Yaqub Nadeem, Zhang Jianbiao, Khalid Muhammad Irfan, Wang Weiru, Helfert Markus, Ahmed Mansoor, Kim Jungsuk
Department of Computer Science and Technology, Beijing University of Technology, Beijing, China.
Department of Information Technology, University of Sialkot, Sialkot, Punjab, Pakistan.
PeerJ Comput Sci. 2025 Jan 23;11:e2647. doi: 10.7717/peerj-cs.2647. eCollection 2025.
Electronic health record transmission and storage involve sensitive information, requiring robust security measures to ensure access is limited to authorized personnel. In the existing state of the art, there is a growing need for efficient access control approaches for the secure accessibility of patient health data by sustainable electronic health records. Locking medical data in a healthcare center forms information isolation; thus, setting up healthcare data exchange platforms is a driving force behind electronic healthcare centers. The healthcare entities access rights like subject, controller, and requester are defined and regulated by access control policies as defined by the General Data Protection Regulation (GDPR). In this work, we have introduced a blend of policy-based access control (PBAC) system backed by blockchain technology, where smart contracts govern the intrinsic part of security and privacy. As a result, any Subject can know at any time who currently has the right to access his data. The PBAC grants access to electronic health records based on predefined policies. Our proposed PBAC approach employs policies in which the subject, controller, and requester can grant access, revoke access, and check logs and actions made in a particular healthcare system. Smart contracts dynamically enforce access control policies and manage access permissions, ensuring that sensitive data is available only to authorized users. Delineating the proposed access control system and comparing it to other systems demonstrates that our approach is more adaptable to various healthcare data protection scenarios where there is a need to share sensitive data simultaneously and a robust need to safeguard the rights of the involved entities.
电子健康记录的传输和存储涉及敏感信息,需要强大的安全措施来确保只有授权人员才能访问。在当前的技术水平下,对于通过可持续的电子健康记录实现患者健康数据的安全访问,高效的访问控制方法的需求日益增长。将医疗数据锁定在医疗中心会形成信息隔离;因此,建立医疗数据交换平台是电子医疗中心发展的驱动力。医疗实体的访问权,如主体、控制者和请求者,由《通用数据保护条例》(GDPR)定义的访问控制政策进行定义和规范。在这项工作中,我们引入了一种基于区块链技术的基于策略的访问控制(PBAC)系统,其中智能合约管理安全和隐私的内在部分。因此,任何主体都可以随时知道当前谁有权访问他的数据。PBAC根据预定义的策略授予对电子健康记录的访问权限。我们提出的PBAC方法采用的策略允许主体、控制者和请求者授予访问权限、撤销访问权限以及检查特定医疗系统中的日志和操作。智能合约动态执行访问控制策略并管理访问权限,确保敏感数据仅对授权用户可用。描述所提出的访问控制系统并将其与其他系统进行比较表明,我们的方法更适用于各种医疗数据保护场景,在这些场景中,既需要同时共享敏感数据,又强烈需要保护相关实体的权利。