Fine-Grained Weighted Access Control with Keyword Search and Malicious User Tracing for Cloud-Based mHealth Systems
摘要
Mobile healthcare (mHealth) empowers individuals to generate and share their Personal Health Records (PHRs) to facilitate remote telemedicine services, leveraging advanced technologies such as the Internet of Things (IoT) and cloud computing. To ensure secure data sharing in public clouds, Ciphertext-Policy Attribute-Based Encryption (CP-ABE) has been widely adopted for fine-grained access control over sensitive PHR data. However, malicious yet authorized users may still leak their decryption keys for illicit financial gain, underscoring the need for traceability and timely revocation of such misbehaving entities. Moreover, most existing CP-ABE schemes support only binary or multi-valued attributes, lacking the expressiveness of weighted attributes, which are crucial for fine-grained policy representation in healthcare scenarios. In this paper, we propose a Searchable Weighted Attribute-based Construction with Traceability (SWACT). In SWACT, each attribute is characterized by both its name and weight, enabling more flexible and expressive access policies while reducing policy complexity without expanding ciphertext size. The scheme incorporates a traceability mechanism to identify malicious users and employs a user binary tree structure to support efficient and scalable direct revocation. Additionally, SWACT enables authorized keyword search and outsourced decryption, significantly reducing computational and communication overhead on the user side. Extensive security analysis and performance evaluation demonstrate that SWACT achieves robust security, high efficiency, and enhanced functionality, making it well-suited for practical mHealth systems.