Long-term verifiability of the electronic healthcare records’ authenticity
International Journal of Medical InformaticsPublished 21 October 2006
Dimitrios Lekkas, Dimitris Gritzalis
Citations38
SJR quartileQ1
SJR score1.19
SNIP1.55
Generate an AI Snapshot to get a quick, structured summary of this paper.
Study Snapshot
ObjectiveStudy objective
MethodsResearch methodology
PopulationPopulation studied
Sample sizeSample sizes
OutcomesStudy outcomes here
ResultsStudy results comes here
LimitationsResearch study limitations comes here
A concise AI-generated summary of the paper will appear here once you click Generate AI Snapshot.
TL;DR
The proposed mechanism implements a successive trust transition towards new entities, modern technologies, and refreshed data, eliminating any dependency of the relying party on ceased entities, obsolete data, or weak old technologies and exhibits strength against various threat scenarios.
Abstract
A future relying party will have to trust only the fresh technology and information provided by the last notary, in order to verify the authenticity of an old signed EHR. A Cumulatively Notarized Signature is strong even in the case of the compromise of a notary in the chain.
Keywords
Computer ScienceDecision Sciences
Communications of the ACMA method for obtaining digital signatures and public-key cryptosystems
13,142 Citations1983Ronald L. Rivest, Adi Shamir +1 more
Communications of the ACMA method for obtaining digital signatures and public-key cryptosystems
13,083 Citations1978Ronald L. Rivest, Adi Shamir +1 more
An encryption method is presented with the novel property that publicly revealing an encryption key does not thereby reveal the corresponding decryption key, soriers or other secure means are not needed to transmit keys.
Practical Cryptography
648 Citations2003Niels Ferguson, Bruce Schneier
Practical Cryptography is the first hands-on cryptographic product implementation guide, bridging the gap between cryptographic theory and real-world cryptographic applications.
International Journal of Medical InformaticsAuthorisation and access control for electronic health record systems
165 Citations2004Bernd Blobel
Based on the author's international engagement in EHR architecture and security standards referring to the revision of CEN ENV 13606, the GEHR/open EHR approach, HL7 and CORBA, models for health-specific and EHR-related roles, for authorisation management and access control have been developed.
International Journal of Medical InformaticsA security architecture for interconnecting health information systems
84 Citations2004Dimitris Gritzalis, Costas Lambrinoudakis
This paper presents a security architecture that has been mainly designed for providing authentication and authorization services in web-based distributed systems, based on a role-based access scheme and on the implementation of an intelligent security agent per site.
IEEE Transactions on Information Technology in BiomedicineTechnical Guidelines for Enhancing Privacy and Data Protection in Modern Electronic Medical Environments
51 Citations2005Stefanos Gritzalis, Costas Lambrinoudakis +2 more
Enabling the Archival Storage of Signed Documents
50 Citations2002Petros Maniatis, Mary Baker
KASTS combines time stamping of signed documents with storage of past signature verification keys and is argued that such an extended archival storage system is feasible and one possible design for it is described.
Computer CommunicationsEstablishing and managing trust within the public key infrastructure
39 Citations2003Dimitrios Lekkas
The capabilities afforded by the Public Key Infrastructure certainly facilitate the growth of secure internet-based transactions, but the provision of acceptable and effective certification services will only be achieved when an enhanced level of trust is established between the entities involved.
Computer CommunicationsTowards a framework for evaluating certificate status information mechanisms
33 Citations2003John Iliadis, Stefanos Gritzalis +4 more
A mechanism-neutral framework for the evaluation of certificate status information (CSI) mechanisms, which collect, process and distribute CSI, and a detailed demonstration of its exploitation is provided.
Lecture notes in computer scienceEfficient Long-Term Validation of Digital Signatures
25 Citations2001Arne Ansper, Ahto Buldas +2 more
This work presents a new scheme that is fast revocation while giving no extra power to on-line service providers; lightweight and scalable; and supply long-term validation.
First MondayA Metadata Approach to Preservation of Digital Resources: The University of North Texas Libraries' Experience
21 Citations2002Daniel Gelaw, Samantha Kelly Hastings +1 more
The role of preservation metadata in facilitating the preservation activities in general is demonstrated and the issues related to digital resources preservation are discussed.
Digital Signatures
20 Citations2002Mohan Atreya, Stephen Paine +3 more
Details on all key topics including public key cryptography, data integrity, public key infrastructures, message authentication standards, business drivers and business models, current worldwide legislation, and PKI documentation are found.
Decision Support SystemsRisking “trust” in a public key infrastructure: old techniques of managing risk applied to new technology
20 Citations2001Andrew D. Fernandes
A layman's overview of what exactly a PKI is, and how one can be built and operated safely and securely is given, and the principles of compromise–containment and regular auditing must be adhered to.
Computers & SecurityAchieving Interoperability in a Multiple-Security- Policies Environment
20 Citations2000Spyros Kokolakis, Evangelos Kiountouzis
It is argued that a policy repository may serve as the basic component of a software tool for the management of multiple security policies and the application of the Metapolicy Development System, which is implemented in Telos, an object-oriented knowledge representation language.
BT Technology JournalSecure Digital Archiving of High-Value Data
6 Citations2001Tim Wright
This paper describes how digital archiving uses PKI-based technologies, including timestamping, and XML structuring to provide controlled access, integrity and legally binding data.
Medical Informatics and the Internet in MedicineAn integrated architecture for deploying a virtual private medical network over the Web
6 Citations2001Dimitrios Gritzalis
A logical Public Key Infrastructure (PKI) architecture is proposed, which is robust, scalable, and based on standards, and can be integrated with existing TTP schemes and infrastructures offering transparency and adequate security.
