Verification and validation of healthcare access control policies

Abstract : In healthcare, data digitization and the use of the Electronic Health Records (EHR) offer several benefits, such as reduction of the space occupied by data, or the ease of data search or data exchanges. IT systems must gradually act as the archivists who manage the access over sensitive data. Those have to be checked to be consistent with patient privacy wishes, hospital rules, and laws and regulations.SGAC, or Solution de Gestion Automatisée du Consentement, aims to offer a solution in which access to patient data would be based on patient rules, hospital rules and laws. However, the freedom granted to the patient can cause several problems: conflicts, hiding of the needed data to heal the patient or simply data-capture error. Therefore, verification and validation of policies are crucial: to conduct this verification, formal methods provide reliable ways to verify properties like proofs or model checking.This thesis provides verification methods applied on SGAC for the patient: it introduces the formal model of SGAC, verification methods of properties such as data reachability or hidden data detection. To conduct those verification in an automated way, SGAC is modelled in B and Alloy; these different models provide access to the tools Alloy and ProB, and thus, automated property verification with model checking
Document type :
Theses
Complete list of metadatas

Cited literature [25 references]  Display  Hide  Download

https://tel.archives-ouvertes.fr/tel-01538386
Contributor : Abes Star <>
Submitted on : Tuesday, June 13, 2017 - 2:43:08 PM
Last modification on : Wednesday, September 4, 2019 - 1:52:06 PM
Long-term archiving on : Tuesday, December 12, 2017 - 3:18:50 PM

File

TH2016PESC1042.pdf
Version validated by the jury (STAR)

Identifiers

  • HAL Id : tel-01538386, version 1

Collections

Citation

Nghi Huynh. Verification and validation of healthcare access control policies. Computation and Language [cs.CL]. Université Paris-Est, 2016. English. ⟨NNT : 2016PESC1042⟩. ⟨tel-01538386⟩

Share

Metrics

Record views

417

Files downloads

185