Journal on Communications ›› 2015, Vol. 36 ›› Issue (12): 200-211.doi: 10.11959/j.issn.1000-436x.2015329

• data security • Previous Articles     Next Articles

Access control scheme for medical data based on PBAC and IBE

Yi-ting ZHANG1,2,Yu-chuan FU1,Ming YANG1,Jun-zhou LUO1   

  1. 1 School of Computer Science and Engineering,Southeast University,Nanjing 210096,China
    2 School of Computer Science & Technology,Nanjing University of Posts and Telecommunications,Nanjing 210023,China
  • Online:2015-12-25 Published:2017-07-17
  • Supported by:
    The National Natural Science Foundation of China;The National Natural Science Foundation of China;The National Key Technology R&D Program of China

Abstract:

Due to the large amount of personal privacy information contained,the medical big data formed in the health care industry was faced with potential threats of both external attacks and internal data leakages.However,traditional access control technology didn’t take into account the important role of user access purpose in the access control schemes that emphasized data privacy,and existing symmetric and asymmetric encryption technologies both face problems such as the complexity of key and certificate management.To address these problems,a novel access control scheme based on PBAC model and IBE encryption technology was proposed,which could provide flexible access control of encrypted medical data.By introducing the concept of conditioned purpose,the PBAC model was extended to achieve full coverage of purpose trees.Furthermore,the scheme used patient ID,conditioned bit and intended purpose as the IBE public key,with which patients’ data were encrypted.Only users who pass the authentication and whose access purposes conform to the intended purposes can obtain the corresponding private keys and the encrypted data,thereby achieving access to patients’ information.Experimental results prove that the scheme can achieve the goals of fine-grained access control and privacy protection with high performance.

No Suggested Reading articles found!