scieee Open visual document viewer

Privilege Management Infrastructure for Virtual Organizations in Healthcare Grids

Calvillo Arbizu, Jorge; Román Martínez, Isabel; Rivas Rivas, Sergio; Roa Romero, Laura María

Abstract

This paper is focused on the management of virtual organizations (VO) inside healthcare environments where grid technology is used as middleware for a healthcare services-oriented architecture (HSOA). Some of the main tasks considered for the provision of an efficient VOmanagement aremanagement of users, assignation of roles to users, assignation of privileges to roles, and definition of resources access policies. These tasks are extremely close to privilege management infrastructures (PMI), so we face VOmanagement services as part of the PMI supporting access control to healthcare resources inside the HSOA. In order to achieve a completely open and interoperable PMI, we review and apply standards of security and architectural design. Moreover, semantic technologies are introduced in decision points for access control allowing the management of a high degree of descriptors by means of ontologies and infer the decision making through rules and reasoners.

Full text

IEEE TRANSACTIONS ON INFORMATION TECHNOLOGY IN BIOMEDICINE, VOL. 00, NO. 00, 2011 1 P i ilege Managemen In as uc u e o Vi ual O ganiza ions in Heal hca e G ids Jo ge Cal illo, S uden Membe , IEEE, Isabel Rom´ an, Se gio Ri as, and Lau a M. Roa, Fellow, IEEE Abs ac —This pape is ocused on he managemen o i ual o ganiza ions (VO) inside heal hca e en i onmen s whe e g id echnology is used as middlewa e o a heal hca e se ices-o ien ed a chi ec u e (HSOA). Some o he main asks conside ed o he p o ision o an e icien VO managemen a e managemen o use s, assigna ion o oles o use s, assigna ion o p i ileges o oles, and de ini ion o esou ces access policies. These asks a e ex emely close o p i ilege managemen in as uc u es (PMI), so we ace VO managemen se ices as pa o he PMI suppo ing access con- ol o heal hca e esou ces inside he HSOA. In o de o achie e a comple ely open and in e ope able PMI, we e iew and apply s anda ds o secu i y and a chi ec u al design. Mo eo e , seman- ic echnologies a e in oduced in decision poin s o access con ol allowing he managemen o a high deg ee o desc ip o s by means o on ologies and in e he decision making h ough ules and ea- sone s. Index Te ms—Access con ol, di ec o y se ices, p i ilege man- agemen in as uc u es (PMI), seman ic echnologies, se ice- o ien ed a chi ec u e (SOA), i ual o ganiza ion (VO). I. INTRODUCTION COMPUTING when de ices and applica ions in a heal h- ca e o ganiza ion make hei acili ies accessible h ough se ices, a ailable ia public and s able in e aces, in eg a ion, and in e ope abili y can be achie ed mo e easily. Fu he mo e, he de elopmen o new and mo e complex se ices, which may be composed om elemen a y ones, o e ing ad anced capabil- i ies o use s, should be mo e e ec i e. The app oach o designing a sys em p o iding se ices o bo h end-use applica ions and o he se ices dis ibu ed in a ne wo k is o en called se ice-o ien ed a chi ec u e (SOA) [1]. A widely accep ed de ini ion o a chi ec u e is “a o mal de- sc ip ion o a sys em, o a de ailed plan o he sys em a com- ponen le el (including hei in e - ela ionships) o guide i s im- plemen a ion, as well as he p inciples and guidelines go e ning i s design and e olu ion o e ime” [2]. By applying all hese Manusc ip ecei ed Ap il 20, 2010; e ised July 29, 2010 and Oc obe 4, 2010; accep ed Decembe 23, 2010. Da e o publica ion; da e o cu en e sion. This wo k was suppo ed in pa by he CIBER-BBN, he Biomedical Enginee - ing G oup in Uni e si y o Se ille and in pa by he Fondo de In es igaci´ on Sani a ia unde P ojec PI082023. J. Cal illo and L. M. Roa a e wi h ISCIII Ini ia i e CIBER-BBN and he Biomedical Enginee ing G oup, Uni e si y o Se ille, Se ille 41092, Spain (e-mail: [email p o ec ed]; [email p o ec ed]). I. Rom´ an is wi h ISCIII Ini ia i e CIBER-BBN and he ´ A ea de Inge- nie ´ ıa Telem´ a ica, Uni e sidad de Se illa Se ille 41092, Spain (e-mail: isabel@ ajano.us.es). S. Ri as is wi h he Biomedical Enginee ing G oup, Uni e si y o Se ille, Se ille 41092, Spain (e-mail: s i as i[email p o ec ed]). Digi al Objec Iden i ie 10.1109/TITB.2010.2104160 ideas o heal hca e en i onmen s we could e e o heal hca e se ices-o ien ed a chi ec u e (HSOA). The collabo a ion be ween en i ies in an SOA could be based on he concep o i ual o ganiza ion (VO) [3], which e e s o a dynamic se o en i ies (indi iduals, sys ems, o ins i u ions) dis ibu ed ac oss di e en adminis a i e domains and sepa- a ed geog aphically, usually wo king owa d a common goal, de ined a ound a se o esou ce-sha ing ules and condi ions. No ma e he na u e o esou ces, hey all o e hei capabili ies h ough