Cargando…

Granular Data Access Control with a Patient-Centric Policy Update for Healthcare

Healthcare is a multi-actor environment that requires independent actors to have a different view of the same data, hence leading to different access rights. Ciphertext Policy-Attribute-based Encryption (CP-ABE) provides a one-to-many access control mechanism by defining an attribute’s policy over c...

Descripción completa

Detalles Bibliográficos
Autores principales: Khan, Fawad, Khan, Saad, Tahir, Shahzaib, Ahmad, Jawad, Tahir, Hasan, Shah, Syed Aziz
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2021
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8161120/
https://www.ncbi.nlm.nih.gov/pubmed/34065312
http://dx.doi.org/10.3390/s21103556
_version_ 1783700436865253376
author Khan, Fawad
Khan, Saad
Tahir, Shahzaib
Ahmad, Jawad
Tahir, Hasan
Shah, Syed Aziz
author_facet Khan, Fawad
Khan, Saad
Tahir, Shahzaib
Ahmad, Jawad
Tahir, Hasan
Shah, Syed Aziz
author_sort Khan, Fawad
collection PubMed
description Healthcare is a multi-actor environment that requires independent actors to have a different view of the same data, hence leading to different access rights. Ciphertext Policy-Attribute-based Encryption (CP-ABE) provides a one-to-many access control mechanism by defining an attribute’s policy over ciphertext. Although, all users satisfying the policy are given access to the same data, this limits its usage in the provision of hierarchical access control and in situations where different users/actors need to have granular access of the data. Moreover, most of the existing CP-ABE schemes either provide static access control or in certain cases the policy update is computationally intensive involving all non-revoked users to actively participate. Aiming to tackle both the challenges, this paper proposes a patient-centric multi message CP-ABE scheme with efficient policy update. Firstly, a general overview of the system architecture implementing the proposed access control mechanism is presented. Thereafter, for enforcing access control a concrete cryptographic construction is proposed and implemented/tested over the physiological data gathered from a healthcare sensor: shimmer sensor. The experiment results reveal that the proposed construction has constant computational cost in both encryption and decryption operations and generates constant size ciphertext for both the original policy and its update parameters. Moreover, the scheme is proven to be selectively secure in the random oracle model under the q-Bilinear Diffie Hellman Exponent (q-BDHE) assumption. Performance analysis of the scheme depicts promising results for practical real-world healthcare applications.
format Online
Article
Text
id pubmed-8161120
institution National Center for Biotechnology Information
language English
publishDate 2021
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-81611202021-05-29 Granular Data Access Control with a Patient-Centric Policy Update for Healthcare Khan, Fawad Khan, Saad Tahir, Shahzaib Ahmad, Jawad Tahir, Hasan Shah, Syed Aziz Sensors (Basel) Article Healthcare is a multi-actor environment that requires independent actors to have a different view of the same data, hence leading to different access rights. Ciphertext Policy-Attribute-based Encryption (CP-ABE) provides a one-to-many access control mechanism by defining an attribute’s policy over ciphertext. Although, all users satisfying the policy are given access to the same data, this limits its usage in the provision of hierarchical access control and in situations where different users/actors need to have granular access of the data. Moreover, most of the existing CP-ABE schemes either provide static access control or in certain cases the policy update is computationally intensive involving all non-revoked users to actively participate. Aiming to tackle both the challenges, this paper proposes a patient-centric multi message CP-ABE scheme with efficient policy update. Firstly, a general overview of the system architecture implementing the proposed access control mechanism is presented. Thereafter, for enforcing access control a concrete cryptographic construction is proposed and implemented/tested over the physiological data gathered from a healthcare sensor: shimmer sensor. The experiment results reveal that the proposed construction has constant computational cost in both encryption and decryption operations and generates constant size ciphertext for both the original policy and its update parameters. Moreover, the scheme is proven to be selectively secure in the random oracle model under the q-Bilinear Diffie Hellman Exponent (q-BDHE) assumption. Performance analysis of the scheme depicts promising results for practical real-world healthcare applications. MDPI 2021-05-20 /pmc/articles/PMC8161120/ /pubmed/34065312 http://dx.doi.org/10.3390/s21103556 Text en © 2021 by the authors. https://creativecommons.org/licenses/by/4.0/Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Khan, Fawad
Khan, Saad
Tahir, Shahzaib
Ahmad, Jawad
Tahir, Hasan
Shah, Syed Aziz
Granular Data Access Control with a Patient-Centric Policy Update for Healthcare
title Granular Data Access Control with a Patient-Centric Policy Update for Healthcare
title_full Granular Data Access Control with a Patient-Centric Policy Update for Healthcare
title_fullStr Granular Data Access Control with a Patient-Centric Policy Update for Healthcare
title_full_unstemmed Granular Data Access Control with a Patient-Centric Policy Update for Healthcare
title_short Granular Data Access Control with a Patient-Centric Policy Update for Healthcare
title_sort granular data access control with a patient-centric policy update for healthcare
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8161120/
https://www.ncbi.nlm.nih.gov/pubmed/34065312
http://dx.doi.org/10.3390/s21103556
work_keys_str_mv AT khanfawad granulardataaccesscontrolwithapatientcentricpolicyupdateforhealthcare
AT khansaad granulardataaccesscontrolwithapatientcentricpolicyupdateforhealthcare
AT tahirshahzaib granulardataaccesscontrolwithapatientcentricpolicyupdateforhealthcare
AT ahmadjawad granulardataaccesscontrolwithapatientcentricpolicyupdateforhealthcare
AT tahirhasan granulardataaccesscontrolwithapatientcentricpolicyupdateforhealthcare
AT shahsyedaziz granulardataaccesscontrolwithapatientcentricpolicyupdateforhealthcare