西安电子科技大学学报 ›› 2024, Vol. 51 ›› Issue (1): 165-176.doi: 10.19665/j.issn1001-2400.20230104

• 网络空间安全 • 上一篇    下一篇

支持受控共享的医疗数据隐私保护方案

郭庆1,2(), 田有亮1,2,3()   

  1. 1.贵州大学 计算机科学与技术学院,贵州 贵阳 550025
    2.贵州大学 公共大数据国家重点实验室,贵州 贵阳 550025
    3.贵州大学 密码学与数据安全研究所,贵州 贵阳 550025
  • 收稿日期:2022-10-27 出版日期:2024-01-20 发布日期:2023-09-05
  • 通讯作者: 田有亮(1982—),男,教授,博士,E-mail:youliangtian@163.com
  • 作者简介:郭庆(1997—),女,贵州大学硕士研究生,E-mail:qingguo_gq@163.com
  • 基金资助:
    国家重点研发计划(2021YFB3101100);国家自然科学基金联合基金重点支持(U1836205);国家自然科学基金(62272123);贵州省高层次创新型人才项目(黔科合平台人才[2020]6008);贵州省科技计划(黔科合平台人才[2020]5017);贵州省科技计划(黔科合支撑[2022]一般065)

Medicaldata privacy protection scheme supporting controlled sharing

GUO Qing1,2(), TIAN Youliang1,2,3()   

  1. 1. College of Computer Science and Technology,Guizhou University,Guiyang 550025,China
    2. Guizhou Provincial Key Laboratory of Public Big Data,Guiyang 550025,China
    3. Institute of Cryptography & Data Security,Guizhou University,Guiyang 550025,China
  • Received:2022-10-27 Online:2024-01-20 Published:2023-09-05

摘要:

患者医疗健康数据信息的合理利用促进了医学研究机构的发展。针对目前患者与医疗研究机构间共享医疗数据隐私易泄露,以及患者对医疗数据的使用情况不可控的问题,提出一种支持受控共享的医疗数据隐私保护方案。首先,将区块链与代理服务器结合设计医疗数据受控共享模型,区块链矿工节点分布式构造代理重加密密钥,使用代理服务器存储和转换医疗数据密文,利用代理重加密技术在保护患者隐私的同时实现医疗数据安全共享。其次,设计用户权限动态调整机制,由患者与区块链授权管理节点交互通过授权列表来更新医疗数据访问权限,实现患者对医疗数据的可控共享。最后,安全性分析表明,所提方案可以在医疗数据隐私保护的同时,实现医疗数据动态共享,并且可以抵抗共谋攻击。性能分析表明,该方案在通信开销、计算开销方面具有优势,适用于患者或医院与研究机构间的数据受控共享。

关键词: 区块链, 医疗数据, 受控共享, 代理重加密, 隐私保护

Abstract:

The rational use of patient medical and health data information has promoted the development of medical research institutions.Aiming at the current difficulties in sharing medical data between patients and medical research institutions,data privacy is easy to leak,and the use of medical data is uncontrollable,a medical data privacy protection scheme supporting controlled sharing is proposed.Firstly,the blockchain and proxy server are combined to design a medical data controlled sharing model that the blockchain miner nodes are distributed to construct proxy re-encryption keys,and the proxy server is used to store and convert medical data ciphertext,and proxy re-encryption technology is used to bring about the secure sharing of medical data while protecting the privacy of patients.Secondly,a dynamic adjustment mechanism of user permissions is designed that the patient and the blockchain authorization management nodes update the access permissions of medical data through the authorization list to realize the controllable sharing of medical data by patients.Finally,the security analysis shows that the proposed scheme can bring about the dynamic sharing of medical data while protecting the privacy of medical data,and can also resist collusion attacks.Performance analysis shows that this scheme has advantages in communication overhead and computing overhead,and is suitable for controlled data sharing between patients or hospitals and research institutions.

Key words: blockchain, medical data, controlled sharing, proxy re-encryption, privacy protection

中图分类号: 

  • TP309
Baidu
map