首页> 外文期刊>International Journal of Information Security >Privacy-preserving personal health record using multi-authority attribute-based encryption with revocation
【24h】

Privacy-preserving personal health record using multi-authority attribute-based encryption with revocation

机译:使用基于多权限基于属性的加密和撤消保护隐私的个人健康记录

获取原文
获取原文并翻译 | 示例
           

摘要

Personal health record (PHR) service is an emerging model for health information exchange. In PHR systems, patient's health records and information are maintained by the patient himself through the Web. In reality, PHRs are often outsourced to be stored at the third parties like cloud service providers. However, there have been serious privacy concerns about cloud service as it may expose user's sensitive data like PHRs to those cloud service providers or unauthorized users. Using attribute-based encryption (ABE) to encrypt patient's PHRs in cloud environment, secure and flexible access control can be achieved. Yet, problems like scalability in key management, fine-grained access control, and efficient user revocation remain to be addressed. In this paper, we propose a privacy-preserving PHR, which supports fine-grained access control and efficient revocation. To be specific, our scheme achieves the goals (1) scalable and fine-grained access control for PHRs by using multi-authority ABE scheme, and (2) efficient on-demand user/attribute revocation and dynamic policy update. In our scheme, we consider the situation that multiple data owners exist, and patient's PHRs are encrypted and stored in semi-trust servers. The access structure in our scheme is expressive access tree structure, and the security of our scheme can be reduced to the standard decisional bilinear Diffie-Hellman assumption.
机译:个人健康记录(PHR)服务是健康信息交换的新兴模型。在PHR系统中,患者本人通过Web维护患者的健康记录和信息。实际上,PHR通常外包给像云服务提供商这样的第三方存储。但是,由于云服务可能会将用户的敏感数据(如PHR)暴露给那些云服务提供商或未经授权的用户,因此存在严重的隐私问题。使用基于属性的加密(ABE)在云环境中对患者的PHR进行加密,可以实现安全灵活的访问控制。但是,诸如密钥管理中的可伸缩性,细粒度的访问控制以及有效的用户吊销等问题仍待解决。在本文中,我们提出了一种保护隐私的PHR,它支持细粒度的访问控制和有效的撤消。具体而言,我们的方案实现了以下目标:(1)通过使用多权限ABE方案对PHR进行可伸缩的细粒度访问控制,以及(2)高效的按需用户/属性吊销和动态策略更新。在我们的方案中,我们考虑到存在多个数据所有者,并且患者的PHR被加密并存储在半信任服务器中的情况。我们的方案中的访问结构是表达性访问树结构,并且我们的方案的安全性可以降低到标准的决策双线性Diffie-Hellman假设。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号