Cargando…

Efficient Privacy-Preserving Access Control Scheme in Electronic Health Records System

The sharing of electronic health records (EHR) in cloud servers is an increasingly important development that can improve the efficiency of medical systems. However, there are several concerns focusing on the issues of security and privacy in EHR system. The EHR data contains the EHR owner’s sensiti...

Descripción completa

Detalles Bibliográficos
Autores principales: Ming, Yang, Zhang, Tingting
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2018
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6210245/
https://www.ncbi.nlm.nih.gov/pubmed/30340411
http://dx.doi.org/10.3390/s18103520
_version_ 1783367068657123328
author Ming, Yang
Zhang, Tingting
author_facet Ming, Yang
Zhang, Tingting
author_sort Ming, Yang
collection PubMed
description The sharing of electronic health records (EHR) in cloud servers is an increasingly important development that can improve the efficiency of medical systems. However, there are several concerns focusing on the issues of security and privacy in EHR system. The EHR data contains the EHR owner’s sensitive personal information, if these data are obtained by a malicious user, it will not only cause the leakage of patient’s privacy, but also affect the doctor’s diagnosis. It is a very challenging problem for the EHR owner fully controls over own EHR data as well as preserves the privacy of himself. In this paper, we propose a new privacy-preserving access control (PPAC) scheme for EHR. To achieve fine-grained access control of the EHR data, we utilize the attribute-based signcryption (ABSC) mechanism to signcrypt data based on the access policy for the linear secret sharing schemes. Employing the cuckoo filter to hide the access policy, it could protect the EHR owner’s privacy information. In addition, the security analysis shows that the proposed scheme is provably secure under the decisional bilinear Diffie-Hellman exponent assumption and the computational Diffie-Hellman exponent assumption in the standard model. Furthermore, the performance analysis indicates that the proposed scheme achieves low costs of communication and computation compared with the related schemes, meanwhile preserves the EHR owner’s privacy. Therefore, the proposed scheme is better suited to EHR system.
format Online
Article
Text
id pubmed-6210245
institution National Center for Biotechnology Information
language English
publishDate 2018
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-62102452018-11-02 Efficient Privacy-Preserving Access Control Scheme in Electronic Health Records System Ming, Yang Zhang, Tingting Sensors (Basel) Article The sharing of electronic health records (EHR) in cloud servers is an increasingly important development that can improve the efficiency of medical systems. However, there are several concerns focusing on the issues of security and privacy in EHR system. The EHR data contains the EHR owner’s sensitive personal information, if these data are obtained by a malicious user, it will not only cause the leakage of patient’s privacy, but also affect the doctor’s diagnosis. It is a very challenging problem for the EHR owner fully controls over own EHR data as well as preserves the privacy of himself. In this paper, we propose a new privacy-preserving access control (PPAC) scheme for EHR. To achieve fine-grained access control of the EHR data, we utilize the attribute-based signcryption (ABSC) mechanism to signcrypt data based on the access policy for the linear secret sharing schemes. Employing the cuckoo filter to hide the access policy, it could protect the EHR owner’s privacy information. In addition, the security analysis shows that the proposed scheme is provably secure under the decisional bilinear Diffie-Hellman exponent assumption and the computational Diffie-Hellman exponent assumption in the standard model. Furthermore, the performance analysis indicates that the proposed scheme achieves low costs of communication and computation compared with the related schemes, meanwhile preserves the EHR owner’s privacy. Therefore, the proposed scheme is better suited to EHR system. MDPI 2018-10-18 /pmc/articles/PMC6210245/ /pubmed/30340411 http://dx.doi.org/10.3390/s18103520 Text en © 2018 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Ming, Yang
Zhang, Tingting
Efficient Privacy-Preserving Access Control Scheme in Electronic Health Records System
title Efficient Privacy-Preserving Access Control Scheme in Electronic Health Records System
title_full Efficient Privacy-Preserving Access Control Scheme in Electronic Health Records System
title_fullStr Efficient Privacy-Preserving Access Control Scheme in Electronic Health Records System
title_full_unstemmed Efficient Privacy-Preserving Access Control Scheme in Electronic Health Records System
title_short Efficient Privacy-Preserving Access Control Scheme in Electronic Health Records System
title_sort efficient privacy-preserving access control scheme in electronic health records system
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6210245/
https://www.ncbi.nlm.nih.gov/pubmed/30340411
http://dx.doi.org/10.3390/s18103520
work_keys_str_mv AT mingyang efficientprivacypreservingaccesscontrolschemeinelectronichealthrecordssystem
AT zhangtingting efficientprivacypreservingaccesscontrolschemeinelectronichealthrecordssystem