Ehr management evolution through purpose-based access control and blockchain smart contracts

被引:0
|
作者
Ullah, Faheem [1 ]
He, Jingsha [1 ]
Zhu, Nafei [1 ]
Wajahat, Ahsan [1 ,2 ]
Nazir, Ahsan [1 ]
Qureshi, Sirajuddin [1 ]
Shahzad, Hasan [3 ]
机构
[1] Beijing Univ Technol, Fac Informat Technol, Beijing 100124, Peoples R China
[2] Northwestern Polytech Univ, Sch Software, Xian 710129, Peoples R China
[3] Beijing Univ Technol, Fac Mat & Mfg, Beijing 100124, Peoples R China
基金
北京市自然科学基金;
关键词
EHR; Purpose based access control; Smart contract; EHR management; IPFS;
D O I
10.1007/s10207-024-00967-0
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The management of Electronic Health Records (EHR) presents challenges in terms of access control and data management. Traditional access control methods often lack the granularity required to effectively manage sensitive EHR data as lack of the context or purpose behind each request. Moreover, EHR data is usually located in centralized cloud servers, which poses a significant risk of a single point of failure. Purpose-Based Access Control (PBAC) with blockchain allows for more fine-grained control over access to EHR by taking into account the purpose of the access request which allows for a more tailored approach to the access control of EHR data. This study presents PBAC with blockchain as a solution to address the shortcomings of EHR management. We formulated access policies in between Medical Data Owner (MDO) and Medical Data Requester (MDR) within the framework of PBAC and implemented it through smart contracts to streamline the processes of EHR user registration and verification, EHR access requests, and access revocation. These smart contracts enforce access control policies, grant and facilitate payment transfers effectively in case of necessary tradeoffs or revocation. EHR data is stored on IPFS, and only corresponding hashes are recorded on the blockchain for better EHR management and scalability. The performance evaluation shows better efficiency of the proposed framework.
引用
收藏
页数:20
相关论文
共 50 条
  • [1] Dynamic Purpose-based Access Control
    Peng, Huanchun
    Gu, Jun
    Ye, Xiaojun
    PROCEEDINGS OF THE 2008 INTERNATIONAL SYMPOSIUM ON PARALLEL AND DISTRIBUTED PROCESSING WITH APPLICATIONS, 2008, : 695 - 700
  • [2] Enhancing MongoDB with Purpose-Based Access Control
    Colombo, Pietro
    Ferrari, Elena
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2017, 14 (06) : 591 - 604
  • [3] Blockchain based Data Access Control using Smart Contracts
    Kiran, Adya
    Dharanikota, Samvid
    Basava, Annappa
    PROCEEDINGS OF THE 2019 IEEE REGION 10 CONFERENCE (TENCON 2019): TECHNOLOGY, KNOWLEDGE, AND SOCIETY, 2019, : 2335 - 2339
  • [4] A purpose-based access control in native XML databases
    Sun, Lili
    Wang, Hua
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2012, 24 (10): : 1154 - 1166
  • [5] Purpose-Based Access Control Policies and Conflicting Analysis
    Wang, Hua
    Sun, Lili
    Varadharajan, Vijay
    SECURITY AND PRIVACY - SILVER LININGS IN THE CLOUD, 2010, 330 : 217 - +
  • [6] Enabling Decentralized and Auditable Access Control for IoT through Blockchain and Smart Contracts
    Truong, Hien
    Hernandez-Ramos, Jose L.
    Martinez, Juan A.
    Bernabe, Jorge Bernal
    Li, Wenting
    Frutos, Agustin Marin
    Skarmeta, Antonio
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [7] A role-involved purpose-based access control model
    Md. Enamul Kabir
    Hua Wang
    Elisa Bertino
    Information Systems Frontiers, 2012, 14 : 809 - 822
  • [8] A role-involved purpose-based access control model
    Kabir, Md Enamul
    Wang, Hua
    Bertino, Elisa
    INFORMATION SYSTEMS FRONTIERS, 2012, 14 (03) : 809 - 822
  • [9] Towards Application-Layer Purpose-Based Access Control
    Pallas, Frank
    Ulbricht, Max-R
    Tai, Stefan
    Peikert, Thomas
    Reppenhagen, Marcel
    Wenzel, Daniel
    Wille, Paul
    Wolf, Karl
    PROCEEDINGS OF THE 35TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING (SAC'20), 2020, : 1288 - 1296
  • [10] CREDENTIAL PURPOSE-BASED ACCESS CONTROL FOR PERSONAL DATA PROTECTION
    Ghani, Norjihan Abdul
    Selamat, Harihodin
    Sidek, Zailani Mohamed
    JOURNAL OF WEB ENGINEERING, 2015, 14 (3-4): : 346 - 360