Title :
SPS: Secure personal health information sharing with patient-centric access control in cloud computing
Author :
Barua, Mrinmoy ; Rongxing Lu ; Xuemin Shen
Author_Institution :
Dept. of Electr. & Comput. Eng., Univ. of Waterloo, Waterloo, ON, Canada
Abstract :
In this paper, we propose a patient-centric personal health information (PHI) sharing and access control scheme, SPS. Proposed SPS encompasses identity based cryptography to ensure security and privacy of PHI by using short digital signature and patient´s pseudo-identity. SPS relieves the health service provider´s (HSP) additional burden for PHI storage, management, and maintenance by incorporating cloud storage services to electronic Health (eHealth) care system. SPS adopts attribute based encryption and assigns different attributes to PHI access requesters based on their roles and relation to the patient. To ensure authenticated PHI access with minimum computation, SPS introduces multi-parties proxy re-encryption protocol. Light weight partial and block PHI audits make the scheme efficient to ensure stored PHI integrity and availability. Extensive performance and security analyses demonstrate that SPS is able to achieve desired security requirements with acceptable computation and storage costs.
Keywords :
access control; cloud computing; cryptographic protocols; digital signatures; electronic health records; medical computing; security of data; HSP; PHI access requesters; PHI sharing; PHI storage; SPS; attribute based encryption; block PHI audits; cloud computing; cloud storage services; digital signature; eHealth care system; electronic health care system; health service provider; identity based cryptography; light weight partial PHI audits; multiparties proxy reencryption protocol; patient pseudoidentity; patient-centric access control; patient-centric personal health information sharing; secure personal health information sharing; security requirements; storage costs; Access control; Cloud computing; Computer architecture; Encryption; Privacy; Patientcentric access control; cloud; eHealth; efficient audit; privacy; security;
Conference_Titel :
Global Communications Conference (GLOBECOM), 2013 IEEE
Conference_Location :
Atlanta, GA
DOI :
10.1109/GLOCOM.2013.6831145