Secure collaborative EHR Sharing using multi-authority attribute-based proxy re-encryption in Web 3.0
【Author】 Duan, Pengfei; Gao, Hongmin; Shen, Yushi; Guo, Zhetao; Ma, Zhaofeng; Tian, Tian; Zhang, Yuqing
【Source】COMPUTER NETWORKS
【影响因子】5.493
【Abstract】Web 3.0 represents a transformative shift toward a decentralized, intelligent, and user-centric Internet. Existing electronic health record (EHR) sharing systems depend on centralized cloud servers for storage and management, with hospitals serving as primary custodians. This centralization often results inpatients losing control and visibility over their EHR data, including who accesses it and how it is utilized, which contradicts the decentralized principles of Web 3.0. In this context, we propose a multi-authority attribute-based proxy re-encryption scheme that facilitates collaborative EHR sharing in Web 3.0. Our design allows the updating of ciphertext policies, thereby eliminating the need for frequent re-encryption of plaintext data amid varying cross-domain access policies. Furthermore, our scheme utilizes blockchain technology to create a decentralized and transparent environment that enables traceable cross-domain EHR sharing records. Additionally, we integrate hybrid encryption with decentralized data hosting platforms, significantly reducing the on-chain storage burden. The use of smart contracts automates the cross-domain EHR sharing and guarantees a fair distribution of benefits among all participants. Security analysis confirms that our scheme is secure against chosen plaintext attacks and resistant to collusion. Performance analysis and simulation experiments validate the efficiency and robustness of our scheme.
【Keywords】Web 3.0; Cross-domain EHR sharing; Multi-authority attribute-based; Proxy re-encryption; Access control; Patient-centric; Security
【发表时间】2024 DEC
【收录时间】2024-10-31
【文献类型】案例研究
【主题类别】
区块链应用-虚拟经济-Web3
Zach
这篇论文研究了一种新型的电子健康记录(EHR)共享系统,旨在适应Web 3.0的去中心化、智能化和用户中心化的特点。现有的EHR共享系统依赖于中心化的云服务器进行存储和管理,医院作为主要保管者,这种中心化往往导致患者失去对其EHR数据的控制和可见性,包括谁可以访问数据以及数据如何被使用,这与Web 3.0的去中心化原则相矛盾。为了解决这一问题,研究人员提出了一种多权限属性基于代理重加密的方案,该方案支持跨域EHR的协作共享。设计允许更新密文策略,从而消除了在不同跨域访问策略下频繁重新加密明文数据的需要。此外,方案利用区块链技术创建了一个去中心化和透明的环境,使得EHR共享记录可追溯。研究还集成了混合加密和去中心化数据托管平台,显著减少了链上存储负担。智能合约的应用自动化跨域EHR共享过程,并确保所有参与者公平分配利益。安全分析确认该方案能够抵御选择明文攻击,并对合谋具有抵抗力。性能分析和模拟实验验证了该方案的效率和鲁棒性。
回复