ASTM E1762-1995(2009) Standard Guide for Electronic Authentication of Health Care Information《医疗保健信息的电子鉴定用的标准指南》.pdf
《ASTM E1762-1995(2009) Standard Guide for Electronic Authentication of Health Care Information《医疗保健信息的电子鉴定用的标准指南》.pdf》由会员分享,可在线阅读,更多相关《ASTM E1762-1995(2009) Standard Guide for Electronic Authentication of Health Care Information《医疗保健信息的电子鉴定用的标准指南》.pdf(16页珍藏版)》请在麦多课文档分享上搜索。
1、Designation: E 1762 95 (Reapproved 2009)An American National StandardStandard Guide forElectronic Authentication of Health Care Information1This standard is issued under the fixed designation E 1762; the number immediately following the designation indicates the year oforiginal adoption or, in the c
2、ase of revision, the year of last revision. A number in parentheses indicates the year of last reapproval. Asuperscript epsilon () indicates an editorial change since the last revision or reapproval.1. Scope1.1 This guide covers:1.1.1 Defining a document structure for use by electronicsignature mech
3、anisms (Section 4),1.1.2 Describing the characteristics of an electronic signa-ture process (Section 5),1.1.3 Defining minimum requirements for different elec-tronic signature mechanisms (Section 5),1.1.4 Defining signature attributes for use with electronicsignature mechanisms (Section 6),1.1.5 Des
4、cribing acceptable electronic signature mecha-nisms and technologies (Section 7),1.1.6 Defining minimum requirements for user identifica-tion, access control, and other security requirements for elec-tronic signatures (Section 9), and1.1.7 Outlining technical details for all electronic signaturemech
5、anisms in sufficient detail to allow interoperability be-tween systems supporting the same signature mechanism(Section 8 and Appendix X1-Appendix X4).1.2 This guide is intended to be complementary to standardsunder development in other organizations. The determinationof which documents require signa
6、tures is out of scope, since itis a matter addressed by law, regulation, accreditation stan-dards, and an organizations policy.1.3 Organizations shall develop policies and procedures thatdefine the content of the medical record, what is a documentedevent, and what time constitutes event time. Organi
7、zationsshould review applicable statutes and regulations, accreditationstandards, and professional practice guidelines in developingthese policies and procedures.2. Referenced Documents2.1 ISO Standards:ISO 9594-8 1993: The Directory: Authentication Frame-work (also available as ITU-S X.509)2ISO 882
8、5-1 1993: Specification of Basic Encoding Rulesfor ASN.12ISO 7816 1993: IC Cards with Contacts2ISO 10036 1994: Contactless IC Cards22.2 ANSI Standards:ANSI X9.30 Part 3: Certificate Management for DSA,November 1994 (ballot copy)3ANSI X9.31 Part 3: Certificate Management for RSA, July1994 (draft)3ANS
9、I X9.31 Part 1: RSA Signature Algorithm, July 1994(ballot copy) (technically aligned with ISO/IEC 9796)3ANSI X9.30 Part 1: Digital Signature Algorithm, July 1994(ballot copy) (technically aligned with NIST FIPS PUB186)3ANSI X9F1, ANSI X9.45: Enhanced Management ControlsUsing Attribute Certificates,
10、September 1994 (draft)32.3 Other Standards:FIPS PUB 112: Standards on Password Usage, May 19854FIPS PUB 181: Secure Hash Standard, 1994 (technicallyaligned with ANSI X9.301)4FIPS PUB 186: Digital Signature Standard, 1994 (techni-cally aligned with ANSI X9.301)4PKCS #1: RSA Encryption Standard (versi
11、on 1.5), Novem-ber 19935PKCS #5: Password-Based Encryption Standard, 19945PKCS #7: Cryptographic Message Syntax Standard, 199453. Terminology3.1 Definitions:3.1.1 access controlthe prevention of unauthorized use ofa resource, including the prevention of use of a resource in anunauthorized manner.3.1
12、.2 accountabilitythe property that ensures that theactions of an entity may be traced uniquely to the entity.3.1.3 attributea piece of information associated with theuse of a document.1This guide is under the jurisdiction of ASTM Committee E31 on HealthcareInformatics and is the direct responsibilit
