Access Grant and Revocation of Electronic Health Records using CP-ABE Dynamic Policy Updation
Shardha Porwal, Sangeeta Mittal · 2023
Electronic Health Records (EHRs) are the digitized form of a patient's health related information and reports in the repository of a healthcare provider. Among the numerous advantages of EHRs, the main disrupting one is real time sharing of health history in case of an emergency when a person has to be admitted to another healthcare provider. Sharing is a complex process, as the security, access control and integrity of the health data needs to be ensured. In this paper, a scheme has been designed to transfer temporary access to the emergency healthcare organization and revoke it after the treatment is over. Authenticated access grant and revocation is designed using Ciphertext Policy - Attribute Based Encryption (CP-ABE) and data encryption has been done using state-of-art symmetric encryption. Evaluation of the scheme shows that it does not incur much computational time overhead with an increasing number of attributes in the access policy. The scheme supports one to many encryption and dynamic policy updation to provide access of EHRs to external entities in real time. Forward secrecy is maintained without any redistribution of keys after revocation.