PAVA: Privacy-Preserving Attribute-Based Verifiable Authentication in Healthcare using Smart Contracts

被引:0
|
作者
Chegenizadeh, Mostafa [1 ]
Tessone, Claudio J. [1 ]
机构
[1] Univ Zurich, Dept Informat, Zurich, Switzerland
关键词
Attribute-Based Encryption; Blind Access Policy; Hidden Access Policy; Internet-of-Things; Blockchain; ENCRYPTION; PROTECTION; SECURITY;
D O I
10.1109/Blockchain62396.2024.00052
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper explores the synergetic potential of blockchain technology and attribute-based encryption to enhance security and privacy in decentralized data sharing systems, particularly within healthcare. We introduce PAVA, a novel privacy-preserving attribute-based scheme, which leverages smart contracts for verifiable authentication and ensures secure data interactions in healthcare applications. The scheme incorporates dual access policies: a data provider policy and a data user policy, which respectively authorize data providers to write (encrypt) and data users to read (decrypt) health data records. Encrypted health data records are stored on a blockchain within a healthcare smart contract, which enforces these access policies while keeping them confidential from unauthorized users and the smart contract itself. This arrangement allows for verifiable authentication checks on both the data providers (user authentication) and the integrity of the data they submit (data authentication) without revealing specific policy attributes. PAVA employs ciphertext-policy attribute-based encryption with partially hidden access policies based on linear secret sharing schemes (LSSS) and integrates blind access policies to facilitate verifiable authentication. Furthermore, the security of PAVA can be proved using the dual system encryption technique under static assumptions in the standard model, demonstrating its robustness and applicability in real-world healthcare data sharing scenarios.
引用
收藏
页码:346 / 353
页数:8
相关论文
共 50 条
  • [41] On the User Acceptance of Privacy-Preserving Attribute-Based Credentials - A Qualitative Study
    Sabouri, Ahmad
    DATA PRIVACY MANAGEMENT AND SECURITY ASSURANCE, 2016, 9963 : 130 - 145
  • [42] Privacy-Preserving Decentralized Key-Policy Attribute-Based Encryption
    Han, Jinguang
    Susilo, Willy
    Mu, Yi
    Yan, Jun
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2012, 23 (11) : 2150 - 2162
  • [43] Verifiable Privacy-Preserving Payment Mechanism for Smart Grids
    Fan, Chun-, I
    Tseng, Yi-Fan
    Huang, Jheng-Jia
    Chen, Yen-Hao
    Kuo, Hsin-Nan
    INTERNET AND DISTRIBUTED COMPUTING SYSTEMS, 2018, 11226 : 52 - 63
  • [44] Privacy-Preserving Smart Metering with Authentication in a Smart Grid
    Hur, Jun Beom
    Koo, Dong Young
    Shin, Young Joo
    APPLIED SCIENCES-BASEL, 2015, 5 (04): : 1503 - 1527
  • [45] Efficient, Verifiable and Privacy Preserving Decentralized Attribute-Based Encryption for Mobile Cloud Computing
    Lyu, Maoxu
    Li, Xuejun
    Li, Hui
    2017 IEEE SECOND INTERNATIONAL CONFERENCE ON DATA SCIENCE IN CYBERSPACE (DSC), 2017, : 195 - 204
  • [46] Securing IoT-Based Smart Healthcare Systems by Using Advanced Lightweight Privacy-Preserving Authentication Scheme
    Das, Sangjukta
    Namasudra, Suyel
    Deb, Suman
    Moreno Ger, Pablo
    Gonzalez Crespo, Ruben
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (21) : 18486 - 18494
  • [47] An Access Control Scheme With Privacy-Preserving Authentication and Flexible Revocation for Smart Healthcare
    Liang, Xiyu
    Liu, Yali
    Ning, Jianting
    IEEE JOURNAL OF BIOMEDICAL AND HEALTH INFORMATICS, 2024, 28 (06) : 3269 - 3278
  • [48] Killing the Password and Preserving Privacy With Device-Centric and Attribute-Based Authentication
    Papadamou, Kostantinos
    Zannettou, Savvas
    Chifor, Bogdan
    Teican, Sorin
    Gugulea, George
    Caponi, Alberto
    Recupero, Annamaria
    Pisa, Claudio
    Bianchi, Giuseppe
    Steven, Gevers
    Xenakis, Christos
    Sirivianos, Michael
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 2183 - 2193
  • [49] Attribute-Based Privacy-Preserving Data Sharing for Dynamic Groups in Cloud Computing
    Xiong, Hu
    Zhang, Hao
    Sun, Jianfei
    IEEE SYSTEMS JOURNAL, 2019, 13 (03): : 2739 - 2750
  • [50] ATM: Attribute-Based Privacy-Preserving Task Assignment and Incentive Mechanism for Crowdsensing
    Xu, Xiaoru
    Yang, Zhihao
    Xian, Yunting
    IEEE ACCESS, 2021, 9 : 60923 - 60933