پدافند الکترونیکی و سایبری

پدافند الکترونیکی و سایبری

طرح تطبیق وظایف با حفظ حریم خصوصی کاربران بر اساس جست‌وجوی شباهت جهت مشاوره پزشکی

نوع مقاله : مقاله پژوهشی

نویسندگان
1 دانشجوی دکتری، دانشگاه شهید بهشتی، تهران، ایران
2 استادیار، پژوهشگاه علوم و فناوری اطلاعات ایران (ایرانداک)، تهران، ایران
3 دانشیار، دانشگاه شهید بهشتی، تهران، ایران
چکیده
با گسترش روزافزون خدمات درمانی غیرحضوری، مدیریت و دسترسی به اطلاعات پزشکان و بیماران از طریق پرونده‌های الکترونیکی سلامت فراهم شده است. یکی از مهم‌ترین مزایای این سیستم‌ها، امکان تطابق بین بیماران و پزشکان بر اساس نیازهای خاص بیماران است که علاوه بر کاهش زمان انتظار، به بهبود کیفیت خدمات درمانی نیز کمک می‌کند. بااین‌حال، چالش‌های مرتبط با حفظ حریم خصوصی بیماران و پزشکان در فرایند ذخیره‌سازی و انتقال داده پزشکی روی سرورها، متأثر از این نگرانی است که اطلاعات حساس بیماران درز پیدا کرده و یا اطلاعات پزشکان دستخوش حملات مهاجمان قرار گیرد؛ بنابراین ایجاد سیستم تطابق کارآمدی که امنیت داده‌ها را تضمین کند، به یک نیاز اساسی تبدیل شده است. به‌منظور مقابله با این چالش‌ها، استفاده از ابزارهای رمزنگاری باهدف محافظت از داده‌ها قبل از بارگذاری آن‌ها روی سرورهای ابری یا سایر سیستم‌های ذخیره‌سازی، به‌عنوان راهکار مؤثری پیشنهاد شده است. باوجوداین، روش‌های سنتی رمزنگاری به دلیل عدم امکان جستوجو و انجام عملیات روی داده‌های رمزگذاری شده، محدودیت‌هایی در ارائه خدمات بهینه ایجاد می‌کنند؛ بنابراین، در این مقاله، مکانیزم نوینی برای ایجاد تطابق امن و کارآمد بین بیماران و پزشکان ارائهشده است که با درنظرگرفتن نیازهای بیمار، امکان جستوجوی چند کلیدواژه روی داده‌های رمزگذاری شده را فراهم می‌کند. در طرح پیشنهادی از روشی نوین بر پایه محاسبه ضرب داخلی برای تطابق و اندازه‌گیری شباهت بین دو بردار استفاده شده است که علاوه بر بهبود کارایی، دقت نتایج حاصلشده را نیز افزایش می‌دهد. تجزیه‌وتحلیل‌های امنیتی انجام‌شده نشان می‌دهند که طرح ارائه‌شده از حریم خصوصی داده‌های پزشکان و بیماران به طور مؤثری محافظت می‌کند و هیچ اطلاعاتی را فاش نمی‌سازد. در مقایسه با مدل‌های پیشین با پیچیدگی زمانی O(nmk)، مدل پیشنهادی با کاهش چشمگیر پیچیدگی به O(n)، دقت تطبیق بالاتر و سرعت جست‌وجوی بهینه‌تری را ارائه می‌دهد. همچنین، با پشتیبانی از بردارهای وزن‌دار، چند کلیدواژه و بهره‌گیری از ASPE، سطح امنیتی بالاتری در برابر حملات KPA و CPA فراهم می‌سازد.
کلیدواژه‌ها
موضوعات

عنوان مقاله English

Privacy-Preserving Task Matching Scheme Based on Similarity Search for Medical Consultation

نویسندگان English

Faezeh Nayyeri 1
Nasrollah Pakniat 2
Ziba Eslami 3
1 PhD Student, Shahid Beheshti University, Tehran, Iran
2 Assistant Professor, Iranian Research Institute for Information Science and Technology of Iran (IranDoc), Tehran, Iran
3 Associate Professor, Shahid Beheshti University, Tehran, Iran
چکیده English

With the growing expansion of remote healthcare services, the management and access to patient and physician information through electronic health records (EHRs) have become increasingly feasible. One of the most significant advantages of such systems is the ability to match patients with physicians based on patients’ specific needs, which not only reduces waiting times but also improves the overall quality of medical services. However, privacy concerns related to the storage and transmission of sensitive medical data on servers pose serious challenges, including the risk of patient data leakage or exposure of physician information to malicious attacks. Consequently, the development of a secure and efficient matching system that ensures data confidentiality has become a critical necessity. To address these challenges, the use of cryptographic tools for protecting data prior to uploading it to cloud servers or other storage platforms has been proposed as an effective solution. Nevertheless, conventional encryption methods impose limitations on service optimization due to their inability to support search and operations over encrypted data. Therefore, this paper proposes a novel mechanism for secure and efficient patient-physician matching, enabling multi-keyword search over encrypted data in accordance with patient-specific requirements. The proposed scheme employs an innovative technique based on inner product computation to facilitate similarity measurement and matching between two vectors, which not only enhances efficiency but also improves the accuracy of the results. Security analysis confirms that the proposed scheme effectively preserves the privacy of both patient and physician data without disclosing any sensitive information. Compared to prior models with a time complexity of 𝑂 (nmk), the proposed scheme significantly reduces the computational complexity to 0 (n) while achieving higher matching accuracy and more efficient search speed. Furthermore, by supporting weighted vectors, multi-keyword queries, and employing ASPE, it offers enhanced security against KPA and CPA attacks.

