{"title":"An Efficient Medical Records Access Control with Auditable Outsourced Encryption and Decryption","authors":"S. Fugkeaw, Len Wirz, Lyhour Hak","doi":"10.1109/KST57286.2023.10086904","DOIUrl":null,"url":null,"abstract":"Existing access control schemes for IoT-Cloud-based settings generally focus on investigating the fine-grained access featured with the lightweight decryption. However, these requirements are not adequate for sensitive and high volumes of data such as IoT healthcare data that is outsourced in the cloud. In this paper, we proposed a secure, fine-grained, and batch-auditable access control scheme, that supports both lightweight encryption and decryption for outsourced IoT-based electronic medical records (EMRs). Technically, our proposed scheme fully offloads a ciphertext-policy attribute-based (CP-ABE) encryption and decryption to the fog nodes to minimize the communication and computation cost for both data owners and data users. We employed blockchain to store the record’s indices and access transactions and developed smart contracts to automate user authentication and verification. In addition, we developed a ciphertext auditing algorithm to efficiently handle batch auditing. For the evaluation, we conducted comparative experiments to show that our scheme is more efficient than related works.","PeriodicalId":351833,"journal":{"name":"2023 15th International Conference on Knowledge and Smart Technology (KST)","volume":"28 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-02-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 15th International Conference on Knowledge and Smart Technology (KST)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/KST57286.2023.10086904","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
Existing access control schemes for IoT-Cloud-based settings generally focus on investigating the fine-grained access featured with the lightweight decryption. However, these requirements are not adequate for sensitive and high volumes of data such as IoT healthcare data that is outsourced in the cloud. In this paper, we proposed a secure, fine-grained, and batch-auditable access control scheme, that supports both lightweight encryption and decryption for outsourced IoT-based electronic medical records (EMRs). Technically, our proposed scheme fully offloads a ciphertext-policy attribute-based (CP-ABE) encryption and decryption to the fog nodes to minimize the communication and computation cost for both data owners and data users. We employed blockchain to store the record’s indices and access transactions and developed smart contracts to automate user authentication and verification. In addition, we developed a ciphertext auditing algorithm to efficiently handle batch auditing. For the evaluation, we conducted comparative experiments to show that our scheme is more efficient than related works.