Self-Protecting Electronic Medical Records Using Attribute-Based Encryption

نویسندگان

  • Joseph A. Akinyele
  • Christoph U. Lehmann
  • Matthew Green
  • Matthew W. Pagano
  • Zachary N. J. Peterson
  • Aviel D. Rubin
چکیده

We provide a design and implementation of self-protecting electronic medical records (EMRs) using attribute-based encryption. Our system allows healthcare organizations to export EMRs to storage locations outside of their trust boundary, including mobile devices, Regional Health Information Organizations (RHIOs), and cloud systems such as Google Health. In contrast to some previous approaches to this problem, our solution is designed to maintain EMR availability even when providers are offline, i.e., where network connectivity is not available (for example, during a natural disaster). To balance the needs of emergency care and patient privacy, our system is designed to provide for fine-grained encryption and is able to protect individual items within an EMR, where each encrypted item may have its own access control policy. To validate our architecture, we implemented a prototype system using a new dual-policy attribute-based encryption library that we developed. Our implementation, which includes an iPhone app for storing and managing EMRs offline, allows for flexible and automatic policy generation. An evaluation of our design shows that our ABE library performs well, has acceptable storage requirements, and is practical and usable on modern smartphones.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Self-Protecting Security Framework for CDA Documents

Clinical Document Architecture (CDA) is a standard for the exchange of electronic medical records. This paper describes a self-protecting security framework for protecting the security and privacy of CDA documents. The framework extends a CDA document with markups from XML based security standards including eXtensible Access Control Markup Language, XML Encryption, and XML Signature. This integ...

متن کامل

Attribute-based Access Control for Cloud-based Electronic Health Record (EHR) Systems

Electronic health record (EHR) system facilitates integrating patients' medical information and improves service productivity. However, user access to patient data in a privacy-preserving manner is still challenging problem. Many studies concerned with security and privacy in EHR systems. Rezaeibagha and Mu [1] have proposed a hybrid architecture for privacy-preserving accessing patient records...

متن کامل

Towards Self-Protecting Security for e-Health CDA Documents

To protect the security and privacy of electronic medical records, it is often necessary to employ a variety of security mechanisms such as encryption, integrity control, authentication, and access control. This paper proposes a framework that extends HL7 Clinical Document Architecture (CDA) documents with markups from XML based security standards, including eXtensible Access Control Markup Lan...

متن کامل

Joint Fingerprinting/Encryption for Medical Image Security

Electronic health records (EHRs) facilitates the healthcare process. However, it can also cause serious security and privacy problems. While various conventional encryption mechanisms can solve some aspects of these problems, they cannot address the illegal distribution of decrypted medical images. To protect decrypted medical images from being illegally distributed by an authorized staff membe...

متن کامل

Securing Healthcare Records in the Cloud Using Attribute-Based Encryption

Cloud Computing has attracted interest as an efficient system for storing and access of data. Sharing of personal electronic health record is an arising concept of exchanging health information for research and other purposes. Cconfidentiality except for authorized users, and access auditability are strong security requirements for health record. This study will examine these requirements and p...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • IACR Cryptology ePrint Archive

دوره 2010  شماره 

صفحات  -

تاریخ انتشار 2010