13、y of Subcommittee E31.25 on HealthcareData Management, Security, Confidentiality, and Privacy.Current edition approved April 1, 2009. Published September 2009. Originallyapproved in 1995. Last previous edition approved in 2003 as E 176295 (2003).2Available from ISO, 1 Rue de Varembe, Case Postale 56
14、, CH 1211, Geneve,Switzerland.3Available from American National Standards Institute (ANSI), 25 W. 43rd St.,4th Floor, New York, NY 10036, http:/www.ansi.org.4Available from National Institute of Standards and Technology (NIST), 100Bureau Dr., Stop 1070, Gaithersburg, MD 20899-1070, http:/www.nist.go
15、v.5Available from RSA Data Security, 100 Marine Parkway, Redwood City, CA64065.1Copyright ASTM International, 100 Barr Harbor Drive, PO Box C700, West Conshohocken, PA 19428-2959, United States.3.1.4 attribute certificatea digitally signed data structurethat binds a user to a set of attributes.3.1.5
16、 authorizationverification that an electronicallysigned transaction is acceptable according to the rules andlimits of the parties involved.3.1.6 authorization certificatean attribute certificate inwhich the attributes indicate constraints on the documents theuser may digitally sign.3.1.7 availabilit
17、ythe property of being accessible anduseable upon demand by an authorized entity.3.1.8 computer-based patient record (CPR)the computer-based patient record is a collection of health informationconcerning one person linked by one or more identifiers. In thecontext of this guide, this term is synonymo
18、us with electronicpatient record and electronic health record.3.1.9 computer-based patient record system (CPRS)theCPRS uses the information of the CPR and performs theapplication functions according to underlying processes and itsinteracting with related data and knowledge bases. CPRS issynonymous w
19、ith electronic patient record systems.3.1.10 data integritythe property that data has not beenaltered or destroyed in an unauthorized manner.3.1.11 data origin authenticationcorroboration that thesource of data received is as claimed.3.1.12 digital signaturedata appended to, or a crypto-graphic tran
20、sformation of, a data unit that allows a recipient ofthe data unit to prove the source and integrity of the data unitand protect against forgery, for example, by the recipient.3.1.13 document access timethe time(s) when the subjectdocument was accessed for reading, writing, or editing.3.1.14 documen
21、t attributean attribute describing a char-acteristic of a document.3.1.15 document creation timethe time of the creation ofthe subject document.3.1.16 document editing timethe time(s) of the editing ofthe subject document.3.1.17 domaina group of systems that are under control ofthe same security aut
22、hority.3.1.18 electronic documenta defined set of digital infor-mation, the minimal unit of information that may be digitallysigned.3.1.19 electronic signaturethe act of attaching a signatureby electronic means.After the electronic signature process, it isa sequence of bits associated with an electr
23、onic document,which binds it to a particular entity.3.1.20 event timethe time of the documented event.3.1.21 one-way hash functiona function that maps stringsof bits to fixed-length strings of bits, satisfying the followingtwo properties:3.1.21.1 It is computationally infeasible to find for a giveno
24、utput an input that maps to this output.3.1.21.2 It is computationally infeasible to find for a giveninput a second input that maps to the same output.3.1.22 private keya key in an asymmetric algorithm; thepossession of this key is restricted, usually to one entity.3.1.23 public keya key in an asymm
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
5000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ASTME176219952009STANDARDGUIDEFORELECTRONICAUTHENTICATIONOFHEALTHCAREINFORMATION 医疗保健 信息 电子 鉴定 标准 指南

链接地址:http://www.mydoc123.com/p-529409.html