International Journal of Medical Informatics
Volume 76, Issue 5 , Pages 484-490, May 2007

End-to-end Security in Telemedical Networks – A Practical Guideline

Institute for Health Information Systems, UMIT, University for Health Sciences, Medical Informatics and Technology, Eduard Wallnöfer Zentrum 1, Hall in Tyrol, Austria

Abstract 

The interconnection of medical networks in different healthcare institutions will be constantly increasing over the next few years, which will require concepts for securing medical data during transfer, since transmitting patient related data via potentially insecure public networks is considered a violation of data privacy.

The aim of our work was to develop a model-based approach towards end-to-end security which is defined as continuous security from point of origin to point of destination in a communication process. We show that end-to-end security must be seen as a holistic security concept, which comprises the following three major parts: authentication and access control, transport security, as well as system security. For integration into existing security infrastructures abuse case models were used, which extend UML use cases, by elements necessary to describe abusive interactions. Abuse case models can be constructed for each part mentioned above, allowing for potential security risks in communication from point of origin to point of destination to be identified and counteractive measures to be directly derived from the abuse case models.

The model-based approach is a guideline to continuous risk assessment and improvement of end-to-end security in medical networks. Validity and relevance to practice will be systematically evaluated using close-to-reality test networks as well as in production environments.

Keywords: Medical informatics, Computer security, Medical network security, Systems analysis

To access this article, please choose from the options below

Login to an existing account or Register a new account.

  • Purchase this article for 31.50 USD (You must login/register to purchase this article)

    Online access for 24 hours. The PDF version can be downloaded as your permanent record.

  • Subscribe to this title

    Get unlimited online access to this article and all other articles in this title 24/7 for one year.

  • Claim access now

    For current subscribers with Society Membership or Account Number.

  • Visit SciVerse ScienceDirect to see if you have access via your institution.
 

PII: S1386-5056(06)00222-X

doi:10.1016/j.ijmedinf.2006.09.020

International Journal of Medical Informatics
Volume 76, Issue 5 , Pages 484-490, May 2007