Electronic Health Record Sharing Method Supporting Dynamic Update and Fast Data Access

By introducing a trusted authorization center and outsourcing decryption mechanism in the electronic health record sharing system, the problem of difficult update of access policies for data sharing in dynamic user groups and slow data access speed is solved, and fast and secure data access and sharing are achieved.

CN115967557BActive Publication Date: 2025-07-01FUJIAN NORMAL UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211640211.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-20
Publication Date
2025-07-01
Estimated Expiration
2042-12-20

AI Technical Summary

Technical Problem

When the prior art performs data sharing among dynamic user groups, access policy updates are difficult and data access speeds are slow, and ciphertext policy attribute-based encryption has problems with key management and calculation pressure.

Method used

An electronic health record sharing method that supports dynamic updates and fast data access is adopted. Through collaboration between trusted authorization centers, cloud servers and data users, dynamic updates and outsourcing decryption of access policies are achieved, reducing the requirements for user-side computing capabilities.

Benefits of technology

It realizes rapid update of access policies without using update keys, reduces computing pressure, improves data access speed, enhances data privacy and security, and is suitable for a wide range of data sharing scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115967557B_ABST
    Figure CN115967557B_ABST
Patent Text Reader

Abstract

The present invention relates to an electronic health record sharing method that supports dynamic update of sharing scope and fast data access, allowing the data owner to initiate an access policy update request. When the cloud server receives the update request, it updates the ciphertext and modifies the access policy according to the user's update requirements. To alleviate the problem of large computational overhead during data access, the present invention outsources most of the computational overhead in the data decryption process to the cloud server for execution. During the outsourcing decryption process, the user public key of the data user always acts as a blinding factor to ensure that the cloud server cannot obtain any information about the plaintext content. Finally, the cloud server sends the generated outsourcing decryption result to the data user, and the data user completes decryption by using the user secret value corresponding to the user public key to eliminate the blinding factor in the ciphertext. Therefore, during the ciphertext update and outsourcing decryption processes, the present invention can ensure the privacy and security of data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of data encryption and access control, and particularly relates to an electronic health record sharing method that supports dynamic update and fast data access. Background Art

[0002] In recent years, Internet of Things (IoT) technology has been widely applied to the healthcare industry. People use IoT devices to collect electronic health records including heart rate, blood pressure, sleep conditions, etc. and store them in the cloud. In this way, doctors can obtain patients' electronic health records in a timely manner to assist in diagnosing diseases. Therefore, the application of cloud data sharing technology can greatly improve the quality of medical services. However, electronic health records are closely related to patients' privacy. If the security of electronic health records stored in the cloud cannot be guaranteed, cloud data sharing technology will be difficult to be widely applied.

[0003] Encrypting data using a symmetric encryption algorithm before uploading can ensure data security, but this brings problems in key management. For example, a patient first encrypts their own electronic health record using a symmetric encryption algorithm and then sends the decryption key to the doctor who has the right to access their data. There are the following problems in this simple scenario. First, the patient may not know the identity of the relevant doctor. Generally speaking, the information that the patient is more likely to know is only some attributes of the doctor (such as hospital, department, etc.). Based on this information alone, the patient will not be able to distribute their key smoothly. Second, a doctor cannot effectively manage the keys of all the patients he is responsible for. A more reasonable approach is to allow the doctor to use a personal key to access the electronic health records of all the patients he is responsible for.

[0004] Attribute-based encryption can provide fine-grained access control capabilities for ciphertext data and has broad application prospects. Attribute-based encryption mainly includes two types: ciphertext-policy attribute-based encryption and key-policy attribute-based encryption. In ciphertext-policy attribute-based encryption, the user key is related to a series of attributes, and the ciphertext is related to an access policy. Decryption can only be completed when the attributes in the key can satisfy the access policy in the ciphertext. In key-policy attribute-based encryption, the key is related to an access policy, and the ciphertext is related to a series of attributes. Since in ciphertext-policy attribute-based encryption, the data owner can stipulate the data sharing scope through the access policy formulated by himself, it is more suitable for the application scenario of data sharing in the cloud environment.

