Medical data security system and method based on attribute-based signcryption ABSC
By adopting a method based on attribute base signature technology combined with blockchain and edge computing in the medical data management system, the security risks of centralized storage, insufficient permission control and large-scale distributed data processing efficiency are solved, decentralized storage, fine-grained access control and high scalability are achieved, and data security and management efficiency are significantly improved.
Patent Information
- Application Number
- CN202510256537.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-05
- Publication Date
- 2025-06-24
AI Technical Summary
The current medical data management system has security risks of centralized storage, insufficient permission control, and efficiency problems in large-scale distributed data processing.
The attribute-based signature (ABSC) technology is adopted, combined with blockchain and edge computing, to achieve decentralized storage, fine-grained access control and high scalability. Ensure the immutability of data through blockchain, the ABSC mechanism realizes fine access control, and edge computing improves computing efficiency and scalability.
It significantly improves data security, management efficiency and system scalability, and meets the security and performance needs in the medical IoT environment.
Smart Images

Figure CN120197190A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of medical data security, and particularly to a medical data security system and method based on attribute-based signcryption (ABSC). Background Art
[0002] With the in-depth development of digitalization of medical information, it has become particularly important to protect the security and privacy of patient data. Most current medical data management systems rely on a centralized storage architecture, which has potential risks of single-point failure and data leakage. In addition, traditional encryption methods are difficult to achieve fine-grained access control, resulting in insufficient permission management. Especially in the Internet of Medical Things (IoMT) environment, where data is widely distributed, existing solutions cannot effectively cope with the challenges of large-scale distributed data processing. Therefore, there is an urgent need for a comprehensive solution that can provide decentralized storage, fine-grained access control, and high scalability.
[0003] To solve the above problems, the present invention proposes a medical data security framework based on attribute-based signcryption (ABSC) technology. By combining blockchain and edge computing, it realizes the efficient and secure management of data. Blockchain technology ensures the immutability of data and eliminates the single-point failure risk of centralized storage. The ABSC mechanism realizes fine-grained access control based on user attributes and prevents unauthorized access. Edge computing improves the scalability and computing efficiency of the system by dispersing data preprocessing to edge nodes, which is particularly suitable for large-scale data management in the IoMT environment.
[0004] In summary, the new framework can comprehensively improve the performance of the system in terms of data security, privacy protection, computing efficiency, and scalability. Summary of the Invention
[0005] The purpose of the present invention is to provide a medical data security system and method based on attribute-based signcryption (ABSC), which solves the problems of centralized storage security risks, insufficient permission control, and efficiency in large-scale distributed data processing existing in current medical data management systems.
[0006] To achieve the above purpose, the present invention provides a medical data security system based on attribute-based signcryption (ABSC), including a system initialization module, a key generation and registration module, a data encryption and storage module, a data access and decryption module, a smart device (SD), and an edge node (ED);
[0007] The system initialization module generates the public key and the master key of the system through a trusted authority (TA), and is responsible for participating in the authentication of entities and key distribution;
[0008] The key generation and registration module generates random values for participating entities through a trusted authority (TA), and obtains a signature key, a verification key, and a decryption key;
[0009] The data encryption and storage module encrypts the medical data collected by the intelligent device SD and stores the encrypted data on the blockchain through the edge node ED;
[0010] The data access and decryption module is used to decrypt the data stored on the blockchain and has a predefined access control policy built in.
[0011] Preferably, the system initialization module is also used to generate three cyclic groups, generate generators and generate bilinear maps. The entities include the service provider SP, the data owner DO, and the data requester DR.
[0012] Preferably, the data encryption and storage module adopts an access tree structure. Through the access control policies of leaf nodes and non-leaf nodes, it controls the access rights of the intelligent device SD to the encrypted data. The access tree structure T performs AND or OR logical operations through threshold gates.
[0013] The present invention also provides a medical data security method based on attribute-based signcryption ABSC, including the following steps:
[0014] S1. System initialization:
[0015] When the system starts, a trusted authority TA generates the keys of the system, including the public key and the master key, and is responsible for participating in the entity authentication and key distribution;
[0016] S2. Key generation and registration:
[0017] The trusted authority TA generates random values for each participating entity and obtains the signature key, verification key, and decryption key corresponding to each participating entity through authentication;
[0018] S3. Data encryption and storage:
[0019] The intelligent device SD collects medical data, and the edge node ED performs data preprocessing and encryption. The encrypted data is stored on the blockchain;
[0020] S4. Data access and decryption:
[0021] The data requester DR makes a data access request. The data owner DO decides whether to authorize according to the predefined access control policy. When the authorization is passed, the data requester DR obtains the encrypted data through the blockchain network and performs a decryption operation using its decryption key.
