Securing Personal Health Records in Cloud Computing: Patient-Centric and Fine-Grained Data Access Control in Multi-owner Settings

被引:0
|
作者
Li, Ming [1 ]
Yu, Shucheng [1 ]
Ren, Kui [2 ]
Lou, Wenjing [1 ]
机构
[1] Worcester Polytech Inst, Dept ECE, Worcester, MA 01609 USA
[2] IIT, Dept ECE, Chicago, IL 60616 USA
基金
美国国家科学基金会;
关键词
Personal health records; cloud computing; patient-centric privacy; fine-grained access control; attribute-based encryption;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Online personal health record (PHR) enables patients to manage their own medical records in a centralized way, which greatly facilitates the storage, access and sharing of personal health data. With the emergence of cloud computing, it is attractive for the PHR service providers to shift their PHR applications and storage into the cloud, in order to enjoy the elastic resources and reduce the operational cost. However, by storing PHRs in the cloud, the patients lose physical control to their personal health data, which makes it necessary for each patient to encrypt her PHR data before uploading to the cloud servers. Under encryption, it is challenging to achieve fine-grained access control to PHR data in a scalable and efficient way. For each patient, the PHR data should be encrypted so that it is scalable with the number of users having access. Also, since there are multiple owners (patients) in a PHR system and every owner would encrypt her PHR files using a different set of cryptographic keys, it is important to reduce the key distribution complexity in such multi-owner settings. Existing cryptographic enforced access control schemes are mostly designed for the single-owner scenarios. In this paper, we propose a novel framework for access control to PHRs within cloud computing environment. To enable fine-grained and scalable access control for PHRs, we leverage attribute based encryption (ABE) techniques to encrypt each patient's PHR data. To reduce the key distribution complexity, we divide the system into multiple security domains, where each domain manages only a subset of the users. In this way, each patient has full control over her own privacy, and the key management complexity is reduced dramatically. Our proposed scheme is also flexible, in that it supports efficient and on-demand revocation of user access rights, and break-glass access under emergency scenarios.
引用
收藏
页码:89 / +
页数:3
相关论文
共 50 条
  • [1] Fine-grained Access Control for Personal Health Records in Cloud Computing
    Li, Wei
    Ni, Wei
    Liu, Dongxi
    Liu, Ren Ping
    Wang, Peishun
    Luo, Shoushan
    [J]. 2017 IEEE 85TH VEHICULAR TECHNOLOGY CONFERENCE (VTC SPRING), 2017,
  • [2] Securing Patient-Centric Personal Health Records Sharing System in Cloud Computing
    Chen Danwei
    Chen Linling
    Fan Xiaowei
    He Liwen
    Pan Su
    Hu Ruoxiang
    [J]. CHINA COMMUNICATIONS, 2014, 11 (01) : 121 - 127
  • [3] Unified Fine-Grained Access Control for Personal Health Records in Cloud Computing
    Li, Wei
    Liu, Bonnie M.
    Liu, Dongxi
    Liu, Ren Ping
    Wang, Peishun
    Luo, Shoushan
    Ni, Wei
    [J]. IEEE JOURNAL OF BIOMEDICAL AND HEALTH INFORMATICS, 2019, 23 (03) : 1278 - 1289
  • [4] Efficient Fine-Grained Access Control for Secure Personal Health Records in Cloud Computing
    He, Kai
    Weng, Jian
    Liu, Joseph K.
    Zhou, Wanlei
    Liu, Jia-Nan
    [J]. NETWORK AND SYSTEM SECURITY, (NSS 2016), 2016, 9955 : 65 - 79
  • [5] A Patient-Centric Access Control Scheme for Personal Health Records in the Cloud
    Huang, Kuo-Hsuan
    Chang, En-Chi
    Wang, Shao-Jui
    [J]. 2013 FOURTH INTERNATIONAL CONFERENCE ON NETWORKING AND DISTRIBUTED COMPUTING (ICNDC), 2013, : 85 - 88
  • [6] A searchable personal health records framework with fine-grained access control in cloud-fog computing
    Sun, Jin
    Wang, Xiaojing
    Wang, Shangping
    Ren, Lili
    [J]. PLOS ONE, 2018, 13 (11):
  • [7] A Patient-Centric Attribute Based Access Control Scheme for Secure Sharing of Personal Health Records Using Cloud Computing
    Pussewalage, Harsha S. Gardiyawasam
    Oleshchuk, Vladimir A.
    [J]. 2016 IEEE 2ND INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (IEEE CIC), 2016, : 46 - 53
  • [8] Optimized Verifiable Fine-Grained Keyword Search in Dynamic Multi-Owner Settings
    Miao, Yinbin
    Deng, Robert H.
    Choo, Kim-Kwang Raymond
    Liu, Ximeng
    Ning, Jianting
    Li, Hongwei
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2021, 18 (04) : 1804 - 1820
  • [9] SPS: Secure Personal Health Information Sharing with Patient-centric Access Control in Cloud Computing
    Barua, Mrinmoy
    Lu, Rongxing
    Shen, Xuemin
    [J]. 2013 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2013, : 647 - 652
  • [10] Fine-grained access control for cloud computing
    Ye, Xinfeng
    Khoussainov, Bakh
    [J]. INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2013, 4 (2-3) : 160 - 168