Lu Chenglang, Wu Zongda, Liu Mingyong, Chen Wei, Guo Junfang
Northwestern Polytechnical University, 710072, Xi'an, Shanxi, People's Republic of China,
J Med Syst. 2013 Dec;37(6):9982. doi: 10.1007/s10916-013-9982-z. Epub 2013 Oct 30.
In medical information systems, there are a lot of confidential information about patient privacy. It is therefore an important problem how to prevent patient's personal privacy information from being disclosed. Although traditional security protection strategies (such as identity authentication and authorization access control) can well ensure data integrity, they cannot prevent system's internal staff (such as administrators) from accessing and disclosing patient privacy information. In this paper, we present an effective scheme to protect patients' personal privacy for a medical information system. In the scheme, privacy data before being stored in the database of the server of a medical information system would be encrypted using traditional encryption algorithms, so that the data even if being disclosed are also difficult to be decrypted and understood. However, to execute various kinds of query operations over the encrypted data efficiently, we would also augment the encrypted data with additional index, so as to process as much of the query as possible at the server side, without the need to decrypt the data. Thus, in this paper, we mainly explore how the index of privacy data is constructed, and how a query operation over privacy data is translated into a new query over the corresponding index so that it can be executed at the server side immediately. Finally, both theoretical analysis and experimental evaluation validate the practicality and effectiveness of our proposed scheme.
在医疗信息系统中,存在大量关于患者隐私的机密信息。因此,如何防止患者个人隐私信息被泄露是一个重要问题。虽然传统的安全保护策略(如身份认证和授权访问控制)能够很好地确保数据完整性,但它们无法防止系统内部人员(如管理员)访问和泄露患者隐私信息。在本文中,我们提出了一种为医疗信息系统保护患者个人隐私的有效方案。在该方案中,医疗信息系统服务器数据库中存储的隐私数据在存储前将使用传统加密算法进行加密,这样即使数据被泄露也难以被解密和理解。然而,为了高效地对加密数据执行各种查询操作,我们还会为加密数据添加额外的索引,以便在服务器端处理尽可能多的查询,而无需解密数据。因此,在本文中,我们主要探讨隐私数据索引如何构建,以及对隐私数据的查询操作如何转换为对相应索引的新查询,以便能在服务器端立即执行。最后,理论分析和实验评估都验证了我们所提方案的实用性和有效性。