Skip to content

Should key to encrypt the data be protected? #44

Description

@Essien-Ge

Contact Details

essien.ge@philips.com

Section Number

2:3.YY3.4.1.3 Expected Actions

What is wrong

Currently the key used to encrypt the document is transmitted in plaintext. I'm not seeing in this way it brings any security improvement compared to simply transmit the document in plaintext.

Describe the solution you'd like

Understood it is inherent from SHL. However still suggest to include some way to encrypt the key, e.g. through the PKI material established in YY-1/2.
Or if not, at least add some security consideration to discuss this.

Relevant log output

Priority

{"Medium" => "Significant issue or clarification. Requires discussion, but should not lead to long debate."}

Code of Conduct

  • I agree to follow the IHE Code of Conduct

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions