• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

支持区块链的数据治理,用于在保护隐私的前提下共享机密数据。

Blockchain-enabled data governance for privacy-preserved sharing of confidential data.

作者信息

Zhang Jingchi, Datta Anwitaman

机构信息

College of Computing and Data Science, Nanyang Technological University, Singapore, Singapore.

De Montfort University Leicester, Leicester, United Kingdom.

出版信息

PeerJ Comput Sci. 2024 Dec 20;10:e2581. doi: 10.7717/peerj-cs.2581. eCollection 2024.

DOI:10.7717/peerj-cs.2581
PMID:39896413
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC11784720/
Abstract

In traditional cloud storage systems, users benefit from the convenience of data accessibility but face significant risks related to security. Ciphertext-policy attribute-based encryption (CP-ABE) schemes are employed to achieve fine-grained access control in cloud services to ensure confidentiality while maintaining data-sharing capabilities. However, existing approaches are impaired by two critical issues: illegal authorization and privacy leakage. Despite extensive discussions in the literature on interoperability, performance, scalability, and stability, the security of ABE-based cloud storage and data-sharing systems against adversaries-particularly those involving adaptively corrupt attribute authorities gaining unauthorized access to users' data-has not been sufficiently explored. Notably, few existing works even address security in the presence of adversaries, raising concerns about the practicality of these systems in real-world scenarios where malicious behavior is a genuine threat. Another pressing issue is privacy leakage, where sensitive user information, such as medical histories in healthcare use cases, embedded within the access policies, may be exposed to all users. This problem is exacerbated in ABE schemes that integrate blockchain technology for enhanced decentralization and interoperability, as using a public ledger shared across multiple users can further compromise privacy. To address these, we propose an enhanced blockchain-based data governance system that employs blockchain technology and attribute-based encryption to prevent illegal authorization and privacy leakage. Our novel ABE encryption system supports multi-authority use cases while hiding access policy and ensuring identity privacy, which also protects data sharing against corrupt authorities. Utilizing the Advanced Encryption Standard (AES) for data encryption, our system is optimized for real-world efficiency. Notably, the encrypted data is stored in a decentralized storage system, like the InterPlanetary File System (IPFS), which does not rely on any centralized service provider and can, therefore, be leveraged to achieve resilience against single-point failures. With the integration of smart contracts and multi-authority attribute-based encryption, coupled with blockchain's inherent transparency and traceability, our system realizes a balanced solution for fine-grained access control with preserved privacy, further fortifying against credential misuse. Besides the system design, we also present security proofs to demonstrate the robustness of the proposed system.

摘要

在传统云存储系统中,用户受益于数据可访问性带来的便利,但面临与安全相关的重大风险。基于密文策略属性的加密(CP-ABE)方案被用于在云服务中实现细粒度访问控制,以确保机密性同时保持数据共享能力。然而,现有方法受到两个关键问题的影响:非法授权和隐私泄露。尽管文献中对互操作性、性能、可扩展性和稳定性进行了广泛讨论,但基于ABE的云存储和数据共享系统针对对手(特别是那些涉及自适应破坏属性授权机构从而未经授权访问用户数据的对手)的安全性尚未得到充分探索。值得注意的是,现有工作中很少有甚至涉及存在对手时的安全性,这引发了对这些系统在恶意行为构成真正威胁的现实场景中的实用性的担忧。另一个紧迫问题是隐私泄露,其中嵌入访问策略中的敏感用户信息(如医疗保健用例中的病史)可能会暴露给所有用户。在为增强去中心化和互操作性而集成区块链技术的ABE方案中,这个问题会更加严重,因为使用跨多个用户共享的公共账本会进一步损害隐私。为了解决这些问题,我们提出了一种基于区块链的增强型数据治理系统,该系统采用区块链技术和基于属性的加密来防止非法授权和隐私泄露。我们新颖的ABE加密系统支持多授权用例,同时隐藏访问策略并确保身份隐私,这也保护数据共享免受腐败授权机构的影响。利用高级加密标准(AES)进行数据加密,我们的系统针对实际效率进行了优化。值得注意的是,加密数据存储在去中心化存储系统中,如星际文件系统(IPFS),它不依赖于任何集中式服务提供商,因此可以用来实现对单点故障的弹性。通过集成智能合约和基于多授权属性的加密,再加上区块链固有的透明度和可追溯性,我们的系统实现了一个兼顾隐私保护的细粒度访问控制的平衡解决方案,进一步防范凭证滥用。除了系统设计,我们还给出了安全证明以展示所提出系统的稳健性。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/04ee/11784720/5f9c309a44aa/peerj-cs-10-2581-g004.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/04ee/11784720/6e157ed9c81a/peerj-cs-10-2581-g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/04ee/11784720/4d670aa0bf39/peerj-cs-10-2581-g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/04ee/11784720/e281c2d6ae88/peerj-cs-10-2581-g003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/04ee/11784720/5f9c309a44aa/peerj-cs-10-2581-g004.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/04ee/11784720/6e157ed9c81a/peerj-cs-10-2581-g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/04ee/11784720/4d670aa0bf39/peerj-cs-10-2581-g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/04ee/11784720/e281c2d6ae88/peerj-cs-10-2581-g003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/04ee/11784720/5f9c309a44aa/peerj-cs-10-2581-g004.jpg

