{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:50:20Z","timestamp":1781106620702,"version":"3.54.1"},"reference-count":34,"publisher":"IGI Global Scientific Publishing","issue":"4","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013,10,1]]},"abstract":"<p>An increasing number of countries are faced with an aging population increasingly needing healthcare services. For any e-health information system, the need for increased trust by such clients with potentially little knowledge of any security scheme involved is paramount. In addition notable scalability of any system has become a critical aspect of system design, development and ongoing management. Meanwhile cryptographic systems provide the security provisions needed for confidentiality, authentication, integrity and non-repudiation. Cryptographic key management, however, must be secure, yet efficient and effective in developing an attitude of trust in system users. Digital certificate-based Public Key Infrastructure has long been the technology of choice or availability for information security\/assurance; however, there appears to be a notable lack of successful implementations and deployments globally. Moreover, recent issues with associated Certificate Authority security have damaged trust in these schemes. This paper proposes the adoption of a centralised public key registry structure, a non-certificate based scheme, for large scale e-health information systems. The proposed structure removes complex certificate management, revocation and a complex certificate validation structure while maintaining overall system security. Moreover, the registry concept may be easier for both healthcare professionals and patients to understand and trust.<\/p>","DOI":"10.4018\/ijehmc.2013100105","type":"journal-article","created":{"date-parts":[[2014,5,9]],"date-time":"2014-05-09T14:36:10Z","timestamp":1399646170000},"page":"66-83","source":"Crossref","is-referenced-by-count":4,"title":["Using a Public Key Registry for Improved Trust and Scalability in National E-Health Systems"],"prefix":"10.4018","volume":"4","author":[{"given":"Vicky","family":"Liu","sequence":"first","affiliation":[{"name":"Science and Engineering Faculty, Queensland University of Technology, Brisbane, Queensland, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"William","family":"Caelli","sequence":"additional","affiliation":[{"name":"Science and Engineering Faculty, Queensland University of Technology, Brisbane, Queensland, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu-Nien Maggie","family":"Chen","sequence":"additional","affiliation":[{"name":"Graduate School of Asia and Pacific Studies, Waseda University, Tokyo, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"ijehmc.2013100105-0","unstructured":"Adams, C., & Lloyd, S. (2002). Understanding PKI: Concepts, standards, deployment and consideratiions (Ed.). Boston, MA: Person Education, Inc."},{"key":"ijehmc.2013100105-1","unstructured":"Adams, C., & Zuccherato, R. (1998). A general, flexible approach to certificate revocation. Entrust Technologies White Paper."},{"key":"ijehmc.2013100105-2","doi-asserted-by":"crossref","unstructured":"Arends, R., Austein, R., Larson, M., Massey, D., & Rose, S. (2005a). RFC4033: DNS security introduction and requirements.","DOI":"10.17487\/rfc4033"},{"key":"ijehmc.2013100105-3","doi-asserted-by":"crossref","unstructured":"Arends, R., Austein, R., Larson, M., Massey, D., & Rose, S. (2005b). RFC4034: DNS resource records for the DNS security extensions.","DOI":"10.17487\/rfc4034"},{"key":"ijehmc.2013100105-4","doi-asserted-by":"crossref","unstructured":"Arends, R., Austein, R., Larson, M., Massey, D., & Rose, S. (2005c). RFC4035: Protocol modifications for the DNS security extensions.","DOI":"10.17487\/rfc4035"},{"key":"ijehmc.2013100105-5","unstructured":"Australian Department of Health and Ageing. (2011). Concept of operations: Relating to the introduction of a personally controlled electronic health record system (Ed.). Canberra: National E-Health Transition Authority Ltd."