se ice in e aces, and he p inciple o dis ibu ion al- lows connec ing hem and composing complex se ices making sepa a ion (adminis a i e, echnical, and geog aphic) anspa - en o he end use . Secu i y is a majo conce n and we could de e mine who can access o a esou ce and unde which condi ions, es ablishing he ules o esou ce sha ing needed o se a VO. Each esou ce owne mus be able o de e mine he policies o con olling access and mus us ha he en o cemen o hese ules is gua an eed. Nowadays, a model ocused on he subjec o ca e (SoC) as adminis a o o his/he in o ma ion is mo e and mo e desi able, in which each indi idual can decide abou he access o in o - ma ion and esou ces ela ed o him/he . In pa allel, legisla ion es ablishes scena ios in which he au ho i y o he SoC can be empo ally in alida ed such as when a isk o public heal h ex- is s o an eme gency ha can esul in i e e sible inju ies o dea h isk. The cu en si ua ion, along he p og essi e dis ibu ion o esou ces ac oss echnological, geog aphy and adminis a i e domains, complica es he comple e managemen by he SoC, equi ing simple adminis a ion p ocedu es. The use o no - malized p i ilege managemen in as uc u es (PMI) [4] o VO managemen could p o ide a ounda ion upon which mecha- nisms o se ices access con ol wi hin an SOA can be buil . To sum up, in o de o achie e he comple e in e ope abili y o esou ces and applica ions, wo issues mus be conside ed. Fi s , he es ablishmen o a s anda dized amewo k and guidelines o he speci ica ion and de elopmen o sys ems can encou age he deploymen o complex SOA and ocus he di e en wo ldwide e o s in o de o ake a s ep o wa d in heal hca e domain. Second, mechanisms o secu i y and access con ol a e keys o achie e eliable dis ibu ed en i onmen s. One aluable ool o de ine a common language easing he au- oma ion o adminis a ion and decision-making asks could be seman ic echnologies, which would allow an SoC o manage his/he own heal h in o ma ion and esou ces. In he ieldo PMIsuppo edbyVOs,se e ale o sha ebeen de eloped. Conc e ely, nume ous ini ia i es aim o enhance accesscon ol insuch he e ogeneousand complexen i onmen s 1089-7771/$26.00 © 2011 IEEE 2 IEEE TRANSACTIONS ON INFORMATION TECHNOLOGY IN BIOMEDICINE, VOL. 00, NO. 00, 2011 TABLE I RELEVANT STANDARDS AND THEIR CONTRIBUTIONS IN THE APPROACHED PMI ei he by applying seman ic echnologies [5], [6] o by means o new secu i y models [7], [8]. Wi hin he heal hca e domain, he e a e some app oaches and heal hg id pla o ms [9]–[13], bu he p i ilege managemen is mainly delega ed o gene al- pu pose middlewa es, and e o s a e mo e ocused on applica- ion o g id echnologies in heal h a he han on he add essing secu i y equi emen s. In his pape , we combine and imp o e pas and cu en e - o s in o de o speci y a PMI suppo ing heal hg ids. To do his, ele an s anda ds o PMI, as well as me hodologies o speci ica ion o hose in as uc u es, a e analyzed om hose o gene al pu pose o hose ha a e ocused on heal hca e en i on- men s. Requi emen s and app oaches a e combined wi h he VO concep and g id echnologies, and we p opose an access con ol managemen in as uc u e o heal hca e en i onmen s based on seman ics and s anda ds complian . Finally, we in oduce a scena io om a eal p ojec whe e a legacy sys em mus be included in he p oposed p i ilege managemen in as uc u e. II. MATERIAL AND METHOD A. PMI Founda ions and Rela ed S anda ds As i has been in oduced ea lie , one o he keys o suc- cess o open and in e ope able solu ions is he adop ion o s anda ds in bo h gene al and heal hca e domains in o de o add ess issues as secu i y and dis ibu ion. In Table I, a se o ele an s anda ds om in e na ional s anda diza ion o ganiza- ions is shown, explici ly indica ing how hey ha e been adop ed in he cu en s udy. The s anda diza ion o ganiza ions a e: he In e na ional O ganiza ion o S anda diza ion (ISO), he In e - na ional Telecommunica ion Union, he In e ne Enginee ing Task Fo ce, he O ganiza ion o he Ad ancemen o S uc- u ed In o ma ion S anda ds, and he Eu opean Commi ee o S anda diza ion (CEN). Acco ding o secu i y ini ia i es, all o hem con ibu e o he common PMI p o iding concep s o ea u es ha ha e been conside ed ele an . Each s anda d included in Table I p o ides speci ic secu i y issues no co e ed (o no so comple ely) by he o he s. In o de o ease in e ope abili y and exchange o in o ma ion, common e minologies ha e o be conside ed and adop ed. In his pape , we ha e used he concep s o [22] o build ou on- ology, bu i is possible—and ecommended— o ex end i wi h o he exis ing e minologies, o example hose o clinical pu - pose [ he sys ema ized nomencla u e o medicine (SNOMED) [25], Galen [26], e c.] o biomedical on ologies [27]. Ou esul - ing on ology is ocused on basic seman ic ea u es o PMI and eases he in eg a ion o o he heal h domain