Auditing and revocation enabled role-based access control over outsourced private EHRs

Weiran Liu, Xiao Liu, Jianwei Liu, Qianhong Wu, Jun Zhang, Yan Li

科研成果: 书/报告/会议事项章节会议稿件同行评审

29 引用 (Scopus)

摘要

Electronic Health Record (EHR) systems have an abundance of convenience for telediagnosis, medical data sharing and management. The main obstacle for wide adoption of EHR systems is due to the privacy concerns of patients. In this work, we propose a role-based access control (RBAC) scheme for EHR systems to secure private EHRs. In our RBAC, there are two main types of roles, namely independent patients and hierarchically organized medical staff. A patient is identified by his/her identity, and a medical staff is recognized by his/her role in the medical institute. A user can comprehend an EHR only if he/she satisfies the access policy associated with this EHR, which implies a fine-grained access control. A public auditor is employed to verify whether the EHR is correctly encapsulated with the specified access policy, which provides an a priori approach to find fraudulent EHRs and prevent potential medical disputes. Moreover, our RBAC enforces a forward revocation mechanism. A revoked user cannot access to the future EHRs even if his/her previous role satisfies the access policy. We analyse the security and efficiency of our RBAC, showing that it is an practical solution to secure EHRs.

源语言英语
主期刊名Proceedings - 2015 IEEE 17th International Conference on High Performance Computing and Communications, 2015 IEEE 7th International Symposium on Cyberspace Safety and Security and 2015 IEEE 12th International Conference on Embedded Software and Systems, HPCC-CSS-ICESS 2015
出版商Institute of Electrical and Electronics Engineers Inc.
336-341
页数6
ISBN(电子版)9781479989362
DOI
出版状态已出版 - 23 11月 2015
已对外发布
活动17th IEEE International Conference on High Performance Computing and Communications, IEEE 7th International Symposium on Cyberspace Safety and Security and IEEE 12th International Conference on Embedded Software and Systems, HPCC-ICESS-CSS 2015 - New York, 美国
期限: 24 8月 201526 8月 2015

出版系列

姓名Proceedings - 2015 IEEE 17th International Conference on High Performance Computing and Communications, 2015 IEEE 7th International Symposium on Cyberspace Safety and Security and 2015 IEEE 12th International Conference on Embedded Software and Systems, HPCC-CSS-ICESS 2015

会议

会议17th IEEE International Conference on High Performance Computing and Communications, IEEE 7th International Symposium on Cyberspace Safety and Security and IEEE 12th International Conference on Embedded Software and Systems, HPCC-ICESS-CSS 2015
国家/地区美国
New York
时期24/08/1526/08/15

指纹

探究 'Auditing and revocation enabled role-based access control over outsourced private EHRs' 的科研主题。它们共同构成独一无二的指纹。

引用此