BS EN 12251-2004 Health informatics - Secure user identification for health care - Management and security of authentication by passwords《健康信息学 保健的安全使用者识别 使用密码校验的管理和安全》.pdf
《BS EN 12251-2004 Health informatics - Secure user identification for health care - Management and security of authentication by passwords《健康信息学 保健的安全使用者识别 使用密码校验的管理和安全》.pdf》由会员分享,可在线阅读,更多相关《BS EN 12251-2004 Health informatics - Secure user identification for health care - Management and security of authentication by passwords《健康信息学 保健的安全使用者识别 使用密码校验的管理和安全》.pdf(16页珍藏版)》请在麦多课文档分享上搜索。
1、BRITISH STANDARD BS EN 12251:2004 Health informatics Secure user identification for health care Management and security of authentication by passwords The European Standard EN 12251:2004 has the status of a British Standard ICS 35.240.80 BS EN 12251:2004 This British Standard was published under the
2、 authority of the Standards Policy and Strategy Committee on 3 September 2004 BSI 3 September 2004 ISBN 0 580 44406 6 National foreword This British Standard is the official English language version of EN 12251:2004. It supersedes DD ENV 12251:2001 which is withdrawn. The UK participation in its pre
3、paration was entrusted to Technical Committee IST/35, Health informatics, which has the responsibility to: A list of organizations represented on this committee can be obtained on request to its secretary. Cross-references The British Standards which implement international or European publications
4、referred to in this document may be found in the BSI Catalogue under the section entitled “International Standards Correspondence Index”, or by using the “Search” facility of the BSI Electronic Catalogue or of British Standards Online. This publication does not purport to include all the necessary p
5、rovisions of a contract. Users are responsible for its correct application. Compliance with a British Standard does not of itself confer immunity from legal obligations. aid enquirers to understand the text; present to the responsible international/European committee any enquiries on the interpretat
6、ion, or proposals for change, and keep the UK interests informed; monitor related international and European developments and promulgate them in the UK. Summary of pages This document comprises a front cover, an inside front cover, the EN title page, pages 2 to 13 and a back cover. The BSI copyright
7、 notice displayed in this document indicates when the document was last issued. Amendments issued since publication Amd. No. Date CommentsEUROPEANSTANDARD NORMEEUROPENNE EUROPISCHENORM EN12251 August2004 ICS35.240.80 Englishversion HealthinformaticsSecureUserIdentificationforHealthCare Managementand
8、SecurityofAuthenticationbyPasswords InformatiquedesantScuritdelidentificationde lutilisateurdessoinsdesantGestionetscuritde lauthentificationdesmotsdepasse MedizinischeInformatikSichereNutzeridentifikationim GesundheitswesenManagementundSicherheitfrdie AuthentifizierungdurchPasswrter ThisEuropeanSta
9、ndardwasapprovedbyCENon21June2004. CENmembersareboundtocomplywiththeCEN/CENELECInternalRegulationswhichstipulatetheconditionsforgivingthisEurope an Standardthestatusofanationalstandardwithoutanyalteration.Uptodatelistsandbibliographicalreferencesconcernings uchnational standardsmaybeobtainedonapplic
10、ationtotheCentralSecretariatortoanyCENmember. ThisEuropeanStandardexistsinthreeofficialversions(English,French,German).Aversioninanyotherlanguagemadebytra nslation undertheresponsibilityofaCENmemberintoitsownlanguageandnotifiedtotheCentralSecretariathasthesamestatusast heofficial versions. CENmember
11、sarethenationalstandardsbodiesofAustria,Belgium,Cyprus,CzechRepublic,Denmark,Estonia,Finland,France, Germany,Greece,Hungary,Iceland,Ireland,Italy,Latvia,Lithuania,Luxembourg,Malta,Netherlands,Norway,Poland,Portugal, Slovakia, Slovenia,Spain,Sweden,SwitzerlandandUnitedKingdom. EUROPEANCOMMITTEEFORSTA
12、NDARDIZATION COMITEUROPENDENORMALISATION EUROPISCHESKOMITEEFRNORMUNG ManagementCentre:ruedeStassart,36B1050Brussels 2004CEN Allrightsofexploitationinanyformandbyanymeansreserved worldwideforCENnationalMembers. Ref.No.EN12251:2004:EEN 12251:2004 (E) 2 Contents page Foreword3 Introduction .4 1 Scope 5
13、 2 Normative references 5 3 Terms and definitions .5 4 Requirements.6 4.1 Unique identification and authentication 6 4.2 Identification and authentication prior to all other interactions .6 4.3 Associating unique identity with users.6 4.4 Maintaining the identity of active users 6 4.5 Log-on message
14、 7 4.6 Number of log-on trials .7 4.7 Incorrectly performed log-on procedure.7 4.8 Display of log-on statistics .7 4.9 Password sharing7 4.10 Password storage7 4.11 Logging of passwords 8 4.12 Password display suppression8 4.13 User-changeability of passwords 8 4.14 Default passwords.8 4.15 Initiali
15、sed passwords 8 4.16 Temporary passwords 8 4.17 Password expiration8 4.18 Password expiration notification .8 4.19 Password reuse .9 4.20 Password complexity 9 Annex A (informative) Potential password complexity requirements .10 Annex B (informative) User responsibilities.11 Annex C (informative) Pa
16、ssword communication .12 Bibliography 13 EN 12251:2004 (E) 3 Foreword This document (EN 12251:2004) has been prepared by Technical Committee CEN/TC 251 “Health informatics”, the secretariat of which is held by SIS. This European Standard shall be given the status of a national standard, either by pu
17、blication of an identical text or by endorsement, at the latest by February 2005, and conflicting national standards shall be withdrawn at the latest by February 2005. This document supersedes ENV 12251:2000. This document is designed to improve the authentication of individual users of health care
18、IT system, by strengthening the automatic software procedures associated with the management of user identifiers and passwords, without resorting to additional hardware facilities. Although the use of passwords, and the need for improved security in this respect, is by no means specific for the Heal
19、th Care field, it is felt strongly that the way in which systems are being used in this field, often in direct support of patient care and handling very sensitive information, urgently call for a good solution in this area. However, the methods specified in this document can possibly be applied in o
20、ther sectors as well at the discretion of users. According to the CEN/CENELEC Internal Regulations, the national standards organizations of the following countries are bound to implement this European Standard: Austria, Belgium, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Gre
21、ece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Slovakia, Slovenia, Spain, Sweden, Switzerland and United Kingdom. EN 12251:2004 (E) 4 Introduction Information Technology (IT) systems in the health care environment are being used in
22、 increasingly sensitive and critical circumstances. To facilitate secure access control to an IT system and within an IT system, it is essential to uniquely establish the identity of all users seeking access. Further, to have confidence that a user really is who he or she claims to be, there is a ne
23、ed for secure means of verifying the claimed identity. The use of passwords, being confidential to each user, and constructed in such a way that others cannot compromise this confidential authentication information easily, is the most common means of authentication in current computer systems, and w
24、ill be so for some time to come. This document can facilitate the wider process of Security Management. Conventional passwords have several disadvantages. Some of these are: They can easily be shared among several users The use of unprotected network technology makes them easy targets for eavesdropp
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- BSEN122512004HEALTHINFORMATICSSECUREUSERIDENTIFICATIONFORHEALTHCAREMANAGEMENTANDSECURITYOFAUTHENTICATIONBYPASSWORDS

链接地址:http://www.mydoc123.com/p-570192.html