Privacy-Preserving Personal Health Record System Using Attribute-Based Encryption
نویسندگان
چکیده
Personal health record (PHR) service is an emerging model for health information exchange. It allows patients to create, manage, control and share their health information with other users as well as healthcare providers. In reality, a PHR service is likely to be hosted by third-party cloud service providers in order to enhance its interoperability. However, there have been serious privacy concerns about outsourcing patients’ PHR data to cloud servers, not only because cloud providers are generally not covered entities under HIPAA, but also due to an increasing number of cloud data breach incidents happened in recent years. In this thesis, we propose a privacy-preserving PHR system using attribute-based encryption (ABE). In this system, patients can encrypt their PHRs and store them on semi-trusted cloud servers such that servers do not have access to sensitive PHR contexts. Meanwhile patients maintain full control over access to their PHR files, by assigning fine-grained, attribute-based access privileges to selected data users, while different users can have access to different parts of their PHR. Our system also provides extra features such as populating PHR from professional electronic health record (EHR) using ABE. In order to evaluate our proposal, we create a Linux library that implement primitive of key-policy attribute-based encryption (KP-ABE) algorithms. We also build a PHR application based on Indivo PCHR system that allow doctors to encrypt and submit their prescription and diagnostic note to PHR servers using KP-ABE. We evaluate the performance efficiency of different ABE schemes as well as the data query time of Indivo PCHR system when PHR data are encrypted under ABE scheme.
منابع مشابه
Attribute-based Access Control for Cloud-based Electronic Health Record (EHR) Systems
Electronic health record (EHR) system facilitates integrating patients' medical information and improves service productivity. However, user access to patient data in a privacy-preserving manner is still challenging problem. Many studies concerned with security and privacy in EHR systems. Rezaeibagha and Mu [1] have proposed a hybrid architecture for privacy-preserving accessing patient records...
متن کاملEfficient and Secure Sharing of Personal Health Records Using Attribute-Based Encryption in Cloud Computing
Recently, personal health record (PHR) has emerged as a patient-centric model of health information exchange, which features storing PHRs electronically in one centralized place, such as a third-party cloud service provider. Personal Health Record is web based application that allows users to directly enter their information such as diagnosis, medications, laboratory tests, immunizations and ot...
متن کاملSurvey on Multi Authority Attribute Based Encryption for Personal Health Record in Cloud Computing
Personal Health Record (PHR) service is an emerging model for health information exchange. PHR system allows patients to create, control manage, and share their health information with other users as well as healthcare providers like Google eHealth. A PHR service is likely to be hosted by third-party cloud service providers in order to enhance its interoperability. The access control and privac...
متن کاملA Survey on an Efficient Technique of Encryption Scheme and its Extension in Cloud Based PHR System
Scalable and secure sharing of personal health record in cloud computing is an emerging trend in Health field for exchange and the use of personal Health information. This sensitive data is shared and stored by the third party reference in cloud computing. Therefore the need of encrypting data stored at this sites is highly essential to reduce the storage space and for the cost reduction. Since...
متن کاملMulti User Access Control and Key Management Mechanism for Personal Health Records
Cloud computing technology helps the individuals to store their essential information over the internet. The users can acquire the information from anywhere whenever needed. Due to the advances in computer technology, Cloud computing has gained an eminent deal of recognition among users. However the users should also be conscious of the privacy issues of having information cached on the cloud. ...
متن کامل