Revocable Outsourcing Multi-Authority ABE for Medical Data in Mobile Cloud
Arthur Sandor Voundi Koe, Juan Tang, Shan Ai, Hongyang Yan, Shiwen Zhang · 2021
With the improvements in mobile healthcare em-boldened by the ubiquity of mobile devices, personal health records are increasingly being outsourced to remote servers to enjoy customer-centric health services. Multi-authority ciphertext-policy attribute-based encryption has been proposed and adopted mainly in recent years, thanks to its flexibility, to guarantee data security, privacy, and fine-grained access control over distant cloud data. However, its practicality still faces three main drawbacks: key escrow, high encryption, and decryption costs, and finally, improper implementation of user and attribute revocations. We introduce in this paper a revocable outsourcing multi-authority attribute-based access control for medical data in the mobile cloud. The advantages of our construction are multifold. First, the expensive encryption operation is outsourced to a semi-honest cloud storage server and is verifiable. Second, the costly decryption operation in current schemes exhibits lower computation in our work and is partially outsourced to the cloud. Third, user and attribute revocations are performed by the semi-trusted cloud storage server, therefore, saving resources on end computing devices. Fourth, our scheme is secure and verifiable under the decisional bilinear Diffie-Hellman assumption.