SmartAccess: Attribute-Based Access Control System for Medical Records Based on Smart Contracts

被引:9
|
作者
De Oliveira, Marcela Tuler [1 ,2 ]
Reis, Lucio Henrik Amorim [1 ,2 ,3 ]
Verginadis, Yiannis [4 ,5 ]
Mattos, Diogo Menezes Ferrazani [3 ]
Olabarriaga, Silvia Delgado [1 ]
机构
[1] Locat Univ Amsterdam, Epidemiol & Data Sci Dept, Amsterdam UMC, NL-1105 AZ Amsterdam, Netherlands
[2] Locat Univ Amsterdam, Biomed Engn & Phys Dept, Amsterdam UMC, NL-1105 AZ Amsterdam, Netherlands
[3] Univ Fed Fluminense, MidiaCom TET PPGEET, UFF, BR-24020140 Niteroi, RJ, Brazil
[4] Athens Univ Econ & Business AUEB, Sch Business, Dept Business Adm, Athens 10434, Greece
[5] Natl Tech Univ Athens NTUA, Inst Commun & Comp Syst, Athens 15780, Greece
基金
欧盟地平线“2020”;
关键词
Attribute-based access control; blockchain; cross-organisation security; electronic medical records; GDPR; healthcare information system; smart contracts; FRAMEWORK; PRIVACY; SECURE;
D O I
10.1109/ACCESS.2022.3217201
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cross-organisation data sharing is challenging because all the involved organisations must agree on 'how' and 'why' the data is processed. Due to a lack of transparency, the organisations need to trust that others comply with the agreements and regulations. We propose to exploit blockchain and smart contracts technologies to define an Attribute-Based Access Control System for cross-organisation medical records sharing, coined SmartAccess. SmartAccess offers joint agreement over access policies and dynamic access control besides blockchain transparency and auditability. We leverage the Attribute-Based Access Control model to implement smart contracts. We deploy and test them on a private and permissioned blockchain, transforming the access control process into a distributed smart contract execution. This paper proposes the SmartAccess system and its application in two healthcare use cases. We introduce the threat model and perform a security analysis of the system. To demonstrate the feasibility of our proposal, we implement a proof-of-concept of the smart contracts, written in Solidity language, with a size-efficient policy representation, and analyse the complexity and scalability of the contracts' functions. Furthermore, we present performance results, measuring the latency and throughput of the transactions to execute the access control functions with different blockchain network consensus setups. We also compare the performance of the SmartAccess system against two open-source Solidity implementations of smart contract-based access control, Role-based Access Control and Access Control List. Finally, we discuss the strengths and drawbacks of our proposal. SmartAccess requires the overhead of a decentralised system, but the trade-off is transparency, regulation compliance and auditability for complex cross-organisation data sharing.
引用
收藏
页码:117836 / 117854
页数:19
相关论文
共 50 条
  • [41] Distributed attribute-based access control system using permissioned blockchain
    Rouhani, Sara
    Belchior, Rafael
    Cruz, Rui S.
    Deters, Ralph
    World Wide Web, 2021, 24 (05): : 1617 - 1644
  • [42] Efficiently Attribute-Based Access Control for Mobile Cloud Storage System
    Lv, Zhiquan
    Chi, Jialin
    Zhang, Min
    Feng, Dengguo
    2014 IEEE 13TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM), 2014, : 292 - 299
  • [43] Distributed attribute-based access control system using permissioned blockchain
    Sara Rouhani
    Rafael Belchior
    Rui S. Cruz
    Ralph Deters
    World Wide Web, 2021, 24 : 1617 - 1644
  • [44] Distributed attribute-based access control system using permissioned blockchain
    Rouhani, Sara
    Belchior, Rafael
    Cruz, Rui S.
    Deters, Ralph
    WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2021, 24 (05): : 1617 - 1644
  • [45] Attribute-based Network and System Access Control Architecture for Industrial Machines
    Kern, Alexander
    Anderl, Reiner
    2019 SIXTH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS: SYSTEMS, MANAGEMENT AND SECURITY (IOTSMS), 2019, : 299 - 306
  • [46] Accountable multi-authority attribute-based data access control in smart grids
    Zhang, Leyou
    Yang, Guang
    Song, Chao
    Wu, Qing
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2023, 35 (07)
  • [47] Dynamic Groups and Attribute-Based Access Control for Next-Generation Smart Cars
    Gupta, Maanak
    Benson, James
    Patwa, Farhan
    Sandhu, Ravi
    PROCEEDINGS OF THE NINTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY (CODASPY '19), 2019, : 61 - 72
  • [48] Attribute-Based Collaborative Access Control Scheme with Constant Ciphertext Length for Smart Grid
    Ge, Jiangyan
    Wen, Mi
    Wang, Liangliang
    Xie, Rong
    IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2022), 2022, : 540 - 546
  • [49] A user-friendly attribute-based data access control scheme for smart grids
    Mu, Tianshi
    Lai, Yuyang
    Feng, Guocong
    Lyu, Huahui
    Yang, Hang
    Deng, Jianfeng
    ALEXANDRIA ENGINEERING JOURNAL, 2023, 67 : 209 - 217
  • [50] Enabling Attribute-Based Access Control in NoSQL Databases
    Gupta, Eeshan
    Sural, Shamik
    Vaidya, Jaideep
    Atluri, Vijayalakshmi
    IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTING, 2023, 11 (01) : 208 - 223