Revocable and Flexible Privacy-Preserving Data Computing with Bilateral Access Control for Cloud-Fog Based EHR Systems
Cloud-fog-assisted electronic health record (EHR) systems offer promising solutions for large-scale medical data storage and processing. However, they also raise critical privacy concerns, particularly regarding secure computation over sensitive data, fine-grained bilateral access control, dynamic revocation, and decryption key exposure. Existing cryptographic primitives, such as functional encryption and matchmaking encryption, address some of these challenges individually but fail to offer a unified solution. In this work, we design a revocable and privacy-preserving data computing system with bilateral access control (RPDC-BAC) for cloud-fog-assisted EHR sharing, built upon our newly proposed cryptographic primitive, called server-aided revocable attribute-based matchmaking functional encryption (SR-AB-MFE). Specifically, our scheme supports expressive bilateral access control and enables computation over encrypted data. In addition, we integrate a time-evolving decryption key mechanism to resist decryption key exposure and a server-aided revocation mechanism to efficiently exclude revoked users. To further reduce receiver-side overhead, fog nodes are delegated to verify the authenticity of the ciphertext and perform partial decryption. We formally define the syntax and construction of the SR-AB-MFE scheme, prove its security under static assumptions, and analyze the security of the proposed RPDC-BAC system against practical threat scenarios. Finally, we demonstrate the efficiency and practicality of our design through comprehensive experimental evaluation.
Paper
The full text of this publication is not hosted on 44B due to licensing.
Read it at OpenAlex