DocumentCode :
1786624
Title :
SPEMR: A new secure personal electronic medical record scheme with privilege separation
Author :
Hui Zhu ; Rong Huang ; Ximeng Liu ; Hui Li
Author_Institution :
State Key Lab. of Integrated Service Networks, Xidian Univ., Xi´an, China
fYear :
2014
fDate :
10-14 June 2014
Firstpage :
700
Lastpage :
705
Abstract :
With the pervasiveness of cloud computing, personal health record (PHR), which is outsourced to the third-party service providers and exchanges health information with patient-centric, has attracted considerable interest recently. However, the flourish of PHR still faces many challenges including privacy preservation and efficiency. Especially, PHR system allows patients to modify electronic medical record (EMR) documents, in which the veracity of patients´ EMR data has been questioned, even resulting in a few health accidents. In this paper, based on the attribute-based encryption and re-encryption under the attribute group keys, we present a new secure personal electronic medical record scheme, called SPEMR, which is privilege separation under the multi-owner settings. In specific, to achieve the veracity of patients´ EMR data and fine-grained access control, we introduce a privilege separation mechanism in SPEMR based on the RSA-Based proxy encryption. And in the SPEMR scheme, each patient can fully control the authorization of accessing to their EMR documents, achieve a fine-grained access policy and on-demand revocation. Detailed security analysis shows that the proposed SPEMR can achieve the data privacy preserving, privilege separation, and on-demand revocation.
Keywords :
authorisation; data privacy; electronic health records; public key cryptography; PHR; RSA-based proxy encryption; SPEMR; attribute group keys; attribute-based encryption; data privacy preserving; fine-grained access control; fine-grained access policy; multiowner settings; ondemand revocation; personal health record; privilege separation; privilege separation mechanism; secure personal electronic medical record scheme; security analysis; Authorization; Encryption; Medical services; Servers; Personal health record; cloud computing; multi-owner settings; privilege separation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications Workshops (ICC), 2014 IEEE International Conference on
Conference_Location :
Sydney, NSW
Type :
conf
DOI :
10.1109/ICCW.2014.6881281
Filename :
6881281
Link To Document :
بازگشت