Title
Pravah: Parameterised Information Flow Control In E-Health
Abstract
We study the problem of enforcing information flow control (IFC) in eHealth systems. IFC mechanisms allow users to control the release and propagation of sensitive information so that confidential information is not observable to unintended principals while collaborating with other legitimate principals. We describe the methodology for modelling the information flow control requirements in a hospital domain using Pravah, a parameterised lattice-based IFC framework. The key advantage of using the parameterised security class lattice is greater precision in stating policies, enhanced usability and a reduced overhead in creating security tags. We can then use type-checking to statically verify that user programs do not violate stated security policies when accessing or manipulating data records. We discuss the main issues in designing the parameterised security class lattice.
Year
DOI
Venue
2016
10.12694/scpe.v17i3.1179
SCALABLE COMPUTING-PRACTICE AND EXPERIENCE
Keywords
Field
DocType
Information flow control, Security, Lattice, Program verification, Parameterised security class
Information flow (information theory),Confidentiality,Computer security,Computer science,Usability,eHealth,Security policy,Information sensitivity,Data records
Journal
Volume
Issue
ISSN
17
3
1895-1767
Citations 
PageRank 
References 
0
0.34
6
Authors
2
Name
Order
Citations
PageRank
Chandrika Bhardwaj100.34
Sanjiva Prasad230140.04