Arid
DOI10.1109/CSCS.2015.76
Managing the Privacy and Security of eHealth Data
Soceanu, Alexandru1; Vasylenko, Maksym1; Egner, Alexandru2; Muntean, Traian3
通讯作者Soceanu, Alexandru
会议名称20th International Conference on System Controls and Computer Science 2015
会议日期MAY 27-29, 2015
会议地点Bucharest, ROMANIA
英文摘要

The large scale adoption of mobile medicine, supported by an increasing number of medical devices and remote access to health services, correlated with the continuous involvement of the patients in their own healthcare, led to the emergence of tremendous amounts of clinical data. They need to be securely transferred, archived and accessed. This paper refers to a new approach for protecting the privacy and security of clinical data through the use of a state of the art encryption scheme and attribute-based access control authorization framework. As personal medical records are often used by different entities (e.g. doctors, pharmacists, nurses, etc.), there is a need for different degrees of authorization access for specific parts of the personal dossier. Appropriate cryptographic tools are presented for allowing partial visibility and valid protection on authorized parts for hierarchical privacy protection of eHealth data. The encryption process relies on ARCANA, a security platform developed at ERISCS research laboratory from University Aix-Marseille. It provides the appropriate cryptographic tools for secure hierarchical access to healthcare data. This ensures that the access of various entities to the healthcare data is accurately and hierarchically controlled. The access control framework used in this research is based on XACML, a standard access control decision model specified by OASIS. The applicability and feasibility of XACML-based policies to regulate the access to patient data are demonstrated through SAFAX. SAFAX is a new public authorization framework developed by the Eindhoven University of Technology tested among others on eHealth case studies, in cooperation with Munich University of Applied Sciences. It is envisioned that the usage of data encryption and public authorization solutions to regulate access control on patients clinical data will have a big impact on the patient's trust in electronic healthcare systems and will speed up their large scale adoption.


英文关键词eHealth Security Privacy Patient Consent XACML ABAC incremental cryptography
来源出版物2015 20TH INTERNATIONAL CONFERENCE ON CONTROL SYSTEMS AND COMPUTER SCIENCE
ISSN2379-0474
EISSN2379-0482
出版年2015
页码439-446
ISBN978-1-4799-1780-8
出版者IEEE
类型Proceedings Paper
语种英语
国家Germany;Netherlands;France
收录类别CPCI-S
WOS记录号WOS:000380375200065
WOS类目Automation & Control Systems ; Computer Science, Information Systems
WOS研究方向Automation & Control Systems ; Computer Science
资源类型会议论文
条目标识符http://119.78.100.177/qdio/handle/2XILL650/303632
作者单位1.Munich Univ Appl Sci, Munich, Germany;
2.Eindhoven Univ Technol, Eindhoven, Netherlands;
3.Aix Marseille Univ, CNRS I2M, ERISCS Res Grp, UMR7373, Marseille, France
推荐引用方式
GB/T 7714
Soceanu, Alexandru,Vasylenko, Maksym,Egner, Alexandru,et al. Managing the Privacy and Security of eHealth Data[C]:IEEE,2015:439-446.
条目包含的文件
条目无相关文件。
个性服务
推荐该条目
保存到收藏夹
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Soceanu, Alexandru]的文章
[Vasylenko, Maksym]的文章
[Egner, Alexandru]的文章
百度学术
百度学术中相似的文章
[Soceanu, Alexandru]的文章
[Vasylenko, Maksym]的文章
[Egner, Alexandru]的文章
必应学术
必应学术中相似的文章
[Soceanu, Alexandru]的文章
[Vasylenko, Maksym]的文章
[Egner, Alexandru]的文章
相关权益政策
暂无数据
收藏/分享

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。