首页> 外文期刊>Computers & Security >A novel access control protocol using proxy signatures for cloud-based health information exchange
【24h】

A novel access control protocol using proxy signatures for cloud-based health information exchange

机译:一种使用代理签名的新型访问控制协议,用于基于云的健康信息交换

获取原文
获取原文并翻译 | 示例

摘要

Health Information Exchange (HIE) allows various providers to electronically share patient health information, enhancing healthcare delivery through coordinated patient care. A primary concern in HIEs is the need for explicit authorization of information exchange in an auditable manner. However, we find that existing approaches for authorization in health information systems exhibit several drawbacks in meeting the needs of HIE, with non-cryptographic approaches lacking a secure and reliable mechanism for access policy enforcement, while cryptographic approaches being too expensive, complex and limited in specifying policies. This paper aims to overcome these drawbacks by presenting a simple and efficient patient-centric authorization protocol for information sharing in cloud-based HIE systems. The proposed protocol is built using a novel trapdoor hash-based proxy signature scheme, and ensures that the authorization is authentic with respect to both providers and patients, and complies with the established access control policies. Features of the proposed protocol include auditability, non-interactive and on-demand operation, and specification and secure/ reliable enforcement of flexible access control policies. A detailed security and performance analysis shows that the proposed protocol is provably secure against forgery under the discrete log assumption, and achieves the best overall performance compared to other well-known schemes in the literature.
机译:健康信息交换(HIE)允许各种提供商以电子方式共享患者健康信息,从而通过协调的患者护理来增强医疗保健的提供。 HIE中的主要问题是需要以可审核的方式明确授权信息交换。但是,我们发现,健康信息系统中的现有授权方法在满足HIE需求方面表现出若干缺点,非加密方法缺乏用于访问策略实施的安全可靠的机制,而加密方法过于昂贵,复杂且受限制。指定政策。本文旨在通过为基于云的HIE系统中的信息共享提供一种简单有效的以患者为中心的授权协议来克服这些缺点。所提出的协议是使用新颖的基于陷门哈希的代理签名方案构建的,可确保授权对于提供者和患者都是真实的,并符合已建立的访问控制策略。拟议协议的功能包括可审核性,非交互式和按需操作,以及灵活的访问控制策略的规范和安全/可靠的实施。详细的安全性和性能分析表明,在离散对数假设下,所提议的协议可安全地防止伪造,并且与文献中的其他众所周知的方案相比,可获得最佳的总体性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号