Privacy preservation of electronic health records with adversarial attacks identification in hybrid cloud

Tehsin Kanwal, Adeel Anjum*, Saif U.R. Malik, Abid Khan, Muazzam A. Khan

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

29 Citations (Scopus)

Abstract

An increasing trend in healthcare organizations to outsource EHRs’ data to the cloud highlights new challenges regarding the privacy of given individuals. Healthcare organizations outsource their EHRs data in a hybrid cloud that elevates the problem of security and privacy in terms of EHRs’ access to an unlimited number of recipients in a hybrid cloud environment. In this paper, we investigated the need for a privacy-preserving access control model for the hybrid cloud. A comprehensive and exploratory analysis of privacy-preserving solutions with the help of taxonomy for cloud-based EHRs is described in this work. We have formally identified the existence of internal access control and external privacy disclosures in outsourcing system architecture for hybrid cloud. Then, we proposed a privacy-preserving XACML based access control model (PPX-AC) that supports fine-grained access control with the multipurpose utilization of EHRs alongside state-of-the-art privacy mechanism. Our proposed approach invalidates the identified security and privacy attacks. We have formally verified the proposed privacy-preserving XACML based access control model (PPX-AC) with the invalidation of identified privacy attacks using High-Level Petri Nets (HLPN). Moreover, property verification of the proposed model in SMT-lib and Z3 solver and implementation of the model proves its effectiveness in terms of privacy-aware EHRs access and multipurpose usage.

Original languageEnglish
Article number103522
Pages (from-to)1-16
Number of pages16
JournalComputer Standards and Interfaces
Volume78
Early online date25 Feb 2021
DOIs
Publication statusPublished - 31 Oct 2021

Keywords

  • Cryptography
  • EHRs
  • Formal verification
  • Generalization
  • Hybrid cloud
  • Privacy

Fingerprint

Dive into the research topics of 'Privacy preservation of electronic health records with adversarial attacks identification in hybrid cloud'. Together they form a unique fingerprint.

Cite this