[0022] Preferably, S1 is specifically:
[0023] S11. For the service provider SP with a pseudo-identity id, according to the security parameter λ, generate three cyclic groups G1, G2, and G3 of prime order p;
[0024] S12. Generate respective generators g1 and g2 for G1 and G2, and generate a bilinear mapping e: G1×G2→G3;
[0025] S13. Select two random exponents α, β ∈ Z p , then the master key mk is calculated by the following formula:
[0026]
[0027] S14. Select hash functions H1: {0,1} * →{0,1} λ and H2: {0,1} * →Z p ; Calculate and t = e(g1, g2) α by a trusted authority TA, and h and t are applied to the subsequent encryption process to achieve the encryption of information;
[0028] S15. The trusted authority TA publishes the public parameters to all relevant entities in the blockchain network, and the formula is as follows:
[0029] pk = (p, G1, G2, H2, g1, g2, h, t).
[0030] Preferably, S2 is specifically:
[0031] S21. The participating entity joins the blockchain network and first registers, and then the trusted authority TA authenticates its identity. After passing the identity authentication, the trusted authority TA runs the KeyGen algorithm and selects a random value r enc , r sign ∈Z p and calculates:
[0032]
[0033] where D enc is a component of the subsequent decryption key sk, and k sign , k ver represent the signature key and the verification key respectively, and are used for encrypting signatures and verifying signatures respectively;
[0034] S22. The trusted authority TA calculates:
[0035] and
[0036] where r j is another value randomly selected for each attribute j ∈ S in the attribute set S, and r j ∈Z p ;
[0037] S23. The trusted authority TA returns the asymmetric key given by for subsequent decryption;
[0038] S24. The trusted authority TA distributes k sign to the participating service providers SP through a secure communication channel, and distributes sk to the intelligent device SD with the attribute set S; for the intelligent device SD' not connected to the trusted authority TA, the corresponding sk is pre-stored in SD' through a predefined access control policy.
[0039] Preferably, S3 is specifically as follows:
[0040] S31. The registered service provider SP generates a random symmetric key k sym , and uses k sym to encrypt the message msg to generate the ciphertext C msg ;
[0041] S32. The service provider SP defines an access tree structure T to represent a group of intelligent devices SD that satisfy the access policy;
[0042] S33. Each non-leaf node in the access tree represents a threshold gate, which performs AND or OR logical operations according to the conditions satisfied by the child nodes;
[0043] S34. Define the function index(x) to represent the order of the leaf nodes of the access tree, and define the set attibute(x) as the attributes of the leaf node x. The service provider SP signs k sym under the access tree structure T.
[0044] Preferably, in S33, for any internal node x in the access tree, let num x be the number of child nodes of x, and k x be the threshold, where 1 ≤ k x ≤ num x ;
[0045] When k x = 1, the threshold gate represents an OR operation, that is, as long as one child node satisfies the condition, the gate opens;
[0046] When k x = num x , it represents an AND operation, that is, all child nodes must satisfy the condition for the threshold gate to open.
[0047] Preferably, in S34, the service provider SP signs k sym under the access tree structure T, and the specific process is as follows:
[0048] First, after the smart device SD collects the data of the data owner DO, the service provider SP runs the SignCrypt algorithm to select a polynomial for each node, including the leaf nodes of node x in the access tree structure T. The polynomial is selected in a top-down manner starting from the root node R, and a value s ∈ Z is randomly selected starting from R p , and q R (0) = s; Then, a d p value is randomly selected from Z x to fully define q x ;
[0049] For other nodes x, assign q x (0) = q par.(x) (index(x)), and a value d p is randomly selected from Z x to fully define q x , let Y denote the set of leaf nodes in the access tree structure T. The service provider SP randomly selects a value ζ ∈ Z p and executes the following formula:
[0050]
[0051] C = h s ;
[0052]
[0053] δ = e(C, g2) ζ ;
[0054] π = H1(msg) + H2(δ);
[0055]
[0056] where H1 and H2 represent hash encryption, is represented as the encrypted value of k sym , C y , C' y are represented as the encrypted values of each leaf node and its attributes in the access tree. δ is used for subsequent decryption and verification of the authenticity of k sym , π represents the signature of the service provider SP on the message msg, and ω and ψ are also used for subsequent authenticity verification;
[0057] Then the signcryption ciphertext ST under the access tree structure T is:
[0058]
[0059] Record the public key pk of the given service provider SP, the pseudo-identity id, the hash value h2 of the block, and the ciphertext ST encrypted by the signature, including the signature π of the service provider SP, and send this record to the blockchain network for verification. The specific form is as follows:
[0060] R = (pk, id, h2, ST).