},{"key":"ijehmc.2013100105-6","author":"S.Berkovits","year":"1994","journal-title":"Public key infrastructure study: Final report"},{"key":"ijehmc.2013100105-7","first-page":"60","article-title":"The European TrustHealth Project experiences with implementing a security infrastructure.","author":"B.Blobel","year":"2000","journal-title":"International Journal of Medical Informatics"},{"key":"ijehmc.2013100105-8","doi-asserted-by":"crossref","unstructured":"Boldyreva, A., Goyal, V., & Kumar, V. (2008). Identity-based Encryption with efficient revocation. In Proceedings of the 15th ACM Conference on Computer and Communications Security (pp. 417-426).","DOI":"10.1145\/1455770.1455823"},{"key":"ijehmc.2013100105-9","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45682-1_30"},{"key":"ijehmc.2013100105-10","unstructured":"Bright, P. (2011). Another fraudulent certificate raises the same old questions about certificate authorities. Retrieved January 22, 2013, from http:\/\/arstechnica.com\/security\/2011\/08\/earlier-this-year-an-iranian\/"},{"key":"ijehmc.2013100105-11","doi-asserted-by":"crossref","unstructured":"Cooper, D. A. (2000). A more efficient use of delta-CRLs. In Proceedings of the 2000 IEEE Symposium on Security and Privacy (S&P) (pp. 190-202).","DOI":"10.1109\/SECPRI.2000.848456"},{"key":"ijehmc.2013100105-12","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1976.1055638"},{"key":"ijehmc.2013100105-13","doi-asserted-by":"crossref","unstructured":"Faldella, E., & Prandini, M. (2000). A novel approach to on-line status authentication of public-key certificates. In Proceedings of the 16th Annual Conference on Computer Security Applications (ACSAC '00) (pp. 270-277).","DOI":"10.1109\/ACSAC.2000.898881"},{"key":"ijehmc.2013100105-14","doi-asserted-by":"crossref","unstructured":"Faldella, E., & Prandini, M. (2002). A flexible scheme for on-line public-key certificate status updating and verification. In Proceedings of the Seventh International Symposium on Computers and Communications (pp. 891-898).","DOI":"10.1109\/ISCC.2002.1021778"},{"key":"ijehmc.2013100105-15","doi-asserted-by":"crossref","unstructured":"Gutmann, P. (2000). A reliable, scalable general-purpose certificate store. In Proceedings of the 16th Annual Conference on Computer Security Applications (ACSAC '00) (pp. 278-287).","DOI":"10.1109\/ACSAC.2000.898882"},{"key":"ijehmc.2013100105-16","unstructured":"Higgins, K. J., & Reading, D. (2011). Digital certificate authority hacked, dozens of phony digital certificates issued: DigiNotar confirms it was breached and Google.com just one of 'several dozens' of fraudulently issued digital certificates obtained by hackers and now revoked. Retrieved October 17, 2012, from http:\/\/www.darkreading.com\/attacks-breaches\/digital-certificate-authority-hacked-doz\/231600498?printer_friendly=this-page"},{"key":"ijehmc.2013100105-17","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2009.04.005"},{"key":"ijehmc.2013100105-18","doi-asserted-by":"crossref","unstructured":"Kocher, P. (1998). A quick introduction to Certificate Revocation Trees.","DOI":"10.1007\/BFb0055481"},{"key":"ijehmc.2013100105-19","doi-asserted-by":"crossref","unstructured":"Leitold, H., Hollosi, A., & Posch, R. (2002). Security architecture of the Austrian citizen card concept. In 18th Annual Computer Security Applications Conference Proceedings (pp. 391-400).","DOI":"10.1109\/CSAC.2002.1176311"},{"key":"ijehmc.2013100105-20","unstructured":"Liu, V. (2011). An architecture for enhanced assurance in e-health systems. Doctoral dissertation, Queensland University of Technology, Australia."},{"key":"ijehmc.2013100105-21","unstructured":"Liu, V., Caelli, W., May, L., & Sahama, T. (2009). Privacy and security in open and trusted health information systems. In Proceedings of the 3rd Australasian Workshop on Health Informatics and Knowledge Management (HIKM 2009) (pp. 25-30). Wellington, New Zealand: Australian Computer Society."