Blockchain Enabled Self-Sovereign Identity and Consent Framework for Secure Healthcare Data Access
Abstract
The medical systems are becoming challenged by the issues associated with the secure verification of patient identities, privacy-protecting access control, and dynamic consent management of Electronic Health Records (EHRs). Conventional centralized designs infringe on patient-centered autonomy, have poor identity management, and put sensitive information at the risk of inaccessible information. The paper introduces a proposal to develop a decentralized and privacy preserving mechanism of access control using blockchain-enabled Self-Sovereign Identity (SSI), as proposing a combination of verifiable credentials (VCs), smart contracts, and zero-knowledge proofs (ZKPs). The proposed Consent-Driven Decentralized Identity Verification Algorithm (CD-DIVA) enables the patient to create decentralised identities, issue tokens of consent, and dynamically assign or remove access rights without having to involve third-party authorities. Smart contracts enable the conjurant enforcement of various consent terms and offer an inauditable audit trail and ZKPs grant healthcare providers with the ability to demonstrate their authority without revealing sensitive information. Experimental assessments show the framework to be efficient in minimizing the access latency, eliminating unauthorized disclosures and providing effective interoperability of heterogeneous healthcare systems. This contribution will be a complement to the current blockchain-based healthcare solutions since it helps adopt a patient-centric, tamper-proof, and privacy-preserving healthcare ecosystem by bridging the access control and trust gap in such systems.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.