Secure and Trusted Paradigm for Interoperable eHealth Services

Slides:



Advertisements
Similar presentations
HOlistic Platform Design for Smart Buildings
Advertisements

S.O.S. eHealth Project Open eHealth initiative for a European large scale pilot of patient summary and electronic prescription Daniel Forslund, Head of.
Conclusions from e-Health
Supporting National e-Health Roadmaps WHO-ITU-WB joint effort WSIS C7 e-Health Facilitation Meeting 13 th May 2010 Hani Eskandar ICT Applications, ITU.
eHealth Actions at European level
Policy recommendations for wider implementation of telemedicine Peeter Ross, MD, PhD e-Health expert, Estonian eHealth Foundation, Estonia.
Security Controls – What Works
2-Jun-15 1 ACCESSING ON LINE SERVICES PROTECTED BY THE ITALIAN EID GIOVANNI MANCA National Center for Information technology in Public Administration (CNIPA)
Emerging Research Dimensions in IT Security Dr. Salar H. Naqvi Senior Member IEEE Research Fellow, CoreGRID Network of Excellence European.
The Digital Agenda for Europe Interoperability and Standards
SEC835 Database and Web application security Information Security Architecture.
AER Network Meeting Cross-border Challenges and Opportunities Regions’ updates on latest developments in e-health Regione Lombardia 14/09/20151Trieste,
How can I trust the rest of Europe ? Requirements and a possible organisation with regard to epSOS and eHealth Frank Robben General manager eHealth platform.
Secure Management of Information across multiple Stakeholders SEMIRAMIS – CIP-ICT PSP SEMIRAMIS General Presentation.
How Hospitals Protect Your Health Information. Your Health Information Privacy Rights You can ask to see or get a copy of your medical record and other.
State Alliance for e-Health Conference Meeting January 26, 2007.
TripCom: Development of a patient summary at European level E. Della Valle, D. Cerizza, D. Foxvog, R. Krummenacher, L. J. B. Nixon, E.
EHealth/mHealth Gisele Roesems Deputy Head of Unit Health and Well-Being DG CONNECT EUROPEAN COMMISSION 2 nd International Conference on Health Informatics.
RIDE ConsortiumRIDE Workshop, December 8, 2006, Brussels 1 The RIDE Roadmap Methodology and the Current Progress Prof. Dr. Asuman Dogac, Turkey Dr. Jos.
Results of the HPC in Europe Taskforce (HET) e-IRG Workshop Kimmo Koski CSC – The Finnish IT Center for Science April 19 th, 2007.
Current challenges for health systems Increasing elderly population –Relative decrease in resources (fewer taxpayers), chronic patients Financial sustainability.
The research leading to these results has received funding from the European Community's Seventh Framework Programme (FP7/ ) under grant agreement.
PAPER PRESENTATION ON NETWORK SECURITY ISSUES BY M.D SAMEER YASMEEN SULTHANA.
EHealth Interoperability – EU Commission activities Dr Octavian Purcarea Unit H1 – ICT for Health Directorate ICT for citizens and businesses DG INFSO.
Catawba County Board of Commissioners Retreat June 11, 2007 It is a great time to be an innovator 2007 Technology Strategic Plan *
ECOGEM Cooperative Advanced Driver Assistance System for Green Cars Burak ONUR Project Coordinator R&D Support Executive
Challenge 6: Mobility, Environmental sustainability and energy efficiency Includes as driving objective: “Sustainable growth and environmental sustainability”
Improving Healthcare with PCP A Galician public health system (SERGAS) Initiative Javier Quiles del Río Program Manager of Innova Saúde and Hospital 2050.
Topic 3A SEMANTIC INTEROPERABILITY: REUSE OF EHR DATA Mats Sundgren.
STREP Research Project HOBNET (FP7- ICT , ) HOlistic Platform Design for Smart Buildings of the Future InterNET (
NCP Info DAY, Brussels, 23 June 2010 NCP Information Day: ICT WP Call 7 - Objective 1.3 Internet-connected Objects Alain Jaume, Deputy Head of Unit.
Creating a European entity Management Architecture for eGovernment Id GUIDE Keiron Salt
19-20 October 2010 IT Directors’ Group meeting 1 Item 6 of the agenda ISA programme Pascal JACQUES Unit B2 - Methodology/Research Local Informatics Security.
© 2014 By Katherine Downing, MA, RHIA, CHPS, PMP.
EID and eSignature programs at National level in Europe Detlef Houdeau Nov 2013 Exploratory seminar on e-signatures for e- business in the South Mediterranean.
E-SENS Electronic Simple European Networked Services e-Health in e-SENS Patient Summary and ePrescription 2nd Year Review, 24th June 2015.
The Future Digital Identity Landscape in Europe Timothée Mangenot, chairman 14th of December, 2015 ACSIEL partners day.
CMSC 818J: Privacy enhancing technologies Lecture 2.
Eric Peirano, Ph.D., TECHNOFI, COO
When BPM meets Blockchain
Security and resilience for Smart Hospitals Key findings
Horizon 2020 Secure Societies European Info Day and Brokerage Event
Eric Peirano, Ph.D., TECHNOFI, COO
Efficient and secure transborder exchange of patient data
The European Union (EU) policy challenge
EAFIP, Athens 19th October Laura Sánchez / Patricia Martínez
Paperless & Cashless Poland Program overview
ICT PSP 2011, 5th call, Pilot Type B, Objective: 2.4 eLearning
Similarities between Grid-enabled Medical and Engineering Applications
Presentation for information days Units involved:
Lecture 6. Information systems
Data Quality: Practice, Technologies and Implications
INTER-Iot kick-off meeting
HOLISDER Integrating Real-Intelligence in Energy Management Systems enabling Holistic Demand Response Optimization in Buildings and Districts Project presentation.
Accelerating the digital transformation of government
CEF eID SMO The use of eID in eHealth
Advancing Telemedicine Adoption in Europe – Developing capacities
ICTPSP Call 2007 ICT for ageing well
Presentation for information days Units involved:
ENabling SafE Multi-Brand Platooning for Europe
HIMSS National Conference New Orleans Convention Center
Opportunities for Cybersecurity and Privacy clusters
Common Solutions to Common Problems
Dashboard eHealth services: actual mockup
SCONE: Secure Linux Containers Environments with Intel SGX
Designed for powerful live monitoring of larger installations
Juan Gonzalez eGovernment & CIP operations
ETSI Standardization Activities on Smart Grids
eHealth/mHealth Gisele Roesems
Presentation transcript:

