Please use this identifier to cite or link to this item:
標題: 醫療行動計算環境中通訊安全之機制
Security Mechanisms for Network Communications in Medical Mobile Computing Environment
作者: 蕭宗志
Hsiao, Tsung-Chih
關鍵字: 整合式醫療資訊系統
出版社: 資訊科學與工程學系所
摘要: 由於現代醫療的進步和病患意識的抬頭,城市與地區之間的醫療資源分配出現不均衡情形;部份地區更因醫療資源不足,常造成病患就診的延誤。目前除了就診的醫院與診所外,仍需要解決部份醫療資源不足地區的問題。例如:高山、離島或偏遠地方,因資源分配較不完善,無法給予病患完善的醫療處理;若在時效和醫療資訊上,可以給予充分的醫療處理和資訊,可避免不必要的損害。 然而,現代醫院內部幾乎都擁有病歷管理中心,而這些病歷都具有法律保護和病患隱私權問題,因此,確保醫療相關資料可在網路上安全無虞的傳輸並保證醫療資訊的隱私性與完整性,需要運用驗證機制來確保這些隱私資訊不被非法人員所竊取。為了提供理想的醫療環境、醫療服務品質及保障照護人和被照護人的權利,完善的醫療行動計算環境是值得探討的議題。 因此,本文以三個面向來整合醫療行動環境,應用無線感測網路的技術和安全驗證機制結合存取控制來整合醫療行動計算環境。首先,以整合醫療環境的驗證機制,來抵抗各種惡意的網路攻擊,例如:通行碼猜測攻擊、重送攻擊或偽冒攻擊等。第二,利用智慧卡和通行碼的雙重認證方法,確保只有合法的醫護人員才可以擷取病患的生理資訊;以及結合時戳的特性,讓醫護人員只能在限定的時間內,不須再經過重覆登錄與認證過程,即可擷取病患的生理資訊,進而提高更好的醫療照護。最後,以階層式金鑰管理中的存取控制問題,解決組織中的金鑰產生及存取問題,同時管制資源和機密性檔案,進行有效權限的存取,避免個人的資料遭到未經授權的存取。
Due to modern medical advances and patient''s consciousness promotion, urban and countryside compete for the medical resources distribution that could cause the situation of medical material disequilibrium. With different situations and regions that could derive from the dissimilar medical environment and resource allocation problems, those issues caused some areas lack of medical materials. Besides, that also results in patient's treatment, such as medical treatment delays and resources distribution wastes. At present, except for hospitals and other dispensaries, people need not only to solve part of area's medical insufficient problems, but to maintain considerably medical standards and demands. For example, while patients are in dangerous conditions which need medical handling and remote districts, resources distribution issue and facilities establishment faultiness could cause patients' life-long injure and death. If people is given some medical recommendations or information in that moment, that could avoid unnecessary damages and death. A modern hospital owns the center of integrity medical record management. All of these medical records provided with law protection and patient privacy security. Therefore, for ensuring the relevance medical data could transmit safety on the Internet and guaranteeing those information's privacy and integrity. It requires authentication to ensure these privacy information not to be obtained by illegal person. The information should be protected includes the patient's treatment records and clinical diagnosis research, which related to patient's privacy. Therefore, this paper is divided into three aspects to integrate medical operational environments, the application of wireless sensor network technology and security authentication, which combined with access control to integrate the whole medical environment. First, using authentication to not only integrate medical environment, but to resist different kinds of malicious attacks, such as Password-guessing attack, Replay attack, Stolen-verifier attack or Impersonation attack. Second, the scheme, which includes a time-bounded characteristic that allows the verified staff to access data without the needs to re-authenticate and re-login into the system within a set period of time. Consequently, the time-bounded property also increases the work efficiency of the system administrators and users. Finally, using hierarchical key management to solve the problems of key production in the organization and the issues of access control; simultaneously, it controlled resources and confidential files to proceed the effectively access control to avoid personal information accessing without unauthorized. Therefore, it provides good medical service quality and takes care of patient's obligation to ensure the patient's family and patient's right. It will be worthy of topic for discussion to confer presently.
