<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMES</journal-id>
<journal-id journal-id-type="nlm-ta">CMES</journal-id>
<journal-id journal-id-type="publisher-id">CMES</journal-id>
<journal-title-group>
<journal-title>Computer Modeling in Engineering &#x0026; Sciences</journal-title>
</journal-title-group>
<issn pub-type="epub">1526-1506</issn>
<issn pub-type="ppub">1526-1492</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">26321</article-id>
<article-id pub-id-type="doi">10.32604/cmes.2023.026321</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>BC-PC-Share: Blockchain-Based Patient-Centric Data Sharing Scheme for PHRs in Cloud Computing</article-title>
<alt-title alt-title-type="left-running-head">BC-PC-Share: Blockchain-Based Patient-Centric Data Sharing Scheme for PHRs in Cloud Computing</alt-title>
<alt-title alt-title-type="right-running-head">BC-PC-Share: Blockchain-Based Patient-Centric Data Sharing Scheme for PHRs in Cloud Computing</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Lan</surname><given-names>Caihui</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Li</surname><given-names>Haifeng</given-names></name><xref ref-type="aff" rid="aff-2">2</xref><xref ref-type="aff" rid="aff-3">3</xref><email>lihaifengdlut@163.com</email></contrib>
<aff id="aff-1"><label>1</label><institution>School of Electronic and Information Engineering, Lanzhou City University</institution>, <addr-line>Lanzhou, 730070</addr-line>, <country>China</country></aff>
<aff id="aff-2"><label>2</label><institution>School of Software, Dalian University of Foreign Languages</institution>, <addr-line>Dalian, 116044</addr-line>, <country>China</country></aff>
<aff id="aff-3"><label>3</label><institution>School of Software, Dalian University of Technology</institution>, <addr-line>Dalian, 116024</addr-line>, <country>China</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Haifeng Li. Email: <email>lihaifengdlut@163.com</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic"><year>2023</year></pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>2</day><month>3</month><year>2023</year>
</pub-date>
<volume>136</volume>
<issue>3</issue>
<fpage>2985</fpage>
<lpage>3010</lpage>
<history>
<date date-type="received">
<day>30</day><month>8</month><year>2022</year>
</date>
<date date-type="accepted">
<day>21</day><month>11</month><year>2022</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2023 Lan and Li</copyright-statement>
<copyright-year>2023</copyright-year>
<copyright-holder>Lan and Li</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMES_26321.pdf"></self-uri>
<abstract>
<p>Sharing of personal health records (PHR) in cloud computing is an essential functionality in the healthcare system. However, how to securely, efficiently and flexibly share PHRs data of the patient in a multi-receiver setting has not been well addressed. For instance, since the trust domain of the cloud server is not identical to the data owner or data user, the semi-trust cloud service provider may intentionally destroy or tamper shared PHRs data of user or only transform partial ciphertext of the shared PHRs or even return wrong computation results to save its storage and computation resource, to pursue maximum economic interest or other malicious purposes. Thus, the PHRs data storing or sharing via the cloud server should be performed with consistency and integrity verification. Fortunately, the emergence of blockchain technology provides new ideas and prospects for ensuring the consistency and integrity of shared PHRs data. To this end, in this work, we leverage the consortium blockchain technology to enhance the trustworthiness of each participant and propose a blockchain-based patient-centric data sharing scheme for PHRs in cloud computing (BC-PC-Share). Different from the state-of-art schemes, our proposal can achieve the following desired properties: (1) Realizing patient-centric PHRs sharing with a public verification function, i.e., which can ensure that the returned shared data is consistent with the requested shared data and the integrity of the shared data is not compromised. (2) Supporting scalable and fine-grained access control and sharing of PHRs data with multiple domain users, such as hospitals, medical research institutes, and medical insurance companies. (3) Achieving efficient user decryption by leveraging the transformation key technique and efficient user revocation by introducing time-controlled access. The security analysis and simulation experiment demonstrate that the proposed BC-PC-Share scheme is a feasible and promising solution for PHRs data sharing via consortium blockchain.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Blockchain</kwd>
<kwd>patient-centric</kwd>
<kwd>personal health records</kwd>
<kwd>data sharing</kwd>
<kwd>attribute-based encryption</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label><title>Introduction</title>
<p>A Personal Health Record (PHR) refers to an electronic record collection administratered by the patients themselves. It commonly includes healthcare information and medical information obtained from a variety of sources, such as multiple healthcare providers (e.g., hospitals) and the patients themselves (e.g., wearable devices) [<xref ref-type="bibr" rid="ref-1">1</xref>,<xref ref-type="bibr" rid="ref-2">2</xref>]. More specifically, PHR usually contains personal information, drug history (including dosages), history of drug allergy, records of previous illnesses and surgeries, chronic health problems, such as high blood pressure, family history, immunization records, lab test results, and other personal health information. A PHR system demonstrates the potential benefits of reducing misunderstandings and mistakes, avoiding unnecessary double treatments, physical examinations and medical tests, and eliminating adverse drug events, and so on in healthcare. The PHR is a patient-centric tool that can help increase patients&#x2019; engagement to actively learn their own health status, easily track the course of treatment, and actively cooperate with the scientific medical treatment of the health care provider. With the assistance of PHR service, the quality of healthcare can be improved significantly. Given their enormous merits, PHR systems have attracted extensive interest worldwide. Cloud computing, as a resource provision platform, offers users mass storage space, powerful computing capability, and ubiquitous access service, which is like the traditional public utility, such as water and electricity [<xref ref-type="bibr" rid="ref-3">3</xref>]. In the pursuit of universal accessibility and low cost, in practice, the PHR service providers usually resort to the cloud server to store and share their PHRs data. Although the great potential benefits are indisputable, the adoption of PHRs data sharing via the cloud computing is hindered by data security and data privacy concerns in the healthcare domain, because the PHRs include a large amount of sensitive information of the patient. For the sake of ensuring the security of the PHRs, a large number of relevant schemes have been put forward, such as [<xref ref-type="bibr" rid="ref-4">4</xref>&#x2013;<xref ref-type="bibr" rid="ref-8">8</xref>]. Nevertheless, these schemes commonly rely on a third trust authority which is difficult to find in reality, and are faced with the single point of failure issue. These security challenges urge further consideration and exploration.</p>
<p>Fortunately, the emerging blockchain technology can provide a promising and feasible solution for the secure sharing of PHRs data. The blockchain technology incorporates many promising characteristics such as decentralization, immutability, traceability, openness and anonymity. The intrinsic value of blockchain is to establish trust in a trustless distributed system without introducing any third trusted authority due to its unique features. In recent years, the blockchain technology has been envisioned as a significant innovation in information technology and aroused considerable interest in both the academic community and the industrial alliance. Over the past few years, sparked by the enormous achievements of blockchain in digital cryptocurrency, many scholars have endeavored to extend its application to various fields, such as Internet of Things [<xref ref-type="bibr" rid="ref-9">9</xref>&#x2013;<xref ref-type="bibr" rid="ref-11">11</xref>], medical data sharing [<xref ref-type="bibr" rid="ref-12">12</xref>&#x2013;<xref ref-type="bibr" rid="ref-15">15</xref>], cloud computing [<xref ref-type="bibr" rid="ref-16">16</xref>&#x2013;<xref ref-type="bibr" rid="ref-18">18</xref>], and so forth.</p>
<sec id="s1_1">
<label>1.1</label><title>Motivation and Contribution</title>
<p><bold>Motivation.</bold> To achieve secure, efficient and flexible PHRs data sharing in multi-receiver settings, it is essential to identify the following potential attacks:</p>
<p>1) Unauthorized access. In a healthcare system, PHRs data requires maintenance in a secure and private environment. The patient should have complete control over his/her PHR data and only the users authorized by the patient can have the right to full or partial access to the patient&#x2019;s PHRs data. Any unauthorized access should be prohibited. In practice, a passive adversary or malicious cloud server may eavesdrop on the sensitive PHRs data of patient for making profits or other evil purpose. All these malicious behaviors can pose a security threat of leaking the sensitive PHR information.</p>
<p>2) Integrity and consistency of shared data. An active malicious adversary may try to get unauthorized right to tamper the PHRs data before an authorized user (e.g., a doctor) can access them. This vicious active attack may lead to a misdiagnosis or a wrong treatment for the patient and cause serious harms to the patient&#x2019;s health. What is even worse, this vicious behavior may cause the death of the patient. Therefore, it is of the utmost importance that the integrity and consistency of the shared sensitive PHRs data of the patient is ensured.</p>
<p>3) Efficient revocation and decryption. To take the advantage of the premium computational ability, we introduce transformation key technique to relieve the heavy computation burden of the data users by offloading computationally intensive operations to the cloud server without leaking any sensitive data nor compromising privacy. This is especially meaningful considering the increasing popularity of resource-limited mobile devices. In addition, the efficient revocation should also be considered.</p>
<p>To achieve the patient-centric data sharing in a multiple receiver setting, it is essential to utilize the fine-grained access control that can support multiple domain users for accessing the PHRs data simultaneously. For instance, the patient intends to share their PHRs data to a hospital for the purpose of gaining the services of diagnosis, examination, and healthcare. And the patient can share partial non-sensitive information with medical research institute for conducting scientific research to enhance the quality of healthcare for human beings. And the patient can also share relevant information with their medical insurance company for processing of medical insurance claims.</p>
<p>Driven by these demands, the attribute-based encryption (ABE) scheme is introduced to guarantee the confidentiality and fine-grained access control simultaneously. However, directly using the ABE mechanism will result in several security issues. Firstly, most of the existing ABE schemes do not support the consistency and integrity checking of the shared data, and that puts the data owner and/or user at a clear disadvantage, especially in medical field, as it can lead to a misdiagnosis or other event that could endanger the patient&#x2019;s life. Secondly, currently, with the broad adoption of mobile devices, the utilization of the highly efficient user revocation and user decryption should be considered because most existing ABE schemes commonly involve heavy cryptographic operations.</p>
