Brown Jordan, Blough Douglas M
School of Electrical & Computer Engr., Georgia Inst. of Technol., Atlanta, GA, USA.
AMIA Annu Symp Proc. 2012;2012:1148-57. Epub 2012 Nov 3.
This paper considers how to verify provenance and integrity of data in medical documents that are exchanged in a distributed system of health IT services. Provenance refers to the sources of health information within the document and integrity means that the information was not modified after generation by the source. Our approach allows intermediate parties to redact the document by removing information that they do not wish to reveal. For example, patients can store verifiable health information and provide subsets of it to third parties, while redacting sensitive information that they do not wish employers, insurers, or others to receive. Our method uses a cryptographic primitive known as a redactable signature. We study practical issues and performance impacts of building, redacting, and verifying Continuity of Care Documents (CCDs) that are protected with redactable signatures. Results show that manipulating redactable CCDs provides superior security and privacy with little computational overhead.
本文探讨了如何在健康信息技术服务分布式系统中交换的医疗文档中验证数据的来源和完整性。来源指文档中健康信息的出处,完整性意味着信息在由来源生成后未被修改。我们的方法允许中间方通过删除他们不想透露的信息来编辑文档。例如,患者可以存储可验证的健康信息,并将其中的子集提供给第三方,同时编辑他们不希望雇主、保险公司或其他方接收的敏感信息。我们的方法使用一种称为可编辑签名的密码原语。我们研究了构建、编辑和验证用可编辑签名保护的医疗护理连续性文档(CCD)的实际问题和性能影响。结果表明,操作可编辑的CCD能在几乎没有计算开销的情况下提供卓越的安全性和隐私性。