Patient-centric medical service matching with fine-grained access control and dynamic user management

Shu Wu,Aiqing Zhang,Ya Gao,Xiaojuan Xie
DOI: https://doi.org/10.1016/j.csi.2024.103833
IF: 3.721
2024-01-21
Computer Standards & Interfaces
Abstract:Personal health records (PHR) offer significant benefit for patients, such as reducing medical cost and improving the quality of medical care. Majority of the current schemes lack provisions for tracking and revoking malicious doctors. The explicit access policies are prone to leaking patient private information. What's more, owning to the uneven distribution of medical supplies, shocking computational overhead during decryption is a burden that can't be ignored for busy medical workers. This paper proposed a patient-centric medical service matching scheme that supports policy hiding, attribute matching, fine-grained access control, and user dynamic management. The scheme uses ciphertext policy-based attribute encryption (CP-ABE) to achieve fine-grained access control and supports policy hiding. It utilizes white-box tracking technology and binary tree structure to achieve malicious doctor tracking. Revocation information is ciphertext to achieve dynamic management of doctors. From the experimental results, it can be concluded that our protocol achieves both patient-centric security and performance advantages.
computer science, software engineering, hardware & architecture
What problem does this paper attempt to address?