计算机科学
计算机网络
撤销
数据共享
对偶(语法数字)
服务器
计算机安全
密码学
秘密分享
数据建模
分布式计算
方案(数学)
数据安全
电子邮件
信息隐私
分布式数据库
认证(法律)
互联网
数据传输
钥匙(锁)
安全多方计算
作者
Lei Mei,Ke Huang,Xiong Li,Hong Wang,Xiaosong Zhang
标识
DOI:10.1109/jiot.2026.3685269
摘要
The Internet of Medical Things (IoMT) enables large-scale sensing and cloud-based sharing of sensitive medical data, where access control must remain fine-grained, dynamic, and robust. In practical healthcare scenarios, access privileges frequently change due to real-world incidents such as physician resignation, role reassignment, emergency response, or patient consent withdrawal, which require both user-level and attribute-level revocation mechanisms. To address these challenges, we propose a Dual Revocable CP-ABE (DABE) scheme that unifies direct and indirect revocation within a single framework, to support diverse medical data sharing scenarios. The proposed system allows data owners to flexibly select revocation modes based on operational needs: indirect revocation efficiently handles large-scale updates for remote medical records via a semi-trusted cloud server, while direct revocation enables immediate access termination through ciphertext updates for highly sensitive data. This dual-mode design improves system robustness and fault tolerance, thus avoiding a single point of failure. Moreover, DABE supports verifiable outsourced decryption to accommodate resource-constrained IoMT devices. Formal security analysis proves IND-CPA security and resistance to collusion attacks, while experimental results demonstrate practical efficiency: the decryption time remains nearly constant (approximately 15–20 ms) regardless of policy complexity, achieving an improvement of over two orders of magnitude compared to existing schemes, with only modest overhead in other phases. These results show that DABE is well-suited for large-scale, dynamic IoMT systems.
科研通智能强力驱动
Strongly Powered by AbleSci AI