TY - JOUR
T1 - Subversion-Resistant Autonomous Path Proxy Re-Encryption With Secure Deduplication for IoMT
AU - Chen, Jiasheng
AU - Cao, Zhenfu
AU - Wang, Lulu
AU - Shen, Jiachen
AU - Xiong, Zehui
AU - Dong, Xiaolei
N1 - Publisher Copyright:
© 2013 IEEE.
PY - 2025
Y1 - 2025
N2 - The Internet of Medical Things (IoMT) consists of many resource-constrained medical devices that provide patients with medical services anytime and anywhere. In such an environment, the collection and sharing of medical records raise serious security concerns. Although various cryptographic schemes have been proposed, most fail to address two critical threats simultaneously: (i) sensitive data exposure caused by external cloud servers and/or open network environments; (ii) algorithm substitution attacks (ASAs) by internal adversaries. Furthermore, when data owners (e.g., delegators) are inconvenient to process their data, it is desirable to establish a more fine-grained way to delegate encryption rights. To tackle these issues, we propose a subversion-resistant autonomous path proxy re-encryption with an equality test function (SRAP-PRET). Specifically, our scheme allows the delegator to create a multi-hop delegation path in advance with the delegator's preferences, effectively preventing unauthorized access. By deploying a cryptographic reverse firewall zone, SRAP-PRET addresses the problem of information leakage caused by adversaries initiating ASAs. Additionally, SRAP-PRET also supports secure deduplication and efficient data decryption. Security analysis shows that SRAP-PRET provides resistance against ASAs and security against chosen plaintext attacks. Performance evaluations demonstrate that SRAP-PRET offers enhanced security properties without sacrificing efficiency.
AB - The Internet of Medical Things (IoMT) consists of many resource-constrained medical devices that provide patients with medical services anytime and anywhere. In such an environment, the collection and sharing of medical records raise serious security concerns. Although various cryptographic schemes have been proposed, most fail to address two critical threats simultaneously: (i) sensitive data exposure caused by external cloud servers and/or open network environments; (ii) algorithm substitution attacks (ASAs) by internal adversaries. Furthermore, when data owners (e.g., delegators) are inconvenient to process their data, it is desirable to establish a more fine-grained way to delegate encryption rights. To tackle these issues, we propose a subversion-resistant autonomous path proxy re-encryption with an equality test function (SRAP-PRET). Specifically, our scheme allows the delegator to create a multi-hop delegation path in advance with the delegator's preferences, effectively preventing unauthorized access. By deploying a cryptographic reverse firewall zone, SRAP-PRET addresses the problem of information leakage caused by adversaries initiating ASAs. Additionally, SRAP-PRET also supports secure deduplication and efficient data decryption. Security analysis shows that SRAP-PRET provides resistance against ASAs and security against chosen plaintext attacks. Performance evaluations demonstrate that SRAP-PRET offers enhanced security properties without sacrificing efficiency.
KW - autonomous path delegation
KW - deduplication
KW - IoMT security
KW - Proxy re-encryption
KW - subversion-resistant
UR - https://www.scopus.com/pages/publications/105025668144
U2 - 10.1109/TNSE.2025.3645991
DO - 10.1109/TNSE.2025.3645991
M3 - 文章
AN - SCOPUS:105025668144
SN - 2327-4697
JO - IEEE Transactions on Network Science and Engineering
JF - IEEE Transactions on Network Science and Engineering
ER -