DOI QR코드

DOI QR Code

Security Requirements of Personal Health Service

개인건강서비스를 위한 보안 요구사항

  • Received : 2015.11.30
  • Accepted : 2015.12.08
  • Published : 2015.12.31

Abstract

When the variety of personal health services are provided in the ICBM(IoT, Cloud, Bigdata, and Mobile) environment, the security requirements of personal health service(PHS) including privacy issues is proposed in this paper. Because it is expected that the services related to personal health are provided in the cloud environment, the security requirements of a cloud environment is firstly investigated and then security threats including direct and indirect threats in a cloud environment are analyzed in terms of the security of PHS. In addition, the security requirements of PHS is developed based on the security requirements of electronic medical record(EMR) for medical service in this paper, then the validity of the proposed security requirements is shown by the relation between security requirements of cloud environment and PHS to indicate that a security requriement is supported by several security requirements of PHS.

본 논문에서는 다양한 형태의 개인건강서비스들이 ICBM(사물인터넷, 클라우드, 빅데이터, 및 모바일) 환경에서 제공될 때, 프라이버시 이슈를 포함하여 개인건강서비스에 대한 보안 요구사항이 제안된다. 개인건강과 연관된 서비스들은 클라우드 환경에서 제공될 것이 예상되므로, 우선적으로 클라우드 환경의 보안 요구사항에 대해 조사한 후, 클라우드 환경에서의 직접적인 위협과 간접적인 위협을 포함한 보안 위협을 개인건강서비스의 보안 관점에서 분석한다. 그리고 본 논문에서 의료서비스를 위한 전자의료기록(EMR)에 대한 보안 요구사항에 기반을 두고 개인건강서비스를 위한 보안 요구사항을 도출한 뒤, 클라우드 환경의 보안요구사항이 개인건강서비스의 보안요구사항에 의해 충족될 수 있음을 나타내는 관계를 보임으로서 제안된 개인건강서비스에 대한 보안 요구사항의 타당성을 제시한다.

Keywords

References

  1. Population Ageing: "1950-2050", UN, http://www.un.org
  2. Health Informatics-Personal Health Device Communication, ISO/IEEE 11073. Available: http://standards.ieee.org
  3. Health Informatics-Personal Health Device Communication Part 20601: Application Profile-Optimized Exchange Protocol. ISO/IEEE Std. 11073-20601-2008
  4. Health Informatics-Personal Health Device Communication Part 20601: Application Profile-Optimized Exchange Protocol Amendment 1. ISO/IEEE Std. 11073-20601a-2010
  5. Health Informatics-Personal Health Device Communication Part 10415: Device Specialization-Weighing Scale. ISO/IEEE Std. 11073-10415-2010
  6. Health Informatics-Personal Health Device Communication Part 10408: Device Specialization-Thermometer. ISO/IEEE Std. 11073-10408-2010
  7. Health Informatics-Personal Health Device Communication Part 10407: Device Specialization-Blood Pressure Monitor. ISO/IEEE Std. 11073-10407-2010
  8. Health Informatics-Personal Health Device Communication Part 10417: Device Specialization-Glucose Meter. ISO/IEEE Std. 11073-10417-2010
  9. Health Informatics-Personal Health Device Communication Part 10406: Device Specialization-Basic Electrocardiograph. ISO/IEEE Std. 11073-10406-2011
  10. Health Informatics-Personal Health Device Communication Part 10471: Device Specialization-Independent Living Activity Hub. ISO/IEEE Std. 11073-10471-2008
  11. Continua Health Alliance. Available: http://www.continuaalliance.org
  12. "Information technology-Cloud computing-R eference architecture," Recommendation ITU-T Y.3502, 2014
  13. "Security framework for cloud computing," Recommendation ITU-T X.1601, 2014
  14. Chanwoo Lee, Sangkon Kim, Youngmin Yeo, Jongsub Moon, "Proposal of Security Requirem ents based on Layers and Roles for the Standar dization of Cloud Computing Security Technology," Journal of Security Engineering, Vol.10, No. 4, pp. 473-488, 2013
  15. Youngmin Yeo, Chanwoo Lee, Jongsub Moon, "Proposal of Security Requirements for the Cl oud Storage Virtualization System," Journal of The Korea Institute of Information Security & Cryptology, Vol.23, No.6, pp.1247-1257, 2013 https://doi.org/10.13089/JKIISC.2013.23.6.1247
  16. "Technical Privacy and Security Requirement for Personal Health Record,", TTA, TTAK.KO-10.0304, 2008

Cited by

  1. 의료 빅 데이터의 활용과 인간공학적 의미에 대한 문헌연구 vol.37, pp.2, 2015, https://doi.org/10.5143/jesk.2018.37.2.143
  2. 질환별 의료영상정보 뷰어 매칭 시스템의 구축 vol.20, pp.5, 2019, https://doi.org/10.7472/jksii.2019.20.5.37