Blockchain-Based Service-Oriented Architecture for Consent Management, Access Control, and Auditing

被引:11
|
作者
Roman-Martinez, Isabel [1 ,2 ]
Calvillo-Arbizu, Jorge [1 ,3 ]
Mayor-Gallego, Vicente J. J. [1 ,2 ]
Madinabeitia-Luque, German [1 ,2 ]
Estepa-Alonso, Antonio J. J. [1 ,2 ]
Estepa-Alonso, Rafael M. M. [1 ,2 ]
机构
[1] Escuela Tecn Super Ingn, Dept Ingn Telemat, Seville 41092, Spain
[2] Univ Seville, Grp Ingn Telemat, Seville 41092, Spain
[3] Univ Seville, Grp Ingn Biomed, Seville 41092, Spain
关键词
Blockchains; Service-oriented architecture; Access control; Medical services; Health information management; General Data Protection Regulation; Blockchain; consent management; fast healthcare information resources (FHIR); general data protection regulation (GDPR); service-oriented architecture (SOA); business process management (BPM); MODEL;
D O I
10.1109/ACCESS.2023.3242605
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Continuity of care requires the exchange of health information among organizations and care teams. The EU General Data Protection Regulation (GDPR) establishes that subject of care should give explicit consent to the treatment of her personal data, and organizations must obey the individual's will. Nevertheless, few solutions focus on guaranteeing the proper execution of consents. We propose a service-oriented architecture, backed by blockchain technology, that enables: (1) tamper-proof and immutable storage of subject of care consents; (2) a fine-grained access control for protecting health data according to consents; and (3) auditing tasks for supervisory authorities (or subjects of care themselves) to assess that healthcare organizations comply with GDPR and granted consents. Standards for health information exchange and access control are adopted to guarantee interoperability. Access control events and the subject of care consents are maintained on a blockchain, providing a trusted collaboration between organizations, supervisory authorities, and individuals. A prototype of the architecture has been implemented as a proof of concept to evaluate the performance of critical components. The application of subject of care consent to control the treatment of personal health data in federated and distributed environments is a pressing concern. The experimental results show that blockchain can effectively support sharing consent and audit events among healthcare organizations, supervisory authorities, and individuals.
引用
收藏
页码:12726 / 12740
页数:15
相关论文
共 50 条
  • [21] Service-oriented architecture and enterprise content management
    不详
    ECONTENT, 2007, 30 (08) : 26 - 29
  • [22] A Blockchain-Based Flexible Data Auditing Scheme for the Cloud Service
    FAN Kefeng
    LI Fei
    YU Haiyang
    YANG Zhen
    ChineseJournalofElectronics, 2021, 30 (06) : 1159 - 1166
  • [23] A Blockchain-Based Flexible Data Auditing Scheme for the Cloud Service
    Fan Kefeng
    Li Fei
    Yu Haiyang
    Yang Zhen
    CHINESE JOURNAL OF ELECTRONICS, 2021, 30 (06) : 1159 - 1166
  • [24] Service-oriented architecture
    Perrey, R
    Lycett, M
    2003 SYMPOSIUM ON APPLICATIONS AND THE INTERNET WORKSHOPS, PROCEEDINGS, 2003, : 116 - 119
  • [25] A service-oriented data access control model
    Meng, Wei
    Li, Fengmin
    Pan, Juchen
    Song, Song
    Bian, Jiali
    SEVENTH INTERNATIONAL CONFERENCE ON ELECTRONICS AND INFORMATION ENGINEERING, 2017, 10322
  • [26] Service-oriented Architecture in IT
    Xin, Chen
    2009 ASIA-PACIFIC CONFERENCE ON INFORMATION PROCESSING (APCIP 2009), VOL 2, PROCEEDINGS, 2009, : 493 - 496
  • [27] Service-oriented architecture
    Akerman, Richard
    LIBRARY JOURNAL, 2007, : 7 - 7
  • [28] Blockchain-based access control for enterprise blockchain applications
    Xu, Lei
    Markus, Isaac
    Subhod, I
    Nayab, Nikhil
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2020, 30 (05)
  • [29] A taxonomic framework for autonomous service management in Service-Oriented Architecture
    Cheun, Du Wan
    La, Hyun Jung
    Kim, Soo Dong
    JOURNAL OF ZHEJIANG UNIVERSITY-SCIENCE C-COMPUTERS & ELECTRONICS, 2012, 13 (05): : 339 - 354
  • [30] A taxonomic framework for autonomous service management in Service-Oriented Architecture
    Du Wan Cheun
    Hyun Jung La
    Soo Dong Kim
    Journal of Zhejiang University SCIENCE C, 2012, 13 : 339 - 354