• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

基于区块链的策略访问控制机制,用于限制对电子健康记录的未经授权访问。

Blockchain enabled policy-based access control mechanism to restrict unauthorized access to electronic health records.

作者信息

Yaqub Nadeem, Zhang Jianbiao, Khalid Muhammad Irfan, Wang Weiru, Helfert Markus, Ahmed Mansoor, Kim Jungsuk

机构信息

Department of Computer Science and Technology, Beijing University of Technology, Beijing, China.

Department of Information Technology, University of Sialkot, Sialkot, Punjab, Pakistan.

出版信息

PeerJ Comput Sci. 2025 Jan 23;11:e2647. doi: 10.7717/peerj-cs.2647. eCollection 2025.

DOI:10.7717/peerj-cs.2647
PMID:39896036
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC11784709/
Abstract

Electronic health record transmission and storage involve sensitive information, requiring robust security measures to ensure access is limited to authorized personnel. In the existing state of the art, there is a growing need for efficient access control approaches for the secure accessibility of patient health data by sustainable electronic health records. Locking medical data in a healthcare center forms information isolation; thus, setting up healthcare data exchange platforms is a driving force behind electronic healthcare centers. The healthcare entities access rights like subject, controller, and requester are defined and regulated by access control policies as defined by the General Data Protection Regulation (GDPR). In this work, we have introduced a blend of policy-based access control (PBAC) system backed by blockchain technology, where smart contracts govern the intrinsic part of security and privacy. As a result, any Subject can know at any time who currently has the right to access his data. The PBAC grants access to electronic health records based on predefined policies. Our proposed PBAC approach employs policies in which the subject, controller, and requester can grant access, revoke access, and check logs and actions made in a particular healthcare system. Smart contracts dynamically enforce access control policies and manage access permissions, ensuring that sensitive data is available only to authorized users. Delineating the proposed access control system and comparing it to other systems demonstrates that our approach is more adaptable to various healthcare data protection scenarios where there is a need to share sensitive data simultaneously and a robust need to safeguard the rights of the involved entities.

摘要

电子健康记录的传输和存储涉及敏感信息,需要强大的安全措施来确保只有授权人员才能访问。在当前的技术水平下,对于通过可持续的电子健康记录实现患者健康数据的安全访问,高效的访问控制方法的需求日益增长。将医疗数据锁定在医疗中心会形成信息隔离;因此,建立医疗数据交换平台是电子医疗中心发展的驱动力。医疗实体的访问权,如主体、控制者和请求者,由《通用数据保护条例》(GDPR)定义的访问控制政策进行定义和规范。在这项工作中,我们引入了一种基于区块链技术的基于策略的访问控制(PBAC)系统,其中智能合约管理安全和隐私的内在部分。因此,任何主体都可以随时知道当前谁有权访问他的数据。PBAC根据预定义的策略授予对电子健康记录的访问权限。我们提出的PBAC方法采用的策略允许主体、控制者和请求者授予访问权限、撤销访问权限以及检查特定医疗系统中的日志和操作。智能合约动态执行访问控制策略并管理访问权限,确保敏感数据仅对授权用户可用。描述所提出的访问控制系统并将其与其他系统进行比较表明,我们的方法更适用于各种医疗数据保护场景,在这些场景中,既需要同时共享敏感数据,又强烈需要保护相关实体的权利。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/b22aeeea43ca/peerj-cs-11-2647-g008.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/859dc81bf28f/peerj-cs-11-2647-g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/834932c6d3f4/peerj-cs-11-2647-g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/e40893de8159/peerj-cs-11-2647-g003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/73e3d6ae7c57/peerj-cs-11-2647-g004.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/bf842720c02c/peerj-cs-11-2647-g005.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/e6acf6dfdd1f/peerj-cs-11-2647-g006.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/8cb2203117ee/peerj-cs-11-2647-g007.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/b22aeeea43ca/peerj-cs-11-2647-g008.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/859dc81bf28f/peerj-cs-11-2647-g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/834932c6d3f4/peerj-cs-11-2647-g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/e40893de8159/peerj-cs-11-2647-g003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/73e3d6ae7c57/peerj-cs-11-2647-g004.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/bf842720c02c/peerj-cs-11-2647-g005.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/e6acf6dfdd1f/peerj-cs-11-2647-g006.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/8cb2203117ee/peerj-cs-11-2647-g007.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/2922/11784709/b22aeeea43ca/peerj-cs-11-2647-g008.jpg

