A Hierarchical Multi Blockchain for Fine Grained Access to Medical Data

被引:31
作者
Malamas, Vangelis [1 ]
Kotzanikolaou, Panayiotis [1 ]
Dasaklis, Thomas K. [1 ]
Burmester, Mike [2 ]
机构
[1] Univ Piraeus, Dept Informat, Piraeus 18534, Greece
[2] Florida State Univ, Dept Comp Sci, Tallahassee, FL 32306 USA
关键词
Stakeholders; Encryption; Hospitals; Data privacy; Medical data; attribute based encryption; fine-grained access control; blockchain; smart contracts; multichain; tailored forensics; distributed trust management; revocation; ATTRIBUTE-BASED ENCRYPTION; HEALTH; PRIVACY; SECURITY; FRAMEWORK; SCHEME;
D O I
10.1109/ACCESS.2020.3011201
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The health care ecosystem involves various interconnected stakeholders with different, and sometimes conflicting security and privacy needs. Sharing medical data, sometimes generated by remote medical devices, is a challenging task. Although several solutions exist in the literature covering functional requirements such as interoperability and scalability, as well as security & privacy requirements such as fine-grained access control and data privacy, balancing between them is not a trivial task as off-the-shelf solutions do not exist. On one hand, centralized cloud architectures provide scalability and interoperable access, but make strong trust assumptions. On the other, decentralized blockchain based solutions favor data privacy and independent trust management, but typically do not support dynamic changes of the underlying trust domains. To cover this gap, in this paper, we present a novel hierarchical multi expressive blockchain architecture. At the top layer, a proxy blockchain enables independently managed trust authorities to interoperate. End-users from different health care domains, such as hospitals or device manufacturers are able to access and securely exchange medical data, provided that a commonly agreed domain-wise access policy is enforced. At the bottom layer, one or more domain blockchains allow each domain (e.g. a hospital or device manufacturer) to enforce their policy and allow fine-grained access control with attribute-based encryption. This architecture is designed to provide the autonomous management of trusted medical data/devices and the transactions of mutually untrusted stakeholders, as well as an inherent forensics mechanism tailored for granular auditing. Smart contracts are used to enforce decentralized policies. Ciphertext-policy attribute based encryption (CP-ABE) is used to distribute the decryption process among end users and the system, as well as support an efficient credential revocation mechanism. We demonstrate the efficiency of the proposed architecture through a proof of concept implementation. Finally we analyse the major security and performance characteristics.
引用
收藏
页码:134393 / 134412
页数:20
相关论文
共 57 条
[31]   Audit-Based Access Control with a Distributed Ledger: Applications to Healthcare Organizations [J].
Morelli, Umberto ;
Ranise, Silvio ;
Sartori, Damiano ;
Sciarretta, Giada ;
Tomasi, Alessandro .
SECURITY AND TRUST MANAGEMENT, STM 2019, 2019, 11738 :19-35
[32]   Electronic Health Record Sharing Scheme With Searchable Attribute-Based Encryption on Blockchain [J].
Niu, Shufen ;
Chen, Lixia ;
Wang, Jinfeng ;
Yu, Fei .
IEEE ACCESS, 2020, 8 :7195-7204
[33]   MedSBA: a novel and secure scheme to share medical data based on blockchain technology and attribute-based encryption [J].
Pournaghi, Seyed Morteza ;
Bayat, Majid ;
Farjami, Yaghoub .
JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2020, 11 (11) :4613-4641
[34]   Blockchain Based Delegatable Access Control Scheme for a Collaborative E-health Environment [J].
Pussewalage, Harsha S. Gardiyawasam ;
Oleshchuk, Vladimir A. .
IEEE 2018 INTERNATIONAL CONGRESS ON CYBERMATICS / 2018 IEEE CONFERENCES ON INTERNET OF THINGS, GREEN COMPUTING AND COMMUNICATIONS, CYBER, PHYSICAL AND SOCIAL COMPUTING, SMART DATA, BLOCKCHAIN, COMPUTER AND INFORMATION TECHNOLOGY, 2018, :1204-1211
[35]   A Distributed Multi-Authority Attribute Based Encryption Scheme for Secure Sharing of Personal Health Records [J].
Pussewalage, Harsha S. Gardiyawasam ;
Oleshchuk, Vladimir A. .
PROCEEDINGS OF THE 22ND ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES (SACMAT'17), 2017, :255-262
[36]   Privacy-preserving personal health record using multi-authority attribute-based encryption with revocation [J].
Qian, Huiling ;
Li, Jiguo ;
Zhang, Yichen ;
Han, Jinguang .
INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2015, 14 (06) :487-497
[37]  
Radhakrishnan BL, 2019, INT CONF ADVAN COMPU, P699, DOI [10.1109/ICACCS.2019.8728483, 10.1109/icaccs.2019.8728483]
[38]  
Ramani V., 2018, 2018 IEEE Global Communications Conference (GLOBECOM), P206, DOI [10.1109/GLOCOM.2018.8647221, DOI 10.1109/GLOCOM.2018.8647221]
[39]   Security, Performance, and Applications of Smart Contracts: A Systematic Survey [J].
Rouhani, Sara ;
Deters, Ralph .
IEEE ACCESS, 2019, 7 :50759-50779
[40]   Efficient Statically-Secure Large-Universe Multi-Authority Attribute-Based Encryption [J].
Rouselakis, Yannis ;
Waters, Brent .
FINANCIAL CRYPTOGRAPHY AND DATA SECURITY (FC 2015), 2015, 8975 :315-332