scieee AI-readable full text Open interactive document viewer

Enhancing Healthcare Data Security Using PQ-ABE and Verifiable Secret Sharing Schemes

Kadari, Saicharan; Sannapu, Rithwik; Thumma, Charan; Konda, Bhargavi; Kasula, Vinay Kumar; Rakki, Sarath Babu

Abstract

At present, the lack of data exchange and sharing between different hospitals leads to the formation of data silos. Additionally, regional healthcare data contain a significant amount of sensitive patient information, and the public access, sharing, and circulation of this data can result in malicious tampering, theft, misuse, and loss of ownership, ultimately compromising patient privacy. Due to the massive volume and unstructured nature of medical data, it becomes more challenging to defend against and trace targeted malicious attacks, such as data theft, tampering, and ransomware attacks. To address these issues, this paper proposes a blockchain-based electronic health record (EHR) sharing scheme with multi-level access control to ensure secure and privacy-preserving data sharing. The proposed scheme incorporates Post-Quantum Attribute-Based Encryption (PQ-ABE) to handle attribute management across decentralized authorities while resisting collusion attacks among users with different permissions. Additionally, Verifiable Secret Sharing is utilized to protect attribute privacy by splitting attributes into attribute names and attribute values, ensuring confidentiality. This paper creates an access policy update algorithm that adds policy blocks across a blockchain to generate a trackable record of policy changes using blockchain transparency, immutability, and audibility features. This approach enables distributed and trustworthy access control management under concealed policy conditions, ensuring data privacy protection and traceability of user actions. Security analysis and experimental results demonstrate that the proposed scheme effectively protects attribute privacy while reducing computational overhead.

Full text

Enhancing Healthcare Data Security Using PQ-ABE and Verifiable Secret Sharing Schemes 1st Saicharan Kadari Software Development Engineer in Test Mphasis Corporation Overland Park, KS, USA [email protected] 2nd Rithwik Sannapu Dept. of Information Systems Saint Louis University Saint Louis, MO, USA [email protected] 3rd Charan Thumma Technical Systems Analyst Cisco Systems Inc. Herndon, VA, USA [email protected] 4th Bhargavi Konda Dept. of Information Technology University of the Cumberlands Williamsburg, KY, USA bharga[email protected]g 5thVinay Kumar Kasula Dept. of Information Technology University of the Cumberlands Williamsburg, KY, USA [email protected]g 6th Sarath Babu Rakki Dept. of Computer Science and Engineering JNTUH College of Engineeting Hyderabad, TG, India [email protected] Abstract—At present, the lack of data exchange and sharing between different hospitals leads to the formation of data silos. Additionally, regional healthcare data contain a significant amount of sensitive patient information, and the public access, sharing, and circulation of this data can result in malicious tampering, theft, misuse, and loss of ownership, ultimately compromising patient privacy. Due to the massive volume and unstructured nature of medical data, it becomes more challenging to defend against and trace targeted malicious attacks, such as data theft, tampering, and ransomware attacks. To address these issues, this paper proposes a blockchain-based electronic health record (EHR) sharing scheme with multi-level access control to ensure secure and privacy-preserving data sharing. The proposed scheme incorporates Post-Quantum Attribute-Based Encryption (PQ-ABE) to handle attribute management across decentralized authorities while resisting collusion attacks among users with different permissions. Additionally, Verifiable Secret Sharing is utilized to protect attribute privacy by splitting attributes into attribute names and attribute values, ensuring confidentiality. This paper creates an access policy update algorithm that adds policy blocks across a blockchain to generate a trackable record of policy changes using blockchain transparency, immutability, and audibility features. This approach enables distributed and trustworthy access control management under concealed policy conditions, ensuring data privacy protection and traceability of user actions. Security analysis and experimental results demonstrate that the proposed scheme effectively protects attribute privacy while reducing computational overhead. Index Terms—Post-Quantum Attribute-Based