Electronic Medical Record Privacy Protection Scheme Based on Attribute Encryption Technology
Shuai Zhang, Feng Guo, Changqiang Jing, Chuan-Kun Wu · 2024
With the development of science and technology and the progress of medical and health system, electronic medical records with the advantages of large storage capacity and easy sharing have gradually replaced traditional paper medical records. In recent years, due to factors such as improper hospital management or hacker attacks, medical privacy leaks have occurred frequently, which not only caused serious privacy violations to patients, but also caused a negative impact on society that cannot be ignored. In order to prevent the leakage of medical privacy data during the sharing process and protect the electronic medical record data of patients, an access control scheme based on attribute encryption technology is proposed. The proposed scheme uses the ordered binary decision diagram (OBDD) as the access structure. Compared with the threshold access structure and the linear secret sharing access structure (LSSS), OBDD can represent any access strategy and support positive and negative values of attributes, and its expression efficiency higher. The proposed scheme combines ciphertext attribute-based encryption (CP-ABE) with the national secret SM4 algorithm, and uses hybrid encryption to realize data protection of electronic medical records. After security analysis and experimental verification, the proposed scheme satisfies the selection plaintext security under the judgment bilinear Diffie-Hellman (DBDH) assumption, and has constant key length and high decryption efficiency, which has higher storage and computing performance advantages than other schemes.