Secret Sharing for Health Data in Multi-provider Clouds

Tatiana Ermakova, Benjamin Fabian
{"title":"Secret Sharing for Health Data in Multi-provider Clouds","authors":"Tatiana Ermakova, Benjamin Fabian","doi":"10.1109/CBI.2013.22","DOIUrl":null,"url":null,"abstract":"The accelerated adoption of cloud computing among enterprises is due to the multiple benefits the technology provides, one of them the simplification of inter-organizational information sharing, which is of utmost importance in healthcare. Nevertheless, moving sensitive health records to the cloud still implies severe security and privacy risks. With this background, we present a novel secure architecture for sharing electronic health records in a cloud environment. We first conducted a systematic literature review and interviews with different experts from the German healthcare industry that allowed us to derive real-world processes and corresponding security and privacy requirements. Based on these results, we designed our multi-provider cloud architecture that satisfies many of the requirements by providing increased availability, confidentiality and integrity of the medical records stored in the cloud. This architecture features secret sharing as an important measure to distribute health records as fragments to different cloud services, which can provide higher redundancy and additional security and privacy protection in the case of key compromise, broken encryption algorithms or their insecure implementation. Finally, we evaluate and select a secret-sharing algorithm for our multi-cloud architecture. We implemented both Shamir's secret-sharing scheme and Rabin's information dispersal algorithm and performed several experiments measuring the execution time. Our results indicate that an adoption of Rabin's algorithm would create a low overhead, giving strong indicators to the feasibility of our approach.","PeriodicalId":443410,"journal":{"name":"2013 IEEE 15th Conference on Business Informatics","volume":"151 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-07-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"67","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 IEEE 15th Conference on Business Informatics","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CBI.2013.22","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 67

Abstract

The accelerated adoption of cloud computing among enterprises is due to the multiple benefits the technology provides, one of them the simplification of inter-organizational information sharing, which is of utmost importance in healthcare. Nevertheless, moving sensitive health records to the cloud still implies severe security and privacy risks. With this background, we present a novel secure architecture for sharing electronic health records in a cloud environment. We first conducted a systematic literature review and interviews with different experts from the German healthcare industry that allowed us to derive real-world processes and corresponding security and privacy requirements. Based on these results, we designed our multi-provider cloud architecture that satisfies many of the requirements by providing increased availability, confidentiality and integrity of the medical records stored in the cloud. This architecture features secret sharing as an important measure to distribute health records as fragments to different cloud services, which can provide higher redundancy and additional security and privacy protection in the case of key compromise, broken encryption algorithms or their insecure implementation. Finally, we evaluate and select a secret-sharing algorithm for our multi-cloud architecture. We implemented both Shamir's secret-sharing scheme and Rabin's information dispersal algorithm and performed several experiments measuring the execution time. Our results indicate that an adoption of Rabin's algorithm would create a low overhead, giving strong indicators to the feasibility of our approach.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
多提供商云中健康数据的秘密共享
云计算在企业中的加速采用是由于该技术提供了多种好处,其中之一是简化了组织间的信息共享,这在医疗保健领域至关重要。然而,将敏感的健康记录转移到云端仍然意味着严重的安全和隐私风险。在此背景下,我们提出了一种在云环境中共享电子健康记录的新型安全体系结构。我们首先进行了系统的文献回顾,并采访了来自德国医疗保健行业的不同专家,这使我们能够得出真实世界的流程和相应的安全和隐私要求。基于这些结果,我们设计了多提供商云架构,该架构通过提高存储在云中的医疗记录的可用性、机密性和完整性来满足许多需求。该架构将秘密共享作为一种重要措施,将健康记录作为片段分发到不同的云服务,这可以在密钥泄露、加密算法被破坏或其实现不安全的情况下提供更高的冗余和额外的安全性和隐私保护。最后,我们评估并选择了一种适合我们多云架构的秘密共享算法。我们实现了Shamir的秘密共享方案和Rabin的信息分散算法,并进行了几个测试执行时间的实验。我们的结果表明,采用Rabin的算法会产生较低的开销,这为我们的方法的可行性提供了强有力的指标。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
An Enterprise Ontology-Based Database for Continuous Monitoring Application Social Computing Literature: A Systematic Review (Re-)Justifying BPM: A Quest for the Interaction Turn Reviewing Subject-Oriented BPM Context-Sensitive Traceability Controlling A Practice-Driven Service Framework for Value Creation
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1