Writing Open Source SunXACML Access Control in
Electronic Health Record with Acceptable Performances
Snezana Sucurovic
1
and Dejan Simic
2
1
Institute Mihajlo Pupin, Volgina 15, 11 000 Belgrade, Serbia
2
Faculty of Organisational Sciences, Computer Science Department
Jove Ilica 154, 11 000 Belgrade, Serbia
Abstract. OASIS is a non–for-profit consortium that drives the development
convergence and adoption of open standards for the global information society.
It involves more than 600 organizations and individuals as well as IT leaders
Sun, Microsoft, IBM and Oracle. One of it’s standard is XACML which ap-
pears a few years ago and now there are about 150 000 hits on Google.
XACML (eXtensible Access Control Markup Language) is not technology re-
lated. Sun published in 2004 open source Sun XACML which is in compliance
with XACML 1.0. specification and now worked to be in compliance with
XACML 2.0. The heart of XACML are attributes values of defined type and
name that is to be attached to a subject, a resource, an action and an environ-
ment in which subject request action on resource. On that way XACML is to
replace Role Based Access Control which dominated for years. The paper ex-
amines performances in CEN 13 606 and ISO 22 600 based healthcare system
which use XACML for access control.
1 Related Work on using XACML
At the RSA 2008 Conference, members of the OASIS open standards consortium, in
cooperation with the Health Information Technologies Standards Panel (HITSP),
demonstrated interoperability of the Extensible Access Control Markup Language
(XACML) version 2.0. Simulating a real world scenario provided by the U.S. De-
partment of Veterans Affairs, the demo showed how XACML ensures successful
authorization decision requests and the exchange of authorization policies. The
XACML Interop at the RSA 2008 conference utilizes requirements from Health Lev-
el Seven (HL7), ASTM International, and the American National Standards Institute
(ANSI). The demo features role-based access control (RBAC), privacy protections,
structured and functional roles, consent codes, emergency overrides and filtering of
sensitive data. Vendors show how XACML obligations can provide capabilities in the
policy decision making process. The use of XACML obligations and identity provid-
ers using the Security Assertion Markup Language (SAML) are also highlighted.
According to the ANSI/HITSP announcement, the multi-vendor demonstrations
"highlight the use of OASIS standards in HITSP-approved guidelines, known as
Sucurovic S. and Simic D. (2009).
Writing Open Source SunXACML Access Control in Electronic Health Record with Acceptable Performances .
In Proceedings of the 1st International Workshop on Open Source in European Health Care: The Time is Ripe, pages 59-68
DOI: 10.5220/0001813400590068
Copyright
c
SciTePress