This paper proposes a novel efficient and privacy-preserving scheme, named SAMA, designed to support secure aggregation and sharing of data intended for users and multiple data recipients and fine-grain access control based on a user-centric approach. It achieves this by deploying two key ideas. First, it uses a multi-key homomorphic cryptosystem to allow flexibility in accommodating both single and multi-user data processing as well as preserving the privacy of users while processing their IoT health data. Second, it uses ciphertext-policy attribute-based encryption to support flexible access control, which ensures users are able to grant data access securely and selectively. Formal security and privacy analyses show that SAMA supports data confidentiality and authorisation. The scheme has also been analysed in terms of computational and communication overheads to demonstrate that it is more efficient than the relevant state-of-the-art solutions.
翻译:本文提出了一个新的高效和隐私保护计划,名为SAMA,旨在支持安全地汇总和共享供用户和多个数据接收者使用的数据,以及基于以用户为中心的细粒访问控制,通过部署两个关键理念实现这一点。首先,它使用多关键同质加密系统,允许灵活地兼顾单一和多用户数据处理,并在处理其IOT健康数据时保护用户的隐私。第二,它使用基于密码政策的属性加密支持灵活的访问控制,确保用户能够安全和有选择地提供数据访问。正式的安全和隐私分析表明SAMA支持数据保密和授权。还从计算和通信间接费用的角度分析了该计划,以表明它比相关的最新解决方案更有效。