>
Fa   |   Ar   |   En
   Attribute-Based Access Control For Cloud-Based Electronic Health Record (Ehr) Systems  
   
نویسنده Zarezadeh Maryam ,Ashouri Talouki Maede ,Siavashi Mohammad
منبع The Isc International Journal Of Information Security - 2020 - دوره : 12 - شماره : 2 - صفحه:129 -140
چکیده    The electronic health record (ehr) system facilitates integrating patients’ medical information and improves service productivity. however, user access to patient data in a privacy-preserving manner is still a challenging problem. many studies concerned with security and privacy in ehr systems. rezaeibagha and mu [1] have proposed a hybrid architecture for privacy-preserving accessing patient records in a cloud system. in their scheme, encrypted ehrs are stored in multiple clouds to provide scalability and privacy. in addition, they considered a role-based access control (rbac) such that for any user, an ehr access policy must be determined. they also encrypt the ehrs by the public keys of all users. so, for a large amount of ehrs, this scheme is not efficient. furthermore, using rbac for access policy makes the policy changing difficult. in their scheme, users cannot search on encrypted ehrs based on diseases, and some physicians must participate in the data retrieval by a requester physician. in this paper, we address these problems by considering ciphertext-policy attribute-based encryption (cp-abe), which is conceptually closer to the traditional access control methods such as rbac. our secure scheme can retrieve encrypted ehr based on a specific disease. furthermore, the proposed scheme guarantees the user access control and the anonymity of the user or data owner during data retrieval. moreover, our scheme is resistant against collusion between unauthorized retrievers to access the data. the analysis shows that our scheme is secure and efficient for cloud-based ehrs.
کلیدواژه Access Control ,Electronic Health Record ,Attribute-Based Encryption ,Ehr ,Cloud Storage
آدرس University Of Isfahan, Department Of Information Technology Engineering, Iran, University Of Isfahan, Department Of Information Technology Engineering, Iran, Shiraz University, Department Of Computer Science And Engineering, Iran
پست الکترونیکی m.siavashi@cse.shirazu.ac.ir
 
     
   
Authors
  
 
 

Copyright 2023
Islamic World Science Citation Center
All Rights Reserved