TY - JOUR
T1 - Trustworthy Delegation Toward Securing Mobile Healthcare Cyber-Physical Systems
AU - Hahn, Changhee
AU - Kwon, Hyunsoo
AU - Hur, Junbeom
N1 - Publisher Copyright:
© 2014 IEEE.
PY - 2019/8
Y1 - 2019/8
N2 - Attribute-based encryption (ABE) offers a promising solution for flexible access control over sensitive personal health records in a mobile healthcare system on top of a public cloud infrastructure. However, ABE cannot be simply applied to lightweight devices due to its substantial computation cost during decryption. This problem could be alleviated by delegating significant parts of the decryption operations to computationally powerful parties, such as cloud servers, but the correctness of the delegated computation would be at stake. Thus, previous works enabled users to validate the partial decryption by employing a cryptographic commitment or message authentication code (MAC). This paper demonstrates that the previous commitment or MAC-based schemes cannot support verifiability in the presence of potentially malevolent cloud servers. We propose two concrete attacks on previous commitment or MAC-based schemes. We propose an effective countermeasure scheme for securing resource-limited mobile healthcare systems and provide a rigorous security proof in the standard model, demonstrating that the proposed scheme is secure against our attacks. The experimental analysis shows that the proposed scheme provides the similar performance compared with the previous commitment-based schemes and outperforms the MAC-based scheme.
AB - Attribute-based encryption (ABE) offers a promising solution for flexible access control over sensitive personal health records in a mobile healthcare system on top of a public cloud infrastructure. However, ABE cannot be simply applied to lightweight devices due to its substantial computation cost during decryption. This problem could be alleviated by delegating significant parts of the decryption operations to computationally powerful parties, such as cloud servers, but the correctness of the delegated computation would be at stake. Thus, previous works enabled users to validate the partial decryption by employing a cryptographic commitment or message authentication code (MAC). This paper demonstrates that the previous commitment or MAC-based schemes cannot support verifiability in the presence of potentially malevolent cloud servers. We propose two concrete attacks on previous commitment or MAC-based schemes. We propose an effective countermeasure scheme for securing resource-limited mobile healthcare systems and provide a rigorous security proof in the standard model, demonstrating that the proposed scheme is secure against our attacks. The experimental analysis shows that the proposed scheme provides the similar performance compared with the previous commitment-based schemes and outperforms the MAC-based scheme.
KW - Attribute-based encryption (ABE)
KW - cloud computing
KW - cyber-physical systems
KW - mobile healthcare
UR - http://www.scopus.com/inward/record.url?scp=85055680767&partnerID=8YFLogxK
U2 - 10.1109/JIOT.2018.2878216
DO - 10.1109/JIOT.2018.2878216
M3 - Article
AN - SCOPUS:85055680767
SN - 2327-4662
VL - 6
SP - 6301
EP - 6309
JO - IEEE Internet of Things Journal
JF - IEEE Internet of Things Journal
IS - 4
M1 - 8510797
ER -