Marie Tcholakian, Karolina Gorna, Maryline Laurent, Hella Kaffel Ben Ayed, Montassar Naghmouchi
{"title":"使用区块链以自主身份同意和基于内容访问医疗记录","authors":"Marie Tcholakian, Karolina Gorna, Maryline Laurent, Hella Kaffel Ben Ayed, Montassar Naghmouchi","doi":"arxiv-2407.21559","DOIUrl":null,"url":null,"abstract":"Electronic Health Records (EHRs) and Medical Data are classified as personal\ndata in every privacy law, meaning that any related service that includes\nprocessing such data must come with full security, confidentiality, privacy and\naccountability. Solutions for health data management, as in storing it, sharing\nand processing it, are emerging quickly and were significantly boosted by the\nCovid-19 pandemic that created a need to move things online. EHRs makes a\ncrucial part of digital identity data, and the same digital identity trends --\nas in self sovereign identity powered by decentralized ledger technologies like\nBlockchain, are being researched or implemented in contexts managing digital\ninteractions between health facilities, patients and health professionals. In\nthis paper, we propose a blockchain-based solution enabling secure exchange of\nEHRs between different parties powered by a self-sovereign identity (SSI)\nwallet and decentralized identifiers. We also make use of a consortium IPFS\nnetwork for off-chain storage and attribute-based encryption (ABE) to ensure\ndata confidentiality and integrity. Through our solution, we grant users full\ncontrol over their medical data, and enable them to securely share it in total\nconfidentiality over secure communication channels between user wallets using\nencryption. We also use DIDs for better user privacy and limit any possible\ncorrelations or identification by using pairwise DIDs. Overall, combining this\nset of technologies guarantees secure exchange of EHRs, secure storage and\nmanagement along with by-design features inherited from the technological\nstack.","PeriodicalId":501168,"journal":{"name":"arXiv - CS - Emerging Technologies","volume":"49 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2024-07-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Self-Sovereign Identity for Consented and Content-Based Access to Medical Records using Blockchain\",\"authors\":\"Marie Tcholakian, Karolina Gorna, Maryline Laurent, Hella Kaffel Ben Ayed, Montassar Naghmouchi\",\"doi\":\"arxiv-2407.21559\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Electronic Health Records (EHRs) and Medical Data are classified as personal\\ndata in every privacy law, meaning that any related service that includes\\nprocessing such data must come with full security, confidentiality, privacy and\\naccountability. Solutions for health data management, as in storing it, sharing\\nand processing it, are emerging quickly and were significantly boosted by the\\nCovid-19 pandemic that created a need to move things online. EHRs makes a\\ncrucial part of digital identity data, and the same digital identity trends --\\nas in self sovereign identity powered by decentralized ledger technologies like\\nBlockchain, are being researched or implemented in contexts managing digital\\ninteractions between health facilities, patients and health professionals. In\\nthis paper, we propose a blockchain-based solution enabling secure exchange of\\nEHRs between different parties powered by a self-sovereign identity (SSI)\\nwallet and decentralized identifiers. We also make use of a consortium IPFS\\nnetwork for off-chain storage and attribute-based encryption (ABE) to ensure\\ndata confidentiality and integrity. Through our solution, we grant users full\\ncontrol over their medical data, and enable them to securely share it in total\\nconfidentiality over secure communication channels between user wallets using\\nencryption. We also use DIDs for better user privacy and limit any possible\\ncorrelations or identification by using pairwise DIDs. Overall, combining this\\nset of technologies guarantees secure exchange of EHRs, secure storage and\\nmanagement along with by-design features inherited from the technological\\nstack.\",\"PeriodicalId\":501168,\"journal\":{\"name\":\"arXiv - CS - Emerging Technologies\",\"volume\":\"49 1\",\"pages\":\"\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2024-07-31\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"arXiv - CS - Emerging Technologies\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/arxiv-2407.21559\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"arXiv - CS - Emerging Technologies","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/arxiv-2407.21559","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
摘要
电子健康记录 (EHR) 和医疗数据在所有隐私法中都被归类为个人数据,这意味着任何包括处理此类数据的相关服务都必须具备全面的安全性、保密性、隐私性和责任性。医疗数据管理解决方案,如存储、共享和处理数据,正在迅速兴起,并因第 19 号科维德病毒大流行而得到极大推动,该病毒产生了将数据转移到网上的需求。电子病历是数字身份数据的重要组成部分,而同样的数字身份趋势--即由区块链等分散式分类账技术驱动的自我主权身份--正在医疗机构、患者和医疗专业人员之间的数字互动管理中得到研究或实施。在本文中,我们提出了一种基于区块链的解决方案,通过自我主权身份(SSI)钱包和去中心化标识符,实现各方之间安全交换电子健康记录。我们还利用联盟 IPFS 网络进行链外存储,并使用基于属性的加密(ABE)来确保数据的机密性和完整性。通过我们的解决方案,用户可以完全控制自己的医疗数据,并通过用户钱包之间的安全通信渠道,使用加密技术安全地共享完全保密的数据。我们还使用 DID 来改善用户隐私,并通过使用成对 DID 来限制任何可能的关联或识别。总之,将这一系列技术结合起来,可以保证电子病历的安全交换、安全存储和管理,以及从技术栈中继承的设计功能。
Self-Sovereign Identity for Consented and Content-Based Access to Medical Records using Blockchain
Electronic Health Records (EHRs) and Medical Data are classified as personal
data in every privacy law, meaning that any related service that includes
processing such data must come with full security, confidentiality, privacy and
accountability. Solutions for health data management, as in storing it, sharing
and processing it, are emerging quickly and were significantly boosted by the
Covid-19 pandemic that created a need to move things online. EHRs makes a
crucial part of digital identity data, and the same digital identity trends --
as in self sovereign identity powered by decentralized ledger technologies like
Blockchain, are being researched or implemented in contexts managing digital
interactions between health facilities, patients and health professionals. In
this paper, we propose a blockchain-based solution enabling secure exchange of
EHRs between different parties powered by a self-sovereign identity (SSI)
wallet and decentralized identifiers. We also make use of a consortium IPFS
network for off-chain storage and attribute-based encryption (ABE) to ensure
data confidentiality and integrity. Through our solution, we grant users full
control over their medical data, and enable them to securely share it in total
confidentiality over secure communication channels between user wallets using
encryption. We also use DIDs for better user privacy and limit any possible
correlations or identification by using pairwise DIDs. Overall, combining this
set of technologies guarantees secure exchange of EHRs, secure storage and
management along with by-design features inherited from the technological
stack.