• DocumentCode
    3191640
  • Title

    SAPPHIRE: Anonymity for enhanced control and private collaboration in healthcare clouds

  • Author

    Pecarina, J. ; Shi Pu ; Jyh-Charn Liu

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Texas A&M Univ., College Station, TX, USA
  • fYear
    2012
  • fDate
    3-6 Dec. 2012
  • Firstpage
    99
  • Lastpage
    106
  • Abstract
    Existing cloud storage systems lack privacy aware architectures that meet accessibility goals for complex collaboration. This deficiency is fully realized in the healthcare industry, where cloud-enabling technology blurs the ownership boundary of health and wellness information. Whether among traditional `stovepiped´ data silos, health information exchanges or personally controlled health information repositories, various forms of privacy neglect are common practice. We propose a paradigm shift in the interaction of users with cloud services that removes unwarranted trust in the cloud service provider and provisions accessibility for collaborators. To realize the paradigm shift, it is necessary to provide anonymity in data storage and separate the administration of access policy and authorization from the mechanisms used for enforcement. The dispensation of authorizations in the SAPPHIRE architecture bootstraps a traditional Kerberos ticket-based approach with `trust verifications´. In our evaluation, we prove the security properties of the SAPPHIRE architecture and implement a small scale prototype. Our analysis shows that SAPPHIRE is a viable extension of collaborative health information systems through the provision of anonymity and enhanced policy administration for the primary data owner.
  • Keywords
    authorisation; cloud computing; data privacy; groupware; health care; medical information systems; storage management; Kerberos ticket-based approach; SAPPHIRE architecture; access policy; authorization; cloud service provider; cloud storage systems; cloud-enabling technology; collaborative health information systems; enhanced control; health information exchange; health information repositories; healthcare clouds; healthcare industry; privacy aware architectures; private collaboration; stovepiped data silo; trust verification; Authentication; Authorization; Cloud computing; Collaboration; Cryptography; Privacy; Authentication and authorization; Cryptographic primitives; Usability and security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cloud Computing Technology and Science (CloudCom), 2012 IEEE 4th International Conference on
  • Conference_Location
    Taipei
  • Print_ISBN
    978-1-4673-4511-8
  • Electronic_ISBN
    978-1-4673-4509-5
  • Type

    conf

  • DOI
    10.1109/CloudCom.2012.6427488
  • Filename
    6427488