Blockchain-Based Service-Oriented Architecture for Consent Management, Access Control, and Auditing

被引:12
作者
Roman-Martinez, Isabel [1 ,2 ]
Calvillo-Arbizu, Jorge [1 ,3 ]
Mayor-Gallego, Vicente J. J. [1 ,2 ]
Madinabeitia-Luque, German [1 ,2 ]
Estepa-Alonso, Antonio J. J. [1 ,2 ]
Estepa-Alonso, Rafael M. M. [1 ,2 ]
机构
[1] Escuela Tecn Super Ingn, Dept Ingn Telemat, Seville 41092, Spain
[2] Univ Seville, Grp Ingn Telemat, Seville 41092, Spain
[3] Univ Seville, Grp Ingn Biomed, Seville 41092, Spain
关键词
Blockchains; Service-oriented architecture; Access control; Medical services; Health information management; General Data Protection Regulation; Blockchain; consent management; fast healthcare information resources (FHIR); general data protection regulation (GDPR); service-oriented architecture (SOA); business process management (BPM); MODEL;
D O I
10.1109/ACCESS.2023.3242605
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Continuity of care requires the exchange of health information among organizations and care teams. The EU General Data Protection Regulation (GDPR) establishes that subject of care should give explicit consent to the treatment of her personal data, and organizations must obey the individual's will. Nevertheless, few solutions focus on guaranteeing the proper execution of consents. We propose a service-oriented architecture, backed by blockchain technology, that enables: (1) tamper-proof and immutable storage of subject of care consents; (2) a fine-grained access control for protecting health data according to consents; and (3) auditing tasks for supervisory authorities (or subjects of care themselves) to assess that healthcare organizations comply with GDPR and granted consents. Standards for health information exchange and access control are adopted to guarantee interoperability. Access control events and the subject of care consents are maintained on a blockchain, providing a trusted collaboration between organizations, supervisory authorities, and individuals. A prototype of the architecture has been implemented as a proof of concept to evaluate the performance of critical components. The application of subject of care consent to control the treatment of personal health data in federated and distributed environments is a pressing concern. The experimental results show that blockchain can effectively support sharing consent and audit events among healthcare organizations, supervisory authorities, and individuals.
引用
收藏
页码:12726 / 12740
页数:15
相关论文
共 50 条
  • [21] A collaborative continuous auditing model under service-oriented architecture environments
    Chen, Ruey-Shun
    Sun, Chia-Ming
    PROCEEDINGS OF THE 6TH WSEAS INTERNATIONAL CONFERENCE ON E-ACTIVITIES: E-ACTIVITIES: NETWORKING THE WORLD, 2007, : 45 - +
  • [22] A Blockchain-based Approach for Continuous Auditing in IT Change Management
    Fraga, Carlos
    Abelem, Antonio
    Borges, Vinicius
    Pinheiro, Billy
    Cordeiro, Weverton
    PROCEEDINGS OF 2024 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, NOMS 2024, 2024,
  • [23] SecureConsent: A Blockchain-based Dynamic and Secure Consent Management for Genomic Data Sharing
    Javed, Ibrahim Tariq
    Lemieux, Victoria
    Regier, Dean A.
    2024 INTERNATIONAL CONFERENCE ON SMART APPLICATIONS, COMMUNICATIONS AND NETWORKING, SMARTNETS-2024, 2024,
  • [24] Enabling Integrity and Compliance Auditing in Blockchain-Based GDPR-Compliant Data Management
    Wang, Lipeng
    Guan, Zhi
    Chen, Zhong
    Hu, Mingsheng
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (23) : 20955 - 20968
  • [25] A Blockchain-Based Flexible Data Auditing Scheme for the Cloud Service
    Fan Kefeng
    Li Fei
    Yu Haiyang
    Yang Zhen
    CHINESE JOURNAL OF ELECTRONICS, 2021, 30 (06) : 1159 - 1166
  • [26] A blockchain-based platform architecture for multimedia data management
    Yue Liu
    Qinghua Lu
    Chunsheng Zhu
    Qiuyu Yu
    Multimedia Tools and Applications, 2021, 80 : 30707 - 30723
  • [27] A blockchain-based platform architecture for multimedia data management
    Liu, Yue
    Lu, Qinghua
    Zhu, Chunsheng
    Yu, Qiuyu
    MULTIMEDIA TOOLS AND APPLICATIONS, 2021, 80 (20) : 30707 - 30723
  • [28] Blockchain-Based Secured Access Control in an IoT System
    Algarni, Sultan
    Eassa, Fathy
    Almarhabi, Khalid
    Almalaise, Abduallah
    Albassam, Emad
    Alsubhi, Khalid
    Yamin, Mohammad
    APPLIED SCIENCES-BASEL, 2021, 11 (04): : 1 - 16
  • [29] Blockchain-based access control mechanism for data traceability
    Xie R.
    Li H.
    Shi G.
    Guo Y.
    Zhang M.
    Dong X.
    Shi, Guozhen (sgz1974@163.com), 1600, Editorial Board of Journal on Communications (41): : 82 - 93
  • [30] Blockchain-based Access Control Mechanism for Big Data
    Liu A.-D.
    Du X.-H.
    Wang N.
    Li S.-Z.
    Ruan Jian Xue Bao/Journal of Software, 2019, 30 (09): : 2636 - 2654