A combined Blockchain and zero-knowledge model for healthcare B2B and B2C data sharing

Q1 Mathematics
Hesham Moosa, Mazen Ali, Hasan Alaswad, W. Elmedany, C. Balakrishna
{"title":"A combined Blockchain and zero-knowledge model for healthcare B2B and B2C data sharing","authors":"Hesham Moosa, Mazen Ali, Hasan Alaswad, W. Elmedany, C. Balakrishna","doi":"10.1080/25765299.2023.2188701","DOIUrl":null,"url":null,"abstract":"The two main forms of healthcare data exchange among entities are business-to-business (B2B) and business-to-customer (B2C). The former uses the electronic data interchange (EDI) technology between healthcare institutions, while the latter is usually conducted by providing web-based interfaces for patients. This research argues that both forms have inherent security and privacy weaknesses. Furthermore, patients lack appropriate transparency and control over their own Personally Identifiable Information (PII). We explore the issues of medical record exchange, analyze them and suggest appropriate solutions in the form of a new model to mitigate them. The vulnerabilities, ranging from critical to minor, include the possibility of Man-in-The-Middle (MiTM) and supply chain attacks, weak cryptography, repudiable transactions, single points of failure (SPOF), and poor access controls. A novel model will be presented in this research for healthcare data sharing which applies the best security practices. The proposed unified model will counter the listed vulnerabilities. It automates the healthcare processes in decentralized architecture by utilizing the smart contracts for B2C transactions such as medicine purchase. The model is based on the Blockchain and zeroknowledge proofs. It is made with novel controls which represent the latest advancements in cybersecurity. It has the potential of setting a new cornerstone. ARTICLE HISTORY Received 24 December 2021 Revised 14 February 2023 Accepted 4 March 2023","PeriodicalId":37239,"journal":{"name":"Arab Journal of Basic and Applied Sciences","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2023-03-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Arab Journal of Basic and Applied Sciences","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1080/25765299.2023.2188701","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"Mathematics","Score":null,"Total":0}
引用次数: 0

Abstract

The two main forms of healthcare data exchange among entities are business-to-business (B2B) and business-to-customer (B2C). The former uses the electronic data interchange (EDI) technology between healthcare institutions, while the latter is usually conducted by providing web-based interfaces for patients. This research argues that both forms have inherent security and privacy weaknesses. Furthermore, patients lack appropriate transparency and control over their own Personally Identifiable Information (PII). We explore the issues of medical record exchange, analyze them and suggest appropriate solutions in the form of a new model to mitigate them. The vulnerabilities, ranging from critical to minor, include the possibility of Man-in-The-Middle (MiTM) and supply chain attacks, weak cryptography, repudiable transactions, single points of failure (SPOF), and poor access controls. A novel model will be presented in this research for healthcare data sharing which applies the best security practices. The proposed unified model will counter the listed vulnerabilities. It automates the healthcare processes in decentralized architecture by utilizing the smart contracts for B2C transactions such as medicine purchase. The model is based on the Blockchain and zeroknowledge proofs. It is made with novel controls which represent the latest advancements in cybersecurity. It has the potential of setting a new cornerstone. ARTICLE HISTORY Received 24 December 2021 Revised 14 February 2023 Accepted 4 March 2023
用于医疗保健B2B和B2C数据共享的区块链和零知识组合模型
实体之间医疗保健数据交换的两种主要形式是企业对企业(B2B)和企业对客户(B2C)。前者使用医疗机构之间的电子数据交换(EDI)技术,而后者通常通过为患者提供基于web的接口来进行。本研究认为,这两种形式都存在固有的安全和隐私弱点。此外,患者对自己的个人身份信息(PII)缺乏适当的透明度和控制。本文对病历交换中存在的问题进行了探讨和分析,并以新模式的形式提出了相应的解决方案。这些漏洞从严重到轻微,包括中间人(MiTM)和供应链攻击的可能性、弱加密、可抵免的事务、单点故障(SPOF)和糟糕的访问控制。本研究将提出一种应用最佳安全实践的医疗保健数据共享新模型。提出的统一模型将对抗所列出的漏洞。它通过利用诸如药品购买等B2C交易的智能合约,在分散的体系结构中自动化医疗保健流程。该模型基于区块链和零知识证明。它是由新颖的控制,代表了网络安全的最新进展。它有可能树立新的基石。文章历史收到2021年12月24日修改2023年2月14日接受2023年3月4日
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
Arab Journal of Basic and Applied Sciences
Arab Journal of Basic and Applied Sciences Mathematics-Mathematics (all)
CiteScore
5.80
自引率
0.00%
发文量
31
审稿时长
36 weeks
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信