<p><bold>Contribution.</bold> To fill the identified gaps, in this work, we employ the consortium blockchain technology to enhance the trustworthiness of each participant and propose a blockchain-based patient-centric data sharing scheme to achieve public verifiability, immutability, scalability and fine-grained PHRs data sharing in a multiple receiver setting. The main contributions of this work are listed as follows:</p>
<p>1) First, we devise a novel blockchain based system model for patient-centric secure data sharing of PHRs in cloud computing under a multiple receiver setting. In the system model, we conceptually categorize the receiver into three different domains: hospitals, medical research institutes, and medical insurance companies.</p>
<p>2) Second, the proposed BC-PC-Share scheme can not only ensure the integrity and consistency of the shared data via semi-trust cloud computing by adopting smart contracts to perform public consistency and integrity checking, but also achieve scalable and fine-grained access control and PHRs data sharing with multiple domain users by utilizing the ABE mechanism. Moreover, the envisaged scheme can significantly reduce the decryption cost by leveraging the transformation key technique and can achieve efficient user revocation by introducing time-controlled access (i.e., the patient indirectly revokes user&#x2019;s access privileges by assigning the invalid period).</p>
<p>3) Finally, we present a concrete security analysis of the proposed BC-PC-Share scheme in terms of the correctness, CPA security, completeness, and efficient user revocation under the random oracle model. Moreover, we conduct a simulation experiment to evaluate the performance of our proposed BC-PC-Share solution. We also make a comparison of our blockchain based solution with several representative works and demonstrate that our scheme is both practical and efficient.</p>
</sec>
<sec id="s1_2">
<label>1.2</label><title>Paper Organization</title>
<p>The remainder of the paper is organized as follows. The related literatures are reviewed in <xref ref-type="sec" rid="s2">Section 2</xref>. The background knowledge is presented in <xref ref-type="sec" rid="s3">Section 3</xref>. The system framework of the BC-PC-Share scheme is modeled in <xref ref-type="sec" rid="s4">Section 4</xref>. Following this, the concrete BC-PC-Share scheme is proposed in <xref ref-type="sec" rid="s5">Section 5</xref>. Next, in <xref ref-type="sec" rid="s6">Sections 6</xref> and <xref ref-type="sec" rid="s7">7</xref>, security analysis and performance evaluation, are respectively conducted. Finally, the conclusion of this work is drawn in <xref ref-type="sec" rid="s8">Section 8</xref>.</p>
</sec>
</sec>
<sec id="s2">
<label>2</label><title>Related Work</title>
<p>In this section, we discuss the literature related to the PHRs sharing, including cloud-based PHRs sharing schemes and blockchain-based PHRs sharing schemes.</p>
<p><italic>A. Cloud-Based PHRs Sharing Schemes</italic></p>
<p>In 2013, Li et al. [<xref ref-type="bibr" rid="ref-4">4</xref>] proposed a patient-centric role-based framework for secure sharing of PHRs data in a cloud computing environment. Considering that the cloud server is not fully trusted, they adopted the ABE mechanism to achieve the confidentiality and secure sharing of PHRs data among different domain users simultaneously. Au et al. [<xref ref-type="bibr" rid="ref-5">5</xref>] suggested a general cloud-based framework for patients to fully control and securely share their sensitive PHRs data with users in the same domain and across domains. Xhafa et al. [<xref ref-type="bibr" rid="ref-7">7</xref>] proposed a multi-authority CP-ABE based PHRs data sharing scheme, which supports hidden access policy as well as the traceability and accountability of misbehaving PHR users. Despite the ABE scheme being very powerful and promising, it still suffers from a decryption efficiency weakness due to the fact that the traditional ABE based schemes involve many expensive pairing operations. To improve the decryption efficiency, many lightweight ABE data sharing schemes with outsourced decryption have been proposed [<xref ref-type="bibr" rid="ref-19">19</xref>&#x2013;<xref ref-type="bibr" rid="ref-22">22</xref>]. Xiong et al. [<xref ref-type="bibr" rid="ref-19">19</xref>] proposed an <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:msup><mml:mi>A</mml:mi><mml:mn>2</mml:mn></mml:msup><mml:msup><mml:mi>B</mml:mi><mml:mn>2</mml:mn></mml:msup><mml:mi>E</mml:mi></mml:math></inline-formula> scheme with the features of hidden access policy, in which they utilized the verifiable outsourcing decryption technique for ABE and the technique of online/offline to reduce the computational cost. However, their scheme does not support user revocation. To enhance the computational efficiency on the user-side in a PHR system, Zhang et al. [<xref ref-type="bibr" rid="ref-6">6</xref>] devised a lightweight scheme called CCP-ABAC-UA. In their scheme, the PHR receivers can access PHRs with non-bilinear-pairing computation. Additionally, their scheme can support public auditing and user revocation.</p>
<p><italic>B. Blockchain-Based PHRs Sharing Schemes</italic></p>
<p>However, all the above-mentioned schemes suffer from the single point of failure issue. To facilitate sharing of PHRs data with a high level of confidence in the distribution setting, the blockchain technique is introduced as a potentially promising approach for building trustworthiness among different distributed institutions.</p>
<p>To improve the quality of medical diagnosis, Zhang et al. [<xref ref-type="bibr" rid="ref-23">23</xref>] utilized private blockchain and consortium blockchain technology to design a secure and privacy-preserving personal health information sharing (BSPP) system, in which by getting the trapdoors from the patient, enables the authorized doctor to have the privilege to search specific health records for certain patients. Thwin et al. [<xref ref-type="bibr" rid="ref-24">24</xref>] suggested a privacy-preserving access control model for secret PHRs data sharing, which supports granting and revoking access rights by incorporating the blockchain technology and proxy re-encryption (PRE) technique. Chen et al. [<xref ref-type="bibr" rid="ref-11">11</xref>] combined the searchable encryption technology with blockchain technology and proposed a blockchain-based searchable encryption scheme for eHealth data outsourced to the public cloud server, however, one of the critical concerning issues is that the cloud server is not fully reliable and not entirely trustworthy. Cao et al. [<xref ref-type="bibr" rid="ref-25">25</xref>] proposed a cloud-based secure eHealth scheme, named TP-EHR, to prevent the EHRs from any illegal tampering by adopting the blockchain technology, where a password-based authentication mechanism was introduced to resist password guessing attacks. Nagasubramanian et al. [<xref ref-type="bibr" rid="ref-26">26</xref>] proposed a KSIBC framework to guarantee the security and integrity of sensitive healthcare data between doctors and patients by leveraging blockchain technology. By combing the ABE and blockchain technology, Yang et al. [<xref ref-type="bibr" rid="ref-27">27</xref>] proposed an ABE keyword search scheme for blockchains, which can support users to search encrypted files over the blockchain according to their attributes. The above-mentioned blockchain-based eHealth data systems have a similar characteristic, that is, all of them do not use blockchain for storing eHealth data, while these schemes use blockchain for storing the metadata. Different from the previous schemes given above, Nagasubramanian et al. [<xref ref-type="bibr" rid="ref-26">26</xref>] and Al Omar et al. [<xref ref-type="bibr" rid="ref-28">28</xref>] store the healthcare data of patients in the blockchain directly and deploy it in the cloud computing environment.</p>
</sec>
<sec id="s3">
<label>3</label><title>Preliminaries</title>
<p>In this section, we present some background knowledge associated with this paper.</p>
<sec id="s3_1">
<label>3.1</label><title>Blockchain</title>
<p>Blockchain contains continuously growing blocks, which are chronologically linked by using a set of cryptography techniques and the consensus algorithm, and thus forming a chain [<xref ref-type="bibr" rid="ref-29">29</xref>,<xref ref-type="bibr" rid="ref-30">30</xref>]. It is the underlying technology of the well-known Bitcoin which was originally developed by a mysterious person, named Satoshi Nakamoto in 2008 [<xref ref-type="bibr" rid="ref-31">31</xref>]. Essentially speaking, blockchain is a distributed publicly shared transaction ledger where transaction data is recorded permanently. As an innovative architecture, the blockchain system integrates many advanced technologies, such as a Peer-to-Peer (P2P) network, distributed ledger, and consensus mechanism as well as smart contracts. In a blockchain network, all the participating nodes are equal and collaborate with each other without the requirement of a trusted central party. Thus, it can eliminate the potential security risk of single point of failure (SPOF).</p>
<p>A block in blockchain is composed of two components: the block header and the block body, and the data structure of blocks is illustrated in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>. Each block in the blockchain contains a hash-pointer that points to the immediate prior block, and this basic structure produces one of the most prominent feature of the blockchain called immutability, i.e., once the data is verified by consensus nodes and stored in a blockchain, it cannot be permanently tampered with because of the irreversibility of cryptographic hash function. And the block body records the specific transaction data by using Merkle hash tree. With the time goes by, the new blocks are continuously generated and appended to the chain and once accepted by the consensus nodes, cannot be tampered with nor removed.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption><title>Data structure of blocks</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_26321-fig-1.tif"/>
</fig>
<p>According to the application scenarios and the access privilege, the blockchain can be divided into three categories: public blockchain, consortium blockchain, and private blockchain.</p>
<p>Public blockchain refers to a blockchain in which anyone around the world can access it at any time to read data, conduct transactions, and consent nodes. Public blockchains are generally regarded as &#x201C;completely decentralized&#x201D; architecture because there is no individual or institution that can control or tamper with the blockchain. The public blockchain generally relies on the incentive mechanism to encourage participants to compete for bookkeeping. For instance, the well-known Bitcoin and Ethereum are two typical applications of public blockchains.</p>
<p>Private blockchain refers to a blockchain whose write permission is controlled by an organization or institution, and the eligibility of participating nodes is severely restricted. The application scenario of private blockchain is generally the internal application of an enterprise, such as database management, and auditing.</p>
<p>Consortium blockchain refers to a blockchain that is managed by several institutions. Each institution runs one or more nodes. Consortium blockchain is generally considered as a &#x201C;partially decentralized&#x201D; platform because the data only allows participations within the system to read, write, and send transactions, and together record transaction data.</p>
</sec>
<sec id="s3_2">
<label>3.2</label><title>Smart Contracts</title>
