127
Views
4
CrossRef citations to date
0
Altmetric
Information Engineering

Secure and efficient access of personal health record: a group-oriented ciphertext-policy attribute-based encryption

, , , , &
Pages 80-86 | Received 20 Aug 2017, Accepted 15 Oct 2018, Published online: 10 Jan 2019
 

ABSTRACT

The personal health record (PHR) service is a promising model for health data exchange. In practice, however, users’ health data need to be stored in an untrusted cloud server, which requires the design of a mechanism to achieve secure data sharing. Although the traditional attribute-based encryption (ABE) can be employed to facilitate PHR sharing with confidentiality protection, it will become powerless when confronting certain case. For instance, this happens when the health data is encrypted under (‘ophthalmologist’ AND ‘dermatologist’) AND (‘chief physician’). The ciphertext cannot be successfully decrypted in the scenario if there is no doctor who is a specialist in both dermatology and ophthalmology, Motivated by this observation, we propose a group-oriented ciphertext-policy ABE, which classifies users into different groups. Specifically, users in the same group own the same group identifier and different users can combine their attributes to complete the decryption. The decryption operation can be completed successfully when the union of their attributes satisfies the Access Control Policy (ACP) involved in the ciphertext. Additionally, we propose a concrete scheme with a constant ciphertext size, which is independent of the count of attributes in the ACP. Our security analysis shows that the proposed scheme is secure against selective chosen-plaintext attack under the decisional n-BDHE assumption.

Disclosure statement

No potential conflict of interest was reported by the authors.

Additional information

Funding

This work was supported by the National Natural Science Foundation of China [grant number 61363006]; National Natural Science Foundation of Guangxi [grant number 2016GXNSFAA380098]; and Science and Technology Program of Guangxi [grant number AB17195045].

Reprints and Corporate Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

To request a reprint or corporate permissions for this article, please click on the relevant link below:

Academic Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

Obtain permissions instantly via Rightslink by clicking on the button below:

If you are unable to obtain permissions via Rightslink, please complete and submit this Permissions form. For more information, please visit our Permissions help page.