A patient-identity security mechanism for electronic medical records during transit and at rest.

Hui-Mei Chao, Shih-Hsiung Twu, Chin-Ming Hsu
{"title":"A patient-identity security mechanism for electronic medical records during transit and at rest.","authors":"Hui-Mei Chao,&nbsp;Shih-Hsiung Twu,&nbsp;Chin-Ming Hsu","doi":"10.1080/14639230500209443","DOIUrl":null,"url":null,"abstract":"<p><p>This paper proposes a patient-identity security mechanism, including an identity cipher/decipher and a user-authentication protocol, to ensure the confidentiality and authentication of patients' electronic medical records (EMRs) during transit and at rest. To support the confidentiality of an EMR, the identity cipher/decipher uses a data-hiding function and three logical-based functions to encrypt/decrypt a patient's identifying data and medical details in an EMR. The ciphertext of the patient's identifying data is patient-EMR related, whereas that of medical details is healthcare agent-EMR related. To support the authentication of an EMR, the user-authentication protocol based on a public key infrastructure uses certificates and dynamic cookies for verification/identification. The identity cipher has been simulated using C programming language running on a 1500 MHz Pentium PC with 512 MB of RAM. The experimental results show that healthcare agents can install large amounts of patients' encrypted EMRs in healthcare databases efficiently. In addition, separately storing the keys in a user's token and an EMR database for decryption increases the safety of patients' EMRs. For each user-authentication trail, the use of certificates and dynamic cookies for verification/identification ensures that only authorized users can obtain access to the EMR, and anyone involved cannot make false claims on the transmission made.</p>","PeriodicalId":80069,"journal":{"name":"Medical informatics and the Internet in medicine","volume":"30 3","pages":"227-40"},"PeriodicalIF":0.0000,"publicationDate":"2005-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://sci-hub-pdf.com/10.1080/14639230500209443","citationCount":"20","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Medical informatics and the Internet in medicine","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1080/14639230500209443","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 20

Abstract

This paper proposes a patient-identity security mechanism, including an identity cipher/decipher and a user-authentication protocol, to ensure the confidentiality and authentication of patients' electronic medical records (EMRs) during transit and at rest. To support the confidentiality of an EMR, the identity cipher/decipher uses a data-hiding function and three logical-based functions to encrypt/decrypt a patient's identifying data and medical details in an EMR. The ciphertext of the patient's identifying data is patient-EMR related, whereas that of medical details is healthcare agent-EMR related. To support the authentication of an EMR, the user-authentication protocol based on a public key infrastructure uses certificates and dynamic cookies for verification/identification. The identity cipher has been simulated using C programming language running on a 1500 MHz Pentium PC with 512 MB of RAM. The experimental results show that healthcare agents can install large amounts of patients' encrypted EMRs in healthcare databases efficiently. In addition, separately storing the keys in a user's token and an EMR database for decryption increases the safety of patients' EMRs. For each user-authentication trail, the use of certificates and dynamic cookies for verification/identification ensures that only authorized users can obtain access to the EMR, and anyone involved cannot make false claims on the transmission made.

电子医疗记录在传输和静止期间的患者身份安全机制。
本文提出了一种患者身份安全机制,包括身份密码/解密和用户认证协议,以确保患者电子病历在传输和静止期间的保密性和认证性。为了支持EMR的机密性,身份密码/解密使用一个数据隐藏功能和三个基于逻辑的功能来加密/解密EMR中患者的身份数据和医疗详细信息。患者识别数据的密文与患者emr相关,而医疗详细信息的密文与医疗保健代理emr相关。为了支持EMR的身份验证,基于公钥基础设施的用户身份验证协议使用证书和动态cookie进行验证/标识。在一台1500 MHz、512mb内存的奔腾计算机上,用C语言对该身份密码进行了仿真。实验结果表明,医疗代理可以高效地在医疗数据库中安装大量患者加密的电子病历。此外,将密钥分别存储在用户令牌和EMR数据库中以进行解密,可以提高患者EMR的安全性。对于每条用户身份验证线索,使用证书和动态cookie进行验证/识别,确保只有授权用户才能访问电子记录,而任何参与的人都不能对所进行的传输作出虚假声明。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信