Department of Computer Science, Sangmyung University, Seoul, South Korea.
Graduate School of Information, Yonsei University, Seoul, South Korea.
PLoS One. 2021 May 11;16(5):e0250992. doi: 10.1371/journal.pone.0250992. eCollection 2021.
With the rapid advancement of information and communication technologies, there is a growing transformation of healthcare systems. A patient's health data can now be centrally stored in the cloud and be shared with multiple healthcare stakeholders, enabling the patient to be collaboratively treated by more than one healthcare institution. However, several issues, including data security and privacy concerns still remain unresolved. Ciphertext-policy attribute-based encryption (CP-ABE) has shown promising potential in providing data security and privacy in cloud-based systems. Nevertheless, the conventional CP-ABE scheme is inadequate for direct adoption in a collaborative ehealth system. For one, its expressiveness is limited as it is based on a monotonic access structure. Second, it lacks an attribute/user revocation mechanism. Third, the computational burden on both the data owner and data users is linear with the number of attributes in the ciphertext. To address these inadequacies, we propose CESCR, a CP-ABE for efficient and secure sharing of health data in collaborative ehealth systems with immediate and efficient attribute/user revocation. The CESCR scheme is unbounded, i.e., it does not bind the size of the attribute universe to the security parameter, it is based on the expressive and non-restrictive ordered binary decision diagram (OBDD) access structure, and it securely outsources the computationally demanding attribute operations of both encryption and decryption processes without requiring a dummy attribute. Security analysis shows that the CESCR scheme is secure in the selective model. Simulation and performance comparisons with related schemes also demonstrate that the CESCR scheme is expressive and efficient.
随着信息和通信技术的飞速发展,医疗保健系统正在发生巨大的变革。患者的健康数据现在可以集中存储在云端,并与多个医疗保健利益相关者共享,使患者能够由多家医疗机构共同治疗。然而,仍有一些问题尚未解决,包括数据安全和隐私问题。密文策略属性基加密(CP-ABE)在提供云系统中的数据安全和隐私方面显示出了很大的潜力。然而,传统的 CP-ABE 方案不足以直接应用于协作电子健康系统。首先,它的表达能力有限,因为它基于单调访问结构。其次,它缺乏属性/用户撤销机制。第三,数据所有者和数据用户的计算负担与密文中的属性数量呈线性关系。为了解决这些不足,我们提出了 CESCR,这是一种用于协作电子健康系统中高效安全的健康数据共享的 CP-ABE,具有即时和有效的属性/用户撤销功能。CESCR 方案是无界的,即它不将属性宇宙的大小绑定到安全参数,它基于表达性和非限制性的有序二叉决策图(OBDD)访问结构,并且安全地外包了加密和解密过程中计算密集型的属性操作,而不需要虚拟属性。安全性分析表明,CESCR 方案在选择模型中是安全的。与相关方案的仿真和性能比较也表明,CESCR 方案具有表达力和效率。