首页> 外文会议>International Conference on Communications, Computation, Networks and Technologies >A Novel 3-Level Access Control (3LAC) Framework for Data Access in a Healthcare Cloud Context
【24h】

A Novel 3-Level Access Control (3LAC) Framework for Data Access in a Healthcare Cloud Context

机译:用于医疗保健云上下文中的数据访问的新型3级访问控制(3LAC)框架

获取原文

摘要

While the use of Personal Health Records (PHRs) in a cloud computing environment brings benefits, it also raises concerns. One of the major concerns is how to prevent patients' data managed by a cloud provider (i.e., a third-party) from being revealed to unauthorised entities, including the cloud provider. One way to address this concern is to protect data by using an Attribute-Based Encryption (ABE) based solution, in which data is encrypted before it is uploaded to the cloud provider. As part of the solution, data is first encrypted by using a symmetric key, which is then protected by using a pair of keys: a public and a private key. The public key is used for encrypting the symmetric key, and the private key is used for decrypting the symmetric key. To access data, a user needs to acquire the private key. Existing work on controlling the access of PHRs in a cloud environment largely focuses on how to make the solutions more fine-grained or how to strike the balance between data access granularity and efficiency. However, there is little work on ensuring how to securely distribute a private key in an ABE based PHRs access control system. This paper addresses the issue by proposing a multi-level approach to private key distribution in a Ciphertext-Policy ABE (CP-ABE) based access control model. This multi-level approach is inspired by our observation that patients' data may not have the same level of sensitivity, and to optimise the trade-off between privacy protection and costs (i.e., computational and communication), the level of access control should be tailored based on the data sensitivity levels. We have implemented these ideas by designing and evaluating a Novel 3-Level Access Control Framework (3LAC) that combines the Shamir's Secret Sharing scheme with a CP-ABE based access control model, in which to access more sensitive data a user needs to acquire more shares, and for the acquisition of each share, there is an authentication process. The results of the evaluation have demonstrated that the 3LAC Framework balances the performance according to the data sensitivity levels as compared with a fixed-level approach.
机译:虽然在云计算环境中使用个人健康记录(PHRS),但它也提出了益处。其中一个主要问题是如何防止由云提供商(即第三方)管理的患者数据被揭示给未经授权的实体,包括云提供商。解决此问题的一种方法是通过使用基于属性的加密(ABE)的解决方案来保护数据,在该解决方案中,在将数据上载到云提供商之前被加密。作为解决方案的一部分,通过使用对称密钥首先加密数据,然后通过使用一对键和私钥来保护该数据。公钥用于加密对称密钥,私钥用于解密对称密钥。要访问数据,用户需要获取私钥。在云环境中控制PHRS访问的现有工作主要侧重于如何使解决方案更精细或如何在数据访问粒度和效率之间取得平衡。但是,确保如何在基于ABE的PHS访问控制系统中牢固地分发私钥的工作很少。本文通过提出基于密文 - 策略ABE(CP-AM-ABE)的访问控制模型中的私钥分布的多级方法来解决该问题。这种多级方法受到我们观察的启发,即患者的数据可能没有相同程度的敏感性,并优化隐私保护和成本之间的权衡(即计算和通信),所访问控制的水平应该是根据数据敏感级别量身定制。我们通过设计和评估了与基于CP-ABE的访问控制模型组合的新颖的3级访问控制框架(3LAC)来实现这些想法,该秘密共享方案将Shamir的秘密共享方案与基于CP-ABE的访问控制模型相结合,其中用于访问更敏感的数据,用户需要获得更多敏感数据共享,并用于获取每个共享,存在身份验证过程。评估结果表明,与固定级别方法相比,3LAC框架根据数据灵敏度水平平衡性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号