{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,30]],"date-time":"2025-04-30T04:24:57Z","timestamp":1745987097979,"version":"3.40.4"},"reference-count":48,"publisher":"Wiley","issue":"3","license":[{"start":{"date-parts":[[2013,3,22]],"date-time":"2013-03-22T00:00:00Z","timestamp":1363910400000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/onlinelibrary.wiley.com\/termsAndConditions#vor"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Security Comm Networks"],"published-print":{"date-parts":[[2014,3]]},"abstract":"<jats:title>ABSTRACT<\/jats:title><jats:p>eHealth is being rapidly deployed. Lower cost and greater productivity attract government and healthcare enterprise to transit from traditional healthcare service to eHealth service. Security and privacy are growing concerns with the widespread deployment of eHealth and the development of next generation of eHealth services. In this paper, we discuss these security problems and propose a high\u2010level security framework that captures required features in the next\u2010generation eHealth infrastructure. Our framework consists of the following: (i) an adaptive trust\u2010aware tag\u2010based privacy control to specify which data to share and whom to share with. The fine\u2010grained control of data access is guaranteed; (ii) a decentralized authorization that relies on trust propagation protocol to provide robust and resilient access control enforcement; and (iii) a hybrid trust management mechanism that addresses access control information depository on a cloud server. It enforces user\u2010defined access control not only in a distributed environment but also in a privacy\u2010preserving manner so as to minimize the disclosure of privileges and of access policies. Copyright \u00a9 2013 John Wiley &amp; Sons, Ltd.<\/jats:p>","DOI":"10.1002\/sec.759","type":"journal-article","created":{"date-parts":[[2013,3,23]],"date-time":"2013-03-23T08:51:34Z","timestamp":1364028694000},"page":"574-587","source":"Crossref","is-referenced-by-count":4,"title":["Access control for cloud\u2010based eHealth social networking: design and evaluation"],"prefix":"10.1002","volume":"7","author":[{"given":"Yan","family":"Bai","sequence":"first","affiliation":[{"name":"Institute of Technology University of Washington Tacoma Tacoma WA 98402 U.S.A."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lirong","family":"Dai","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Software Engineering Seattle University Seattle WA 98122 U.S.A."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sam","family":"Chung","sequence":"additional","affiliation":[{"name":"Institute of Technology University of Washington Tacoma Tacoma WA 98402 U.S.A."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Durga D.","family":"Devaraj","sequence":"additional","affiliation":[{"name":"Institute of Technology University of Washington Tacoma Tacoma WA 98402 U.S.A."}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"311","published-online":{"date-parts":[[2013,3,22]]},"reference":[{"volume-title":"eHealth in the Era of Web 2.0, Virtually Informed: The Internet as (New) Health Information Source (Virinfo 2008)","year":"2008","author":"Witteman H","key":"e_1_2_8_2_1"},{"key":"e_1_2_8_3_1","doi-asserted-by":"publisher","DOI":"10.2196\/jmir.1510"},{"key":"e_1_2_8_4_1","doi-asserted-by":"crossref","unstructured":"LinJandet al.Fine\u2010grained data access control systems with user accountability in cloud computing inthe Proceedings of 2010 IEEE Second International Conference on Cloud Computing Technology and Science(CloudCom) Nov\/Dec2010 Indianapolis USA pp. 89\u201396.","DOI":"10.1109\/CloudCom.2010.44"},{"key":"e_1_2_8_5_1","doi-asserted-by":"publisher","DOI":"10.2196\/jmir.1056"},{"key":"e_1_2_8_6_1","first-page":"145","volume-title":"Springer\u2010Verlag Lecture Notes in Computer Science","author":"Hu L","year":"2009"},{"key":"e_1_2_8_7_1","unstructured":"HansenF OleshchukV.Application of role\u2010based access control in wireless healthcare information systems inthe Proceedings of Scandinavian Conference in Health Informatics 2003 Arendal Norway June2003 pp. 30\u201333."