UPCommons Portal del coneixement obert de la UPC http://upcommons.upc.edu/e-prints Aquesta és una còpia de la versió author’s final draft d'un article publicat a la revista Multimedia tools and applications. La publicació final està disponible a Springer a través de http://dx.doi.org/10.1007/s11042-013-1829-6 This is a copy of the author 's final draft version of an article published in the journal Multimedia tools and applications. The final publication is available at Springer via http://dx.doi.org/10.1007/s11042-013-1829-6 Article publicat / Published article: Xhafa, F., Li, Jingwei, Zhao, G., Li, Jin, Chen, X., Wong, D.S., F. (2015) Designing cloud-based electronic health record system with attribute-based encryption. " Multimedia tools and applications". Vol. 74, num. 10. p.3441-3458. Doi: 10.1007/s11042-013-1829-6
Noname manuscript No. (will be inserted by the editor) Designing Cloud-based Electronic Health Record System with Attribute-based Encryption Fatos Xhafa ·Jingwei Li ·Gansen Zhao ·Jin Li ·Xiaofeng Chen ·Duncan S. Wong the date of receipt and acceptance should be inserted later Abstract With the development of cloud computing, electronic health record (EHR) system has appeared in the form of patient-centric, in which patients store their personal health records (PHRs) at a remote cloud server and selectively share them with physicians for convenient medical care. Although the newly emerged form has many advantages over traditional client-server model, it inevitably introduces patients’ concerns on the privacy of their PHRs due to the fact that cloud servers are very likely to be in a different trusted domain from that of the patients. In this paper, aiming at allowing for efficient storing and sharing PHRs and also eliminating patients’ worries about PHR privacy, we design a secure cloud-based EHR system, which guarantees security and privacy of medical data stored in the cloud, relying on cryptographic primitive but not the full trust over cloud servers. Based on our proposed basic EHR system, we provide Fatos Xhafa Dept de Llenguatges i Sistemes Inform`atics, Universitat Polit`ecnica de Catalunya, Spain E-mail: [email protected]c.edu Jingwei Li College of Information Technical Science, Nankai University, China E-mail: [email protected] Gansen Zhao School of Computer Science,South China Normal University, China E-mail: [email protected] Jin Li School of Computer Science, Guangzhou University, China E-mail: [email protected] Xiaofeng Chen State Key Laboratory of Integrated Service Networks (ISN), Xidian University, China E-mail: xfc[email protected] Duncan S. Wong Department of Computer Science, City University of Hong Kong, Hong Kong E-mail:
[email protected]
2 Fatos Xhafa et al. several extensions including adding searchability, supporting revocation functionality and enabling efficient local decryption, which fills the gap between theoretical proposal and practical application. Keywords Electronic health record ·Attribute-based encryption ·Cloud computing 1 Introduction Electronic health record (EHR) is an evolving concept defined as a systematic collection of electronic health information about individual patients or populations. Compared with traditional paper-based health record, EHR has many basic benefits including being easily accessed and computerized, and the elimination of poor penmanship, which has historically plagued the medical chart [38][33]. Besides the basic benefits, from the perspective of system level, EHR system can also have particular functionalities which hold great promise in improving the quality of care and reducing costs at the health care system [29]. Due to the great advantages of EHR, the Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 that was signed into law as part of the “stimulus package” represents the largest US initiative to date that is designed to encourage widespread use of EHRs. Traditionally, health care system using EHRs (without loss of generality we call it EHR system throughout this paper) was built in the client-server model. Specifically, this type of system stores data in house, requiring a server, hardware and software to be installed in the physician’s office. With the recent development of cloud computing [1], it greatly desires to migrate the patients’ data at the in-house servers to the cloud, which leads to the emergence of a new type of EHR system, namely the cloud-based EHR system. Compared with the traditional client-server setting, the cloud-based EHR system has many great advantages, such as requiring simpler implementation and less IT resources, reducing the cost of EHR installation, proving superior accessibility and collaboration, providing better scalability, etc. In tandem with the great use of cloud-based EHR system, it rises concerns on the privacy over patients’ personal health records (PHRs). Specifically, although it is believed that security in today’s cloud-based applications is generally improved than the security in traditional systems in the sense that more resources can be devoted to solving security issues, unauthorized access to sensitive data is one of the most critical concerns from cloud-based customers (i.e., patients in our applications). Such a concern originates from the fact that cloud servers are very likely to be in a different trusted domain from that of the customers. It is thus hard to imagine that the patients would like to store their PHRs on the cloud to selectively share with physicians for medical care. In this paper, aiming at allowing for secure storing and sharing PHRs and also making patients cancel worries about the privacy of their PHRs, we design a secure cloud-based EHR system using attribute-based encryption (ABE). The system allows the patients to share their PHRs with physicians
