Electronic Health Record (EHR) Access Control Case Study



  
Case Discussion Questions

a.     List three benefits and three risks for using Smart Cards and PKI.


            PKI
           Smart Card
Benefits
·        PKI provides secure transactions
It makes sure that the exchange of confidential data is done via secure extranets and virtual private networks (VPN). When using VPN, there is easy access to business-critical data that is stored in internal networks.

·        PKI provides authentication
It can provides guarantee about the user. It can check the identity about the users and can check this come from legitimate user or not.

·         More secure than passwords
 A malicious user must obtain both the private key and the corresponding passphrase to pose as a legitimate user.


·        More Secure
Smart cards are use encryption methods to secure the this. The heart of smart card is microprocessor. It can contact with card reader.

·        Smart Cards are portable
Every card holders can access immediately. The have to freedom to access.

·        Prevents Fraud
Smart can easy to use  as a credit card and debit cards. It can identify the right user.
Risks
·         Theft CA signing private keys or root keys.
·         We need a thorough understanding of PKI and asymmetric encryption principles to set this up. It's not the simplest thing to do for a sys admin. For end-users it’s mostly transparent.
·         PKI can be easily lost data in encryption methods.
·        Smart card processing power are limited.
·        It can be a target of various attacks such as Trojan horse,  viruses .
·        Smart card can be easily lost or stolen.

         

b.    Explain how Smart Cards/PKI maintains data integrity.

Data integrity: Information and programs are changed only in a specified and authorized     manner. maintenance of, and the assurance of the accuracy and consistency of, data over its entire life-cycle, and is a critical aspect to the design, implementation and usage of any system which stores, processes, or retrieves data.

PKI provides data integrity, which protects the system against unauthorized data. Modification by assuring that the received data is accurate and complete, and has not been altered or modified.

c.     Explain how Smart Cards/PKI maintains data confidentiality.
Data confidentiality is a property of data, usually resulting from legislative measures, which prevents       it from unauthorized disclosure.

PKI protect the information from being seen unauthorized people. This happens because of encryption. The PKI confidentiality service is the framework through which such a common understanding can be reached in a way that is transparent to the actual entities involved. 


d.    Explain how Smart Cards/PKI maintains data authenticity.

In information security, message authentication or data origin authentication is a property that a message has not been modified while in transit (data integrity) and that the receiving party can verify the source of the message.


Entity identification, by itself, serves simply to identify the specific entity involved, essentially in isolation from any other activity that the entity might want to perform





































Comments

Popular posts from this blog

How to hack windows 2000 using nessus.....

OpenID Connect Introduction

About Heartland Payment System Cyber Attack