Abstract

In the traditional electronic health record (EHR) management system, each medical service center manages their own health records, respectively, which are difficult to share on the different medical platforms. Recently, blockchain technology is one of the popular alternatives to enable medical service centers based on different platforms to share EHRs. However, it is hard to store whole EHR data in blockchain because of the size and the price of blockchain. To resolve this problem, cloud computing is considered as a promising solution. Cloud computing offers advantageous properties such as storage availability and scalability. Unfortunately, the EHR system with cloud computing can be vulnerable to various attacks because the sensitive data is sent over a public channel. We propose the secure protocol for cloud-assisted EHR system using blockchain. In the proposed scheme, blockchain technology is used to provide data integrity and access control using log transactions and the cloud server stores and manages the patient’s EHRs to provide secure storage resources. We use an elliptic curve cryptosystems (ECC) to provide secure health data sharing with cloud computing. We demonstrate that the proposed EHR system can prevent various attacks by using informal security analysis and automated validation of internet security protocols and applications (AVISPA) simulation. Furthermore, we prove that the proposed EHR system provides secure mutual authentication using BAN logic analysis. We then compare the computation overhead, communication overhead, and security properties with existing schemes. Consequently, the proposed EHR system is suitable for the practical healthcare system considering security and efficiency.

Highlights

  • As patient healthcare records have been developed from traditional paper management to electronic record management, they can be safely stored and accessed and authorized only by legitimate medical centers [1]

  • We proposed the secure protocol for cloud-assisted electronic health record (EHR) system using blockchain to resolve these problems

  • We proved that the proposed scheme prevents various attacks and provides secure mutual authentication, anonymity, and perfect forward secrecy

Read more

Summary

Introduction

As patient healthcare records have been developed from traditional paper management to electronic record management, they can be safely stored and accessed and authorized only by legitimate medical centers [1]. The cloud-based EHR system can be vulnerable to potential attacks because the sensitive data is sent over a public channel To resolve these security problems, the cloud-based EHR systems require a secure and efficient protocol. E-health record system using blockchain to provide integrity and decentralization for the EHR sharing and health diagnosis These cloud-assisted EHR systems using blockchain [17,18] do not address a secure protocol for registration, authentication, transaction uploading, and so on. We propose the secure protocol for cloud-assisted EHR system using blockchain to guarantee security, integrity, and decentralization for EHR sharing and health diagnosis. In the proposed EHR system, blockchain technology is used to efficiently provide data integrity and access control using log transactions. The proposed EHR system provides secure health data sharing in a public channel using ECC

Research Contributions
Organization
Related Works
Adversary Model
Hyperledger Fabric
Cloud-Assisted EHR System Model Using Blockchain
Proposed Protocol for Cloud-Assisted EHR System Using Blockchain
Patient Registration Phase
Medical Center Registration Phase
Authentication Phase
Smart Contract Uploading Phase
EHR Storing Phase
EHR Requesting Phase
Log Transaction Uploading Phase
Security Analysis
Impersonation Attack
Session Key Disclosure Attack
Perfect Forward Secrecy
Replay Attack
Privileged Insider Attack
Mutual Authentication
BAN Logic Analysis
Proof Using BAN Logic
AVISPA Analysis
Computation Cost
Communication Cost
Security Properties
Conclusions

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.