کلیدواژه‌ها English

Searchable Encryption Task Matching Privacy
Preserving Similarity Search

Smiley face

 

[2]           R. Niemelä, M. Pikkarainen, M. Ervasti, and J. Reponen, "The change of pediatric surgery practice due to the emergence of connected health technologies," Technological Forecasting & Social Change, vol. 146, pp. 352-365, 2019. https://doi.org/ 10.1016/j.techfore.2019.06.001.
[3]           H. Xia, and B. McKernan, "Privacy in Crowdsourcing: a Review of the Threats and Challenges," Computer Supported Cooperative Work (CSCW), vol. 29, pp. 263-301, 2020. https://doi.org/ 10.1007/s10606-020-09374-0.
[4]           X. Fu, L. T. Yang, J. Li, X. Yang, and Z. Yang, "A Searchable Symmetric Encryption-Based Privacy Protection Scheme for Cloud-Assisted Mobile Crowdsourcing," Internet of Things, vol. 11, no. 2, pp. 1910-1924, 2024. https://doi.org/ 10.1109/JIOT.2023.3320666.
[5]           B. Guo, Y. Liu, L. Wang, V.O.K. Li, J.C.K. Lam, and Z. Yu, "Task Allocation in Spatial Crowdsourcing: Current State and Future Directions," IEEE Internet of Things Journal, vol. 5, no. 3, pp. 1749-1764, 2018. https://doi.org/ 10.1109/JIOT.2018.2815982.
[6]           J. Shu, and X. Jia, "Secure Task Recommendation in Crowdsourcing," IEEE Global Communications Conference (GLOBECOM), pp. 1-6, 2016. https://doi.org/ 10.1109/GLOCOM.2016.7842254.
[7]           S.K. Eizadi, M. Rafiei Korkvandi, and A. Khosh Sefat, "A novel architecture for database outsourcing in cloud computing with regard to data life cycle," Electronic and Cyber Defense, vol. 2, no. 4, pp. 41-54,  2015. DOR: 20.1001.1.23224347.1393.2.4.19.3 (in Persian).
[8]           S. R. B. Gummidi, "A Survey of Spatial Crowdsourcing," ACM Transactions on Database Systems, vol. 44, no. 2, pp. 1-46, 2019. https://doi.org/ 10.1145/3291933.
[9]           S. Dishman, and V.G. Duffy, "The Reaches of Crowdsourcing: A Systematic Literature Review," International Conference on Human-Computer Interaction, pp. 229-248, 2021. https://doi.org/ 10.1007/978-3-030-90238-4_17.
[10]         R. Lian, Y. Zheng, and C. Wang "PrivRo: A Privacy-Preserving Crowdsourcing Service with Robust Quality Awareness," Transactions on Services Computing, vol. 17, no. 4, pp. 1682-1697, 2024. https://doi.org/ 10.1109/TSC.2024.3377158.
[11]         J. Shu, X. Liu, Y. Zhang, X. Jia, and R. H. Deng, "Dual-side privacy-preserving task matching for spatial crowdsourcing," Journal of Network and Computer Applications, vol. 123, pp. 101-111, 2018. https://doi.org/ 10.1016/j.jnca.2018.09.007.
[12]         J. Shu, X. Jia, K. Yang, and H. Wang, "Privacy-Preserving Task Recommendation Services for Crowdsourcing," Transactions on Services Computing, vol. 14, no. 1, pp. 235-247, 2018. https://doi.org/ 10.1109/TSC.2018.2791601.
[13]         T. Peng, W. Zhong, G. Wang, S. Zhang, E. Luo, and T. Wang, "Spatiotemporal-aware Privacy-preserving Task Matching in Mobile Crowdsensing," Internet of Things Journal, vol. 11, no. 2, pp. 2394-2406, 2023. https://doi.org/ 10.1109/JIOT.2023.3292284.
[14]         Y. Gong, Y. Guo, and Y. Fang, "A privacy-preserving task recommendation framework for mobile crowdsourcing," IEEE Global Communications Conference, pp. 588-593, 2014. https://doi.org/ 10.1109/GLOCOM.2014.7036871.
[15]         R. Zhang, R. Xue, and L. Liu, "Searchable Encryption for Healthcare Clouds: A Survey," Transactions on Services Computing, vol. 11, no. 6, pp. 978-96, 2017. https://doi.org/10.1109/TSC.2017.2762296.
[16]         Y. Watanabe, T. Nakai, K. Ohara, T. Nojima, Y. Liu, M. Iwamoto, and K. Ohta, "How to Make a Secure Index for Searchable Symmetric Encryption, Revisited," IEICE Transactions on Fundamentals of Electronics, vol. 105, no. 12, pp. 1559-1577, 2022. https://doi.org/ 10.1587/transfun.2021EAP1163.