[0005] However, there are problems with ciphertext-policy attribute-based encryption in terms of difficult access policy updates and slow data access speeds. Suppose several hospitals collaborate to provide a cloud-based electronic health record sharing service to patients. Patients visiting these hospitals can share their electronic health records with medical staff in these hospitals. Considering data security and personal privacy, patients will formulate an access policy before uploading data. Only medical staff who meet this access policy can access the patients' electronic health records. Correspondingly, these hospitals will assign attributes related to their duties to their medical staff. If the attributes of medical staff can meet the access policy of a patient's electronic health record, they are called the authorized doctors of that patient. After the authorized doctor finishes the treatment, the patient hopes to modify the sharing scope of his electronic health record so that the medical staff responsible for nursing in another hospital can understand his situation. At this time, he needs to revoke the access rights of the previous authorized doctor and grant them to the medical staff in another hospital.

[0006] There are mainly two problems involved. On the one hand, data sharing among a dynamic user group needs to be achieved by updating the access policy. Although we can simply let the patient download all the ciphertexts, decrypt them, encrypt them with the new access policy, and then upload them to the cloud to solve this problem, this will result in a large amount of computational overhead. Using proxy re-encryption technology is an optional solution, but proxy re-encryption technology requires the use of re-encryption keys, which poses a risk of key leakage. More importantly, proxy re-encryption cannot modify the access policy. In some other solutions, there is a way to expand the access policy by providing the authorized users with the function of adding access policies to the ciphertext, however, this will make the ciphertext become more and more bloated. On the other hand, due to a large number of bilinear pairing calculations involved in ciphertext-policy attribute-based encryption, the Internet of Things devices used by data users are often unable to handle this work. To relieve the computational pressure on the user-side Internet of Things devices, an outsourcing computing method needs to be used to improve the data access speed and enhance the usage experience of data users. Summary of the Invention

[0007] In view of this, the purpose of the present invention is to provide an electronic health record sharing method that supports dynamic updates and fast data access, aiming to solve the above problems.

[0008] To achieve the above purpose, the present invention adopts the following technical solutions:

[0009] An electronic health record sharing method that supports dynamic updates and fast data access, providing a system including a trusted authorization center, a cloud server, data users, and data owners, comprising the following steps:

[0010] Step S1: The trusted authorization center and the cloud server each generate public parameters and private keys, publish their public parameters, and secretly store their private keys;

[0011] Step S2: The data user generates a user public key and a secret value, and at the same time applies to the trusted authorization center for registration. The trusted authorization center calculates and distributes the corresponding attribute keys according to the attribute set submitted by the user.

[0012] Step S3: The data owner generates an access policy according to the expected sharing group of the electronic health record, encrypts the electronic health record to be shared through the access policy to generate a ciphertext, and uploads the ciphertext to the cloud server. The cloud server saves the ciphertext after blinding it.

[0013] Step S4: The data owner sends an update request to the cloud server, and the cloud server updates the access policy of the corresponding ciphertext.

[0014] Step S5: The data user submits decryption key application data access to the cloud server, and the cloud server performs an outsourced decryption operation to generate an outsourced ciphertext and returns it to the data user; after receiving the outsourced ciphertext, the data user decrypts the outsourced decryption result using its own secret value.

[0015] Furthermore, the specific content of step S1 is as follows:

[0016] (1) The trusted authorization center provides an elliptic curve group and a bilinear mapping according to the security parameter λ where represents an elliptic curve cyclic group of order p, represents a bilinear mapping, and let Z p represent an integer group of order p;

[0017] (2) The trusted authorization center selects random numbers α, β ∈ Z p , random group elements g, h, u, v, Then calculate the α-th power g α of g and the β-th power g β of g respectively;

[0018] (3) The trusted authorization center publishes the public parameters and saves the master private key msk = {α, β};

[0019] (4) The cloud server randomly selects and saves the cloud server private key sk c = s c , where s c ∈ Z p ;

[0020] (5) The cloud server calculates the s c -th power of g and publishes its public parameters

[0021] Further, the specific steps of step S2 are as follows:

[0022] (1) The data user randomly selects and saves the data user secret value sv u = s u , where s u ∈Z p ;

[0023] (2) The data user calculates the s u -th power of g and publishes its public key

[0024] (3) The data user provides the attribute set S = {A1, A2,..., A k} for which the key is to be applied and its own public key pp u ;

[0025] (4) The trusted authorization center selects k + 1 random numbers r, r1, r2,..., r k ∈Z p , calculates the decryption key component K0 = pp u α w r , the decryption key component K1 = g r ; for the trusted center calculates the decryption key component related to the attribute A τ and and finally generates the decryption key dk S = {S, K0, K1, {K τ,2 , K τ,3} τ∈[k]};

[0026] (5) The trusted authorization center sends the decryption key dk S to the data user.

