Auditing and revocation enabled role-based access control over outsourced private EHRs

Weiran Liu, Xiao Liu, Jianwei Liu, Qianhong Wu, Jun Zhang, Yan Li

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

29 Citations (Scopus)

Abstract

Electronic Health Record (EHR) systems have an abundance of convenience for telediagnosis, medical data sharing and management. The main obstacle for wide adoption of EHR systems is due to the privacy concerns of patients. In this work, we propose a role-based access control (RBAC) scheme for EHR systems to secure private EHRs. In our RBAC, there are two main types of roles, namely independent patients and hierarchically organized medical staff. A patient is identified by his/her identity, and a medical staff is recognized by his/her role in the medical institute. A user can comprehend an EHR only if he/she satisfies the access policy associated with this EHR, which implies a fine-grained access control. A public auditor is employed to verify whether the EHR is correctly encapsulated with the specified access policy, which provides an a priori approach to find fraudulent EHRs and prevent potential medical disputes. Moreover, our RBAC enforces a forward revocation mechanism. A revoked user cannot access to the future EHRs even if his/her previous role satisfies the access policy. We analyse the security and efficiency of our RBAC, showing that it is an practical solution to secure EHRs.

Original languageEnglish
Title of host publicationProceedings - 2015 IEEE 17th International Conference on High Performance Computing and Communications, 2015 IEEE 7th International Symposium on Cyberspace Safety and Security and 2015 IEEE 12th International Conference on Embedded Software and Systems, HPCC-CSS-ICESS 2015
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages336-341
Number of pages6
ISBN (Electronic)9781479989362
DOIs
Publication statusPublished - 23 Nov 2015
Externally publishedYes
Event17th IEEE International Conference on High Performance Computing and Communications, IEEE 7th International Symposium on Cyberspace Safety and Security and IEEE 12th International Conference on Embedded Software and Systems, HPCC-ICESS-CSS 2015 - New York, United States
Duration: 24 Aug 201526 Aug 2015

Publication series

NameProceedings - 2015 IEEE 17th International Conference on High Performance Computing and Communications, 2015 IEEE 7th International Symposium on Cyberspace Safety and Security and 2015 IEEE 12th International Conference on Embedded Software and Systems, HPCC-CSS-ICESS 2015

Conference

Conference17th IEEE International Conference on High Performance Computing and Communications, IEEE 7th International Symposium on Cyberspace Safety and Security and IEEE 12th International Conference on Embedded Software and Systems, HPCC-ICESS-CSS 2015
Country/TerritoryUnited States
CityNew York
Period24/08/1526/08/15

Keywords

  • Data privacy
  • Electronic health record
  • Forward revocation
  • Public audit
  • Role-based access control

Fingerprint

Dive into the research topics of 'Auditing and revocation enabled role-based access control over outsourced private EHRs'. Together they form a unique fingerprint.

Cite this