Secure and Trusted Paradigm for Interoperable eHealth Services John Avramidis EULAMBIA Advanced Technologies Ltd H2020 PROJECT CLUSTERING WORKSHOP 31th January 2018, Athens, Greece

H2020 PROJECT CLUSTERING WORKSHOP KONFIDO means “Trust” in Esperanto H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 2

KONFIDO Consortium 15 partners 7 countries 2 pilots H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 3

KONFIDO Vision Provide a holistic approach to address the challenge of secure cross-border exchange of eHealth data H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 4

Interoperable and secure European eHealth services Our Goal Interoperable and secure European eHealth services Storage Disseminatio n Processing Presentation H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 5

Country B should be aware of: Cross-Border eHealth Data Retrieval Country B Country A Data Request Patient Data Country B should be aware of: Data formats and protocols of every country A The national infrastructure of every country A Regulations of every country A H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 6

Previous work on the field – Our guide The epSOS Project (I & II) 2008-2013 Smart Open Services for European Patient Goal: To develop a practical eHealth framework and ICT infrastructure, based on existing national infrastructures, that enables secure access to patient health information, particularly with respect to a basic Patient Summary and ePrescription, between European healthcare systems. H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 7

OpenNCP is the technical outcome of the epSOS project eHDSI and OpenNCP OpenNCP is the technical outcome of the epSOS project OpenNCP is a part of the eHealth Digital Service Infrastructure (eHDSI) and allows for the exchange of eHealth Data in Europe H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 8

The epSOS Mediated Approach National Contact Point (NCP) in charge of: Interacting with the other NCPs Pivoting documents Encode the pivoted document in the national structure Interact with the National Infrastructure (NI) H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 9

Security Assessment of epSOS Security of communications is ensured by employment of cryptography and secure protocols Security of communicating parties is not enforced by technical means It is instead assumed by legally binding agreement No protection is offered against propagation of cyberattacks Instead, attacks which success in compromising a NI can exploit NCP to propagate to other countries These security aspects were out of scope of epSOS H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 10

Here comes… H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 11

KONFIDO innovation pillars 1st Pillar: Enhancement of the trust and security of interoperable eHealth services 2nd Pillar: Continuous validation and proof of concept demonstrations 3rd Pillar: Focus on stakeholders, improving user acceptance, adhering to standards and legal and ethical directives H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 12

KONFIDO Challenges Develop a holistic secure solution for interoperable eHealth services Consider storage, dissemination, processing and presentation Successfully develop system components System Integration Ensure interoperability and scalability Handle legal, privacy and ethical issues H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 13

1st Pillar Enhancement of the trust and security of interoperable eHealth services H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 14

Six state-of-the-art Technologies Exploit the new security extensions of COTS CPUs for creating protected execution environments for eHealth applications Develop novel photonic encryption key generation technologies Build an efficient homomorphic encryption mechanism supporting secured health data storage, processing and exchange Develop customized SIEM solutions for real-time monitoring of the security of eHealth applications Implement disruptive logging and auditing mechanisms Design and implement a eIDAS compliant eID infrastructure Security information & event management H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 15

