Back to Search Start Over

Model-based security analysis of the German health card architecture.

Authors :
Jürjens, J.
Rumm, R.
Jürjens, J
Source :
Methods of Information in Medicine; 2008, Vol. 47 Issue 5, p409-416, 8p, 5 Diagrams
Publication Year :
2008

Abstract

<bold>Objectives: </bold>Health-care information systems are particularly security-critical. In order to make these applications secure, the security analysis has to be an integral part of the system design and IT management process for such systems.<bold>Methods: </bold>This work presents the experiences and results from the security analysis of the system architecture of the German Health Card, by making use of an approach to model-based security engineering that is based on the UML extension UMLsec. The focus lies on the security mechanisms and security policies of the smart-card-based architecture which were analyzed using the UMLsec method and tools.<bold>Results: </bold>Main results of the paper include a report on the employment of the UMLsec method in an industrial health information systems context as well as indications of its benefits and limitations. In particular, two potential security weaknesses were detected and countermeasures discussed.<bold>Conclusions: </bold>The results indicate that it can be feasible to apply a model-based security analysis using UMLsec to an industrial health information system like the German Health Card architecture, and that doing so can have concrete benefits (such as discovering potential weaknesses, and an increased confidence that no further vulnerabilities of the kind that were considered are present). [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
00261270
Volume :
47
Issue :
5
Database :
Complementary Index
Journal :
Methods of Information in Medicine
Publication Type :
Academic Journal
Accession number :
35179879
Full Text :
https://doi.org/10.3414/ME9122