Enhancing identity and access management using Hyperledger Fabric and OAuth 2.0: A block-chain-based approach for security and scalability for healthcare industry
{"title":"Enhancing identity and access management using Hyperledger Fabric and OAuth 2.0: A block-chain-based approach for security and scalability for healthcare industry","authors":"Shrabani Sutradhar , Sunil Karforma , Rajesh Bose , Sandip Roy , Sonia Djebali , Debnath Bhattacharyya","doi":"10.1016/j.iotcps.2023.07.004","DOIUrl":null,"url":null,"abstract":"<div><p>Block-chain-based Identity and access management framework is a promising solution to privacy and security issues raised during the exchange of patient data in the healthcare industry. This technology ensures the confidentiality and integrity of sensitive information by providing a decentralized and immutable ledger. In our research, we propose an identity and access management system that employs Hyper-ledger Fabric and OAuth 2.0 for improved security and scalability. This combination allows for transparency and immutability of user transactions and minimizes the risk of fraud and unauthorized access. Additionally, Hyper-ledger Fabric's privacy, security, and scalability features enable granular access control to sensitive information, while OAuth 2.0 authorizes only trusted third-party applications to access specific data on the Fabric network. The proposed approach can handle large volumes of data and support multiple applications, thus providing a secure and scalable solution for managing access to the Fabric network. Moreover, our solution employs Role-based access control based on the patient's role, ensuring privacy and confidentiality. Our statistical analysis demonstrates that the proposed approach can efficiently and securely manage patient identity and access, potentially transforming the healthcare industry by enhancing data interoperability, reducing fraud and errors, and improving patient privacy and security. Furthermore, our solution can facilitate compliance with regulatory requirements such as HIPAA and GDPR.</p></div>","PeriodicalId":100724,"journal":{"name":"Internet of Things and Cyber-Physical Systems","volume":"4 ","pages":"Pages 49-67"},"PeriodicalIF":0.0000,"publicationDate":"2023-07-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Internet of Things and Cyber-Physical Systems","FirstCategoryId":"1085","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2667345223000470","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
Block-chain-based Identity and access management framework is a promising solution to privacy and security issues raised during the exchange of patient data in the healthcare industry. This technology ensures the confidentiality and integrity of sensitive information by providing a decentralized and immutable ledger. In our research, we propose an identity and access management system that employs Hyper-ledger Fabric and OAuth 2.0 for improved security and scalability. This combination allows for transparency and immutability of user transactions and minimizes the risk of fraud and unauthorized access. Additionally, Hyper-ledger Fabric's privacy, security, and scalability features enable granular access control to sensitive information, while OAuth 2.0 authorizes only trusted third-party applications to access specific data on the Fabric network. The proposed approach can handle large volumes of data and support multiple applications, thus providing a secure and scalable solution for managing access to the Fabric network. Moreover, our solution employs Role-based access control based on the patient's role, ensuring privacy and confidentiality. Our statistical analysis demonstrates that the proposed approach can efficiently and securely manage patient identity and access, potentially transforming the healthcare industry by enhancing data interoperability, reducing fraud and errors, and improving patient privacy and security. Furthermore, our solution can facilitate compliance with regulatory requirements such as HIPAA and GDPR.