SDN-Based Security Enforcement Framework for Data Sharing Systems of Smart Healthcare

SDN-Based Security Enforcement Framework for Data Sharing Systems of Smart Healthcare
复制标题

基于SDN的智慧医疗数据共享系统安全执行框架

DOI:
10.1109/tnsm.2019.2941214
复制
发表时间:
2020-03-01
影响因子:
5.3
通讯作者:
Ke, Changbo
Ke, Changbo
中科院分区:
计算机科学2区
文献类型:
--
作者:
Meng, Yunfei;Huang, Zhiqiu;Ke, Changbo

文献摘要

被引文献

相似文献

作为新颖的医疗保健Paradiagm,智能医疗保健可以为患者提供更高效,高质量的医疗服务。但是,Smart Healthcare需要患者共享其生理信息以进行在线诊断,如果Smart Healthcare的数据共享系统缺乏有效的安全机制,则这些敏感信息可能会被非法或恶意用户滥用。此外,Smart Healthcare需要面对一些全新的挑战,例如资源约束的物联网,身份盗用攻击和内部攻击。为了解决这些问题,我们为SMART Healthcare的数据共享系统提出了一个基于SDN的安全执法框架。在我们的框架中,每个患者在数据共享系统中都有专用的虚拟机,每台虚拟机提供了一个组数据服务,可以向那些授权的服务消费者或物联网事物发布。在Additon中,虚拟机受到基于SDN的网关的保护,该网关提供了防火墙机制,并保证只有授权的东西可以访问患者的虚拟机。由于每件事都有一个独特的MAC地址,因此我们的框架可以有效地验证资源受到的物联网事物并解决由身份盗用引起的问题。为了验证我们的框架的有效性和可行性,我们使用POX控制器和Mininet Emulator实施了实验系统。实验结果说明了我们的框架在不同的测试方案下是有效的。随着信息流模型的扩大规模,该框架仍然可以很好地工作,并且其性能仍然可以接受。
As novel healthcare paradiagm, smart healthcare can provide more efficient and high quality medical services for patients. However, smart healthcare needs patients to share their physiological information for online diagnoses, if the data sharing system of smart healthcare lacks effective security mechanisms, these sensitive information might be abused by illegal or malicious users. Moreover, smart healthcare needs to confront some brand-new challenges, such as resource-constrained IoT things, identity theft attacks and insider attacks. To tackle these problems, we propose a SDN-based security enforcement framework for data sharing systems of smart healthcare. In our framework, each patient has a dedicated virtual machine in data sharing system, each virtual machine provides a group data services which can be released to those authorized service consumers or IoT things. In additon, virtual machine is protected by the SDN-based gateway which provides a firewall mechanism and guarantees only authorized things can access patient’s virtual machine. Since each thing has a unique MAC address, thus our framework can effectively authenticate resource-constrained IoT things and tackle the problems caused by identity theft. To validate the effectiveness and feasibility of our framework, we implement an experimental system using POX controller and Mininet emulator. The experimental results illustrate our framework is effective under different test scenarios. As increasing the scale of information flow model, the framework can still work well and its performance can be still acceptable.