Inference Attack-Resistant E-Healthcare Cloud System with Fine-Grained Access Control

被引:13
|
作者
Zhang, Wei [1 ,2 ]
Lin, Yaping [1 ,2 ]
Wu, Jie [3 ]
Zhou, Ting [1 ,2 ]
机构
[1] Hunan Univ, Coll Comp Sci & Elect Engn, Changsha 410082, Peoples R China
[2] Key Lab Trusted Comp & Networks Hunan Prov, Changsha 410082, Peoples R China
[3] Temple Univ, Dept Comp & Informat Sci, 1805 N Broad St, Philadelphia, PA 19122 USA
基金
中国国家自然科学基金;
关键词
Encryption; Access control; Dentistry; Privacy; E-healthcare cloud; electronic healthcare record (EHR); inference attack; fine-grained access control; two-layer encryption;
D O I
10.1109/TSC.2018.2790943
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The e-healthcare cloud system has shown its potential to improve the quality of healthcare and individuals' quality of life. Unfortunately, security and privacy impede its widespread deployment and application. There are several research works focusing on preserving the privacy of the electronic healthcare record (EHR) data. However, these works have two main limitations. First, they only support the 'black or white' access control policy. Second, they suffer from the inference attack. In this paper, for the first time, we design an inference attack-resistant e-healthcare cloud system with fine-grained access control. We first propose a two-layer encryption scheme. To ensure an efficient and fine-grained access control over the EHR data, we design the first-layer encryption, where we devise a specialized access policy for each data attribute in the EHR, and encrypt them individually with high efficiency. To preserve the privacy of role attributes and access policies used in the first-layer encryption, we systematically construct the second-layer encryption. To take full advantage of the cloud server, we propose to let the cloud execute computationally intensive works on behalf of the data user without knowing any sensitive information. To preserve the access pattern of data attributes in the EHR, we further construct a blind data retrieving protocol. We also demonstrate that our scheme can be easily extended to support search functionality. Finally, we conduct extensive security analyses and performance evaluations, which confirm the efficacy and efficiency of our schemes.
引用
收藏
页码:167 / 178
页数:12
相关论文
共 50 条
  • [1] Secure and fine-grained access control on e-healthcare records in mobile cloud computing
    Liu, Yi
    Zhang, Yinghui
    Ling, Jie
    Liu, Zhusong
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 78 : 1020 - 1026
  • [2] Secure Fine-Grained Encrypted Keyword Search for E-Healthcare Cloud
    Wang, Haijiang
    Ning, Jianting
    Huang, Xinyi
    Wei, Guiyi
    Poh, Geong Sen
    Liu, Ximeng
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2021, 18 (03) : 1307 - 1319
  • [3] Flexible and Fine-Grained Access Control for EHR in Blockchain-Assisted E-Healthcare Systems
    Chen, Dajiang
    Zhang, Li
    Liao, Zeyu
    Dai, Hong-Ning
    Zhang, Ning
    Shen, Xuemin
    Pang, Minghui
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (06) : 10992 - 11007
  • [4] FHPT: Fine-Grained EHR Sharing in E-Healthcare Cloud with Hidden Policy and Traceability
    Ying, Zuobin
    Si, Yuanping
    Ma, Jianfeng
    Liu, Ximeng
    Xu, Shengmin
    [J]. 2020 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2020,
  • [5] Towards a fine-grained access control for Cloud
    Msahli, Mounira
    Chen, Xiuzhen
    Serhrouchni, Ahmed
    [J]. 2014 IEEE 11TH INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE), 2014, : 286 - 291
  • [6] Fine-grained access control for cloud computing
    Ye, Xinfeng
    Khoussainov, Bakh
    [J]. INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2013, 4 (2-3) : 160 - 168
  • [7] A blockchain-based fine-grained data sharing scheme for e-healthcare system
    Lin, Gaofan
    Wang, Haijiang
    Wan, Jian
    Zhang, Lei
    Huang, Jie
    [J]. JOURNAL OF SYSTEMS ARCHITECTURE, 2022, 132
  • [8] Access control management for e-Healthcare in cloud environment
    Sun, Lili
    Yong, Jianming
    Soar, Jeffrey
    [J]. EAI ENDORSED TRANSACTIONS ON SCALABLE INFORMATION SYSTEMS, 2014, 1 (02) : 1 - 11
  • [9] Towards a Flexible Fine-Grained Access Control System for Modern Cloud Applications
    Shiftehfar, Reza
    Mechitov, Kirill
    Agha, Gul
    [J]. 2014 IEEE 7TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2014, : 966 - 967
  • [10] Fine-grained Access Control Scheme Based on Cloud Storage
    Niu, Xiaojie
    [J]. 2017 INTERNATIONAL CONFERENCE ON COMPUTER NETWORK, ELECTRONIC AND AUTOMATION (ICCNEA), 2017, : 512 - 515