Hybrid and Secure E-Health Data Sharing Architecture
255
4 Analysis of the Proposed Retrieval Process
File retrieval, also known as file reconstruction, is the reversal process of file
distribution and file slicing. In this framework the retrieval process starts when
a data requester DR needs to get an EHR. He must log in and submit the EHR
identifier (ID R ). HSDSA checks if the DR has the right to get the requested
EHR. If the authorisation succeeded, then the reconstruction phase starts.
4.1 The Reconstruction Phase
Since the reconstruction of R
requires a massive amount of computation and
that client resources are limited, we will use the reconstruction outsourcing
scheme proposed in [5]. The framework assigns a CSP (CSP R ) to reconstruct
shares S
j . The reconstruction is considered successfull only if CSP R gets at least
t shares from CSP 1 , ..., CSP n . We assume that CSP R gets k shares.
⎡
⎣
S 11 , ...S m1
...
S 1k , ..., S mk
⎤
⎦ , (k ≥ t)
CSP R computes S
j for j = (1, ..., m) using Lagrange interpolation polynomial
and sends them to HSDSA:
S
j =
k
i=1
S ji
k
l=1,l =i
x i
x i − x l
mod p (j = 1, ..., m)
(3)
To make sure that CSP R could not reveal any useful information, knowing that
he is a curious and dishonest party, doing an exclusive OR operation helps to
blind the content. Upon receipt of the shares, the HSDSA framework performs
the exclusive OR operation between S
j and H(R
) to get S j .
4.2 The Recovery Phase
This phase aims to securely transfer the Data Owner’s private key to the right
Data Requester. Table 2 illustrates the main steps related to this phase.
Once the reconstruction phase is done, HSDSA sends ID DO /ID DR to the
Data Owner and to the Data Receiver. First the DR has to prove to the DO
that he holds the right hash value of the original file (H(R))
and that he is
the correct DR. For this purpose, a Schnorr’s identification protocol [7] is used
not only to prove the hash possession but also to verify the DR identity. In the
process of the latter algorithm the DO checks if H(R)
?
= (H(R))
), and verifies
if the n first bits of the DR identity match the ID DR previously sent by FI.
Then the DO and the DR must establish a secure connection for key exchange,
based on Diffie-Hellman (DH) scheme Ephemeral version [8], reinforced with the
hash value of the original file (H(R)). Establishing a session means that the two
partners have agreed on session key (K s ) that will be used to crypt partners
Précédent

- 262/446

Suivant