Cargando…

The Integrated Holistic Security and Privacy Framework Deployed in CrowdHEALTH Project

INTRODUCTION: Individuals and healthcare providers need to trust that the EHRs are protected and that the confidentiality of their personal information is not at stake. AIM: Within CrowdHEALTH project, a security and privacy framework that ensures confidentiality, integrity, and availability of the...

Descripción completa

Detalles Bibliográficos
Autores principales: Malliaros, Stefanos, Xenakis, Christos, Moldovan, George, Mantas, John, Magdalinou, Andriana, Montandon, Lydia
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Academy of Medical sciences 2019
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7085323/
https://www.ncbi.nlm.nih.gov/pubmed/32210501
http://dx.doi.org/10.5455/aim.2019.27.333-340
_version_ 1783508920246992896
author Malliaros, Stefanos
Xenakis, Christos
Moldovan, George
Mantas, John
Magdalinou, Andriana
Montandon, Lydia
author_facet Malliaros, Stefanos
Xenakis, Christos
Moldovan, George
Mantas, John
Magdalinou, Andriana
Montandon, Lydia
author_sort Malliaros, Stefanos
collection PubMed
description INTRODUCTION: Individuals and healthcare providers need to trust that the EHRs are protected and that the confidentiality of their personal information is not at stake. AIM: Within CrowdHEALTH project, a security and privacy framework that ensures confidentiality, integrity, and availability of the data was developed. METHODS: The CrowdHEALTH Security and Privacy framework includes Privacy Enhancing Technologies (PETs) in order to comply with the GDPR EU laws of data protection. CrowdHEALTH deploys OpenID Connect, an authentication protocol to provide flexibility, scalability, and lightweight user authentication as well as the attribute-base access control (ABAC) mechanism which supports creating efficient access control policies. RESULTS: CrowdHEALTH integrates ABAC with OpenID Connect to build an effective and scalable base for end-users’ authorization. CrowdHEALTH’s security and privacy framework interacts with other CrowdHEALTH’s components, for instance the Big Data Platform, that depends on user authentication and authorization. CrowdHEALTH users are able to access the CrowdHEALTH’s database based on the result of an ABAC request. Moreover, due to the fact that the CrowdHEALTH system requires proofs during the interactions with data producers of low trust or low reputation level, the requirements for the Trust and Reputation Model have been identified. CONCLUSION: The CrowdHEALTH Integrated Holistic Security and Privacy framework meets the security criteria for an e-health cross-border system, due to the adoption of security mechanisms, such as user authentication, user authorization, access control, data anonymization, trust management and reputation modelling. The implemented framework remains to be tested to ensure its robustness and to evaluate its performance. The holistic security and privacy framework might be adapted during the project’s life circle according to new legislations.
format Online
Article
Text
id pubmed-7085323
institution National Center for Biotechnology Information
language English
publishDate 2019
publisher Academy of Medical sciences
record_format MEDLINE/PubMed
spelling pubmed-70853232020-03-24 The Integrated Holistic Security and Privacy Framework Deployed in CrowdHEALTH Project Malliaros, Stefanos Xenakis, Christos Moldovan, George Mantas, John Magdalinou, Andriana Montandon, Lydia Acta Inform Med Original Paper INTRODUCTION: Individuals and healthcare providers need to trust that the EHRs are protected and that the confidentiality of their personal information is not at stake. AIM: Within CrowdHEALTH project, a security and privacy framework that ensures confidentiality, integrity, and availability of the data was developed. METHODS: The CrowdHEALTH Security and Privacy framework includes Privacy Enhancing Technologies (PETs) in order to comply with the GDPR EU laws of data protection. CrowdHEALTH deploys OpenID Connect, an authentication protocol to provide flexibility, scalability, and lightweight user authentication as well as the attribute-base access control (ABAC) mechanism which supports creating efficient access control policies. RESULTS: CrowdHEALTH integrates ABAC with OpenID Connect to build an effective and scalable base for end-users’ authorization. CrowdHEALTH’s security and privacy framework interacts with other CrowdHEALTH’s components, for instance the Big Data Platform, that depends on user authentication and authorization. CrowdHEALTH users are able to access the CrowdHEALTH’s database based on the result of an ABAC request. Moreover, due to the fact that the CrowdHEALTH system requires proofs during the interactions with data producers of low trust or low reputation level, the requirements for the Trust and Reputation Model have been identified. CONCLUSION: The CrowdHEALTH Integrated Holistic Security and Privacy framework meets the security criteria for an e-health cross-border system, due to the adoption of security mechanisms, such as user authentication, user authorization, access control, data anonymization, trust management and reputation modelling. The implemented framework remains to be tested to ensure its robustness and to evaluate its performance. The holistic security and privacy framework might be adapted during the project’s life circle according to new legislations. Academy of Medical sciences 2019-12 /pmc/articles/PMC7085323/ /pubmed/32210501 http://dx.doi.org/10.5455/aim.2019.27.333-340 Text en © 2019 Stefanos Malliaros, Christos Xenakis, George Moldovan, John Mantas, Andriana Magdalinou, Lydia Montandon http://creativecommons.org/licenses/by-nc/4.0/ This is an Open Access article distributed under the terms of the Creative Commons Attribution Non-Commercial License (http://creativecommons.org/licenses/by-nc/4.0/) which permits unrestricted non-commercial use, distribution, and reproduction in any medium, provided the original work is properly cited.
spellingShingle Original Paper
Malliaros, Stefanos
Xenakis, Christos
Moldovan, George
Mantas, John
Magdalinou, Andriana
Montandon, Lydia
The Integrated Holistic Security and Privacy Framework Deployed in CrowdHEALTH Project
title The Integrated Holistic Security and Privacy Framework Deployed in CrowdHEALTH Project
title_full The Integrated Holistic Security and Privacy Framework Deployed in CrowdHEALTH Project
title_fullStr The Integrated Holistic Security and Privacy Framework Deployed in CrowdHEALTH Project
title_full_unstemmed The Integrated Holistic Security and Privacy Framework Deployed in CrowdHEALTH Project
title_short The Integrated Holistic Security and Privacy Framework Deployed in CrowdHEALTH Project
title_sort integrated holistic security and privacy framework deployed in crowdhealth project
topic Original Paper
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7085323/
https://www.ncbi.nlm.nih.gov/pubmed/32210501
http://dx.doi.org/10.5455/aim.2019.27.333-340
work_keys_str_mv AT malliarosstefanos theintegratedholisticsecurityandprivacyframeworkdeployedincrowdhealthproject
AT xenakischristos theintegratedholisticsecurityandprivacyframeworkdeployedincrowdhealthproject
AT moldovangeorge theintegratedholisticsecurityandprivacyframeworkdeployedincrowdhealthproject
AT mantasjohn theintegratedholisticsecurityandprivacyframeworkdeployedincrowdhealthproject
AT magdalinouandriana theintegratedholisticsecurityandprivacyframeworkdeployedincrowdhealthproject
AT montandonlydia theintegratedholisticsecurityandprivacyframeworkdeployedincrowdhealthproject
AT malliarosstefanos integratedholisticsecurityandprivacyframeworkdeployedincrowdhealthproject
AT xenakischristos integratedholisticsecurityandprivacyframeworkdeployedincrowdhealthproject
AT moldovangeorge integratedholisticsecurityandprivacyframeworkdeployedincrowdhealthproject
AT mantasjohn integratedholisticsecurityandprivacyframeworkdeployedincrowdhealthproject
AT magdalinouandriana integratedholisticsecurityandprivacyframeworkdeployedincrowdhealthproject
AT montandonlydia integratedholisticsecurityandprivacyframeworkdeployedincrowdhealthproject