Only code running inside enclave sees data in clear Trusted Execution Environment (Intel SGX) Application splitted in: Trusted and Untrusted parts App runs & creates enclave which is placed in trusted memory Only code running inside enclave sees data in clear Intel Software Guard eXtensions (SGX) is an extension of the x86 ISA designed to support trusted computing SGX – based software is built around the concept of enclave Hardware – supported containers capable to guarantee the code executed therein The TCB is limited to the enclave Separation between trusted and untrusted part of an application Remote (and local) attestation between enclaves H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 16

Same PUF-challenge allow the same response! Photonic Unclonable Function (PUF) Electronic circuit Photonic Token Deterministic operation Same PUF-challenge allow the same response! Challenge Physical object Response Bit string (seed) Optical stimulus Bit string (key) Image (speckle) PUF characteristics : ► Repeatability Immunity to noise: The same object, challenge generates the same response robustness Immunity to replication even by malicious manufacturer ► Practically impossible to replicate unclonability ► Computationally unrealistic to simulate Immunity to machine learning, brute force, or simulation unpredictability H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 17

without violating the patients’ privacy Homomorphic Cryptography Parties: User – private data owner Server – owner of algorithm Goal: Server executes algorithm on HE data User obtains algorithm result on private data Can perform analysis on medical data without violating the patients’ privacy H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 18

Support a distributed analysis of high volumes of data KONFIDO SIEM A Security Information & Event Monitoring (SIEM) component is needed, in order to: Support a distributed analysis of high volumes of data Discover anomalies in the normal operation of the healthcare security system Protect the OpenNCP infrastructure from distributed attacks (ex. DDoS) H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 19

Disruptive Logging and Auditing Provides traceability and liability support Based on the blockchain design pattern Logs all privacy-critical operations A legally binding system based on blockchain auditing that allows to prove that specific eHealth data: Have been requested by a legitimate entity Have been provided (or not) H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 20

eIDAS Authentication OpenNCP deals with: Physicians Pharmacists Patients eIDAS authentication refers to how these different users authenticate with OpenNCP with eIDAS compliant identities H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 21

OpenNCP Reference Architecture Country 3 … Country 1 Country 1 EHR EHR NCP 3 Level 3 Level 3 Level 2 Level 2 Hospital Health Center Hospital Health Center NCP 1 NCP 2 OpenNCP National Infrastructure National Infrastructure Mobile Devices General Practitioner Mobile Devices General Practitioner Triage Home Care Triage Home Care Level 1 Level 1 H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 22

Conceptual view of KONFIDO architecture H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 23

Information flow (topmost level) H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 24

Before KONFIDO Deployment Country 3 … NCP 3 Country 1 Country 2 National Infrastructure NCP 1 NCP 2 National Infrastructure OpenNCP H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 25

KONFIDO Services Deployment TEE KONFIDO SERVICES/APIs KONFIDO Services Deployment Country 3 … KONFIDO Country 1 Country 2 TEE NCP 3 KONFIDO KONFIDO KONFIDO KONFIDO TEE TEE TEE TEE National Infrastructure NCP 1 NCP 1 National Infrastructure KONFIDO SERVICES/APIs TEE TEE KONFIDO SERVICES/APIs PUF eiDAS Auditing Services HE H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 26

Continuous validation and proof of concept demonstrations 2nd Pillar Continuous validation and proof of concept demonstrations H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 27

Objectives Perform preliminary module and system assessments and validation campaigns well before the pilot demonstrations Perform two (2) iterations on the specification and development of the proposed solutions Organize two (2) diverse and iterative demonstration campaigns in three (3) different member states H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 28

Validation Pilots Pilot sites in: Italy Denmark Spain H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 29

Scenario 1: Cross-border health data exchange across EU Validation Pilots Scenario 1: Cross-border health data exchange across EU Scenario 2: Secure cross-region and cross- border mobility for emergency management and patient empowerment H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 30

3rd Pillar Focus on stakeholders, improving user acceptance, adhering to standards and legal and ethical directives H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 31

Achieve wide acceptance of KONFIDO’s solutions Objectives Adhere to existing National and European legal directives and ethical norms Achieve wide acceptance of KONFIDO’s solutions Achieve wide user engagement steering KONFIDO’s solutions Define appropriate business models and a go-to- market strategy H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 32

KONFIDO outcome Smartly integrate the different components/tools into a ‘universal’ security toolbox to provide a complete packaged security solution to eHealth/mHealth Uniform, seamless and interoperable interface, operating under a common security and privacy framework Consideration of legal, operational/policy and ethical aspects H2020 PROJECT CLUSTERING WORKSHOP 31st January 2018 33

www.konfido-project.eu @konfidoproject twitter.com/konfidoproject www.facebook.com/konfidoproject/ www.linkedin.com/in/konfido-project-860427134/ www.konfido-project.eu @konfidoproject john.avramidis@eulambia.com