mo e specialized e minologies. B. HSOA and S anda diza ion Se e al pa adigms (SOA is one o he mos p omising among hem) ha e been app oached o add ess he inhe en complexi y in he dis ibu ed compu ing sys ems, bu he design, de elop- men , deploymen , main enance, and e olu ion o a dis ibu ed sys em a e highly complex asks. Consequen ly, i is essen ial ha he a chi ec u e (and any unc ion necessa y o suppo i ) be de ined in a se o s anda ds, so ha mul iple endo s can collabo a e in he p o ision o dis ibu ed sys ems. Some heal hca e a chi ec u es’ app oaches a e de eloped by s anda diza ion o ganiza ions, like CEN [28] o he Objec Man- agemen G oup [29]. In he heal hca e con ex , he ISO 12967 Heal h In o ma ion Se ice A chi ec u e (HISA) s anda d de- sc ibes an a chi ec u e o he in eg a ion o heal hca e in o - ma ion se ices. An impo an basis o he p oduc ion o his se ice a chi ec u e s anda d is he e e ence model-open dis- ibu ed p ocessing (RM-ODP) me hodology [30]. The speci- ica ions a e o malized a oiding any dependence on speci ic echnological p oduc s and/o solu ions. One o he equi emen s in ou esea ch has been ha ou esul s we e easily inco po a ed, and in e ope able, in he se o in o ma ion sys ems o a heal hca e o ganiza ion using s an- da ds. The ac ual implemen a ion o an SOA equi es a mid- dlewa e laye lying be ween he compu ing and ne wo king in- as uc u e and he se ices in a dis ibu ed compu ing sys em. This middlewa e is in ended o o e a highe le el o abs ac- ion o he unde lying compu ing and ne wo king esou ces by hiding he dis ibu ion and he e ogenei y o implemen a ion CALVILLO e al.: PRIVILEGE MANAGEMENT INFRASTRUCTURE FOR VIRTUAL ORGANIZATIONS IN HEALTHCARE GRIDS 3 echnologies. Ou esea ch is ocused on he use o g id as mid- dlewa e o he HSOA. C. P i ilege Managemen in G id Globus oolki is a g id middlewa e implemen a ion includ- ing a secu i y amewo k ( he Globus Secu i y In as uc u e— GSI) [31] ha p o ides common au hen ica ion and au- ho iza ion mechanisms as well as connec ions o ex e nal in as uc u es. The dynamic na u e o VO necessi a es i s au oma ing he disco e y o po en ial p o ide s, hen acqui ing access igh s o ce ain se ices, and inally en o cing he access con ol policy on un ime upon esou ces alloca ion. Se e al ini ia i es ha e appea ed, such as he communi y au ho iza ion se ice [32] o he i ual o ganiza ion membe ship se ice (VOMS) [33], which aim o es ablish con ol mechanisms by de ining g oups o use s o a ibu es o educe he managemen asks. Ano he eme ging app oach is o delega e ex e nal in as uc- u es o make access con ol decision o g id se ices. The p i - ilege and ole managemen in as uc u e s anda ds alida ion (PERMIS) [34] is an example o a policy based au ho iza ion in as uc u e. D. Seman ic Technologies Ano he c ucial co ne s one o comple ely in e ope able and open HSOA is he use o seman ic echnologies. Following he SOA pa adigm, we a e conside ing highly he e ogeneous sce- na ios whe e he schemas o a ibu es a e complex oo. I is un- easible o come o an ag eemen wi h all he esou ce p o ide s cu en ly (o in he u u e) in ol ed. By using on ologies de- sc ibing concep s o esou ces oge he wi h in e ence engines, we can ob ain mainly h ee ad an ages. Fi s , SOA cha ac e - is ics as openness and in e ope abili y a e enhanced because o he unde s anding be ween di e en pa ies is eased. I is achie ed by sha ing he o mal de ini ions o esou ces desc ip- o s as on ologies. The adminis a o will use hese desc ip o s o label he esou ces o he di e en VO. Second, by passing an on ology o concep s h ough a easone we can in e new knowledge and add i as explici ela ions and elemen s. Las , by in oducing seman ic in e ence in he mechanisms o access con ol, he de elopmen o elemen s making decisions can be eased. The access con ol policies would be exp essed acco d- ing o on ologies ( esou ces, use a ibu es, en i onmen , e c.) and ule languages. So he logic o decision poin s could be educed o an in e ence engine he esul s o which would be he pe mission o p ohibi ion o access. One o he mos popula seman ic ools is he Web On ology Language (OWL) [35], a knowledge ep esen a ion language based on desc ip ion logic and Resou ce Desc ip ion F ame- wo k (RDF) ep esen a ion. OWL co e s he speci ica ion o on ologies and i has p e iously been used o he o maliza ion o policies o access con ol [5], [36], [37]. In o de o w i e ules composed o OWL concep s a special ule language is equi ed and a p omising app oach is he Seman ic Web Rule Language (SWRL) [38] ha allows es ablishing complex ela- ions among p ope ies ex ending he OWL exp essi i y. The e a e cu en e o s using SWRL in conjunc ion wi h OWL o desc ibe access con ol policies [6], [39]. All he p e ious wo ks in his ield (i.e., use o OWL and SWRL o de ine policies and decision