跳到主要导航 跳到搜索 跳到主要内容

Auditing revocable privacy-preserving access control for EHRs in clouds

  • Beihang University
  • University of Electronic Science and Technology of China
  • CAS - Institute of Information Engineering

科研成果: 期刊稿件文章同行评审

摘要

Electronic Health Record (EHR) systems bring an abundance of convenience for telediagnosis, medical data sharing and management. A main obstacle for wide adoption of EHR systems is due to the privacy concerns of patients. In this work, we propose a role-based access control (RBAC) scheme for EHR systems to secure private EHRs. In our RBAC, there are two main types of roles, namely independent patients and hierarchically organized medical staffs. A patient is identified by his/her identity, and a medical staff is recognized by his/her role in the medical institute. A user can comprehend an EHR only if he/she satisfies the access policy associated with this EHR, which implies a fine-grained access control. A public auditor is employed to verify whether the EHR is correctly encapsulated with the specified access policy, which provides an a priori approach to find fraudulent EHRs and reduce potential medical disputes. Moreover, our RBAC enforces a forward revocation mechanism. A revoked user cannot access the future EHRs even if his/her previous role satisfies the access policy. These security properties are formally proven under well-established assumptions. Theoretical and experimental analyses show the efficiency of our RBAC in terms of communication and computation.

源语言英语
页(从-至)1871-1888
页数18
期刊Computer Journal
60
12
DOI
出版状态已出版 - 1 12月 2017

指纹

探究 'Auditing revocable privacy-preserving access control for EHRs in clouds' 的科研主题。它们共同构成独一无二的指纹。

引用此