Identity-Private Healthcare Data Sharing on Blockchain via Zero-Knowledge Proofs and Account Abstraction
Abstract
Blockchains are considered for healthcare data sharing due to their immutability, decentralization, and auditability. However, ledger transparency exposes on-chain identifiers and activity metadata, enabling linkage across pseudonyms and inference over user behavior. Prior work has primarily focused on content confidentiality and access control, while leaving identity unlinkability insufficiently addressed. To this end, we present an approach that integrates Account ion (AA), zeroknowledge proofs (Groth16), and Pedersen commitments. The approach embeds proof- and commitment-based verification into programmable smart contract accounts (SCAs), enabling authentication without disclosing identifiers and decoupling transactions from static keys. We develop a proof-of-concept on the Polygon Amoy testnet using Circom and Solidity, and evaluate privacy under a global, passive, external, static, and computationally bounded attacker. For the ERC-4337 comparison, the attacker is assumed to know user-SCA mappings; for the account-shuffling comparison, the attacker knows one SCA per user. Using entropy metrics and clustering-based inference over on-chain metadata, our approach achieves the maximum entropy of $\log _{2}(10) \approx 3.32$ in a ten-user setting (versus 0 for ERC-4337 as specified, i.e., without privacy extensions) and substantially reduces clustering accuracy relative to address shuffling (ARI $0.468 \rightarrow 0.038$, NMI $0.653 \rightarrow 0.177$), while maintaining the auditability required for healthcare governance.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.