making) ha e gene al pu pose and hey do no add ess he speci ic equi emen s o access con ol in such a complex domain as heal h. In ou ap- p oach, we use he OWL language o de elop an on ology o esou ce desc ip o s, in ol ed ac o s, and con ex cha ac e is- ics ha can be implica ed in he decision o access (as physical loca ion whe e he access is pe o med, da e and ime, pu pose o use, e c.). The access con ol policies ha e been exp essed by means o SWRL ules and es ed and execu ed by using he Jess engine [40] due o i s compa ibili y wi h P o ´ eg´ e-OWL pla o m [41] ha allowed de eloping he knowledge base, i.e., OWL on ology and SWRL ules. SWRL ules o de ining policies and easoning wi h Jess in a heal hca e se ing ha e been also applied in [9]. The main di e ence wi h he cu en s udy is ha hey use hese ools o ha monize da a p o ec ion legisla ion in Eu ope, and in his pa- pe , an on ology and ules a e p oposed o ease he managemen o heal h in o ma ion and esou ces by an adminis a o who can be he own SoC. Due o he di e ences on app oaches, in his s udy nei he on ology no ules could be eused om p e ious e o s and hey ha e been comple ely buil om he pe spec i e o his pape . III. RESULTS A. Secu i y In as uc u e and Use Cases The app oached secu i y in as uc u e is based on he s an- da ds, me hodologies, and echnologies e ised ea lie . We ha e combined and imp o ed hem in o de o build an open and comple e solu ion. On one hand, i uses he eX ensible Access Con ol Ma kup Language (XACML) speci ica ion [18] adding c ucial elemen s cen e ed on seman ic managemen . The esul is he se ices decomposi ion in Fig. 1, an imp o ed e ision o he XACML s anda d. On he o he hand, he au ho iza- ion schema ollows he guidelines o he a ibu e-based access con ol (ABAC) access con ol schema, in which p i ileges a e g ouped in a ibu es, and each indi idual is assigned a se o hose. In ou app oach, hose a ibu es a e speci ied in a concep on ology desc ibed in he nex sec ion. Ano he impo an poin we include in his e ision o he XACML s anda d is he conside a ion o sepa a e and dis- ibu ed policy in o ma ion poin s (PIP). Each one ollows i s own unc ional p o ocol (cen e ed on a pa icula kind o a - ibu es, ecei ing eques s, and sending in o ma ion) and i is connec ed o he ela ed knowledge base. Following his end, he p oposed in as uc u e eplaces cen alized componen s o he XACML schema wi h se ices ha can be dis ibu ed and decomposed in o he simple se ices. F om an a chi ec u al poin o iew, Fig. 1 shows se ices om di e en laye s o he HSOA. Thus, policy en o cemen poin (PEP) se ices di ec ly ela ed o esou cesbelong o hein as uc u elaye ;se ices as con ex handle easing dis ibu ion and loca ion a e pa o mid- dlewa e laye ; esou ce and en i onmen knowledge bases, PIP se ices, and policy decision poin (PDP) se ices, all belong o 4 IEEE TRANSACTIONS ON INFORMATION TECHNOLOGY IN BIOMEDICINE, VOL. 00, NO. 00, 2011 Fig. 1. Use case 1: using a g id se ice h ough he PREDIRCAM po al. he gene ic se ice laye ; inally, he c eden ial eposi o y and he policies seman ic knowledge base a e pa o he heal hca e domain se ices laye because o hei unc ionali y and con en a e speci ically de ined o his domain. Acco ding o implemen a ion and echnology, al hough he e exis se e al app oaches o add ess p i ilege managemen in g id, in many cases hese only p esen pa ial solu ions o he whole conce n. In gene al, e o s a e d i en o p o ide PMI common o all g id se ices. In ac ual heal hca e sys ems, e en wi h g id in as uc u es deployed, he e a e se e al he e oge- neous sys ems whose adap abili y o g id is no easible. Gene - ally, each sys em has i s local p i ilege managemen o access con ol and i does no wan delega e access decision o hi d pa ies. We ha e me his issue in he PREDIRCAM p ojec [42], which is de eloping and alida ing an in elligen pla o m o biomedical echnologies o moni o ing,p e en ion,andpe son- alized ea men o melli us diabe es, he ca diac and me abolic isk, and he enal insu iciency. One o he main componen s o he pla o m o PRE en ion DIabe es and CA dioMe abolic Risk (PREDIRCAM) p ojec is he pla o m o ollowing up o exe cise ou ines and ood habi s o pa ien s. This pla o m has been de eloped using he Con en Manage Sys em (CMS) D upal [43] e sion 6. D upal ollows a scheme comple ely cen alized wi h a local da abase s o ing con en s o CMS. Incompa ibili ies appea when we y o in oduce D upal in he g id in as uc u e because he o me p o ides i s own use managemen wi h local pe mission h ough login and passwo d, and he la e uses a public key in as uc u e wi h X.509 ce i i- ca es o au hen ica ion and a ibu e ce i ica es o au ho iza ion. To in eg a e au onomous sys ems wi h hei own local p i i- lege managemen in he g id we ha e e iewed h ee use cases: he sys em ac ing as clien o a g id se