Title :
XDS-I Outsourcing Proxy: Ensuring Confidentiality While Preserving Interoperability
Author :
Ribeiro, LuiÌs S. ; Viana-Ferreira, Carlos ; Oliveira, Jose Luis ; Costa, C.
Author_Institution :
DETI/IEETA, Univ. of Aveiro, Aveiro, Portugal
Abstract :
The interoperability of services and the sharing of health data have been a continuous goal for health professionals, patients, institutions, and policy makers. However, several issues have been hindering this goal, such as incompatible implementations of standards (e.g., HL7, DICOM), multiple ontologies, and security constraints. Cross-enterprise document sharing (XDS) workflows were proposed by Integrating the Healthcare Enterprise (IHE) to address current limitations in exchanging clinical data among organizations. To ensure data protection, XDS actors must be placed in trustworthy domains, which are normally inside such institutions. However, due to rapidly growing IT requirements, the outsourcing of resources in the Cloud is becoming very appealing. This paper presents a software proxy that enables the outsourcing of XDS architectural parts while preserving the interoperability, confidentiality, and searchability of clinical information. A key component in our architecture is a new searchable encryption (SE) scheme-Posterior Playfair Searchable Encryption (PPSE)-which, besides keeping the same confidentiality levels of the stored data, hides the search patterns to the adversary, bringing improvements when compared to the remaining practical state-of-the-art SE schemes.
Keywords :
biomedical imaging; cloud computing; cryptography; data protection; electronic health records; health care; open systems; resource allocation; trusted computing; DICOM; HL7; IHE; PPSE; SE schemes; XDS architectural; XDS-I outsourcing proxy; clinical data; cloud computing; cross-enterprise document sharing; health data; integrating healthcare enterprise; interoperability; multiple ontologies; posterior playfair searchable encryption; searchable encryption scheme; security constraints; software proxy; DICOM; Encryption; Medical services; Standards; Cloud computing; Integrating the Healthcare Enterprise (IHE); cross-enterprise document sharing (XDS) for imaging (XDS-I); medical imaging; searchable encryption (SE);
Journal_Title :
Biomedical and Health Informatics, IEEE Journal of
DOI :
10.1109/JBHI.2013.2292776