<p>Smart contract [<xref ref-type="bibr" rid="ref-32">32</xref>] is a terminology used to describe some special script codes deployed on the blockchain that automatically executes all or parts of an agreement on all the nodes of the blockchain network among distributed untrustworthy entities without the involvement of a third trusted central party if a predefined condition is fulfilled. Smart contract is commonly an indispensably key component of the applications based on blockchain or distributed ledger technology. When predetermined conditions are met, the smart contracts automatically trigger the execution of an agreement. Moreover, they can also trigger the next action to support automatic continuous execution, namely, to form a workflow. To prevent contract from being tampered with, the smart contracts are copied to each node of the blockchain network. To further prevent contracts from being tampered with, each node also holds a copy of the smart contracts and executes the codes. The execution result of the smart contract is visible to each participant node and is verified by all participants. Only when all the participants agree on the result will they update their ledger. By this mechanism, it can yield a correct, immutable, and credible result, and further can avoid any disputes regarding the execution result of smart contracts. Thus, the smart contract can be regarded as a public trusted mechanism for correctness, but not for privacy [<xref ref-type="bibr" rid="ref-11">11</xref>].</p>
</sec>
<sec id="s3_3">
<label>3.3</label><title>Access Structure</title>
<fig id="fig-6">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_26321-fig-6.tif"/>
</fig>
<p>It should be noted that, in our work, the role of the parties is represented by the attributes. Therefore, the access structure <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:mrow><mml:mi mathvariant="double-struck">A</mml:mi></mml:mrow></mml:math></inline-formula> will consist of the authorized sets of attributes. From now on, unless otherwise indicated, an access structure is referred to a monotone one in our context.</p>
</sec>
<sec id="s3_4">
<label>3.4</label><title>Access Tree</title>
<p>An access tree is used to describe an access structure [<xref ref-type="bibr" rid="ref-33">33</xref>]. In this subsection, a brief description of an access policy tree is given below:</p>
<p><italic>T</italic>: This represents an access tree representing the access structure.</p>
<p><italic>x</italic>: This represents a node in the access tree <italic>T</italic>, which can be categorized into two types: Leaf node and non-leaf node (interior node). Each non-leaf interior node is represented by a threshold gate, such as &#x201C;AND&#x201D; or &#x201C;OR&#x201D; threshold gate while each leaf node is associated with an attribute.</p>
<p><inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:mi>n</mml:mi><mml:mi>u</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>: This represents the number of children of the node <italic>x</italic>.</p>
<p><inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>: This represents the threshold value of node <italic>x</italic>, where <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:mn>0</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x2264;</mml:mo><mml:mi>n</mml:mi><mml:mi>u</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>. If <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> and <italic>x</italic> is an interior node, it means that the threshold is an &#x201C;OR&#x201D; gate. If <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mi>n</mml:mi><mml:mi>u</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> and <italic>x</italic> is an interior node, it means that the threshold is an &#x201C;AND&#x201D; gate. In particular, the threshold value of each leaf node <italic>x</italic> is defined as <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>.</p>
<p><italic>parent</italic>(<italic>x</italic>): The function <italic>parent</italic>(<italic>x</italic>) is used to return the parent of the node <italic>x</italic> in the access tree.</p>
<p><italic>index</italic>(<italic>x</italic>): The function <italic>index</italic>(<italic>x</italic>) is used to return a unique number associated with the node <italic>x</italic>, where the number is uniquely assigned to <italic>x</italic> in a certain manner.</p>
<p><italic>att</italic>(<italic>x</italic>): The function <italic>att</italic>(<italic>x</italic>) is used to return an attribute associated with the leaf node <italic>x</italic> in the access tree.</p>
<p><inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>: This represents the sub-tree for <italic>T</italic> rooted at the node <italic>x</italic> in the access tree.</p>
<p>If an attribute set <italic>S</italic> matches the sub-access-tree <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>, it is represented as <inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>. <inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> outputs 1 if and only if the following conditions are satisfied:
<list list-type="simple">
<list-item><label>(1)</label><p>If <italic>x</italic> is a leaf node, <inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> if and only if <italic>att</italic>(<italic>x</italic>) <inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:mo>&#x2208;</mml:mo></mml:math></inline-formula> <italic>S</italic>.</p></list-item>
<list-item><label>(2)</label><p>If <italic>x</italic> is an interior node, each child <inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> of node <italic>x</italic> is individually computed in a recursive way. <inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> if and only if at least <inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> children return 1.</p></list-item>
</list></p>
</sec>
<sec id="s3_5">
<label>3.5</label><title>Attribute-Based Encryption</title>
<p>Attribute-based encryption(ABE) is a hot direction in cryptographic research in recent years. It can effectively realize fine-grained non-interactive access control mechanisms and has a broad range of application prospects. In 2005, Sahai et al. [<xref ref-type="bibr" rid="ref-34">34</xref>] first developed a new idea of a fuzzy identity-based encryption scheme (Fuzzy-IBE), in which the unique identity information was extended to biological characteristic information. And later, it was developed to the notion of attribute-based encryption by Goyal et al. [<xref ref-type="bibr" rid="ref-35">35</xref>]. On the base of the combination approach of the secret key and ciphertext associated with the access policy, the ABE schemes can be mainly classed as Key-Policy ABE(KP-ABE) scheme [<xref ref-type="bibr" rid="ref-35">35</xref>] and Ciphertext-Policy ABE(CP-ABE) scheme [<xref ref-type="bibr" rid="ref-33">33</xref>]. In the KP-ABE mechanism, the secret keys are bound with an access policy and the ciphertext are bound with a set of attributes. In contrast, in the CP-ABE mechanism, the secret keys are associated with a set of attributes and the ciphertext are bound with an access policy. In the CP-ABE scheme, the data owners can define access policies over ciphertexts arbitrarily, therefore, it is more suited for fine grained access control than KP-ABE scheme in cloud computing. By virtue of this merit, a number of CP-ABE schemes for securely sharing medical data have been proposed in cloud computing [<xref ref-type="bibr" rid="ref-4">4</xref>,<xref ref-type="bibr" rid="ref-36">36</xref>&#x2013;<xref ref-type="bibr" rid="ref-38">38</xref>].</p>
</sec>
<sec id="s3_6">
<label>3.6</label><title>Bilinear Pairing</title>
<fig id="fig-7">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_26321-fig-7.tif"/>
</fig>
</sec>
<sec id="s3_7">
<label>3.7</label><title>Complexity Assumptions</title>
<fig id="fig-8">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_26321-fig-8.tif"/>
</fig>
</sec>
</sec>
<sec id="s4">
<label>4</label><title>System Model</title>
<p>In this section, we discuss the system model of the proposed BC-PC-Share scheme, including the system architecture, the workflow of the proposed scheme and the general definition of the BC-PC-Share scheme.</p>
<sec id="s4_1">
<label>4.1</label><title>System Architecture</title>
<p>In this work, we consider a specific scenario that a patient wants to share his/her PHRs data to multiple organizations, such as hospitals, medical research institutes, and medical insurance companies for different uses and purposes. Thus, we adopt a consortium blockchain to reserve the authentication information and achieve the patient-centric secure medical data sharing. Accordingly, as illustrated in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>, the system model of the proposed BC-PC-Share scheme mainly consists of four entities: the Data Owner (DO), the Data User (DU), the Cloud Service Provider (CSP), and the BlockChain (BC). The patient-centric data sharing framework can be divided into three different layers, named Data Layer, User Layer and Authentication layer, respectively. The function of each layer is discussed as follows:</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption><title>System model of BC-PC-Share</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_26321-fig-2.tif"/>
</fig>
 <p> 1) Data Layer. The function of this layer is to provide the storage service for the data owner DO and provide the downloading service for the data user DU. There is only one entity in the Data Layer.</p>
<p>&#x2022; CSP. The CSP is responsible for storing the patient&#x2019;s encrypted PHRs data uploaded by the patient, and it is also responsible for simplifying the complicated ciphertext and providing the service of downloading the shared data for the authorized data user DU. Note that the CSP is generally regarded as a semi-trusted third party because its trust domain is not identical to the DO or DU. Especially, the cloud computing provider may intentionally destroy or tamper with the user&#x2019;s sensitive data or only transform partial ciphertext of the shared PHRs or even return wrong computation results in a bid to save its storage and computation resource to pursue maximum economic interest, or other malicious purpose. Thus, the data storing to the CSP or the shared data downloading from the CSP should be performed with integrity and consistency verification and the validity of the ciphertext transformed by the CSP should also be checked.</p>
<p>2) User Layer. The components of this layer include two entities: the data owner DO and the data user DU. Their roles in our scheme can be described as below:</p>
<p>&#x2022; DO. In the proposed BC-PC-Share scheme, the DO is referred to as the patient owning a series of PHR data and with full control over his/her PHR data for sharing them with hospitals, medical research institutes, medical insurance companies and other entities.</p>
<p>&#x2022; DU. The DU is referred to the individuals or organizations that are allowed to access the patient&#x2019;s PHR data for medically relevant purposes. Only the authenticated users can access the specified PHR data of the patient. In the proposed BC-PC-Share scheme, the DU is categorized into three different types according to their different uses of the PHR data: the hospital (for the purpose of diagnosis, examination, and healthcare for the patient himself/herself), the medical research institute (for the purpose of conducting scientific research to enhance the quality of healthcare for human beings), and the medical insurance company (for the purpose of providing medical insurance services).</p>
<p>3) Authentication layer. The component of this layer only includes one entity, named the Blockchain. The function of this layer is to record the related authentication information during the PHR data storage and sharing process by the blockchain network. The blockchain plays an essential role in our scheme. It is a peer-to-peer network composed of consensus nodes, a data pool, miners and so on. The consortium blockchain is introduced in our system to keep the authentication information and achieve secure data storage and data sharing.</p>

</sec>
<sec id="s4_2">
