Department of Computer Science & Engineering, Ponjesly College of Engineering, Nagercoil
Online published on 11 November, 2013.
Personal Health Record (PHR) is an emerging patient-centric model of health information exchange. PHR service allows a patient to create, manage, and control the personal health data, which has made the storage, retrieval, and sharing of the medical information more efficient. Each patient has full control of the medical records and can share the health data with a wide range of users, including healthcare providers, family members or friends. To assure the patients’ control over access to their own PHRs, it is a promising method to encrypt the PHRs before outsourcing. Issues such as risks of privacy exposure,scalability in key management, flexible access and efficient user revocation, have remained the most important challenges towards achieving fine-grained, cryptographically enforced data access control. To achieve fine-grained and scalable data access control for PHRs, we use attribute based encryption (ABE) techniques to encrypt each patient's PHR file. The multiple data owner scenario is focused and the users in the PHR system are divided into multiple security domains that greatly reduces the key management complexity for owners and users.