Title Suppressed Due to Excessive Length 3 selectively by encrypting the data using patients’ symptoms of illness without knowing the precise description of their illnesses or the departments of physicians. In our proposed system, the actual PHR is encrypted with efficient symmetric key encryption, while the symmetric key is encapsulated with ABE. This hybrid encryption paradigm will not sacrifice the efficiency of our system too much. For key encapsulation, we use the threshold ABE [34] as underlying primitive to enable the physician to access with false-tolerant, which is realistic in practice. Then, based on the proposed basic EHR system, we provide several extensions to make it allow for search, revocation and efficient local decryption, which fills the gap between our system proposal and practical application. The rest of this paper is organized as follows. In Section 2, we review the works related to EHR and ABE. In Section 3, we provide the system model and design goals for the cloud-based EHR system. In Section 4, we design the basic EHR system. In Section 5, several extensions are added to the basic EHR system based on practical requirements. Finally conclusion is drawn in Section 6. 2 Related Work 2.1 Electronic Health Record System The paper-based health records in use may generate an extensive paper trail. There is consequently a great interest in moving from paper-based health records to EHRs, and building new health care system with EHRs. Until now, many standards have related the regulations that an EHR system should satisfy. For example the Health Insurance Portability and Accountability Act (HIPAA) of 1996 which is the most frequently used regulation defines the privacy rules of USA health informatics. We suggest the readers refer to [10] for other detailed regulations and standards. Security and privacy play an important role in today’s EHR system. Aiming at allowing physicians to access patients’ health data without disclosing patients’ personal data, the pseudo anonymity technique has been applied in several works [31][32][8]. Of these, [8] used an approach for reversible pseudonym generation; [32] proposed the possibility of sharing pseudonyms based on Shamir secret sharing [35]. Besides anonymize identity, many works (e.g., [2][9][13][14][15] to list a few) suggested that EHR data should also be encrypted in order to increase security. Concerning on the deployment of EHR system in cloud, Li et al. [28] addressed the problem of authorized private keyword searches on encrypted PHRs in cloud computing environment, and presented a scalable and finegrained authorization framework for this purpose. Haas et al. [13] and Zhang et al. [40] considered that patients should not trust that the cloud service provider cannot access their EHR data, particularly when the cloud service provider is unrelated to patient or health institutions, and proposed crypto-
4 Fatos Xhafa et al. graphic solutions. The work most related to ours is from Narayan et al. [30] who proposed the use of ABE to ensure that the cloud service provider cannot see (or copy) EHR data. Compared with our work, the previous work [30] lacks of the consideration of the fault-tolerance and reducing local computation in decryption. In addition, Narayan et al.’s work [30] uses a public-key searchable encryption [4] which involves computationally intensive operations such as bilinear mappings and is not scalable. In this work, our searchability is just based on lightweight pattern match and suitable for the EHR application consisting of large number of PHRs. 2.2 Attribute-based Encryption The notion of ABE, which was introduced as fuzzy identity-based encryption in [34], was firstly dealt with by Goyal et al. [11]. Two different and complementary notions of ABE were defined as key-policy attribute-based encryption (KP-ABE) and ciphertext-policy attribute-based encryption (CP-ABE). A construction of KP-ABE was provided in the same paper [11], while the first CP-APE construction supporting tree-based access structure in generic group model is presented by Bethencourt et al. [3]. Subsequently, a number of variants of ABE schemes have been proposed since its introduction. They range from extending its functionality to proposing schemes with stronger security proofs. Such as ABE schemes supporting for any kinds of access structures [7][37], ABE with multi-authorities [5][6][18], full secure ABE [16][17][20], unbounded ABE [19], etc. Recently, a novel outsourcing paradigm for ABE was provided for reduce local computation [41][12][22] [23]. The common idea in these work is to utilize secure outsourcing technique to delegate the overhead computation during encryption/decryption/key-issuing to third party such that the local computation is minimized. In this paper we follow this outsourcing paradigm to realize efficient local decryption. 3 Problem Statement 3.1 System Model In this paper, we consider a cloud computing environment which hosts the PHR service. Specifically, as shown in Fig. 1 there are four entities involved in this system. –Patient. It is an entity which creates its PHRs, and stores them at the cloud server such that physicians equipped with professional capabilities are able to access them. –Cloud Server. It is an entity which is responsible for storing patients’ (encrypted) PHRs in a database and performing searches for the physicians.
