{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,20]],"date-time":"2026-04-20T10:22:43Z","timestamp":1776680563605,"version":"3.51.2"},"reference-count":29,"publisher":"Association for Computing Machinery (ACM)","issue":"2s","license":[{"start":{"date-parts":[[2021,5,18]],"date-time":"2021-05-18T00:00:00Z","timestamp":1621296000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Multimedia Comput. Commun. Appl."],"published-print":{"date-parts":[[2021,6,21]]},"abstract":"<jats:p>e-Health applications enable one to acquire, process, and share patient medical data to improve diagnosis, treatment, and patient monitoring. Despite the undeniable benefits brought by the digitization of health systems, the transmission of and access to medical information raises critical issues, mainly related to security and privacy. While several security mechanisms exist that can be applied in an e-Health system, they may not be adequate due to the complexity of involved workflows, and to the possible inherent correlation among health-related concepts that may be exploited by unauthorized subjects. In this article, we propose a novel methodology for the validation of security and privacy policies in a complex e-Health system, that leverages a formal description of clinical workflows and a semantically enriched definition of the data model used by the workflows, in order to build a comprehensive model of the system that can be analyzed with automated model checking and ontology-based reasoning techniques. To validate the proposed methodology, we applied it to two case studies, subjected to the directives of the EU GDPR regulation for the protection of health data, and demonstrated its ability to correctly verify the fulfillment of desired policies in different scenarios.<\/jats:p>","DOI":"10.1145\/3412373","type":"journal-article","created":{"date-parts":[[2021,5,18]],"date-time":"2021-05-18T14:43:16Z","timestamp":1621348996000},"page":"1-22","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":12,"title":["A Security and Privacy Validation Methodology for e-Health Systems"],"prefix":"10.1145","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5128-5558","authenticated-orcid":false,"given":"Flora","family":"Amato","sequence":"first","affiliation":[{"name":"University of Naples Federico II, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Valentina","family":"Casola","sequence":"additional","affiliation":[{"name":"University of Naples Federico II, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giovanni","family":"Cozzolino","sequence":"additional","affiliation":[{"name":"University of Naples Federico II, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alessandra","family":"De Benedictis","sequence":"additional","affiliation":[{"name":"University of Naples Federico II, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nicola","family":"Mazzocca","sequence":"additional","affiliation":[{"name":"University of Naples Federico II, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Francesco","family":"Moscato","sequence":"additional","affiliation":[{"name":"University of Campania Luigi Vanvitelli, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,5,18]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1006\/inco.1993.1024"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1016\/0304-3975(94)90010-8"},{"key":"#cr-split#-e_1_2_1_3_1.1","doi-asserted-by":"crossref","unstructured":"F. Amato V. Casola G. Cozzolino A. De Benedictis and F. Moscato. 2019. Exploiting workflow languages and semantics for validation of security policies in IoT composite services. IEEE Internet of Things Journal (2019) 1-1. DOI:https:\/\/doi.org\/10.1109\/JIOT.2019.2960316 10.1109\/JIOT.2019.2960316","DOI":"10.1109\/JIOT.2019.2960316"},{"key":"#cr-split#-e_1_2_1_3_1.2","doi-asserted-by":"crossref","unstructured":"F. Amato V. Casola G. Cozzolino A. De Benedictis and F. Moscato. 2019. Exploiting workflow languages and semantics for validation of security policies in IoT composite services. IEEE Internet of Things Journal (2019) 1-1. DOI:https:\/\/doi.org\/10.1109\/JIOT.2019.2960316","DOI":"10.1109\/JIOT.2019.2960316"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1002\/smr.1944"},{"issue":"2020","key":"e_1_2_1_5_1","first-page":"163","article-title":"Using hierarchical timed coloured Petri nets in the formal study of TRBAC security policies","volume":"19","author":"Attia Hasiba","year":"2019","unstructured":"Hasiba Attia , Laid Kahloul , Saber Benharzallah , and Samir Bourekkache . 2019 . Using hierarchical timed coloured Petri nets in the formal study of TRBAC security policies . International Journal of Information Security 19 ( 2020 ), 163 \u2013 187 . DOI:https:\/\/doi.org\/10.1007\/s10207-019-00448-9 10.1007\/s10207-019-00448-9 Hasiba Attia, Laid Kahloul, Saber Benharzallah, and Samir Bourekkache. 