物联网医疗设备的可追溯和多权威CP-ABE方案

IF 4.6 2区 计算机科学 Q1 COMPUTER SCIENCE, HARDWARE & ARCHITECTURE
Yiran Zhang, Huizheng Geng, Li Su, Shen He, Fang Liu
{"title":"物联网医疗设备的可追溯和多权威CP-ABE方案","authors":"Yiran Zhang,&nbsp;Huizheng Geng,&nbsp;Li Su,&nbsp;Shen He,&nbsp;Fang Liu","doi":"10.1016/j.comnet.2025.111754","DOIUrl":null,"url":null,"abstract":"<div><div>The Internet of Things (IoT) is rapidly transforming healthcare, enabling real-time monitoring and intelligent services. However, secure and accountable data sharing in such settings remains challenging due to stringent privacy requirements and the limited computing capabilities of IoT medical devices. Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is widely used for fine-grained access control, and its multi-authority variant (MCP-ABE) enhances scalability by allowing decentralized attribute management. While recent works have explored traceability in MCP-ABE, most existing schemes remain too computationally heavy for practical deployment on constrained medical devices. To overcome this issue, we propose a traceable multi-authority CP-ABE scheme specifically tailored for IoT healthcare environments. The scheme introduces an IoT-aware lightweight decryption framework, where a locally deployed Data User Assistant performs all pairing-based computations and delivers a partially decrypted result to the user. Unlike traditional outsourced decryption, our scheme requires the user to encrypt only the key not the full dataset and avoids any ciphertext re-encryption. In the final decryption phase, the user device completes only a single exponentiation, reducing the decryption complexity from multiple pairing operations to a minimal computation load. This design substantially lowers the burden on user devices, making the scheme practically deployable in real-world medical IoT systems. Furthermore, our scheme integrates traceability into a decentralized multi-authority structure, supporting white-box accountability under the LRSW assumption while preserving collaborative key management and user privacy. Performance evaluation demonstrates its efficiency and suitability for resource-constrained healthcare scenarios.</div></div>","PeriodicalId":50637,"journal":{"name":"Computer Networks","volume":"273 ","pages":"Article 111754"},"PeriodicalIF":4.6000,"publicationDate":"2025-10-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"A traceable and multi-authority CP-ABE scheme for IoT medical devices\",\"authors\":\"Yiran Zhang,&nbsp;Huizheng Geng,&nbsp;Li Su,&nbsp;Shen He,&nbsp;Fang Liu\",\"doi\":\"10.1016/j.comnet.2025.111754\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><div>The Internet of Things (IoT) is rapidly transforming healthcare, enabling real-time monitoring and intelligent services. However, secure and accountable data sharing in such settings remains challenging due to stringent privacy requirements and the limited computing capabilities of IoT medical devices. Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is widely used for fine-grained access control, and its multi-authority variant (MCP-ABE) enhances scalability by allowing decentralized attribute management. While recent works have explored traceability in MCP-ABE, most existing schemes remain too computationally heavy for practical deployment on constrained medical devices. To overcome this issue, we propose a traceable multi-authority CP-ABE scheme specifically tailored for IoT healthcare environments. The scheme introduces an IoT-aware lightweight decryption framework, where a locally deployed Data User Assistant performs all pairing-based computations and delivers a partially decrypted result to the user. Unlike traditional outsourced decryption, our scheme requires the user to encrypt only the key not the full dataset and avoids any ciphertext re-encryption. In the final decryption phase, the user device completes only a single exponentiation, reducing the decryption complexity from multiple pairing operations to a minimal computation load. This design substantially lowers the burden on user devices, making the scheme practically deployable in real-world medical IoT systems. Furthermore, our scheme integrates traceability into a decentralized multi-authority structure, supporting white-box accountability under the LRSW assumption while preserving collaborative key management and user privacy. Performance evaluation demonstrates its efficiency and suitability for resource-constrained healthcare scenarios.</div></div>\",\"PeriodicalId\":50637,\"journal\":{\"name\":\"Computer Networks\",\"volume\":\"273 \",\"pages\":\"Article 111754\"},\"PeriodicalIF\":4.6000,\"publicationDate\":\"2025-10-09\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Computer Networks\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S1389128625007200\",\"RegionNum\":2,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"COMPUTER SCIENCE, HARDWARE & ARCHITECTURE\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Computer Networks","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S1389128625007200","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, HARDWARE & ARCHITECTURE","Score":null,"Total":0}
引用次数: 0

