The Context and the SitBAC Models for Privacy Preservation-An Experimental Comparison of Model Comprehension and Synthesis

被引:6
作者
Beimel, Dizza [1 ]
Peleg, Mor [2 ]
机构
[1] Ruppin Acad Ctr, Dept Ind Engn & Management, IL-40250 Emek Hefer, Israel
[2] Univ Haifa, Dept Management Informat Syst, IL-31905 Haifa, Israel
关键词
Knowledge representation; access control; RBAC; SitBAC; authorization; conceptual model; ontology; ENTITY-RELATIONSHIP; DESIGN;
D O I
10.1109/TKDE.2009.161
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Situation-Based Access Control (SitBAC) is a conceptual model for representing access control policies of healthcare organizations by characterizing situations of access to patient data. The SitBAC model enables formal representation of access situations as an ontology of concepts (Patient, Data Requestor, EHR, Task, and Response) along with their attributes and relationships. A competing access control model is the Contextual Role-Based Access Control (Context) model. The Context model uses logical expressions (rules) that specify contextual authorizations (i.e., characteristics of access requests that are available at access time). Open questions that relate to formal representation of scenarios involving access to patient data are: 1) which of the two models yields a formal representation that is easier to comprehend; 2) which of the two models facilitates the synthesis of correct models, and how does the task complexity affect the performance of comprehension and synthesis. In this study, we address these questions through a controlled experiment. The results of the experiment suggest that while there are no differences between the two models when it comes to comprehending or synthesizing simple scenarios of data access, for complex scenarios, there is a significant advantage to the SitBAC model in terms of both comprehension and synthesis.
引用
收藏
页码:1475 / 1488
页数:14
相关论文
共 33 条
[1]  
[Anonymous], 2001, KSL0105
[2]  
[Anonymous], 2000, ACM WORKSHOP ROLEBAS
[3]  
[Anonymous], 1956, HDB 1 COGNITIVE DOMA
[4]   COMPARING REPRESENTATIONS WITH RELATIONAL AND EER MODELS [J].
BATRA, D ;
HOFFER, JA ;
BOSTROM, RP .
COMMUNICATIONS OF THE ACM, 1990, 33 (02) :126-139
[5]   An experimental investigation of formality in UML-based development [J].
Briand, LC ;
Labiche, Y ;
Di Penta, M ;
Yan-Bondoc, H .
IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2005, 31 (10) :833-849
[6]   A GUIDE TO THE EVALUATION OF CONDENSED PHASE EXPLOSIONS [J].
DAVIES, PA .
JOURNAL OF HAZARDOUS MATERIALS, 1993, 33 (01) :1-33
[7]   SOHO/EPHIN observation of a multiple large solar energetic particles event in November 1997 [J].
Gómez-Herrero, R ;
Rodríguez-Frías, MD ;
del Peral, L ;
Müller-Mellin, R ;
Kunow, H .
ASTROPARTICLE PHYSICS, 2002, 17 (01) :1-12
[8]   Usability analysis of visual programming environments: A 'cognitive dimensions' framework [J].
Green, TRG ;
Petre, M .
JOURNAL OF VISUAL LANGUAGES AND COMPUTING, 1996, 7 (02) :131-174
[9]   Toward principles for the design of ontologies used for knowledge sharing [J].
Gruber, TR .
INTERNATIONAL JOURNAL OF HUMAN-COMPUTER STUDIES, 1995, 43 (5-6) :907-928
[10]   EZPAL: Environment for composing constraint axioms by instantlating templates [J].
Hou, CSJ ;
Musen, MA ;
Noy, NF .
INTERNATIONAL JOURNAL OF HUMAN-COMPUTER STUDIES, 2005, 62 (05) :578-596