[0061] Preferably, in S4, after the smart device SD receives the ciphertext ST encrypted by the signature of the blockchain and the signature π of the service provider SP, it first decrypts to recover the symmetric key k sym and the encrypted message msy, then checks the integrity of the encrypted message msg, and finally verifies the signature.
[0062] Therefore, the present invention adopts the above-mentioned medical data security system and method based on attribute-based signcryption ABSC, and the beneficial effects are as follows:
[0063] (1) The present invention proposes a medical data security framework combining blockchain and edge computing, which adopts the attribute-based signcryption (ABSC) technology to solve the security and privacy problems in medical data management; this framework collects medical data through smart devices, performs data preprocessing and encryption at the edge nodes, and securely stores the encrypted data on the blockchain.
[0064] (2) Based on the user's attribute set, the system proposed by the present invention realizes fine-grained access control to ensure that only users who meet specific conditions can access sensitive information.
[0065] (3) The medical data security framework combining blockchain and edge computing proposed by the present invention also ensures the transparency and immutability of data through the decentralized blockchain technology, while improving the scalability and computing efficiency of the system in the medical Internet of Things environment.
[0066] (4) The experimental results show that the present invention significantly improves the data security, management efficiency, and processing ability of resource-constrained devices.
[0067] Next, through the drawings and embodiments, the technical solutions of the present invention will be further described in detail. Description of the Drawings
[0068] Figure 1 is the overall structural block diagram of an embodiment of the medical data security system based on attribute-based signcryption ABSC of the present invention;
[0069] Figure 2 is the overall working flow chart of an embodiment of the medical data security method based on attribute-based signcryption ABSC of the present invention. Detailed Embodiments
[0070] The technical solutions of the present invention will be further described below with reference to the accompanying drawings and embodiments.
[0071] Unless otherwise defined, the technical terms or scientific terms used in the present invention shall have the ordinary meanings understood by those of ordinary skill in the field to which the present invention pertains. The "first", "second" and similar terms used in the present invention do not denote any order, quantity or importance, but are only used to distinguish different components. The terms such as "comprising" or "including" mean that the elements or items appearing before this term cover the elements or items listed after this term and their equivalents, without excluding other elements or items. The terms such as "connected" or "coupled" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The terms such as "upper", "lower", "left", "right" are only used to indicate relative positional relationships, and when the absolute position of the object being described changes, the relative positional relationship may also change accordingly.
[0072] A medical data security system based on attribute-based signcryption (ABSC) includes a system initialization module, a key generation and registration module, a data encryption and storage module, a data access and decryption module, smart devices (SD) and edge nodes (ED).
[0073] The system initialization module generates the public key and the master key of the system through a trusted authority (TA), and is responsible for participating in entity authentication and key distribution; the entities include service providers (SP), data owners (DO) and data requesters (DR).
[0074] The system initialization module is further used to generate three cyclic groups, generate their respective generators and generate a bilinear map to ensure the security and efficiency of key generation.
[0075] The key generation and registration module generates random values for the participating entities through a trusted authority (TA), and obtains signature keys, verification keys and decryption keys to ensure the identity legitimacy and data security of service providers (SP), data owners (DO) and data requesters (DR).
[0076] The data encryption and storage module encrypts the medical data collected by smart devices (SD), and stores the encrypted data on the blockchain through edge nodes (ED) to ensure the immutability and transparency of the data.
[0077] The data encryption and storage module adopts an access tree structure. Through the access control policies of leaf nodes and non-leaf nodes, it controls the access rights of the smart device SD to encrypted data. The access tree structure T performs AND or OR logical operations through threshold gates to ensure that only eligible users can decrypt and access the data stored on the blockchain.
