Privacy-aware relationship semantics-based XACML access control model for electronic health records in hybrid cloud

被引:8
|
作者
Kanwal, Tehsin [1 ]
Jabbar, Ather Abdul [1 ]
Anjum, Adeel [1 ]
Malik, Saif U. R. [1 ,2 ]
Khan, Abid [1 ]
Ahmad, Naveed [1 ]
Manzoor, Umar [3 ]
Shahzad, Muhammad Naeem [4 ]
Balubaid, Muhammad A. [5 ]
机构
[1] Comsats Inst Informat Technol, Dept Comp Sci, Pk Rd Chak Shahzad, Islamabad 45550, Pakistan
[2] Cybernetica AS, Tallinn, Estonia
[3] Univ Hull, Dept Comp Sci & Technol, Kingston Upon Hull, N Humberside, England
[4] Comsats Univ Islamabad, Dept Elect Engn, Lahore, Pakistan
[5] King Abdulaziz Univ, Dept Ind Engn, Fac Engn, Riyadh, Saudi Arabia
关键词
Electronic health records; hybrid cloud; privacy; relationship; access control; cryptography; SECURITY; MANAGEMENT;
D O I
10.1177/1550147719846050
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
State-of-the-art progress in cloud computing encouraged the healthcare organizations to outsource the management of electronic health records to cloud service providers using hybrid cloud. A hybrid cloud is an infrastructure consisting of a private cloud (managed by the organization) and a public cloud (managed by the cloud service provider). The use of hybrid cloud enables electronic health records to be exchanged between medical institutions and supports multipurpose usage of electronic health records. Along with the benefits, cloud-based electronic health records also raise the problems of security and privacy specifically in terms of electronic health records access. A comprehensive and exploratory analysis of privacy-preserving solutions revealed that most current systems do not support fine-grained access control or consider additional factors such as privacy preservation and relationship semantics. In this article, we investigated the need of a privacy-aware fine-grained access control model for the hybrid cloud. We propose a privacy-aware relationship semantics-based XACML access control model that performs hybrid relationship and attribute-based access control using extensible access control markup language. The proposed approach supports fine-grained relation-based access control with state-of-the-art privacy mechanism named Anatomy for enhanced multipurpose electronic health records usage. The proposed (privacy-aware relationship semantics-based XACML access control model) model provides and maintains an efficient privacy versus utility trade-off. We formally verify the proposed model (privacy-aware relationship semantics-based XACML access control model) and implemented to check its effectiveness in terms of privacy-aware electronic health records access and multipurpose utilization. Experimental results show that in the proposed (privacy-aware relationship semantics-based XACML access control model) model, access policies based on relationships and electronic health records anonymization can perform well in terms of access policy response time and space storage.
引用
收藏
页数:24
相关论文
共 50 条
  • [41] Access Control Model for Sharing Composite Electronic Health Records
    Jin, Jing
    Ahn, Gail-Joon
    Covington, Michael J.
    Zhang, Xinwen
    [J]. COLLABORATIVE COMPUTING: NETWORKING, APPLICATIONS AND WORKSHARING, 2009, 10 : 340 - +
  • [42] Sensitive and Energetic IoT Access Control for Managing Cloud Electronic Health Records
    Riad, Khaled
    Hamza, Rafik
    Yan, Hongyang
    [J]. IEEE ACCESS, 2019, 7 : 86384 - 86393
  • [43] COVID-19 and future pandemics: A blockchain-based privacy-aware secure borderless travel solution from electronic health records
    Odoom, Justice
    Huang, Xiaofang
    Danso, Samuel Akwasi
    [J]. Software - Practice and Experience, 2022, 52 (10) : 2263 - 2287
  • [44] COVID-19 and future pandemics: A blockchain-based privacy-aware secure borderless travel solution from electronic health records
    Odoom, Justice
    Huang, Xiaofang
    Danso, Samuel Akwasi
    [J]. SOFTWARE-PRACTICE & EXPERIENCE, 2022, 52 (10): : 2263 - 2287
  • [45] Efficient Privacy-Preserving Access Control Scheme in Electronic Health Records System
    Ming, Yang
    Zhang, Tingting
    [J]. SENSORS, 2018, 18 (10)
  • [46] Privacy Preservation and Access Control for Sharing Electronic Health Records Using Blockchain Technology
    Boumezbeur, Insaf
    Zarour, Karim
    [J]. ACTA INFORMATICA PRAGENSIA, 2022, 11 (01) : 105 - 122
  • [47] Audit-Based Access Control for Electronic Health Records
    Dekker, M. A. C.
    Etalle, S.
    [J]. ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2007, 168 : 221 - 236
  • [48] Blockchain-Based Access Control for Electronic Health Records
    Sami, Khandoker Tahmid
    Toorani, Mohsen
    [J]. SECURE AND RESILIENT DIGITAL TRANSFORMATION OF HEALTHCARE, SUNRISE 2023, 2024, 1884 : 21 - 33
  • [49] A Dynamic Privacy Aware Access Control Model for Location Based Services
    Karimi, Leila
    Palanisamy, Balaji
    Joshi, James
    [J]. 2016 IEEE 2ND INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (IEEE CIC), 2016, : 554 - 557
  • [50] A blockchain-based privacy-preserving and access-control framework for electronic health records management
    Jakhar A.K.
    Singh M.
    Sharma R.
    Viriyasitavat W.
    Dhiman G.
    Goel S.
    [J]. Multimedia Tools and Applications, 2024, 83 (36) : 84195 - 84229