Secure Yet Practical PHR Sharing: A Hybrid Approach of NFT and Attribute-Based Encryption
Abstract
Personal Health Records (PHRs) enable personalized and continuous healthcare services, but contain highly sensitive information, requiring strong security and privacy safeguards. Self-sovereign architectures, where individuals retain full control over their data, represent a promising model for secure PHR sharing. In our prior work, we implemented a blockchain-based system using Non-Fungible Tokens (NFTs) to represent data ownership and usage rights. While NFTs provide tamper resistance, NFT-only access control is vulnerable to wallet compromise and requires explicit user consent, making it unsuitable for emergency access when patients are unconscious or otherwise unable to consent. To address these limitations, we newly propose a hybrid PHR-sharing framework combining NFTs with Attribute-Based Encryption (ABE). Our new approach enforces cryptographic access policies beyond NFT possession and enables emergency access to predefined medical information without explicit user consent. We analyze representative attack scenarios and show that the scheme provides secure access control and rights management. We implement a prototype and evaluate its performance. For 1 MB of data, used as a practical upper bound for text-based PHR records based on wearable-device measurements, retrieval takes approximately 1 second, while registration and access granting take approximately 12 and 6 seconds on the Base testnet, a high-speed Ethereum-compatible test network. These results demonstrate practical feasibility, with further optimization possible through faster blockchain networks or reduced blockchain transactions.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.