<label>4.2</label><title>Workflow of the BC-PC-Share Scheme</title>
<p>The interaction between each entity is shown in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>, and the specific workflow of the BC-PC-Share scheme (the description of each numbered step) in <xref ref-type="fig" rid="fig-2">Fig. 2</xref> can be described as follows.</p>
<p>&#x2460; The patient (PHR data owner, DO) encrypts his/her PHR data to be outsourced and uploads the generated ciphertext to the cloud server for storage.</p>
<p>&#x2461; The DO generates the storage authentication information for the outsourced PHR data and sends it to the smart contracts for storage verification.</p>
<p>&#x2462; The cloud server generates the storage validation request and sends it to the smart contracts for storage validation verification. If the storage verification is passed, the smart contracts send the storage authentication information as a transaction to the blockchain.</p>
<p>&#x2463; The DU sends a data sharing request with his/her attributes to the DO.</p>
<p>&#x2464; After successful verification of the validity of the request of DU, the data owner DO generates a user decryption key for DU and sends it to the DU.</p>
<p>&#x2465; At the same time, the DO generates a cloud-assisted transformation key for the DU and sends it to the cloud server.</p>
<p>&#x2466; After transforming the complicated ciphertext to a simplified ciphertext, the cloud server sends the transformation authentication information to the smart contracts for transform validation verification. If the transform verification is passed, the smart contracts send the storage authentication information as a transaction to the blockchain.</p>
<p>&#x2467; The consensus nodes in the blockchain inform the data user DU to download the shared PHR data from the cloud server.</p>
<p>&#x2468; The DU downloads the encrypted sharing data from the cloud server.</p>
<p>&#x2469; The DU decrypts the untampered encrypted sharing data and obtains the correct plain message.</p>
<sec id="s4_2_1">
<label>4.2.1</label><title>Formal Definition</title>
<fig id="fig-9">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_26321-fig-9.tif"/>
</fig>
<p>&#x25CF; PHR data storage stage</p>
<p>The PHR data storage stage contains six procedures, i.e., Signingkey Generation, Ciphertext Generation, Storage Authentication Generation, Storage Validation Request, Storage Verification, Block Generation, and Storage Confirm, respectively. The brief description of each procedure is given below:</p>
<p>1) Signingkey Generation.</p>
<p>The DO randomly generates a signing key pair.</p>
<p>2) Ciphertext Generation.</p>
<p>The DO defines an access structure (policy), and encrypts the plaintext message to generate the corresponding ciphertext.</p>
<p>3) Storage Authentication Generation.</p>
<p>The DO sends the ciphertext to the cloud server for storage and sends the corresponding storage authentication information to the smart contracts, respectively.</p>
<p>4) Storage Validation Request.</p>
<p>The cloud server generates the storage validation request and sends it to the smart contracts for storage validation</p>
<p>5) Storage Verification.</p>
<p>The smart contracts automatically execute the storage verification. If the storage verification is passed, the smart contracts send the storage authentication information as a transaction to the blockchain.</p>
<p>6) Block Generation.</p>
<p>The consensus nodes in the blockchain run the consensus algorithm to verify the transaction which is sent by smart contracts and generate a valid block linked to the blockchain, then return the block ID to the data owner DO and the cloud server, respectively.</p>
<p>7) Storage Confirm.</p>
<p>According to the information of the returned block ID, the DO can confirm whether his/her data has been stored in integrity in the cloud server.</p>
<p>&#x25CF; PHR data sharing stage</p>
<p>The PHR data sharing stage involves six procedures, named, Signingkey Generation, Sharing Request Generation, Sharing Request Authorization, PHRs Transformation and Sharing, Transformation Verification and Block Generation, and Decryption, respectively. The brief description of each procedure is given below:</p>
<p>1) Signingkey Generation.</p>
<p>The data user DU generates a random signing key pair.</p>
<p>2) Sharing Request Authorization.</p>
<p>The DU sends a data sharing request to the DO.</p>
<p>3) Sharing Request Authorization.</p>
<p>The DO generates the cloud-assisted transformation key <italic>TK</italic> and the user decryption key <italic>UK</italic>, then sends the former to the cloud server and sends the latter to the DU, respectively.</p>
<p>4) PHR Transformation and Sharing.</p>
<p>The cloud server calls the <inline-formula id="ieqn-54"><mml:math id="mml-ieqn-54"><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>s</mml:mi><mml:mi>f</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> algorithm to transform the complicated ciphertext to a simplified ciphertext. Next, the cloud server sends the transformation authentication information to the smart contracts for transform validation verification.</p>
<p>5) Transformation Verification and Block Generation.</p>
<p>The smart contracts verify the integrity and consistency of the shared PHR information (i.e., the validity of the transformed ciphertext given by the cloud server). If the transformation verification is passed, the smart contracts send the transformation authentication information as a transaction to the blockchain. Then, the consensus nodes in the blockchain perform the consensus algorithm (e.g., PBFT) to verify the transaction and generate a valid block linked to the blockchain.</p>
<p>6) Decryption.</p>
<p>After the above successful verification, the DU can decrypt the untampered encrypted PHR data with the user decryption key obtained from the DO and recover the plain message.</p>
</sec>
</sec>
</sec>
<sec id="s5">
<label>5</label><title>The Concrete BC-PC-Share Scheme</title>
<sec id="s5_1">
<label>5.1</label><title>Scheme Description</title>
<p>In this section, we first design a novel cloud-assisted decryption algorithm of CP-ABE with public third-party verification in subsection <italic>A</italic>, then we propose the concrete blockchain-based patient-centric data sharing scheme for PHRs in cloud computing in subsection <italic>B</italic>.</p>
<p><italic>A. Attribute-Based Encryption with Public Verifiable Outsourced Decryption (PVOD-ABE)</italic></p>
<p>Lai et al. [<xref ref-type="bibr" rid="ref-39">39</xref>] proposed a novel model of CP-ABE with verifiable outsourced decryption to guarantee the correctness of the outsourced ciphertext transformation by an untrusted third party (e.g., the remote cloud server). Undoubtedly, the feature of verifiability is a tremendous progress for outsourcing ABE schemes. Nevertheless, their scheme only supported the data user to check the validity of the outsourced ciphertext transformation and failed to support the public verification. Thus, their scheme is not appropriate for the blockchain scenarios. To fill this gap, in this subsection, we develop an Attribute-Based Encryption with Public Verifiable Outsourced Decryption (PVOD-ABE) algorithm, which cannot only achieve the goal of outsourcing the majority of the intensive decryption operations to the cloud server to reduce the computational burden of the classical CP-ABE scheme, but also support the good security property of public verification.</p>
<p>Now, we present the details of our proposed PVOD-ABE algorithm, which consists of five steps, that is, <italic>SystemSetup</italic>, <italic>KeyGen</italic>, <italic>Encrypt</italic>, <inline-formula id="ieqn-55"><mml:math id="mml-ieqn-55"><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>s</mml:mi><mml:mi>f</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>, and <italic>UserDecrypt</italic>. Each of them is described as follows:
<list list-type="bullet">
<list-item>
<p><inline-formula id="ieqn-56"><mml:math id="mml-ieqn-56"><mml:mi>S</mml:mi><mml:mi>y</mml:mi><mml:mi>s</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi><mml:mi>S</mml:mi><mml:mi>e</mml:mi><mml:mi>t</mml:mi><mml:mi>u</mml:mi><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo>,</mml:mo><mml:mi>U</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>M</mml:mi><mml:mi>S</mml:mi><mml:mi>K</mml:mi><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. This step is performed by the DO. Given a system security parameter <italic>k</italic> and the universal attribute set <italic>U</italic>, it first chooses two multiplicative cyclic groups <inline-formula id="ieqn-57"><mml:math id="mml-ieqn-57"><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-58"><mml:math id="mml-ieqn-58"><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> with the same prime order <inline-formula id="ieqn-59"><mml:math id="mml-ieqn-59"><mml:mi>q</mml:mi><mml:mtext>&#xA0;</mml:mtext><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x2265;</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mn>2</mml:mn></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, a bilinear map <inline-formula id="ieqn-60"><mml:math id="mml-ieqn-60"><mml:mi>e</mml:mi><mml:mrow><mml:mo>:</mml:mo></mml:mrow><mml:mtext>&#xA0;</mml:mtext><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x00D7;</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> between the two group <inline-formula id="ieqn-61"><mml:math id="mml-ieqn-61"><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-62"><mml:math id="mml-ieqn-62"><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>, and three secure one-way hash functions <inline-formula id="ieqn-63"><mml:math id="mml-ieqn-63"><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo>:</mml:mo></mml:mrow><mml:mtext>&#xA0;</mml:mtext><mml:msubsup><mml:mi>Z</mml:mi><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-64"><mml:math id="mml-ieqn-64"><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo>:</mml:mo></mml:mrow><mml:mtext>&#xA0;</mml:mtext><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula> and <inline-formula id="ieqn-65"><mml:math id="mml-ieqn-65"><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo>:</mml:mo></mml:mrow><mml:mtext>&#xA0;</mml:mtext><mml:mrow><mml:msup><mml:mrow><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>. Then, it defines the Lagrange coefficients as <inline-formula id="ieqn-66"><mml:math id="mml-ieqn-66"><mml:mrow><mml:msub><mml:mrow><mml:mi>L</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>K</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:munder><mml:mo movablelimits="false">&#x220F;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>K</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>i</mml:mi></mml:mrow></mml:munder><mml:mrow><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mi>x</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>j</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>j</mml:mi></mml:mrow></mml:mfrac></mml:mstyle></mml:mrow></mml:math></inline-formula>, where <inline-formula id="ieqn-67"><mml:math id="mml-ieqn-67"><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup></mml:math></inline-formula>, and the <italic>K</italic> is a set with the elements in <inline-formula id="ieqn-68"><mml:math id="mml-ieqn-68"><mml:msubsup><mml:mi>Z</mml:mi><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup></mml:math></inline-formula>. Next, it randomly picks <inline-formula id="ieqn-69"><mml:math id="mml-ieqn-69"><mml:mi>g</mml:mi><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> and <inline-formula id="ieqn-70"><mml:math id="mml-ieqn-70"><mml:mi>&#x03B1;</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03B2;</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup></mml:math></inline-formula>, then computes <inline-formula id="ieqn-71"><mml:math id="mml-ieqn-71"><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>&#x03B1;</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-72"><mml:math id="mml-ieqn-72"><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:msup><mml:mrow><mml:mi>&#x03B1;</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>. Denote the master public key and the master secrete key pair as (<inline-formula id="ieqn-73"><mml:math id="mml-ieqn-73"><mml:mi>M</mml:mi><mml:mi>P</mml:mi><mml:mi>K</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>g</mml:mi><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, <inline-formula id="ieqn-74"><mml:math id="mml-ieqn-74"><mml:mi>M</mml:mi><mml:mi>S</mml:mi><mml:mi>K</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03B2;</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>). Finally, the DO publishes the system public parameters <inline-formula id="ieqn-75"><mml:math id="mml-ieqn-75"><mml:mi>P</mml:mi><mml:mi>P</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, and keeps the master secrete key <italic>MSK</italic> confidentially.</p></list-item>
