Title :
Model-Driven Application-Level Encryption for the Privacy of E-health Data
Author :
Ding, Yun ; Klein, Karsten
Author_Institution :
R&D Basis Technol., InterComponentWare AG, Walldorf, Germany
Abstract :
We propose a novel model-driven application-level encryption solution to protect the privacy and confidentiality of health data in response to the growing public concern about the privacy of health data. Domain experts specify sensitive data which are to be protected by encryption in the application´s domain model. Security experts specify the cryptographic parameters used for the encryption in a security configuration. Both specifications are highly flexible to support different granularities of data to be encrypted and appropriate security levels. Based on the domain model, our code generator for Model-Driven Software Development generates code and configuration artifacts to control the encryption and decryption logic in the application and perform database schema modifications. Our encryption infrastructure outside the database (hence, application-level encryption) utilizes the security configuration to perform encryption and decryption.The generator relieves application developers from a significant amount of migration work required by application-level encryption. Hence, our approach combines the flexibility, security and independence from database vendors of application-level encryption and the transparency of database-level encryption. Our model-driven application-level encryption has been integrated into our eHealth Framework, a comprehensive platform for the development of electronic health care solutions. Our approach can be applied to other domains as well.
Keywords :
cryptography; data privacy; database management systems; health care; medical information systems; software engineering; application-level encryption; code artifact; configuration artifact; data confidentiality; data privacy; database schema modifications; database-level encryption; decryption logic; domain experts; e-health data; electronic health care solutions; encryption logic; model-driven software development; security configuration; security experts; Application software; Availability; Cryptography; Data mining; Data privacy; Data security; Databases; Electronic mail; Protection; Research and development; Cryptography; Database Encryption; Privacy- Enhancing Technologies; Security and Privacy in E-Health;
Conference_Titel :
Availability, Reliability, and Security, 2010. ARES '10 International Conference on
Conference_Location :
Krakow
Print_ISBN :
978-1-4244-5879-0
DOI :
10.1109/ARES.2010.91