H–trace: a fine–grained access control and traceability framework for medical data sharing based on administrative hierarchies
TL;DR
H-Trace aligns cryptographic delegation with healthcare administrative structures through Hierarchical Ciphertext-Policy Attribute-Based Encryption (H-CP-ABE), and decouples policy enforcement from bulk data encryption using a Key Encapsulation Mechanism–Data Encapsulation Mechanism hybrid architecture.
Abstract
The rapid digitalization of healthcare is driving medical data sharing across hospitals, departments, regional centers, and health authorities. In such cross-domain settings, secure sharing requires fine-grained authorization, chain-confirmed revocation, auditable access, and accountability for content leakage after legitimate use. Existing access-control schemes often fail to capture real healthcare administrative hierarchies, impose heavy computation on lightweight clinical terminals, or stop at key-level accountability. To address these challenges, we propose H-Trace, a hierarchical access-control and traceability framework for medical data sharing. H-Trace aligns cryptographic delegation with healthcare administrative structures through Hierarchical Ciphertext-Policy Attribute-Based Encryption (H-CP-ABE), and decouples policy enforcement from bulk data encryption using a Key Encapsulation Mechanism–Data Encapsulation Mechanism hybrid architecture. Gateway-assisted transformation shifts pairing-intensive computation away from resource-constrained terminals, while a permissioned consortium blockchain maintains revocation states, audit records, session metadata, and watermark anchors. For ex-post leakage investigation, H-Trace embeds session-bound invisible watermarks into released medical images, binding the released content to user identity, access session, and on-chain evidence. Security analysis shows that H-Trace achieves selective IND-CPA security and resists collusion attacks and out-of-scope delegation. Prototype evaluations demonstrate sub-millisecond post-transformation secret-recovery overhead in the tested setting, efficient protection of large medical files, and recoverable watermark tracing under typical distortions while maintaining diagnostic readability.