Lavida: Large-Universe, Verifiable, and Dynamic Fine-Grained Access Control for E-Health Cloud

被引:0
|
作者
Zhao, Jun [1 ]
Zhang, Kai [2 ]
Gong, Junqing [1 ]
Qian, Haifeng [1 ]
机构
[1] East China Normal Univ, Software Engn Inst, Shanghai 200062, Peoples R China
[2] Shanghai Univ Elect Power, Coll Comp Sci & Technol, Shanghai 201306, Peoples R China
基金
中国国家自然科学基金;
关键词
Cryptography; Access control; Hospitals; Systems architecture; Software engineering; Privacy; Encryption; E-health cloud; attribute-based proxy re-encryption; large-universe; partially hidden policy; verifiability; PROXY RE-ENCRYPTION; SECURE;
D O I
10.1109/TIFS.2024.3350925
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Electronic healthcare (E-health) cloud system enables electronic health records (EHRs) sharing and improves efficiency of diagnosis and treatment. In order to address EHRs confidentiality and authorized user access control in E-health cloud, attribute-based proxy re-encryption (ABPRE) has been widely employed which provides dynamic fine-grained access control over encrypted EHRs. Unfortunately, existing ABPRE schemes still have the following defects: 1) capacity of attribute-universe is defined at setup; 2) verifiable mechanism for re-encryption reveals EHRs about patients; 3) traditional access policy reveals sensitive information pertaining to patients. This paper focuses on these issues and presents large-universe, verifiable and privacy-preserving dynamic fine-grained access control scheme for E-health cloud. More details, we solve limitation of attribute-universe to large-universe, which means that attributes aren't required to be enumerated at setup. Considering disclosure of underlying EHRs in verifiable mechanism, scheme introduces non-interactive zero-knowledge proof as verifiable mechanism that supports public validation and doesn't leak EHRs of patients. Furthermore, partially hidden policy is employed to protect privacy of patients in policy, which divides attribute into attribute name and attribute value, displaying attribute name and hiding attribute value. Finally, experimental evaluation is given that demonstrates the more comprehensive functionality of our scheme without sacrificing significant computational overhead.
引用
收藏
页码:2732 / 2745
页数:14
相关论文
共 50 条
  • [1] Fine-grained and Efficient Access Control in E-health Environment
    Miao, Tiantian
    Shen, Jian
    Jin, Xin
    Lai, Jin-Feng
    [J]. JOURNAL OF INTERNET TECHNOLOGY, 2019, 20 (07): : 2169 - 2176
  • [2] Fine-grained Access Control Scheme Supporting Cloud-assisted Write Permission Control in Cloud-aided E-Health System
    He, Kai
    Wang, Ziqi
    Shi, Jiaoli
    Deng, Anyuan
    Lv, Shunlin
    [J]. International Journal of Network Security, 2022, 24 (03) : 457 - 468
  • [3] Dynamic Fine-Grained Access Control in e-Health Using the Secure SQL Server System as an Enabler of the Future Internet
    Paulin, Alois
    Thuemmler, Christoph
    [J]. 2016 IEEE 18TH INTERNATIONAL CONFERENCE ON E-HEALTH NETWORKING, APPLICATIONS AND SERVICES (HEALTHCOM), 2016, : 245 - 248
  • [4] Towards a fine-grained access control for Cloud
    Msahli, Mounira
    Chen, Xiuzhen
    Serhrouchni, Ahmed
    [J]. 2014 IEEE 11TH INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE), 2014, : 286 - 291
  • [5] Fine-grained access control for cloud computing
    Ye, Xinfeng
    Khoussainov, Bakh
    [J]. INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2013, 4 (2-3) : 160 - 168
  • [6] Fine-grained Access Control for Personal Health Records in Cloud Computing
    Li, Wei
    Ni, Wei
    Liu, Dongxi
    Liu, Ren Ping
    Wang, Peishun
    Luo, Shoushan
    [J]. 2017 IEEE 85TH VEHICULAR TECHNOLOGY CONFERENCE (VTC SPRING), 2017,
  • [7] Secure Fine-Grained Access Control and Data Sharing for Dynamic Groups in the Cloud
    Xu, Shengmin
    Yang, Guomin
    Mu, Yi
    Deng, Robert H.
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2018, 13 (08) : 2101 - 2113
  • [8] A Fine-Grained and Dynamic Access Control Model for Smart Home in Cloud Environment
    Xie, Pengshou
    Zhang, Pengyun
    Feng, Tao
    Zhang, Minghu
    Li, Xiaoye
    Qi, Linge
    [J]. International Journal of Network Security, 2023, 25 (06) : 970 - 982
  • [9] A flexible fine-grained dynamic access control approach for cloud computing environment
    Saima Mehraj
    M. Tariq Banday
    [J]. Cluster Computing, 2021, 24 : 1413 - 1434
  • [10] A flexible fine-grained dynamic access control approach for cloud computing environment
    Mehraj, Saima
    Banday, M. Tariq
    [J]. CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2021, 24 (02): : 1413 - 1434