Fine-Grained Access Control in mHealth with Hidden Policy and Traceability

被引:1
|
作者
Li, Qi [1 ,2 ]
Zhang, Yinghui [3 ]
Zhang, Tao [4 ]
机构
[1] Nanjing Univ Posts & Telecommun, Sch Comp Sci, Nanjing 210023, Peoples R China
[2] Nanjing Univ Posts & Telecommun, Jiangsu Key Lab Big Data Secur & Intelligent Proc, Nanjing, Peoples R China
[3] Xian Univ Posts & Telecommun, Natl Engn Lab Wireless Secur, Xian 710121, Peoples R China
[4] Xidian Univ, Sch Comp Sci & Technol, Xian 710071, Peoples R China
基金
中国国家自然科学基金;
关键词
CP-ABE; Partially hidden policy; Traceability; Large universe; Adaptive security; ATTRIBUTE-BASED ENCRYPTION; SECURE;
D O I
10.1007/978-3-030-36442-7_17
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is a well-received cryptographic primitive to securely share personal health records (PHRs) in mobile healthcare (mHealth). Nevertheless, traditional CP-ABE can not be directly deployed in mHealth. First, the attribute universe scale is bounded to the system security parameter and lack of scalability. Second, the sensitive data is encrypted, but the access policy is in the plaintext form. Last but not least, it is difficult to catch the malicious user who intentionally leaks his access privilege since that the same attributes mean the same access privilege. In this paper, we propose HTAC, a fine-grained access control scheme with partially hidden policy and white-box traceability. In HTAC, the system attribute universe is larger universe without any redundant restriction. Each attribute is described by an attribute name and an attribute value. The attribute value is embedded in the PHR ciphertext and the plaintext attribute name is clear in the access policy. Moreover, the malicious user who illegally leaks his (partial or modified) private key could be precisely traced. The security analysis and performance comparison demonstrate that HTAC is secure and practical for mHealth applications.
引用
收藏
页码:261 / 274
页数:14
相关论文
共 50 条
  • [21] Fine-grained access control policy in blockchain-enabled edge computing
    He, Guangxuan
    Li, Chunlin
    Shu, Yong
    Luo, Youlong
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2024, 221
  • [22] Fine-Grained Access Control via XACML Policy Optimization in Cloud Computing
    Pei, Xin
    Yu, Huiqun
    Fan, Guisheng
    [J]. INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 2015, 25 (9-10) : 1709 - 1714
  • [23] Combined access control model embedding configurable policy for fine-grained data security
    Zhu, Lei
    He, Ping
    Hei, Xinhong
    Yao, Yanni
    Wang, Yichuan
    Ji, Wenjiang
    Zhao, Qin
    Pan, Long
    [J]. MICROPROCESSORS AND MICROSYSTEMS, 2020, 75
  • [24] An implementation design of a fine-grained database access control policy consistency checking mechanism
    Purevjii, Bat-Odon
    Aritsugi, Masayoshi
    Imai, Sayaka
    Kanamori, Yoshinari
    [J]. KNOWLEDGE-BASED INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS: KES 2007 - WIRN 2007, PT II, PROCEEDINGS, 2007, 4693 : 752 - 760
  • [25] Declarative Cartography under Fine-Grained Access Control
    Jensen, Thomas
    Salles, Marcos Antonio Vaz
    Bang, Michael Vindahl
    [J]. 30TH INTERNATIONAL CONFERENCE ON SCIENTIFIC AND STATISTICAL DATABASE MANAGEMENT (SSDBM 2018), 2018,
  • [26] The Fine-Grained Security Access Control of Spatial Data
    Ma, Fuguang
    Gao, Yong
    Yan, Menglong
    Xu, Fuchun
    Liu, Ding
    [J]. 2010 18TH INTERNATIONAL CONFERENCE ON GEOINFORMATICS, 2010,
  • [27] Fine-grained access control for GridFTP using SecPAL
    Humphrey, Marty
    Park, Sang-Min
    Feng, Jun
    Beekwilder, Nonn
    Wassor, Glenn
    Hogg, Jason
    LaMacchia, Brian
    Dillaway, Blair
    [J]. 2007 8TH IEEE/ACM INTERNATIONAL CONFERENCE ON GRID COMPUTING, 2007, : 185 - +
  • [28] Key-Policy Weighted Attribute Based Encryption for Fine-Grained Access Control
    Liu, Ximeng
    Zhu, Hui
    Ma, Jianfeng
    Ma, Jun
    Ma, Siqi
    [J]. 2014 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (ICC), 2014, : 694 - 699
  • [29] Towards a Fine-Grained Access Control Mechanism for Privacy Protection and Policy Conflict Resolution
    Ha Xuan Son
    Chen, En
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2019, 10 (02) : 507 - 516
  • [30] Fine-grained Access Control Model Based on RBAC
    Gao, Lei
    Pan, Shulin
    [J]. AUTOMATION EQUIPMENT AND SYSTEMS, PTS 1-4, 2012, 468-471 : 1667 - +