Department of Information Security, National University of Sciences and Technology, Sector H-12, Islamabad 44000, Pakistan.
Department of Computer Science & IT, Sarhad University of Science and Information Technology, Peshawar 25000, Pakistan.
Sensors (Basel). 2021 May 20;21(10):3556. doi: 10.3390/s21103556.
Healthcare is a multi-actor environment that requires independent actors to have a different view of the same data, hence leading to different access rights. Ciphertext Policy-Attribute-based Encryption (CP-ABE) provides a one-to-many access control mechanism by defining an attribute's policy over ciphertext. Although, all users satisfying the policy are given access to the same data, this limits its usage in the provision of hierarchical access control and in situations where different users/actors need to have granular access of the data. Moreover, most of the existing CP-ABE schemes either provide static access control or in certain cases the policy update is computationally intensive involving all non-revoked users to actively participate. Aiming to tackle both the challenges, this paper proposes a patient-centric multi message CP-ABE scheme with efficient policy update. Firstly, a general overview of the system architecture implementing the proposed access control mechanism is presented. Thereafter, for enforcing access control a concrete cryptographic construction is proposed and implemented/tested over the physiological data gathered from a healthcare sensor: shimmer sensor. The experiment results reveal that the proposed construction has constant computational cost in both encryption and decryption operations and generates constant size ciphertext for both the original policy and its update parameters. Moreover, the scheme is proven to be selectively secure in the random oracle model under the q-Bilinear Diffie Hellman Exponent (q-BDHE) assumption. Performance analysis of the scheme depicts promising results for practical real-world healthcare applications.
医疗保健是一个多主体环境,需要独立的主体对同一数据有不同的看法,从而导致不同的访问权限。密文策略属性基加密(CP-ABE)通过在密文上定义属性策略提供了一种一对多的访问控制机制。尽管所有满足策略的用户都可以访问相同的数据,但这限制了它在提供分层访问控制和在不同用户/主体需要对数据进行细粒度访问的情况下的使用。此外,大多数现有的 CP-ABE 方案要么提供静态访问控制,要么在某些情况下策略更新计算密集,涉及所有未撤销的用户积极参与。为了解决这两个挑战,本文提出了一种基于患者的多消息 CP-ABE 方案,具有高效的策略更新。首先,提出了一种实现所提出的访问控制机制的系统架构的概述。此后,为了实施访问控制,提出了一个具体的密码学构造,并在从医疗保健传感器(Shimmer 传感器)收集的生理数据上进行了实施/测试。实验结果表明,所提出的构造在加密和解密操作中具有恒定的计算成本,并为原始策略及其更新参数生成恒定大小的密文。此外,该方案在随机 oracle 模型下基于 q-Bilinear Diffie Hellman Exponent(q-BDHE)假设被证明是选择性安全的。该方案的性能分析表明,它在实际的医疗保健应用中具有有前途的结果。