Towards scalable authentication in health services

Gail-Joon Ahn1, Dongwan Shin1
1College of Information Technology, University of North Carolina, Charlotte, USA

Tóm tắt

Over the last two decades, many attempts have been made to computerize the management of patient records using advanced computing and networking facilities across healthcare providers such as hospitals, clinics, and clearing agencies. In addition to this transition from a disparate and paper-based infrastructure to a consolidated and digital medium-based one, we have been confronted with privacy and security requirements since the advent of the Health Insurance Portability and Accountability Act (HIPPA). The problem we seek to address in this paper is to provide authentication of individual identity in the context of accessing critical information in Web-based e-health systems including secure transmission of data across the Internet. These problems have technical solutions that are well known, but the solutions in general are strongly biased toward a single individual interacting with a single application. In this paper, we propose a scalable token-based authentication architecture and demonstrate how we can implement this architecture using commercial-off-the-set technologies. Our approach focuses on vendor-neutral specifications. The proof-of-concept prototype has been implemented so that the pilot testing may be conducted at various sites.

Từ khóa

#Authentication #Computer networks #Computer network management #Health information management #Medical services #Hospitals #Privacy #Data security #Information security #Insurance

Tài liệu tham khảo

0, PKCS #11 compatible iKey 2000, PKCS 11 v2 11 Draft 1 Cryptographic Token Interface Standard 1996, The SSL Protocol Version 3 0 Draft 0, North Carolina Department of Health and Human Services 0, For the Record Protecting Electronic Health Information steiner, 1988, Kerberos: An Authentication Service for Open Network Systems, Proc 5th USENIX UNIX Security Symp gobioff, 1996, Smart Cards in hostile environments, Proceedings of the Second Usenix Workshop on Electronic Commerce stabell-kula, 1999, Providing Authentication to Messages Signed with a Smart Card in Hostile Environment, USENIX Workshop on Smartcard Technology 1994, NIST FIPS 190 Guideline for the Use of Advanced Authentication Technology Alternatives john, 1997, A Survey of Authentication Protocol Literature, Technical Report 10.1145/74850.74852 0, PKCS #11 compatible smart card 10.1109/30.826377 ellison, 2000, Ten Risks of PKI: What you are not being told about Public Key Infrastructure, Computers and Security Journal, 16, 1 0, Health Insurance Portability and Accountability Act of 1996 0, PKCS #11 compatible iButton