[0027] Further, the specific steps of step S3 are as follows:

[0028] (1) The data owner prepares the electronic health record information msg to be encrypted and the corresponding access policy matrix (M, ρ), where M represents a matrix of size l × n and ρ is the mapping from the row numbers of the matrix to the corresponding attributes;

[0029] (2) The data owner selects the secret s to be shared, selects l - 1 random numbers to form a vector * = (s, x2,..., x l ) T ; for i ∈ [l], the data owner calculates λ i = M ix; The data owner selects l random numbers t1, t2, …, t l ∈Z p , and calculates the ciphertext component C = msg·e(g, pp c ) αs , C0 = g s ; For i ∈ [l], the data owner calculates the ciphertext components related to the attributes in the access policy For k ∈ l], the data owner calculates the ciphertext components related to the attributes in the access policy Finally, generate the ciphertext CT = {(M, ρ), C, C0, {C i,1 , C i,2 , C i,3} i∈[l] , {H k} k∈[l]};

[0030] (3) The data owner sends the ciphertext CT to the cloud server;

[0031] (4) After receiving the ciphertext CT, the cloud server selects a random number to blind the ciphertext and secretly stores

[0032] (5) The cloud server stores the blinded ciphertext CT = {(M, ρ), C, C0, {C i,1 , C i,2 , C i,3} i∈[l] , {H k} k∈ [l]}.

[0033] Furthermore, the specific steps of step S4 are as follows:

[0034] (1) For a certain attribute to be updated, the data owner makes loc represent the position of the attribute to be modified in the access policy, makes op represent the operation to be performed on this attribute, and makes cont represent the attribute used for the update operation; The update operation op includes a total of ADD AND , ADD OR , DEL AND , DEL OR 4 options, where ADD AND means adding an AND-connected attribute after the attribute at the loc position, ADD OR means adding an OR-connected attribute after the attribute at the loc position, DEL AND means deleting the AND-connected attribute at the loc position, DEL ORIndicates deleting the attributes connected by OR at the loc position; subsequently, the data owner sends an update request APupdate = {loc i , op i , cont i} i∈[|APupdate|] ;

[0035] (2) Let l' be the number of rows of the updated access policy matrix. The cloud server selects random numbers t1, t2, …, t l' , For j ∈ [l'], the cloud server calculates the ciphertext update component where is the random number used to protect {H k} k∈[n] in the ciphertext CT. The cloud server updates the ciphertext C = C η , C0 = C0 η , and for i ∈ [l'], calculates C i,1 = C i,1 ·C 1,i u , C i,2 = C i,2 ·C 2,i u , C i,3 = C i,3 ·C 3,i u , and for k ∈ [n'], calculates

[0036] (3) The cloud service stores the updated ciphertext CT = {(M, ρ), C, C0, {C i,1 , C i,2 , C i,3} i∈[l’] , {H k} k∈[n’]}.

[0037] Furthermore, the ADD AND operation is specifically as follows: If the initial access policy (M, ρ) contains content, the cloud server outputs ⊥; otherwise, for the attribute attr ∈ content, the cloud server selects random numbers t, x l+1 ∈ Z p , and calculates the newly added ciphertext C attr,2 = (u attr h) -t , C attr,3 = g t , where Let ATTR be the parent attribute of attr, and the cloud server calculates If the parent attribute ATTR itself has a sibling attribute ATTR', the cloud server needs to perform the same operation on its sibling attribute, that is, calculate Subsequently, the cloud server will add H l+1 to {H k}.

[0038] Furthermore, the ADD OR operation is specifically as follows: If the initial access policy (M, ρ) contains content, the cloud server outputs ⊥; otherwise, for the attribute attr ∈ content, the cloud server selects a random number t ∈ Z p ; Since the newly added attribute attr is connected to the attributes in the access policy through OR, the secret share corresponding to attr is the same as the attribute located at the loc position; Let l be the row in the matrix corresponding to the newly added attribute, and the cloud server calculates the newly added ciphertext

[0039] Furthermore, the DEL AND operation is specifically as follows: If the initial access policy (M, ρ) does not contain content, the cloud server outputs ⊥; otherwise, for the attribute attr ∈ content, the cloud server calculates the relevant elements of the secret sharing of the attribute attr through the access policy matrix M and H k Delete {C , C attr,1 , C attr,2 , C attr,3} from the ciphertext CT; Let ATTR be the parent attribute of attr, and the cloud server calculates If the parent attribute ATTR itself has a sibling attribute ATTR', the cloud server needs to perform the same operation on its sibling attribute, that is, calculate Finally, the cloud server deletes H k from {H attr .

[0040] Furthermore, the DEL OR operation is specifically as follows: If the initial access policy (M, ρ) does not contain content, the cloud server outputs ⊥. Otherwise, for the attribute attr ∈ content, the cloud server directly deletes {C attr,1 , C attr,2 , C attr,3} from the ciphertext CT.

[0041] Furthermore, the step S5 is specifically as follows:

[0042] (1) After the cloud server receives the decryption key dk S submitted by the data user, it compares it with the access policy in the ciphertext;

[0043] (2) If the attributes in the key can satisfy the access policy, the cloud server calculates

[0044]

[0045]

[0046] Subsequently, the cloud server sends the result CT out ={CT pre , C'} of the outsourced calculation to the data user;

[0047] (3) If the attributes in the key cannot satisfy the access policy, the cloud server returns ⊥, indicating that the algorithm stops;

[0048] (4) After receiving the outsourced decryption result from the cloud server, the corresponding data user uses the secret value sv u saved by itself to restore the electronic health record information to complete a data access.

[0049] The present invention has the following beneficial effects compared with the prior art:

[0050] 1. The present invention can ensure the privacy and security of data during the process of ciphertext update and outsourced decryption. Technically, in order to ensure that there is no ambiguity in the access policy update request, all access policies used in the present invention adopt the form of the principal conjunctive normal form;

[0051] 2. The present invention does not need to use an update key in the access policy update, and only needs the data user to send an update request to the cloud server. Therefore, it is more reliable in terms of security;

[0052] 3. The present invention uses the method of outsourced calculation to reduce the requirements for the computing power of the data user side. Therefore, the applicable scope is wider;

[0053] 4. Compared with the existing data sharing schemes that can modify the data sharing scope, the present invention has higher flexibility and a wider applicable scope, and can effectively promote the wide application of electronic health record sharing. Brief Description of the Drawings

[0054] Figure 1 is the system model diagram of the present invention;

[0055] Figure 2 is the execution sequence diagram in an embodiment of the present invention;

[0056] Figure 3 is the attribute relationship diagram in an embodiment of the present invention;

[0057] Figure 4It is a diagram showing the policy update and matrix change in an embodiment of the present invention. Detailed implementation manners

[0058] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.

[0059] Please refer to Figure 1 , the present invention provides an electronic health record sharing method supporting dynamic update and fast data access, and provides a system including a trusted authorization center, a cloud server, a data user, and a data owner, including the following steps:

[0060] Step S1: The trusted authorization center and the cloud server respectively generate public parameters and private keys, publish their public parameters, and secretly save the private keys;

[0061] Step S2: The data user generates a user public key and a secret value, and at the same time applies to the trusted authorization center for registration. The trusted authorization center calculates and distributes corresponding attribute keys according to the attribute set submitted by the user;

[0062] Step S3: The data owner generates an access policy according to the expected sharing group of the electronic health record, encrypts the electronic health record to be shared through the access policy to generate a ciphertext, and uploads the ciphertext to the cloud server. The cloud server saves the ciphertext after blinding;

[0063] Step S4: The data owner sends an update request to the cloud server, and the cloud server updates the access policy of the corresponding ciphertext;

[0064] Step S5: The data user submits a decryption key application to the cloud server for data access. The cloud server performs an outsourced decryption operation to generate an outsourced ciphertext and returns it to the data user; after receiving the outsourced ciphertext, the data user decrypts the outsourced decryption result using its own secret value.

[0065] In this embodiment, step S1 is specifically as follows:

[0066] (1) The trusted authorization center provides an elliptic curve group and a bilinear mapping according to the security parameter λ where represents an elliptic curve cyclic group of order p, represents a bilinear mapping, and let Z p represent an integer group of order p;

[0067] (2) The trusted authorization center selects random numbers α, β ∈ Z p , random group elements g, h, u, v, Then calculate the α-th power g α of g and the β-th power g β of g respectively;

[0068] (3) The trusted authorization center discloses the public parameters Save the master private key msk = {α, β};

[0069] (4) The cloud server randomly selects and saves the cloud server private key sk c = s c , where s c ∈Z p ;

[0070] (5) The cloud server calculates the s c -th power of g and discloses its public parameters

[0071] In this embodiment, step S2 is specifically as follows:

[0072] (1) The data user randomly selects and saves the data user secret value sv u = s u , where s u ∈Z p ;

[0073] (2) The data user calculates the s u -th power of g and discloses its public key

[0074] (3) The data user provides the attribute set S = {A1, A2,..., A k} and its own public key pp u to the trusted authorization center;

[0075] (4) The trusted authorization center selects k + 1 random numbers r, r1, r2,..., r k ∈Z p , calculates the decryption key component K0 = pp u α w r , the decryption key component K1 = g r ; For the trusted center calculates the decryption key component τ related to the attribute A and Finally, generate the decryption key dk S = {S, K0, K1, {K τ,2 , K τ,3} τ∈[k]} for the data user's attribute set S;

[0076] (5) The trusted authorization center sends the decryption key dk S to the data user.

