Knowledge Resource Center for Ecological Environment in Arid Area
DOI | 10.1109/CSCS.2015.76 |
Managing the Privacy and Security of eHealth Data | |
Soceanu, Alexandru1; Vasylenko, Maksym1; Egner, Alexandru2; Muntean, Traian3 | |
通讯作者 | Soceanu, Alexandru |
会议名称 | 20th International Conference on System Controls and Computer Science 2015 |
会议日期 | MAY 27-29, 2015 |
会议地点 | Bucharest, ROMANIA |
英文摘要 | The large scale adoption of mobile medicine, supported by an increasing number of medical devices and remote access to health services, correlated with the continuous involvement of the patients in their own healthcare, led to the emergence of tremendous amounts of clinical data. They need to be securely transferred, archived and accessed. This paper refers to a new approach for protecting the privacy and security of clinical data through the use of a state of the art encryption scheme and attribute-based access control authorization framework. As personal medical records are often used by different entities (e.g. doctors, pharmacists, nurses, etc.), there is a need for different degrees of authorization access for specific parts of the personal dossier. Appropriate cryptographic tools are presented for allowing partial visibility and valid protection on authorized parts for hierarchical privacy protection of eHealth data. The encryption process relies on ARCANA, a security platform developed at ERISCS research laboratory from University Aix-Marseille. It provides the appropriate cryptographic tools for secure hierarchical access to healthcare data. This ensures that the access of various entities to the healthcare data is accurately and hierarchically controlled. The access control framework used in this research is based on XACML, a standard access control decision model specified by OASIS. The applicability and feasibility of XACML-based policies to regulate the access to patient data are demonstrated through SAFAX. SAFAX is a new public authorization framework developed by the Eindhoven University of Technology tested among others on eHealth case studies, in cooperation with Munich University of Applied Sciences. It is envisioned that the usage of data encryption and public authorization solutions to regulate access control on patients clinical data will have a big impact on the patient's trust in electronic healthcare systems and will speed up their large scale adoption. |
英文关键词 | eHealth Security Privacy Patient Consent XACML ABAC incremental cryptography |
来源出版物 | 2015 20TH INTERNATIONAL CONFERENCE ON CONTROL SYSTEMS AND COMPUTER SCIENCE |
ISSN | 2379-0474 |
EISSN | 2379-0482 |
出版年 | 2015 |
页码 | 439-446 |
ISBN | 978-1-4799-1780-8 |
出版者 | IEEE |
类型 | Proceedings Paper |
语种 | 英语 |
国家 | Germany;Netherlands;France |
收录类别 | CPCI-S |
WOS记录号 | WOS:000380375200065 |
WOS类目 | Automation & Control Systems ; Computer Science, Information Systems |
WOS研究方向 | Automation & Control Systems ; Computer Science |
资源类型 | 会议论文 |
条目标识符 | http://119.78.100.177/qdio/handle/2XILL650/303632 |
作者单位 | 1.Munich Univ Appl Sci, Munich, Germany; 2.Eindhoven Univ Technol, Eindhoven, Netherlands; 3.Aix Marseille Univ, CNRS I2M, ERISCS Res Grp, UMR7373, Marseille, France |
推荐引用方式 GB/T 7714 | Soceanu, Alexandru,Vasylenko, Maksym,Egner, Alexandru,et al. Managing the Privacy and Security of eHealth Data[C]:IEEE,2015:439-446. |
条目包含的文件 | 条目无相关文件。 |
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。