Addressing the challenges of privacy leakage, fragmented data silos, and high computational overhead in traditional ciphertext-policy attribute-based encryption (CP-ABE) for medical data sharing, this paper proposes an improved CP-ABE framework with outsourced decryption, integrated with consortium blockchain and the InterPlanetary File System (IPFS). The framework introduces a medical-scenario-adapted CP-ABE architecture based on a lightweight FAME design, optimizing attribute key generation and transformation key design to accommodate resource-constrained medical terminals. A hybrid encryption system is employed, combining symmetric encryption for high-efficiency processing of large medical data and CP-ABE for fine-grained access control of symmetric keys. To reduce user computational burden, a proxy-assisted secure decryption architecture is implemented, where the proxy server handles most decryption tasks while ensuring resistance to malicious proxy behavior. Furthermore, the framework provides rigorous formal security verification, achieving IND-CPA security and resilience against collusion and malicious proxy attacks. Comprehensive performance evaluations demonstrate significant improvements in key generation, encryption, and decryption efficiency, offering a better balance between security and efficiency for practical medical data sharing applications.
Li et al. (Fri,) studied this question.