相似文献

1
Blockchain-enabled data governance for privacy-preserved sharing of confidential data.支持区块链的数据治理,用于在保护隐私的前提下共享机密数据。
PeerJ Comput Sci. 2024 Dec 20;10:e2581. doi: 10.7717/peerj-cs.2581. eCollection 2024.
2
Privacy Preservation in Patient Information Exchange Systems Based on Blockchain: System Design Study.基于区块链的患者信息交换系统中的隐私保护:系统设计研究。
J Med Internet Res. 2022 Mar 22;24(3):e29108. doi: 10.2196/29108.
3
A robust algorithm for authenticated health data access via blockchain and cloud computing.一种通过区块链和云计算进行认证的健康数据访问的稳健算法。
PLoS One. 2024 Sep 23;19(9):e0307039. doi: 10.1371/journal.pone.0307039. eCollection 2024.
4
An Access Control Scheme Based on Blockchain and Ciphertext Policy-Attribute Based Encryption.一种基于区块链和基于密文策略属性加密的访问控制方案。
Sensors (Basel). 2023 Sep 23;23(19):8038. doi: 10.3390/s23198038.
5
Blockchain-Based Access Control Scheme for Secure Shared Personal Health Records over Decentralised Storage.基于区块链的去中心化存储中安全共享个人健康记录的访问控制方案。
Sensors (Basel). 2021 Apr 2;21(7):2462. doi: 10.3390/s21072462.
6
Blockchain-based proxy re-encryption access control method for biological risk privacy protection of agricultural products.基于区块链的农产品生物风险隐私保护代理重加密访问控制方法。
Sci Rep. 2024 Aug 29;14(1):20048. doi: 10.1038/s41598-024-70533-0.
7
A Secure Data Sharing Model Utilizing Attribute-Based Signcryption in Blockchain Technology.一种利用区块链技术中基于属性的签密的安全数据共享模型。
Sensors (Basel). 2024 Dec 30;25(1):160. doi: 10.3390/s25010160.
8
A privacy-preserving blockchain-based tracing model for virus-infected people in cloud.一种基于区块链的云环境中病毒感染者隐私保护追踪模型。
Expert Syst Appl. 2023 Jan;211:118545. doi: 10.1016/j.eswa.2022.118545. Epub 2022 Aug 18.
9
HealthLock: Blockchain-Based Privacy Preservation Using Homomorphic Encryption in Internet of Things Healthcare Applications.HealthLock:物联网医疗应用中基于同态加密的区块链隐私保护
Sensors (Basel). 2023 Jul 28;23(15):6762. doi: 10.3390/s23156762.
10
Healthchain: A novel framework on privacy preservation of electronic health records using blockchain technology.健康链:利用区块链技术保护电子健康记录隐私的新框架。
PLoS One. 2020 Dec 9;15(12):e0243043. doi: 10.1371/journal.pone.0243043. eCollection 2020.