Privacy Preservation for Outsourced Medical Data With Flexible Access Control

被引:10
|
作者
Zhou, Xingguan [1 ]
Liu, Jianwei [1 ]
Wu, Qianhong [1 ]
Zhang, Zongyang [1 ,2 ]
机构
[1] Beihang Univ, Sch Cyber Sci & Technol, Beijing 100191, Peoples R China
[2] Chinese Acad Sci, Inst Informat Engn, State Key Lab Informat Secur, Beijing 100093, Peoples R China
来源
IEEE ACCESS | 2018年 / 6卷
基金
国家重点研发计划; 北京市自然科学基金;
关键词
Privacy preservation; security; electronic medical record; IDENTITY-BASED ENCRYPTION; SYSTEM; HIBE;
D O I
10.1109/ACCESS.2018.2810243
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Electronic medical records (EMRs) play an important role in healthcare networks. Since these records always contain considerable sensitive information regarding patients, privacy preservation for the EMR system is critical. Current schemes usually authorize a user to read one's EMR if and only if his/her role satisfies the defined access policy. However, these existing schemes allow an adversary to link patients' identities to their doctors. Therefore, classifications of patients' diseases are leaked without adversaries actually seeing patients' EMRs. To address this problem, we present two anonymous schemes. They not only achieve data confidentiality but also realize anonymity for individuals. The first scheme achieves moderate security, where adversaries choose attack targets before obtaining information from the EMR system. The second scheme achieves full security, where adversaries adaptively choose attack targets after interaction with the EMR system. We provide rigorous proof showing the security and anonymity of our schemes. In addition, we propose an approach in which EMR owners can search for their EMRs in an anonymous system. For a better user experience, we apply the online/offine approach to speed up data processing. Experimental results show that the time complexity for key generation and EMR encapsulation can be reduced to milliseconds.
引用
收藏
页码:14827 / 14841
页数:15
相关论文
共 50 条
  • [1] Computing Maximum and Minimum with Privacy Preservation and Flexible Access Control
    Ding, Wenxiu
    Yan, Zheng
    Qian, Xinren
    Deng, Robert H.
    [J]. 2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [2] Privacy and Access Control for Outsourced Personal Records
    Maffei, Matteo
    Malavolta, Giulio
    Reinert, Manuel
    Schroeder, Dominique
    [J]. 2015 IEEE SYMPOSIUM ON SECURITY AND PRIVACY SP 2015, 2015, : 341 - 358
  • [3] Secure Outsourced Medical Data against Unexpected Leakage with Flexible Access Control in a Cloud Storage System
    Zhou, Xingguang
    Liu, Jianwei
    Zhang, Zongyang
    Wu, Qianhong
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2020, 2020
  • [4] A faster outsourced medical image retrieval scheme with privacy preservation
    Duan, Yating
    Li, Yanping
    Lu, Laifeng
    Ding, Yong
    [J]. JOURNAL OF SYSTEMS ARCHITECTURE, 2022, 122
  • [5] Privacy and ownership preserving of outsourced medical data
    Bertino, E
    Ooi, BC
    Yang, YJ
    Deng, RH
    [J]. ICDE 2005: 21ST INTERNATIONAL CONFERENCE ON DATA ENGINEERING, PROCEEDINGS, 2005, : 521 - 532
  • [6] Privacy-Preserving Data Processing with Flexible Access Control
    Ding, Wenxiu
    Yan, Zheng
    Deng, Robert H.
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2020, 17 (02) : 363 - 376
  • [7] Privacy of Outsourced Data
    di Vimercati, Sabrina De Capitani
    Foresti, Sara
    [J]. PRIVACY AND IDENTITY MANAGEMENT FOR LIFE, 2010, 320 : 174 - 187
  • [8] Privacy preservation in outsourced mobility traces through compact data structures
    Calderoni, Luca
    Bandini, Samantha
    Maio, Dario
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2020, 55
  • [9] Group ORAM for privacy and access control in outsourced personal records
    Maffei, Matteo
    Malavolta, Giulio
    Reinert, Manuel
    Schroeder, Dominique
    [J]. JOURNAL OF COMPUTER SECURITY, 2019, 27 (01) : 1 - 47
  • [10] Efficient Query Processing on Outsourced Encrypted Data in Cloud with Privacy Preservation
    Purushothama, B. R.
    Amberker, B. B.
    [J]. 2012 INTERNATIONAL SYMPOSIUM ON CLOUD AND SERVICES COMPUTING (ISCOS 2012), 2012, : 88 - 95