Secure Access Control for Ehealth Data in Emergency Rescue Case Based on Traceable Attribute-Based Encryption

Yuan Shen,Wei Song,Changsheng Zhao,Zhiyong Peng
DOI: https://doi.org/10.1109/trustcom56396.2022.00037
2022-01-01
Abstract:With the development of cloud computing, patients can obtain efficient and high-quality medical services by uploading their eHealth data to the cloud for sharing among medical personnel. Because eHealth data contain lots of sensitive information, they are always encrypted before uploading to protect patients’ privacy. Ciphertext-policy attribute-based encryption (CP-ABE) is a commonly used cryptographic primitive since it achieves fine-grained and one-to-many access control on the encrypted data. However, encrypted eHealth data may become an obstacle for some healthcare scenarios, especially the emergency rescue scenes. In addition, the one-to-many access manner makes the traditional CP-ABE mechanism hard to track the identity of a traitor who sells the decryption privilege to others. In this paper, we propose an Emergency Access Control and Traceable (EmACT) attribute-based encryption scheme to address these issues. In addition, EmACT outsources the heavy bilinear computations of the decryption to the cloud, which means that EmACT is adaptable to the resource-constrained health-monitoring devices. The proposed scheme’s security is formally proven, and the experimental results demonstrate that EmACT is efficient and practicable.
What problem does this paper attempt to address?