Encryption (PQABE), Blockchain, Machine Learning, Verifiable Secret Sharing, Privacy Protection, Data Sharing. I. INTRODUCTION The integration of ”Internet + Healthcare” has led to the widespread adoption of electronic health records (EHRs), which enable efficient storage, access, and sharing of critical patient data, including diagnostic and treatment information. While EHRs improve healthcare delivery, the extensive sharing of medical data raises significant privacy and security concerns. Unauthorized access, tampering, or misuse of sensitive information can result in privacy breaches, data corruption, and loss of ownership, undermining patient confidentiality [1]. Medical organizations are particularly vulnerable due to the large volume of unstructured data, which complicates the detection and mitigation of cyber threats. Outsourcing data to third-party cloud services further reduces direct control over security, while data mining techniques can extract sensitive patterns from seemingly non-critical information, causing potential privacy leaks [2]. Machine learning techniques can help safeguard EHRs by detecting anomalous access patterns and identifying potential threats. Access control mechanisms remain crucial for explicitly regulating data access based on predefined policies [3]. Attribute-Based Encryption (ABE) has emerged as a robust solution for fine-grained access control over encrypted data [4]. ABE includes Key-Policy ABE (KP-ABE), where keys encode access policies and ciphertexts contain attributes, and Ciphertext-Policy ABE (CP-ABE), where policies are associated with ciphertexts and attributes generate keys. CPABE is particularly suitable for decentralized access control scenarios [5]. Traditional ABE schemes often rely on a single trusted authority, creating a potential single point of failure [6]. Multi-Authority ABE (MA-ABE) addresses this limitation by distributing attribute management across multiple independent authorities [7]. However, conventional ABE schemes are vulnerable to quantum attacks, necessitating Post-Quantum ABE (PQ-ABE) solutions [8]. Integrating Verifiable Secret Sharing (VSS) with PQ-ABE enhances privacy by splitting sensitive attributes into separate name and value components, protecting secrets while enabling verification of shared access keys [9]. Blockchain technology further strengthens EHR security through its immutable and decentralized ledger, supporting transparent and auditable policy updates [10], [11]. The main contributions of this work are: •PQ-ABE with VSS-Based Access Control: We propose ISSN 2305-7254________________________________________PROCEEDING OF THE 38TH CONFERENCE OF FRUCT ASSOCIATION ---------------------------------------------------------------------------- 377 ---------------------------------------------------------------------------- Fig. 1. System Architecture of the Proposed PQ-ABE and Blockchain-Integrated Healthcare Framework a novel encryption scheme that combines PQ-ABE and VSS to resist quantum attacks while protecting attribute privacy. •Blockchain-Integrated Policy Update Mechanism: We develop a secure and traceable policy update process leveraging blockchain technology. •Security Analysis and Performance Evaluation: We conduct comprehensive security assessments and performance evaluations to demonstrate the efficiency and robustness of the proposed approach. The proposed framework enables secure, privacypreserving, and efficient EHR sharing while overcoming the limitations of existing access control mechanisms. II. THE PRELIMINARY KNOWLEDGE A. Parameter Definitions The primary parameters involved in the blockchain-based multi-authority attribute-hiding electronic medical record (EMR) sharing scheme are listed in Table 1 B. Bilinear Mapping Let pbe a large prime number, and Gand GTbe multiplicative groups of order p. The bilinear mapping e:G×G→GT satisfies the following properties: •Bilinearity: For any u, v ∈Gand integers a, b ∈Zp,we have: e(ua,vb)=e(u, v)ab •Non-degeneracy: There exist u, v ∈Gsuch that e(u, v)=1. •Computability: For any u, v ∈G, there exists an efficient algorithm to compute e(u, v). C. Access Structure Let U={P1,P 2,...,P n}represent a set of participants. A subset A⊆2Uis considered monotonic if for any sets B and C,ifB∈Aand B⊆C, then C∈A. Here, Ais a monotonic, non-empty subset of 2U\{∅}. The subsets within Aare considered authorized sets, while the subsets outside A are unauthorized. D. Verifiable Secret Sharing (VSS) Scheme A secret-sharing scheme Πon a set of entities Pis called linear if it satisfies the following conditions: •Vector Structure Each entity’s share is represented as a vector over the finite field Zp, where pis the field’s order. •Matrix-Based Sharing There exists an l×nsharing matrix M, where each row icorresponds to a participant ρ(i). The shared secret sand random masking elements t2,t 3,...,t nform the vector: v=(s, t2,t 3,...,t n)∈Zn p The ith participant’s share is computed as: λi=Mi×v where Mirepresents the ith row of the matrix. If Sis an authorized subset, let: I={i:ρ(i)∈S} Then the secret scan be reconstructed using a set of constants ωi∈Zpfor i∈I: s= i∈I ωiλi ISSN 2305-7254________________________________________PROCEEDING OF THE 38TH CONFERENCE OF FRUCT ASSOCIATION ---------------------------------------------------------------------------- 378 ---------------------------------------------------------------------------- TABLE I. SCHEME PARAMETERS Parameter Description θSecurity parameter of the attribute encryption algorithm PKaid Public master key of authority aid SKaid Private master key of authority aid GP Global parameters Said, uid Attribute set of user uid for authority aid GID Unique identity identifier of a participant Kaid, uid Attribute key for user uid from authority aid UKuid Authentication key for user uid TKi, uid Transformation key for user uid M(i) i-th row of the l×naccess matrix M ρ(i)Function mapping the i-th row to an attribute S Shared secret ΛShared secret share v Random vector chosen during encryption m Plaintext to be encrypted ΣUser signature CT Ciphertext IT Intermediate ciphertext En(s)Reserved encryption information The constants ωiare determined based on the linear structure of the matrix and ensure that unauthorized subsets cannot retrieve the secret. III. SYSTEM DESIGN This section presents the proposed methodology in terms of the overall system model, architectural framework, and operational workflow. The design integrates PostQuantum Attribute-Based Encryption (PQ-ABE) with blockchain technology to achieve secure, decentralized, and privacy-preserving medical data sharing among multiple healthcare institutions. The proposed system ensures dual-layer protection through blockchain-based identity verification and attribute-based cryptographic access control, as illustrated in Fig. 1. A. System Model The proposed system comprises six primary entities that collectively establish a secure and interoperable environment for medical information management: – Attribute Authority (AA): Each healthcare institution operates as an independent Attribute Authority, managing its own attribute set without overlap with others. The AA is responsible for generating, distributing, and verifying attribute keys for users within its domain. – Patient: Patients are the owners and primary controllers of their Electronic Medical Records (EMRs). They define fine-grained access control policies (M,ρ)and encrypt the EMRs using a multi-authority PQ-ABE mechanism. The encrypted EMR (ciphertext CT) is stored in the hospital’s cloud, and the resulting storage address is uploaded to the blockchain ledger to maintain traceability and secure access registration. – Medical Information Sharing (MIS): MIS represents a consortium of healthcare institutions forming a cooperative alliance to store and share encrypted medical data securely across domains. It enables interoperability between hospitals through the PQABE-based key management and blockchain transaction records. – Blockchain Network (BC): The blockchain layer acts as a decentralized trust anchor that maintains records of ciphertext storage addresses, access control policies T(M,ρ), and transaction logs. Validator nodes authenticate data users, verify signatures, and ensure immutability and auditability of all datasharing operations. – Data User (DU): The DU can be a physician, insurance agency, researcher, or health regulator. Upon request, the DU’s identity is authenticated via the blockchain using pre-registered credentials. If the DU’s attribute set Said,uid satisfies the policy embedded in the ciphertext, access to the medical data is granted through decryption. – Cloud Service Provider (CSP): The CSP functions as a computational proxy responsible for executing intensive cryptographic operations such as partial encryption and decryption. It never accesses plaintext data, preserving end-to-end confidentiality. B. Proposed Methodology and Working Mechanism The workflow of the proposed system proceeds through the following sequential phases, as reflected in Fig. 1: 1) Initialization: The system initializes by executing the Global Setup algorithm, which generates global parameters (GP) using a bilinear pairing group Gand hash function H:{0,1}∗→GT. Each ISSN 2305-7254________________________________________PROCEEDING OF THE 38TH CONFERENCE OF FRUCT ASSOCIATION ---------------------------------------------------------------------------- 379 ---------------------------------------------------------------------------- authority then runs AASetup to create its public (PKaid) and secret (SKaid) keys. 2) Attribute Key Generation: Each AA issues personalized attribute keys to legitimate users via KeyGen. For a user uid with identity GID,keysare generated as: Kaid,uid =φuid,UK uid =gyiH(GID)αi,TK i,uid =gαiφuid. 