<list-item>
<p><italic>KeyGen</italic>(<italic>MSK</italic>, <italic>PP</italic>, <italic>S</italic>) &#x2192; (<italic>TK</italic>, <italic>UK</italic>). Upon receiving the master secrete key <inline-formula id="ieqn-76"><mml:math id="mml-ieqn-76"><mml:mi>M</mml:mi><mml:mi>S</mml:mi><mml:mi>K</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>a</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03B2;</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, the system public parameters <italic>PP</italic>, and the attribute set of user <italic>S</italic>, the key generation algorithm firstly selects three random numbers <inline-formula id="ieqn-77"><mml:math id="mml-ieqn-77"><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mi>d</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup></mml:math></inline-formula>, then for each attribute, randomly chooses a number <inline-formula id="ieqn-78"><mml:math id="mml-ieqn-78"><mml:mrow><mml:msub><mml:mrow><mml:mi>u</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup></mml:math></inline-formula> and computes <inline-formula id="ieqn-79"><mml:math id="mml-ieqn-79"><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>K</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>K</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>K</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-80"><mml:math id="mml-ieqn-80"><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>K</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>+</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msubsup><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>&#x03C9;</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>u</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-81"><mml:math id="mml-ieqn-81"><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>K</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>u</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>. Finally, it returns the transform key <inline-formula id="ieqn-82"><mml:math id="mml-ieqn-82"><mml:mi>T</mml:mi><mml:mi>K</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>K</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>S</mml:mi></mml:mrow><mml:mrow><mml:mi>U</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo></mml:math></inline-formula> <inline-formula id="ieqn-83"><mml:math id="mml-ieqn-83"><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>&#x03B1;</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mi>&#x03B2;</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and the user decryption key <italic>UK</italic> &#x003D; <italic>t</italic>.</p></list-item>
<list-item>
<p><italic>Encrypt</italic>(<italic>PP</italic>, <italic>T</italic>, <italic>m</italic>) &#x2192; (<italic>CT</italic>). On input the system public parameters <italic>PP</italic>, the access policy tree <italic>T</italic>, and the message <inline-formula id="ieqn-84"><mml:math id="mml-ieqn-84"><mml:mi>m</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula> to be encrypted, the data owner DO generates the ciphertext <italic>CT</italic> as follows:</p></list-item>
</list>
<list list-type="simple">
<list-item><label>(1)</label><p>The DO randomly selects <inline-formula id="ieqn-85"><mml:math id="mml-ieqn-85"><mml:mi>r</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup></mml:math></inline-formula>, and assigns a polynomial <inline-formula id="ieqn-86"><mml:math id="mml-ieqn-86"><mml:mrow><mml:msub><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> with the degree <inline-formula id="ieqn-87"><mml:math id="mml-ieqn-87"><mml:mrow><mml:msub><mml:mrow><mml:mi>d</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> in a top-down approach, and sets <inline-formula id="ieqn-88"><mml:math id="mml-ieqn-88"><mml:mrow><mml:msub><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>r</mml:mi></mml:math></inline-formula>, where the node <italic>root</italic> is the root of the access policy tree <italic>T</italic>. Otherwise, for non-root node <italic>x</italic>, the DO sets <inline-formula id="ieqn-89"><mml:math id="mml-ieqn-89"><mml:mrow><mml:msub><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where <italic>p</italic>(<italic>x</italic>) denotes the parent node of <italic>x</italic>, and <italic>index</italic>(<italic>x</italic>) denotes a unique number assigned to <italic>x</italic> in an arbitrary order.</p></list-item>
<list-item><label>(2)</label><p>Calculate <inline-formula id="ieqn-90"><mml:math id="mml-ieqn-90"><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> for each leaf node <italic>x</italic>, where <inline-formula id="ieqn-91"><mml:math id="mml-ieqn-91"><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-92"><mml:math id="mml-ieqn-92"><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>t</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mrow><mml:msub><mml:mrow><mml:mi>h</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula> and <inline-formula id="ieqn-93"><mml:math id="mml-ieqn-93"><mml:mrow><mml:msub><mml:mrow><mml:mi>h</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>t</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Here, the function <italic>att</italic>(<italic>x</italic>) is used to return an attribute associated with the leaf node <italic>x</italic> in the access tree <italic>T</italic>.</p></list-item>
<list-item><label>(3)</label><p>The DO computes <inline-formula id="ieqn-94"><mml:math id="mml-ieqn-94"><mml:mi>K</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>r</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula id="ieqn-95"><mml:math id="mml-ieqn-95"><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mi>m</mml:mi><mml:mo>&#x2295;</mml:mo><mml:mi>K</mml:mi></mml:math></inline-formula>.</p></list-item>
<list-item><label>(4)</label><p>Finally, the DO outputs <inline-formula id="ieqn-96"><mml:math id="mml-ieqn-96"><mml:mi>C</mml:mi><mml:mi>T</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>T</mml:mi><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:msubsup><mml:mi>C</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>.</p></list-item>
</list>
<list list-type="simple">
<list-item>
<p>&#x2022; <inline-formula id="ieqn-97"><mml:math id="mml-ieqn-97"><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>s</mml:mi><mml:mi>f</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>P</mml:mi><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:mi>T</mml:mi><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mi>K</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>C</mml:mi><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></p></list-item>
</list></p>
<p>This algorithm is used to transform the complicated ciphertext <italic>CT</italic> to a simplified ciphertext <italic>CT</italic><sup><italic>&#x2032;</italic></sup> by the cloud server. The specific steps for the transform process are as follows:
<list list-type="simple">
<list-item><label>(1)</label><p>The cloud server defines a recursive algorithm <italic>Dec</italic>(<italic>CT</italic>, <italic>TK</italic>, <italic>x</italic>). It takes the ciphertext <italic>CT</italic>, the cloud-assisted transformation key <italic>TK</italic>, and a node <italic>x</italic> in the access tree <italic>T</italic> as input.</p></list-item>
</list>
<list list-type="simple">
<list-item><label>(a)</label><p>If <italic>x</italic> is the leaf node, then</p></list-item>
</list>
<list list-type="simple">
<list-item><label>(1)</label><p>If <inline-formula id="ieqn-98"><mml:math id="mml-ieqn-98"><mml:mrow><mml:msub><mml:mrow><mml:mi>&#x03C9;</mml:mi></mml:mrow><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>t</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2208;</mml:mo><mml:mi>S</mml:mi></mml:math></inline-formula>, then return as <xref ref-type="disp-formula" rid="eqn-1">formula (1)</xref>.</p></list-item>
</list></p>
<p><disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mi>D</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>C</mml:mi><mml:mi>T</mml:mi><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mi>K</mml:mi><mml:mo>,</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mtd><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow><mml:mo>,</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mrow><mml:mtext>+</mml:mtext></mml:mrow><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>&#x03C9;</mml:mi></mml:mrow><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msup><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>&#x03C9;</mml:mi></mml:mrow><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>u</mml:mi></mml:mrow><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>&#x03C9;</mml:mi></mml:mrow><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msup><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>&#x03C9;</mml:mi></mml:mrow><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>u</mml:mi></mml:mrow><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow><mml:mi>e</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>g</mml:mi><mml:mo>,</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>
<list list-type="simple">
<list-item><label>(2)</label><p>If <inline-formula id="ieqn-99"><mml:math id="mml-ieqn-99"><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>t</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2209;</mml:mo><mml:mi>S</mml:mi></mml:math></inline-formula>, then return <italic>Dec</italic>(<italic>CT</italic>, <italic>TK</italic>, <italic>x</italic>) &#x003D; &#x22A5;.</p></list-item>
<list-item><label>(b)</label><p>For node <italic>x</italic> is an internal node of access tree <italic>T</italic>, for all the children <italic>z</italic> of <italic>x</italic>, if the number of nodes which satisfy <italic>Dec</italic>(<italic>CT</italic>, <italic>TK</italic>, <italic>z</italic>) &#x2260; &#x22A5; is less than the threshold <inline-formula id="ieqn-100"><mml:math id="mml-ieqn-100"><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>, then return <italic>Dec</italic>(<italic>CT</italic>, <italic>TK</italic>, <italic>x</italic>) &#x003D; &#x22A5;. Otherwise, randomly chooses <inline-formula id="ieqn-101"><mml:math id="mml-ieqn-101"><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> child nodes such that <italic>Dec</italic>(<italic>CT</italic>, <italic>TK</italic>, <italic>z</italic>) &#x2260; &#x22A5; to construct a node set <inline-formula id="ieqn-102"><mml:math id="mml-ieqn-102"><mml:msubsup><mml:mi>S</mml:mi><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>z</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>z</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:msubsup><mml:mi>S</mml:mi><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msubsup></mml:mrow></mml:math></inline-formula>, then continue to calculate as <xref ref-type="disp-formula" rid="eqn-2">formula (2)</xref>.</p></list-item>
</list></p>
