A Blockchain-Based Trustworthy Access Control Scheme for Medical Data Sharing

Blockchain is commonly employed in access control to provide safe medical data exchange because of the characteristics of decentralization, nontamperability, and traceability. Patients share personal health data by granting access rights to users or medical institutions. The major purpose of the exi...

Full description

Bibliographic Details
Main Authors: Canling Wang, Wei Wu, Fulong Chen, Hong Shu, Ji Zhang, Yuxuan Zhang, Taochun Wang, Dong Xie, Chuanxin Zhao
Format: Article
Language:English
Published: Hindawi-IET 2024-01-01
Series:IET Information Security
Online Access:http://dx.doi.org/10.1049/2024/5559522
_version_ 1797321084932980736
author Canling Wang
Wei Wu
Fulong Chen
Hong Shu
Ji Zhang
Yuxuan Zhang
Taochun Wang
Dong Xie
Chuanxin Zhao
author_facet Canling Wang
Wei Wu
Fulong Chen
Hong Shu
Ji Zhang
Yuxuan Zhang
Taochun Wang
Dong Xie
Chuanxin Zhao
author_sort Canling Wang
collection DOAJ
description Blockchain is commonly employed in access control to provide safe medical data exchange because of the characteristics of decentralization, nontamperability, and traceability. Patients share personal health data by granting access rights to users or medical institutions. The major purpose of the existing access control techniques is to identify users who are permitted to access medical data. They hardly ever recognize internal assailants from legitimate entities. Medical data will involve multilayer access within the authorized organizations. Considering the cost of permissions management and the problem of insider malicious node attacks, users hope to implement authorization constraints within the authorized institutions. It can prevent their data from being maliciously disclosed by end-users from different authorized healthcare domains. For the purpose to achieve the fine-grained permissions propagation control of medical data in sharing institutions, a trust-based authorization access control mechanism is suggested in this study. Trust thresholds are assigned to different privileges based on their sensitivity and used to generate zero-knowledge proof to be broadcasted among blockchain nodes. This method evaluates the trust of each user through the dynamic trust calculation model. And meanwhile, smart contract is employed to verify whether the user’s trust can activate some permissions and ensure the privacy of the user’s trust in the process of authorization verification. In addition, the authorization transaction between users and institutions is recorded on the blockchain for patient traceability and accountability. The feasibility and effectiveness of the scheme are demonstrated through comprehensive comparisons and extensive experiments.
first_indexed 2024-03-08T04:52:27Z
format Article
id doaj.art-42906c84d83f4f228e6de0386b0b131e
institution Directory Open Access Journal
issn 1751-8717
language English
last_indexed 2024-03-08T04:52:27Z
publishDate 2024-01-01
publisher Hindawi-IET
record_format Article
series IET Information Security
spelling doaj.art-42906c84d83f4f228e6de0386b0b131e2024-02-08T00:00:01ZengHindawi-IETIET Information Security1751-87172024-01-01202410.1049/2024/5559522A Blockchain-Based Trustworthy Access Control Scheme for Medical Data SharingCanling Wang0Wei Wu1Fulong Chen2Hong Shu3Ji Zhang4Yuxuan Zhang5Taochun Wang6Dong Xie7Chuanxin Zhao8Anhui Provincial Key Laboratory of Network and Information SecurityAnhui Provincial Key Laboratory of Network and Information SecurityAnhui Provincial Key Laboratory of Network and Information SecurityTongling UniversityUniversity of Southern QueenslandAnhui Provincial Key Laboratory of Network and Information SecurityAnhui Provincial Key Laboratory of Network and Information SecurityAnhui Provincial Key Laboratory of Network and Information SecurityAnhui Provincial Key Laboratory of Network and Information SecurityBlockchain is commonly employed in access control to provide safe medical data exchange because of the characteristics of decentralization, nontamperability, and traceability. Patients share personal health data by granting access rights to users or medical institutions. The major purpose of the existing access control techniques is to identify users who are permitted to access medical data. They hardly ever recognize internal assailants from legitimate entities. Medical data will involve multilayer access within the authorized organizations. Considering the cost of permissions management and the problem of insider malicious node attacks, users hope to implement authorization constraints within the authorized institutions. It can prevent their data from being maliciously disclosed by end-users from different authorized healthcare domains. For the purpose to achieve the fine-grained permissions propagation control of medical data in sharing institutions, a trust-based authorization access control mechanism is suggested in this study. Trust thresholds are assigned to different privileges based on their sensitivity and used to generate zero-knowledge proof to be broadcasted among blockchain nodes. This method evaluates the trust of each user through the dynamic trust calculation model. And meanwhile, smart contract is employed to verify whether the user’s trust can activate some permissions and ensure the privacy of the user’s trust in the process of authorization verification. In addition, the authorization transaction between users and institutions is recorded on the blockchain for patient traceability and accountability. The feasibility and effectiveness of the scheme are demonstrated through comprehensive comparisons and extensive experiments.http://dx.doi.org/10.1049/2024/5559522
spellingShingle Canling Wang
Wei Wu
Fulong Chen
Hong Shu
Ji Zhang
Yuxuan Zhang
Taochun Wang
Dong Xie
Chuanxin Zhao
A Blockchain-Based Trustworthy Access Control Scheme for Medical Data Sharing
IET Information Security
title A Blockchain-Based Trustworthy Access Control Scheme for Medical Data Sharing
title_full A Blockchain-Based Trustworthy Access Control Scheme for Medical Data Sharing
title_fullStr A Blockchain-Based Trustworthy Access Control Scheme for Medical Data Sharing
title_full_unstemmed A Blockchain-Based Trustworthy Access Control Scheme for Medical Data Sharing
title_short A Blockchain-Based Trustworthy Access Control Scheme for Medical Data Sharing
title_sort blockchain based trustworthy access control scheme for medical data sharing
url http://dx.doi.org/10.1049/2024/5559522
work_keys_str_mv AT canlingwang ablockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT weiwu ablockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT fulongchen ablockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT hongshu ablockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT jizhang ablockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT yuxuanzhang ablockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT taochunwang ablockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT dongxie ablockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT chuanxinzhao ablockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT canlingwang blockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT weiwu blockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT fulongchen blockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT hongshu blockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT jizhang blockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT yuxuanzhang blockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT taochunwang blockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT dongxie blockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing
AT chuanxinzhao blockchainbasedtrustworthyaccesscontrolschemeformedicaldatasharing