Privacy-aware relationship semantics–based XACML access control model for electronic health records in hybrid cloud

Abstract

State-of-the-art progress in cloud computing encouraged the healthcare organizations to outsource the management of electronic health records to cloud service providers using hybrid cloud. A hybrid cloud is an infrastructure consisting of a private cloud (managed by the organization) and a public cloud (managed by the cloud service provider). The use of hybrid cloud enables electronic health records to be exchanged between medical institutions and supports multipurpose usage of electronic health records. Along with the benefits, cloud-based electronic health records also raise the problems of security and privacy specifically in terms of electronic health records access. A comprehensive and exploratory analysis of privacy-preserving solutions revealed that most current systems do not support fine-grained access control or consider additional factors such as privacy preservation and relationship semantics. In this article, we investigated the need of a privacy-aware fine-grained access control model for the hybrid cloud. We propose a privacy-aware relationship semantics–based XACML access control model that performs hybrid relationship and attribute-based access control using extensible access control markup language. The proposed approach supports fine-grained relation-based access control with state-of-the-art privacy mechanism named Anatomy for enhanced multipurpose electronic health records usage. The proposed (privacy-aware relationship semantics–based XACML access control model) model provides and maintains an efficient privacy versus utility trade-off. We formally verify the proposed model (privacy-aware relationship semantics–based XACML access control model) and implemented to check its effectiveness in terms of privacy-aware electronic health records access and multipurpose utilization. Experimental results show that in the proposed (privacy-aware relationship semantics–based XACML access control model) model, access policies based on relationships and electronic health records anonymization can perform well in terms of access policy response time and space storage.

Publication DOI: https://doi.org/10.1177/1550147719846050
Additional Information: © The Author(s) 2019. This article is distributed under the terms of the Creative Commons Attribution 4.0 License (http://www.creativecommons.org/licenses/by/4.0/) which permits any use, reproduction and distribution of the work without further permission provided the original work is attributed as specified on the SAGE and Open Access pages (https://us.sagepub.com/en-us/nam/open-access-at-sage).
Uncontrolled Keywords: access control,cryptography,Electronic health records,hybrid cloud,privacy,relationship,Engineering(all),Computer Networks and Communications
Publication ISSN: 1550-1477
Last Modified: 20 Mar 2024 08:22
Date Deposited: 02 Dec 2022 13:49
Full Text Link:
Related URLs: https://journal ... 550147719846050 (Publisher URL)
PURE Output Type: Article
Published Date: 2019-06
Published Online Date: 2019-06-21
Accepted Date: 2019-03-26
Authors: Kanwal, Tehsin
Jabbar, Ather Abdul
Anjum, Adeel
Malik, Saif U.R.
Khan, Abid
Ahmad, Naveed
Manzoor, Umar (ORCID Profile 0000-0001-7602-1914)
Shahzad, Muhammad Naeem
Balubaid, Muhammad A.

Download

[img]

Version: Published Version

License: Creative Commons Attribution

| Preview

Export / Share Citation


Statistics

Additional statistics for this record