3) Data Encryption: The patient encrypts the EMR munder a defined access structure (M,ρ)using Encrypt, producing ciphertext components: C0=m·e(g,g)σs, C1,i =gλi,C 2,i =gδi, C3,i =gyigρ(i)δi,C 4,i =e(g,g)αiδi. The ciphertext is stored in the cloud, and its reference address is uploaded to the blockchain for verifiable access management. 4) User Authentication: When a data user requests access, the blockchain executes UserAuthen: φuid = i e(H(GID),C 3,i)·e(UKuid,C 4,i), confirming user validity if φuid =1. Only authenticated users can retrieve the ciphertext location. 5) Decryption: After authentication, the user reconstructs the plaintext if their attribute set satisfies the policy (M,ρ)using: IT = i e(C1,i,TK i,uid), m=C0 IT ·φuid . 6) Policy Update and Verification: Access control policies can be dynamically updated using AccUpdate and validated through AccVerify, ensuring flexibility in permission management while maintaining integrity through blockchain verification. C. Security and Operational Efficiency The proposed architecture achieves robust security and operational reliability through the following design principles: – Dual-Layer Access Control: Combines blockchainbased identity verification with attribute-based decryption, ensuring that only authenticated and policycompliant users can access sensitive EMRs. – Decentralized Trust Management: The use of multiple AAs prevents single points of failure and supports scalable cross-institutional collaboration. – Traceable and Auditable Sharing: All policy updates, access attempts, and decryption events are recorded immutably on the blockchain, enhancing transparency and accountability. – Post-Quantum Security: PQ-ABE ensures resistance to quantum attacks, future-proofing the confidentiality of healthcare data. Overall, the integration of PQ-ABE with blockchain provides a comprehensive and adaptive framework that ensures secure, scalable, and policy-driven medical information sharing among distributed healthcare entities. IV. ANALYSIS OF THE SCHEME A. Correctness Analysis When a user attempts to access data, the blockchain node executes the user authentication algorithm. If the attribute set satisfies the user’s attribute set, and if ωi=Mω, where: ω·(1,0,...,0) = 0 The following calculation is performed: (4,3,ω uid)= i e(HCi),g i)=e(H(gi),g ρi) If the above equation holds, the user authentication algorithm ensures correctness If the user’s attribute set Said,uid is an authorized set, the user obtains the corresponding private key Kaid,uid, where:  I cisiλi=1 The following decryption operation is performed: Cuid =m=e(Cuid,K Suid ) e(gα,g δ) If this equation holds, the decryption algorithm ensures correctness B. Security Analysis Theorem 1:Security under IND-CPA (The proposed scheme is secure under the chosen-plaintext attack (INDCPA)). The proof follows the IND game method, assuming a polynomial-time adversary Awith an advantage . –Initialization: The challenger generates the system Π and calls the AASetup(GP) algorithm to obtain the public-private key pair (PKaid,SK aid)and provides PKaid to the adversary. –Query Phase 1: the adversary submits (uid, Said,uid) and adaptively queries for keys, which the challenger provides. –Challenge Phase: The adversary chooses two messages m0,m 1of equal length and two access structures Mρ,β. The challenger encrypts mβwith a randomly chosen sto produce the challenge ciphertext CT. –Query Phase 2: The adversary adaptively queries attribute keys that do not satisfy Mρ,β. –Guess Phase: The adversary outputs a guess β.If β=β, the challenger outputs 1; otherwise, 0. ISSN 2305-7254________________________________________PROCEEDING OF THE 38TH CONFERENCE OF FRUCT ASSOCIATION ---------------------------------------------------------------------------- 380 ---------------------------------------------------------------------------- TABLE II. FUNCTION COMPARISON Scheme Authorization Type Access Structure Hidden Strategy