Fine-Grained Access Control in mHealth with Hidden Policy and Traceability

被引:1
|
作者
Li, Qi [1 ,2 ]
Zhang, Yinghui [3 ]
Zhang, Tao [4 ]
机构
[1] Nanjing Univ Posts & Telecommun, Sch Comp Sci, Nanjing 210023, Peoples R China
[2] Nanjing Univ Posts & Telecommun, Jiangsu Key Lab Big Data Secur & Intelligent Proc, Nanjing, Peoples R China
[3] Xian Univ Posts & Telecommun, Natl Engn Lab Wireless Secur, Xian 710121, Peoples R China
[4] Xidian Univ, Sch Comp Sci & Technol, Xian 710071, Peoples R China
基金
中国国家自然科学基金;
关键词
CP-ABE; Partially hidden policy; Traceability; Large universe; Adaptive security; ATTRIBUTE-BASED ENCRYPTION; SECURE;
D O I
10.1007/978-3-030-36442-7_17
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is a well-received cryptographic primitive to securely share personal health records (PHRs) in mobile healthcare (mHealth). Nevertheless, traditional CP-ABE can not be directly deployed in mHealth. First, the attribute universe scale is bounded to the system security parameter and lack of scalability. Second, the sensitive data is encrypted, but the access policy is in the plaintext form. Last but not least, it is difficult to catch the malicious user who intentionally leaks his access privilege since that the same attributes mean the same access privilege. In this paper, we propose HTAC, a fine-grained access control scheme with partially hidden policy and white-box traceability. In HTAC, the system attribute universe is larger universe without any redundant restriction. Each attribute is described by an attribute name and an attribute value. The attribute value is embedded in the PHR ciphertext and the plaintext attribute name is clear in the access policy. Moreover, the malicious user who illegally leaks his (partial or modified) private key could be precisely traced. The security analysis and performance comparison demonstrate that HTAC is secure and practical for mHealth applications.
引用
收藏
页码:261 / 274
页数:14
相关论文
共 50 条
  • [1] HTAC: Fine-Grained Policy-Hiding and Traceable Access Control in mHealth
    Li, Qi
    Zhang, Yinghui
    Zhang, Tao
    Huang, Haiping
    He, Yingjie
    Xiong, Jinbo
    [J]. IEEE ACCESS, 2020, 8 : 123430 - 123439
  • [2] Access policy sheet for access control in fine-grained XML
    Wu, J
    Mu, Y
    Seberry, J
    Ruan, C
    [J]. EMBEDDED AND UBIQUITOUS COMPUTING - EUC 2005 WORKSHOPS, PROCEEDINGS, 2005, 3823 : 1273 - 1282
  • [3] Fine-grained cooperative access control scheme with hidden policies
    Han Gang
    Xing Qixuan
    Zhang Yinghui
    [J]. The Journal of China Universities of Posts and Telecommunications, 2021, 28 (06) : 13 - 25
  • [4] Fine-grained cooperative access control scheme with hidden policies
    Gang, Han
    Qixuan, Xing
    Yinghui, Zhang
    [J]. Journal of China Universities of Posts and Telecommunications, 2021, 28 (06): : 13 - 25
  • [5] Using XACML for Embedded and Fine-Grained Access Control Policy
    Hsieh, George
    Foster, Keith
    Emamali, Gerald
    Patrick, Gregory
    Marvel, Lisa
    [J]. 2009 INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY (ARES), VOLS 1 AND 2, 2009, : 462 - +
  • [6] FHPT: Fine-Grained EHR Sharing in E-Healthcare Cloud with Hidden Policy and Traceability
    Ying, Zuobin
    Si, Yuanping
    Ma, Jianfeng
    Liu, Ximeng
    Xu, Shengmin
    [J]. 2020 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2020,
  • [7] Fine-grained multi-authority access control in IoT-enabled mHealth
    Qi Li
    Hongbo Zhu
    Jinbo Xiong
    Ruo Mo
    Zuobin Ying
    Huaqun Wang
    [J]. Annals of Telecommunications, 2019, 74 : 389 - 400
  • [8] Fine-grained multi-authority access control in IoT-enabled mHealth
    Li, Qi
    Zhu, Hongbo
    Xiong, Jinbo
    Mo, Ruo
    Ying, Zuobin
    Wang, Huaqun
    [J]. ANNALS OF TELECOMMUNICATIONS, 2019, 74 (7-8) : 389 - 400
  • [9] Reliable Policy Updating Under Efficient Policy Hidden Fine-Grained Access Control Framework for Cloud Data Sharing
    Ying, Zuobin
    Jiang, Wenjie
    Liu, Ximeng
    Xu, Shengmin
    Deng, Robert H.
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2022, 15 (06) : 3485 - 3498
  • [10] Fine-Grained Access Control for Microservices
    Nehme, Antonio
    Jesus, Vitor
    Mahbub, Khaled
    Abdallah, Ali
    [J]. FOUNDATIONS AND PRACTICE OF SECURITY, FPS 2018, 2019, 11358 : 285 - 300