Title Suppressed Due to Excessive Length 5 Fig. 1 Architecture for EHR System –Global Authority. It is an entity which is responsible for key management. Specifically, it generates keys for physicians of the system, and publishes public parameters needed by cryptographic operations. –Physicians. It is an entity which can submit query to retrieve PHRs stored at cloud server. More precisely, in this paper we consider the physicians to be from the public domain, that is they are usually not personally known by the patients. The physicians are able to obtain their private keys due to their professional responsibilities, and need to access the PHRs for providing medical care. Based on the system above, we then provide an overview of our proposed EHR system. – System Setup.Public parameter and master secret key are initialized for the system, and the global authority keeps the master secret key and publishes the public parameters outside. – Physician Authorization.When a physician wants to join the system, he/she has to apply for his/her private key at the authority according to his/her professional responsibilities. – PHR Storage.When a patient wants to create and share his/her PHR at the cloud server, he/she encrypts and sends the PHR to cloud server. – PHR Access.When a physician wants to access a PHR, he/she downloads ciphertext from the cloud server and decrypts it. 3.2 Adversary Model and Design Goals In this paper, we assume the global authority is fully trusted, and consider a “honest-but-curious” server which has been widely adopted in many existing
6 Fatos Xhafa et al. works [36][24][25]. Specifically, the cloud server will be “curious” for learning the underlying meanings of the PHRs, but still honestly follow our proposed protocols. Also, the cloud server could collude with some physicians to help them derive additional information about patients’ PHRs beyond physicians’ accessing scope. Then, under the adversary model clarified above, we attempt to address the problem of building an efficient fine-grained access control EHR system in the cloud environment. Specifically, we allow the patient to enforce an access policy on EHR according his/her disease which precisely designates the group of physicians allowed to access the EHR. Also the cloud server is prevented from learning the underlying meaning of the EHRs even if it colludes with physicians not in the scope of the target EHRs. Besides this, we require that all the goals should be achieved efficiently in the sense that the EHR system is scalable. 4 Basic EHR System In this section, we will firstly introduce the background of ABE, and then describe our design specification adapting to practical needs. Finally, the basic EHR system as well as its security analysis are provided. 4.1 Attribute-based Encryption Attribute-based encryption has been widely applied to impose fine-grained access control on encrypted data recently. There are two kinds of ABE having been proposed: KP-ABE and CP-ABE. In KP-ABE, the access policy is assigned in private key, whereas, in CP-ABE, it is specified in ciphertext. Without loss of generality, we are able to denote (Ienc, Ikey) as the input to encryption and key generation of ABE. Accordingly, in CP-ABE scheme, (Ienc, Ikey)=(A, ω) while that is (ω, A) in KP-ABE, where ωand Aare attribute set and access structure, respectively. Then, an ABE scheme is consisted of four algorithms below. –Setup(λ) : The setup algorithm takes as input – a security parameter λ. It outputs the public key pk and the master secret key msk. –KeyGen(Ikey, msk) : The key extraction algorithm takes as input – an access structure (resp. attribute set) Ikey and the master secret key msk. It outputs the user’s private key sk. –Encrypt(m, Ienc) : The encryption algorithm takes as input – a message m and the attribute set (resp. access structure) Ienc. It outputs the ciphertext ct. –Decrypt(ct, sk) : The decryption algorithm takes as input – a ciphertext ct which was assumed to be encrypted under the attribute set (resp. access structure) Ienc and the private key sk for access structure (resp. attribute
