首页> 外文会议>International Symposium on Medical Information and Communication Technology >Secure access delegation of encrypted medical information
【24h】

Secure access delegation of encrypted medical information

机译:安全访问授权的加密医疗信息

获取原文

摘要

The design of modern medical data information systems is driven by the need to collect and present data to authorized users. For collected medical data to be effective and improve patient treatment it must be transported from a device, aggregated, and analyzed to produce results that can be shared with care providers. Medical data may be analyzed and used years after collection at different locations because data sources and care providers often operate on different time scales and are geographically distributed. The need for distributed and long-term medical data storage thus requires an effective security model to delegate data access. Current data access delegation models do not provide end-to-end protection. An effective delegation model must keep data encrypted at all times and avoid the need to share decryption keys to avoid security vulnerabilities. We present a secure information architecture and prototype to implement such a model with end-to-end data encryption while restricting data access to designated recipients. Our architecture integrates recent Proxy Re-Encryption (PRE) advances into a client-server based security model that can be applied to open Internet communications. We discuss design tradeoffs and show experimental results. Our architecture lowers health care data management costs by enabling the secure outsourcing of data hosting to low-cost cloud computing environments. The architecture will also reduce the vulnerability of health care data systems to security challenges such as attacks compromising confidentiality and malicious insiders.
机译:现代医学数据信息系统的设计是由收集数据并将其提供给授权用户的需求所驱动的。为了使收集的医疗数据有效并改善患者治疗,必须将其从设备中传输,汇总和分析,以产生可与护理提供者共享的结果。由于数据源和护理提供者通常在不同的时间范围内进行操作并且在地理上分布,因此可能会在收集后多年在不同位置分析和使用医学数据。因此,对分布式和长期医学数据存储的需求需要有效的安全模型来委派数据访问。当前的数据访问委托模型不提供端到端保护。有效的委派模型必须始终保持数据加密,并且避免共享解密密钥以避免安全漏洞。我们提出了一种安全的信息体系结构和原型,以通过端到端数据加密来实现这种模型,同时将数据访问限制在指定的接收方。我们的体系结构将最新的代理重新加密(PRE)进展集成到了基于客户端-服务器的安全模型中,该模型可用于开放Internet通信。我们讨论设计权衡并显示实验结果。我们的架构通过将数据托管安全外包到低成本云计算环境中来降低医疗保健数据管理成本。该体系结构还将减少医疗保健数据系统面临的安全挑战(例如,破坏机密性和恶意内部人员的攻击)的脆弱性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号