Attribute-based access control scheme for secure storage and sharing of EHRs using blockchain and IPFS

被引:8
|
作者
Kaur, Jasleen [1 ]
Rani, Rinkle [1 ]
Kalra, Nidhi [1 ]
机构
[1] Thapar Inst Engn & Technol, Comp Sci & Engn Dept, Patiala 147004, Punjab, India
关键词
Blockchain; Electronic Health Record; InterPlanetary file system; Ethereum; Smart Contract; Attribute Based Encryption;
D O I
10.1007/s10586-023-04038-2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Medical records are one of the crucial documents and a significant asset for anyone seeking treatment. Electronic health records (EHRs) have made a dynamic shift by making them easier to manage, facilitate and share among various stakeholders such as doctors, lab technicians, and insurance agents. EHRs are vulnerable to hacker, cybercriminal attacks, and data breaches. Once compromised, health records cannot be retrieved. As a result, patients must have control over who gets their EHRs, when they get them, and where they get them. To address the aforementioned issue, this paper proposes a blockchain-based secure record-keeping and trustworthy sharing system. In order to do this, a distributed off-chain storage architecture for large-scale medical data storage is developed, which overcomes the drawbacks of on-chain data storage and enhances scalability. The distributed storage, i.e., InterPlanetary File System, is a content-addressable storage that ensures the integrity of the content such that a slight modification in the stored EHR records results in a change in the obtained hash value. Furthermore, a Ciphertext Policy Attribute-Based Encryption (CP-ABE) algorithm integrated with blockchain technology is designed for fine-grained access control, allowing only authorized users to access specific EHR data based on their attributes. The combination of CP-ABE with blockchain technology provides a tamper-proof and verifiable audit trail of all data access and updations made to EHRs. This enhances accountability and ensures that the patients or owners can track and verify all actions taken on the data. To implement the proposed system, the Remix-Ethereum IDE is used. Smart contracts (SCs) are designed with access permissions so patients have complete control over their records. The scalability and immutability of the system is ensured by storing the hash of the encrypted EHRs on the blockchain and the actual encrypted records on IPFS. The security analysis of the proposed system is carried out by evaluating its resistance to various attacks. Additionally, potential security flaws in the proposed SCs are investigated using the Oyente tool. Different test cases are presented to demonstrate the functionality and cost analysis of the proposed system.
引用
收藏
页码:1047 / 1061
页数:15
相关论文
共 50 条
  • [41] Secure Remote Cloud File Sharing With Attribute-Based Access Control and Performance Optimization
    Chen, E.
    Zhu, Yan
    Liang, Kaitai
    Yin, Hongjian
    [J]. IEEE TRANSACTIONS ON CLOUD COMPUTING, 2023, 11 (01) : 579 - 594
  • [42] Secure Multi-Authority Data Access Control Scheme in Cloud Storage System Based on Attribute-Based Signcryption
    Xu, Qian
    Tan, Chengxiang
    Fan, Zhijie
    Zhu, Wenye
    Xiao, Ya
    Cheng, Fujia
    [J]. IEEE ACCESS, 2018, 6 : 34051 - 34074
  • [43] Non-Repudiation Storage and Access Control Scheme of Insurance Data Based on Blockchain in IPFS
    Sun, Jin
    Yao, Xiaomin
    Wang, Shangping
    Wu, Ying
    [J]. IEEE ACCESS, 2020, 8 : 155145 - 155155
  • [44] Blockchain-Based Multiple Authorities Attribute-Based Encryption for EHR Access Control Scheme
    Yang, Xiaohui
    Zhang, Chenshuo
    [J]. APPLIED SCIENCES-BASEL, 2022, 12 (21):
  • [45] An Attribute Based Access Control Scheme for Secure Sharing of Electronic Health Records
    Pussewalage, Harsha S. Gardiyawasam
    Oleshchuk, Vladimir A.
    [J]. 2016 IEEE 18TH INTERNATIONAL CONFERENCE ON E-HEALTH NETWORKING, APPLICATIONS AND SERVICES (HEALTHCOM), 2016, : 551 - 556
  • [46] An Attribute-Based Controlled Collaborative Access Control Scheme for Public Cloud Storage
    Xue, Yingjie
    Xue, Kaiping
    Gai, Na
    Hong, Jianan
    Wei, David S. L.
    Hong, Peilin
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2019, 14 (11) : 2927 - 2942
  • [47] A Temporal and Spatial Constrained Attribute-Based Access Control Scheme for Cloud Storage
    Liu, Zechao
    Jiang, Zoe L.
    Wang, Xuan
    Yiu, S. M.
    Zhang, Ruoqing
    Wu, Yulin
    [J]. 2018 17TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (IEEE TRUSTCOM) / 12TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (IEEE BIGDATASE), 2018, : 614 - 623
  • [48] Attribute-Based Access Control Scheme for Secure Identity Resolution in Prognostics and Health Management
    He, Yunhua
    Yan, Zihe
    Yuan, Tingli
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (13): : 23140 - 23155
  • [49] Using attribute-based access control to enable attribute-based messaging
    Bobba, Rakesh
    Fatemieh, Omid
    Khan, Fariba
    Gunter, Carl A.
    Khurana, Himanshu
    [J]. 22ND ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2006, : 403 - +
  • [50] Blockchain-Assisted Hierarchical Attribute-Based Encryption Scheme for Secure Information Sharing in Industrial Internet of Things
    Sasikumar, A.
    Ravi, Logesh
    Devarajan, Malathi
    Selvalakshmi, A.
    Almaktoom, Abdulaziz Turki
    Almazyad, Abdulaziz S.
    Xiong, Guojiang
    Mohamed, Ali Wagdy
    [J]. IEEE ACCESS, 2024, 12 : 12586 - 12601