ice, he sys em being a se ice wi h local p i ilege managemen ha is accessed by a g id clien , and inally, he sys em as a se ice accessed by a g id clien , bu he access con ol is managed by he global g id in- as uc u e. Fig. 1 shows he i s use case whe e he sys em (in ou pa icula case, he PREDIRCAM pla o m) ac s as a clien o a g id se ice, hanks o g id use capabili ies delega ion. We show he main componen s in he designed au hen ica ion and au ho iza ion in as uc u e. This app oach is lexible and scal- able and i acili a es he managemen o di e en iden i ies o he same use and he single sign on. Mo eo e , PIP se ices o esou ce, en i onmen , and subjec , and PDP se ices a e all independen elemen s, adding lexibili y o he managemen o VO. In he ac ual implemen a ion o his a chi ec u e e e y unc ional elemen can be dis ibu ed in he g id, in o de o p e en he dependence in cen alized elemen s. We ha e selec ed and adap ed echnical solu ions o each unc ional elemen . Fo example, iden i y p o ide and CALVILLO e al.: PRIVILEGE MANAGEMENT INFRASTRUCTURE FOR VIRTUAL ORGANIZATIONS IN HEALTHCARE GRIDS 5 Fig. 2. Use case 2: using PREDIRCAM po al acili ies using local secu i y. delega ion elemen s a e p o ided by he Globus Secu i y In as- uc u e. An e icien PDP se ice is implemen ed in PERMIS and he subjec PIP se ice is based on VOMS. Resou ce PIP se ice is based in he Globus Moni o ing & Disco e y Sys em (MDS) [44]. The con ex handle se ice belongs o middlewa e and i deals wi h he dis ibu ion and loca ion o he di e en se ices; hus, i can be implemen ed in se e al ways and e en i could be in eg a ed in PDP and PIP se ices. Fo he sake o simplici y, in he p oposed in as uc u e Globus MDS pe o ms asks o disco e ing and communica ing be ween he di e en PIP, PEP, and PDP se ices. In ou app oach, he ede a ion and au onomy o sys ems is acili a ed because legacy se ices could be in eg a ed and hey can choose be ween adop ing g id secu i y in as uc u e o main aining hei own, as depic ed in Figs. 2 and 3. The i s one shows he use case in which he legacy sys em expo s some in e aces o g id in as uc u e bu holding i s local p i ilege managemen . In Fig. 3, we achie e he in eg a ion by modi ying he legacy sys em in o de o use he p i ilege managemen in as uc u e o g id. Finally, in PREDIRCAM p ojec we ha e adop ed he so- lu ion o Fig. 3, and he i s s ep o achie e he in eg a ion be ween he pla o m and he g id in as uc u e is o make he au hen ica ion in D upal accep s X.509 ce i ica es. To p o ide D upal wi h ce i ica e capabili ies, we ha e added he “login ce i ica e” module [45]. Now ou legacy sys em (i.e., D upal) allows he egis a ion o new use s o he access o egis e ed use s o he esou ces p o ec ed by he PMI using X.509 ce i i- ca es, and all his wi hou making any change o he da abase o he CMS. Fig. 3. Use case 3: using PREDIRCAM po al acili ies published as g id se ice using g id p i ilege managemen in as uc u e. B. On ology and Policies o Con olling Access To achie e he a iabili y deg ee equi ed by access con ol policies,we ha emodeled anon ology o heal hca e domain ul- illing all he po en ial ea u es o ca ego iza ion o esou ces. By using his on ology, he adminis a o (po en ially he SoC) can ha e a e sa ile con ol o e he access o esou ces h ough he po en ial ac o s who can access, he na u e o he in o ma- ion,c ea ion da es,au ho s, physicalloca ion o access, pu pose o use, e c. Ano e iewo hede elopedon ology isshown inFig. 4.I is composed o : an on ology o heal hca e ac o s, ano he ocused on esou ce desc ip o s, and a hi d one abou secu i y used o c ea e he access con ol policies. Fig. 4 includes he po en ial ac o s who can y o access o p o ec ed objec s (people, o - ganiza ions, o de ices), he wo ca ego ies o objec s o which he access mus be con olled (in o ma ion and esou ces), and a spec um o desc ip o s o cha ac e ize hese objec s (poin ing i s na u e, anonymiza ion le el, ela ed disease, a ailabili y o di e en pu poses, e c.). As i has been exposed ea lie , policies uling he access o esou ces a e de ined by means o SWRL language and based on he concep on ologies. In his app oach, a policy is a “ho n-like” ule in which he an eceden is composed o elemen s (ac o s, esou ces, a ibu es, en i onmen ea u es, e c.) condi ioning he decision, and he consequen speci ies i he eques ed ac ion is pe mi ed o p ohibi ed. An example o policy is “allow my pa ne o see all my in o ma ion ela ed o sexually ansmi ed diseases since yea 2000 and in which hi d pe sons a e no in ol ed,” ha is exp essed in SWRL as ollows: who:Pe son(?pe ) ∧who:hasRela ion(?pe , who:SPOUSE) ∧ wha :Clinical_In o ma ion(?in ) ∧a :Sexual_O gans(?dis) ∧isRela edTo(?in , ?dis) ∧a :Subjec _O _Ca e(?soc) ∧ isRela edTo(?in , ?soc) ∧wha :c ea ionTime(?in , ? ime) ∧ empo al:no Be o e(? ime, "2000-1-1") →ac