Ullah Faheem, He Jingsha, Zhu Nafei, Wajahat Ahsan, Nazir Ahsan, Qureshi Sirajuddin, Pathan Muhammad Salman, Dev Soumyabrata
Faculty of Information Technology, Beijing University of Technology, Beijing, China.
School of Computing, Dublin City University, Dublin, Ireland.
Heliyon. 2024 Aug 10;10(16):e34407. doi: 10.1016/j.heliyon.2024.e34407. eCollection 2024 Aug 30.
In the realm of modern healthcare, Electronic Health Records serve as invaluable assets, yet they also pose significant security challenges. The absence of access auditing mechanisms, which includes the audit trails, results in accountability gaps and magnifies security vulnerabilities. This situation effectively paves the way for unauthorized data alterations to occur without detection or consequences. Inadequate compliance auditing procedures, particularly in verifying and validating access control policies, expose healthcare organizations to risks such as data breaches, and unauthorized data usage. These vulnerabilities result from unchecked unauthorized access activities. Additionally, the absence of audit logs complicates investigations, weakens proactive security measures, and raises concerns to put healthcare institutions at risk. This study addresses the pressing need for robust auditing systems designed to scrutinize access to data, encompassing who accesses it, when, and for what purpose. Our research delves into the complex field of auditing, which includes establishing an immutable audit trail to enhance data security through blockchain technology. We also integrate Purpose-Based Access Control () alongside smart contracts to strengthen compliance auditing by validating access legitimacy and reducing unauthorized entries. Our contributions encompass the creation of audit trail of access, compliance auditing via policy verification, the generation of audit logs, and the derivation of data-driven insights, fortifying access security.
在现代医疗保健领域,电子健康记录是非常宝贵的资产,但也带来了重大的安全挑战。缺乏包括审计跟踪在内的访问审计机制,会导致问责漏洞,并放大安全漏洞。这种情况实际上为未经授权的数据更改创造了条件,使其在未被发现或无需承担后果的情况下发生。合规审计程序不完善,尤其是在验证和确认访问控制策略方面,使医疗保健组织面临数据泄露和未经授权的数据使用等风险。这些漏洞源于未经检查的未经授权访问活动。此外,缺乏审计日志会使调查复杂化,削弱主动安全措施,并引发对将医疗机构置于风险之中的担忧。本研究满足了对强大审计系统的迫切需求,该系统旨在审查对数据的访问,包括谁访问了数据、何时访问以及出于何种目的访问。我们的研究深入探讨了审计这一复杂领域,其中包括通过区块链技术建立不可变的审计跟踪以增强数据安全性。我们还将基于目的的访问控制(Purpose-Based Access Control,PBAC)与智能合约相结合,通过验证访问合法性和减少未经授权的条目来加强合规审计。我们的贡献包括创建访问审计跟踪、通过策略验证进行合规审计、生成审计日志以及得出数据驱动的见解,从而加强访问安全性。