[0077] In this embodiment, step S3 is specifically as follows:

[0078] (1) The data owner prepares the electronic health record information msg to be encrypted and the corresponding access policy matrix (M, ρ), where M represents a matrix of size l×n, and ρ is the mapping from the row numbers of the matrix to the corresponding attributes;

[0079] (2) The data owner selects the secret s to be shared, selects l - 1 random numbers to form the vector x = (s, x2,..., x l ) T ; for i ∈ [l], the data owner calculates λ i = M i x; the data owner selects l random numbers t1, t2,..., t l ∈ Z p , calculates the ciphertext component C = msg·e(g, pp c ) αs , C0 = g s ; for i ∈ [l], the data owner calculates the ciphertext components related to the attributes in the access policy For k ∈ l], the data owner calculates the ciphertext components related to the attributes in the access policy Finally, the ciphertext CT = {(M, ρ), C, C0, {C i,1 , C i,2 , C i,3} i∈[l] , {H k} k∈[l]} is generated;

[0080] (3) The data owner sends the ciphertext CT to the cloud server;

[0081] (4) After receiving the ciphertext CT, the cloud server selects a random number to blind the ciphertext and secretly stores it

[0082] (5) The cloud server stores the blinded ciphertext CT = {(M, ρ), C, C0, {C i,1 , C i,2 , C i,3}i ∈[l] , {H k} k∈[l]}.

[0083] In this embodiment, step S4 is specifically as follows:

[0084] (1) For a certain attribute to be updated, the data owner makes loc represent the position of the attribute to be modified in the access policy, op represent the operation to be performed on this attribute, and cont represent the attribute used for the update operation; the update operation op includes ADD AND , ADD OR , DEL AND , DEL OR 4 options, where ADD AND means adding an attribute connected by AND after the attribute at the loc position, ADD OR means adding an attribute connected by OR after the attribute at the loc position, DEL AND means deleting the attribute connected by AND at the loc position, DEL OR means deleting the attribute connected by OR at the loc position; subsequently, the data owner sends an update request APupdate = {loc i , op i , cont i} i∈[|APupdate|] ;

[0085] (2) Let l' be the number of rows of the updated access policy matrix. The cloud server selects random numbers t1, t2, …, t l' , For j ∈ [l'], the cloud server calculates the ciphertext update component where is the random number used to protect {H k} k∈[n] in the ciphertext CT. The cloud server updates the ciphertext C = C η , C0 = C0 η . For i ∈ [l'], it calculates C i,1 = C i,1 · C 1,i u , C i,2 = C i,2 · C 2,i u , C i,3 = C i,3 · C 3,i u . For k ∈ [n'], it calculates

[0086] (3) The cloud service stores the updated ciphertext CT = {(M, ρ), C, C0, {C i,1 , C i,2 , C i,3} i∈[l’] , {H k}k∈[n’]}.

[0087] Preferably, in this embodiment, ADD AND operation, specifically: If the initial access policy (M, ρ) contains content, the cloud server outputs ⊥; otherwise, for the attribute attr ∈ content, the cloud server selects random numbers t, x l+1 ∈ Z p , and calculates the new ciphertext C attr,2 =(u attr h) -t , C attr,3 =g t , where Let ATTR be the parent attribute of attr, and the cloud server calculates If the parent attribute ATTR itself has a sibling attribute ATTR’, the cloud server needs to perform the same operation on its sibling attribute, that is, calculate Subsequently, the cloud server adds H l+1 to {H k}.

[0088] Preferably, in this embodiment, ADD OR operation, specifically: If the initial access policy (M, ρ) contains content, the cloud server outputs ⊥; otherwise, for the attribute attr ∈ content, the cloud server selects a random number t ∈ Z p ; Since the newly added attribute attr is connected to the attributes in the access policy through OR, the secret share corresponding to attr is the same as the attribute located at the loc position; Let l be the row corresponding to the newly added attribute in the matrix, and the cloud server calculates the new ciphertext C attr,2 =(u attr h) -t , C attr,3 =gt.

