Healthcare blockchains provide an innovative way to store healthcare information, execute healthcare transactions, and build trust for healthcare data sharing and data integration in a decentralized open healthcare network environment. Although the healthcare blockchain technology has attracted broad interests and attention in industry, government and academia, the security and privacy concerns remain the focus of debate when deploying blockchains for information sharing in the healthcare sector from business operation to research collaboration. This paper focuses on the security and privacy requirements for medical data sharing using blockchain, and provides a comprehensive analysis of the security and privacy risks and requirements, accompanied by technical solution techniques and strategies. First, we discuss the security and privacy requirements and attributes required for electronic medical data sharing by deploying the healthcare blockchain. Second, we categorize existing efforts into three reference blockchain usage scenarios for electronic medical data sharing, and discuss the technologies for implementing these security and privacy properties in the three categories of usage scenarios for healthcare blockchain, such as anonymous signatures, attribute-based encryption, zero-knowledge proofs, verification techniques for smart contract security. Finally, we discuss other potential blockchain application scenarios in healthcare sector. We conjecture that this survey will help healthcare professionals, decision makers, and healthcare service developers to gain technical and intuitive insights into the security and privacy of healthcare blockchains in terms of concepts, risks, requirements, development and deployment technologies and systems.
翻译:保健链链提供了储存保健信息、执行保健交易和在分散的开放保健网环境中建立保健数据共享和数据整合信任的创新方式。虽然保健链链技术吸引了工业、政府和学术界的广泛兴趣和关注,但安全和隐私问题仍然是在部署保健部门从商业运作到研究协作的信息共享链时辩论的重点。本文件侧重于利用安全链共享医疗数据的安全和隐私要求,并在技术解决方案技术和战略的配合下,全面分析安全和隐私风险和要求。首先,我们讨论通过部署保健链分享电子医疗数据所需的安全和隐私要求和属性。第二,我们将现有努力分为电子医疗数据共享的三种参考链使用情景,并讨论在保健链的三类使用情景中落实这些安全和隐私特性的技术,例如匿名签名、基于属性的加密、零知识证据、智能合同安全保障的核查技术。我们预测,这项调查将有助于保健专业人员、决策者、安全链使用概念和医疗保健服务开发的供应链要求,以及安全系统、安全配置技术风险的发展。我们预计,这一调查将帮助保健系统专业工作者、决策者、保密概念和医疗保健服务开发的供应链要求和供应链风险。