},{"key":"e_1_2_8_8_1","doi-asserted-by":"crossref","unstructured":"WilikensM FeritiS SannaA MaseraM.A context\u2010related authorization and access control method based on RBAC: a case study from the health care domain inthe Proceedings of the seventh ACM symposium on Access control models and technologies June2002 Monterrey California USA pp. 117\u2013124.","DOI":"10.1145\/507711.507730"},{"key":"e_1_2_8_9_1","first-page":"211","volume-title":"A Spatial\u2010temporal Role\u2010based Access Control Model","author":"Ray I","year":"2007"},{"key":"e_1_2_8_10_1","doi-asserted-by":"crossref","unstructured":"BoonyarattaphanA BaiY ChungS PoovendranR.Spatial\u2010temporal access control for e\u2010Health services inthe Proceedings of the 5th IEEE International Conference on Networking Architecture and Storage(NAS 2010) Macau China July2010 pp. 269\u2013276.","DOI":"10.1109\/NAS.2010.38"},{"volume-title":"The First Workshop on Pervasive Security, Privacy and Trust","year":"2004","author":"Hu J","key":"e_1_2_8_11_1"},{"key":"e_1_2_8_12_1","unstructured":"KumarM NewmanR.STRBAC \u2010 an approach towards spatio\u2010temporal role\u2010based access control in the Proceedings ofthe 3rd IASTED International Conference on Communication Network and Information Security(CNIS) Cambridge USA October2006 pp. 150\u2013155."},{"key":"e_1_2_8_13_1","doi-asserted-by":"crossref","unstructured":"NarayananHAJ GunesMH.Ensuring access control in cloud provisioned healthcare systems inthe ProceedingsofIEEE 2011 Consumer Communications and Networking Conference(CCNC) Las Vegas NV USA Jan.2011 pp. 247\u2013251.","DOI":"10.1109\/CCNC.2011.5766466"},{"issue":"2","key":"e_1_2_8_14_1","first-page":"10","article-title":"HCRBAC \u2013 an access control system for collaborative context\u2010aware healthcare services in mauritius","volume":"2","author":"Moonian O","year":"2008","journal-title":"Journal of Health Informatics in Developing Countries"},{"key":"e_1_2_8_15_1","doi-asserted-by":"crossref","unstructured":"AjayiO SinnottR StellA.Dynamic trust negotiation for flexible e\u2010health collaborations inthe Proceedings of the 15th Mardi Gras Conference Baton Rouge USA February2008.","DOI":"10.1145\/1341811.1341821"},{"key":"e_1_2_8_16_1","doi-asserted-by":"crossref","unstructured":"ChakrabortyS RayI.TrustBAC: integrating trust relationships into the RBAC model for access control in open systems inthe Proceedings of the 11th ACM Symposium on Access Control Models and Technologies June2006 Lake Tahoe CA USA pp.49\u201358.","DOI":"10.1145\/1133058.1133067"},{"key":"e_1_2_8_17_1","unstructured":"TranH HitchensM VaradharajanV WattersP.A trust based access control framework for P2P file\u2010sharing systems inthe Proceedings of the 38th Hawaii International Conference on System Sciences Hawaii USA January2005."},{"key":"e_1_2_8_18_1","doi-asserted-by":"crossref","unstructured":"GuptaR SomaniAK.Reputation management framework and its use as currency in large\u2010scale peer\u2010to\u2010peer networks inthe Proceedings of the 4th International Conference on Peer to Peer Computing Washington DC USA pp.124\u2013132.","DOI":"10.1109\/PTP.2004.1334939"},{"key":"e_1_2_8_19_1","doi-asserted-by":"crossref","unstructured":"ChenY LiuY.Research the access control strategy on p2p based on interest classify trust and security grade inthe Proceedings of 2010 Second International Conference on Networks Security Wireless Communications and Trusted Computing(NSWCTC) Wuhan China April2010 pp.450\u2013453.","DOI":"10.1109\/NSWCTC.2010.112"},{"key":"e_1_2_8_20_1","unstructured":"GohE ShachamH ModaduguN BonehD.SiRiUS: securing remote untrusted storage inthe Proceedings of the10th Annual Network and Distributed System Security Symposium(NDSS) San Diego USA Feb.2003 pp.131\u2013145."},{"key":"e_1_2_8_21_1","unstructured":"KallahallaMandet al.Plutus: scalable secure file sharing on untrusted storage inthe Proceedings of the 2nd Conference on File and Storage Technologies Berkeley USA March2003 pp.29\u201342."