Single- and Extended-Authority CP-ABE for E-Healthcare Security in Cloud-IoT

Authors

  • Gurupriya K G Research Scholar, Research Department of Computer Science , AJK College of Arts and Science(Autonomous), Coimbatore, Tamilnadu-641105, India
  • Dr. A. S Aneeshkumar Research Supervisor and Head, PG & Research Department of Computer Science and Applications, AJK College of Arts and Science(Autonomous), Coimbatore, Tamilnadu-641105, India

DOI:

https://doi.org/10.70917/ijcisim-2026-5342

Keywords:

CP-ABE, E-Healthcare, Cloud-IoT Security, Attribute Revocation, DBDH, Monotone Span Programs, Big Data; EHR, HIPAA, GDPR, Proxy Re-Encryption, ARM Cortex

Abstract

The integration of Internet of Things (IoT) devices into clinical environments has generated volumes of electronic health records (EHRs) that exceed the management capacity of conventional access control mechanisms when these records are offloaded to cloud platforms. Protecting health records with fine-grained, cryptographically enforced access control while supporting dynamic credential revocation at cloud scale has remained an open problem in practice. Existing Ciphertext-Policy Attribute-Based Encryption (CP-ABE) schemes incur revocation costs that scale with the ciphertext archive size, lack computational feasibility on constrained IoT microcontrollers, or fail to address deployments where the Cloud Service Provider (CSP) itself is an untrusted adversary. This paper proposes two new CP-ABE constructions that close all three gaps simultaneously. Single-Authority CP-ABE (SA-CP-ABE) targets private hospital clouds under a semi-trusted CSP model and introduces a lazy versioned-key revocation mechanism in which the Trusted Authority broadcasts a single 32-byte group element per revocation event, achieving O(1) cost independent of the ciphertext archive size N. Extended-Authority CP-ABE (EA-CP-ABE) extends the construction to the fully untrusted public cloud by adding Pedersen-commitment-based policy anonymisation that hides the access policy structure from the CSP, and a conditional proxy re-encryption protocol that allows the CSP to perform revocation-driven ciphertext updates without observing the attribute being revoked. Both schemes are formalized in ten equations covering system setup, key generation, encryption, Monotone Span Program (MSP) secret sharing, decryption, and the two-step O(1) attribute revocation protocol. Security proofs under the Decisional Bilinear Diffie-Hellman (DBDH) assumption in the random oracle model establish IND-CPA security (Theorem 1) and revocation security (Theorem 2); IND-CCA security follows from standard one-time signature composition. Experimental evaluation across eight tables on an Intel Xeon E5-2690 v4 server and seven embedded hardware platforms confirms that SA-CP-ABE reduces ciphertext size by 44% over Yang et al. and maintains a constant 8.2 ms revocation latency regardless of policy size or concurrent user load, versus 312–389 ms for Yang et al. EA-CP-ABE adds a fixed 17% size overhead while achieving complete policy hiding. Both schemes run on ARM Cortex-M0 microcontrollers at 18.8 ms per sensor sample in batched mode and comply with HIPAA and GDPR technical safeguard requirements.

Downloads

Download data is not yet available.

Downloads

Published

2026-08-30

How to Cite

Gurupriya K G, & Dr. A. S Aneeshkumar. (2026). Single- and Extended-Authority CP-ABE for E-Healthcare Security in Cloud-IoT. International Journal of Computer Information Systems and Industrial Management Applications, 18(21s), 752–772. https://doi.org/10.70917/ijcisim-2026-5342

Issue

Section

Original Articles