ASTM E2212 - 02a(2010) Standard Practice for Healthcare Certificate Policy (Withdrawn 2017).pdf
《ASTM E2212 - 02a(2010) Standard Practice for Healthcare Certificate Policy (Withdrawn 2017).pdf》由会员分享,可在线阅读,更多相关《ASTM E2212 - 02a(2010) Standard Practice for Healthcare Certificate Policy (Withdrawn 2017).pdf(21页珍藏版)》请在麦多课文档分享上搜索。
1、Designation: E2212 02a (Reapproved 2010) An American National StandardStandard Practice forHealthcare Certificate Policy1This standard is issued under the fixed designation E2212; the number immediately following the designation indicates the year oforiginal adoption or, in the case of revision, the
2、 year of last revision. A number in parentheses indicates the year of last reapproval. Asuperscript epsilon () indicates an editorial change since the last revision or reapproval.1. Scope1.1 This practice covers a policy (“the policy”) for digitalcertificates that support the authentication, authori
3、zation,confidentiality, integrity, and nonrepudiation requirements ofpersons and organizations that electronically create, disclose,receive, or otherwise transact health information.1.2 This practice defines a policy for three classes ofcertificates: (1) entity certificates issued to computing compo
4、-nents such as servers, devices, applications, processes, oraccounts reflecting role assignment; (2) basic individual cer-tificates issued to natural persons involved in the exchange ofhealth information used for healthcare provisioning; and (3)clinical individual certificates issued to natural pers
5、ons andused for authentication of prescriptive orders relating to theclinical treatment of patients.1.3 The policy defined by this practice covers: (1) definitionof healthcare certificates, healthcare certification authorities,healthcare subscribers, and healthcare relying parties; (2)appropriate us
6、e of healthcare certificates; (3) general condi-tions for the issuance of healthcare certificates; (4) healthcarecertificate formats and profile; and (5) requirements for theprotection of key material.1.4 The policy establishes minimum responsibilities forhealthcare certification authorities, relyin
7、g parties, and certifi-cate subscribers.2. Referenced Documents2.1 ASTM Standards:2E2084 Specification for Authentication of Healthcare Infor-mation Using Digital Signatures (Withdrawn 2009)3E2086 Guide for Internet and Intranet Healthcare Security(Withdrawn 2009)32.2 Other Documents:Public Law 104-
8、191, Aug. 21, 1996, Health Insurance Por-tability and Accountability Act of 19964RFC 2527Internet X.509 Public Key Infrastructure Cer-tificate Policy and Certification Practices Frame-work, PKIX Working Group Internet Draft, January 3,20025RFC 2560Internet X.509 Public Key Infrastructure OnlineCerti
9、ficate Status Protocol, OCSP, June 199963. Terminology3.1 Certificate and Related TermsA certificate, also re-ferred to as a digital certificate or public key certificate, bindsa public key value to information identifying the entityassociated with the use of a corresponding private key. Anentity ma
10、y be an individual, organization, account, role,computer process, or device. The entity identified within thecertificate is referred to as the certificate subject. The certificateis typically used to verify the digital signature of the certificatesubject or to encrypt information for that subject. T
11、he reliabil-ity of the binding of a public key to a certificate subject isasserted by the certification authority (CA) that creates, issues,and distributes certificates. Certification authority is synony-mous with certificate authority. Parties that depend on theaccuracy of information in the certif
12、icate are referred to asrelying parties. Certificate users are the collective relyingparties and subscribers.3.2 Certificate Policy:3.2.1 The X.509 standard defines a certificate policy (CP) as“a named set of rules that indicates the applicability of acertificate to a particular community and/or cla
13、ss of applicationwith common security requirements.” For example, a particularcertificate policy might indicate the type of certificate appli-cable for authenticating electronic data interchange transac-tions for the trading of goods within a specified price range. Incontrast, Practice E2212 address
14、es rules for certificates thatsupport the authentication, authorization, confidentiality,integrity, and nonrepudiation requirements of persons andorganizations that electronically create, disclose, receive, orotherwise transact health information.1This practice is under the jurisdiction of ASTM Comm
15、ittee E31 on HealthcareInformatics, and is the direct responsibility of Subcommittee E31.25 on HealthcareData Management, Security, Confidentiality, and Privacy.Current edition approved March 1, 2010. Published August 2010. Originallyapproved in 2002. Last previous edition approved in 2002 as E22120
16、2a. DOI:10.1520/E2212-02AR10.2For referenced ASTM standards, visit the ASTM website, www.astm.org, orcontact ASTM Customer Service at serviceastm.org. For Annual Book of ASTMStandards volume information, refer to the standards Document Summary page onthe ASTM website.3The last approved version of th
17、is historical standard is referenced onwww.astm.org.4Available at http:/aspe.hhs.gov/admnsimp/pl104191.htm.5Available at www.ietf.org/html.charters/pkix-charter.html.6Available at http:/www.ietf.org/rfc/rfc2560.txt.Copyright ASTM International, 100 Barr Harbor Drive, PO Box C700, West Conshohocken,
18、PA 19428-2959. United StatesNOTICE: This standard has either been superseded and replaced by a new version or withdrawn.Contact ASTM International (www.astm.org) for the latest information13.2.2 Certificates contain a registered certificate policy ob-ject identifier (OID) that the relying party may
19、use to decidewhether a certificate may be trusted for a particular purpose.The OID registration process follows the procedures specifiedin ISO/IEC and ITU standards. The party that registers the OIDalso publishes the CP for examination by certificate users andother parties. Each certificate should r
20、efer to a CP, but may alsorefer to additional nonconflicting CP.3.2.3 Certificate policies constitute a basis for accreditingCA. Certificate policies are also used to establish a trustrelationship between two or more CA (cross-certification).When CA issue cross-certificates, one CA assesses and reco
21、g-nizes the relevant certificate policies of the other CA.3.3 Certification Practice StatementThe term certificationpractice statement (CPS) is defined in the Internet X.509 PublicKey Infrastructure Certificate Policy and Certificate PracticesFramework as “a statement of the practices, which a certi
22、fica-tion authority employs in issuing certificates.” The CPS isdifferentiated from the CP in the same way that any policy isdifferent from a practice statement. The CPS is a comprehen-sive description by the CA of the methods, components, andprocedures it has elected to implement and which define h
23、owit conducts itself throughout the certificate life cycle. A CAwith a single CPS may support multiple certificate policies ifthe certificates it issues will be used for different applicationpurposes or by different certificate user communities, or both.Any number of CA, with unique CPS, may support
24、 the samecertificate policy.3.4 Relationship Between a Certificate Policy and a Certi-fication Practice Statement:3.4.1 A certificate policy assigns responsibilities to variousparticipants in a public key infrastructure (PKI). These respon-sibilities may be stated in differential levels of specifici
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
5000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ASTM E2212 02 2010 Standard Practice for Healthcare Certificate Policy Withdrawn 2017

链接地址:http://www.mydoc123.com/p-287075.html