• DocumentCode
    549472
  • Title

    RBTBAC: Secure access and management of EHR data

  • Author

    Rui Zhang ; Jiqiang Liu ; Zhen Han ; Ling Liu

  • Author_Institution
    Sch. of Comput. & Inf. Technol., Beijing Jiaotong Univ., Beijing, China
  • fYear
    2011
  • fDate
    27-29 June 2011
  • Firstpage
    494
  • Lastpage
    499
  • Abstract
    Security and privacy are widely recognized as important and personalized requirements for access and management of Electric Health Record (EHR) data. Different patients may have different privacy and security policies for their EHR data in different context. In this paper we argue that EHR data needs to be managed with customizable access control in both spatial and temporal dimension. We present a role-based and time-bound access control model (RBTBAC) that provides more flexibility of both roles (spatial capability) and temporal capability to control the access of sensitive data from time dimension. Through algorithmic combination of role-based access control and time-bound key management, RBTBAC model has three salient features. First, we have developed a privacy-aware and dynamic key structure for role-based privacy aware access and management of EHR data, focusing on the consistency of access authorization (including data and time interval) with the activated role of user. In addition to role-based access, a path-invisible EHR structure is build for preserving privacy of patients. Second, we have employed a time tree method for generating time granule values, offering fine granularity of time-bound access authorization and control. Our experimental results show that tree-like time structure can improve the performance of the key management scheme significantly and RBTBAC model is more suitable than existing solutions for EHR data management since it offers high-efficiency and better security and privacy for patients.
  • Keywords
    authorisation; cryptography; data privacy; medical information systems; trees (mathematics); EHR data management; RBTBAC; dynamic key structure; electric health record; path-invisible EHR structure; privacy policy; privacy-aware structure; role-based access control; secure access; security policy; spatial dimension; temporal dimension; time tree method; time-bound access authorization; time-bound access control; time-bound key management; tree-like time structure; Complexity theory; Cryptography; Data models; Dentistry; Hardware; Privacy; Software; EHR system; privacy preserving; role-based access control; time tree; time-bound key management;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Society (i-Society), 2011 International Conference on
  • Conference_Location
    London
  • Print_ISBN
    978-1-61284-148-9
  • Type

    conf

  • Filename
    5978546