A puncturing-based KP-ABE scheme for immediate and scalable user revocation in cloud-assisted IoMT

Abstract In cloud-assisted Internet of Medical Things (IoMT), medical data are continuously uploaded by resource-constrained devices, while user privileges may change after ciphertexts have been stored. This makes timely revocation a practical requirement for secure data sharing. Existing KP-ABE revocation mechanisms usually depend on ciphertext re-encryption, key updates, or revocation-list checking, which can cause considerable computational and communication overhead and may delay revocation in large-scale settings. To reduce this bottleneck, a puncturable KP-ABE construction is introduced for cloud-assisted IoMT. Revocation is bound to tag-related ciphertext components, so a revocation event is handled by puncturing rather than by re-encrypting historical ciphertexts or updating the keys of non-revoked users. In the resulting workflow, the DO specifies access and restriction policies, the DSM executes puncturing, the DSC undertakes outsourced decryption, and the DU keeps the local secret required for final recovery. The workflow offloads costly operations to the cloud and verifies outsourced processing through key blinding, authenticated key registration, and signatures. The scheme is proven selectively IND-CPA secure under the Decisional Bilinear Diffie-Hellman assumption. Theoretical analysis and Charm-Crypto experiments show that the revocation cost does not increase with the number of revoked users and that outsourced punctured decryption saves 2 n r pairing operations compared with Pun-KP-ABE. The evaluation shows lower outsourced punctured-decryption cost and stable revocation cost in the tested IoMT setting.

Authors

Institutions

Publication Details

Journal
Journal of King Saud University - Computer and Information Sciences
Published
2026-09-25
DOI
https://doi.org/10.1007/s44443-026-01288-z
Primary Topic
Cryptography and Data Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

A puncturing-based KP-ABE scheme for immediate and scalable user revocation in cloud-assisted IoMT

Ruonan Chen, Qinglan Zhao, Haoran Zhang, Dong Zheng et al.
Journal of King Saud University - Computer and Information Sciences
Cryptography and Data Security
article

A puncturing-based KP-ABE scheme for immediate and scalable user revocation in cloud-assisted IoMT

Ruonan Chen, Qinglan Zhao, Haoran Zhang, Dong Zheng, Meiling Zhang
article en

Abstract

Abstract In cloud-assisted Internet of Medical Things (IoMT), medical data are continuously uploaded by resource-constrained devices, while user privileges may change after ciphertexts have been stored. This makes timely revocation a practical requirement for secure data sharing. Existing KP-ABE revocation mechanisms usually depend on ciphertext re-encryption, key updates, or revocation-list checking, which can cause considerable computational and communication overhead and may delay revocation in large-scale settings. To reduce this bottleneck, a puncturable KP-ABE construction is introduced for cloud-assisted IoMT. Revocation is bound to tag-related ciphertext components, so a revocation event is handled by puncturing rather than by re-encrypting historical ciphertexts or updating the keys of non-revoked users. In the resulting workflow, the DO specifies access and restriction policies, the DSM executes puncturing, the DSC undertakes outsourced decryption, and the DU keeps the local secret required for final recovery. The workflow offloads costly operations to the cloud and verifies outsourced processing through key blinding, authenticated key registration, and signatures. The scheme is proven selectively IND-CPA secure under the Decisional Bilinear Diffie-Hellman assumption. Theoretical analysis and Charm-Crypto experiments show that the revocation cost does not increase with the number of revoked users and that outsourced punctured decryption saves 2 n r pairing operations compared with Pun-KP-ABE. The evaluation shows lower outsourced punctured-decryption cost and stable revocation cost in the tested IoMT setting.

Journal of King Saud University - Computer and Information SciencesVol. 38(8)
Xi’an University of Posts and Telecommunications (CN)
Openalex Percentile: Top 9%
Cryptography and Data Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

A puncturing-based KP-ABE scheme for immediate and scalable user revocation in cloud-assisted IoMT — Ruonan Chen, Qinglan Zhao, et al. · Journal of King Saud University - Computer and Information Sciences (2026) | TGRS Research Map | TGRS