Privacy-aware relationship semantics-based XACML access control model for electronic health records in hybrid cloud

被引:8
|
作者
Kanwal, Tehsin [1 ]
Jabbar, Ather Abdul [1 ]
Anjum, Adeel [1 ]
Malik, Saif U. R. [1 ,2 ]
Khan, Abid [1 ]
Ahmad, Naveed [1 ]
Manzoor, Umar [3 ]
Shahzad, Muhammad Naeem [4 ]
Balubaid, Muhammad A. [5 ]
机构
[1] Comsats Inst Informat Technol, Dept Comp Sci, Pk Rd Chak Shahzad, Islamabad 45550, Pakistan
[2] Cybernetica AS, Tallinn, Estonia
[3] Univ Hull, Dept Comp Sci & Technol, Kingston Upon Hull, N Humberside, England
[4] Comsats Univ Islamabad, Dept Elect Engn, Lahore, Pakistan
[5] King Abdulaziz Univ, Dept Ind Engn, Fac Engn, Riyadh, Saudi Arabia
关键词
Electronic health records; hybrid cloud; privacy; relationship; access control; cryptography; SECURITY; MANAGEMENT;
D O I
10.1177/1550147719846050
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
State-of-the-art progress in cloud computing encouraged the healthcare organizations to outsource the management of electronic health records to cloud service providers using hybrid cloud. A hybrid cloud is an infrastructure consisting of a private cloud (managed by the organization) and a public cloud (managed by the cloud service provider). The use of hybrid cloud enables electronic health records to be exchanged between medical institutions and supports multipurpose usage of electronic health records. Along with the benefits, cloud-based electronic health records also raise the problems of security and privacy specifically in terms of electronic health records access. A comprehensive and exploratory analysis of privacy-preserving solutions revealed that most current systems do not support fine-grained access control or consider additional factors such as privacy preservation and relationship semantics. In this article, we investigated the need of a privacy-aware fine-grained access control model for the hybrid cloud. We propose a privacy-aware relationship semantics-based XACML access control model that performs hybrid relationship and attribute-based access control using extensible access control markup language. The proposed approach supports fine-grained relation-based access control with state-of-the-art privacy mechanism named Anatomy for enhanced multipurpose electronic health records usage. The proposed (privacy-aware relationship semantics-based XACML access control model) model provides and maintains an efficient privacy versus utility trade-off. We formally verify the proposed model (privacy-aware relationship semantics-based XACML access control model) and implemented to check its effectiveness in terms of privacy-aware electronic health records access and multipurpose utilization. Experimental results show that in the proposed (privacy-aware relationship semantics-based XACML access control model) model, access policies based on relationships and electronic health records anonymization can perform well in terms of access policy response time and space storage.
引用
收藏
页数:24
相关论文
共 50 条
  • [31] Risk-Based Privacy-Aware Access Control for Threat Detection Systems
    Metoui, Nadia
    Bezzi, Michele
    Armando, Alessandro
    [J]. TRANSACTIONS ON LARGE-SCALE DATA- AND KNOWLEDGECENTERED SYSTEMS XXXVI: SPECIAL ISSUE ON DATA AND SECURITY ENGINEERING, 2018, 10720 : 1 - 30
  • [32] Secure smart health with privacy-aware aggregate authentication and access control in Internet of Things
    Zhang, Yinghui
    Deng, Robert H.
    Han, Gang
    Zheng, Dong
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2018, 123 : 89 - 100
  • [33] A Contextual Privacy-Aware Access Control Model for Network Monitoring Workflows: Work in Progress
    Papagiannakopoulou, Eugenia I. .
    Koukovini, Maria N.
    Lioudakis, Georgios V.
    Garcia-Alfaro, Joaquin
    Kaklamani, Dimitra I.
    Venieris, Iakovos S.
    [J]. FOUNDATIONS AND PRACTICE OF SECURITY, 2011, 6888 : 208 - +
  • [34] Credential based hybrid access control methodology for shared Electronic Health Records
    Dagdee, Nirmal
    Vijaywargiya, Ruchi
    [J]. 2009 INTERNATIONAL CONFERENCE ON INFORMATION MANAGEMENT AND ENGINEERING, PROCEEDINGS, 2009, : 624 - +
  • [35] Privacy preservation of electronic health records with adversarial attacks identification in hybrid cloud
    Kanwal, Tehsin
    Anjum, Adeel
    Malik, Saif U. R.
    Khan, Abid
    Khan, Muazzam A.
    [J]. COMPUTER STANDARDS & INTERFACES, 2021, 78
  • [36] DSMAC: Privacy-Aware Decentralized Self-Management of Data Access Control Based on Blockchain for Health Data
    Saidi, Hafida
    Labraoui, Nabila
    Ari, Ado Adamou Abba
    Maglaras, Leandros A.
    Emati, Joel Herve Mboussam
    [J]. IEEE ACCESS, 2022, 10 : 101011 - 101028
  • [37] Privacy Aware Access Control for Cloud-Based Data Platforms
    McCarthy, Donal
    Malone, Paul
    Hange, Johannes
    Doyle, Kenny
    Robson, Eric
    Conway, Dylan
    Ivanov, Stepan
    Radziwonowicz, Lukasz
    Kleinfeld, Robert
    Michalareas, Theodoros
    Kastrinogiannis, Timotheos
    Stasinos, Nikos
    Lampathaki, Fenareti
    [J]. CYBER SECURITY AND PRIVACY, CSP INNOVATION FORUM 2015, 2015, 530 : 26 - 37
  • [38] Privacy-Aware Risk-Adaptive Access Control in Health Information Systems using Topic Models
    Zhang, Wenxi
    Li, Hao
    Zhang, Min
    Lv, Zhiquan
    [J]. SACMAT'18: PROCEEDINGS OF THE 23RD ACM SYMPOSIUM ON ACCESS CONTROL MODELS & TECHNOLOGIES, 2018, : 61 - 67
  • [39] Lightweight and Privacy-Aware Fine-Grained Access Control for IoT-Oriented Smart Health
    Sun, Jianfei
    Xiong, Hu
    Liu, Ximeng
    Zhang, Yinghui
    Nie, Xuyun
    Deng, Robert H.
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2020, 7 (07) : 6566 - 6575
  • [40] Integrity and Privacy-Aware, Patient-Centric Health Record Access Control Framework Using a Blockchain
    Abutaleb, Rayan Anwar
    Alqahtany, Saad Said
    Syed, Toqeer Ali
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (02):