DSMAC: Privacy-Aware Decentralized Self-Management of Data Access Control Based on Blockchain for Health Data

被引:49
作者
Saidi, Hafida [1 ]
Labraoui, Nabila [2 ]
Ari, Ado Adamou Abba [3 ,4 ]
Maglaras, Leandros A. [5 ]
Emati, Joel Herve Mboussam [4 ]
机构
[1] Univ Abou Bekr Belkaid Tlemcen, STIC Lab, Tilimsen 13000, Algeria
[2] Univ Abou Bekr Belkaid Tlemcen, LRI Lab, Tilimsen 13000, Algeria
[3] Univ Paris Saclay, DAVID Lab, Univ Versailles St Quentin En Yvelines, F-78000 Versailles, France
[4] Univ Maroua, Dept Comp Sci, Maroua, Cameroon
[5] De Montfort Univ, Sch Comp Sci & Informat, Leicester LE1 9BH, Leics, England
关键词
Access control; Blockchains; Medical services; Data privacy; Security; Privacy; Smart contracts; Decentralized control; Blockchain; data privacy; decentralized access control; decentralized identifier (DID); IoMT sensors; self sovereign identity (SSI); smart contract; verifiable credential (VC);
D O I
10.1109/ACCESS.2022.3207803
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, the interest in using wireless communication technologies and mobile devices in the healthcare environment has increased. However, despite increased attention to the security of electronic health records, patient privacy is still at risk for data breaches. Thus, it is quite a challenge to involve an access control system especially if the patient's medical data are accessible by users who have diverse privileges in different situations. Blockchain is a new technology that can be adopted for decentralized access control management issues. Nevertheless, different scalability, security, and privacy challenges affect this technology. To address these issues, we suggest a novel Decentralized Self-Management of data Access Control (DSMAC) system using a blockchain-based Self-Sovereign Identity (SSI) model for privacy-preserving medical data, empowering patients with mechanisms to preserve control over their personal information and allowing them to self-grant access rights to their medical data. DSMAC leverages smart contracts to conduct Role-based Access Control policies and adopts the implementation of decentralized identifiers and verifiable credentials to describe advanced access control techniques for emergency cases. Finally, by evaluating performance and comparing analyses with other schemes, DSMAC can satisfy the privacy requirements of medical systems in terms of privacy, scalability, and sustainability, and offers a new approach for emergency cases.
引用
收藏
页码:101011 / 101028
页数:18
相关论文
共 60 条
[1]   Enabling privacy and security in Cloud of Things: Architecture, applications, security & privacy challenges [J].
Ari, Ado Adamou Abba ;
Ngangmo, Olga Kengni ;
Titouna, Chafiq ;
Thiare, Ousmane ;
Kolyang ;
Mohamadou, Alidou ;
Gueroui, Abdelhak Mourad .
APPLIED COMPUTING AND INFORMATICS, 2024, 20 (1/2) :119-141
[2]   WHISPER: A Location Privacy-Preserving Scheme Using Transmission Range Changing for Internet of Vehicles [J].
Babaghayou, Messaoud ;
Labraoui, Nabila ;
Abba Ari, Ado Adamou ;
Ferrag, Mohamed Amine ;
Maglaras, Leandros ;
Janicke, Helge .
SENSORS, 2021, 21 (07)
[3]  
Banerjee Abhik, 2022, Blockchain based Internet of Things. Lecture Notes on Data Engineering and Communications Technologies (112), P113, DOI 10.1007/978-981-16-9260-4_5
[4]   SSIBAC: Self-Sovereign Identity Based Access Control [J].
Belchior, Rafael ;
Putz, Benedikt ;
Pernul, Guenther ;
Correia, Miguel ;
Vasconcelos, Andre ;
Guerreiro, Sergio .
2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, :1935-1943
[5]  
Boldrin L., 2021, PROC 7 INT C SYST IN, P1
[6]   Distributed Ledger Technology for eHealth Identity Privacy: State of The Art and Future Perspective [J].
Bouras, Mohammed Amine ;
Lu, Qinghua ;
Zhang, Fan ;
Wan, Yueliang ;
Zhang, Tao ;
Ning, Huansheng .
SENSORS, 2020, 20 (02)
[7]  
Capraz S., 2021, BLOCKCHAIN TECHNOLOG, P109, DOI DOI 10.1007/978-981-33-6470-7_7
[8]   RBAC-SC: Role-Based Access Control Using Smart Contract [J].
Cruz, Jason Paul ;
Kaji, Yuichi ;
Yanai, Naoto .
IEEE ACCESS, 2018, 6 :12240-12251
[9]   Ancile: Privacy-preserving framework for access control and interoperability of electronic health records using blockchain technology [J].
Dagher, Gaby G. ;
Mohler, Jordan ;
Milojkovic, Matea ;
Marella, Praneeth Babu .
SUSTAINABLE CITIES AND SOCIETY, 2018, 39 :283-297
[10]  
Dundar Y, 2020, J Mod Technol Eng, V5, P189