信息网络安全 ›› 2023, Vol. 23 ›› Issue (5): 85-94.doi: 10.3969/j.issn.1671-1122.2023.05.009

• 技术研究 • 上一篇    下一篇

EHR系统中一种验证外包加密数据正确性的访问控制方案

张晓旭, 石润华()   

  1. 华北电力大学控制与计算机工程学院,北京 102206
  • 收稿日期:2022-12-10 出版日期:2023-05-10 发布日期:2023-05-15
  • 通讯作者: 石润华 E-mail:rhshi@ncepu.edu.cn
  • 作者简介:张晓旭(1998—),女,天津,硕士研究生,主要研究方向为访问控制、数据完整性检测|石润华(1974—),男,安徽,教授,博士,主要研究方向为量子信息安全
  • 基金资助:
    国家自然科学基金(61772001)

An Access Control Scheme for Verifying the Correctness of Outsourcing Encrypted Data in EHR System

ZHANG Xiaoxu, SHI Runhua()   

  1. School of Control and Computer Engineering, North China Electric Power University, Beijing 102206, China
  • Received:2022-12-10 Online:2023-05-10 Published:2023-05-15
  • Contact: SHI Runhua E-mail:rhshi@ncepu.edu.cn

摘要:

为了满足人们对远程医疗服务日益增长的需求,近年来电子医疗记录(EHR)系统很受欢迎。数据所有者可以通过移动设备将EHR上传到云服务器以获取数据共享。然而,EHR系统可能存在隐私泄露的风险。基于属性的加密(ABE)为数据的安全共享提供了一个良好的解决方案。通常移动设备计算能力有限,ABE的复杂加密操作实现较为困难。因此,文章将繁重的加密操作分配给边缘服务器(ES)。然而,ES可能会遭到攻击,因此检查ES是否正确加密了明文至关重要。文章提出一种基于零知识证明的双外包轻量级的验证方案,检查ES中数据的正确性。为了防止EHR信息泄露给不诚实的ES,文章将区块链与混合加密相结合,以实现更加安全的数据共享。实验结果表明,该方案是安全有效的,且计算效率更高。

关键词: 边缘计算, 访问控制, EHR系统, 零知识证明, 数据正确性

Abstract:

To meet the growing demand for telemedicine services, electronic health record (EHR) systems have become popular in recent years. Data owners can upload EHRs to the cloud for data sharing via mobile devices. However, there can be privacy breaches in EHR systems. Attribute-based encryption (ABE) provided a good solution for the secure sharing of data. Usually, mobile devices have limited computing power and it is very difficult to implement the complex encryption operations of ABE. Therefore, this paper assigned heavy encryption operations to the edge server (ES). However, the ES could be subject to attacks. It was crucial to check whether the ES encrypts the correct plaintext. This paper proposed a double-outsourced lightweight verification scheme based on zero-knowledge proofs to check the correctness of the data in the ES. To prevent EHR information from being leaked to dishonest ESs, this paper combined blockchain with hybrid encryption for more secure data sharing. Experimental results show that the proposed scheme is effective.

Key words: edge computing, access control, EHR systems, zero-knowledge proof, data correctness

中图分类号: