Papers1 provider · 1 record
December 31, 2025· IEEE Transactions on Dependable and Secure Computing
article

Secure Distributed Threshold Decryption Scheme for Electronic Personal Health Records Sharing System

Authors:Isaac Amankona ObiriQi XiaJianbin GaoHu XiaYang Liu

Abstract

The growing adoption of electronic personal health records (ePHRs) demands cryptographic solutions that ensure secure and efficient data access. Threshold cryptography provides a framework for controlled multi-party access, yet existing schemes face practical limitations. Many require trusted key dealers, creating single points of failure and key escrow vulnerabilities, while others rely on pairing-based constructions that scale poorly. Furthermore, batch-oriented processing in previous schemes fails to support individual on-demand access patterns typical in healthcare applications. We propose a Distributed Identity-Based Threshold Decryption (DIBTD) scheme that addresses these limitations. First, our protocol removes all trusted setup assumptions through a fully distributed key generation mechanism based on verifiable secret sharing. Second, it achieves constant-time encryption and decryption operations, independent of committee size, by using efficient elliptic curve operations on secp256k1 rather than computationally heavy pairings, yielding up to 56× faster encryption than prior work. Third, DIBTD integrates the detection of malicious actors via zero-knowledge proofs, allowing the dynamic exclusion of compromised participants during system initialization. We provide formal security proofs showing the security of IND-CCA2 in the random oracle model under the discrete logarithm of the elliptic curve (ECDLP) and computational Diffie-Hellman (CDH) assumptions. The scheme remains secure against adaptive adversaries that control up to$t-1$participants. Experimental evaluation demonstrates practical efficiency: ciphertexts of only 86 bytes, constant 33-byte public keys, and sub-millisecond encryption latency. A pure Rust implementation on commodity hardware achieves 0.065ms per patient record while maintaining 128-bit security.

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.