Privacy-aware relationship semantics-based XACML access control model for electronic health records in hybrid cloud

被引:8
|
作者
Kanwal, Tehsin [1 ]
Jabbar, Ather Abdul [1 ]
Anjum, Adeel [1 ]
Malik, Saif U. R. [1 ,2 ]
Khan, Abid [1 ]
Ahmad, Naveed [1 ]
Manzoor, Umar [3 ]
Shahzad, Muhammad Naeem [4 ]
Balubaid, Muhammad A. [5 ]
机构
[1] Comsats Inst Informat Technol, Dept Comp Sci, Pk Rd Chak Shahzad, Islamabad 45550, Pakistan
[2] Cybernetica AS, Tallinn, Estonia
[3] Univ Hull, Dept Comp Sci & Technol, Kingston Upon Hull, N Humberside, England
[4] Comsats Univ Islamabad, Dept Elect Engn, Lahore, Pakistan
[5] King Abdulaziz Univ, Dept Ind Engn, Fac Engn, Riyadh, Saudi Arabia
关键词
Electronic health records; hybrid cloud; privacy; relationship; access control; cryptography; SECURITY; MANAGEMENT;
D O I
10.1177/1550147719846050
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
State-of-the-art progress in cloud computing encouraged the healthcare organizations to outsource the management of electronic health records to cloud service providers using hybrid cloud. A hybrid cloud is an infrastructure consisting of a private cloud (managed by the organization) and a public cloud (managed by the cloud service provider). The use of hybrid cloud enables electronic health records to be exchanged between medical institutions and supports multipurpose usage of electronic health records. Along with the benefits, cloud-based electronic health records also raise the problems of security and privacy specifically in terms of electronic health records access. A comprehensive and exploratory analysis of privacy-preserving solutions revealed that most current systems do not support fine-grained access control or consider additional factors such as privacy preservation and relationship semantics. In this article, we investigated the need of a privacy-aware fine-grained access control model for the hybrid cloud. We propose a privacy-aware relationship semantics-based XACML access control model that performs hybrid relationship and attribute-based access control using extensible access control markup language. The proposed approach supports fine-grained relation-based access control with state-of-the-art privacy mechanism named Anatomy for enhanced multipurpose electronic health records usage. The proposed (privacy-aware relationship semantics-based XACML access control model) model provides and maintains an efficient privacy versus utility trade-off. We formally verify the proposed model (privacy-aware relationship semantics-based XACML access control model) and implemented to check its effectiveness in terms of privacy-aware electronic health records access and multipurpose utilization. Experimental results show that in the proposed (privacy-aware relationship semantics-based XACML access control model) model, access policies based on relationships and electronic health records anonymization can perform well in terms of access policy response time and space storage.
引用
收藏
页数:24
相关论文
共 50 条
  • [1] GATEway to the Cloud Case study: A privacy-aware environment for Electronic Health Records research
    Smith, Rob
    Xu, Jie
    Hima, Saman
    Johnson, Owen
    [J]. 2013 IEEE SEVENTH INTERNATIONAL SYMPOSIUM ON SERVICE-ORIENTED SYSTEM ENGINEERING (SOSE 2013), 2013, : 292 - 297
  • [2] Privacy-aware Role Based Access Control
    Ni, Qun
    Trombetta, Alberto
    Bertino, Elisa
    Lobo, Jorge
    [J]. SACMAT'07: PROCEEDINGS OF THE 12TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2007, : 41 - 50
  • [3] Privacy-Aware Role-Based Access Control
    Ni, Qun
    Bertino, Elisa
    Lobo, Jorge
    Calo, Seraphin B.
    [J]. IEEE SECURITY & PRIVACY, 2009, 7 (04) : 35 - 43
  • [4] Conditional privacy-aware role based access control
    Ni, Qun
    Lin, Dan
    Bertino, Elisa
    Lobo, Jorge
    [J]. COMPUTER SECURITY - ESORICS 2007, PROCEEDINGS, 2007, 4734 : 72 - +
  • [5] Privacy-Aware Role-Based Access Control
    Ni, Qun
    Bertino, Elisa
    Lobo, Jorge
    Brodie, Carolyn
    Karat, Clare-Marie
    Karat, John
    Trombetta, Alberto
    [J]. ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2010, 13 (03)
  • [6] Privacy-aware multi-tenant access control for cloud workflow
    Wen Y.
    Liu J.
    Dou W.
    Chen A.
    Zhou M.
    [J]. Jisuanji Jicheng Zhizao Xitong/Computer Integrated Manufacturing Systems, CIMS, 2019, 25 (04): : 894 - 900
  • [7] Consumer Oriented Privacy Preserving Access Control for Electronic Health Records in the Cloud
    Fernando, Ruchith
    Ranchal, Rohit
    An, Byungchan
    ben Othmane, Lotfi
    Bhargava, Bharat
    [J]. PROCEEDINGS OF 2016 IEEE 9TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2016, : 608 - 615
  • [8] A privacy-aware access control model for distributed network monitoring
    Papagiannakopoulou, Eugenia I.
    Koukovini, Maria N.
    Lioudakis, Georgios V.
    Garcia-Alfaro, Joaquin
    Kaklamani, Dimitra I.
    Venieris, Iakovos S.
    Cuppens, Frederic
    Cuppens-Boulahia, Nora
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2013, 39 (07) : 2263 - 2281
  • [9] Privacy query rewriting algorithm instrumented by a privacy-aware access control model
    Said Oulmakhzoune
    Nora Cuppens-Boulahia
    Frédéric Cuppens
    Stéphane Morucci
    Mahmoud Barhamgi
    Djamal Benslimane
    [J]. annals of telecommunications - annales des télécommunications, 2014, 69 : 3 - 19
  • [10] Privacy query rewriting algorithm instrumented by a privacy-aware access control model
    Oulmakhzoune, Said
    Cuppens-Boulahia, Nora
    Cuppens, Frederic
    Morucci, Stephane
    Barhamgi, Mahmoud
    Benslimane, Djamal
    [J]. ANNALS OF TELECOMMUNICATIONS, 2014, 69 (1-2) : 3 - 19