[0078] The data requester obtains the decryption key through the attribute-based signcryption mechanism. The data access and decryption module is used to decrypt the data stored on the blockchain and ensure the legal access to the data through the built-in predefined access control policy. As Figure 1 shows the interaction process of modules such as the smart device SD, edge node ED, service provider SP, data owner DO, and data requester DR
[0079] As Figure 2 shown, the present invention also provides a medical data security method based on attribute-based signcryption (ABSC), which includes the following four steps: (1) system initialization, (2) key generation and registration, (3) data encryption and storage, and (4) data access and decryption. These four steps cooperate with each other to form a complete medical data security management process. In this process, through the attribute-based signcryption (ABSC) technology, combined with blockchain and edge computing, the decentralized storage of data, fine-grained access control, and efficient encryption and decryption operations are realized, ensuring the security and privacy of data. Specifically:
[0080] S1. System initialization:
[0081] When the system starts, the trusted authority TA generates the keys of the system to ensure the basic security of all subsequent operations, including generating the public key and the master key of the system, and is responsible for participating in the authentication and key distribution of entities. All participating service providers SP, data owners DO, and data requesters DR must be authenticated to obtain the corresponding keys. Ensure the legality, security, and authenticity of the identity of each entity in the authentication and key distribution process in the system. The trusted authority TA will only participate in the system initialization and entity registration phases. Once the tasks of these phases are completed, the trusted authority TA will remain offline to ensure the decentralization and security of the system.
[0082] Specifically, S1 is as follows:
[0083] S11. For the service provider SP with a pseudo-identity id, generate three cyclic groups G1, G2, and G3 of prime order p according to the security parameter λ;
[0084] S12. Generate their respective generators g1 and g2 for G1 and G2 respectively, and generate an efficiently computable bilinear mapping e: G1×G2→G3;
[0085] S13. Select two random exponents α, β ∈ Z p , then the master key mk is calculated as follows:
[0086]
[0087] S14. Select hash functions H1: {0, 1} * →{0, 1} λ and H2: {0, 1} * →Z p ; calculate and t = e(g1, g2) α through a trusted authority TA, where is applied to the subsequent encryption process to achieve the encryption of information;
[0088] S15. The trusted authority TA publishes the public parameters to all relevant entities in the blockchain network, and the formula is as follows:
[0089] pk = (p, G1, G2, H2, g1, g2, h, t).
[0090] S2. Key generation and registration:
[0091] In this stage, the present invention generates random values for each entity participating in the blockchain network, such as service providers SP, data owners DO, and data requesters DR, through a trusted authority TA, and obtains three important keys corresponding to each participating entity through authentication: a signature key, a verification key, and a decryption key.
[0092] With these keys, the service provider SP will use these keys to encrypt and sign the data it processes to ensure the integrity and confidentiality of the data during transmission and storage. The data requester DR obtains the corresponding decryption key through the attribute set so that it can decrypt the data when the access policy is met. This mechanism ensures that only users who meet specific conditions can access sensitive information, further enhancing the security of the data.
[0093] S2 is specifically as follows:
[0094] S21. When the participating entities, namely service providers SP, data owners DO, and data requesters DR, join the blockchain network, they first register, and then the trusted authority TA authenticates them. After passing the authentication, the trusted authority TA runs the KeyGen algorithm and selects random values r enc , r sign ∈Z p and calculates:
[0095]
[0096]
[0097] Among them, D enc is a component of the subsequent decryption key sk. For details, see S23; k sign and k ver respectively represent the signature key and the verification key, which are used for encrypting signatures and verifying signatures respectively.
[0098] S22. The trusted authority TA calculates:
[0099] and
[0100] Among them, r j is another value randomly selected for each attribute j ∈ in the attribute set S. r j ∈Z p ;
[0101] S23. The trusted authority TA returns the asymmetric key given by for subsequent decryption;
[0102] S24. The trusted authority TA distributes k sign to the participating service providers SP through a secure communication channel, and distributes sk to the smart device SD with the attribute set S; in addition, for the smart device SD' not connected to the trusted authority TA, the corresponding sk is pre-stored in SD' through a predefined access control policy.
[0103] S3. Data encryption and storage:
[0104] The smart device SD in the system is responsible for collecting the medical data of patients. After the data is collected, these smart devices SD first perform data preprocessing and then encrypt the data. The encrypted data is uploaded to the edge node ED for storage. The edge node ED is not only responsible for data processing and storage, but also publishes the encrypted data to the blockchain. Through the characteristics of the blockchain, the transparency and immutability of the data are ensured.
[0105] In addition, the attribute-based signcryption ABSC technology is adopted. Through the access tree structure T, it is ensured that only users who meet the preset attribute conditions can decrypt and access this data, thereby effectively controlling the data access rights and realizing the refined management of the data.
[0106] Specifically, S3 is as follows:
[0107] S31. The registered service provider SP generates a random symmetric key k sym , and uses k sym to encrypt the message msg, thereby generating the ciphertext C msg ;
[0108] S32. The service provider SP defines an access tree structure T to represent a set of smart devices SD that satisfy the access policy, that is, the access of the smart devices SD to the encrypted message is controlled through the access tree structure T;
[0109] S33. Each non-leaf node in the access tree represents a threshold gate, which performs an AND or OR logical operation according to the conditions satisfied by the child nodes, determined by the number of its child nodes and the threshold; while each leaf node represents an attribute.
[0110] For any internal node x in the access tree, let num x be the number of child nodes of x, and k x be the threshold, where 1 ≤ k x ≤ num x ;
[0111] When k x = 1, the threshold gate represents an OR operation, that is, as long as one child node satisfies the condition, the gate opens;
[0112] When k x = num x , it represents an AND operation, that is, all child nodes must satisfy the condition for the threshold gate to open.
[0113] S34. Define the function index(x) to represent the order of the leaf nodes of the access tree and help set unique values from 1 to num; at the same time, the set attibute(x) is also defined as the attribute of the leaf node x. Once the access tree structure T is defined, the service provider SP signs the k sym under the access tree structure T. The specific process is as follows:
[0114] First, after the smart device SD collects the data of the data owner DO, the service provider SP runs the SignCrypt algorithm to select a polynomial for each node, including the leaf nodes of the node x in the access tree structure T. These polynomials are selected in a top-down manner starting from the root node R. And starting from R, it randomly selects a value s ∈ Z p , and assigns q R (0) = s; then, it randomly selects a d p value from Z x to fully define q x .
[0115] On the other hand, for other nodes x, it also assigns q x (0) = q par.(x) (index(x)), and randomly selects a value d p from Z x to fully define qx , let \(Y\) denote the set of leaf nodes in the access tree structure \(T\), and the service provider \(SP\) randomly selects a value \(\zeta\in Z\) p and executes the following formula:
[0116]
[0117] \(C = h\) s ;
[0118]
[0119] \(\delta=e(C,g^{2})\) ζ ;
[0120] \(\pi = H_{1}(msg)+H_{2}(\delta)\);
[0121]
[0122] where \(H_{1}\), \(H_{2}\) denote hash encryption, denoted as the encrypted value of \(k\), \(C\) sym , \(C'\) y denoted as the encrypted values of each leaf node and its attributes in the access tree, \(\delta\) is used for subsequent decryption and verification of the authenticity of \(k\) y , \(\pi\) represents the signature of the service provider \(SP\) on the message \(msg\), and \(\omega\), \(\psi\) are also applied to subsequent authenticity verification. sym Then the symbol-encrypted ciphertext \(ST\) under the access tree structure \(T\) is formed as:
[0123] Finally, record the public key \(pk\) of the given service provider \(SP\), the pseudo-identity \(id\), the hash value \(h_{2}\) of the block, and the signature-encrypted ciphertext \(ST\), including the signature \(\pi\) of the service provider \(SP\), and send this record to the blockchain network for verification, in the following specific form:
[0124]
[0125] \(R=(pk, id, h_{2}, ST)\).
[0126] R = (pk, id, h2, ST).
[0127] S4. Data access and decryption:
[0128] When the data requester \(DR\) makes a data access request, it must first send a request to the data owner \(DO\). The data owner \(DO\) decides whether to authorize the access right of the requester according to the pre-defined access control policy. When the authorization is passed, the data requester \(DR\) will obtain the encrypted data through the blockchain network and perform decryption operations using the attribute-based signcryption \(ABSC\) mechanism and its decryption key. The whole process ensures the security of the data and the legitimacy of the requester, preventing unauthorized access.
