and escorts service
 
Tirupati Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Tirupati Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetTirupati Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Tirupati Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real MeetChandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meetpriyashah722354
 
Russian Call Girls in Noida Pallavi 9711199171 High Class Call Girl Near Me
Russian Call Girls in Noida Pallavi 9711199171 High Class Call Girl Near MeRussian Call Girls in Noida Pallavi 9711199171 High Class Call Girl Near Me
Russian Call Girls in Noida Pallavi 9711199171 High Class Call Girl Near Memriyagarg453
 
VIP Call Girl Sector 32 Noida Just Book Me 9711199171
VIP Call Girl Sector 32 Noida Just Book Me 9711199171VIP Call Girl Sector 32 Noida Just Book Me 9711199171
VIP Call Girl Sector 32 Noida Just Book Me 9711199171Call Girls Service Gurgaon
 
VIP Call Girl Sector 10 Noida Call Me: 9711199171
VIP Call Girl Sector 10 Noida Call Me: 9711199171VIP Call Girl Sector 10 Noida Call Me: 9711199171
VIP Call Girl Sector 10 Noida Call Me: 9711199171Call Girls Service Gurgaon
 
Sambalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Sambalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetSambalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Sambalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
Russian Call Girls Kota * 8250192130 Service starts from just ₹9999 ✅
Russian Call Girls Kota * 8250192130 Service starts from just ₹9999 ✅Russian Call Girls Kota * 8250192130 Service starts from just ₹9999 ✅
Russian Call Girls Kota * 8250192130 Service starts from just ₹9999 ✅gragmanisha42
 
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.ktanvi103
 
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...Ahmedabad Call Girls
 
Call Girls Patiala Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Patiala Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Patiala Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Patiala Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 

Kürzlich hochgeladen (20)

VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near MeVIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
 
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
 
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF ...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF  ...❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF  ...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF ...
 
❤️♀️@ Jaipur Call Girls ❤️♀️@ Meghna Jaipur Call Girls Number CRTHNR Call G...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Meghna Jaipur Call Girls Number CRTHNR   Call G...❤️♀️@ Jaipur Call Girls ❤️♀️@ Meghna Jaipur Call Girls Number CRTHNR   Call G...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Meghna Jaipur Call Girls Number CRTHNR Call G...
 
Krishnagiri call girls Tamil aunty 7877702510
Krishnagiri call girls Tamil aunty 7877702510Krishnagiri call girls Tamil aunty 7877702510
Krishnagiri call girls Tamil aunty 7877702510
 
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
 
(Ajay) Call Girls in Dehradun- 8854095900 Escorts Service 50% Off with Cash O...
(Ajay) Call Girls in Dehradun- 8854095900 Escorts Service 50% Off with Cash O...(Ajay) Call Girls in Dehradun- 8854095900 Escorts Service 50% Off with Cash O...
(Ajay) Call Girls in Dehradun- 8854095900 Escorts Service 50% Off with Cash O...
 
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetbhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Call Girls Service In Goa 💋 9316020077💋 Goa Call Girls By Russian Call Girl...
Call Girls Service In Goa  💋 9316020077💋 Goa Call Girls  By Russian Call Girl...Call Girls Service In Goa  💋 9316020077💋 Goa Call Girls  By Russian Call Girl...
Call Girls Service In Goa 💋 9316020077💋 Goa Call Girls By Russian Call Girl...
 
Tirupati Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Tirupati Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetTirupati Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Tirupati Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real MeetChandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
Chandigarh Call Girls 👙 7001035870 👙 Genuine WhatsApp Number for Real Meet
 
Russian Call Girls in Noida Pallavi 9711199171 High Class Call Girl Near Me
Russian Call Girls in Noida Pallavi 9711199171 High Class Call Girl Near MeRussian Call Girls in Noida Pallavi 9711199171 High Class Call Girl Near Me
Russian Call Girls in Noida Pallavi 9711199171 High Class Call Girl Near Me
 
VIP Call Girl Sector 32 Noida Just Book Me 9711199171
VIP Call Girl Sector 32 Noida Just Book Me 9711199171VIP Call Girl Sector 32 Noida Just Book Me 9711199171
VIP Call Girl Sector 32 Noida Just Book Me 9711199171
 
VIP Call Girl Sector 10 Noida Call Me: 9711199171
VIP Call Girl Sector 10 Noida Call Me: 9711199171VIP Call Girl Sector 10 Noida Call Me: 9711199171
VIP Call Girl Sector 10 Noida Call Me: 9711199171
 
Sambalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Sambalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetSambalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Sambalpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Russian Call Girls Kota * 8250192130 Service starts from just ₹9999 ✅
Russian Call Girls Kota * 8250192130 Service starts from just ₹9999 ✅Russian Call Girls Kota * 8250192130 Service starts from just ₹9999 ✅
Russian Call Girls Kota * 8250192130 Service starts from just ₹9999 ✅
 
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
Call Now ☎ 9999965857 !! Call Girls in Hauz Khas Escort Service Delhi N.C.R.
 
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...
 
