PAVA: Privacy-Preserving Attribute-Based Verifiable Authentication in Healthcare using Smart Contracts

被引:0
|
作者
Chegenizadeh, Mostafa [1 ]
Tessone, Claudio J. [1 ]
机构
[1] Univ Zurich, Dept Informat, Zurich, Switzerland
关键词
Attribute-Based Encryption; Blind Access Policy; Hidden Access Policy; Internet-of-Things; Blockchain; ENCRYPTION; PROTECTION; SECURITY;
D O I
10.1109/Blockchain62396.2024.00052
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper explores the synergetic potential of blockchain technology and attribute-based encryption to enhance security and privacy in decentralized data sharing systems, particularly within healthcare. We introduce PAVA, a novel privacy-preserving attribute-based scheme, which leverages smart contracts for verifiable authentication and ensures secure data interactions in healthcare applications. The scheme incorporates dual access policies: a data provider policy and a data user policy, which respectively authorize data providers to write (encrypt) and data users to read (decrypt) health data records. Encrypted health data records are stored on a blockchain within a healthcare smart contract, which enforces these access policies while keeping them confidential from unauthorized users and the smart contract itself. This arrangement allows for verifiable authentication checks on both the data providers (user authentication) and the integrity of the data they submit (data authentication) without revealing specific policy attributes. PAVA employs ciphertext-policy attribute-based encryption with partially hidden access policies based on linear secret sharing schemes (LSSS) and integrates blind access policies to facilitate verifiable authentication. Furthermore, the security of PAVA can be proved using the dual system encryption technique under static assumptions in the standard model, demonstrating its robustness and applicability in real-world healthcare data sharing scenarios.
引用
收藏
页码:346 / 353
页数:8
相关论文
共 50 条
  • [11] Efficient privacy-preserving authentication protocol using PUFs with blockchain smart contracts
    Patil, Akash Suresh
    Hamza, Rafik
    Hassan, Alzubair
    Jiang, Nan
    Yan, Hongyang
    Li, Jin
    COMPUTERS & SECURITY, 2020, 97 (97)
  • [12] A Privacy-Preserving Attribute-Based Access Control Scheme
    Xu, Yang
    Zeng, Quanrun
    Wang, Guojun
    Zhang, Cheng
    Ren, Ju
    Zhang, Yaoxue
    SECURITY, PRIVACY, AND ANONYMITY IN COMPUTATION, COMMUNICATION, AND STORAGE (SPACCS 2018), 2018, 11342 : 361 - 370
  • [13] Privacy-preserving attribute-based access control using homomorphic encryption
    Kerl, Malte
    Bodin, Ulf
    Schelen, Olov
    CYBERSECURITY, 2025, 8 (01):
  • [14] Privacy-preserving Blockchain based IoT Ecosystem using Attribute-based Encryption
    Rahulamathavan, Yogachandran
    Phan, Raphael C-W
    Rajarajan, Muttukrishnan
    Misra, Sudip
    Kondoz, Ahmet
    2017 IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATIONS SYSTEMS (ANTS), 2017,
  • [15] A Privacy-Preserving Multi-Authority Attribute-Based Encryption Approach for Mobile Healthcare
    Meng, Dacheng
    Luo, Entao
    Wang, Guojun
    PROCEEDINGS 2016 IEEE 13TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SENSOR SYSTEMS (MASS 2016), 2016, : 299 - 306
  • [16] Assessment of attribute-based credentials for privacy-preserving road traffic services in smart cities
    de Fuentes, J. M.
    Gonzalez-Manzano, L.
    Serna-Olvera, J.
    Veseli, F.
    PERSONAL AND UBIQUITOUS COMPUTING, 2017, 21 (05) : 869 - 891
  • [17] Assessment of attribute-based credentials for privacy-preserving road traffic services in smart cities
    J. M. de Fuentes
    L. González-Manzano
    J. Serna-Olvera
    F. Veseli
    Personal and Ubiquitous Computing, 2017, 21 : 869 - 891
  • [18] Concepts Around Privacy-Preserving Attribute-Based Credentials Making Authentication with Anonymous Credentials Practical
    Camenisch, Jan
    PRIVACY AND IDENTITY MANAGEMENT FOR EMERGING SERVICES AND TECHNOLOGIES, 2014, 421 : 53 - 63
  • [19] Privacy-preserving credential smart contracts using Zokrates
    Kim, Geunyoung
    Ham, Yunsik
    Ryou, Jaecheol
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2024, 18 (08): : 2417 - 2430
  • [20] Privacy-Preserving Electronic Ticket Scheme with Attribute-Based Credentials
    Han, Jinguang
    Chen, Liqun
    Schneider, Steve
    Treharne, Helen
    Wesemeyer, Stephan
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2021, 18 (04) : 1836 - 1849