Suppr超能文献

使用基于属性加密的细粒度数据库字段搜索用于电子医疗云

Fine-grained Database Field Search Using Attribute-Based Encryption for E-Healthcare Clouds.

作者信息

Guo Cheng, Zhuang Ruhan, Jie Yingmo, Ren Yizhi, Wu Ting, Choo Kim-Kwang Raymond

机构信息

School of Software Technology, Dalian University of Technology, Dalian, China.

Key Laboratory for Ubiquitous Network and Service Software of Liaoning Province, Dalian, China.

出版信息

J Med Syst. 2016 Nov;40(11):235. doi: 10.1007/s10916-016-0588-0. Epub 2016 Sep 21.

Abstract

An effectively designed e-healthcare system can significantly enhance the quality of access and experience of healthcare users, including facilitating medical and healthcare providers in ensuring a smooth delivery of services. Ensuring the security of patients' electronic health records (EHRs) in the e-healthcare system is an active research area. EHRs may be outsourced to a third-party, such as a community healthcare cloud service provider for storage due to cost-saving measures. Generally, encrypting the EHRs when they are stored in the system (i.e. data-at-rest) or prior to outsourcing the data is used to ensure data confidentiality. Searchable encryption (SE) scheme is a promising technique that can ensure the protection of private information without compromising on performance. In this paper, we propose a novel framework for controlling access to EHRs stored in semi-trusted cloud servers (e.g. a private cloud or a community cloud). To achieve fine-grained access control for EHRs, we leverage the ciphertext-policy attribute-based encryption (CP-ABE) technique to encrypt tables published by hospitals, including patients' EHRs, and the table is stored in the database with the primary key being the patient's unique identity. Our framework can enable different users with different privileges to search on different database fields. Differ from previous attempts to secure outsourcing of data, we emphasize the control of the searches of the fields within the database. We demonstrate the utility of the scheme by evaluating the scheme using datasets from the University of California, Irvine.

摘要

一个设计有效的电子医疗保健系统可以显著提高医疗保健用户的访问质量和体验,包括帮助医疗保健提供者确保服务的顺利提供。确保电子医疗保健系统中患者电子健康记录(EHR)的安全性是一个活跃的研究领域。由于成本节约措施,EHR可能会外包给第三方,如社区医疗保健云服务提供商进行存储。通常,在EHR存储在系统中(即静态数据)或外包数据之前对其进行加密,以确保数据机密性。可搜索加密(SE)方案是一种很有前途的技术,可以在不影响性能的情况下确保对私人信息的保护。在本文中,我们提出了一个新颖的框架,用于控制对半可信云服务器(如私有云或社区云)中存储的EHR的访问。为了实现对EHR的细粒度访问控制,我们利用基于密文策略属性的加密(CP-ABE)技术对医院发布的表格进行加密,包括患者的EHR,并且该表格存储在数据库中,主键为患者的唯一身份。我们的框架可以使具有不同权限的不同用户在不同的数据库字段上进行搜索。与以前保护数据外包的尝试不同,我们强调对数据库内字段搜索的控制。我们通过使用来自加利福尼亚大学欧文分校的数据集对该方案进行评估,展示了该方案的实用性。

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验