},{"key":"e_1_2_8_22_1","doi-asserted-by":"crossref","unstructured":"GuptaAandet al.A selective encryption approach to fine\u2010grained access control for P2P file sharing inthe Proceedings of the 6th International Conference on Collaborative Computing:Networking Applications and Worksharing Chicago USA October2010 pp.1\u201310.","DOI":"10.4108\/icst.collaboratecom.2010.4"},{"key":"e_1_2_8_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1183463.1183470"},{"key":"e_1_2_8_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-11282-9_25"},{"key":"e_1_2_8_25_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2005.05.019"},{"key":"e_1_2_8_26_1","doi-asserted-by":"crossref","unstructured":"JawadMandet al.A data privacy service for structured P2P systems Mexican International Conference in Computer Science Mexico City Mexico September2009.","DOI":"10.1109\/ENC.2009.32"},{"key":"e_1_2_8_27_1","doi-asserted-by":"crossref","unstructured":"BonifatiA WangW LiuR.SPac: a distributed peer\u2010to\u2010peer secure and privacy\u2010aware social space inthe Proceedings of the 19th International Conference on Information and Knowledge Management Toronto Canada October2010 pp. 1953\u20131954.","DOI":"10.1145\/1871437.1871781"},{"key":"e_1_2_8_28_1","doi-asserted-by":"crossref","unstructured":"SquicciariniA ShehabM PaciF.Collective privacy management in social networks inthe Proceedings of the 18th international conference on World Wide Web Madrid Spain April2009 pp. 521\u2013530.","DOI":"10.1145\/1526709.1526780"},{"key":"e_1_2_8_29_1","doi-asserted-by":"crossref","unstructured":"Al\u2010HamdaniW.Cryptography based access control in healthcare web systems inthe Proceedings of 2010 Information Security Curriculum Development Conference Kennesaw GA USA October2010 pp. 66\u201379.","DOI":"10.1145\/1940941.1940960"},{"key":"e_1_2_8_30_1","doi-asserted-by":"crossref","unstructured":"YoonJP ChenZ.Using privilege chain for access control and trustiness of resources in cloud computing inthe Proceedings of the Second International Conference on Networked Digital Technologies Prague Czech Republic July 2010 pp. 358\u2013368.","DOI":"10.1007\/978-3-642-14292-5_37"},{"key":"e_1_2_8_31_1","doi-asserted-by":"crossref","unstructured":"ChenY LuoJ NiX.A fuzzy trust evaluation based access control in grid environment inthe Proceedings of the Third ChinaGrid Annual Conference Dunhuang Gansu China August2008 pp.190\u2013196.","DOI":"10.1109\/ChinaGrid.2008.35"},{"key":"e_1_2_8_32_1","doi-asserted-by":"crossref","unstructured":"LevyK SargentB BaiY.A trust\u2010aware tag\u2010based privacy control for eHealth 2.0 inthe Proceedings of the 12th Annual Conference on Information Technology Education(SIGITE 2011) West Point USA October2011 pp.251\u2013256.","DOI":"10.1145\/2047594.2047659"},{"key":"e_1_2_8_33_1","doi-asserted-by":"crossref","unstructured":"KrishnamurthyB WillsCE.Characterizing privacy in online social networks inthe Proceedings of the First Workshop on Online Social Networks Seattle USA August2008 pp. 37\u201342.","DOI":"10.1145\/1397735.1397744"},{"key":"e_1_2_8_34_1","doi-asserted-by":"crossref","unstructured":"YoungAL Quan\u2010HaaseA.Information revelation and internet privacy concerns on social network sites: a case study of Facebook inthe Proceedings of the Fourth International Conference on Communities and Technologies University Park PA USA June2009 pp. 265\u2013274.","DOI":"10.1145\/1556460.1556499"},{"key":"e_1_2_8_35_1","doi-asserted-by":"crossref","unstructured":"AndersonJ DiazC BonneauJ StajanoF.Privacy\u2010enabling social networking over untrusted networks in theProceedings of the Second ACM Workshop on Online Social Networks Barcelona Spain August2009 pp. 1\u20136.","DOI":"10.1145\/1592665.1592667"},{"key":"e_1_2_8_36_1","unstructured":"BeatoF KohlweissM WoutersK.Enforcing access control in social network sites inthe Proceedings of Hot Topics in Privacy Enhancing Technologies Seattle USA August2009 pp. 1\u201310."