Title Suppressed Due to Excessive Length 7 Name Age Sex Region Possible Illness Contact Information Alice 65 female Boston heart disease XXX-XXX-XXXX Bob 30 male New York XXX-XXX-XXXX Lisa 45 female Washington DC XXX-XXX-XXXX Table 1 An Example of PHR set) Ikey. It outputs the message mif γ(Ikey, Ienc) = 1 and the error symbol ⊥otherwise, where the predicate γis predefined. 4.2 Design Specification 4.2.1 PHR Structure In the EHR system, a patient’s PHR describes detailed personal information of him/her. Table. 1 illustrates an example of three personal information in EHR for Alice. Note that the entry of possible illness can be let blank if the patient does not know it properly. In practice, a patient may want to share his/her record with a physician familiar with his/her symptoms, but do not want to allow others to read anything about personal information. Therefore, in our EHR system, we require that PHR will be encrypted under the symptoms of patient’s disease, which potentially specifies the underlying physicians allowed to access patient’s personal information. 4.2.2 Physician Attributes The physicians’ attributes, consisting of many kinds of symptoms of the diseases that the physician is professional in, are obtained from the global authority. For example, if a physician is professional in heart disease and has obtained the qualification certificate for this disease, he/she can make an authentication at authority with the certificate. The authority then assigns him with a private key for the corresponding symptoms including heartache, shortness of breath, dizziness and so on. Using this private key, the physician is able to later access the PHRs within his/her scope. 4.2.3 Access Policy Suppose all the symptoms of diseases constitute a universe U={u1, u2, . . . , un} where uiindicates a symptom of disease such as heartache or dizziness (we then will not distinguish the term of symptom and attribute used in the rest of this paper). Then, each patient’s disease and the professional abilities of physician can be described as subsets of symptoms, that is ˆω⊆ U and ω⊆ U respectively.
8 Fatos Xhafa et al. Next, we specify the policy for accessing PHRs. Recall that we use “symptoms” to describe both patient’s disease and physician’s professional abilities. Intuitively, if an identical set of symptoms is owned by a patient and a physician, it has a significant probability that the physician specializes in the patient’s disease. It is advisable to allow such a physician to access this patient’s personal information and provide a rigorous treatment on his/her illness. Besides the “exact match”, we emphasize that we should add error-tolerance property in our EHR system to allow for a private key (derived from a measurement of a disease) to decrypt a PHR encrypted with a slightly different measurement of the same disease. This is because the symptom-based measurement for disease is noisy in both folds. On one side, we cannot always require that the same disease is expressed in an identical set of symptoms. For example the disease pneumonia appears in somebody in the symptoms of headache and dry cough, but for others it may present with whole body aches and having a fever. On the other side, an identical set of symptoms may be derived from different disease. For example, a simple symptom of cough could be the result of catching a cold, but it is also attributed to infecting pneumonia. Aiming at helping patient receive medical treatment as rigorous as possible, while preventing others not professional in disease accessing the PHRs, we use a threshold function shown below to measure whether a physician with ωcan access the PHR encrypted under ˆωor not (1 indicates access is allowed while 0 otherwise), where dis the fault tolerance allowed. γ(ˆω, ω) = {1|ω∩ˆω| ≥ d 0|ω∩ˆω|< d 4.3 System Description Based on the design specification elaborated above, we then provide our basic system in detail as follows. Note that in our system, we utilize the threshold ABE [34] shown in Fig. 2 as underlying primitive. System Setup.Suppose the attributes in universe Uare taken from Zq. Choose a security parameter λand run the procedure Setup(λ) of underlying ABE primitive to obtain the public key pk and the master secret key msk. The public key is then published, while the master key is kept by global authority as a secret. Physician Authorization.Assuming a new physician wants to join the EHR system, he/she needs to be issued a private key for later accessing patients’ PHRs. In concrete, the physician provides the authority with his/her qualification certificate for proving his/her specialized in a certain set of diseases. The global authority then computes a set of symptoms ωwhich he/she is able to professionally deal with. Finally the global authority runs KeyGen(ω, msk) and assigns the corresponding private key sk to this physician.