2019. Using hierarchical timed coloured Petri nets in the formal study of TRBAC security policies. International Journal of Information Security 19 (2020), 163\u2013187. DOI:https:\/\/doi.org\/10.1007\/s10207-019-00448-9","journal-title":"International Journal of Information Security"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/2699444"},{"key":"e_1_2_1_7_1","volume-title":"Larsen","author":"Behrmann Gerd","year":"2004","unstructured":"Gerd Behrmann , Alexandre David , and Kim G . Larsen . 2004 . A tutorial on UPPAAL. Formal Methods for the Design of Real-time Systems. Springer , 200\u2013236. Gerd Behrmann, Alexandre David, and Kim G. Larsen. 2004. A tutorial on UPPAAL. Formal Methods for the Design of Real-time Systems. Springer, 200\u2013236."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2919982"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3326467.3326496"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijmedinf.2010.10.006"},{"key":"e_1_2_1_11_1","volume-title":"International Conference on Network-Based Information Systems. Springer, 944\u2013951","author":"Cuomo Salvatore","year":"2018","unstructured":"Salvatore Cuomo , Francesco Maiorano , and Francesco Piccialli . 2018 . Remarks of social data mining applications in the Internet of data . In International Conference on Network-Based Information Systems. Springer, 944\u2013951 . Salvatore Cuomo, Francesco Maiorano, and Francesco Piccialli. 2018. Remarks of social data mining applications in the Internet of data. In International Conference on Network-Based Information Systems. Springer, 944\u2013951."},{"key":"e_1_2_1_12_1","volume-title":"Retrieved","author":"European Commission","year":"2020","unstructured":"European Commission . [n.d.]. General Data Protection Regulation . Retrieved January 23, 2020 from https:\/\/gdpr-info.eu\/. European Commission. [n.d.]. General Data Protection Regulation. Retrieved January 23, 2020 from https:\/\/gdpr-info.eu\/."},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.micpro.2019.102938"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-013-0205-x"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3194133.3194140"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2020.02.018"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1142\/S021819401100513X"},{"key":"e_1_2_1_18_1","volume-title":"2016 IEEE 17th International Conference on Information Reuse and Integration (IRI\u201916)","author":"Hu V. C.","year":"2016","unstructured":"V. C. Hu and D. R. Kuhn . 2016. General methods for access control policy verification (application paper) . In 2016 IEEE 17th International Conference on Information Reuse and Integration (IRI\u201916) . 315\u2013323. DOI:https:\/\/doi.org\/10.1109\/IRI. 2016 .49 10.1109\/IRI.2016.49 V. C. Hu and D. R. Kuhn. 2016. General methods for access control policy verification (application paper). In 2016 IEEE 17th International Conference on Information Reuse and Integration (IRI\u201916). 315\u2013323. DOI:https:\/\/doi.org\/10.1109\/IRI.2016.49"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3295749"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/s12652-019-01292-4"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/IWISA.2010.5473291"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijinfomgt.2018.10.020"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.entcs.2005.10.021"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2010.09.002"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1002\/cpe.4700"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSC.2018.2797277"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-018-6263-3"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10270-012-0233-4"}],"container-title":["ACM Transactions on Multimedia Computing, Communications, and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3412373","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3412373","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:25:01Z","timestamp":1750195501000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3412373"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,5,18]]},"references-count":29,"journal-issue":{"issue":"2s","published-print":{"date-parts":[[2021,6,21]]}},"alternative-id":["10.1145\/3412373"],"URL":"https:\/\/doi.org\/10.1145\/3412373","relation":{},"ISSN":["1551-6857","1551-6865"],"issn-type":[{"value":"1551-6857","type":"print"},{"value":"1551-6865","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,5,18]]},"assertion":[{"value":"2020-02-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-07-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-05-18","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}