收藏 分享(赏)

ASTM_E_2212_-_02a_2010.pdf

上传人:益****师 文档编号:169897 上传时间:2023-03-04 格式:PDF 页数:21 大小:183.66KB
下载 相关 举报
ASTM_E_2212_-_02a_2010.pdf_第1页
第1页 / 共21页
ASTM_E_2212_-_02a_2010.pdf_第2页
第2页 / 共21页
ASTM_E_2212_-_02a_2010.pdf_第3页
第3页 / 共21页
ASTM_E_2212_-_02a_2010.pdf_第4页
第4页 / 共21页
ASTM_E_2212_-_02a_2010.pdf_第5页
第5页 / 共21页
ASTM_E_2212_-_02a_2010.pdf_第6页
第6页 / 共21页
亲,该文档总共21页,到这儿已超出免费预览范围,如果喜欢就下载吧!
资源描述

1、Designation:E221202a(Reapproved 2010)An American National StandardStandard Practice forHealthcare Certificate Policy1This standard is issued under the fixed designation E2212;the number immediately following the designation indicates the year oforiginal adoption or,in the case of revision,the year o

2、f last revision.A number in parentheses indicates the year of last reapproval.Asuperscript epsilon()indicates an editorial change since the last revision or reapproval.1.Scope1.1 This practice covers a policy(“the policy”)for digitalcertificates that support the authentication,authorization,con-fide

3、ntiality,integrity,and nonrepudiation requirements of per-sons and organizations that electronically create,disclose,receive,or otherwise transact health information.1.2 This practice defines a policy for three classes ofcertificates:(1)entity certificates issued to computing compo-nents such as ser

4、vers,devices,applications,processes,oraccounts reflecting role assignment;(2)basic individual cer-tificates issued to natural persons involved in the exchange ofhealth information used for healthcare provisioning;and(3)clinical individual certificates issued to natural persons andused for authentica

5、tion of prescriptive orders relating to theclinical treatment of patients.1.3 The policy defined by this practice covers:(1)definitionof healthcare certificates,healthcare certification authorities,healthcare subscribers,and healthcare relying parties;(2)appropriate use of healthcare certificates;(3

6、)general condi-tions for the issuance of healthcare certificates;(4)healthcarecertificate formats and profile;and(5)requirements for theprotection of key material.1.4 The policy establishes minimum responsibilities forhealthcare certification authorities,relying parties,and certifi-cate subscribers.

7、2.Referenced Documents2.1 ASTM Standards:2E2084 Specification for Authentication of Healthcare Infor-mation Using Digital Signatures(Withdrawn 2009)3E2086 Guide for Internet and Intranet Healthcare Security(Withdrawn 2009)32.2 Other Documents:Public Law 104-191,Aug.21,1996,Health Insurance Por-tabil

8、ity and Accountability Act of 19964RFC 2527Internet X.509 Public Key Infrastructure Cer-tificate Policy and Certification Practices Frame-work,PKIX Working Group Internet Draft,January 3,20025RFC 2560Internet X.509 Public Key Infrastructure OnlineCertificate Status Protocol,OCSP,June 199963.Terminol

9、ogy3.1 Certificate and Related TermsA certificate,also re-ferred to as a digital certificate or public key certificate,bindsa public key value to information identifying the entityassociated with the use of a corresponding private key.Anentity may be an individual,organization,account,role,computer

10、process,or device.The entity identified within thecertificate is referred to as the certificate subject.The certificateis typically used to verify the digital signature of the certificatesubject or to encrypt information for that subject.The reliabil-ity of the binding of a public key to a certifica

11、te subject isasserted by the certification authority(CA)that creates,issues,and distributes certificates.Certification authority is synony-mous with certificate authority.Parties that depend on theaccuracy of information in the certificate are referred to asrelying parties.Certificate users are the

12、collective relyingparties and subscribers.3.2 Certificate Policy:3.2.1 The X.509 standard defines a certificate policy(CP)as“a named set of rules that indicates the applicability of acertificate to a particular community and/or class of applicationwith common security requirements.”For example,a par

13、ticularcertificate policy might indicate the type of certificate appli-cable for authenticating electronic data interchange transac-tions for the trading of goods within a specified price range.Incontrast,Practice E2212 addresses rules for certificates thatsupport the authentication,authorization,co

14、nfidentiality,integ-rity,and nonrepudiation requirements of persons and organi-zations that electronically create,disclose,receive,or other-wise transact health information.1This practice is under the jurisdiction of ASTM Committee E31 on HealthcareInformatics,and is the direct responsibility of Sub

15、committee E31.25 on HealthcareData Management,Security,Confidentiality,and Privacy.Current edition approved March 1,2010.Published August 2010.Originallyapproved in 2002.Last previous edition approved in 2002 as E221202a.DOI:10.1520/E2212-02AR10.2For referenced ASTM standards,visit the ASTM website,

16、www.astm.org,orcontact ASTM Customer Service at serviceastm.org.For Annual Book of ASTMStandards volume information,refer to the standards Document Summary page onthe ASTM website.3The last approved version of this historical standard is referenced onwww.astm.org.4Available at http:/aspe.hhs.gov/admnsimp/pl104191.htm.5Available at www.ietf.org/html.charters/pkix-charter.html.6Available at http:/www.ietf.org/rfc/rfc2560.txt.Copyright ASTM International,100 Barr Harbor Drive,PO Box C700,West Consh

展开阅读全文
相关资源
猜你喜欢
相关搜索

当前位置:首页 > 专业资料 > 国外标准

copyright@ 2008-2023 wnwk.com网站版权所有

经营许可证编号:浙ICP备2024059924号-2