11.07.2015 Views

Document Metadata Subscription - IHE

Document Metadata Subscription - IHE

Document Metadata Subscription - IHE

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>IHE</strong> Technical Framework Supplement - <strong>Document</strong> <strong>Metadata</strong> <strong>Subscription</strong> (DSUB)6658. $XDS<strong>Document</strong>EntryAuthorPerson: this parameter matches against theXDS<strong>Document</strong>Entry.author metadata elements in a given registry submission. Allproperties of this parameter specified in ITI TF-2a: 3.18.4.1.2.3.7.1 are applicable inthis transaction.3.52.5.3 Combining topics and filter expressions670675A topic defines static rules for creating notifications. This transaction defines two topics in ITITF-2b: 3.52.5.1. Each subscription request shall contain exactly one topic expression.A filter expression is equivalent to a specific stored query with certain parameters. Filterconditions expressed as query parameters and used in the expressions must satisfy the samerequirements as a corresponding Registry Stored Query:• the values for all specified query parameters must match (AND all differentparameters)• at least one of the values of multi-valued parameters must match (OR the values in amulti-valued query parameter)3.52.6 Security Considerations680685690695700The risk assessment for the <strong>Document</strong> <strong>Metadata</strong> Subscribe transaction is described in the riskassessment spreadsheet for the <strong>Document</strong> <strong>Metadata</strong> <strong>Subscription</strong> profile, which is available from<strong>IHE</strong> at http://wiki.ihe.net/images/4/46/DSUB_risk_assesment.xls. The derived mitigations are asfollows:• <strong>Document</strong> <strong>Metadata</strong> Subscriber and <strong>Document</strong> <strong>Metadata</strong> Notification Broker shall begrouped with an ATNA Secure Node or Secure Application actor for NodeAuthentication and Audit Trails• The use of encrypted TLS is recommended when the transmission is not otherwisesecured (e.g. transmission over a secure network)As it is possible through the document metadata subscribe transaction to maliciously overloadthe <strong>Document</strong> <strong>Metadata</strong> Notification Recipient actors, it is recommended that a strongauthentication be used in combination with access rights enforcement and that authenticationdata should be conveyed through XUA. This recommendation also addresses the possibility ofmalicious cancellations of subscriptions.Additionally, it is recommended that organizational measures be taken to avoid:• overload of a <strong>Document</strong> <strong>Metadata</strong> Notification Recipient through subscription whichcannot be cancelled because the subscription id has been lost e.g. through anadministrative service allowing cancellation of subscription under well definedcircumstances• cancellation of a subscription unnoticed by the intended document metadatanotification recipient e.g. through an informative message (out of the scope of thisprofile) sent to the intended recipient2009-08-10 24 Copyright © 2009: <strong>IHE</strong> International

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!