摘要

物联网(IoT)正在迅速改变医疗保健,实现实时监控和智能服务。然而,由于严格的隐私要求和物联网医疗设备有限的计算能力,在这种环境中安全可靠的数据共享仍然具有挑战性。基于密文策略属性的加密(CP-ABE)广泛用于细粒度访问控制,其多权威变体(MCP-ABE)通过允许分散的属性管理来增强可伸缩性。虽然最近的工作已经探索了MCP-ABE的可追溯性,但大多数现有方案对于在受限医疗设备上的实际部署来说,计算量仍然太大。为了克服这个问题,我们提出了一种专门为物联网医疗保健环境量身定制的可跟踪的多权威CP-ABE方案。该方案引入了一个物联网感知的轻量级解密框架,其中本地部署的数据用户助理执行所有基于配对的计算,并向用户提供部分解密的结果。与传统的外包解密不同,我们的方案只要求用户加密密钥而不是整个数据集,并且避免了任何密文的重新加密。在最后的解密阶段,用户设备只完成一次幂运算,从而将解密复杂性从多个配对操作降低到最小的计算负载。该设计大大降低了用户设备的负担,使该方案可在实际医疗物联网系统中实际部署。此外,我们的方案将可追溯性集成到分散的多权威结构中,支持LRSW假设下的白盒问责制,同时保留协作密钥管理和用户隐私。性能评估证明了其在资源受限的医疗保健场景中的效率和适用性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A traceable and multi-authority CP-ABE scheme for IoT medical devices
The Internet of Things (IoT) is rapidly transforming healthcare, enabling real-time monitoring and intelligent services. However, secure and accountable data sharing in such settings remains challenging due to stringent privacy requirements and the limited computing capabilities of IoT medical devices. Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is widely used for fine-grained access control, and its multi-authority variant (MCP-ABE) enhances scalability by allowing decentralized attribute management. While recent works have explored traceability in MCP-ABE, most existing schemes remain too computationally heavy for practical deployment on constrained medical devices. To overcome this issue, we propose a traceable multi-authority CP-ABE scheme specifically tailored for IoT healthcare environments. The scheme introduces an IoT-aware lightweight decryption framework, where a locally deployed Data User Assistant performs all pairing-based computations and delivers a partially decrypted result to the user. Unlike traditional outsourced decryption, our scheme requires the user to encrypt only the key not the full dataset and avoids any ciphertext re-encryption. In the final decryption phase, the user device completes only a single exponentiation, reducing the decryption complexity from multiple pairing operations to a minimal computation load. This design substantially lowers the burden on user devices, making the scheme practically deployable in real-world medical IoT systems. Furthermore, our scheme integrates traceability into a decentralized multi-authority structure, supporting white-box accountability under the LRSW assumption while preserving collaborative key management and user privacy. Performance evaluation demonstrates its efficiency and suitability for resource-constrained healthcare scenarios.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
Computer Networks
Computer Networks 工程技术-电信学
CiteScore
10.80
自引率
3.60%
发文量
434
审稿时长
8.6 months
期刊介绍: Computer Networks is an international, archival journal providing a publication vehicle for complete coverage of all topics of interest to those involved in the computer communications networking area. The audience includes researchers, managers and operators of networks as well as designers and implementors. The Editorial Board will consider any material for publication that is of interest to those groups.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信