• DocumentCode
    1958554
  • Title

    Model-Driven Application-Level Encryption for the Privacy of E-health Data

  • Author

    Ding, Yun ; Klein, Karsten

  • Author_Institution
    R&D Basis Technol., InterComponentWare AG, Walldorf, Germany
  • fYear
    2010
  • fDate
    15-18 Feb. 2010
  • Firstpage
    341
  • Lastpage
    346
  • Abstract
    We propose a novel model-driven application-level encryption solution to protect the privacy and confidentiality of health data in response to the growing public concern about the privacy of health data. Domain experts specify sensitive data which are to be protected by encryption in the application´s domain model. Security experts specify the cryptographic parameters used for the encryption in a security configuration. Both specifications are highly flexible to support different granularities of data to be encrypted and appropriate security levels. Based on the domain model, our code generator for Model-Driven Software Development generates code and configuration artifacts to control the encryption and decryption logic in the application and perform database schema modifications. Our encryption infrastructure outside the database (hence, application-level encryption) utilizes the security configuration to perform encryption and decryption.The generator relieves application developers from a significant amount of migration work required by application-level encryption. Hence, our approach combines the flexibility, security and independence from database vendors of application-level encryption and the transparency of database-level encryption. Our model-driven application-level encryption has been integrated into our eHealth Framework, a comprehensive platform for the development of electronic health care solutions. Our approach can be applied to other domains as well.
  • Keywords
    cryptography; data privacy; database management systems; health care; medical information systems; software engineering; application-level encryption; code artifact; configuration artifact; data confidentiality; data privacy; database schema modifications; database-level encryption; decryption logic; domain experts; e-health data; electronic health care solutions; encryption logic; model-driven software development; security configuration; security experts; Application software; Availability; Cryptography; Data mining; Data privacy; Data security; Databases; Electronic mail; Protection; Research and development; Cryptography; Database Encryption; Privacy- Enhancing Technologies; Security and Privacy in E-Health;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability, and Security, 2010. ARES '10 International Conference on
  • Conference_Location
    Krakow
  • Print_ISBN
    978-1-4244-5879-0
  • Type

    conf

  • DOI
    10.1109/ARES.2010.91
  • Filename
    5438071