<p><disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mi>D</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>C</mml:mi><mml:mi>T</mml:mi><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mi>K</mml:mi><mml:mo>,</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mtd><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:munder><mml:mo movablelimits="false">&#x220F;</mml:mo><mml:mrow><mml:mi>z</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:msubsup><mml:mi>S</mml:mi><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msubsup></mml:mrow></mml:mrow></mml:munder><mml:mrow><mml:mi>D</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>C</mml:mi><mml:mi>T</mml:mi><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mi>K</mml:mi><mml:mo>,</mml:mo><mml:mi>z</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>L</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>S</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow><mml:mi>e</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>g</mml:mi><mml:mo>,</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>
<list list-type="simple">
<list-item><label>(2)</label><p>The cloud server obtains <inline-formula id="ieqn-103"><mml:math id="mml-ieqn-103"><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi><mml:msup><mml:mrow><mml:mi>p</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mi>e</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>g</mml:mi><mml:mo>,</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula> by calling <italic>Dec</italic>(<italic>CT</italic>, <italic>TK</italic>, <italic>root</italic>), where <italic>root</italic> is the root node of the access tree <italic>T</italic>. Further, we could get <inline-formula id="ieqn-104"><mml:math id="mml-ieqn-104"><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi><mml:mi>p</mml:mi><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi><mml:msup><mml:mrow><mml:mi>p</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msup></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>3</mml:mn></mml:mrow><mml:mrow><mml:mi>r</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac></mml:mstyle><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>.</p></list-item>
<list-item><label>(3)</label><p>The cloud server returns the simplified ciphertext <inline-formula id="ieqn-105"><mml:math id="mml-ieqn-105"><mml:mi>C</mml:mi><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>.</p></list-item>
</list>
<list list-type="simple">
<list-item>
<p>&#x2022; <italic>UserDecrypt</italic>(<italic>PP</italic>, <italic>UK</italic>, <italic>CT</italic><sup><italic>&#x2032;</italic></sup>) &#x2192; (<italic>m</italic>)</p></list-item>
</list></p>
<p>On input the public parameters <italic>PP</italic>, and the transformed cyphertext <italic>CT</italic><sup><italic>&#x2032;</italic></sup>, the DU first verify the validity of the outsourced decryption by checking whether <inline-formula id="ieqn-106"><mml:math id="mml-ieqn-106"><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>p</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:msup><mml:mrow><mml:mi>&#x03B1;</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mi>&#x03B2;</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> holds or not. If the equation holds, it means that the transformed ciphertext is valid. After the verification is passed, the DU computes <inline-formula id="ieqn-107"><mml:math id="mml-ieqn-107"><mml:mi>K</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>p</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:msup><mml:mrow><mml:mi>t</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, then the DU decrypts the ciphertext and obtains the plaintext message <inline-formula id="ieqn-108"><mml:math id="mml-ieqn-108"><mml:mi>m</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x2295;</mml:mo><mml:mi>K</mml:mi></mml:math></inline-formula>. Actually, the verification process can be performed by a public verifier because the verification equation is independent with the decryption key.</p>
<p><bold>Correctness Proof:</bold></p>
<p>According to <xref ref-type="disp-formula" rid="eqn-1">formulas (1)</xref> and <xref ref-type="disp-formula" rid="eqn-2">(2)</xref>, the value of <italic>temp</italic> in the transformed ciphertext <italic>CT</italic><sup><italic>&#x2032;</italic></sup> can be computed as <xref ref-type="disp-formula" rid="eqn-3">formula (3)</xref>.</p>
<p><disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi><mml:mi>p</mml:mi></mml:mtd><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>D</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>C</mml:mi><mml:mi>T</mml:mi><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mi>K</mml:mi><mml:mo>,</mml:mo><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>3</mml:mn></mml:mrow><mml:mrow><mml:mi>r</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
<p>Then, the data user DU can gain the plain message <italic>m</italic> by the user decryption key <italic>UK</italic> as follows. <inline-formula id="ieqn-109"><mml:math id="mml-ieqn-109"><mml:mi>m</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x2295;</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>r</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x2295;</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>p</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:msup><mml:mi>t</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Therefore, the data user DU can recover the shared data. Hence, the correctness of the PVOD-ABE is proved.</p>
<p><italic>B. The Construction of the BC-PC-Share Scheme</italic></p>
<p>On the base of the PVOD-ABE algorithm in subsection <italic>A</italic>, we propose a blockchain-based patient-centric data sharing scheme for PHR data in cloud computing, which consists of two procedures: PHR data storage stage and PHR data sharing stage. To fulfill the automatic public verification, we resort to smart contracts in the proposed BC-PC-Share scheme. In addition, only the patient (i.e., the owner of the smart contract) can deploy the smart contracts on the blockchain, where the entire content of a contract is transparent to all participating nodes in the blockchain and each node can interact with the smart contract. It should be noted that all involved transactions below will automatically trigger the execution of the smart contracts if predefined conditions are satisfied. And the execution result of smart contracts is correct, immutable, and credible to all nodes as long as the security of the blockchain is guaranteed. In this sense, it cannot only achieve public verification, but also reduce the burden of data integrity and consistency checking for the patient and multiple data users.</p>
<p>&#x2022; PHR data storage stage</p>
<p>In the PHR data storage stage, we introduce a hash linked list to record the storage authentication information of each file in the blockchain and use &#x201C;link&#x201D; as a pointer to the head of the hash list for supporting scalable storage verification by utilizing the smart contract. Specifically, the patient (DO) can outsource their PHR data to the cloud server by performing the following seven steps, namely Signingkey Generation, Ciphertext Generation, Storage Authentication Generation, Storage Validation Request, Storage Verification, Block Generation, and Storage Confirm, respectively. Each of them is described in detail as follows:</p>
<p>(1) Signingkey Generation.</p>
<p>The data owner DO first runs <italic>SystemSetup</italic> algorithm of the PVOD-ABE to generate the system public parameters <italic>PP</italic>, and generates a random signing key pair (<inline-formula id="ieqn-110"><mml:math id="mml-ieqn-110"><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>O</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-111"><mml:math id="mml-ieqn-111"><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>O</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>).</p>
<p>(2) Ciphertext Generation.</p>
<p>Given a plaintext file <italic>m</italic>, the DO defines an access policy tree <italic>T</italic>, then generates the corresponding ciphertext <italic>CT</italic> by calling the <italic>Encrypt</italic> algorithm of the PVOD-ABE.</p>
<p>(3) Storage Authentication Generation.</p>
<p>The data owner DO calculates <inline-formula id="ieqn-112"><mml:math id="mml-ieqn-112"><mml:mi>R</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>C</mml:mi><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula id="ieqn-113"><mml:math id="mml-ieqn-113"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi>O</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>S</mml:mi><mml:mi>S</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>O</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>l</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mi>R</mml:mi><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo>,</mml:mo><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>O</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mi>p</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, and let <inline-formula id="ieqn-114"><mml:math id="mml-ieqn-114"><mml:mi>l</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>C</mml:mi><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo>,</mml:mo><mml:mi>I</mml:mi><mml:mi>D</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where the pointer <italic>prelink</italic> is pointed to the head of the previous linked hash list, which is introduced for facilitating retrieval of the storage authentication information of the entire user&#x2019;s data stored in the cloud server at different times by connecting them as a complete linked hash list. The pointer <italic>link</italic> is initially a fixed-length string (e.g., all &#x201C;1&#x201D; strings). <inline-formula id="ieqn-115"><mml:math id="mml-ieqn-115"><mml:mi>p</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> is the public key of the cloud server. <italic>time</italic> is a timestamp representing the signing time. <italic>ID</italic> is the block label for storing <inline-formula id="ieqn-116"><mml:math id="mml-ieqn-116"><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>C</mml:mi><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mo>,</mml:mo><mml:mi>p</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi></mml:math></inline-formula>. The data owner DO keeps the value of <italic>link</italic> locally. At last, the DO sends the ciphertext <italic>CT</italic> to the cloud server for storage and the corresponding storage authentication information <inline-formula id="ieqn-117"><mml:math id="mml-ieqn-117"><mml:mi>A</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi><mml:mi>h</mml:mi><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mn>1</mml:mn><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi>O</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>l</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mi>R</mml:mi><mml:mo>,</mml:mo><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>O</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mi>p</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> to the smart contracts, respectively.</p>
<p>(4) Storage Validation Request.</p>
<p>Upon receiving the ciphertext <italic>CT</italic>, the cloud server generates the storage validation request <inline-formula id="ieqn-118"><mml:math id="mml-ieqn-118"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:mi>S</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>C</mml:mi><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>C</mml:mi><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, and finally sends it to the smart contracts for storage validation verification.</p>
<p>(5) Storage Verification.</p>
<p>The storage validation request from the cloud server will automatically trigger the deployed smart contracts to execute the storage validation by determining whether <inline-formula id="ieqn-119"><mml:math id="mml-ieqn-119"><mml:msub><mml:mi>H</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>C</mml:mi><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>R</mml:mi></mml:math></inline-formula> holds or not. If it holds, the smart contracts confirm that the relevant PHRs information has been stored intact on the cloud server intactly, i.e., the storage verification is passed. Finally, the smart contracts send the storage authentication information <italic>Authen</italic>1 as a transaction to the blockchain.</p>