[0129] After receiving the signed and encrypted ciphertext ST from the blockchain and the signature π from the service provider SP, the smart device SD first decrypts to recover the symmetric key k sym and the encrypted message msg, then checks the integrity of the encrypted message msg, and finally verifies the signature. The specific process is as follows:
[0130] First, the smart device SD executes the DesignCryption algorithm. Consider the recursive algorithm DecryptNode(ST, sk, x) that takes pk, ST, and sk as inputs. Here, sk has a set of attributes and a node x from the access tree T. If x is a leaf node, set i = attibute(x). For this case, the algorithm will return:
[0131]
[0132] On the other hand, if x is a non-leaf node, the algorithm first calls DecryptNode(ST, sk, z) for each leaf node z of node x, and the output will be stored as F z .
[0133] Let S x be a set of leaf nodes of x with an arbitrary storage size k x , and F for all child nodes z z ≠⊥. If the above set S x exists, the algorithm executes as follows to obtain F z :
[0134]
[0135] where i z = index(z), S' x = {index(z)||z ∈ S x};
[0136] After that, the DesignCryption algorithm calls the function of the root node r of the access tree. The smart device SD can recover the symmetric key, but only if it holds the attribute set S. After meeting the conditions, set After decryption, the symmetric key k' is calculated by the following formula sym :
[0137]
[0138] Subsequently, the device SD also calculates where Once k' is obtained sym, the smart device SD will use it to decrypt the message into msg'. Next, the smart device SD will calculate H1(msg') + H2(δ'), and if the final result is equal to π, the smart device SD can confirm that msg has not been modified.
[0139] Therefore, the present invention adopts the above-mentioned medical data security system and method based on attribute-based signcryption ABSC. By combining blockchain and edge computing, the present invention can provide decentralized storage, fine-grained access control, and high scalability, meeting the security and performance requirements in the Internet of Medical Things (IoMT) environment.
[0140] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that they can still modify or equivalently replace the technical solutions of the present invention, and these modifications or equivalent replacements do not make the modified technical solutions deviate from the spirit and scope of the technical solutions of the present invention.
Claims
1. A medical data security system based on attribute-based signcryption (ABSC), characterized by: It includes system initialization module, key generation and registration module, data encryption and storage module, data access and decryption module, smart device SD and edge node ED; The system initialization module generates the system's public key and master key through the trusted authority TA, and is responsible for the identity authentication and key distribution of participating entities; The key generation and registration module generates random values for participating entities through the trusted authority TA and obtains the signing key, verification key and decryption key; The data encryption and storage module encrypts the medical data collected by the smart device SD and stores the encrypted data on the blockchain through the edge node ED; The data access and decryption module is used to decrypt data stored on the blockchain and has built-in predefined access control policies.
2. A medical data security system based on attribute-based signcryption (ABSC) according to claim 1, characterized in that: The system initialization module is also used to generate three cyclic groups, generate generators and generate bilinear maps. The entities include the service provider SP, the data owner DO and the data requester DR.
3. A medical data security system based on attribute-based signcryption (ABSC) according to claim 2, characterized in that: The data encryption and storage module adopts an access tree structure, and controls the access rights of the smart device SD to the encrypted data through the access control strategy of leaf nodes and non-leaf nodes. The access tree structure T performs AND or OR logical operations through threshold gates.
4. A medical data security method based on attribute-based signcryption (ABSC), characterized in that: The following steps are involved: S1. System initialization: When the system starts, the trusted authority TA generates the system's keys, including public keys and master keys, and is responsible for the identity authentication and key distribution of participating entities; S2. Key generation and registration: Generate a random value for each participating entity through a trusted authority TA, and obtain the signature key, verification key, and decryption key corresponding to each participating entity through identity authentication; S3, data encryption and storage: Smart devices SD collect medical data, pre-process and encrypt the data at the edge node ED, and the encrypted data is stored on the blockchain; S4. Data access and decryption: The data requester DR makes a data access request, and the data owner DO decides whether to authorize it based on the pre-defined access control policy. Once the authorization is passed, the data requester DR obtains the encrypted data through the blockchain network and uses its decryption key to perform decryption operations.
5. According to claim 4, a medical data security method based on attribute-based signcryption (ABSC) is characterized in that: S1 is specifically: S11, for a service provider SP with a pseudo identity id, generate three cyclic groups G1, G2 and G3 of prime order p according to a security parameter λ; S12, generate generators g1 and g2 for G1 and G2 respectively, and generate a bilinear map e : G1×G2→G3; S13. Select two random exponents α, β∈Z p , then the master key mk is calculated by the following formula: S14. Select hash function H1: {0,1} * →{0,1} λ and G2: {0,1} * →Z p ; Calculated by a trusted authority TA and t = e(g1, g2) α , h and t are used in the subsequent encryption process to encrypt the information; S15. The trusted institution TA publishes the public parameters to all relevant entities of the blockchain network. The formula is as follows: pk=(p,G1,G2,H2,g1,g2,h,t).
