252
T. Ismail et al.
– The storage phase starts when a DO wants to store his EHRs, he calculates the digital signature of his EHR (R), encrypts R using Rivest–Shamir–
Adleman (RSA) algorithm for both and logs in to the HSDSA. Then, the DO
uploads his encrypted record (R
) and the hash value of the original record
H(R). HSDSA generates a unique identifier (ID R ) of the EHR to guarantee
the anonymity of stored data in Cloud servers and stores H(ID DO ), H(R) and
ID R . The framework calculates the hash of the uploaded EHR (R
) and splits
it into m shares. Then, it performs an exclusive OR operation between each
share (S
i ) and the hash value of R
. The distribution is done using Shamir’s
secret sharing algorithm and the resulted shares are sent to n different Cloud
Server Providers CSP 1 , ... CSP n .
– The reconstruction phase starts when a DO or an authorised user DR
wants to get the EHR, he sends a request to the framework. After confirming
the request, HSDSA assigns a CSP (CSP R ) to perform the reconstruction
step. The CSP R gets t shares or more from CSP 1 , ... CSP n . Once the reconstruction is done, the CSP R returns the resulted shares to the framework.
– Finally, the recovery phase, when the DR wants to get the DO’s private
key, he has to prove that he is the right DR and he has the correct hash value
of R. To this end, the Schnorr algorithm is used. Once, the DO makes sure
that the DR is an authorised requester and that he possesses the encrypted
version of the EHR (R
), then the DR and the DO try to establish a session
using Diffie-Hellman (DH) algorithm to exchange decryption key securely.
Once they agree on a session key, K s . The DO encrypts his private key using
K s and sends it to the DR. Once the private key is extracted, the DR can
finally recover the desired EHR (R).
3 Analysis of the Proposed Storage Process
In the following, we detail the techniques used in the two phases of the storage
process: the registration phase and the storage phase.
3.1 The Registration Phase
As recommended in cloud-based storage solutions, building a trust relationship
between partners is a necessity. To achieve this goal, the first step is to make
sure that all users are registered to the framework. If a new user wants to benefit
from services provided by the HSDSA framework, he must be correctly authenticated. Once he registers, he receives a value containing the hash of his identity
H(ID DO,DR ) in order to maintain the anonymity of user identities.
3.2 The Storage Phase
HSDSA acts as an intermediary between DO and CSPs. Our goal is to provide a secure storage facility to authorised users. This phase involves Shamir’s
secret sharing technique to make sure that the multi-cloud environment, used to
T. Ismail et al.
– The storage phase starts when a DO wants to store his EHRs, he calculates the digital signature of his EHR (R), encrypts R using Rivest–Shamir–
Adleman (RSA) algorithm for both and logs in to the HSDSA. Then, the DO
uploads his encrypted record (R
) and the hash value of the original record
H(R). HSDSA generates a unique identifier (ID R ) of the EHR to guarantee
the anonymity of stored data in Cloud servers and stores H(ID DO ), H(R) and
ID R . The framework calculates the hash of the uploaded EHR (R
) and splits
it into m shares. Then, it performs an exclusive OR operation between each
share (S
i ) and the hash value of R
. The distribution is done using Shamir’s
secret sharing algorithm and the resulted shares are sent to n different Cloud
Server Providers CSP 1 , ... CSP n .
– The reconstruction phase starts when a DO or an authorised user DR
wants to get the EHR, he sends a request to the framework. After confirming
the request, HSDSA assigns a CSP (CSP R ) to perform the reconstruction
step. The CSP R gets t shares or more from CSP 1 , ... CSP n . Once the reconstruction is done, the CSP R returns the resulted shares to the framework.
– Finally, the recovery phase, when the DR wants to get the DO’s private
key, he has to prove that he is the right DR and he has the correct hash value
of R. To this end, the Schnorr algorithm is used. Once, the DO makes sure
that the DR is an authorised requester and that he possesses the encrypted
version of the EHR (R
), then the DR and the DO try to establish a session
using Diffie-Hellman (DH) algorithm to exchange decryption key securely.
Once they agree on a session key, K s . The DO encrypts his private key using
K s and sends it to the DR. Once the private key is extracted, the DR can
finally recover the desired EHR (R).
3 Analysis of the Proposed Storage Process
In the following, we detail the techniques used in the two phases of the storage
process: the registration phase and the storage phase.
3.1 The Registration Phase
As recommended in cloud-based storage solutions, building a trust relationship
between partners is a necessity. To achieve this goal, the first step is to make
sure that all users are registered to the framework. If a new user wants to benefit
from services provided by the HSDSA framework, he must be correctly authenticated. Once he registers, he receives a value containing the hash of his identity
H(ID DO,DR ) in order to maintain the anonymity of user identities.
3.2 The Storage Phase
HSDSA acts as an intermediary between DO and CSPs. Our goal is to provide a secure storage facility to authorised users. This phase involves Shamir’s
secret sharing technique to make sure that the multi-cloud environment, used to