Title Suppressed Due to Excessive Length 15 KeyBlind(sk) : Upon receiving a private key sk = ({di0, di1}i∈ω) generated from the authority, physician picks t∈RZqand computes d′ i0=dt i0and d′ i1=dt i1for each i∈ω. Finally output f sk = ({d′ i0, d′ i1}i∈ω) and the redefined private key sk = ({di0, di1}i∈ω, t) Decryptout(f sk, ct) : Suppose that a ciphertext ct = (c0, c1,{ei}i∈ˆω) is encrypted under an attribute set ˆωand D-CSP is assigned with a blinded private key f sk for attribute set ω, which satisfies the restriction that γ(ˆω, ω) = 1. Then, D-CSP proceeds as follows. Firstly, an arbitrary d-element subset set S⊆ˆω∩ωis selected. Then, the partial decryption is computed as c′ 0=∏i∈Se(c1,d′ i0)∆i,S (0) ∏i∈Se(d′ i1,ei)∆i,S (0) =e(g1, g2)st. Finally D-CSP returns ct′= (c0, c′ 0). Decrypt(sk, ct′) : . Upon receiving the partially decrypted ciphertext ct′from D-CSP, physician computes c0/(c′ 0)1/t =m. Fig. 4 Algorithms for Reducing Computation for Physicians PHRsAccess.Instead of directly decrypting ciphertext by themselves, the physicians firstly forward the searched encrypted PHRs to D-CSP (for simplicity our description starts from receiving the results and we omit the workflow of search which is detailedly elaborated in the same stage shown in Section 5.1). The D-CSP reads the corresponding stored f sk for this physician and runs the outsourced decryption algorithm Decryptout shown in Fig. 4 for each forwarded ciphertext. After performing partial decryption, D-CSP then sends all the partially decrypted ciphertexts to the physician, which runs the local decryption algorithm Decrypt on each of them to obtain symmetric key. With these keys, physician finally does the symmetric decryption and get the plain PHRs. 6 Conclusion In this paper, aiming at allowing for efficient storing and sharing PHRs in today’s cloud computing, we design a secure cloud-based EHR system using ABE. Our system allows the patients to selectively share their PHRs with physicians by performing encryption under their current symptoms but without knowing the precise description of their illnesses or the departments of physicians needed in medical treatment. Furthermore, in order to fill the gap between theoretical proposal and practical application, we provide three extensions including adding searchability, supporting physician revocation functionality, allowing for efficient local decryption, on our basic EHR system. We believe our final system meets the practical requirements in today’s EHR service. Acknowledgement This work is supported by National Natural Science Foundation of China (Grant No.61100224, No.61272455), Guangdong Natural Science Foundation
16 Fatos Xhafa et al. (No.S2013010013671), Guangzhou Research Infrastructure Development Fund (No. 201222412), Guangzhou Zhujiang Science and Technology Future Fellow Fund (No. 2011J2200089), and the MOE-China Mobile Research Fund (No. MCM20121051). References 1. Armbrust, M., Fox, A., Griffith, R., Joseph, A.D.: A View of Cloud Computing. Communications of the . . . 53(4), 50–58 (2010) 2. Benaloh, J., Chase, M., Horvitz, E., Lauter, K.: Patient Controlled Encryption: Ensuring Privacy of Electronic Medical Records. In: CCSW ’09 Proceedings of the 2009 ACM workshop on Cloud computing security, pp. 103–114 (2009) 3. Bethencourt, J., Sahai, A., Waters, B.: Ciphertext-Policy Attribute-Based Encryption. In: SP ’07: Proceedings of the 2007 IEEE Symposium on Security and Privacy, pp. 321–334. IEEE Computer Society (2007) 4. Boneh, D., Di Crescenzo, G., Ostrovsky, R., Persiano, G.: Public Key Encryption with Keyword Search. In: Advances in Cryptology-Eurocrypt 2004, pp. 506–522. Springer (2004) 5. Chase, M.: Multi-Authority Attribute