Journal of Information Security Reserach ›› 2024, Vol. 10 ›› Issue (6): 554-.

Previous Articles     Next Articles

A Traceable Encryption Scheme for Medical Data Based on  Smart Contract and Fog Computing

Chang Yuqing, He Wanmeng, Zhou Luyao, and Peng Zhenwan   

  1. (School of Biomedical Engineering, Anhui Medical University, Hefei 230012)
  • Online:2024-06-06 Published:2024-06-08

基于智能合约和雾计算的医疗数据可追溯加密方案

常雨晴贺婉朦周璐瑶彭振皖   

  1. (安徽医科大学生物医学工程学院合肥230012)
  • 通讯作者: 常雨晴 硕士研究生.主要研究方向为访问控制. 15656962250@163.com
  • 作者简介:常雨晴 硕士研究生.主要研究方向为访问控制. 15656962250@163.com 贺婉朦 硕士研究生.主要研究方向为医学智慧医疗. hwm8824@163.com 周璐瑶 硕士研究生.主要研究方向为机器学习、智慧医疗. 2245012416@stu.ahmu.edu.cn 彭振皖 博士,讲师.主要研究方向为区块链、安全多方计算. pengzhenwan@ahmu.edu.cn

Abstract: Traditional medical system solves problems such as medical record management, patient information storage, medical resource scheduling, and so on. However, it suffered from shortcomings such as medical privacy breaches, data security concerns, and high loads on end devices when dealing with everincreasing data volumes and complex access control requirements. To solve the above problems, this paper proposes a traceable encryption scheme based on smart contract and fog computing for medical data privacy protection. By introducing authorization mechanisms and revocable attributebased encryption, the privacy of medical data is effectively protected and the abuse of key is avoided. Additionally, data security is further enhanced by embedding user information in private keys. As the participant of access control, smart contract is responsible for the authentication of the user’s authorization, and part of the decryption operation is undertaken by the fog node, thus reducing the load of the terminal device and achieving load balancing. In comparison with other similar schemes, the proposed approach demonstrates higher computing and storage efficiency.


Key words: Attribute encryption, access control, Fog nodes, Medical data privacy, smart contract

摘要: 传统的医疗系统解决了诸如医疗记录管理、患者信息存储、医疗资源调度等问题.然而,在应对日益增加的数据量和复杂的访问控制需求时存在着医疗隐私泄露、数据安全性和终端设备负载等缺陷.针对以上问题,提出一种面向医疗数据隐私保护的基于智能合约和雾计算的可追溯加密方案.通过引入授权机制和基于属性加密的可撤销机制,有效保护了医疗数据的隐私,并避免了密钥滥用的情况.同时,通过在私钥中嵌入用户信息,进一步增强数据安全性.智能合约作为访问控制的参与方,负责执行用户的授权验证,部分解密操作由雾节点承担,从而减轻了终端设备的负荷,实现了负载均衡.通过与其他同类型方案进行计算开销、存储开销和安全性的对比发现,该方案具有更高的计算和存储效率.


关键词: 属性加密, 访问控制, 雾节点, 医疗数据隐私, 智能合约

CLC Number: