【24h】

Crypt-EHRServer: Protecting Confidentiality with Attribute-Based Encryption and Encrypted Query Processing

机译:Crypt-EHRServer:通过基于属性的加密和加密的查询处理保护机密性

获取原文
获取原文并翻译 | 示例

摘要

OpenEHR is an open standard specification for developing flexible electronic health record (EHR) management system. It defines the standard service models and APIs, and offers a whole lifetime data storage method to the patient's record. As an important OpenEHR system component, EHRServer plays the role of back-end services repository for data storage and query. It complies with the openEHR specifications and adopts MySQL database. However, current EHRServer has many limitations. For example, its official requirement stresses that one organization cannot access the EHR owned by other organizations. The original EHRServer database is in plaintext format. It can lead to the risk of electronic record leakage. Encryption is one common protection method, but the current EHRServer APIs do not support encrypted data query. That restricts building EHRServer on the cloud. What's more, the inconvenience of information sharing among different organizations may also hinder the extension of OpenEHR coverage to more domains and countries. To solve the above open problems, in this paper, we explore two approaches which guarantee the security and flexibility of sharing EHR on the cloud and thus propose a new architecture called Crypt-EHRServer. Firstly, we use attribute-based encryption to realize flexible EHR access authority for different authorized organizations. Secondly, we learn from an efficient ciphertext query model, CryptDB, and adopt their onion encryption approach to support standard SQL queries on the encrypted EHR. The result of our work could provide a flexible, scalable and secure EHR system. Crypt-EHRServer will benefit OpenEHR's widespread adoption in the world, and will also arouse people's awareness about incorporating security criteria into the design of electronic health records management systems.
机译:OpenEHR是用于开发灵活的电子健康记录(EHR)管理系统的开放标准规范。它定义了标准的服务模型和API,并为患者的记录提供了整个生命周期的数据存储方法。作为重要的OpenEHR系统组件,EHRServer充当用于数据存储和查询的后端服务存储库。它符合openEHR规范,并采用MySQL数据库。但是,当前的EHRServer具有许多限制。例如,其官方要求强调一个组织不能访问其他组织拥有的EHR。原始的EHRServer数据库为纯文本格式。这可能会导致电子记录泄漏的风险。加密是一种常见的保护方法,但是当前的EHRServer API不支持加密的数据查询。这限制了在云上构建EHRServer。此外,不同组织之间信息共享的不便也可能会阻碍OpenEHR的覆盖范围扩展到更多领域和国家。为了解决上述开放性问题,本文探索了两种方法来保证在云上共享EHR的安全性和灵活性,从而提出了一种称为Crypt-EHRServer的新体系结构。首先,我们使用基于属性的加密为不同的授权组织实现灵活的EHR访问权限。其次,我们从高效的密文查询模型CryptDB中学习,并采用其洋葱加密方法来支持加密的EHR上的标准SQL查询。我们工作的结果可以提供一个灵活,可扩展和安全的电子病历系统。 Crypt-EHRServer将有利于OpenEHR在世界范围内的广泛采用,还将唤起人们关于将安全性标准纳入电子病历管理系统设计的意识。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号