• DocumentCode
    687880
  • Title

    Multiparty privacy protection for electronic health records

  • Author

    Xun Yi ; Yuan Miao ; Bertino, Elisa ; Willemson, Jan

  • Author_Institution
    Coll. of Eng. & Sci., Victoria Univ., Melbourne, VIC, Australia
  • fYear
    2013
  • fDate
    9-13 Dec. 2013
  • Firstpage
    2730
  • Lastpage
    2735
  • Abstract
    Recently, the amount of personal medical information online is increasing exponentially, opening up new avenues for hackers to expose personal data that, unlike financial information, can result in a permanent violation of privacy. To protect the privacy of patient data, such as electronic health records (EHRs), access control was used before and attributed-based encryption is used recently. These techniques can effectively prevent from the outside attacks, but are hard to withstand the inside attacks, where the database administrator or the key manager is an attacker. In this paper, we provide a solution to protect the privacy of patient data (EHRs) under the multi-party framework where all EHRs are encrypted with the common public key and an encrypted EHR can be decrypted only by the cooperation of all parties. Based on the ElGamal threshold public key encryption scheme, we propose several EHR access control protocols where multiple parties cooperate to control clinicians´ access to EHRs without actually knowing EHRs. Our solution can protect the patient data against the inside attacks as long as at least one party can be trusted. Because our solution is built on Public Key Infrastructure (PKI), it facilitates the clinician registration and revocation.
  • Keywords
    access protocols; cryptographic protocols; data privacy; electronic health records; public key cryptography; EHR access control protocols; ElGamal threshold public key encryption scheme; PKI; attributed-based encryption; clinician registration; clinician revocation; common public key; database administrator; electronic health records; encrypted EHR; inside attacks; key manager; multiparty framework; patient data privacy; permanent privacy violation; personal data; personal medical information; public key infrastructure; Access control; Databases; Encryption; Logic gates; Protocols; Public key; Servers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Global Communications Conference (GLOBECOM), 2013 IEEE
  • Conference_Location
    Atlanta, GA
  • Type

    conf

  • DOI
    10.1109/GLOCOM.2013.6831487
  • Filename
    6831487