<p>(6) Block Generation.</p>
<p>The consensus nodes in the blockchain perform the consensus algorithm (e.g., PBFT) to verify the transaction and generate a valid block linked to the blockchain and return the block ID to the data owner DO and the cloud server, respectively.</p>
<p>(7) Storage Confirm.</p>
<p>According to the information of the returned block ID, the data owner DO can confirm his/her data has been stored in integrity in the cloud server.</p>
<p>&#x2022; PHR data sharing stage</p>
<p>In the PHR data sharing stage, we leverage the blockchain to achieve a publicly verifiable data sharing scheme between the DO and the DU, i.e., the DU can verify the integrity and consistency of the shared PHR data. Specifically, the PHR data sharing stage is composed of six procedures, namely, Signingkey Generation, Sharing Request Generation, Sharing Request Authorization, PHR Transformation and Sharing, Transformation Verification and Block Generation, and Decryption, respectively. Each of them is described in detail as follows:</p>
<p>(1) Signingkey Generation.</p>
<p>The data user DU generates a random signing key pair (<inline-formula id="ieqn-120"><mml:math id="mml-ieqn-120"><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>U</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-121"><mml:math id="mml-ieqn-121"><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>U</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>).</p>
<p>(2) Sharing Request Generation.</p>
<p>The data user DU calculates <inline-formula id="ieqn-122"><mml:math id="mml-ieqn-122"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi>U</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>S</mml:mi><mml:mi>S</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>U</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>U</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mi>p</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> as a data sharing request and sends it to the data owner DO.</p>
<p>(3) Sharing Request Authorization.</p>
<p>After successful verification of <inline-formula id="ieqn-123"><mml:math id="mml-ieqn-123"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi>U</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, the DO firstly calculates <inline-formula id="ieqn-124"><mml:math id="mml-ieqn-124"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi>O</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mi>S</mml:mi><mml:mi>S</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>O</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi>U</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>l</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>p</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msup><mml:mrow><mml:mi>&#x03B1;</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mi>&#x03B2;</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, and calls the <italic>KeyGen</italic> algorithm of the PVOD-ABE to generate the cloud-assisted transformation key <italic>TK</italic> and the user decryption key <italic>UK</italic>, then sends <inline-formula id="ieqn-125"><mml:math id="mml-ieqn-125"><mml:mrow><mml:mo stretchy='false'>(</mml:mo><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>O</mml:mi></mml:msub><mml:mo>&#x0032;</mml:mo><mml:mo>&#x007C;</mml:mo><mml:mo>&#x007C;</mml:mo><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>U</mml:mi></mml:msub><mml:mo>&#x007C;</mml:mo><mml:mo>&#x007C;</mml:mo><mml:mi>T</mml:mi><mml:mi>K</mml:mi><mml:mo stretchy='false'>)</mml:mo></mml:mrow></mml:math></inline-formula> to the cloud server and <inline-formula id="ieqn-126"><mml:math id="mml-ieqn-126"><mml:mrow><mml:mo stretchy='false'>(</mml:mo><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>O</mml:mi></mml:msub><mml:mo>&#x2032;</mml:mo><mml:mo>&#x007C;</mml:mo><mml:mo>&#x007C;</mml:mo><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>U</mml:mi></mml:msub><mml:mo>&#x007C;</mml:mo><mml:mo>&#x007C;</mml:mo><mml:mi>U</mml:mi><mml:mi>K</mml:mi><mml:mo stretchy='false'>)</mml:mo></mml:mrow></mml:math></inline-formula> to the data user DU, respectively.</p>
<p>(4) PHR Transformation and Sharing.</p>
<p>Upon receiving the message <inline-formula id="ieqn-127"><mml:math id="mml-ieqn-127"><mml:mrow><mml:mo stretchy='false'>(</mml:mo><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>O</mml:mi><mml:mo>&#x0027;</mml:mo></mml:msubsup><mml:mo>&#x007C;</mml:mo><mml:mo>&#x007C;</mml:mo><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>U</mml:mi></mml:msub><mml:mo>&#x007C;</mml:mo><mml:mo>&#x007C;</mml:mo><mml:mi>T</mml:mi><mml:mi>K</mml:mi><mml:mo stretchy='false'>)</mml:mo></mml:mrow></mml:math></inline-formula> from the DO, the cloud server verifies its valid and whether <italic>period</italic> is within the validity period, the cloud server selects the corresponding ciphertext <inline-formula id="ieqn-128"><mml:math id="mml-ieqn-128"><mml:mi>C</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>C</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo></mml:math></inline-formula> <inline-formula id="ieqn-129"><mml:math id="mml-ieqn-129"><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> which satisfy the attribute set <inline-formula id="ieqn-130"><mml:math id="mml-ieqn-130"><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>U</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> of DU, and calls the <inline-formula id="ieqn-131"><mml:math id="mml-ieqn-131"><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>s</mml:mi><mml:mi>f</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> algorithm of the PVOD-ABE to transform the complicated ciphertext <inline-formula id="ieqn-132"><mml:math id="mml-ieqn-132"><mml:mi>C</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>C</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo></mml:math></inline-formula> <inline-formula id="ieqn-133"><mml:math id="mml-ieqn-133"><mml:mi>C</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> to a simplified ciphertext <inline-formula id="ieqn-134"><mml:math id="mml-ieqn-134"><mml:msup><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>C</mml:mi><mml:msup><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:msup><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:msup><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Thus, migrating the majority of the heavy computation costs of the DU to the cloud server and thus greatly reducing the decryption overhead of the DU. Next, the cloud server sends the transformation authentication information <inline-formula id="ieqn-135"><mml:math id="mml-ieqn-135"><mml:mrow><mml:mi>A</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi><mml:mi>h</mml:mi><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mn>2</mml:mn><mml:mo>=</mml:mo><mml:mi>S</mml:mi><mml:mi>S</mml:mi><mml:mi>i</mml:mi><mml:msub><mml:mi>g</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>C</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo stretchy='false'>(</mml:mo><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>O</mml:mi><mml:mo>&#x0027;</mml:mo></mml:msubsup><mml:mo>&#x007C;</mml:mo><mml:mo>&#x007C;</mml:mo><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>U</mml:mi></mml:msub><mml:mo>&#x007C;</mml:mo><mml:mo>&#x007C;</mml:mo><mml:mi>l</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>k</mml:mi><mml:mo>&#x007C;</mml:mo><mml:mo>&#x007C;</mml:mo><mml:msup><mml:mi>&#x03B1;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup><mml:mi>&#x03B2;</mml:mi><mml:mi>k</mml:mi><mml:mo>&#x007C;</mml:mo><mml:mo>&#x007C;</mml:mo><mml:mi>A</mml:mi><mml:mi>D</mml:mi><mml:mo stretchy='false'>(</mml:mo><mml:mi>C</mml:mi><mml:mo stretchy='false'>)</mml:mo><mml:mo>&#x007C;</mml:mo><mml:mo>&#x007C;</mml:mo><mml:mi>A</mml:mi><mml:mi>D</mml:mi><mml:mo stretchy='false'>(</mml:mo><mml:msup><mml:mi>C</mml:mi><mml:mo>&#x0027;</mml:mo></mml:msup><mml:mo stretchy='false'>)</mml:mo><mml:mo stretchy='false'>)</mml:mo></mml:mrow></mml:math></inline-formula> to the smart contracts for transform validation verification.</p>
<p>(5) PHRs Verification and Block Generation.</p>
<p>Since the cloud server is a semi-trusted third party and it may return tampered data to the data user, it is therefore essential to verify the integrity and consistency of the shared PHR information, i.e., the returned shared data should be consistent with the requested shared data and the integrity of the shared data is not tampered. Concretely, it will automatically trigger the deployed smart contracts to perform integrity and consistency verification of <inline-formula id="ieqn-136"><mml:math id="mml-ieqn-136"><mml:mi>C</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>C</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> by comparing the transformation authenticate information <italic>Authen</italic>2 with the hash value retrieved from the hash list pointed by the pointer <italic>link</italic> in blockchain. If the hash values retrieved from the blockchain is equal to the hash values sent by the cloud server in <italic>Authen</italic>2, it means that the validity of the transformed ciphertext given by the cloud server can be guaranteed. Then, the consensus nodes in the blockchain perform the consensus algorithm (e.g., PBFT) to verify the transaction and generate a valid block linked to the blockchain.</p>
<p>Subsequently, the smart contracts verify the validity of the outsourced decryption by checking whether <inline-formula id="ieqn-137"><mml:math id="mml-ieqn-137"><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>p</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:msup><mml:mrow><mml:mi>&#x03B1;</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mi>&#x03B2;</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> holds or not. If the equation holds, it means that the transformed ciphertext is valid. Then, the consensus nodes in the blockchain perform the consensus algorithm (e.g., PBFT) to verify the transaction and generate a valid block linked to the blockchain.</p>
<p>(6) Decryption.</p>
<p>After the above successful verification, the data user DU downloads the encrypted sharing data from the cloud server and decrypts the untampered encrypted PHRs data with the user decryption key <italic>UK</italic> obtained from the DO and get the plain PHRs data as follows: <inline-formula id="ieqn-138"><mml:math id="mml-ieqn-138"><mml:mi>K</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>p</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:msup><mml:mi>t</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msup></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mi>m</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x2295;</mml:mo><mml:mi>K</mml:mi></mml:math></inline-formula>. Otherwise, outputs &#x22A5;.</p>
</sec>
</sec>
<sec id="s6">
<label>6</label><title>Security Analysis</title>
<sec id="s6_1">
<label>6.1</label><title>Security Model</title>
<p>Prior to proving the security of the proposed scheme, we first describe the security model for our work, which is adapted from the security model of Lai et al. [<xref ref-type="bibr" rid="ref-39">39</xref>]. To formalize the security model, the adaptive Chosen Plaintext Attacks (CPA) security game between a challenger <inline-formula id="ieqn-139"><mml:math id="mml-ieqn-139"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> and an adversary <inline-formula id="ieqn-140"><mml:math id="mml-ieqn-140"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> is defined as follows:
<list list-type="bullet">
<list-item>
