Loading...
Please wait, while we are loading the content...
Scalable and secure sharing of personal health records in cloud computing using attribute-based encryption.
| Content Provider | CiteSeerX |
|---|---|
| Author | Yu, Shucheng Zheng, Yao Ren, Kui Lou, Wenjing |
| Abstract | Abstract—Personal health record (PHR) is an emerging patient-centric model of health information exchange, which is often outsourced to be stored at a third party, such as cloud providers. However, there have been wide privacy concerns as personal health information could be exposed to those third party servers and to unauthorized parties. To assure the patients ’ control over access to their own PHRs, it is a promising method to encrypt the PHRs before outsourcing. Yet, issues such as risks of privacy exposure, scalability in key management, flexible access and efficient user revocation, have remained the most important challenges toward achieving fine-grained, cryptographically enforced data access control. In this paper, we propose a novel patient-centric framework and a suite of mechanisms for data access control to PHRs stored in semi-trusted servers. To achieve fine-grained and scalable data access control for PHRs, we leverage attribute based encryption (ABE) techniques to encrypt each patient’s PHR file. Different from previous works in secure data outsourcing, we focus on the multiple data owner scenario, and divide the users in the PHR system into multiple security domains that greatly reduces the key management complexity for owners and users. A high degree of patient privacy is guaranteed simultaneously by exploiting multi-authority ABE. Our scheme also enables dynamic modification of access policies or file attributes, supports efficient on-demand user/attribute revocation and break-glass access under emergency scenarios. Extensive analytical and experimental results are presented which show the security, scalability and efficiency of our proposed scheme. Index Terms—Personal health records, cloud computing, data privacy, fine-grained access control, attribute-based encryption 1 |
| File Format | |
| Access Restriction | Open |
| Subject Keyword | Attribute-based Encryption Cloud Computing Secure Sharing Personal Health Record Data Access Control Patient-centric Model Emergency Scenario Privacy Exposure Patient Control Multiple Data Owner Scenario Novel Patient-centric Framework Personal Health Information Patient Privacy Important Challenge Access Policy User Attribute Revocation Index Term Personal Health Record Secure Data Outsourcing Patient Phr File High Degree Break-glass Access Previous Work File Attribute Third Party Efficient User Revocation Multiple Security Unauthorized Party Promising Method Fine-grained Access Control Semi-trusted Server Data Privacy Phr System Scalable Data Access Control Third Party Server Multi-authority Abe Health Information Exchange Key Management Complexity Dynamic Modification Key Management Cloud Provider Experimental Result Abstract Personal Health Record Wide Privacy Concern Flexible Access |
| Content Type | Text |