Abstract
Personal health record (PHR) was an emerging patient centric model in health information exchange, which was very often outsourced in stored at third party, such as cloud providers. However, there have been wide privacy concerns as personal health information will be exposed to those third parties servers and to unauthorized parties. To assure the patients' control over access to their own PHRs, it was promising method to encrypt the PHRs before outsourcing. The issues such as risks of data exposure, scalability of the key management, very flexibleaccess, and efficient user revocation, will be remain as the important challenge inorder to achieve fine-grained, cryptographically enforced data access control. In this paper, we proposed a novel patient-centric framework and a suite of mechanism for the data access control to PHRs will be stored the in semi-trusted servers. Inorder to get a fine-grained and scalable data access control for PHRs, the attribute-based encryption (ABE) technique inorder encrypt each patient's PHR file. Different from previous works in the secure data outsourcing, and we focus on the multiple data owner scenario, and divide the users in the PHR system into multiple security domains that will greatly reduce the key management complexity for owners and users. High degree of patient privacy is been guaranteed simultaneously by exploiting multiauthority Attribute Based Encryption .The scheme enables dynamic modification of access policies or file attributes, supports in efficient on-demand user/attribute revocation and break-glass access under the emergency scenario. Extensive analytical and experimental results were presented which shows the needs for security, scalability, and the efficiency of our proposed scheme.