{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,26]],"date-time":"2026-01-26T10:30:28Z","timestamp":1769423428903,"version":"3.49.0"},"reference-count":33,"publisher":"SAGE Publications","issue":"9","license":[{"start":{"date-parts":[[2019,9,1]],"date-time":"2019-09-01T00:00:00Z","timestamp":1567296000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["International Journal of Distributed Sensor Networks"],"published-print":{"date-parts":[[2019,9]]},"abstract":"<jats:p> Data and information security is considered to be an important and challenging task for any field of life. But it becomes more critical especially when it deals with the medical field due to life and health hazards. The ratio of internal security threats to external threats always remains high. A huge number of efforts and technical expertise are required in the case of attacking the system from the external environment. But it requires fewer efforts if a system is attacked internally by the stakeholders of the system. This article presents an access control model that secures the medical data of patients against internal cybersecurity threats. It allows only the legitimate users, that is, authorized patients and doctors to communicate despite the fact of physical boundaries. The proposed model implements authorization in combination with permissions and roles instead of roles only for medical staff. It removes the discrepancies in the existing access control models. The proposed model ensures communication among doctors and patients in a secure, private, and efficient manner. The model is demonstrated by using mathematical modeling along with implementation examples. The proposed model outperformed in comparison with state-of-the-art access control models. <\/jats:p>","DOI":"10.1177\/1550147719875653","type":"journal-article","created":{"date-parts":[[2019,9,23]],"date-time":"2019-09-23T05:32:57Z","timestamp":1569216777000},"page":"155014771987565","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":25,"title":["Privacy-based medical data protection against internal security threats in heterogeneous Internet of Medical Things"],"prefix":"10.1177","volume":"15","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2675-1975","authenticated-orcid":false,"given":"Muhammad Asif","family":"Habib","sequence":"first","affiliation":[{"name":"Department of Computer Science, National Textile University, Faisalabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"C M Nadeem","family":"Faisal","sequence":"additional","affiliation":[{"name":"Department of Computer Science, National Textile University, Faisalabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shahzad","family":"Sarwar","sequence":"additional","affiliation":[{"name":"Punjab University of College of Information Technology, University of the Punjab, Lahore, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Muhammad Ahsan","family":"Latif","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Agriculture, Faisalabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Farhan","family":"Aadil","sequence":"additional","affiliation":[{"name":"Department of Computer Science, COMSATS University, Islamabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mudassar","family":"Ahmad","sequence":"additional","affiliation":[{"name":"Department of Computer Science, National Textile University, Faisalabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rehan","family":"Ashraf","sequence":"additional","affiliation":[{"name":"Department of Computer Science, National Textile University, Faisalabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Muazzam","family":"Maqsood","sequence":"additional","affiliation":[{"name":"Department of Computer Science, COMSATS University, Islamabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2019,9,23]]},"reference":[{"key":"bibr1-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1109\/MCC.2018.011791712"},{"key":"bibr2-1550147719875653","volume-title":"Secure RBAC with dynamic, efficient & usable DSD","author":"Habib MA","year":"2011"},{"key":"bibr3-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1109\/2.485845"},{"key":"bibr5-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2839065"},{"key":"bibr6-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-10-3226-4_14"},{"key":"bibr7-1550147719875653","volume-title":"Proceedings of 3rd international conference on availability, reliability, and security (ARES) (Presentation keynote lecture)","author":"Sandhu R"},{"key":"bibr8-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2017.05.413"},{"key":"bibr9-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2837163"},{"key":"bibr10-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2817615"},{"key":"bibr11-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2840504"},{"key":"bibr12-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2799522"},{"key":"bibr13-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-22635-4_8"},{"key":"bibr14-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-26690-9_34"},{"key":"bibr15-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1080\/18756891.2016.1144149"},{"key":"bibr16-1550147719875653","unstructured":"Osborn SL, Tripunitara MV, Molloy I. (eds). 19th ACM symposium on access control models and technologies, SACMAT \u201814, London, ON, Canada \u2014June 25\u201327, 2014. New York: ACM, 2014, pp.103\u2013114."},{"key":"bibr17-1550147719875653","first-page":"2935638","volume":"2016","author":"Li J","year":"2016","journal-title":"Math Probl Eng"},{"key":"bibr18-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1007\/978-81-322-2674-1_12"},{"key":"bibr19-1550147719875653","first-page":"83","volume":"9","author":"Khakpour S","year":"2017","journal-title":"Veh Commun"},{"key":"bibr20-1550147719875653","first-page":"1","volume-title":"2014 8th international conference on signal processing and communication systems (ICSPCS)","author":"Habib MA"},{"key":"bibr21-1550147719875653","first-page":"1","volume-title":"2009 international conference for Internet technology and secured transactions, (ICITST)","author":"Habib MA"},{"key":"bibr22-1550147719875653","first-page":"241","volume-title":"Proceedings 1995 computer security applications conference","author":"Ferraiolo D"},{"key":"bibr23-1550147719875653","volume-title":"3rd ACM workshop on role based access control (RBAC)","author":"Moffett JD."},{"key":"bibr24-1550147719875653","first-page":"554","volume-title":"Proceedings of the 15th National computer security conference (NCSC)","author":"Ferraiolo D"},{"key":"bibr25-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1145\/344287.344300"},{"key":"bibr26-1550147719875653","first-page":"6","volume-title":"21st national information systems security conference","author":"Jansen WA"},{"key":"bibr27-1550147719875653","first-page":"153","volume-title":"Proceedings of 4th ACM workshop on role-based access control","author":"Moffett JD"},{"key":"bibr28-1550147719875653","first-page":"184","volume-title":"Proceedings IEEE computer society symposium on research in security and privacy","author":"Baldwin RW"},{"key":"bibr29-1550147719875653","volume-title":"Proceedings of the IFIP WG11.3 working conference on database security VII","author":"Nyanchama M"},{"key":"bibr30-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1145\/300830.300832"},{"key":"bibr31-1550147719875653","first-page":"3","volume-title":"Proceedings of the sixth ACM symposium on Access control models and technologies","author":"Schaad A"},{"key":"bibr32-1550147719875653","doi-asserted-by":"publisher","DOI":"10.4258\/hir.2015.21.4.271"},{"key":"bibr33-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2016.05.032"},{"key":"bibr34-1550147719875653","doi-asserted-by":"publisher","DOI":"10.1007\/s10916-015-0318-z"}],"container-title":["International Journal of Distributed Sensor Networks"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/1550147719875653","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/journals.sagepub.com\/doi\/full-xml\/10.1177\/1550147719875653","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/1550147719875653","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,23]],"date-time":"2019-09-23T05:33:04Z","timestamp":1569216784000},"score":1,"resource":{"primary":{"URL":"http:\/\/journals.sagepub.com\/doi\/10.1177\/1550147719875653"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,9]]},"references-count":33,"journal-issue":{"issue":"9","published-online":{"date-parts":[[2019,9,23]]},"published-print":{"date-parts":[[2019,9]]}},"alternative-id":["10.1177\/1550147719875653"],"URL":"https:\/\/doi.org\/10.1177\/1550147719875653","relation":{},"ISSN":["1550-1477","1550-1477"],"issn-type":[{"value":"1550-1477","type":"print"},{"value":"1550-1477","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,9]]}}}