A puncturing-based KP-ABE scheme for immediate and scalable user revocation in cloud-assisted IoMT
Abstract In cloud-assisted Internet of Medical Things (IoMT), medical data are continuously uploaded by resource-constrained devices, while user privileges may change after ciphertexts have been stored. This makes timely revocation a practical requirement for secure data sharing. Existing KP-ABE revocation mechanisms usually depend on ciphertext re-encryption, key updates, or revocation-list checking, which can cause considerable computational and communication overhead and may delay revocation in large-scale settings. To reduce this bottleneck, a puncturable KP-ABE construction is introduced for cloud-assisted IoMT. Revocation is bound to tag-related ciphertext components, so a revocation event is handled by puncturing rather than by re-encrypting historical ciphertexts or updating the keys of non-revoked users. In the resulting workflow, the DO specifies access and restriction policies, the DSM executes puncturing, the DSC undertakes outsourced decryption, and the DU keeps the local secret required for final recovery. The workflow offloads costly operations to the cloud and verifies outsourced processing through key blinding, authenticated key registration, and signatures. The scheme is proven selectively IND-CPA secure under the Decisional Bilinear Diffie-Hellman assumption. Theoretical analysis and Charm-Crypto experiments show that the revocation cost does not increase with the number of revoked users and that outsourced punctured decryption saves 2 n r pairing operations compared with Pun-KP-ABE. The evaluation shows lower outsourced punctured-decryption cost and stable revocation cost in the tested IoMT setting.
Authors
- Ruonan Chen (ORCID: https://orcid.org/0000-0003-3417-5653)
- Qinglan Zhao (ORCID: https://orcid.org/0000-0002-4780-8598)
- Haoran Zhang (ORCID: https://orcid.org/0009-0000-1723-213X)
- Dong Zheng (ORCID: https://orcid.org/0000-0002-3860-2037)
- Meiling Zhang
Institutions
- Xi’an University of Posts and Telecommunications (CN)
Publication Details
- Journal
- Journal of King Saud University - Computer and Information Sciences
- Published
- 2026-09-25
- DOI
- https://doi.org/10.1007/s44443-026-01288-z
- Primary Topic
- Cryptography and Data Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00