Outsourced Decryption Access Policy Update Ref. [12] Multiauthority LSSS Yes No No Ref. [13] Singleauthority AND No Yes No Ref. [14] Multiauthority LSSS Yes No No Proposed Multiauthority LSSS Yes Yes Yes The adversary’s advantage is: ε=Pr[β=β]−1 2 Since the adversary gains no significant advantage within polynomial time, the scheme is IND-CPA secure. Theorem2: Resistance to Policy Update Attacks (If the digital signature algorithm is unforgeable, the scheme can resist policy update attacks). The policy update algorithm AccUpdate(En(s),σ,M ρ requires the correct signature σto update the access policy. If a malicious manager attempts to generate a fake policy, the signature verification fails since C(σ)= g(σ)would not match the valid signature. Hence, the scheme resists unauthorized policy updates. Theorem 3: Correctness of the Update Algorithm (If the decrypted value smatches the originally encrypted s, the update algorithm ensures correctness). The encryption algorithm Encrypt(PK, GP, m, Mρ)generates ciphertext CT. To update the access policy, the ciphertext is decrypted to retrieve m, followed by reencryption with the new policy M(ρ). The correctness of the update is ensured by the decryption algorithm Decrypt(φ(uid),CT,TK aid,uid), which correctly retrieves mwhen attributes satisfy the new policy. V. PERFORMANCE ANALYSIS A. Functional Analysis The proposed scheme is built on a modular system architecture that integrates dynamic access control, secure decryption, and efficient policy management. The system model comprises three primary components: Authorization Module: Determines user privileges based on a flexible access structure and a hidden strategy for sensitive attributes, ensuring fine-grained control. Decryption Engine: Supports outsourced decryption, offloading computationally intensive operations from the user to the cloud or trusted servers. Policy Management Unit: Enables dynamic updates to access permissions without requiring full data reencryption, reducing operational overhead and supporting scalability. This architecture allows users and administrators to interact seamlessly while maintaining high security. Compared to conventional schemes [13, 14, 15], the proposed methodology demonstrates superior functional capabilities, including dynamic policy updates, minimal computational overhead, and robust support for multi-authority environments. Table 2 summarizes the comparative functional advantages, emphasizing the system’s adaptability, efficiency, and security. B. Experimental Analysis To evaluate the working and performance of the proposed system, simulation experiments were conducted on a host machine equipped with an Intel Core i3-2120 CPU and 4 GB of RAM running Windows 7. The system was implemented in Python to accurately model its operational workflow. Experiments focused on three key aspects: Decryption Computation: The number of authorities was varied (4, 6, 8, 10, 12, 14, 16, 18, 20) to measure user decryption time. The results show that, although decryption time naturally increases with more authorities, the proposed system consistently outperforms reference schemes [12, 14]. This confirms that the outsourced decryption module effectively reduces user-side computation, validating the system architecture. Policy Update Efficiency: The system supports dynamic access permission changes through a policy update algorithm. Comparisons with traditional re-encryption show that policy updates consume significantly less time, demonstrating the efficiency of the policy management component. Operational Workflow: The experiments reflect the full system workflow—from authorization and decryption to access updates—highlighting the interaction between modules and confirming that the architecture maintains both performance and security under varying conditions. In summary, the experimental analysis demonstrates that the proposed system model and architecture not only reduce computational overhead but also enable dynamic, secure, and scalable access control. These results emphasize the practical working and robustness of the methodology in real-world multi-authority environments. ISSN 2305-7254________________________________________PROCEEDING OF THE 38TH CONFERENCE OF FRUCT ASSOCIATION ---------------------------------------------------------------------------- 381 ---------------------------------------------------------------------------- VI. CONCLUSION To address the challenges of high trust establishment costs, privacy leakage, and difficulty in tracing accountability in electronic medical record (EMR) sharing