DocumentCode
687880
Title
Multiparty privacy protection for electronic health records
Author
Xun Yi ; Yuan Miao ; Bertino, Elisa ; Willemson, Jan
Author_Institution
Coll. of Eng. & Sci., Victoria Univ., Melbourne, VIC, Australia
fYear
2013
fDate
9-13 Dec. 2013
Firstpage
2730
Lastpage
2735
Abstract
Recently, the amount of personal medical information online is increasing exponentially, opening up new avenues for hackers to expose personal data that, unlike financial information, can result in a permanent violation of privacy. To protect the privacy of patient data, such as electronic health records (EHRs), access control was used before and attributed-based encryption is used recently. These techniques can effectively prevent from the outside attacks, but are hard to withstand the inside attacks, where the database administrator or the key manager is an attacker. In this paper, we provide a solution to protect the privacy of patient data (EHRs) under the multi-party framework where all EHRs are encrypted with the common public key and an encrypted EHR can be decrypted only by the cooperation of all parties. Based on the ElGamal threshold public key encryption scheme, we propose several EHR access control protocols where multiple parties cooperate to control clinicians´ access to EHRs without actually knowing EHRs. Our solution can protect the patient data against the inside attacks as long as at least one party can be trusted. Because our solution is built on Public Key Infrastructure (PKI), it facilitates the clinician registration and revocation.
Keywords
access protocols; cryptographic protocols; data privacy; electronic health records; public key cryptography; EHR access control protocols; ElGamal threshold public key encryption scheme; PKI; attributed-based encryption; clinician registration; clinician revocation; common public key; database administrator; electronic health records; encrypted EHR; inside attacks; key manager; multiparty framework; patient data privacy; permanent privacy violation; personal data; personal medical information; public key infrastructure; Access control; Databases; Encryption; Logic gates; Protocols; Public key; Servers;
fLanguage
English
Publisher
ieee
Conference_Titel
Global Communications Conference (GLOBECOM), 2013 IEEE
Conference_Location
Atlanta, GA
Type
conf
DOI
10.1109/GLOCOM.2013.6831487
Filename
6831487
Link To Document