[17]         Q. Liu, Y. Guo, J. Wu, and G. Wang, "Effective Query Grouping Strategy in Clouds," Computer Science and Technology, vol. 32, no. 6, pp. 1231-1249, 2017. https://doi.org/ 10.1007/s11390-017-1797-9.
[18]         J. Shu, X. Liu, X. Jia, and K. Yan, "Anonymous Privacy-Preserving Task Matching in Crowdsourcing," Internet of Things Journal, vol. 5, no. 4, pp. 3068-3078, 2018. https://doi.org/ 10.1109/JIOT.2018.2830784.
[19]         R. A. Popa, and N. Zeldovich, "Multi-Key Searchable Encryption," IACR Cryptology ePrint Archive, 2013.
[20]         H. Bao, Z. Wang, R. Lu, C. Huang, and B. Li, "TAMT: Privacy-Preserving Task Assignment with Multi-Threshold Range Search for Spatial Crowdsourcing Applications," IEEE Transactions on Big Data, pp. 1-13, 2024. https://doi.org/ 10.1109/TBDATA.2024.3403374.
[21]         A. Kiayias, O. Oksuz, A. Russell, Q. Tang, and B. Wang, "Efficient Encrypted Keyword Search for Multi-user Data Sharing," European symposium on research in computer security, pp. 173-195, 2016. https://doi.org/ 10.1007/978-3-319-45744-4_9.
[22]         F. Zhao, T. Nishide, and K. Sakurai, "Multi-User Keyword Search Scheme for Secure Data Sharing with Fine-Grained Access Control," International Conference on Information Security and Cryptology-ICISC 2011: 14th International Conference, Seoul, Korea, pp. 406-418, 2012. https://doi.org/ 10.1007/978-3-642-31912-9_27.
[23]         K. Liang, C. Su, J. Chen, and J. K. Liu, "Efficient Multi-Function Data Sharing and Searching Mechanism for Cloud-Based Encrypted Data," 11th ACM on Asia Conference on Computer and Communications Security, pp. 83-94, 2016.  https://doi.org/ 10.1145/2897845.289786.
[24]         H. Li, D. Liu, Y. Dai, T. H. Luan, and X. S. Shen, "Enabling Efficient Multi-Keyword Ranked Search Over Encrypted Mobile Cloud Data Through Blind Storage," Emerging Topics in Computing, vol. 3, no. 1, pp. 127-138, 2014. https://doi.org/ 10.1109/TETC.2014.2371239.
[25]         Y. Miao, W. Zheng, X. Jia, X. Liu, K. K. R. Choo, and R. H. Deng, "Ranked Keyword Search over Encrypted Cloud Data Through Machine Learning Method," IEEE Transactions on Services Computing, vol. 16, no. 1, pp. 525-536, 2021. https://doi.org/ 10.1109/TSC.2021.3140098.
[26]         N. Cao, C. Wang, M. Li, and K. Ren, "Privacy-preserving multi-keyword ranked search over encrypted cloud data," Transactions on parallel and distributed systems, vol. 25, no. 1, pp. 222-233, 2014. https://doi.org/ 10.1109/TPDS.2013.45.
[27]         W. K. Wong, D. W. Cheung, B. Kao, and N. Mamoulis, "Secure kNN Computation on Encrypted Databases," International Conference on Management of data, pp. 139-152, 2009. https://doi.org/ 10.1145/1559845.155986.
[28]         M. Zhang, Y. Chen, and J. Huang, "SE-PPFM: A Searchable Encryption Scheme Supporting Privacy-Preserving Fuzzy Multikeyword in Cloud Systems," Systems Journal, vol. 15, no. 2, pp. 2980-2988, 2020. https://doi.org/ 10.1109/JSYST.2020.2997932.
[29]         F. Song, Z. Qin, D. Liu, J. Zhang, X. Lin, and X. Shen, "Privacy-Preserving Task Matching with Threshold Similarity Search via Vehicular Crowdsourcing," Transactions on Vehicular Technology, vol. 70, no. 7, pp. 7161-7175, 2021. https://doi.org/ 10.1109/TVT.2021.3088869.
[30]         G. Soltan, A. Wong, and C. S. Yang, "A Vector Space Model for Automatic Indexing," Information Retrieval and Language Processing, vol. 18, no. 11, pp. 613-620, 1975. https://doi.org/ 10.1145/361219.361220.

  • تاریخ دریافت 23 دی 1404
  • تاریخ بازنگری 04 اسفند 1404
  • تاریخ پذیرش 16 فروردین 1405
  • تاریخ انتشار 02 اردیبهشت 1405