As digital healthcare evolves, the security of electronic health records (EHR) becomes increasingly crucial. This study presents the GPT-Onto-CAABAC framework, integrating Generative Pretrained Transformer (GPT), medical-legal ontologies and Context-Aware Attribute-Based Access Control (CAABAC) to enhance EHR access security. Unlike traditional models, GPT-Onto-CAABAC dynamically interprets policies and adapts to changing healthcare and legal environments, offering customized access control solutions. Through empirical evaluation, this framework is shown to be effective in improving EHR security by accurately aligning access decisions with complex regulatory and situational requirements. The findings suggest its broader applicability in sectors where access control must meet stringent compliance and adaptability standards.
翻译:随着数字医疗的发展,电子健康记录(EHR)的安全性问题变得愈发关键。本研究提出GPT-Onto-CAABAC框架,整合了生成式预训练Transformer(GPT)、医疗法律本体论及上下文感知属性基访问控制(CAABAC),以增强EHR访问安全性。与传统模型不同,GPT-Onto-CAABAC能够动态解释策略并适应不断变化的医疗及法律环境,提供定制化的访问控制解决方案。通过实证评估,该框架通过精准对齐访问决策与复杂的法规及情境需求,被证明能有效提升EHR安全性。研究结果表明,该框架在需要满足严格合规性与适应性标准的访问控制领域具有更广泛的适用性。