Non-interactive revocable identity-based access control over e-healthcare records

  • Yunya Zhou
  • , Jianwei Liu
  • , Hua Deng
  • , Bo Qin
  • , Lei Zhang

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Scopus citations

Abstract

Revocation of access control on private e-healthcare records (EHRs) allows to revoke the access rights of valid users. Most existing solutions rely on a trusted third party too much to generate and update decryption keys, or require the computations of non-revoked users during the revocation, which make them impractical for some more complicated scenarios. In this paper, we propose a new revocation model, referred to as non-interactive revocable identity-based access control (NRIBAC) on EHRs. In NRIBAC, a trusted third party only needs to generate secret keys for group authorities and each group authority can generate decryption keys for the users in its domain. The NRIBAC distinguishes itself from other revocation schemes by the advantageous feature that it does not require any participation of non-revoked users in the revocation. We construct an NRIBAC scheme with short ciphertexts and decryption keys by leveraging hierarchical identity-based encryption and introducing the version information. We formally prove the security of the NRIBAC scheme and conduct thorough theoretical analysis to evaluate the performance. The results reveal that the scheme provides favorable revocation procedure without disturbing non-revoked users.

Original languageEnglish
Title of host publicationInformation Security Practice and Experience - 11th International Conference, ISPEC 2015, Proceedings
EditorsJavier Lopez, Yongdong Wu
PublisherSpringer Verlag
Pages485-498
Number of pages14
ISBN (Print)9783319175324
DOIs
StatePublished - 2015
Event11th International Conference on Information Security Practice and Experience, ISPEC 2015 - Beijing, China
Duration: 5 May 20158 May 2015

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume9065
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference11th International Conference on Information Security Practice and Experience, ISPEC 2015
Country/TerritoryChina
CityBeijing
Period5/05/158/05/15

Keywords

  • E-healthcare records
  • Identity-based access control
  • Non-interaction
  • Revocation

Fingerprint

Dive into the research topics of 'Non-interactive revocable identity-based access control over e-healthcare records'. Together they form a unique fingerprint.

Cite this