SGAC: A patient-centered access control method

Nghi Huynh, Marc Frappier, Herman Pooda, Amel Mammar, Regine Laleau

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

This paper presents SGAC(Solution de Gestion Automatisée du Consentement, automatised consent management solution), a new healthcare access control model and its support tool, that manages patient wishes regarding access to their electronic health record (EHR). The development of this model has been achieved in the scope of a project with the Sherbrooke University Hospital, and thus has been adapted to take into account laws and regulations applicable in Québec and Canada, as they set bounds to patient wishes: under strictly defined contexts, patient consent can be overridden to protect his/her life. Moreover, since patient wishes and laws can be in conflict, SGAC provides a mechanism to address this problem. Besides, laws do not cover all cases where consent should be overridden to ensure patient safety. To this end, we define a formal model of SGAC which allows for property verification, making it possible to detect these cases. A performance comparison with XACML (WSO2/Balana) is presented and demonstrates the superior performances of SGAC.

Original languageEnglish
Title of host publicationIEEE RCIS 2016 - IEEE 10th International Conference on Research Challenges in Information Science
EditorsJolita Ralyte, Sergio Espana, Carine Souveyet
PublisherIEEE Computer Society
ISBN (Electronic)9781479987092
DOIs
Publication statusPublished - 23 Aug 2016
Externally publishedYes
Event10th IEEE International Conference on Research Challenges in Information Science, IEEE RCIS 2016 - Grenoble, France
Duration: 1 May 20163 May 2016

Publication series

NameProceedings - International Conference on Research Challenges in Information Science
Volume2016-August
ISSN (Print)2151-1349
ISSN (Electronic)2151-1357

Conference

Conference10th IEEE International Conference on Research Challenges in Information Science, IEEE RCIS 2016
Country/TerritoryFrance
CityGrenoble
Period1/05/163/05/16

Keywords

  • access control method
  • consent management
  • formal model
  • healthcare
  • verification

Fingerprint

Dive into the research topics of 'SGAC: A patient-centered access control method'. Together they form a unique fingerprint.

Cite this