[0089] Preferably, in this embodiment, DEL AND operation, specifically: If the initial access policy (M, ρ) does not contain content, the cloud server outputs ⊥; otherwise, for the attribute attr ∈ content, the cloud server calculates the elements related to the secret sharing of the attribute attr through the access policy matrix M and H k Delete {C , C attr,1 , C attr,2 , C attr,3} from the ciphertext CT; Let ATTR be the parent attribute of attr, and the cloud server calculates If the parent attribute ATTR itself has a sibling attribute ATTR', the cloud server needs to perform the same operation on its sibling attribute, that is, calculate Finally, the cloud server deletes H from {H k} attr .

[0090] Preferably, in this embodiment, the DEL OR operation is specifically as follows: If the initial access policy (M, ρ) does not contain content, the cloud server outputs ⊥. Otherwise, for the attribute attr ∈ content, the cloud server directly deletes {C attr,1 , C attr,2 , C attr,3} from the ciphertext CT

[0091] In this embodiment, step S5 is specifically as follows:

[0092] (1) After the cloud server receives the decryption key dk submitted by the data user S , it compares it with the access policy in the ciphertext;

[0093] (2) If the attributes in the key can satisfy the access policy, the cloud server calculates

[0094]

[0095]

[0096] Subsequently, the cloud server sends the result CT out = {CT pre , C'} of the outsourced calculation to the data user;

[0097] (3) If the attributes in the key cannot satisfy the access policy, the cloud server returns ⊥, indicating that the algorithm stops;

[0098] (4) After receiving the outsourced decryption result from the cloud server, the corresponding data user uses the secret value sv saved by itself u to restore the electronic health record information to complete a data access.

[0099] Technically, to ensure that there is no ambiguity in the access policy update request, all access policies used in the present invention adopt the form of the principal conjunctive normal form. Compared with existing data sharing schemes, the present invention supports modifying the access policy in the direction of less restrictions, so it supports more flexible modification of the data sharing scope. The present invention does not need to use an update key in the access policy update, and only requires the data user to send an update request to the cloud server, so it is more reliable in terms of security. The present invention uses the method of outsourcing computing to reduce the requirements for the computing power of the data user side, so the applicable scope is wider. Generally speaking, the present invention has higher flexibility and applicable scope compared with existing data sharing schemes that can modify the data sharing scope.

[0100] In this embodiment, Figure 3 shows the access policy (AORC) AND D AND B in the form of the principal conjunctive normal form, where the attributes connected by OR use the same color, and the attributes connected by AND use different colors. Define the attributes connected by OR as sibling relationships, such as A and C are sibling attributes to each other; the attributes connected by AND are parent-child relationships, such as the parent attribute of B is D or C, and the parent attribute of D is C or B.

[0101] In this embodiment, Figure 4 shows the change situation of the corresponding access policy matrix when the access policy is updated. All access policies in the present invention adopt the form of the principal conjunctive normal form, and the matrix corresponding to the access policy is completely composed of three elements: 1, 0, and -1 (M represents the matrix before update, and M' represents the matrix after update).

[0102] As Figure 4 shown in (a) below, when performing the DEL AND operation to delete the attribute B connected to the attribute D by AND. First, delete the row [00 - 1] representing the attribute B in the matrix. Since the deleted attribute B is connected to the attribute D by AND, to balance the impact of the deletion operation, add [00 - 1] to the row [0 - 10] representing the parent attribute D of the attribute B in the matrix. Since the parent attribute D has no sibling attributes, no other changes need to be made, and the row representing the attribute D after update is [0 - 1 - 1].

[0103] As Figure 4 shown in (b) below, when performing the DEL OR operation to delete the attribute A connected to the attribute C by OR. First, delete the row

[11] representing the attribute A in the matrix. Since the deleted attribute A is connected to the attribute C by OR, no other changes need to be made.

[0104] As Figure 4 shown in (c) below, when performing the ADD ORWhen performing the ADD operation to add Attribute B connected by OR at the position of Attribute D. First, the row [0-1] representing Attribute B is added. Since the added Attribute B is connected to Attribute D by OR, no other changes are required.

[0105] As Figure 4 shown in (d) below, when performing the ADD AND operation to add Attribute B connected by AND at the position of Attribute D. First, the row [00-1] representing Attribute B is added. Since the added attribute is connected to Attribute D by AND, to balance the impact of the addition operation, [00-1] is subtracted from the row

[11] of the parent attribute A of Attribute B in the matrix. Since the parent attribute A has a sibling attribute C, the same operation of subtracting [00-1] needs to be performed on the row representing Attribute C. After the update, the rows representing Attribute A and Attribute C in the matrix are both

[111] .

