Fine-grained access control of EHRs in cloud using CP-ABE with user revocation

被引:0
作者
Gandikota Ramu
B. Eswara Reddy
Appawala Jayanthi
L. V. Narasimha Prasad
机构
[1] Institute of Aeronautical Engineering,Department of Computer Science & Engineering
[2] JNTUA College of Engineering,Department of Computer Science & Engineering
来源
Health and Technology | 2019年 / 9卷
关键词
E-health; Privacy and security; Cloud; EHRs; And CP-ABE;
D O I
暂无
中图分类号
学科分类号
摘要
Cloud computing is a novel model for computing and storing. It enables elasticity, on-demand and low-cost usage of computing resources. Electronic health record (EHR) is an emerging patient-oriented paradigm for sharing of medical data. With the arrival of cloud computing, health care industries outsource their EHR to the cloud servers but, at the same time there is increased demand and concern for outsourced EHR’s security also. The major concerns in data outsourcing are the implementation of access policies and policies modification. To address these issues, the optimal solution is Ciphertext Policy Attribute Based Encryption (CP-ABE). CP-ABE allows the patients to describe their own access policies and implement those policies on their data before outsourcing into the cloud servers. But there are major limitations like key escrow and user revocation problems. In this paper, we proposed a modified CP-ABE scheme with user revocation to strengthen data outsourcing system in cloud architecture. The proposed system addresses the key-escrow and revocation problems. 1) The key-escrow problem is solved by using two-authority computation between the key generator authority and cloud server and 2) An immediate attribute modification method is used to achieve fine-grained user revocation. Security analysis and performance evaluation demonstrates that the proposed system is efficient to achieve security in outsourced EHRs in cloud servers.
引用
收藏
页码:487 / 496
页数:9
相关论文
共 2 条
[1]  
Rafaeli S(2003)A survey of key management for secure group communication ACM Comput Surv 35 309-329
[2]  
Mandl KD(2001)Public standards and patients’ control: how to keep electronic medical RecordsAccessible but private BMJ 322 283-287