A medical big data access control model based on smart contracts and risk in the blockchain environment

The rapid development of the Hospital Information System has significantly enhanced the convenience of medical research and the management of medical information. However, the internal misuse and privacy leakage of medical big data are critical issues that need to be addressed in the process of medi...

Full description

Bibliographic Details
Main Authors: Xuetao Pu, Rong Jiang, Zhiming Song, Zhihong Liang, Liang Yang
Format: Article
Language:English
Published: Frontiers Media S.A. 2024-03-01
Series:Frontiers in Public Health
Subjects:
Online Access:https://www.frontiersin.org/articles/10.3389/fpubh.2024.1358184/full
_version_ 1797238465991016448
author Xuetao Pu
Xuetao Pu
Rong Jiang
Rong Jiang
Zhiming Song
Zhiming Song
Zhihong Liang
Liang Yang
Liang Yang
author_facet Xuetao Pu
Xuetao Pu
Rong Jiang
Rong Jiang
Zhiming Song
Zhiming Song
Zhihong Liang
Liang Yang
Liang Yang
author_sort Xuetao Pu
collection DOAJ
description The rapid development of the Hospital Information System has significantly enhanced the convenience of medical research and the management of medical information. However, the internal misuse and privacy leakage of medical big data are critical issues that need to be addressed in the process of medical research and information management. Access control serves as a method to prevent data misuse and privacy leakage. Nevertheless, traditional access control methods, limited by their single usage scenario and susceptibility to single point failures, fail to adapt to the polymorphic, real-time, and sensitive characteristics of medical big data scenarios. This paper proposes a smart contracts and risk-based access control model (SCR-BAC). This model integrates smart contracts with traditional risk-based access control and deploys risk-based access control policies in the form of smart contracts into the blockchain, thereby ensuring the protection of medical data. The model categorizes risk into historical and current risk, quantifies the historical risk based on the time decay factor and the doctor’s historical behavior, and updates the doctor’s composite risk value in real time. The access control policy, based on the comprehensive risk, is deployed into the blockchain in the form of a smart contract. The distributed nature of the blockchain is utilized to automatically enforce access control, thereby resolving the issue of single point failures. Simulation experiments demonstrate that the access control model proposed in this paper effectively curbs the access behavior of malicious doctors to a certain extent and imposes a limiting effect on the internal abuse and privacy leakage of medical big data.
first_indexed 2024-04-24T17:36:05Z
format Article
id doaj.art-6b8eb8b99a0c48049212b569c0f13957
institution Directory Open Access Journal
issn 2296-2565
language English
last_indexed 2024-04-24T17:36:05Z
publishDate 2024-03-01
publisher Frontiers Media S.A.
record_format Article
series Frontiers in Public Health
spelling doaj.art-6b8eb8b99a0c48049212b569c0f139572024-03-28T04:50:03ZengFrontiers Media S.A.Frontiers in Public Health2296-25652024-03-011210.3389/fpubh.2024.13581841358184A medical big data access control model based on smart contracts and risk in the blockchain environmentXuetao Pu0Xuetao Pu1Rong Jiang2Rong Jiang3Zhiming Song4Zhiming Song5Zhihong Liang6Liang Yang7Liang Yang8Faculty of Information Engineering and Automation, Kunming University of Science and Technology, Kunming, ChinaYunnan Key Laboratory of Service Computing, Yunnan University of Finance and Economics, Kunming, ChinaYunnan Key Laboratory of Service Computing, Yunnan University of Finance and Economics, Kunming, ChinaInstitute of Intelligence Applications, Yunnan University of Finance and Economics, Kunming, ChinaYunnan Key Laboratory of Service Computing, Yunnan University of Finance and Economics, Kunming, ChinaInstitute of Intelligence Applications, Yunnan University of Finance and Economics, Kunming, ChinaInstitute of Big Data and Artificial Intelligence, Southwest Forestry University, Kunming, ChinaFaculty of Information Engineering and Automation, Kunming University of Science and Technology, Kunming, ChinaYunnan Key Laboratory of Service Computing, Yunnan University of Finance and Economics, Kunming, ChinaThe rapid development of the Hospital Information System has significantly enhanced the convenience of medical research and the management of medical information. However, the internal misuse and privacy leakage of medical big data are critical issues that need to be addressed in the process of medical research and information management. Access control serves as a method to prevent data misuse and privacy leakage. Nevertheless, traditional access control methods, limited by their single usage scenario and susceptibility to single point failures, fail to adapt to the polymorphic, real-time, and sensitive characteristics of medical big data scenarios. This paper proposes a smart contracts and risk-based access control model (SCR-BAC). This model integrates smart contracts with traditional risk-based access control and deploys risk-based access control policies in the form of smart contracts into the blockchain, thereby ensuring the protection of medical data. The model categorizes risk into historical and current risk, quantifies the historical risk based on the time decay factor and the doctor’s historical behavior, and updates the doctor’s composite risk value in real time. The access control policy, based on the comprehensive risk, is deployed into the blockchain in the form of a smart contract. The distributed nature of the blockchain is utilized to automatically enforce access control, thereby resolving the issue of single point failures. Simulation experiments demonstrate that the access control model proposed in this paper effectively curbs the access behavior of malicious doctors to a certain extent and imposes a limiting effect on the internal abuse and privacy leakage of medical big data.https://www.frontiersin.org/articles/10.3389/fpubh.2024.1358184/fullmedical big dataaccess controlsmart contractsriskblockchain
spellingShingle Xuetao Pu
Xuetao Pu
Rong Jiang
Rong Jiang
Zhiming Song
Zhiming Song
Zhihong Liang
Liang Yang
Liang Yang
A medical big data access control model based on smart contracts and risk in the blockchain environment
Frontiers in Public Health
medical big data
access control
smart contracts
risk
blockchain
title A medical big data access control model based on smart contracts and risk in the blockchain environment
title_full A medical big data access control model based on smart contracts and risk in the blockchain environment
title_fullStr A medical big data access control model based on smart contracts and risk in the blockchain environment
title_full_unstemmed A medical big data access control model based on smart contracts and risk in the blockchain environment
title_short A medical big data access control model based on smart contracts and risk in the blockchain environment
title_sort medical big data access control model based on smart contracts and risk in the blockchain environment
topic medical big data
access control
smart contracts
risk
blockchain
url https://www.frontiersin.org/articles/10.3389/fpubh.2024.1358184/full
work_keys_str_mv AT xuetaopu amedicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT xuetaopu amedicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT rongjiang amedicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT rongjiang amedicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT zhimingsong amedicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT zhimingsong amedicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT zhihongliang amedicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT liangyang amedicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT liangyang amedicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT xuetaopu medicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT xuetaopu medicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT rongjiang medicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT rongjiang medicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT zhimingsong medicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT zhimingsong medicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT zhihongliang medicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT liangyang medicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment
AT liangyang medicalbigdataaccesscontrolmodelbasedonsmartcontractsandriskintheblockchainenvironment