Based Encryption. Theory of Cryptography pp. 515–534 (2007) 6. Chase, M., Chow, S.: Improving Privacy and Security in Multi-Authority AttributeBased Encryption. In: CCS ’09 Proceedings of the 16th ACM conference on Computer and communications security, pp. 121–130 (2009) 7. Cheung, L., Newport, C.: Provably Secure Ciphertext Policy ABE. In: CCS ’07: Proceedings of the 14th ACM conference on Computer and communications security, pp. 456–465. ACM Request Permissions (2007) 8. Elger, B.S., Iavindrasana, J., Lo Iacono, L., M¨uller, H., Roduit, N., Summers, P., Wright, J.: Strategies for Health Data Exchange for Secondary, Cross-Institutional Clinical Research. Computer Methods and Programs in Biomedicine 99(3), 22–22 (2010) 9. Farzandipour, M.M., Sadoughi, F.F., Ahmadi, M.M., Karimi, I.I.: Security Requirements and Solutions in Electronic Health Records: Lessons Learned From a Comparative Study. Journal of Medical Systems 34(4), 629–642 (2010) 10. Fern´andez-Alem´an, J.L., Se˜nor, I.C., Lozoya, P. ´ A.O., Toval, A.: Security and Privacy in Electronic Health Records: a Systematic Literature Review. Journal of biomedical informatics 46(3), 541–562 (2013) 11. Goyal, V., Pandey, O., Sahai, A., Waters, B.: Attribute-Based Encryption for FineGrained Access Control of Encrypted Data. In: Proceedings of the 13th ACM conference on Computer and communications security, pp. 89–98. ACM (2006) 12. Green, M., Hohenberger, S., Waters, B.: Outsourcing the Decryption of ABE Ciphertexts. In: SEC’11: Proceedings of the 20th USENIX conference on Security, pp. 34–49. USENIX Association (2011) 13. Haas, S., Wohlgemuth, S., Echizen, I., Sonehara, N.: Aspects of Privacy for Electronic Health Records. international journal of Medical Informatics 80(2), e26–31 (2011) 14. Hu, Chen, Hou: A Hybrid Public Key Infrastructure Solution (HPKI) for HIPAA Privacy/Security Regulations. Computer Standards & Interfaces 32(5-6), 7–7 (2010) 15. Lee, W.B.W., Lee, C.D.C.: A Cryptographic Key Management Solution for HIPAA Privacy/Security Regulations. Information Technology in Biomedicine, IEEE Transactions on 12(1), 34–41 (2007) 16. Lewko, A., Okamoto, T., Sahai, A., Takashima, K., Waters, B.: Fully Secure Functional Encryption: Attribute-Based Encryption and (Hierarchical) Inner Product Encryption. In: EUROCRYPT’10: Proceedings of the 29th Annual international conference on Theory and Applications of Cryptographic Techniques, pp. 62–91. Springer-Verlag (2010) 17. Lewko, A., Waters, B.: New Techniques for Dual System Encryption and Fully Secure HIBE with Short Ciphertexts. Theory of Cryptography pp. 455–479 (2010)
Title Suppressed Due to Excessive Length 17 18. Lewko, A., Waters, B.: Decentralizing Attribute-Based Encryption. EUROCRYPT’11 Proceedings of the 30th Annual international conference on Theory and applications of cryptographic techniques: advances in cryptology pp. 568–588 (2011) 19. Lewko, A., Waters, B.: Unbounded HIBE and Attribute-Based Encryption. EUROCRYPT’11 Proceedings of the 30th Annual international conference on Theory and applications of cryptographic techniques: advances in cryptology pp. 547–567 (2011) 20. Lewko, A., Waters, B.: New Proof Methods for Attribute-Based Encryption: Achieving Full Security Through Selective Techniques. Advances in Cryptology–CRYPTO 2012 pp. 180–198 (2012) 21. Li, J., Chen, X., Li, J., Jia, C., Ma, J., Lou, W.: Fine-Grained Access Control System Based on Outsourced Attribute-Based Encryption. In: Computer Security–ESORICS 2013, pp. 592–609 (2013) 22. Li, J., Huang, X., Li, J., Chen, X., Xiang, Y.: Securely Outsourcing Attribute-based Encryption with Checkability. IEEE Transactions on Parallel and Distributed Systems p. http://doi.ieeecomputersociety.org/10.1109/TPDS.2013.271 (2013) 23. Li, J., Jia, C., Li, J., Chen, X.: Outsourcing Encryption of Attribute-Based Encryption with Mapreduce. ICICS’12: Proceedings of the 14th international conference on Information and Communications Security pp. 191–201 (2012) 24. Li, J., Li, J., Chen, X., Liu, Z., Jia, C.: Privacy-preserving data utilization in hybrid clouds. Future Generation Computer Systems (2013) 25. Li, J., Li, J., Liu, Z., Jia, C.: Enabling efficient and secure data sharing in cloud computing. Concurrency and Computation: Practice and Experience pp. n/a–n/a (2013) 26. Li, J., Wang, Q., Wang, C., Cao, N., Ren, K., Lou, W.: Enabling Efficient Fuzzy Keyword Search over Encrypted Data in Cloud Computing. IACR Cryptology ePrint Archive pp. 1–16 (2009) 27. Li, J., Wang, Q., Wang, C., Cao, N., Ren, K., Lou, W.: Fuzzy Keyword Search Over Encrypted Data in Cloud Computing. In: INFOCOM’10: Proceedings of the 29th conference on Information communications, pp. 1–5. IEEE Press (2010) 28. Li, M., Yu, S., Cao, N., Lou, W.: Authorized Private Keyword Search over Encrypted Data in Cloud Computing. In: ICDCS ’11: Proceedings of the 2011 31st International Conference on Distributed Computing Systems, pp. 383–392. IEEE Computer Society (2011) 29. Menachemi, N., Collum, T.H.: Benefits and Drawbacks of Electronic Health Record Systems. Risk management and healthcare (4), 47–55 (2011) 30. Narayan, S., Gagn´e, M., Safavi-Naini, R.: Privacy Preserving EHR System Using Attribute-Based Infrastructure. In: CCSW ’10 Proceedings of the 2010 ACM workshop on Cloud computing security workshop, pp. 47–52. ACM Request Permissions (2010) 31. Neubauer, T., Heurix, J.: A Methodology for the Pseudonymization of Medical Data. International Journal of Medical Informatics 80(3) (2011) 32. Riedl, B., Grascher, V., Neubauer, T.: Applying a Threshold Scheme to the Pseudonymization of Health Data. In: PRDC ’07: Proceedings of the 13th Pacific Rim International Symposium on Dependable Computing, pp. 397–400. IEEE Computer Society (2007) 33. Rodr´ıguez-Vera, F.J., Marin, Y., Sanchez, A., Borrachero, C.: Illegible Handwriting in Medical Records. Journal of the Royal Medical Records 95(11), 545–546 (2002) 34. Sahai, A., Waters, B.: Fuzzy Identity-Based Encryption. In: EUROCRYPT’05: Proceedings of the 24th annual international conference on Theory and Applications of Cryptographic Techniques, pp. 457–473. Springer-Verlag (2005) 35. Shamir, A.: How to Share a Secret. Communications of the ACM 22(11), 612–613 (1979) 36. Song, D.X., Wagner, D., Perrig, A.: Practical techniques for searches on encrypted data. In: Security and Privacy, 2000. S&P 2000. Proceedings. 2000 IEEE Symposium on, pp. 44–55 (2000) 37. Waters, B.: Ciphertext-Policy Attribute-Based Encryption: an Expressive, Efficient, and Provably Secure Realization. In: Public Key Cryptography–PKC 2011, pp. 53– 70. Springer (2011)
18 Fatos Xhafa et al. 38. Winslow, E.H.E., Nestor, V.A.V., Davidoff, S.K.S., Thompson, P.G.P., Borum, J.C.J.: Legibility and Completeness of Physicians’ Handwritten Medication Orders. Heart & Lung: The Journal of Acute and Critical Care 26(2), 158–164 (1997) 39. Yu, S., Wang, C., Ren, K., Lou, W.: Achieving Secure, Scalable, and Fine-Grained Data Access Control in Cloud Computing. In: 2010 Proceedings IEEE INFOCOM, pp. 1–9. IEEE (2010) 40. Zhang, R.Z.R., Liu, L.L.L.: Security Models and Requirements for Healthcare Application Clouds. 2010 IEEE 3rd International Conference on Cloud Computing (CLOUD) pp. 268–275 (2010) 41. Zhou, Z., Huang, D.: Efficient and Secure Data Storage Operations for Mobile Cloud Computing. In: 2012 8th International Conference on Network and Service Management (CNSM), pp. 37–45. IEEE (2012)