Delegated Authorization Framework for EHR Services using Attribute Based Encryption

dc.contributor.authorJoshi, Maithilee
dc.contributor.authorJoshi, Karuna Pande
dc.contributor.authorFinin, Tim
dc.date.accessioned2019-09-26T14:23:11Z
dc.date.available2019-09-26T14:23:11Z
dc.date.issued2019-05-20
dc.description.abstractMedical organizations find it challenging to adopt cloud-based Electronic Health Records (EHR) services due to the risk of data breaches and the resulting compromise of patient data. Existing authorization models follow a patient-centric approach for EHR management, where the responsibility of authorizing data access is handled at the patients end. This creates a significant overhead for the patient who must authorize every access of their health record. This is not practical given that multiple personnel are typically involved in providing care and that the patient may not always be in a state to provide this authorization. Hence there is a need to develop a proper authorization delegation mechanism for safe, secure and easy to use cloud-based EHR Service management. We present a novel, centralized, attribute-based authorization mechanism that uses Attribute Based Encryption (ABE) and allows for delegated secure access of patient records. This mechanism transfers the service management overhead from the patient to the medical organization and allows easy delegation of cloud-based EHRs access authority to medical providers.en
dc.description.sponsorshipThis research was supported by the Office of Naval Research under grants N00014-15-1-2228 and N00014-16-WX01489. We thank Dr. Seung Geol Choi (USNA), Dr. Eliot Siegel (University of Maryland Medical Center) and members of the Ebiquity Research Group for their vital input. This work was conducted using the Protege resource, which is supported by grant GM10331601 from the National Institute of General Medical Sciences of the United States National Institutes of Health.en
dc.description.urihttps://ieeexplore.ieee.org/document/8718336en
dc.format.extent12 pagesen
dc.genrepreprints
dc.genrejournal articlesen
dc.identifierdoi:10.13016/m2b5cs-yhpv
dc.identifier.citationM. Joshi, K. P. Joshi and T. Finin, "Delegated Authorization Framework for EHR Services Using Attribute-Based Encryption," in IEEE Transactions on Services Computing, vol. 14, no. 6, pp. 1612-1623, 1 Nov.-Dec. 2021, doi: 10.1109/TSC.2019.2917438.en
dc.identifier.urihttps://doi.org/10.1109/TSC.2019.2917438
dc.identifier.urihttp://hdl.handle.net/11603/14602
dc.language.isoenen
dc.publisherIEEEen
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Information Systems Department Collection
dc.relation.ispartofUMBC Faculty Collection
dc.relation.ispartofUMBC Computer Science and Electrical Engineering Department
dc.rights© 2019 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.
dc.subjectUMBC Ebiquity Research Group
dc.subjectAttribute Based Encryption (ABE)en
dc.subjectAttribute Based Access Control (ABAC)en
dc.subjectElectronic Health Record (EHR)en
dc.subjectCloud Storageen
dc.subjectSemantic Weben
dc.subjectAccess Brokeren
dc.subjectKnowledge Graph (Ontology)en
dc.subjectCloud Computingen
dc.titleDelegated Authorization Framework for EHR Services using Attribute Based Encryptionen
dc.typeTexten

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
08718336.pdf
Size:
1.79 MB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
2.56 KB
Format:
Item-specific license agreed upon to submission
Description: