Skip to main content

Research Repository

Advanced Search

Granular Data Access Control with a Patient-Centric Policy Update for Healthcare

Khan, Fawad; Khan, Saad; Tahir, Shahzaib; Ahmad, Jawad; Tahir, Hasan; Shah, Syed Aziz

Authors

Fawad Khan

Saad Khan

Shahzaib Tahir

Hasan Tahir

Syed Aziz Shah



Abstract

Healthcare is a multi-actor environment that requires independent actors to have a different view of the same data, hence leading to different access rights. Ciphertext Policy-Attribute-based Encryption (CP-ABE) provides a one-to-many access control mechanism by defining an attribute’s policy over ciphertext. Although, all users satisfying the policy are given access to the same data, this limits its usage in the provision of hierarchical access control and in situations where different users/actors need to have granular access of the data. Moreover, most of the existing CP-ABE schemes either provide static access control or in certain cases the policy update is computationally intensive involving all non-revoked users to actively participate. Aiming to tackle both the challenges, this paper proposes a patient-centric multi message CP-ABE scheme with efficient policy update. Firstly, a general overview of the system architecture implementing the proposed access control mechanism is presented. Thereafter, for enforcing access control a concrete cryptographic construction is proposed and implemented/tested over the physiological data gathered from a healthcare sensor: shimmer sensor. The experiment results reveal that the proposed construction has constant computational cost in both encryption and decryption operations and generates constant size ciphertext for both the original policy and its update parameters. Moreover, the scheme is proven to be selectively secure in the random oracle model under the q-Bilinear Diffie Hellman Exponent (q-BDHE) assumption. Performance analysis of the scheme depicts promising results for practical real-world healthcare applications.

Citation

Khan, F., Khan, S., Tahir, S., Ahmad, J., Tahir, H., & Shah, S. A. (2021). Granular Data Access Control with a Patient-Centric Policy Update for Healthcare. Sensors, 21(10), Article 3556. https://doi.org/10.3390/s21103556

Journal Article Type Article
Acceptance Date May 13, 2021
Online Publication Date May 20, 2021
Publication Date 2021-05
Deposit Date May 24, 2021
Publicly Available Date May 24, 2021
Journal Sensors
Electronic ISSN 1424-8220
Publisher MDPI
Peer Reviewed Peer Reviewed
Volume 21
Issue 10
Article Number 3556
DOI https://doi.org/10.3390/s21103556
Keywords multi message; hierarchal; policy update; constant computations; constant size ciphertext
Public URL http://researchrepository.napier.ac.uk/Output/2774528

Files

Granular Data Access Control With A Patient-Centric Policy Update For Healthcare (1 Mb)
PDF

Publisher Licence URL
http://creativecommons.org/licenses/by/4.0/

Copyright Statement
This is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.





You might also like



Downloadable Citations