Privacy-Preservation Enhanced and Efficient Attribute-Based Access Control for Smart Health in Cloud-Assisted Internet of Things

Hui Yin,Yin Zhu,Hua Deng,Lu Ou,Zheng Qin,Keqin Li
DOI: https://doi.org/10.1109/jiot.2024.3470891
IF: 10.6
2024-01-01
IEEE Internet of Things Journal
Abstract:The deep integration of Internet of Things (IoT) and cloud computing promotes a wide deployment of Body Area Networks (BAN) for smart health services. The data security raises new challenges when patients’ Health Records (HRs) are uploaded into the cloud server by BAN. The Attribute-Based Encryption (ABE) primitive is a potential option to ensure HRs security, which provides the data confidentiality guarantee and fine-grained access control simultaneously via cryptographic means. However, most ABE schemes are unsuitable to be deployed in smart health application as access policies associated with encrypted HRs reveal patient’s privacies. Though the recently proposed ABE with partially hidden access policy based on composite order can alleviate the privacy leakage by only disclosing the attribute names and concealing the practical attribute values, the exposed attribute names still leak individual privacies. In this paper, we put forward a privacy-enhanced and efficient ABE construction with fully hidden access policy over prime order group based on the prominent ABE construction due to Bethencourt et al.. Our scheme hides the sensitive attributes in the access structure by several non-trivial designs without compromising the correctness and security. Moreover, our scheme’s performance is far superior to the attribute partially hidden schemes. Extensive experiments demonstrate the conclusion.
What problem does this paper attempt to address?