A smart contract-driven access control scheme with integrity checking for electronic health records

被引:0
|
作者
Li, Hongzhi [1 ]
Li, Dun [2 ]
Liang, Wei [3 ]
机构
[1] Chizhou Univ, Sch Big Data & Artificial Intelligence, Chizhou 247000, Peoples R China
[2] Tsinghua Univ, Dept Ind Engn, Beijing 100000, Peoples R China
[3] Hunan Univ Sci & Technol, Sch Comp Sci & Engn, Xiangtan 411100, Peoples R China
关键词
Smart contract; Access control; Electronic health records (EHRs); Data integrity; Healthcare systems; INTERNET; MODEL;
D O I
10.1007/s10586-024-04524-1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The application of healthcare systems has led to an explosive growth in personal electronic health records (EHRs). These EHRs are generated from different healthcare institutions and stored in cloud data centers, respectively. However, data owners lose the authority to control and track their private and sensitive EHRs. In fact, data owners cannot establish rules for EHRs exchanging and sharing, nor can they verify the integrity of EHRs stored in semi-trusted clouds. Hence, an individual-centric access control framework is required to realize data access control. In this study, we construct a data access control framework, which integrates decentralized smart contracts and role-based access control (RBAC) to provide fine-grained data access control services. The key ideas of this schme includes: (1) a fine-grained access control framework for EHRs is proposed to achieve trusted access control; (2) a personalized policies definition mechanism is adopted to achieve patient-centric data access control; (3) a integrity checking mechanism for the shared EHRs is implemented to ensure the availability of medical records. Finally, we analyze the security properties of this scheme and develop a prototype system to evaluate its performance. Both theoretical analysis and experiment results demonstrate that this scheme can provide fine-grained access control and efficient integrity checking services for EHRs.
引用
收藏
页码:11515 / 11535
页数:21
相关论文
共 50 条
  • [1] Decentralized Data Access with IPFS and Smart Contract Permission Management for Electronic Health Records
    Verdonck, Michael
    Poels, Geert
    BUSINESS PROCESS MANAGEMENT WORKSHOPS, BPM 2020 INTERNATIONAL WORKSHOPS, 2020, 397 : 5 - 16
  • [2] Specifying and verifying contract-driven service compositions using commitments and model checking
    Bataineh, Ahmed Saleh
    Bentahar, Jamal
    El Menshawy, Mohamed
    Dssouli, Rachida
    EXPERT SYSTEMS WITH APPLICATIONS, 2017, 74 : 151 - 184
  • [3] An Attribute Based Access Control Scheme for Secure Sharing of Electronic Health Records
    Pussewalage, Harsha S. Gardiyawasam
    Oleshchuk, Vladimir A.
    2016 IEEE 18TH INTERNATIONAL CONFERENCE ON E-HEALTH NETWORKING, APPLICATIONS AND SERVICES (HEALTHCOM), 2016, : 551 - 556
  • [4] Smart Contract-Driven Mechanism Design to Mitigate Information Diffusion in Social Networks
    Paul, Arinjita
    Suppakitpaisarn, Vorapong
    Rangan, C. Pandu
    MATHEMATICAL RESEARCH FOR BLOCKCHAIN ECONOMY, MARBLE 2019, 2020, : 201 - 216
  • [5] Unlocking Blockchain Interconnectivity: Smart Contract-Driven Cross-Chain Communication
    Zala, Kirtirajsinh
    Modi, Vyom
    Giri, Deepakkumar
    Acharya, Biswaranjan
    Mallik, Saurav
    Qin, Hong
    IEEE ACCESS, 2023, 11 : 75365 - 75380
  • [6] Efficient Privacy-Preserving Access Control Scheme in Electronic Health Records System
    Ming, Yang
    Zhang, Tingting
    SENSORS, 2018, 18 (10)
  • [7] A Fine-Grained Access Control Scheme for Electronic Health Records Based on Roles and Attributes
    Zhang, Shaobo
    Yang, Shuo
    Zhu, Gengming
    Luo, Entao
    Zhang, Jiyong
    Xiang, Desheng
    UBIQUITOUS SECURITY, 2022, 1557 : 25 - 37
  • [8] Privacy Oriented Access Control for Electronic Health Records
    Gajanayake, Randike
    Lannella, Renato
    Sahama, Tony
    ELECTRONIC JOURNAL OF HEALTH INFORMATICS, 2014, 8 (02):
  • [9] Access control requirements for processing electronic health records
    Alhaqbani, Bandar
    Fidge, Colin
    BUSINESS PROCESS MANAGEMENT WORKSHOPS, 2008, 4928 : 371 - 382
  • [10] Attribute-Based Access Control for Smart Cities: A Smart-Contract-Driven Framework
    Zhang, Yuanyu
    Yutaka, Mirei
    Sasabe, Masahiro
    Kasahara, Shoji
    IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (08) : 6372 - 6384