IEEE J Biomed Health Inform. 2023 Feb;27(2):698-709. doi: 10.1109/JBHI.2022.3203577. Epub 2023 Feb 3.
With the increasing penetration of the Internet of things (IoT) into people's lives, the limitations of traditional medical systems are emerging. First, the typical way of handling sensitive information can easily lead to privacy disclosure. Second, the medical system is relatively isolated. It is difficult for one medical system to share data with another, and the scope of users' activities is limited within the system boundary. To solve these two problems, we propose a new privacy-preserving medical data-sharing scheme by introducing the authorization mechanism and attribute-based encryption (ABE) based on blockchain, which breaks system boundaries and realizes data sharing among several medical institutions. ABE is used to realize scalable access control. In addition, doctors can share their knowledge to diagnose users by introducing many-to-many matching, which means that patients' health data can be represented by multiple keywords and doctors' expertise can be represented by multiple interests. We provide the correctness and security analysis of our scheme and implement a prototype tool on Ethereum. The experimental results show that our scheme solves the contradiction between the privacy preservation of medical data and the necessity of data sharing.
随着物联网 (IoT) 越来越深入人们的生活,传统医疗系统的局限性开始显现。首先,传统医疗系统处理敏感信息的典型方式很容易导致隐私泄露。其次,医疗系统相对孤立,一个医疗系统很难与另一个医疗系统共享数据,用户的活动范围也局限在系统边界内。为了解决这两个问题,我们提出了一种新的基于区块链的隐私保护医疗数据共享方案,通过引入授权机制和基于属性的加密 (ABE),打破了系统的界限,实现了多个医疗机构之间的数据共享。ABE 用于实现可扩展的访问控制。此外,通过引入多对多匹配,医生可以共享他们的知识来诊断用户,这意味着患者的健康数据可以用多个关键字表示,而医生的专业知识可以用多个兴趣来表示。我们对方案进行了正确性和安全性分析,并在以太坊上实现了一个原型工具。实验结果表明,我们的方案解决了医疗数据隐私保护和数据共享必要性之间的矛盾。