Delegated Authorization Framework for EHR Services using Attribute Based Encryption

dc.contributor.authorJoshi, Maithilee
dc.contributor.authorJoshi, Karuna Pande
dc.contributor.authorFinin, Tim
dc.date.accessioned2019-09-26T14:23:11Z
dc.date.available2019-09-26T14:23:11Z
dc.date.issued2019-05-20
dc.description.abstractMedical organizations find it challenging to adopt cloud-based Electronic Health Records (EHR) services due to the risk of data breaches and the resulting compromise of patient data. Existing authorization models follow a patient-centric approach for EHR management, where the responsibility of authorizing data access is handled at the patients end. This creates a significant overhead for the patient who must authorize every access of their health record. This is not practical given that multiple personnel are typically involved in providing care and that the patient may not always be in a state to provide this authorization. Hence there is a need to develop a proper authorization delegation mechanism for safe, secure and easy to use cloud-based EHR Service management. We present a novel, centralized, attribute-based authorization mechanism that uses Attribute Based Encryption (ABE) and allows for delegated secure access of patient records. This mechanism transfers the service management overhead from the patient to the medical organization and allows easy delegation of cloud-based EHRs access authority to medical providers.en_US
dc.description.sponsorshipThis research was supported by the Office of Naval Research under grants N00014-15-1-2228 and N00014-16-WX01489. We thank Dr. Seung Geol Choi (USNA), Dr. Eliot Siegel (University of Maryland Medical Center) and members of the Ebiquity Research Group for their vital input. This work was conducted using the Protege resource, which is supported by grant GM10331601 from the National Institute of General Medical Sciences of the United States National Institutes of Health.en_US
dc.description.urihttps://ieeexplore.ieee.org/document/8718336en_US
dc.format.extent12 pagesen_US
dc.genrejournal articlesen_US
dc.genrepreprints
dc.identifierdoi:10.13016/m2b5cs-yhpv
dc.identifier.citationM. Joshi, K. P. Joshi and T. Finin, "Delegated Authorization Framework for EHR Services Using Attribute-Based Encryption," in IEEE Transactions on Services Computing, vol. 14, no. 6, pp. 1612-1623, 1 Nov.-Dec. 2021, doi: 10.1109/TSC.2019.2917438.en_US
dc.identifier.urihttps://doi.org/10.1109/TSC.2019.2917438
dc.identifier.urihttp://hdl.handle.net/11603/14602
dc.language.isoen_USen_US
dc.publisherIEEEen_US
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Information Systems Department Collection
dc.relation.ispartofUMBC Faculty Collection
dc.relation.ispartofUMBC Computer Science and Electrical Engineering Department
dc.rights© 2019 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.
dc.subjectAttribute Based Encryption (ABE)en_US
dc.subjectAttribute Based Access Control (ABAC)en_US
dc.subjectElectronic Health Record (EHR)en_US
dc.subjectCloud Storageen_US
dc.subjectSemantic Weben_US
dc.subjectAccess Brokeren_US
dc.subjectKnowledge Graph (Ontology)en_US
dc.subjectCloud Computingen_US
dc.subjectUMBC Ebiquity Research Group
dc.titleDelegated Authorization Framework for EHR Services using Attribute Based Encryptionen_US
dc.typeTexten_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
08718336.pdf
Size:
1.79 MB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
2.56 KB
Format:
Item-specific license agreed upon to submission
Description: