Blockchain-Based Service-Oriented Architecture for Consent Management, Access Control, and Auditing

被引:14
作者
Roman-Martinez, Isabel [1 ,2 ]
Calvillo-Arbizu, Jorge [1 ,3 ]
Mayor-Gallego, Vicente J. J. [1 ,2 ]
Madinabeitia-Luque, German [1 ,2 ]
Estepa-Alonso, Antonio J. J. [1 ,2 ]
Estepa-Alonso, Rafael M. M. [1 ,2 ]
机构
[1] Escuela Tecn Super Ingn, Dept Ingn Telemat, Seville 41092, Spain
[2] Univ Seville, Grp Ingn Telemat, Seville 41092, Spain
[3] Univ Seville, Grp Ingn Biomed, Seville 41092, Spain
关键词
Blockchains; Service-oriented architecture; Access control; Medical services; Health information management; General Data Protection Regulation; Blockchain; consent management; fast healthcare information resources (FHIR); general data protection regulation (GDPR); service-oriented architecture (SOA); business process management (BPM); MODEL;
D O I
10.1109/ACCESS.2023.3242605
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Continuity of care requires the exchange of health information among organizations and care teams. The EU General Data Protection Regulation (GDPR) establishes that subject of care should give explicit consent to the treatment of her personal data, and organizations must obey the individual's will. Nevertheless, few solutions focus on guaranteeing the proper execution of consents. We propose a service-oriented architecture, backed by blockchain technology, that enables: (1) tamper-proof and immutable storage of subject of care consents; (2) a fine-grained access control for protecting health data according to consents; and (3) auditing tasks for supervisory authorities (or subjects of care themselves) to assess that healthcare organizations comply with GDPR and granted consents. Standards for health information exchange and access control are adopted to guarantee interoperability. Access control events and the subject of care consents are maintained on a blockchain, providing a trusted collaboration between organizations, supervisory authorities, and individuals. A prototype of the architecture has been implemented as a proof of concept to evaluate the performance of critical components. The application of subject of care consent to control the treatment of personal health data in federated and distributed environments is a pressing concern. The experimental results show that blockchain can effectively support sharing consent and audit events among healthcare organizations, supervisory authorities, and individuals.
引用
收藏
页码:12726 / 12740
页数:15
相关论文
共 50 条
[41]   Blockchain-based EHR storage and access control system [J].
Gupta, Sunil ;
Bansiya, Akansha ;
Saini, Mansi ;
Sidhu, Amuleek .
INTERNATIONAL JOURNAL OF INFORMATION AND COMPUTER SECURITY, 2023, 21 (1-2) :70-81
[42]   Cryptographically Enforced Access Control in Blockchain-Based Platforms [J].
Ghaffaripour, Shadan ;
Miri, Ali .
2019 IEEE/ACS 16TH INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS (AICCSA 2019), 2019,
[43]   Blockchain-Based Access Control Mechanism in Electronic Evidence [J].
Zhang, Yunjia ;
Wang, Jian ;
He, Xudong ;
Liu, Jiqiang .
BLOCKCHAIN TECHNOLOGY AND APPLICATION, CBCC 2020, 2021, 1305 :17-33
[44]   A taxonomic framework for autonomous service management in Service-Oriented Architecture [J].
Du Wan CHEUN ;
Hyun Jung LA ;
Soo Dong KIM .
Frontiers of Information Technology & Electronic Engineering, 2012, (05) :339-354
[45]   Implementing Service-Oriented Architecture in Organizations [J].
Choi, Jae ;
Nazareth, Derek L. ;
Jain, Hemant K. .
JOURNAL OF MANAGEMENT INFORMATION SYSTEMS, 2010, 26 (04) :253-286
[46]   The integrated framework for internal control based on service-oriented architecture (SOA) [J].
Niu Y. .
Advances in Information Sciences and Service Sciences, 2011, 3 (08) :275-282
[47]   An Attribute and Role based Access Control Model for Service-Oriented Environment [J].
Wei, Yonghe ;
Shi, Chunjing ;
Shao, Weiping .
2010 CHINESE CONTROL AND DECISION CONFERENCE, VOLS 1-5, 2010, :4451-4455
[48]   A Secure Blockchain-Based Access Control Architecture for IoT-Healthcare Applications [J].
Raj, Anu ;
Prakash, Shiva .
NATIONAL ACADEMY SCIENCE LETTERS-INDIA, 2024, 47 (05) :529-537
[49]   Blockchain-based access control management for Decentralized Online Social Networks [J].
Rahman, Mohsin Ur ;
Guidi, Barbara ;
Baiardi, Fabrizio .
JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2020, 144 :41-54
[50]   Trust-based Service-Oriented Architecture [J].
Aljazzaf, Zainab M. ;
Capretz, Miriam A. M. ;
Perry, Mark .
JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2016, 28 (04) :470-480