Secure Collaborative Platform for Health Care Research in an Open Environment: Perspective on Accountability in Access Control.

Internet of Things accountability attribute-based encryption blockchain cloud computing eHealth data interoperability mobile phone privacy research platform for health care security

Journal

Journal of medical Internet research
ISSN: 1438-8871
Titre abrégé: J Med Internet Res
Pays: Canada
ID NLM: 100959882

Informations de publication

Date de publication:
14 10 2022
Historique:
received: 14 03 2022
accepted: 30 08 2022
revised: 02 08 2022
entrez: 14 10 2022
pubmed: 15 10 2022
medline: 19 10 2022
Statut: epublish

Résumé

With the recent use of IT in health care, a variety of eHealth data are increasingly being collected and stored by national health agencies. As these eHealth data can advance the modern health care system and make it smarter, many researchers want to use these data in their studies. However, using eHealth data brings about privacy and security concerns. The analytical environment that supports health care research must also consider many requirements. For these reasons, countries generally provide research platforms for health care, but some data providers (eg, patients) are still concerned about the security and privacy of their eHealth data. Thus, a more secure platform for health care research that guarantees the utility of eHealth data while focusing on its security and privacy is needed. This study aims to implement a research platform for health care called the health care big data platform (HBDP), which is more secure than previous health care research platforms. The HBDP uses attribute-based encryption to achieve fine-grained access control and encryption of stored eHealth data in an open environment. Moreover, in the HBDP, platform administrators can perform the appropriate follow-up (eg, block illegal users) and monitoring through a private blockchain. In other words, the HBDP supports accountability in access control. We first identified potential security threats in the health care domain. We then defined the security requirements to minimize the identified threats. In particular, the requirements were defined based on the security solutions used in existing health care research platforms. We then proposed the HBDP, which meets defined security requirements (ie, access control, encryption of stored eHealth data, and accountability). Finally, we implemented the HBDP to prove its feasibility. This study carried out case studies for illegal user detection via the implemented HBDP based on specific scenarios related to the threats. As a result, the platform detected illegal users appropriately via the security agent. Furthermore, in the empirical evaluation of massive data encryption (eg, 100,000 rows with 3 sensitive columns within 46 columns) for column-level encryption, full encryption after column-level encryption, and full decryption including column-level decryption, our approach achieved approximately 3 minutes, 1 minute, and 9 minutes, respectively. In the blockchain, average latencies and throughputs in 1Org with 2Peers reached approximately 18 seconds and 49 transactions per second (TPS) in read mode and approximately 4 seconds and 120 TPS in write mode in 300 TPS. The HBDP enables fine-grained access control and secure storage of eHealth data via attribute-based encryption cryptography. It also provides nonrepudiation and accountability through the blockchain. Therefore, we consider that our proposal provides a sufficiently secure environment for the use of eHealth data in health care research.

Sections du résumé

BACKGROUND
With the recent use of IT in health care, a variety of eHealth data are increasingly being collected and stored by national health agencies. As these eHealth data can advance the modern health care system and make it smarter, many researchers want to use these data in their studies. However, using eHealth data brings about privacy and security concerns. The analytical environment that supports health care research must also consider many requirements. For these reasons, countries generally provide research platforms for health care, but some data providers (eg, patients) are still concerned about the security and privacy of their eHealth data. Thus, a more secure platform for health care research that guarantees the utility of eHealth data while focusing on its security and privacy is needed.
OBJECTIVE
This study aims to implement a research platform for health care called the health care big data platform (HBDP), which is more secure than previous health care research platforms. The HBDP uses attribute-based encryption to achieve fine-grained access control and encryption of stored eHealth data in an open environment. Moreover, in the HBDP, platform administrators can perform the appropriate follow-up (eg, block illegal users) and monitoring through a private blockchain. In other words, the HBDP supports accountability in access control.
METHODS
We first identified potential security threats in the health care domain. We then defined the security requirements to minimize the identified threats. In particular, the requirements were defined based on the security solutions used in existing health care research platforms. We then proposed the HBDP, which meets defined security requirements (ie, access control, encryption of stored eHealth data, and accountability). Finally, we implemented the HBDP to prove its feasibility.
RESULTS
This study carried out case studies for illegal user detection via the implemented HBDP based on specific scenarios related to the threats. As a result, the platform detected illegal users appropriately via the security agent. Furthermore, in the empirical evaluation of massive data encryption (eg, 100,000 rows with 3 sensitive columns within 46 columns) for column-level encryption, full encryption after column-level encryption, and full decryption including column-level decryption, our approach achieved approximately 3 minutes, 1 minute, and 9 minutes, respectively. In the blockchain, average latencies and throughputs in 1Org with 2Peers reached approximately 18 seconds and 49 transactions per second (TPS) in read mode and approximately 4 seconds and 120 TPS in write mode in 300 TPS.
CONCLUSIONS
The HBDP enables fine-grained access control and secure storage of eHealth data via attribute-based encryption cryptography. It also provides nonrepudiation and accountability through the blockchain. Therefore, we consider that our proposal provides a sufficiently secure environment for the use of eHealth data in health care research.

