论文标题
安全的多方授权授权,用于访问和共享电子健康记录
Secure Multi-Party Delegated Authorisation For Access and Sharing of Electronic Health Records
论文作者
论文摘要
及时在提供商之间及时共享电子健康记录(EHR),这对于促进医学研究并促使患者的护理至关重要。通过共享,至关重要的是,患者可以控制谁可以访问数据以及何时何时访问数据,并保证其数据的安全性和隐私。在当前的文献中,提出了各种系统模型,加密技术和访问控制机制,该机制需要在共享之前同意患者的同意。但是,他们主要专注于患者,可以根据要求授权EHR访问。这是不切实际的,因为患者可能并不总是处于良好状态,以提供此授权,例如,无意识并需要立即医疗护理。为了解决这一差距,本文提出了一种有效且安全的协议,以预先将授权授权到多方授权,以便在患者无法使用时访问EHR。该解决方案采用了一种新颖的方法来将自我主张的身份概念和框架与安全的多方计算相结合,以实现安全的身份和授权验证。理论分析表明,它提高了协议和验证过程的效率,以确保患者数据的安全性和隐私性。
Timely sharing of electronic health records (EHR) across providers is essential and significance in facilitating medical researches and prompt patients' care. With sharing, it is crucial that patients can control who can access their data and when, and guarantee the security and privacy of their data. In current literature, various system models, cryptographic techniques and access control mechanisms are proposed which requires patient's consent before sharing. However, they mostly focus on patient is available to authorize the access of the EHR upon requested. This is impractical given that the patient may not always be in a good state to provide this authorization, eg, being unconscious and requires immediate medical attention. To address this gap, this paper proposes an efficient and secure protocol for the pre-delegation of authorization to multi-party for the access of the EHR when patient is unavailable to do so. The solution adopts a novel approach to combine self-sovereign identity concepts and framework with secure multi-party computation to enable secure identity and authorization verification. Theoretical analysis showed that it increased the efficiency of the protocol and verification processes to ensure the security and privacy of patient's data.