Title :
PSMPA: Patient Self-Controllable and Multi-Level Privacy-Preserving Cooperative Authentication in Distributedm-Healthcare Cloud Computing System
Author :
Jun Zhou ; Xiaodong Lin ; Xiaolei Dong ; Zhenfu Cao
Author_Institution :
Shanghai Key Lab. for Trustworthy Comput., East China Normal Univ., Shanghai, China
Abstract :
Distributed m-healthcare cloud computing system significantly facilitates efficient patient treatment for medical consultation by sharing personal health information among healthcare providers. However, it brings about the challenge of keeping both the data confidentiality and patients´ identity privacy simultaneously. Many existing access control and anonymous authentication schemes cannot be straightforwardly exploited. To solve the problem, in this paper, a novel authorized accessible privacy model (AAPM) is established. Patients can authorize physicians by setting an access tree supporting flexible threshold predicates. Then, based on it, by devising a new technique of attribute-based designated verifier signature, a patient self-controllable multi-level privacy-preserving cooperative authentication scheme (PSMPA) realizing three levels of security and privacy requirement in distributed m-healthcare cloud computing system is proposed. The directly authorized physicians, the indirectly authorized physicians and the unauthorized persons in medical consultation can respectively decipher the personal health information and/or verify patients´ identities by satisfying the access tree with their own attribute sets. Finally, the formal security proof and simulation results illustrate our scheme can resist various kinds of attacks and far outperforms the previous ones in terms of computational, communication and storage overhead.
Keywords :
authorisation; cloud computing; data privacy; digital signatures; health care; mobile computing; patient treatment; AAPM; PSMPA; access tree; attribute sets; attribute-based designated verifier signature; authorized accessible privacy model; data confidentiality; distributed m-healthcare cloud computing system; formal security proof; healthcare providers; medical consultation; patient identity privacy; patient self-controllable and multilevel privacy-preserving cooperative authentication; patient treatment; personal health information sharing; privacy requirement; security requirement; threshold predicates; Authentication; Cloud computing; Computational modeling; Medical services; Privacy; Public key; Authentication; access control; distributed cloud computing; m-healthcare system; security and privacy;
Journal_Title :
Parallel and Distributed Systems, IEEE Transactions on
DOI :
10.1109/TPDS.2014.2314119