• DocumentCode
    1786624
  • Title

    SPEMR: A new secure personal electronic medical record scheme with privilege separation

  • Author

    Hui Zhu ; Rong Huang ; Ximeng Liu ; Hui Li

  • Author_Institution
    State Key Lab. of Integrated Service Networks, Xidian Univ., Xi´an, China
  • fYear
    2014
  • fDate
    10-14 June 2014
  • Firstpage
    700
  • Lastpage
    705
  • Abstract
    With the pervasiveness of cloud computing, personal health record (PHR), which is outsourced to the third-party service providers and exchanges health information with patient-centric, has attracted considerable interest recently. However, the flourish of PHR still faces many challenges including privacy preservation and efficiency. Especially, PHR system allows patients to modify electronic medical record (EMR) documents, in which the veracity of patients´ EMR data has been questioned, even resulting in a few health accidents. In this paper, based on the attribute-based encryption and re-encryption under the attribute group keys, we present a new secure personal electronic medical record scheme, called SPEMR, which is privilege separation under the multi-owner settings. In specific, to achieve the veracity of patients´ EMR data and fine-grained access control, we introduce a privilege separation mechanism in SPEMR based on the RSA-Based proxy encryption. And in the SPEMR scheme, each patient can fully control the authorization of accessing to their EMR documents, achieve a fine-grained access policy and on-demand revocation. Detailed security analysis shows that the proposed SPEMR can achieve the data privacy preserving, privilege separation, and on-demand revocation.
  • Keywords
    authorisation; data privacy; electronic health records; public key cryptography; PHR; RSA-based proxy encryption; SPEMR; attribute group keys; attribute-based encryption; data privacy preserving; fine-grained access control; fine-grained access policy; multiowner settings; ondemand revocation; personal health record; privilege separation; privilege separation mechanism; secure personal electronic medical record scheme; security analysis; Authorization; Encryption; Medical services; Servers; Personal health record; cloud computing; multi-owner settings; privilege separation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications Workshops (ICC), 2014 IEEE International Conference on
  • Conference_Location
    Sydney, NSW
  • Type

    conf

  • DOI
    10.1109/ICCW.2014.6881281
  • Filename
    6881281