A secure and efficient CP-ABSC scheme for EHR sharing in MIoT environments
摘要
The emergence of the Medical Internet of Things (MIoT) has facilitated the effective creation and exchange of Electronic Health Records (EHRs) using cloud-based systems. Nevertheless, the risk of outsourcing sensitive medical information to semi-trusted cloud platforms is that the data confidentiality, integrity, and the enforcement of fine-grained access control will be highly questionable. To address these challenges, the cryptographic primitive known as Attribute-Based Signcryption (ABSC) has been introduced to combine encryption and signature capabilities. However, current ABSC schemes are either computationally costly because they require bilinear operations or they use some form of outsourcing (fog or edge server) which adds complexity to the system and assumptions of trust. To mitigate these limitations, the paper presents a safe and effective Ciphertext-Policy Attribute-Based Signcryption (CP-ABSC) protocol that will be used in MIoT-based EHR sharing. The scheme proposed allows access to fine-grained access control through access tree structures and message confidentiality and ciphertext unforgeability under the standard security model. The proposed design, unlike the current methods, removes the dependency on outsourced computation and, therefore, lowers the system dependency and increases the practical deployability. Moreover, the scheme facilitates public verification, which enables users of data to authenticate the authenticity of signcrypted EHR data. Thorough security analysis proves that the given scheme has the desired security properties, such as confidentiality and unforgeability. Moreover, the scheme has been evaluated in terms of computational and communication overhead, which demonstrates that the scheme has a balanced trade-off between efficiency and security. The findings suggest that the suggested CP-ABSC scheme can be used in the context of secure and feasible EHR sharing in MIoT settings.