},{"key":"ijehmc.2013100105-22","unstructured":"Liu, V., Caelli, W., Smith, M. L., Lee, M., Ng, Z., Foo, J., & Li, W. (2010). Secure architecture for australia\u2018s index based e-health environment. In A. Maeder & D. Hansen (Eds.), Fourth Australasian Workshop on Health Informatics and Knowledge Management (HIKM 2010), Conferences in Research and Practice in Information Technology (CRPIT) (Vol. 108, pp. 7-16)."},{"key":"ijehmc.2013100105-23","unstructured":"Liu, V., Franco, L., Caelli, W., May, L., & Sahama, T. (2009). Open and trusted information systems\/health informatics access control (OTHIS\/HIAC). In L. Brankovic & W. Susilo (Eds.), Proceedings of the Seventh Australasian Information Security Conference (AISC 2009) (pp. 99-108). Wellington, New Zealand: Australian Computer Science."},{"key":"ijehmc.2013100105-24","unstructured":"Messmer, E. (2013). Multivendor power council formed to address digital certificate issues. Retrieved April 20, 2013, from http:\/\/www.networkworld.com\/news\/2013\/021413-council-digital-certificate-266728.html"},{"key":"ijehmc.2013100105-25","author":"S.Micali","year":"1996","journal-title":"Efficient certificate revocation"},{"key":"ijehmc.2013100105-26","doi-asserted-by":"publisher","DOI":"10.1109\/49.839932"},{"key":"ijehmc.2013100105-27","doi-asserted-by":"crossref","unstructured":"Shamir, A. (1985). Identity-based cryptosystems and signature schemes. In Proceedings of CRYPTO 84 on Advances in Cryptology (pp. 47-53). Springer-Verlag.","DOI":"10.1007\/3-540-39568-7_5"},{"key":"ijehmc.2013100105-28","doi-asserted-by":"crossref","unstructured":"Shen, P., Liu, V., & Caelli, W. (2012). A viable and sustaninable key management approach for a national e-health environment. In Proceedings of the 2012 IEEE 14th International Conference on e-Health Networking, Applications and Services (HealthCom) (pp. 347-352).","DOI":"10.1109\/HealthCom.2012.6379434"},{"key":"ijehmc.2013100105-29","doi-asserted-by":"publisher","DOI":"10.4018\/jisp.2012010103"},{"key":"ijehmc.2013100105-30","doi-asserted-by":"crossref","unstructured":"Slagell, A., Bonilla, R., & Yurcik, W. (2006). A survey of PKI components and scalability issues. In Proceedings of the 25th IEEE International Performance, Computing, and Communications Conference (IPCCC) (pp. 10-484).","DOI":"10.1109\/.2006.1629442"},{"key":"ijehmc.2013100105-31","unstructured":"Stroetmann, K. A., & Lilischkis, S. (2007). e-Health strategy and implementation activities in Germany. Retrieved October 17, 2012, from http:\/\/www.ehealthera.org\/database\/documents\/ERA_Reports\/Germany_eHERA Country_Report_final_30-06-2007.pdf"},{"key":"ijehmc.2013100105-32","unstructured":"The Internet Society. (1999). X.509 internet public key infrastructure online certificate status protocol \u2013 OCSP (Ed.). IETF."},{"key":"ijehmc.2013100105-33","unstructured":"The United Nations. (2002). World population ageing: 1950-2050. Retrieved October 17, 2012, from http:\/\/www.un.org\/esa\/population\/publications\/worldageing19502050\/"}],"container-title":["International Journal of E-Health and Medical Communications"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=107055","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T23:29:30Z","timestamp":1654126170000},"score":1,"resource":{"primary":{"URL":"https:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/ijehmc.2013100105"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2013,10,1]]},"references-count":34,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2013,10]]}},"URL":"https:\/\/doi.org\/10.4018\/ijehmc.2013100105","relation":{},"ISSN":["1947-315X","1947-3168"],"issn-type":[{"value":"1947-315X","type":"print"},{"value":"1947-3168","type":"electronic"}],"subject":[],"published":{"date-parts":[[2013,10,1]]}}}