[0106] The above are only the preferred embodiments of the present invention. All equivalent changes and modifications made according to the scope of the patent application of the present invention shall fall within the scope of the present invention.

Claims

1. An electronic health record sharing method that supports dynamic updates and fast data access, providing a system including a trusted authorization center, a cloud server, data users, and data owners, characterized in that, Including the following steps: Step S1: The trusted authorization center and the cloud server each generate public parameters and private keys, publish their public parameters, and secretly store the private keys; Step S2: The data user generates a user public key and a secret value, and at the same time applies to the trusted authorization center for registration. The trusted authorization center calculates and distributes the corresponding attribute keys according to the attribute set submitted by the user; Step S3: The data owner generates an access policy according to the expected sharing group of the electronic health record, encrypts the electronic health record to be shared through the access policy to generate a ciphertext, and uploads the ciphertext to the cloud server. The cloud server saves the ciphertext after blinding it; Step S4: The data owner sends an update request to the cloud server, and the cloud server updates the access policy of the corresponding ciphertext; Step S5: The data user submits a decryption key application to the cloud server for data access. The cloud server performs an outsourced decryption operation to generate an outsourced ciphertext and returns it to the data user; after receiving the outsourced ciphertext, the data user decrypts the outsourced decryption result using its own secret value; The specific content of step S1 is as follows: (1) The Trusted Authorization Center provides an elliptic curve group and a bilinear mapping according to the security parameter λ where represents an elliptic curve cyclic group of order p, represents a bilinear mapping, and let Z p represent the integer group of order p; (2) The trusted authorization center selects random numbers α, β ∈ Z p , and random group elements Then it calculates the α-th power of g, g α and the β-th power of g, g β ; (3) The trusted authorization center discloses public parameters Save the master private key msk = {α, β}; (4) The cloud server randomly selects and saves the cloud server private key sk c = s c , where s c ∈Z p ; (5) Cloud server calculates the s-th power of g c power and discloses its public parameters The specific content of step S3 is as follows: (1) The data owner prepares the electronic health record information msg to be encrypted and the corresponding access policy matrix (M, ρ), where M represents a matrix of size l×n, and ρ is the mapping from the row number of the matrix to the corresponding attribute; (2) The data owner selects the secret s to be shared and selects l - 1 random numbers to form a vector x = (s, x2, …, x l ) T ; For \(i\in[l]\), the data owner computes \(\lambda\) i = \(M\) i \(x\); the data owner selects \(l\) random numbers \(t_1,t_2,\ldots,t\) l \(\in\mathbb{Z}\) p , computes the ciphertext component \(C = \text{msg}\cdot e(g,\mathsf{pp}\) c ) αs , \(C_0 = g\) s ; For \(i\in[l]\), the data owner calculates the ciphertext components related to the attributes in the access policy For \(k\in[l]\), the data owner calculates the ciphertext components related to the attributes in the access policy Finally, generate the ciphertext \(CT =\{(M,\rho),C,C_0,\{C i,1 ,C i,2 ,C i,3 \}\ i∈[l] ,\{H k \}\ k∈[l] \}; (3) The data owner sends the ciphertext CT to the cloud server; After the cloud server receives the ciphertext CT, it selects a random number to blind the ciphertext and secretly stores it (5) The cloud server stores the blinded ciphertext CT = {(M, ρ), C, C0, {C i,1 , C i,2 , C i,3} i∈[l] , {H k} k∈[l]}; The specific content of step S4 is as follows: (1) For a certain attribute to be updated, the data owner makes loc represent the position of the attribute to be modified in the access policy, makes op represent the operation to be performed on this attribute, and makes cont represent the attribute used for the update operation; the update operation op includes ADD AND , ADD OR , DEL AND , DEL OR 4 options, where ADD AND means adding an attribute connected by AND after the attribute at the loc position, ADD OR means adding an attribute connected by OR after the attribute at the loc position, DEL AND means deleting the attribute connected by AND at the loc position, DEL OR means deleting the attribute connected by OR at the loc position; then the data owner sends an update request APupdate = {loc i , op i , cont i} i∈[|APupdate|] ; (2) Let l' be the number of rows of the updated access policy matrix, and the cloud server selects a random number For j ∈ [l'], the cloud server calculates the ciphertext update component where is the random number used to protect {H k} k∈[l] in the ciphertext CT; The cloud server updates the ciphertext C = C η , C0 = C0 η , for i ∈ [l'], calculate C i,1 = C i,1 ·C 1,i u , C i,2 = C i,2 ·C 2,i u , C i,3 = C i,3 ·C 3,i u , for k ∈ [l'], calculate (3) Cloud service storage updates the ciphertext CT = {(M, ρ), C, C0, {C i,1 , C i,2 , C i,3} i∈[l’] , {H k} k∈[l’]}}。 2. The method for sharing electronic health records supporting dynamic update and fast data access according to claim 1, wherein The specific content of step S2 is as follows: (1) The data user randomly selects and saves the data user secret value sv u = s u , where s u ∈Z p ; (2) The data user calculates the s-th power of g u power and discloses its public key (3) The data user provides the set of attributes S = {A1, A2, …, A k} and their public key pp u ; (4) The trusted authorization center selects k + 1 random numbers r, r1, r2, …, r k ∈Z p , and calculates the decryption key component K0 = pp u α w r , and the decryption key component K1 = g r ; For the trusted center calculates the decryption key components related to the attribute A τ and finally generates the decryption key dk for the data user's attribute set S = {S, K0, K1, {K S , K τ,2 , K τ,3} τ∈[k]}; (5) The trusted authorization center sends the decryption key dk S to the data user.

