@book{e88b6e1408be4761bd0819dc3c9aaeec,
title = "Audit-Based Access Control for Electronic Health Records",
abstract = "Traditional access control mechanisms aim to prevent illegal actions a-priori occurrence, i.e. before granting a request for a document. There are scenarios however where the security decision can not be made on the fly. For these settings we developed a language and a framework for a-posteriori access control. In this paper we show how the framework can be used in a practical scenario. In particular, we work out the example of an Electronic Health Record (EHR) system, we outline the full architecture needed for audit-based access control and we discuss the requirements and limitations of this approach concerning the underlying infrastructure and its users.",
keywords = "SCS-Cybersecurity, Distributed access control, Audit, Accountability",
author = "M.A.C. Dekker and S. Etalle",
year = "2006",
month = jul,
day = "1",
language = "English",
series = "CTIT Technical Report Series",
publisher = "Centre for Telematics and Information Technology (CTIT)",
number = "06-49",
address = "Netherlands",
}