Call Girls Patiala Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Patiala Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Patiala Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Patiala Just Call 9907093804 Top Class Call Girl Service Available
 

Risk and Credentials based Access Control

  • 1. RISK-AWARE INTEGRITY MANAGEMENT FRAMEWORK FOR DISTRIBUTED HEALTHCARE SYSTEMS Aastha Madaan Research Fellow, WSL, IIIT-B ※ Research work done as a part of Work Package – 3 of the TRUMP Project [2] Collaborative Healthcare Setup Appointments/ Patient information Pathology Results Treatment/Procedures/ Problem Lists Nursing Notes EHR
  • 2. TRUMP: REQUIREMENTS o Collaborating & Heterogeneous Care providers and receivers 2  Self-Intervention for Chronic Illnesses Multi-agency Care Disjoint/distributed agencies Limited Resources CHALLENGES o Unit of Exchange of Health Information  EHRs  TRUMP Unit Subjective UtilityBounded Validity Interrelated Utility Divergent Aggregation
  • 3. TRUMP UNIT Attributes RecordId PName Age Sex Version_id Data Imported Worlds and Participation Organization Treatment Person Person …… … Primary care Provider Therapy Physician Specialist …… … DISTRIBUTED KNOWLEDGE REPRESENTATION FRAMEWORK 3 • Many Worlds on a Frame (MWF) Knowledge Representation framework proposed in [3], [5] EHR UoD Schema
  • 4. AN EXAMPLE (1) * Screenshots Source: MTech Students - TRUMP Project
  • 10. RISK-AWARE INTEGRITY MANAGEMENT  Integrating “Trust” and “Risk” measures with earlier proposed Credentials based Access Control (CBAC) [4]  Flexible, bottom-up approach  Associate policies based on user credentials  Define Risk and Trust Measures
  • 11. INTEGRATING TRAAC AND CBAC (1)  Access control  Agnostic to actual end-users  Zoned Policy Model [TRAAC]  Zoned Privilege Packages 11 share deny readu reads undefined o Type of Requests  Read & Share o Data Object Policy  Zones assigned o Risk  Request & Trust  Requestor o Types of Trust  Obligation & Sharing Hospital X Department of Health Health-care Providers Association Role: Heart Specialist Role: Secretary Role: President
  • 12. 12  TRAAC approach  Misses CONTEXT during Trust Update  E.g in Which context was the particular violation made  TRAAC+ CBAC  MWF captures the context of a given interaction  Visibility of Policies  Critical to avoid unintentional violation  TRAAC+CBAC  Policy viewed as a Data Element  Credentials of a user  participation set  Credentials  Privilege Package  View applicable policies  Update of Sharing and Obligation based Trust  Assignment of Sensitivity Category  Information INTEGRATING TRAAC AND CBAC (2)
  • 13. ASSOCIATING TRUST  Trust  Probability with which a Privilege Package is entrusted to a world  Privilege package  Assertion1, Assertion2, Assertion3,…., Assertionn  Assertion  Set of role(Type, Location)  Trust value  Aggregation of trust values associated with each role in a the user’s participation set  Trust across system elements  User trust in system  Privacy of Information  System trust in users  Authenticated information  Trust between users  History of Events  Evaluating trust  Risk Mitigation Strategy  Obligations to be performed in a given domain  Sharing Trust & Obligation Trust 13
  • 14. ASSOCIATING RISK  Risk  Probability with which a data-access is granted to a World with a Stakeholder with a Privilege Package, P  Assign  Sensitivity category to  Worlds  Calculate  Loss sustained due to access  Undesirable Events  Fake credentials of a user Illegitimate access made by user  Risk Score = Loss * Probability of Undesirable Events  Risk Domain  Type and Location of a World  Risk Mitigation Strategy ? 14 Allow Deny Access based On Risk
  • 15. CONCERNS  Emergency Access  Bypassing Access Rules  Patient  Owner of data or subject of data  Modelling stakeholder as a data element answer this?  Complex Information Flows  Involve Delegation  Responsibility  Update Trust 15  Quantification of Risk and Trust  Revocation of Privilege Packages  Boundary conditions Risk & Trust  Risk Mitigation Strategies and Obligation  Trust Delegation  Visualization of Risk  Access granted to a stakeholder
  • 16. REFERENCES 1. Burnett, C., Chen, L., Norman, T.~J. and Edwards, P. (2014). TRAAC: Trust and Risk Aware Access Control. Proceedings of the 12th Annual Conference on Privacy, Security and Trust (PST2014), Toronto, Canada. 2. Burnett, C., Edwards, P., Norman, T. J., Chen, L., Rahulamathavan, Y., Jaffray, M., & Pignotti, E. (2013). TRUMP: A Trusted Mobile Platform for Self-management of Chronic Illness in Rural Areas. In Trust and Trustworthy Computing (pp. 142-150). Springer Berlin Heidelberg. 3. Chinmay Jog, Sweety Agrawal, Srinath Srinivasa. Distributing a Trust Framework for Utilitarian Data Exchanges in Inter-Organizational Collaborations. Proceedings of the Second ACM iKDD Conference on Data Sciences (CoDS 2015), March 2015, Bangalore, India. 4. Sweety Agrawal, Chinmay Jog, Srinath Srinivasa. Integrity Management in a Trusted Utilitarian Data Exchange Platform. Proceedings of the 13th International Conference on Ontologies, Databases and Applications of Semantics (ODBASE 2014), Amantea, Italy, October 2014. 5. Srinath Srinivasa, Sweety Agrawal, Chinmay Jog and Jayati Deshmukh. Characterizing Open Utilitarian Knowledge. Proceedings of the First IKDD Conference on Data Sciences (CoDS 2014), New Delhi, India, March 2014. 16