Blockchain-Based Service-Oriented Architecture for Consent Management, Access Control, and Auditing

被引:11
|
作者
Roman-Martinez, Isabel [1 ,2 ]
Calvillo-Arbizu, Jorge [1 ,3 ]
Mayor-Gallego, Vicente J. J. [1 ,2 ]
Madinabeitia-Luque, German [1 ,2 ]
Estepa-Alonso, Antonio J. J. [1 ,2 ]
Estepa-Alonso, Rafael M. M. [1 ,2 ]
机构
[1] Escuela Tecn Super Ingn, Dept Ingn Telemat, Seville 41092, Spain
[2] Univ Seville, Grp Ingn Telemat, Seville 41092, Spain
[3] Univ Seville, Grp Ingn Biomed, Seville 41092, Spain
关键词
Blockchains; Service-oriented architecture; Access control; Medical services; Health information management; General Data Protection Regulation; Blockchain; consent management; fast healthcare information resources (FHIR); general data protection regulation (GDPR); service-oriented architecture (SOA); business process management (BPM); MODEL;
D O I
10.1109/ACCESS.2023.3242605
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Continuity of care requires the exchange of health information among organizations and care teams. The EU General Data Protection Regulation (GDPR) establishes that subject of care should give explicit consent to the treatment of her personal data, and organizations must obey the individual's will. Nevertheless, few solutions focus on guaranteeing the proper execution of consents. We propose a service-oriented architecture, backed by blockchain technology, that enables: (1) tamper-proof and immutable storage of subject of care consents; (2) a fine-grained access control for protecting health data according to consents; and (3) auditing tasks for supervisory authorities (or subjects of care themselves) to assess that healthcare organizations comply with GDPR and granted consents. Standards for health information exchange and access control are adopted to guarantee interoperability. Access control events and the subject of care consents are maintained on a blockchain, providing a trusted collaboration between organizations, supervisory authorities, and individuals. A prototype of the architecture has been implemented as a proof of concept to evaluate the performance of critical components. The application of subject of care consent to control the treatment of personal health data in federated and distributed environments is a pressing concern. The experimental results show that blockchain can effectively support sharing consent and audit events among healthcare organizations, supervisory authorities, and individuals.
引用
收藏
页码:12726 / 12740
页数:15
相关论文
共 50 条
  • [31] Identity as a service - Towards a service-oriented identity management architecture
    Emig, Christian
    Brandt, Frank
    Kreuzer, Sebastian
    Abeck, Sebastian
    DEPENDABLE AND ADAPTABLE NETWORKS AND SERVICES, PROCEEDINGS, 2007, 4606 : 1 - +
  • [32] A situation-aware access control based privacy-preserving service matchmaking approach for Service-Oriented Architecture
    Yau, Stephen S.
    Liu, Junwei
    2007 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2007, : 1056 - +
  • [33] An enterprise electronic contract management system based on service-oriented architecture
    Chieu, Trieu C.
    Nguyen, Thao
    Maradugu, Sridhar
    Kwok, Thomas
    2007 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS, 2007, : 613 - +
  • [34] A taxonomic framework for autonomous service management in Service-Oriented Architecture
    Du Wan CHEUN
    Hyun Jung LA
    Soo Dong KIM
    JournalofZhejiangUniversity-ScienceC(Computers&Electronics), 2012, 13 (05) : 339 - 354
  • [35] Blockchain-based Auxiliary Systems for Pseudonymization and Consent Management
    Lapwattanaworakul, Jiraphat
    Srisa-An, Chetneti
    Aribarg, Thannob
    TEM JOURNAL-TECHNOLOGY EDUCATION MANAGEMENT INFORMATICS, 2023, 12 (04): : 2470 - 2480
  • [36] On Composition of Service Component Based on Service-Oriented Architecture
    Wan Fang
    Shen JianJing
    Han Ding
    Zhang Hui
    PROCEEDINGS OF THE 27TH CHINESE CONTROL CONFERENCE, VOL 5, 2008, : 573 - +
  • [37] A taxonomic framework for autonomous service management in Service-Oriented Architecture
    Du Wan Cheun
    Hyun Jung La
    Soo Dong Kim
    Frontiers of Information Technology & Electronic Engineering, 2014, (01) : 12 - 12
  • [38] Platform for intelligent management of Industrial Machinery based on service-oriented architecture
    Herrera-Quintero, Luis Felipe
    Berenguer-Miralles, Vicente
    Restrepo-Calle, Felipe
    Gomez, Raul
    Gilart-Iglesias, Virgilio
    Macia-Perez, Francisco
    DISTANCE LEARNING, MULTIMEDIA AND VIDEO TECHNOLOGIES, 2008, : 121 - 127
  • [39] A taxonomic framework for autonomous service management in Service-Oriented Architecture
    Du Wan CHEUN
    Hyun Jung LA
    Soo Dong KIM
    Frontiers of Information Technology & Electronic Engineering, 2012, (05) : 339 - 354
  • [40] A Blockchain-based Data Usage Auditing Architecture with Enhanced Privacy and Availability
    Kaaniche, Nesrine
    Laurent, Maryline
    2017 IEEE 16TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2017, : 403 - 407