6. A medical data security method based on attribute-based signcryption (ABSC) according to claim 5, characterized in that: S2 is specifically: S21. Participating entities must first register to join the blockchain network, and then the trusted institution TA authenticates their identity. After the identity is authenticated, the trusted institution TA runs the KeyGen algorithm and selects a random value r enc , r sign ∈Z p And calculate: Among them, D enc It is a component of the subsequent decryption key sk, k sign , k ver They represent the signing key and verification key, which are used to encrypt the signature and verify the signature respectively; S22. Calculation by the trusted institution TA: and Among them, r j Another value randomly selected for each attribute j∈S in the attribute set S, r j ∈Z p ; S23, the trusted institution TA returns The given asymmetric key is used for subsequent decryption; S24, the trusted institution TA sends k sign Assigned to the participating service providers SP, and assign sk to the smart device SD with the attribute set S; the smart device SD' that is not connected to the trusted organization TA saves the corresponding sk in SD' in advance through the predefined access control policy.
7. A medical data security method based on attribute-based signcryption (ABSC) according to claim 6, characterized in that: S3 is specifically: S31. The registered service provider SP generates a random symmetric key k sym , and use k sym Encrypt message msg, generate ciphertext C msg ; S32, the service provider SP defines an access tree structure T to represent a group of smart devices SD that meet the access policy; S33, each non-leaf node in the access tree represents a threshold gate, and an AND or OR logic operation is performed according to the conditions satisfied by the child nodes; S34. Define the function index(x) to represent the order of visiting the leaf nodes of the tree, define the set attibute(x) as the attributes of the leaf node x, and the service provider SP has access to the k nodes under the tree structure T. sym Sign.
8. The medical data security method based on attribute-based signcryption (ABSC) according to claim 7, characterized in that: In S33, for any internal node x in the access tree, let num x is the number of child nodes of x, k x is the threshold, where 1≤k x ≤num x ; When k x =1, the threshold gate represents an OR operation, that is, as long as one child node meets the condition, the gate is open; When k x =num x , it indicates an AND operation, that is, all child nodes must meet the conditions before the threshold gate is opened.
9. The medical data security method based on attribute-based signcryption (ABSC) according to claim 8, characterized in that: In S34, the service provider SP accesses the k sym Signing, the specific process is: First, after the smart device SD collects the data of the data owner DO, the service provider SP runs the SignCrypt algorithm to select a polynomial for each node, including the leaf node of node x in the access tree structure T. The polynomial is selected in a top-down manner starting from the root node R, and a value s∈Z is randomly selected starting from R. p , and assign q R (0) = s; Then, from Z p Randomly select d x The value is used to fully define q x ; For other nodes x, assign q x (0) = q par .(x)(index(x)), and from Z p Randomly select a value d from x To fully define q x , let Y represent the set of leaf nodes in the access tree structure T, and the service provider SP randomly selects a value And execute the following formula: C=h s ; π=H1(msg)+H2(δ); Among them, H1 and H2 represent hash encryption. Denoted as k sym The encrypted value of C y , C' y It is represented as the encrypted value of each leaf node and its attributes in the access tree, and δ is used for subsequent decryption and verification k sym The authenticity of , π represents the signature of the service provider SP on the message msg, ω, ψ are also used for subsequent authenticity verification; Then the symbolic encrypted ciphertext ST under the access tree structure T is: Record the public key pk of a given service provider SP, as well as the pseudo-identity id, the hash value h2 of the block, and the signature encrypted ciphertext ST, including the signature π of the service provider SP, and send the record to the blockchain network for verification. The specific form is as follows: R=(pk,id,h2,ST)。 10. A medical data security method based on attribute-based signcryption (ABSC) according to claim 9, characterized in that: In S4, after the smart device SD receives the blockchain’s signature encrypted ciphertext ST and the service provider SP’s signature π, it first decrypts and recovers the symmetric key k sym And encrypt the message msg, then check the integrity of the encrypted message msg, and finally verify the signature.