3. The method for sharing electronic health records supporting dynamic update and fast data access according to claim 2, wherein The ADD AND operation is as follows: If the initial access policy (M, ρ) contains content, the cloud server outputs ⊥; otherwise, for the attribute attr ∈ content, the cloud server selects random numbers t, x l+1 ∈ Z p and calculates the new ciphertext C attr,2 =(u attr h) -t , C attr,3 = g t , where Let ATTR be the parent attribute of attr, and the cloud server calculates If the parent attribute ATTR itself has a sibling attribute ATTR', the cloud server needs to perform the same operation on its sibling attribute, that is, calculate Subsequently, the cloud server adds H l+1 to {H k}.

4. The method for sharing electronic health records supporting dynamic update and fast data access according to claim 2, wherein The ADD OR operation is as follows: If the initial access policy (M, ρ) contains content, the cloud server outputs ⊥; otherwise, for the attribute attr ∈ content, the cloud server selects a random number t ∈ Z p ; Since the newly added attribute attr is connected to the attributes in the access policy through OR, the secret share corresponding to attr is the same as the attribute located at the loc position; Let l_a be the row in the matrix corresponding to the newly added attribute, and the cloud server calculates the newly added ciphertext C attr,2 =(u attr h) -t , C attr,3 =g t .

5. The method for sharing electronic health records supporting dynamic update and fast data access according to claim 2, wherein The DEL AND operation is as follows: If the initial access policy (M, ρ) does not contain content, the cloud server outputs ⊥; otherwise, for the attribute attr ∈ content, the cloud server calculates the elements related to the secret sharing of the attribute attr through the access policy matrix M and H k and deletes {C , C attr,1 , C attr,2 , C attr,3} from the ciphertext CT; Let ATTR be the parent attribute of attr, and the cloud server calculates If the parent attribute ATTR itself has a sibling attribute ATTR', the cloud server needs to perform the same operation on its sibling attribute, that is, calculate Finally, the cloud server deletes H k from {H l_attr .

6. The method for sharing electronic health records supporting dynamic update and fast data access according to claim 2, characterized in that The DEL OR operation is as follows: If the initial access policy (M, ρ) does not contain content, the cloud server outputs ⊥; otherwise, for the attribute attr ∈ content, the cloud server directly deletes {C attr,1 , C attr,2 , C attr,3}.

7. The method for sharing electronic health records supporting dynamic update and fast data access according to claim 2, characterized in that The specific content of step S5 is as follows: (1) After the cloud server receives the decryption key dk submitted by the data user, it compares it with the access policy in the ciphertext; S After that, it compares with the access policy in the ciphertext; (2) If the attributes in the key can satisfy the access policy, the cloud server calculates Subsequently, the cloud server sends the result CT of the outsourced computation out ={CT pre , C'} to the data user; (3) If the attributes in the key cannot satisfy the access policy, the cloud server returns ⊥, indicating that the algorithm stops; (4) The corresponding data user uses the secret value sv saved by himself / herself after receiving the outsourcing decryption result from the cloud server u Restore the electronic health record information Complete one data access.

Citation Information

Patent Citations

  • Cloud storage outsourced decryption attribute-based encryption method capable of limiting access times

    CN109639677A

  • Multi-authorization center access control method supporting strategy hiding and cloud storage system

    CN110099043A