},{"key":"e_1_2_8_37_1","doi-asserted-by":"crossref","unstructured":"JahidS MittalP BorisovN.EASiER: encryption\u2010based access control in social networks with efficient revocation inthe Proceedings of the 6th ACM Symposium on Information Computer and Communications Security(ASIACCS 2011) Hong Kong China March2011 pp.411\u2013415.","DOI":"10.1145\/1966913.1966970"},{"key":"e_1_2_8_38_1","doi-asserted-by":"crossref","unstructured":"BenalohJ ChaseM HorvitzE LauterK.Patient controlled encryption: ensuring privacy of electronic medical records inthe Proceedings of the 2009 ACM Workshop on Cloud Computing Security Chicago Illinois USA November2009 pp.103\u2013114.","DOI":"10.1145\/1655008.1655024"},{"key":"e_1_2_8_39_1","doi-asserted-by":"crossref","unstructured":"HartM CastilleC JohnsonR StentA.Usable privacy controls for blogs inthe Proceedings of the 2009 International Conference on Computational Science and Engineering Wuhan China December2009 pp.401\u2013408.","DOI":"10.1109\/CSE.2009.425"},{"key":"e_1_2_8_40_1","doi-asserted-by":"crossref","unstructured":"ZhuY HuyH AhnyGail\u2010Joon HuangyD WangS.Towards temporal access control in cloud computing inthe Proceedings of IEEE INFOCOM\u201912 Orlando USA March2012 pp. 2576\u20132580.","DOI":"10.1109\/INFCOM.2012.6195656"},{"key":"e_1_2_8_41_1","doi-asserted-by":"crossref","unstructured":"LuoS LiuF RenC.A hierarchy attribute\u2010based access control model for cloud storage inthe Proceedings of 2011 International Conference on Machine Learning and Cybernetics Beijing China July2011 pp.1146\u20131150.","DOI":"10.1109\/ICMLC.2011.6016897"},{"key":"e_1_2_8_42_1","doi-asserted-by":"crossref","unstructured":"RujS NayakA StojmenovicI.DACC: distributed access control in clouds inthe Proceedings of 2011 IEEE 10th International Conference on Security and Privacy in Computing and Communications(TrustCom) Changsha China November2011 pp.91\u201398.","DOI":"10.1109\/TrustCom.2011.15"},{"key":"e_1_2_8_43_1","first-page":"146","article-title":"Secure role based data access control in cloud computing","author":"Preiya VS","year":"2011","journal-title":"International Journal of Computer Trends and Technology"},{"key":"e_1_2_8_44_1","doi-asserted-by":"crossref","unstructured":"YuS WangC RenK LouW.Achieving secure scalable and fine\u2010grained data access control in cloud computing inthe Proceedings of IEEE INFOCOM\u201910 San Diego USA March2010 pp.534\u2013542.","DOI":"10.1109\/INFCOM.2010.5462174"},{"issue":"03","key":"e_1_2_8_45_1","first-page":"1152","article-title":"Capability\u2010based cryptographic data access control in cloud computing","volume":"03","author":"Hota C","year":"2011","journal-title":"International Journal of Advanced Networking and Applications"},{"key":"e_1_2_8_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2011.153"},{"issue":"2","key":"e_1_2_8_47_1","first-page":"176","article-title":"Rapid access control on Ubuntu cloud computing with facial recognition and fingerprint identification","volume":"3","author":"Chang BR","year":"2012","journal-title":"Journal of Information Hiding and Multimedia Signal Processing"},{"key":"e_1_2_8_48_1","doi-asserted-by":"crossref","unstructured":"DiepNN HungLX ZhungY LeeS LeeY\u2010K andLeeH.Enforcing access control using risk assessment inthe Proceedings of the Fourth European Conference on Universal Multiservice Networks Toulouse France February2007 pp.419\u2013424.","DOI":"10.1109\/ECUMN.2007.19"},{"key":"e_1_2_8_49_1","doi-asserted-by":"crossref","unstructured":"SunL WangR YongJ WuG.Semantic access control for cloud computing based on e\u2010Healthcare inthe Proceedings of the 2012 IEEE 16th International Conference on Computer Supported Cooperative Work in Design May2012 Wuhan China pp.512\u2013518.","DOI":"10.1109\/CSCWD.2012.6221866"}],"container-title":["Security and Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.wiley.com\/onlinelibrary\/tdm\/v1\/articles\/10.1002%2Fsec.759","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.wiley.com\/onlinelibrary\/tdm\/v1\/articles\/10.1002%2Fsec.759","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/pdf\/10.1002\/sec.759","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,30]],"date-time":"2025-04-30T01:44:23Z","timestamp":1745977463000},"score":1,"resource":{"primary":{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/10.1002\/sec.759"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,3,22]]},"references-count":48,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2014,3]]}},"alternative-id":["10.1002\/sec.759"],"URL":"https:\/\/doi.org\/10.1002\/sec.759","archive":["Portico"],"relation":{},"ISSN":["1939-0114","1939-0122"],"issn-type":[{"type":"print","value":"1939-0114"},{"type":"electronic","value":"1939-0122"}],"subject":[],"published":{"date-parts":[[2013,3,22]]}}}