{"title":"Implementing One Time Password based security mechanism for securing personal health records in cloud","authors":"K. Ramesh, S. Ramesh","doi":"10.1109/ICCICCT.2014.6993099","DOIUrl":null,"url":null,"abstract":"Personal Health Record (PHR) is an emerging patient-centric model of health information exchange, which is often outsourced to be stored at a third party, such as cloud providers. Researches had been taken up in enhancing the security of the out sourced PHRs by implementing the Attribute Based Encryption (ABE) to assure the patients control over their PHRs. Yet, most of the attribute based encryption introduces complexity in access control, key management, privacy exposure and scalability of the System. However, the authentication module of the PHR system had been researched less when compared to the security module of the system. In this paper, we propose a \"One Time Password\" user authentication module along with Advanced Encryption Standard (AES) for encrypting the owners personal Health Record before uploading it onto the semi trusted cloud server.","PeriodicalId":6615,"journal":{"name":"2014 International Conference on Control, Instrumentation, Communication and Computational Technologies (ICCICCT)","volume":"83 1","pages":"968-972"},"PeriodicalIF":0.0000,"publicationDate":"2014-07-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"11","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 International Conference on Control, Instrumentation, Communication and Computational Technologies (ICCICCT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCICCT.2014.6993099","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 11
Abstract
Personal Health Record (PHR) is an emerging patient-centric model of health information exchange, which is often outsourced to be stored at a third party, such as cloud providers. Researches had been taken up in enhancing the security of the out sourced PHRs by implementing the Attribute Based Encryption (ABE) to assure the patients control over their PHRs. Yet, most of the attribute based encryption introduces complexity in access control, key management, privacy exposure and scalability of the System. However, the authentication module of the PHR system had been researched less when compared to the security module of the system. In this paper, we propose a "One Time Password" user authentication module along with Advanced Encryption Standard (AES) for encrypting the owners personal Health Record before uploading it onto the semi trusted cloud server.
个人健康记录(PHR)是一种新兴的以患者为中心的健康信息交换模式,通常将其外包给第三方(如云提供商)存储。通过采用基于属性的加密技术(Attribute Based Encryption, ABE)来提高外发病历的安全性,以确保患者对自己的病历进行控制。然而,大多数基于属性的加密在访问控制、密钥管理、隐私暴露和系统可伸缩性方面引入了复杂性。然而,相对于系统的安全模块,对PHR系统的认证模块研究较少。在本文中,我们提出了一个“一次性密码”用户认证模块和高级加密标准(AES),用于在将所有者的个人健康记录上传到半可信云服务器之前对其进行加密。