DocumentCode
1786624
Title
SPEMR: A new secure personal electronic medical record scheme with privilege separation
Author
Hui Zhu ; Rong Huang ; Ximeng Liu ; Hui Li
Author_Institution
State Key Lab. of Integrated Service Networks, Xidian Univ., Xi´an, China
fYear
2014
fDate
10-14 June 2014
Firstpage
700
Lastpage
705
Abstract
With the pervasiveness of cloud computing, personal health record (PHR), which is outsourced to the third-party service providers and exchanges health information with patient-centric, has attracted considerable interest recently. However, the flourish of PHR still faces many challenges including privacy preservation and efficiency. Especially, PHR system allows patients to modify electronic medical record (EMR) documents, in which the veracity of patients´ EMR data has been questioned, even resulting in a few health accidents. In this paper, based on the attribute-based encryption and re-encryption under the attribute group keys, we present a new secure personal electronic medical record scheme, called SPEMR, which is privilege separation under the multi-owner settings. In specific, to achieve the veracity of patients´ EMR data and fine-grained access control, we introduce a privilege separation mechanism in SPEMR based on the RSA-Based proxy encryption. And in the SPEMR scheme, each patient can fully control the authorization of accessing to their EMR documents, achieve a fine-grained access policy and on-demand revocation. Detailed security analysis shows that the proposed SPEMR can achieve the data privacy preserving, privilege separation, and on-demand revocation.
Keywords
authorisation; data privacy; electronic health records; public key cryptography; PHR; RSA-based proxy encryption; SPEMR; attribute group keys; attribute-based encryption; data privacy preserving; fine-grained access control; fine-grained access policy; multiowner settings; ondemand revocation; personal health record; privilege separation; privilege separation mechanism; secure personal electronic medical record scheme; security analysis; Authorization; Encryption; Medical services; Servers; Personal health record; cloud computing; multi-owner settings; privilege separation;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications Workshops (ICC), 2014 IEEE International Conference on
Conference_Location
Sydney, NSW
Type
conf
DOI
10.1109/ICCW.2014.6881281
Filename
6881281
Link To Document