SSL-XIoMT:安全,可扩展,轻量级跨域IoMT共享与SSI和ZKP认证

Lyhour Hak;Somchart Fugkeaw
{"title":"SSL-XIoMT:安全,可扩展,轻量级跨域IoMT共享与SSI和ZKP认证","authors":"Lyhour Hak;Somchart Fugkeaw","doi":"10.1109/OJCS.2025.3570087","DOIUrl":null,"url":null,"abstract":"The Internet of Medical Things (IoMT) is transforming healthcare by enabling devices to generate and share critical patient data. However, securely sharing this data across different healthcare entities remains a significant challenge due to concerns over privacy and security. Traditional solutions using Ciphertext Policy Attribute-Based Encryption (CP-ABE), Self-Sovereign Identity (SSI), and Zero-Knowledge Proofs (ZKPs) offer secure and anonymous data access, but they often fall short in scalability and integration, particularly in cross domain environments. To address these limitations, we introduce SSL-XIoMT, an optimized SSI and ZKP authentication framework within a consortium Hyperledger-based environment. This innovative system integrates SSI under advanced Zero-Knowledge Scalable Transparent Argument of Knowledge (ZK-STARK) and Plonk protocols within a consortium Hyperledger framework for privacy-preserving identity verification. We enhance identity privacy by integrating Multi-Party Computation (MPC), ensuring that identity credentials and ZKP proofs are securely shared and reconstructed without exposing sensitive information. Additionally, we optimize CP-ABE by offloading complex computations to fog nodes, which pre-compute attributes and logical operations. This approach significantly reduces computational overhead and enhances both privacy and efficiency. Our extensive analysis shows that SSL-XIoMT dramatically improves the performance of processing time for CP-ABE encryption and decryption compared to current methods. Moreover, our hybrid ZKPs based authentication approach outperforms the existing schemes regarding processing time and flexibility. The throughput test also demonstrates that SSL-XIoMT is practical for large scale cross-domain data sharing implementation.","PeriodicalId":13205,"journal":{"name":"IEEE Open Journal of the Computer Society","volume":"6 ","pages":"714-725"},"PeriodicalIF":0.0000,"publicationDate":"2025-03-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=11003572","citationCount":"0","resultStr":"{\"title\":\"SSL-XIoMT: Secure, Scalable, and Lightweight Cross-Domain IoMT Sharing With SSI and ZKP Authentication\",\"authors\":\"Lyhour Hak;Somchart Fugkeaw\",\"doi\":\"10.1109/OJCS.2025.3570087\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The Internet of Medical Things (IoMT) is transforming healthcare by enabling devices to generate and share critical patient data. However, securely sharing this data across different healthcare entities remains a significant challenge due to concerns over privacy and security. Traditional solutions using Ciphertext Policy Attribute-Based Encryption (CP-ABE), Self-Sovereign Identity (SSI), and Zero-Knowledge Proofs (ZKPs) offer secure and anonymous data access, but they often fall short in scalability and integration, particularly in cross domain environments. To address these limitations, we introduce SSL-XIoMT, an optimized SSI and ZKP authentication framework within a consortium Hyperledger-based environment. This innovative system integrates SSI under advanced Zero-Knowledge Scalable Transparent Argument of Knowledge (ZK-STARK) and Plonk protocols within a consortium Hyperledger framework for privacy-preserving identity verification. We enhance identity privacy by integrating Multi-Party Computation (MPC), ensuring that identity credentials and ZKP proofs are securely shared and reconstructed without exposing sensitive information. Additionally, we optimize CP-ABE by offloading complex computations to fog nodes, which pre-compute attributes and logical operations. This approach significantly reduces computational overhead and enhances both privacy and efficiency. Our extensive analysis shows that SSL-XIoMT dramatically improves the performance of processing time for CP-ABE encryption and decryption compared to current methods. Moreover, our hybrid ZKPs based authentication approach outperforms the existing schemes regarding processing time and flexibility. The throughput test also demonstrates that SSL-XIoMT is practical for large scale cross-domain data sharing implementation.\",\"PeriodicalId\":13205,\"journal\":{\"name\":\"IEEE Open Journal of the Computer Society\",\"volume\":\"6 \",\"pages\":\"714-725\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2025-03-14\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=11003572\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"IEEE Open Journal of the Computer Society\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://ieeexplore.ieee.org/document/11003572/\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Open Journal of the Computer Society","FirstCategoryId":"1085","ListUrlMain":"https://ieeexplore.ieee.org/document/11003572/","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

医疗物联网(IoMT)通过使设备能够生成和共享关键的患者数据,正在改变医疗保健行业。然而,由于对隐私和安全的担忧,在不同的医疗保健实体之间安全地共享这些数据仍然是一个重大挑战。使用密文策略基于属性的加密(CP-ABE)、自主身份(SSI)和零知识证明(zkp)的传统解决方案提供安全和匿名的数据访问,但它们通常在可扩展性和集成方面存在不足,特别是在跨域环境中。为了解决这些限制,我们引入了SSL-XIoMT,这是一个基于超级账本的财团环境中优化的SSI和ZKP身份验证框架。这个创新的系统将SSI集成在先进的零知识可扩展透明知识论证(ZK-STARK)和Plonk协议下,在一个财团超级账本框架内进行隐私保护身份验证。我们通过集成多方计算(MPC)来增强身份隐私,确保身份凭证和ZKP证明在不暴露敏感信息的情况下安全地共享和重建。此外,我们通过将复杂的计算卸载到雾节点来优化CP-ABE,雾节点可以预先计算属性和逻辑操作。这种方法显著降低了计算开销,增强了隐私性和效率。我们的广泛分析表明,与当前方法相比,SSL-XIoMT显著提高了CP-ABE加密和解密的处理时间性能。此外,我们基于zkp的混合身份验证方法在处理时间和灵活性方面优于现有方案。吞吐量测试也证明了SSL-XIoMT对于大规模跨域数据共享的实现是可行的。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
SSL-XIoMT: Secure, Scalable, and Lightweight Cross-Domain IoMT Sharing With SSI and ZKP Authentication
The Internet of Medical Things (IoMT) is transforming healthcare by enabling devices to generate and share critical patient data. However, securely sharing this data across different healthcare entities remains a significant challenge due to concerns over privacy and security. Traditional solutions using Ciphertext Policy Attribute-Based Encryption (CP-ABE), Self-Sovereign Identity (SSI), and Zero-Knowledge Proofs (ZKPs) offer secure and anonymous data access, but they often fall short in scalability and integration, particularly in cross domain environments. To address these limitations, we introduce SSL-XIoMT, an optimized SSI and ZKP authentication framework within a consortium Hyperledger-based environment. This innovative system integrates SSI under advanced Zero-Knowledge Scalable Transparent Argument of Knowledge (ZK-STARK) and Plonk protocols within a consortium Hyperledger framework for privacy-preserving identity verification. We enhance identity privacy by integrating Multi-Party Computation (MPC), ensuring that identity credentials and ZKP proofs are securely shared and reconstructed without exposing sensitive information. Additionally, we optimize CP-ABE by offloading complex computations to fog nodes, which pre-compute attributes and logical operations. This approach significantly reduces computational overhead and enhances both privacy and efficiency. Our extensive analysis shows that SSL-XIoMT dramatically improves the performance of processing time for CP-ABE encryption and decryption compared to current methods. Moreover, our hybrid ZKPs based authentication approach outperforms the existing schemes regarding processing time and flexibility. The throughput test also demonstrates that SSL-XIoMT is practical for large scale cross-domain data sharing implementation.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
12.60
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信