ionPe mi ed(?pe , ?in ) The in e p e a ion o a ule as p e ious one is: i condi ions speci ied in an eceden a e ue (i.e., he e a e OWL indi idu- als sa is ying all clauses), hen he p ope y “ac ionPe mi ed” 6 IEEE TRANSACTIONS ON INFORMATION TECHNOLOGY IN BIOMEDICINE, VOL. 00, NO. 00, 2011 Fig. 4. O e iew o on ology o heal hca e domain concep s. (o “ac ionP ohibi ed”) mus be c ea ed among ac o /s and e- sou ce/s. This p ocess o checking ules and c ea ing p ope ies is ealized by he in e ence engine Jess as i is explained la e . The p ocess o decision making pe o med by PDP se ice is: when i ecei es all he in o ma ion om PIP se ices h ough con ex handle se ice, i combines he on ology wi h SWRL ules, and he Jess engine execu es he in e ence. The in e ed axioms a e inco po a ed o he on ology, and he Seman ic Que y-Enhanced Web Rule Language (SQWRL) is used o e - i y heexis enceo hep ope ies“ac ionPe mi ed”and“ac ion- P ohibi ed” be ween he access eques e and he eques ed e- sou ce (e.g., ac ionPe mi ed(SPOUSE,?p) →sqw l:selec (?p)). A e ob aining he esul s om SQWRL que ies, he possible scena ios a e as ollows. 1) The e is a p ope y o pe mission (o p ohibi ion); hen he decision o accep ance (denega ion) o access is made. 2) Two o mo e policies de ined by he SoC a e incohe en , and he e exis he wo p ope ies (pe mission and p ohi- bi ion) a he same ime; he mo e conse a i e decision is made (i.e., denying he access). 3) The e is no policy uling he eques ed access, and any decisioncanno bemade; wesol e his scena ioby making hePDP odeny he eques and communica ing o he SoC o speci y (i he/she will) he ule con olling his kind o access. C. No maliza ion and A chi ec u al Design We ha e conside ed in all scena ios wha heal h in o ma ics s anda ds a e es ablished. Fo example, in ou in as uc u e i is essen ial ha ligh weigh di ec o y access p o ocol (LDAP) eposi o ies con o m o [4] and [24]. Mo eo e , he esul s de- sc ibed ea lie (i.e., secu i y in as uc u e, speci ica ion o poli- cies, and access decision making) ha e been de eloped wi hin a no malized a chi ec u e ollowing p inciples o in e ope abili y and openness. As was p esen ed in he sec ion o me hodology, RM-ODP and HISA ha e been chosen o he no maliza ion o he heal hca e se ices a chi ec u e suppo ing ou app oach. This s anda d o malizes only undamen al aspec s, which a e common and cu en ly essen ial in any ad anced heal hca e sys- em, so i has been ex ended in di e en ea u es. Fig. 5 shows he ul illmen be ween ac o s and oles wi hin he Secu i y In as uc u e Communi y, he scope o which is o es ablish a con olled access o p o ec ed esou ces by means o policies. Among he ele an ac o s he e a e some sys ems (ID p o ide , con ex handle , policy en o cemen , in o ma ion, and decision) and en i ies ela ed o people o o ganiza ions ( e- sou ce owne , use , and use agen ). The en e p ise iewpoin abs ac s om eal implemen a ions o use cases and i p esen s en i ies in ol ed in he secu i y in as uc u e communi y co e - ing all possible scena ios. The unc ionali y o each ac o in he communi y is desc ibed by he ole/s ha he ac o ul ills. The a ailable oles a e: eques e , iden i y p o ide , decision agen , esou ce and policy admin, esou ce access manage , con ex manage , e c. This diag am is pa o he no maliza ion o he en e p ise iewpoin desc ibed by HISA, RM-ODP, and he s anda d ISO 15414 [46] p o iding he p ope en e p ise language. All he componen s suppo ing he access con ol in ou app oach ha e been designed as se ices inside he HSOA, by using he ISO 19793 s anda d [47] o hei inclusion and o maliza ion in he di e en ODP iewpoin s, and imp o ing hei eu iliza ion and scalabili y. In o ma ion and compu a ional iewpoin s inhe i di ec ly om HISA s anda ds including also he amewo k o common concep s and sys ems es ablished by he s anda ds desc ibed in CALVILLO e al.: PRIVILEGE MANAGEMENT INFRASTRUCTURE FOR VIRTUAL ORGANIZATIONS IN HEALTHCARE GRIDS 7 Fig. 5. Ac o ole ul illmen and assignmen ules. Sec ion II-A. Enginee ing and echnology iewpoin s deal wi h implemen a ion issues and speci y how g id echnologies (in ou case, he Globus middlewa e) p o ide he capabili ies o ou p i ilege managemen in as uc u e. Al hough in his s udy, a eal implemen a ion wi h g id echnologies has been desc ibed, he o maliza ion o he in as uc u e by using ODP allows o he middlewa e echnologies o be used. Thus, only enginee - ing and echnology iewpoin s would ha e o be p o ided. A mo e de ailed speci ica ion o he iewpoin s o ou ap- p oach will be he ocus o u u e s udies. IV. CONCLUSION Ou s udy has been ocused on he de elopmen o a heal h- ca e PMI ha an SoC could adminis a e, i.e., he/she could decide abou he access o his/he heal h esou ces. How his scena io is achie ed i is wha he au ho s conside he g ea con ibu ion o his