Attribute-Based Encryption for Electronic Medical Cloud Health Files

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current medical data access control systems in electronic medical clouds face challenges such as exposure of user attribute information, high decryption complexity, and inflexible access policies, particularly in protecting sensitive health data, which compromises privacy and security.

Innovation Solution

A health file access control system and method that utilizes a medical management center to generate system public and private keys, enabling health file users to encrypt and decrypt health files securely, while hiding attribute values and ensuring efficient decryption without exposing access policies, using attribute-based encryption with constant-sized public keys and low computational complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If attribute-based encryption is used to protect health file privacy, then data confidentiality is improved, but user attribute information is exposed in the ciphertext

Engineering Contradiction:
Improvedata confidentialityVSAvoidattribute privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts and removes the harmful element (attribute values) from the ciphertext structure. The access policy is represented only by attribute names without exposing actual attribute values, thereby protecting user privacy while maintaining encryption functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary mechanism where the ciphertext contains encrypted access policies that mediate between the need for access control and privacy protection. The attribute hiding technique acts as an intermediary layer that prevents direct exposure of sensitive attribute information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If existing attribute-hiding attribute-based encryption schemes are used, then attribute privacy is protected, but decryption computation complexity increases

Engineering Contradiction:
Improveattribute privacyVSAvoiddecryption computation complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent changes the parameters of the encryption scheme by using constant-sized public keys and optimizing the ciphertext structure. These parameter changes reduce the computational burden during decryption while maintaining attribute hiding capabilities.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If fine-grained access control is implemented, then data security is improved, but access policy flexibility is reduced

Engineering Contradiction:
Improvedata securityVSAvoidaccess policy flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access policies that can be flexibly configured and modified. The system allows access policies to be dynamically adjusted based on different scenarios while maintaining fine-grained control, making the access control mechanism both secure and adaptable.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11379609B2Health file access control system and method in electronic medical cloud
Publication Date: 2022.07.05 XIAN UNIV OF POSTS & TELECOMM
  • US11379609B2 patent drawing
  • US11379609B2 patent drawing
  • US11379609B2 patent drawing

AI summary

The present invention provides a health file access control system and method in an electronic medical cloud. The system comprises: a medical management center unit configured to generate a system public key and a system private key, and generate a private key for corresponding utilizer's attributes according to the system public key, the system private key, and a set of utilizer's attributes; an electronic medical cloud storage unit configured to receive and store a privacy-protected health file ciphertext; and at least one health file user access unit configured to encrypt the health file according to the system public key to obtain the privacy-protected health file ciphertext, and/or generate the set of utilizer's attribute, and decrypt the privacy-protected health file ciphertext according to the system public key and the private key for utilizer's attributes. The health file access control system and method in the electronic medical cloud provided by the present invention not only ensure the confidentiality of the health file, but also improve the security and calculation efficiency of the health file access.