Audited credential delegation: a usable security solution for the virtual physiological human toolkit

作者:Haidar Ali N; Zasada Stefan J; Coveney Peter V*; Abdallah Ali E; Beckles Bruce; Jones Mike A S
来源:Interface Focus, 2011, 1(3): 462-473.
DOI:10.1098/rsfs.2010.0026

摘要

We present applications of audited credential delegation (ACD), a usable security solution for authentication, authorization and auditing in distributed virtual physiological human (VPH) project environments that removes the use of digital certificates from end-users' experience. Current security solutions are based on public key infrastructure (PKI). While PKI offers strong security for VPH projects, it suffers from serious usability shortcomings in terms of end-user acquisition and management of credentials which deter scientists from exploiting distributed VPH environments. By contrast, ACD supports the use of local credentials. Currently, a local ACD username-password combination can be used to access grid-based resources while Shibboleth support is underway. Moreover, ACD provides seamless and secure access to shared patient data, tools and infrastructure, thus supporting the provision of personalized medicine for patients, scientists and clinicians participating in e-health projects from a local to the widest international scale.

  • 出版日期2011-6-6