International Conference on Cloud Computing

Attribute Based Encryption for Secure Access to Cloud Based EHR Systems

, , and

Medical organizations find it challenging to adopt cloud-based electronic medical records services, due to the risk of data breaches and the resulting compromise of patient data. Existing authorization models follow a patient centric approach for EHR management where the responsibility of authorizing data access is handled at the patients’ end. This however creates a significant overhead for the patient who has to authorize every access of their health record. This is not practical given the multiple personnel involved in providing care and that at times the patient may not be in a state to provide this authorization. Hence there is a need of developing a proper authorization delegation mechanism for safe, secure and easy cloud-based EHR management. We have developed a novel, centralized, attribute based authorization mechanism that uses Attribute Based Encryption (ABE) and allows for delegated secure access of patient records. This mechanism transfers the service management overhead from the patient to the medical organization and allows easy delegation of cloud-based EHR’s access authority to the medical providers. In this paper, we describe this novel ABE approach as well as the prototype system that we have created to illustrate it.


  • 274779 bytes

access broker, attribute based access control (abac), attribute based encryption (abe), cloud computing, cloud computing, cloud storage, electronic health record (ehr), healthcare, knowledge graph, ontology, privacy, security, semantic web

InProceedings

IEEE

IEEE

http://doi.org/10.1109/CLOUD.2018.00139

The EHR Manager Application is an open-source web application developed in Python to manage the field-level, attribute based encryption and access control of patient electronic healthcare records.

Downloads: 1989 downloads

UMBC ebiquity