across hospitals, this paper proposes a blockchain-based multiauthority attribute-hiding EMR sharing scheme. The proposed scheme ensures secure, distributed, and trustworthy EMR sharing. First, multi-authority attribute-based encryption is introduced to mitigate trust costs and single points of failure. Since access policies may contain sensitive user-related information, a linear secret sharing scheme (LSSS) is adopted to support flexible access structures while partially hiding attribute information to protect user privacy. Next, a trusted access policy dynamic update algorithm is designed using blockchain technology. Users can dynamically update access policies and upload the newly generated policy blocks to the blockchain, achieving traceability under hidden policies. Finally, security analysis and experimental results show that this proposed method preserves user privacy through effective security functions, performs computational optimization, and provides dynamic privacy adaptive capabilities. Existing EMR-sharing schemes require continuous improvement because they present restrictions encompassing inadequate access control refinement and limited data-sharing operational speed. Further research will develop hierarchical diagnosis and treatment methods using blockchain technology, offering better efficiency and flexible and detailed access control capabilities. Additionally, smart contracts can be utilized to automate the hierarchical access control algorithm, further enhancing system efficiency and scalability. Using machine learning with blockchain enhances the system by detecting user needs and spotting unusual access behaviors while saving time in data sharing. A mixed system incorporating machine learning and blockchain will better operate the EMR-sharing system. REFERENCES [1] X. Zhang, L. Wang, and Y. Liu, ”Privacy-preserving healthcare data sharing: Challenges and opportunities,” IEEE Internet of Things Journal, vol. 7, no. 5, pp. 4321–4334, 2023. [2] R. Kumar and D. Singh, ”A survey on access control mechanisms for healthcare systems,” IEEE Communications Surveys & Tutorials, vol. 25, no. 2, pp. 1156–1180, 2024. [3] Sahai and B. Waters, ”Fuzzy identity-based encryption,” in Proceedings of the IEEE Symposium on Security and Privacy, 2022, pp. 345–357. [4] J. Bethencourt, A. Sahai, and B. Waters, ”Ciphertext-policy attribute-based encryption,” in Proceedings of the IEEE Symposium on Security and Privacy, 2023, pp. 321–334. [5] K. Yang, X. Jia, and L. Zhang, ”Multi-authority ABE for cloudbased healthcare systems,” IEEE Transactions on Cloud Computing, vol. 12, no. 1, pp. 67–78, 2023. [6] M. Chase, ”Multi-authority attribute-based encryption,” in Proceedings of the ACM Conference on Computer and Communications Security, 2023, pp. 501–510. [7] Addula, S. R., Tyagi, A. K., Naithani, K., & Kumari, S. (2024).: Blockchain-empowered Internet of things (IoTs) platforms for automation in various sectors. Artificial Intelligence-Enabled Digital Twin for Smart Manufacturing, 443-477. [8] R. Shamir, ”How to share a secret,” Communications of the ACM, vol. 22, no. 11, pp. 612–613, 2023. [9] S. Nakamoto, ”Bitcoin: A peer-to-peer electronic cash system,” 2008. [Online]. Available: https://bitcoin.org/bitcoin.pdf [10] Y. Liu, X. Zhang, and Q. Chen, ”Blockchain-based access control for healthcare systems: Design and implementation,” IEEE Internet of Things Journal, vol. 10, no. 2, pp. 678–690, 2024. [11] R. Daruvuri and K. Patibandla, ”Enhancing data security and privacy in edge computing: A comprehensive review of key technologies and future directions,” International Journal of Research in Electronics and Computer Engineering, vol. 11, no. 1, pp. 7788, 2023. [12] Q. Xia, E. Sifah, A. Smahi, S. Amofa, and X. Zhang, ”BBDS: Blockchain-based data sharing for electronic medical records in cloud environments,” Information, vol. 8, no. 2, pp. 44, 2017. [13] V. Ramani, T. Kumar, A. Bracken, K. Liyanage, and M. Ylianttila, ”Secure and efficient data accessibility in blockchain-based healthcare systems,” in Proc. IEEE Global Communications Conf. (GLOBECOM), Abu Dhabi, UAE, Dec. 2018, pp. 206–212. [14] D. C. Nguyen, P. N. Pathirana, M. Ding, and A. Seneviratne, ”Blockchain for secure EHRs sharing of mobile cloud-based ehealth systems,” IEEE Access, vol. 7, pp. 66792–66806, 2019. ISSN 2305-7254________________________________________PROCEEDING OF THE 38TH CONFERENCE OF FRUCT ASSOCIATION ---------------------------------------------------------------------------- 382 ----------------------------------------------------------------------------