Blockchain-Based Service-Oriented Architecture for Consent Management, Access Control, and Auditing

被引:11
|
作者
Roman-Martinez, Isabel [1 ,2 ]
Calvillo-Arbizu, Jorge [1 ,3 ]
Mayor-Gallego, Vicente J. J. [1 ,2 ]
Madinabeitia-Luque, German [1 ,2 ]
Estepa-Alonso, Antonio J. J. [1 ,2 ]
Estepa-Alonso, Rafael M. M. [1 ,2 ]
机构
[1] Escuela Tecn Super Ingn, Dept Ingn Telemat, Seville 41092, Spain
[2] Univ Seville, Grp Ingn Telemat, Seville 41092, Spain
[3] Univ Seville, Grp Ingn Biomed, Seville 41092, Spain
关键词
Blockchains; Service-oriented architecture; Access control; Medical services; Health information management; General Data Protection Regulation; Blockchain; consent management; fast healthcare information resources (FHIR); general data protection regulation (GDPR); service-oriented architecture (SOA); business process management (BPM); MODEL;
D O I
10.1109/ACCESS.2023.3242605
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Continuity of care requires the exchange of health information among organizations and care teams. The EU General Data Protection Regulation (GDPR) establishes that subject of care should give explicit consent to the treatment of her personal data, and organizations must obey the individual's will. Nevertheless, few solutions focus on guaranteeing the proper execution of consents. We propose a service-oriented architecture, backed by blockchain technology, that enables: (1) tamper-proof and immutable storage of subject of care consents; (2) a fine-grained access control for protecting health data according to consents; and (3) auditing tasks for supervisory authorities (or subjects of care themselves) to assess that healthcare organizations comply with GDPR and granted consents. Standards for health information exchange and access control are adopted to guarantee interoperability. Access control events and the subject of care consents are maintained on a blockchain, providing a trusted collaboration between organizations, supervisory authorities, and individuals. A prototype of the architecture has been implemented as a proof of concept to evaluate the performance of critical components. The application of subject of care consent to control the treatment of personal health data in federated and distributed environments is a pressing concern. The experimental results show that blockchain can effectively support sharing consent and audit events among healthcare organizations, supervisory authorities, and individuals.
引用
收藏
页码:12726 / 12740
页数:15
相关论文
共 50 条
  • [1] A Blockchain-Based Trust Framework for Service-Oriented Architecture
    Chen, Hanlin
    Chen, Yan
    Lin, Bing
    Bullet, Xing Chen
    Ma, Yun
    Huang, Gang
    2024 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, ICWS 2024, 2024, : 437 - 446
  • [2] A Blockchain-Based Architecture for Access Control Management of IoT Applications
    Moursy, Islam Ahmed
    Ghanem, Sahar Mohamed
    ElDerini, Mohamed Nazih
    2022 27TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2022), 2022,
  • [3] A Blockchain-Based Hybrid Architecture for Auditable Consent Management
    Can, Ozgu
    Dag, Tunahan
    Kantarcioglu, Murat
    IEEE ACCESS, 2024, 12 : 100419 - 100445
  • [4] Privacy Preserving Access Control in Service-Oriented Architecture
    Ranchal, Rohit
    Bhargava, Bharat
    Fernando, Ruchith
    Lei, Hui
    Jin, Zhongjun
    2016 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES (ICWS), 2016, : 412 - 419
  • [5] Ontology Management in a Service-oriented Architecture Architecture of a Knowledge Base Access Service
    Mossgraber, Juergen
    Rospocher, Marco
    2012 23RD INTERNATIONAL WORKSHOP ON DATABASE AND EXPERT SYSTEMS APPLICATIONS (DEXA), 2012, : 289 - 293
  • [6] A Blockchain-Based Service-Oriented Framework to Enable Cooperation of Swarm Robots
    Huang, Chung-Yu
    Li, Jhih-Yi
    Huang, Jhih-Yuan
    Lee, Wei-Po
    ADVANCES IN SWARM INTELLIGENCE, ICSI 2023, PT II, 2023, 13969 : 3 - 15
  • [7] Privacy-Oriented Blockchain-Based Distributed Key Management Architecture for Hierarchical Access Control in the IoT Scenario
    Ma, Mingxin
    Shi, Guozhen
    Li, Fenghua
    IEEE ACCESS, 2019, 7 : 34045 - 34059
  • [8] Intelligent security and access control framework for service-oriented architecture
    El Yamany, Hany F.
    Capretz, Miriam A. M.
    Allison, David S.
    INFORMATION AND SOFTWARE TECHNOLOGY, 2010, 52 (02) : 220 - 236
  • [9] Exploration of access control mechanisms for service-oriented network architecture
    Rudra, Bhawana
    Vyas, O. P.
    INTERNATIONAL JOURNAL OF INTERNET PROTOCOL TECHNOLOGY, 2015, 9 (01) : 1 - 11
  • [10] Service-oriented role-based access control
    Xu, Feng
    Lai, Hai-Guang
    Huang, Hao
    Xie, Li
    Jisuanji Xuebao/Chinese Journal of Computers, 2005, 28 (04): : 686 - 693