相似文献

1
Blockchain enabled policy-based access control mechanism to restrict unauthorized access to electronic health records.基于区块链的策略访问控制机制,用于限制对电子健康记录的未经授权访问。
PeerJ Comput Sci. 2025 Jan 23;11:e2647. doi: 10.7717/peerj-cs.2647. eCollection 2025.
2
Privacy Preservation in Patient Information Exchange Systems Based on Blockchain: System Design Study.基于区块链的患者信息交换系统中的隐私保护:系统设计研究。
J Med Internet Res. 2022 Mar 22;24(3):e29108. doi: 10.2196/29108.
3
Opportunistic access control scheme for enhancing IoT-enabled healthcare security using blockchain and machine learning.基于区块链和机器学习的用于增强物联网医疗保健安全性的机会访问控制方案
Sci Rep. 2025 Mar 4;15(1):7589. doi: 10.1038/s41598-025-90908-1.
4
HealthLock: Blockchain-Based Privacy Preservation Using Homomorphic Encryption in Internet of Things Healthcare Applications.HealthLock:物联网医疗应用中基于同态加密的区块链隐私保护
Sensors (Basel). 2023 Jul 28;23(15):6762. doi: 10.3390/s23156762.
5
Blockchain-enabled EHR access auditing: Enhancing healthcare data security.基于区块链的电子健康记录访问审计:增强医疗数据安全性。
Heliyon. 2024 Aug 10;10(16):e34407. doi: 10.1016/j.heliyon.2024.e34407. eCollection 2024 Aug 30.
6
Blockchain-enabled data governance for privacy-preserved sharing of confidential data.支持区块链的数据治理,用于在保护隐私的前提下共享机密数据。
PeerJ Comput Sci. 2024 Dec 20;10:e2581. doi: 10.7717/peerj-cs.2581. eCollection 2024.
7
A blockchain-based framework for electronic medical records sharing with fine-grained access control.基于区块链的电子病历共享细粒度访问控制框架。
PLoS One. 2020 Oct 6;15(10):e0239946. doi: 10.1371/journal.pone.0239946. eCollection 2020.
8
Privacy-Preserved Electronic Medical Record Exchanging and Sharing: A Blockchain-Based Smart Healthcare System.隐私保护的电子病历交换和共享:基于区块链的智能医疗系统。
IEEE J Biomed Health Inform. 2022 May;26(5):1917-1927. doi: 10.1109/JBHI.2021.3123643. Epub 2022 May 5.
9
A robust algorithm for authenticated health data access via blockchain and cloud computing.一种通过区块链和云计算进行认证的健康数据访问的稳健算法。
PLoS One. 2024 Sep 23;19(9):e0307039. doi: 10.1371/journal.pone.0307039. eCollection 2024.
10
Blockchain-Powered Healthcare Systems: Enhancing Scalability and Security with Hybrid Deep Learning.区块链赋能的医疗保健系统:通过混合深度学习提高可扩展性和安全性。
Sensors (Basel). 2023 Sep 7;23(18):7740. doi: 10.3390/s23187740.

本文引用的文献

1
Permissioned blockchain network for proactive access control to electronic health records.许可区块链网络,实现对电子健康记录的主动访问控制。
BMC Med Inform Decis Mak. 2024 Oct 15;24(1):303. doi: 10.1186/s12911-024-02708-8.
2
Enhancing Data Protection in Dynamic Consent Management Systems: Formalizing Privacy and Security Definitions with Differential Privacy, Decentralization, and Zero-Knowledge Proofs.增强动态同意管理系统中的数据保护:使用差分隐私、去中心化和零知识证明来规范隐私和安全定义。
Sensors (Basel). 2023 Sep 1;23(17):7604. doi: 10.3390/s23177604.
3
A Consortium Blockchain-Based Secure and Trusted Electronic Portfolio Management Scheme.
基于联盟区块链的安全可信电子档案管理方案。
Sensors (Basel). 2022 Feb 8;22(3):1271. doi: 10.3390/s22031271.
4
A Smart Contract-Based Dynamic Consent Management System for Personal Data Usage under GDPR.基于 GDPR 下的个人数据使用的智能合约式动态同意管理系统。
Sensors (Basel). 2021 Nov 30;21(23):7994. doi: 10.3390/s21237994.
5
Granular Data Access Control with a Patient-Centric Policy Update for Healthcare.面向医疗保健的以患者为中心的策略更新的细粒度数据访问控制。
Sensors (Basel). 2021 May 20;21(10):3556. doi: 10.3390/s21103556.
6
Exploiting Smart Contracts for Capability-Based Access Control in the Internet of Things.利用智能合约实现物联网中的基于能力的访问控制。
Sensors (Basel). 2020 Mar 24;20(6):1793. doi: 10.3390/s20061793.