• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

计算机工程与科学 ›› 2024, Vol. 46 ›› Issue (08): 1403-1413.

• 计算机网络与信息安全 • 上一篇    下一篇

智慧医疗系统中可容错的多维度密文跨域聚合方案

张晓均,李兴鹏,张经伟,唐伟   

  1. (西南石油大学计算机与软件学院网络空间安全研究中心,四川 成都 610500)
  • 收稿日期:2023-03-29 修回日期:2023-12-12 接受日期:2024-08-25 出版日期:2024-08-25 发布日期:2024-09-02
  • 基金资助:
    国家自然科学基金(61902327);中国博士后科学基金(2020M681316);成都市科技局项目(2021-YF05-00965-SN)

A multi-dimensional ciphertexts cross domain aggregation scheme supporting fault tolerance in intelligent medical systems

ZHANG Xiao-jun,LI Xing-peng,ZHANG Jing-wei,TANG Wei   

  1. (Research Center for Cyber Security,School of Computer Science and Software Engineering,
    Southwest Petroleum University,Chengdu 610500,China)
  • Received:2023-03-29 Revised:2023-12-12 Accepted:2024-08-25 Online:2024-08-25 Published:2024-09-02

摘要: 为解决智慧医疗系统中数据孤岛问题,实现医疗数据安全汇聚的目标,同时确保医疗数据传输与存储过程的机密性、完整性与可用性,提出了支持传输容错的可验证多维医疗密文跨域聚合方案。该方案将边缘服务器集成到传统的云计算架构,通过设计同态加密算法,并结合Shamir秘密共享技术,实现多维度加密数据可传输容错的2层聚合。该方案设计了基于椭圆曲线的数字签名算法,确保医疗加密数据在传输与存储过程中的完整性。医疗数据分析中心可以向云服务器灵活选取目标区域进行跨域聚合,并借助云审计机制对获取到的聚合结果进行轻量级完整性验证。根据霍纳法则,医疗数据分析中心利用解密私钥可以直接获得相应区域终端用户各个维度医疗数据的聚合结果。通过安全性分析与性能比较表明,该方案能够安全高效地部署在智慧医疗系统。

关键词: 医疗密文, 边缘计算, 跨域聚合, 传输容错, 完整性验证

Abstract: To address the problem of data islands in Intelligent medical systems, achieve the goal of medical data security convergence, and simultaneously ensure the confidentiality, integrity and availability of medical data in transmission and storage process, this paper proposes a verifiable multi-dimensional medical ciphertexts cross domain aggregation scheme supporting transmission fault tolerance. The scheme integrates edge computing servers into the traditional cloud computing framework. By designing a homomorphic encryption algorithm and combining the Shamir secret sharing technology, this scheme realizes two-layer aggregation of multi-dimensional encrypted data with transmission fault tolerance. The scheme designs a digital signature algorithm based on elliptic curve, to ensure the integrity of medical encrypted data in the process of transmission and storage. In particular, the medical data analysis center can flexibly select target areas from the cloud server for cross domain aggregation, and exploit cloud storage audit mechanism to fulfil the lightweight integrity verification of the aggregation results. According to Horner's rule and the private key, the medical data analysis center can obtain the aggregation results of various dimensions of medical data from end users in the corresponding region. Security analysis and performance comparison demonstrate that this scheme can be securely and efficiently deployed in intelligent medical systems. 

Key words: medical ciphertexts, edge computing, cross domain aggregation, transmission fault tole- rance, integrity verification