Identifiants

pubmed: 36240003
pii: v24i10e37978
doi: 10.2196/37978
pmc: PMC9617185
doi:

Types de publication

Journal Article Research Support, Non-U.S. Gov't

Langues

eng

Sous-ensembles de citation

IM

Pagination

e37978

Informations de copyright

©Giluk Kang, Young-Gab Kim. Originally published in the Journal of Medical Internet Research (https://www.jmir.org), 14.10.2022.

Références

ACM Comput Surv. 2015 Sep;48(1):
pubmed: 26640318
J Am Med Inform Assoc. 2006 Jan-Feb;13(1):30-9
pubmed: 16221939
Trials. 2020 Feb 18;21(1):200
pubmed: 32070405
Int J Epidemiol. 2020 Jun 1;49(3):738-739f
pubmed: 31930310
Int J Environ Res Public Health. 2021 Sep 14;18(18):
pubmed: 34574593
Comput Struct Biotechnol J. 2018 Jul 29;16:267-278
pubmed: 30108685
Source Code Biol Med. 2010 Sep 21;5:9
pubmed: 20858241
J Biomed Inform. 2015 Feb;53:162-73
pubmed: 25463966
J Med Syst. 2016 Nov;40(11):235
pubmed: 27653042
Acta Inform Med. 2019 Dec;27(4):253-258
pubmed: 32055092
AMIA Annu Symp Proc. 2020 Mar 04;2019:673-680
pubmed: 32308862
Stat Med. 2015 Oct 15;34(23):3081-103
pubmed: 26045214
J Am Med Inform Assoc. 2019 Aug 1;26(8-9):737-748
pubmed: 31162545
Res Involv Engagem. 2021 Jun 14;7(1):40
pubmed: 34127076
EGEMS (Wash DC). 2019 Mar 29;7(1):6
pubmed: 30972355
J Med Internet Res. 2020 Jun 4;22(6):e18579
pubmed: 32496199
Int J Popul Data Sci. 2019 Nov 20;4(2):1134
pubmed: 34095541

Auteurs

Giluk Kang (G)

Department of Computer and Information Security, and Convergence Engineering for Intelligent Drone, Sejong University, Seoul, Republic of Korea.

Young-Gab Kim (YG)

Department of Computer and Information Security, and Convergence Engineering for Intelligent Drone, Sejong University, Seoul, Republic of Korea.

Articles similaires

[Redispensing of expensive oral anticancer medicines: a practical application].

Lisanne N van Merendonk, Kübra Akgöl, Bastiaan Nuijen
1.00
Humans Antineoplastic Agents Administration, Oral Drug Costs Counterfeit Drugs

Smoking Cessation and Incident Cardiovascular Disease.

Jun Hwan Cho, Seung Yong Shin, Hoseob Kim et al.
1.00
Humans Male Smoking Cessation Cardiovascular Diseases Female
Humans United States Aged Cross-Sectional Studies Medicare Part C
1.00
Humans Yoga Low Back Pain Female Male

Classifications MeSH