Skip to content
Open access

H–trace: a fine–grained access control and traceability framework for medical data sharing based on administrative hierarchies

Aug 2026 · Journal of King Saud University: Computer and Information Sciences · Vol 38 · 0 citations · 28 references

TL;DR

H-Trace aligns cryptographic delegation with healthcare administrative structures through Hierarchical Ciphertext-Policy Attribute-Based Encryption (H-CP-ABE), and decouples policy enforcement from bulk data encryption using a Key Encapsulation Mechanism–Data Encapsulation Mechanism hybrid architecture.

Abstract

The rapid digitalization of healthcare is driving medical data sharing across hospitals, departments, regional centers, and health authorities. In such cross-domain settings, secure sharing requires fine-grained authorization, chain-confirmed revocation, auditable access, and accountability for content leakage after legitimate use. Existing access-control schemes often fail to capture real healthcare administrative hierarchies, impose heavy computation on lightweight clinical terminals, or stop at key-level accountability. To address these challenges, we propose H-Trace, a hierarchical access-control and traceability framework for medical data sharing. H-Trace aligns cryptographic delegation with healthcare administrative structures through Hierarchical Ciphertext-Policy Attribute-Based Encryption (H-CP-ABE), and decouples policy enforcement from bulk data encryption using a Key Encapsulation Mechanism–Data Encapsulation Mechanism hybrid architecture. Gateway-assisted transformation shifts pairing-intensive computation away from resource-constrained terminals, while a permissioned consortium blockchain maintains revocation states, audit records, session metadata, and watermark anchors. For ex-post leakage investigation, H-Trace embeds session-bound invisible watermarks into released medical images, binding the released content to user identity, access session, and on-chain evidence. Security analysis shows that H-Trace achieves selective IND-CPA security and resists collusion attacks and out-of-scope delegation. Prototype evaluations demonstrate sub-millisecond post-transformation secret-recovery overhead in the tested setting, efficient protection of large medical files, and recoverable watermark tracing under typical distortions while maintaining diagnostic readability.

Read PDF

Similar papers

Open access Aug 2026

Patient-Centric Secure Medical Record Sharing on Ethereum: A Proof-of-Concept Study of Smart Contract-Based Access Control

Fragmented electronic medical records (EMRs) across healthcare institutions hinder coordinated care and increase cybersecurity risks for sensitive patient data. While blockchain has been proposed for medical data governance, existing architectures remain often overly complex and lack minimal, verifiable implementations...

Jian-Hao Yuan · 0 citations
Open access Aug 2026

Verifiable and Accountable Multi-Authority CP-ABE with Consent Binding and Revocation for Cloud EHR

In regulated cross-institution electronic health record (EHR) sharing, access control may need to respect patient consent while also providing issuance accountability and revocation correctness. Existing multi-authority ciphertext-policy attribute-based encryption (MA-CP-ABE) schemes provide decentralized attribute man...

Noshaba Naeem, Mohsen Toorani · 0 citations
Open access Aug 2026

Single- and Extended-Authority CP-ABE for E-Healthcare Security in Cloud-IoT

The integration of Internet of Things (IoT) devices into clinical environments has generated volumes of electronic health records (EHRs) that exceed the management capacity of conventional access control mechanisms when these records are offloaded to cloud platforms. Protecting health records with fine-grained, cryptog...

K. G. Gurupriya, A. S. Aneeshkumar · 0 citations
Aug 2026

Lightweight and Scalable Blockchain-Based Integrity Verification for EHR Systems

The modern use of Electronic Health Records (EHRs) has made healthcare useful but it’s growing demand also raised more concerns about data integrity, unauthorised changes, and the ability to audit centralised storage systems. The existing blockchain-based healthcare solutions largely emphasis on sharing data and contro...

Richa Pandey · 0 citations
Open access 2026

A Blockchain-Based Role-Based Access Control Gateway for Secure Electronic Health Record Access and Tamper-Evident Auditing

Electronic Health Record (EHR) systems store sensitive patient information and require strong access control and reliable audit records. Traditional centralized Role-Based Access Control (RBAC) systems may be vulnerable to unauthorized access, privilege escalation, audit-log modification, and undetected changes to stor...

O. Saleh, Shouki A. Ebad · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.