PAVA: Privacy-Preserving Attribute-Based Verifiable Authentication in Healthcare using Smart Contracts

被引:0
|
作者
Chegenizadeh, Mostafa [1 ]
Tessone, Claudio J. [1 ]
机构
[1] Univ Zurich, Dept Informat, Zurich, Switzerland
关键词
Attribute-Based Encryption; Blind Access Policy; Hidden Access Policy; Internet-of-Things; Blockchain; ENCRYPTION; PROTECTION; SECURITY;
D O I
10.1109/Blockchain62396.2024.00052
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper explores the synergetic potential of blockchain technology and attribute-based encryption to enhance security and privacy in decentralized data sharing systems, particularly within healthcare. We introduce PAVA, a novel privacy-preserving attribute-based scheme, which leverages smart contracts for verifiable authentication and ensures secure data interactions in healthcare applications. The scheme incorporates dual access policies: a data provider policy and a data user policy, which respectively authorize data providers to write (encrypt) and data users to read (decrypt) health data records. Encrypted health data records are stored on a blockchain within a healthcare smart contract, which enforces these access policies while keeping them confidential from unauthorized users and the smart contract itself. This arrangement allows for verifiable authentication checks on both the data providers (user authentication) and the integrity of the data they submit (data authentication) without revealing specific policy attributes. PAVA employs ciphertext-policy attribute-based encryption with partially hidden access policies based on linear secret sharing schemes (LSSS) and integrates blind access policies to facilitate verifiable authentication. Furthermore, the security of PAVA can be proved using the dual system encryption technique under static assumptions in the standard model, demonstrating its robustness and applicability in real-world healthcare data sharing scenarios.
引用
收藏
页码:346 / 353
页数:8
相关论文
共 50 条
  • [21] Constraints Validation in Privacy-Preserving Attribute-Based Access Control
    Oleshchuk, Vladimir
    2015 IEEE 8TH INTERNATIONAL CONFERENCE ON INTELLIGENT DATA ACQUISITION AND ADVANCED COMPUTING SYSTEMS: TECHNOLOGY AND APPLICATIONS (IDAACS), VOLS 1-2, 2015, : 429 - 431
  • [22] Efficient and privacy-preserving traceable attribute-based encryption in blockchain
    Axin Wu
    Yinghui Zhang
    Xiaokun Zheng
    Rui Guo
    Qinglan Zhao
    Dong Zheng
    Annals of Telecommunications, 2019, 74 : 401 - 411
  • [23] Distance-Bounding, Privacy-Preserving Attribute-Based Credentials
    Bosk, Daniel
    Bouget, Simon
    Buchegger, Sonja
    CRYPTOLOGY AND NETWORK SECURITY, CANS 2020, 2020, 12579 : 147 - 166
  • [24] Privacy-Preserving Online Parking Based on Smart Contracts
    Dzurenda, Petr
    Angles-Tafalla, Carles
    Ricci, Sara
    Malina, Lukas
    ARES 2021: 16TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, 2021,
  • [25] Privacy-preserving attribute-based access control for grid computing
    Park, Sang M.
    Chung, Soon M.
    INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2014, 5 (04) : 286 - 296
  • [26] Dynamic Attribute-Based Privacy-Preserving Genomic Susceptibility Testing
    Namazi, Mina
    Eryonucu, Cihan
    Ayday, Erman
    Perez-Gonzalez, Fernando
    SAC '19: PROCEEDINGS OF THE 34TH ACM/SIGAPP SYMPOSIUM ON APPLIED COMPUTING, 2019, : 1467 - 1474
  • [27] Novel Secure Privacy-Preserving Decentralized Attribute-Based Encryption
    Liang, Pengfei
    Zhang, Leyou
    Shang, Yujie
    FRONTIERS IN CYBER SECURITY, 2018, 879 : 66 - 80
  • [28] Efficient and privacy-preserving traceable attribute-based encryption in blockchain
    Wu, Axin
    Zhang, Yinghui
    Zheng, Xiaokun
    Guo, Rui
    Zhao, Qinglan
    Zheng, Dong
    ANNALS OF TELECOMMUNICATIONS, 2019, 74 (7-8) : 401 - 411
  • [29] Privacy-Preserving Authentication Systems Using Smart Devices
    Malina, Lukas
    Hajny, Jan
    Martinasek, Zdenek
    2016 39TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS AND SIGNAL PROCESSING (TSP), 2016, : 11 - 14
  • [30] Privacy-Preserving Digital Rights Management based on Attribute-based Encryption
    Petrlic, Ronald
    Sorge, Christoph
    2014 6TH INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2014,