ENV 13608-3-2000 en Health Informatics - Security for Healthcare Communication - Part 3 Secure Data Channels《健康信息学 保健通讯安全性 第3部分 安全数据通道》.pdf
《ENV 13608-3-2000 en Health Informatics - Security for Healthcare Communication - Part 3 Secure Data Channels《健康信息学 保健通讯安全性 第3部分 安全数据通道》.pdf》由会员分享,可在线阅读,更多相关《ENV 13608-3-2000 en Health Informatics - Security for Healthcare Communication - Part 3 Secure Data Channels《健康信息学 保健通讯安全性 第3部分 安全数据通道》.pdf(25页珍藏版)》请在麦多课文档分享上搜索。
1、 STD-BSI DD ENV 13bO8-3-ENGL 2000 Lb24bb 0858L4 885 DRAFT FOR DEVELOPMENT Health informatics - Security for Healthcare communication - Part 3: Secure data channels ICs 35.240.80 NO COPYING WITHOUT BSI PERMISSION EXCEPT AS PERMITTED BY COPYRIGHT LAW DD ENV 13608-3 :ZOO0 National foreword been prepare
2、d under the Mon of the DISC Board, was published under the authority of the Standards Committee and comes into effect on 15 August 2000 bd. No. O BSI 082000 ISBN O 580 36486 7 This DE 18 Annex D (informative) Plaintext recovery . 21 Bibliography . 22 Page 3 ENV 13608-312000 Foreword This European Pr
3、estandard has been prepared by Technical Committee CENEC 25 1 “Health informatics“, the secretaxiat of which is held by SIS. According to the CENKENELEC Internal Regulations, the national standards organizations of the following countries are bound to announce this European Prestandard: Austria, Bel
4、gium, Czech Republic, Denmark, Finland, France, Germany, Greece, Iceland, Ireland, Italy, Luxembourg, Netherlands, Norway, Portugal, Spain, Sweden, Switzerland and the United Kingdom. This multipart standard consists of the following parts, under the general title Security for Healthcare Communicati
5、on (SEC-COM): - - - Part 1: Concepts and Terminology Part 2: Secure Data Objects Part 3: Secure Data Channels This standard is designed to meet the demands of the Technical Report CEN/TC251/N98-110 Informatics - Framework for security protection of health care communication. Health This standard was
6、 drafted using the conventions of the ISODEC directive Part 3. All annexes are informative. Introdwc tion The use of data processing and telecommunications in health care must be accompanied by appropriate security measures to ensure data confidentiality and integrity in compliance with the legal fr
7、amework, protecting patients as well as professional accountability and organizational assets. In addition, availability aspects are important to consider in many systems. In that sense, the SEC-COM series of standards has the intention of explaining and detailing to the healthcare end user the diff
8、erent alternatives they have to cope with in terms of security measures that might be implemented to fulfil their security needs and obligations. Incorporated within this is the standardization of some elements related to the information communication process where they fall within the security doma
9、in. In the continuity of the Framework for security protection of health care communication (CENEC25 1/N98- llO), hereafter denoted the Framework, whose CEN Report aimed at promoting a better understanding of the security issues in relations to the healthcare IT-communication, this European Restanda
10、rd shall aid in producing systems to enable health professionals and applications to communicate and interact securely and therefore safely, legitimately, lawfully and precisely. The SEC-COM series of standards are key communication security standards that can be generically applied to a wide range
11、of communication protocols and information system applications relevant to healthcare, though they are neither complete nor exhaustive in that respect. These standards must be defined within the context and scenarios defined by the TC251 work programme, in which the messaging paradigm for informatio
12、n system interaction is one of the essentials, as it was reflected by the Framework (Framework for security -protection of health care communication.) Page 4 ENV 13608-3:2000 Secure Data Channel This part 3 of the European Prestandard on Security for Healthcare Communication describes how to securel
13、y communicate arbitrary octet streams by means of a secure data channel communication protocol. NOTE NOTE This standard does not specify methods related to availability, storage or transportation of key certificates or other in-fra-structural issues, nor does it cover application security aspects su
14、ch as user authentication. A secure data channel is defined for the purposes of this standard as a reliable communication protocol that implements the following security services: 1. authentication of communicating entities prior to the communication of any other data preservation of data integrity
15、2. preservation of confidentiality of the communicated data. A secure data channel protocol operates in two distinct phases which, however, may be repeated: 1. 2. negotiation phase: authentication of communicating entities (e.g. exchange of Certificates), negotiation of the cipher suite to be used,
16、derivation of a shared secret using a key exchange algorithm communication phase: transmission of user data encrypted according to the negotiated cipher suite. In addition the secure data channel can be closed by either party when it is no longer required. The concept of a secure data channel can be
17、 best understood by looking at it?s properties, especially in comparison with the properties of a secure data object (prENV 13608-2, part 2 of this European Prestandard): 1. Interactivity: the negotiation phase allows the communicating entities to interactively agree upon a cipher suite that meets b
18、oth parties? security policies for the communication scenario in question (e.g. national vs. international communication). If the cipher suite negotiation is unsuccessful, no communication session is established. Transience: the secure data channel, being part of a layered communication protocol, re
19、ceives and delivers unsecured user data from and back to the calling layer. The encrypted representation of the data is transient (e.g. available only during transmission) and unavailable to the calling layer (e.g. application). Performance: after the establishment of the cipher suite and shared sec
20、ret during the negotiation phase, there is no need to use the computationally resource intensive asymmetric cryptographic algorithms during the communication phase. On the other hand, because of the transience of the encrypted representation of the data, encryption must be performed during the commu
21、nication process and cannot be pre-computed off-line. Forward secrecy: can be easily implemented as part of the key exchange protocol. Completeness: since the authentication of the communicating entities (e.g. certificate exchange) is part of the protocol, no additional out-of-band communication (e.
22、g. look-up of certificates in a trusted directory) is required to use the secure data channel, except if certificate revocation lists are used. Transparency: a secure data channel can be implemented such that it?s upper service access point resembles it?s lower service access point (e.g. TCP/IP sock
23、et interface). This allows the easy addition of security services to existing non-security-aware systems and protocols by integrating the secure data channel as an additional layer in the communication protocol stack. A well-known example for this approach is ?Secure HTP? (HTP over SSL3). 2. 3. 4. 5
24、. 6. The IETF Transport Layer Security (TLS) specification is a description of how to provide a secure data channel. Although TLS is an ETF Specification, it is not limited to TCP/IP. TLS only requires the presence of a reliable transmission protocol. This European Prestandard defines a set of profi
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ENV1360832000ENHEALTHINFORMATICSSECURITYFORHEALTHCARECOMMUNICATIONPART3SECUREDATACHANNELS 健康 信息学 保健 通讯

链接地址:http://www.mydoc123.com/p-727342.html