|
As e-commerce / e-government development, network security, more and more people's attention, and the medical industry's peculiarities is for security put forward higher requirements. Public Key Infrastructure (PKI) is the more mature network security solution that provides for the electronic medical records of five main security features: authentication, access control, data confidentiality, data integrity, non-repudiation of data. Article surveys the literature, other methods of comparison to PKI / PMI system for analysis and studies described, first of all cryptographic techniques are described, and then introduced the PKI / PMI basic principles, including the architecture, the certificate data structure, system components, and model, the basic principles of careful study, based on the PKI / PMI trust and authorization services technology into Yunnan Province Chinese Medicine Hospital EHR system, designed based on PKI / PMI EHR authentication and authorization model. This design of PKI / PMI system strictly adhere to the X.509 protocol specification, and the model uses public key certificates and attribute certificates joint dual certificate access as a basic EHR implementation mechanism to attribute certificate for the carrier to achieve a centralized electronic medical records authentication and authorization management. CA model design will be placed outside the hospital, while the PMI attribute authority is placed within the hospital, in line with the actual situation of the hospital, cost savings, improve work efficiency. In this paper, the properties of the short period of validity of the certificate set thinking, reaching conserve server resources. Specifically, the main work of this paper are: 1, the overall structure of this system, authentication module, the authorization module, access control module, each module were designed in detail. 2, the authentication module, the authorization module, access control module workflow conducted in-depth discussion and study. 3, the authorization module in the various sub-function modules, AA management services, registration services ARA, attribute certificate application, revocation, renewal and other servers were designed in detail and description. The LDAP-based technology, the directory server design also made the appropriate introduction, the realization of a simple certificate storage and download functions. 4, for electronic medical records system security management, personnel management is also very important - ring, the paper also made on the issue of the relevant laws and regulations on the description of the contents. 5, the last of database security solutions to make a further elaboration. The system is in a certain range and extent to meet the information security of electronic medical records confidentiality, integrity and non-repudiation requirements, and thus facilitate the flexibility to implement electronic medical records security access control. Of PKI / PMI application examples developed in the medical industry, electronic medical records to obtain legal status, and to accelerate the promotion of electronic medical records systems of health information and provide a theoretical reference, has a very important meaning.
|