BAA: A Novel Decentralized Authorization System for Privacy-Sensitive Medical Data

Cong Zha,Yulei Wu,Zexun Jiang,Wenqian Zhao,Hao Yin
DOI: https://doi.org/10.1109/trustcom60117.2023.00155
2024-01-01
Abstract:Data authorization is the basis for the orderly sharing of medical data. Most of the applied decentralized authorization mechanisms rely on blockchain, but face the problems of privacy leakage and low efficiency. To solve these problems, we design a policy-driven decentralized authorization system named BAA, which protects user's behavior privacy in medical data sharing and improves efficiency of both on-chain and off-chain. In order to achieve these goals, BAA uses authorization tokens to represent permissions, protects privacy of the authorization process through hiding user behaviors, realizes batch data accessing by proposing a two-tier Merkle tree, and saves authorization data in a two-tier blockchain to improve on-chain efficiency. Extensive experimental results show that the overhead of cryptographic operations in BAA is acceptable compared to that in traditional authorization systems. In addition, throughput and latency of each operation in BAA can meet the efficiency needs of medical data authorization. The results also show that the preset authorization in blockchain is effective for reducing data user's waiting time and improving the efficiency of authorization.
What problem does this paper attempt to address?