XML 기반 PHI를 휴대하기 위한 프라이버시 보안

서효정1), 방대욱*2), 김윤년3), 윤경일4), 박명화5)

1)계명대학교 대학원 컴퓨터공학과
2)계명대학교 정보통신대학 컴퓨터공학과
3)계명대학교 의과대학 내과학교실
4)계명대학교 의과대학 의료정보학교실
5)계명대학교 간호대학 간호학과

Abstract : The purpose of this study was to design a specification of privacy security for a XML-based PHI, MyPHR. MyPHR document has a root element, MyPhr, with two child elements, MyPhrHeader and MyPhrBody. MyPhrHeader element has management information of itself, and MyPhrBody element includes one or more MyPhrModules which represent their own type of health record. MyPHR guarantees privacy security through access control and encryption specification that can be processed only by its management system. It has elements representing access control lists within MyPhr document and permits to encrypt elements representing private information by using XML Encryption. Private information of MyPHR document is included within both protectedInfo element of MyPhrHeader and MyPhtBody element. This study identified that privacy security is guaranteed by two security mechanisms, encryption and access control. Encryption hides private information from all persons excepting the person who has the security key, and access control protects unauthorized access of private information.
keyword : personal health record, privacy security, encryption, access control


Copyright (c) 2002 by The Korean Society of Medical Informatics