Skip to main navigation Skip to search Skip to main content

Auditing revocable privacy-preserving access control for EHRs in clouds

  • Beihang University
  • University of Electronic Science and Technology of China
  • CAS - Institute of Information Engineering

Research output: Contribution to journalArticlepeer-review

Abstract

Electronic Health Record (EHR) systems bring an abundance of convenience for telediagnosis, medical data sharing and management. A main obstacle for wide adoption of EHR systems is due to the privacy concerns of patients. In this work, we propose a role-based access control (RBAC) scheme for EHR systems to secure private EHRs. In our RBAC, there are two main types of roles, namely independent patients and hierarchically organized medical staffs. A patient is identified by his/her identity, and a medical staff is recognized by his/her role in the medical institute. A user can comprehend an EHR only if he/she satisfies the access policy associated with this EHR, which implies a fine-grained access control. A public auditor is employed to verify whether the EHR is correctly encapsulated with the specified access policy, which provides an a priori approach to find fraudulent EHRs and reduce potential medical disputes. Moreover, our RBAC enforces a forward revocation mechanism. A revoked user cannot access the future EHRs even if his/her previous role satisfies the access policy. These security properties are formally proven under well-established assumptions. Theoretical and experimental analyses show the efficiency of our RBAC in terms of communication and computation.

Original languageEnglish
Pages (from-to)1871-1888
Number of pages18
JournalComputer Journal
Volume60
Issue number12
DOIs
StatePublished - 1 Dec 2017

Keywords

  • Data secrecy
  • Electronic health record
  • Forward revocation
  • Public audit
  • Role-based access control

Fingerprint

Dive into the research topics of 'Auditing revocable privacy-preserving access control for EHRs in clouds'. Together they form a unique fingerprint.

Cite this