pape . Th oughou he en i e p ocess o de elopmen ( om design o implemen a ion), se e al con ibu ions can be ema ked. In he i s s age and ha ing he openness and in e ope abili y as c ucial equi emen s, nume ous s anda ds (o secu i y, a chi- ec u e o maliza ion, e minologies, e c.) ha e been analyzed. The mos ele an ones ha e been combined and enhanced in o de o build a seman ic based PMI. T adi ional and cen alized app oaches as XACML and ole-based access con ol (RBAC) ha e been imp o ed by conside ing he dis ibu ion and com- posi ion o se ices ollowing he SOA pa adigm, and also he seman ic managemen in decision poin s o access con ol al- lowing au oma ing adminis a ion asks. In his phase, he PMI has been o malized acco ding o ODP and HISA s anda ds. Al hough he la e is heal hca e domain speci ic, i does no conside secu i y issues, and in his s udy an ex ension o i has been necessa y. Due o his o maliza ion is no malized and echnology independen , he esul ing PMI can be implemen ed by means o di e en pla o m and echnologies, and all he implemen a ions e ain he same le els o in e ope abili y, scal- abili y, and openness. In a second s age, h ee use cases ha e been analyzed in o de o s udy he openness o he PMI and he po en ial in eg a ion o legacy sys ems wi h i . These use cases allowed ex ac ing unc ional equi emen s o bo h he PMI and he legacy sys em, s essing he adequacy o conside ing he p oblem o legacy sys em in eg a ion in an ea ly s age o he sys em design. The nex phase has ocused on he implemen a ion, and he PMI se ices ha e been pa icula ized like conc e e echnologi- calelemen s.G id echnologiesha ebeenselec edasunde lying middlewa e and all he componen s ha e been adap ed o wo k oge he and be con o med o selec ed s anda ds suppo ing he designed PMI in he i s s age. In pa allel, a concep on ology has been de eloped o suppo he access con ol mechanisms o PMI. Mo eo e , SWRL has been used as policy language and i has been shown how seman ic echnologies (on ologies, in e ence engines, and ule languages) could au oma e admin- is a ion asks and acili a e a lexible and scalable managemen o dynamic VOs. Finally, ou implemen ed PMI has been p o ed in a eal p ojec (PREDIRCAM). We ha e aced he in eg a ion o a legacy sys em wi h he PMI and he solu ion o he hi d use case was a success. To achie e his, he legacy sys em was adap ed o manage X.509 ce i ica es and be able o communica e wi h he whole PMI and p o ec ed esou ces, delega ing he access con ol o he no malized pla o m. REFERENCES [1] T. E l, SOA P inciples o Se ice Design. Englewood Cli s, NJ: P en ice-Hall, 2008. [2] The Open G oup. (2009). TOGAF, En e p ise edi ion, e sion 9. [Online]. A ailable: h p://www.openg oup.o g/a chi ec u e/ oga 9- doc/a ch/index.h ml. 8 IEEE TRANSACTIONS ON INFORMATION TECHNOLOGY IN BIOMEDICINE, VOL. 00, NO. 00, 2011 [3] I.Fos e ,C.Kesselman,andS.Tuecke, “The ana omy o he g id: Enabling scalable i ual o ganiza ions,” In . J. Supe compu . Appl., ol. 15, no. 3, pp. 200–222, 2001. [4] Heal h In o ma ics—P i ilege Managemen and Access Con ol,ISO 22600-1,2, 2006. [5] D. T i ella o, F. Spiessens, N. Zannone, and S. E alle, “POLIPO: Policies & On oLogies o in e ope abili y, po abili y, and au onomy,” in P oc. Policy, IEEE Compu . Soc., Jul., 2009, pp. 110–113. [6] N. Elahi, M. Chowdhu y, and J. Noll, “Seman ic access con ol in web based communi ies,” in P oc. 3 d In . Mul i-Con . Compu . Global In o m. Technol., Jul./Aug., 2008, pp. 131–136. [7] N. Zhang, L. Yao, A. Nenadic, J. Chin, C. Goble, A. Rec o , D. Chadwick, S. O enko, and Q. Shi, “Achie ing ine-g ained access con ol in i ual o ganiza ions,” Concu ency Compu .: P ac . Expe ., ol. 19, pp. 1333– 1352, 2007. [8] R. Sinno , D. Chadwick, T. Dohe y, D. Ma in, A. S ell, G. S ewa , L. Su, and J. Wa , “Ad anced secu i y o i ual o ganiza ions: The p os and cons o cen alized s decen alized secu i y models,” in P oc. 8 h IEEE In . Symp. Clus e Compu . G id, May, 2008, pp. 106–113. [9] H. B. Rahmouni, T. Solomonides, M. C. Mon , and S. Shiu, “On ology- based p i acy compliance on Eu opean heal hg id domains,” S ud. Heal h Technol. In o ma ., ol. 147, pp. 183–189, 2009. [10] I. Rom´ an, L. Roa, L. Reina, and G. Madinabei ia, “Demog aphic man- agemen in a ede a ed heal hca e en i onmen ,” In . J. Med. In ., ol. 75, no. 9, pp. 671–682, 2006. [11] D. K e ing, J. Ba , K. Be ono , O. Dzhimo a, J. Falkne , M. Ha ung, A. Hoheisel, T. Knoch, T. Lingne , Y. Mohammed, K. Pe e , E. Rahm, U. Sax, D. Somme eld, T. S einke, T. Tolxdo , M. Vossbe g, F. Viezens, and A. Weisbecke , “MediGRID: Towa ds a use iendly secu ed g id in as uc u e,” Fu u e Gene a . Compu . Sys ., ol. 25, no. 3, pp. 326– 336, 2009. [12] D. J. Powe , E. A. Poli ou, M. A. Slaymake , and A. C. Simpson, “Towa ds secu e g id-enabled heal hca e,” So w. – P ac ice Exp., ol. 35, no. 9, pp. 857–871, 2005. [13] D. Olmedilla, O. Rana, B. Ma hews, and W. Nejdl, “Secu i y and us issues in seman ic g ids,” in P oc. Dags hul Semin. Semi. G id: Con e - gence Technol., 2005, p. 05271. [14] In o ma ion Technology—Open Sys ems In e connec ion—Secu i y F amewo ks o Open Sys ems, ISO 10181-1,2, 1996. [15] The Di ec o y: Public-Key and A ibu e Ce i ica e F amewo ks, ITU-T Rec. X.509, 2008. [16] In e ne Secu i y Glossa y, RFC 4949, e sion 2, 2007. [17] Te minology o Policy-Based Managemen , RFC 3198, 2001. [18] OASIS. (2005). XACML 2.0 Co e, eX ensible Access Con ol Ma kup Language Ve sion 2.0, OASIS. [Online]. A ailable: h p://www.oasis- open.o g/commi ees/xacml. [19] S. Can o J. Kemp R. Philpo E. Male . (2005). Asse ions and p o ocols o he oasis secu i y asse ion ma kup language (SAML), 2.0, [On- line]. A ailable: h p://docs.oasis-open.o g/secu i y/saml/ 2.0/saml-co e- 2.0-os.pd . [20] Ligh weigh Di ec o y Access P o ocol, e sion 2, RFC 3494, 2003. [21] The Di ec o y: O e iew, ITU-T Rec. X.500, 2008. [22] Heal h In o ma ics—Sys em o Concep s o Suppo Con inui y o Ca e— Pa 1: Basic Concep s, Eu opean Commi ee o S anda diza ion, CEN/TC 251, EN 13940-1, 2006. [23] Heal h In o ma ics—Elec onic Heal h Reco d Communica ion—Pa 4: Secu i y, ISO 13606-4, 2007. [24] Heal h In o ma ics—Di ec o y Se ices o Secu i y, Communica ions and Iden i ica ion o P o essionals and Pa ien s, ISO 21091, 2005. [25] The Sys ema ized Nomencla u e o Medicine (SNOMED) [Online]. A ail- able: h p://www.ih sdo.o g/snomed-c /. [26] A. Rec o and W. Nowlan, “The GALEN p ojec ,” Compu . Me hods P og ams Biomed., ol. 45, no. 1–2, pp. 75–78, 1994. [27] OBO Found y. (2010, Jul.). “The open biological and biomedical on olo- gies,” [Online]. A ailable: h p://www.obo ound y.o g/. [28] Heal h In o ma ics – Se ice A chi ec u e, ISO 12967-1,2,3, 2008. [29] CORBAmed OMG. (2010, Jul.). HDTF s anda ds [Online]. A ailable: h p://heal hca e.omg.o g/Roadmap/co bamed_ oadmap.h m. [30] In o ma ion Technology—Open Dis ibu ed P ocessing—Re e ence Model, ISO 10746-1,2,3,4, 1998 (Re ised in 2010). [31] Globus Toolki Secu i y. (2010, Jul.). [Online]. A ailable: h p://www. globus.o g/ oolki /docs/la es -s able/secu i y/. [32] I. Fos e , C. Kesselman, L. Pea lman, S. Tuecke, and V. Welch, “The communi y au ho iza ion se ice: S a us and u u e,” p esen ed a he P oc. o he Compu . in High Ene gy Physics, La Jolla, CA, Ma . 2003. [33] R. Al ie i, R. Cecchini, V. Ciaschini, L. dell’Agnello, A. F ohne , K. Lo en ey, and F. Spa a o, “F om g idmap- ile o oms: Managing au ho iza ion in a g id en i onmen ,” Fu u e Gene a ion Comp. Sys ., ol. 21, no. 4, pp. 549–558, 2005. [34] Pe mis (p ojec unded by he ISIS p og am). (2010, Jul.). [Online]. A ail- able: h p://www.pe mis.o g/index.h ml. [35] P. Pa el-Schneide , P. Hayes, and I. Ho ocks. (2004). OWL web on- ology language seman ics and abs ac syn ax, [Online]. A ailable: h p://www.w3.o g/TR/owl-seman ics/. [36] T. Finin, A. Joshi, L. Kagal, J. Niu, R. Sandhu, W. Winsbo ough, and B. Thu aisingham, “ROWLBAC: Rep esen ing ole based access con ol in OWL,” in P oc. 13 h Symp. Access Con ol Models. Technol., Jun., 2008, pp. 73–82. [37] M. Knech el, J. Hladik, and F. Dau, “Using OWL DL easoning o de- cide abou au ho iza ion in RBAC,” in P oc. OWLED Wo kshop OWL: Expe iences and Di ec ions, 2008. [38] I. Ho ocks, P. Pa el-Schneide , H. Boley, S. Tabe , B. G oso , and M. Dean, 2004. SWRL: A seman ic web ule language combining OWL and RuleML, [Online]. A ailable: h p://www.w3.o g/Submission/ SWRL/ [39] H. Shen, “A seman ic-awa e a ibu e-based access con ol model o web se ices,” Lec . N. Compu . Sci., ol. 5574, pp. 693–703, 2009. [40] Jess Rule Engine. (2010, Jul.). [Online]. A ailable: h p://www.jess ules. com/jess/index.sh ml. [41] H. Knublauch, R. Fe ge son, N. Noy, and M. Musen, “The p o ´ eg´ eOWL plugin: An open de elopmen en i onmen o seman ic web applica- ions,” in P oc. 3 d In . Seman ic Web Con ., 2004, pp. 229–243. [42] P. He e o, M. E. He nando, L. Roa, E. G´ omez, and A. de Lei a, “PREDIRCAM: Technological pla o m o he p e en ion o diabe es melli us and ca dioMe abolic isk,” p esen ed a he 2nd Con . on Ad- anced Technologies and T ea men s o Diabe es, 2009, A hens, G eece. [43] CMS D upal. (2010, Jul.). [Online]. A ailable: h p://d upal.o g. [44] MDS. (2010, Jul.). [Online]. A ailable: h p://www.globus.o g/ oolki /mds/. [45] Login Ce i ica e Module. (2010, Jul.). [Online]. A ailable: h p://d upal.o g/p ojec /ce i ica elogin. [46] In o ma ion Technology—Open Dis ibu ed P ocessing—Re e ence Model—En e p ise Language, ISO 15414, 2006. [47] In o ma ion Technology—Open Dis ibu ed P ocessing—Use o UML o ODP Sys em Speci ica ions, ISO 19793, 2008. Au ho ’s pho og aphs and biog aphies no a ailable a he ime o publica ion.