<p><bold>Setup.</bold> The challenger <inline-formula id="ieqn-141"><mml:math id="mml-ieqn-141"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> runs <italic>SystemSetup</italic> algorithm with the security parameter <italic>k</italic> and attribute universe <italic>U</italic> to generate the system public parameters <italic>PP</italic>, and returns them to the adversary <inline-formula id="ieqn-142"><mml:math id="mml-ieqn-142"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>.</p></list-item>
<list-item>
<p><bold>Query Phase I.</bold> The attacker <inline-formula id="ieqn-143"><mml:math id="mml-ieqn-143"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> adaptively issues the following queries:</p></list-item>
</list>
<list list-type="simple">
<list-item><p>&#x2013; <italic>TK</italic> query. Given an attribute set <italic>S</italic> from <inline-formula id="ieqn-144"><mml:math id="mml-ieqn-144"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>, the challenger <inline-formula id="ieqn-145"><mml:math id="mml-ieqn-145"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> runs <italic>KeyGen</italic> algorithm to generate the transformation key <italic>TK</italic> and returns it to the adversary <inline-formula id="ieqn-146"><mml:math id="mml-ieqn-146"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>.</p></list-item>
<list-item><p>&#x2013; <italic>UK</italic> query. Given an attribute set <italic>S</italic> from <inline-formula id="ieqn-147"><mml:math id="mml-ieqn-147"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>, the challenger <inline-formula id="ieqn-148"><mml:math id="mml-ieqn-148"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> runs <italic>KeyGen</italic> algorithm to generate the user decryption key <italic>UK</italic> and returns it to the adversary <inline-formula id="ieqn-149"><mml:math id="mml-ieqn-149"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>.</p></list-item>
<list-item><p>&#x2013; <inline-formula id="ieqn-150"><mml:math id="mml-ieqn-150"><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>s</mml:mi><mml:mi>f</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> query. Given a ciphertext <italic>CT</italic>, the challenger <inline-formula id="ieqn-151"><mml:math id="mml-ieqn-151"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> runs <inline-formula id="ieqn-152"><mml:math id="mml-ieqn-152"><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>s</mml:mi><mml:mi>f</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> algorithm to generate the transformed ciphertext <inline-formula id="ieqn-153"><mml:math id="mml-ieqn-153"><mml:mi>C</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula> and returns it to <inline-formula id="ieqn-154"><mml:math id="mml-ieqn-154"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>.</p></list-item>
</list>
<list list-type="bullet">
<list-item>
<p><bold>Challenge.</bold> Once <bold>Query Phase I</bold> is over, the attacker <inline-formula id="ieqn-155"><mml:math id="mml-ieqn-155"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> submits two messages <inline-formula id="ieqn-156"><mml:math id="mml-ieqn-156"><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-157"><mml:math id="mml-ieqn-157"><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> with equal length and one access structure <inline-formula id="ieqn-158"><mml:math id="mml-ieqn-158"><mml:mrow><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>, the challenger <inline-formula id="ieqn-159"><mml:math id="mml-ieqn-159"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> randomly selects <italic>b</italic> &#x2208; {0, 1}, then returns the challenge ciphertext <inline-formula id="ieqn-160"><mml:math id="mml-ieqn-160"><mml:mi>C</mml:mi><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:math></inline-formula> to the adversary <inline-formula id="ieqn-161"><mml:math id="mml-ieqn-161"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>.</p></list-item>
<list-item>
<p><bold>Query Phase II.</bold> The adversary <inline-formula id="ieqn-162"><mml:math id="mml-ieqn-162"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> continues to adaptively issue the queries in <bold>Query Phase I</bold> with the following two restrictions:</p></list-item>
</list>
<list list-type="simple">
<list-item><label>1)</label><p>The adversary <inline-formula id="ieqn-163"><mml:math id="mml-ieqn-163"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> cannot simultaneously make the <italic>TK</italic> Query and the <italic>UK</italic> Query on the attribute sets that satisfy the challenging access structures <inline-formula id="ieqn-164"><mml:math id="mml-ieqn-164"><mml:mrow><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>.</p></list-item>
<list-item><label>2)</label><p>If the adversary <inline-formula id="ieqn-165"><mml:math id="mml-ieqn-165"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> has made the <italic>TK</italic> Query, he/she cannot make the <italic>UK</italic> Query on the attribute sets that satisfy the challenging access structures <inline-formula id="ieqn-166"><mml:math id="mml-ieqn-166"><mml:mrow><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula> and vice versa.</p></list-item>
</list>
<list list-type="bullet">
<list-item>
<p><bold>Guess.</bold> At the end of the game, the adversary <inline-formula id="ieqn-167"><mml:math id="mml-ieqn-167"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> outputs a guess <italic>b</italic><sup><italic>&#x2032;</italic></sup> &#x2208; {0, 1} for <italic>b</italic> and the adversary <inline-formula id="ieqn-168"><mml:math id="mml-ieqn-168"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> succeeds in the security game if and only if <italic>b</italic><sup><italic>&#x2032;</italic></sup> &#x003D; <italic>b</italic>.</p></list-item>
</list></p>
</sec>
<sec id="s6_2">
<label>6.2</label><title>Security Proof</title>
<p>In this subsection, we discuss the security of the proposed BC-PC-Share scheme under the general assumptions and the random oracle model, including CPA security, completeness, and efficient user revocation.</p>
<fig id="fig-10">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_26321-fig-10.tif"/>
</fig>
<p><bold>Proof.</bold> Since our devised BC-PC-Share scheme is constructed on the basis of the aforementioned PVOD-ABE algorithm, the data confidentiality of the BC-PC-Share scheme is guaranteed by the PVOD-ABE scheme. The CPA security proof of the PVOD-ABE scheme is described as a security game between a challenger <inline-formula id="ieqn-169"><mml:math id="mml-ieqn-169"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> and an adversary <inline-formula id="ieqn-170"><mml:math id="mml-ieqn-170"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>. Given an instance of the DBDH problem <inline-formula id="ieqn-171"><mml:math id="mml-ieqn-171"><mml:mo stretchy="false">(</mml:mo><mml:mi>g</mml:mi><mml:mo>,</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo>,</mml:mo><mml:mi>R</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> randomly, the aim of the challenger <inline-formula id="ieqn-172"><mml:math id="mml-ieqn-172"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> is to decide if <inline-formula id="ieqn-173"><mml:math id="mml-ieqn-173"><mml:mi>R</mml:mi><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>g</mml:mi><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:msup><mml:mrow><mml:mi>a</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula> holds or not. The specific processes of the security game are as follows:
<list list-type="bullet">
<list-item>
<p><bold>Setup.</bold> The challenger <inline-formula id="ieqn-174"><mml:math id="mml-ieqn-174"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> performs the Setup algorithm and returns the relevant system global parameters to the adversary <inline-formula id="ieqn-175"><mml:math id="mml-ieqn-175"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>as follows:</p></list-item>
</list>
<list list-type="simple">
<list-item><label>(1)</label><p>The challenger <inline-formula id="ieqn-176"><mml:math id="mml-ieqn-176"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> firstly defines two secure one-way hash functions: <inline-formula id="ieqn-177"><mml:math id="mml-ieqn-177"><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03C9;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:msup><mml:mrow><mml:msub><mml:mrow><mml:mtext>g</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>&#x03C9;</mml:mi></mml:mrow></mml:msup><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>r</mml:mi></mml:mrow><mml:mrow><mml:mi>&#x03C9;</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>, where <inline-formula id="ieqn-178"><mml:math id="mml-ieqn-178"><mml:mrow><mml:msub><mml:mrow><mml:mi>r</mml:mi></mml:mrow><mml:mrow><mml:mi>&#x03C9;</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mo>&#x2208;</mml:mo></mml:mrow><mml:mrow><mml:mi>R</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:msubsup><mml:mi>Z</mml:mi><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup></mml:math></inline-formula>, and <inline-formula id="ieqn-179"><mml:math id="mml-ieqn-179"><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>R</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>K</mml:mi></mml:math></inline-formula>, where <inline-formula id="ieqn-180"><mml:math id="mml-ieqn-180"><mml:mi>K</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mo>&#x2208;</mml:mo></mml:mrow><mml:mrow><mml:mi>R</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:msup><mml:mrow><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>.</p></list-item>
<list-item><label>(2)</label><p>The challenger <inline-formula id="ieqn-181"><mml:math id="mml-ieqn-181"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> chooses two random numbers <inline-formula id="ieqn-182"><mml:math id="mml-ieqn-182"><mml:mi>r</mml:mi><mml:mo>,</mml:mo><mml:mi>v</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup></mml:math></inline-formula>, and returns the system global parameters to the adversary <inline-formula id="ieqn-183"><mml:math id="mml-ieqn-183"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>.</p></list-item>
<list-item><label>(3)</label><p>The challenger <inline-formula id="ieqn-184"><mml:math id="mml-ieqn-184"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> chooses two random numbers <inline-formula id="ieqn-185"><mml:math id="mml-ieqn-185"><mml:mi>r</mml:mi><mml:mo>,</mml:mo><mml:mi>v</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup></mml:math></inline-formula>, and returns the system global parameters <inline-formula id="ieqn-186"><mml:math id="mml-ieqn-186"><mml:mi>P</mml:mi><mml:mi>P</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi>g</mml:mi><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>v</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo>,</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> to the adversary <inline-formula id="ieqn-187"><mml:math id="mml-ieqn-187"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>. The adversary <inline-formula id="ieqn-188"><mml:math id="mml-ieqn-188"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> can only obtain the value of hash function by performing hash query. And <inline-formula id="ieqn-189"><mml:math id="mml-ieqn-189"><mml:mi>M</mml:mi><mml:mi>S</mml:mi><mml:mi>K</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>=</mml:mo><mml:mi>a</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03B2;</mml:mi><mml:mo>=</mml:mo><mml:mi>a</mml:mi><mml:mi>v</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> is the master secret key. In addition, the challenger <inline-formula id="ieqn-190"><mml:math id="mml-ieqn-190"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> maintains a list <italic>TKList</italic>, which is initially an empty list.</p></list-item>
</list>
<list list-type="bullet">
<list-item>
<p><bold>Query Phase I.</bold> The adversary <inline-formula id="ieqn-191"><mml:math id="mml-ieqn-191"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> initiates a series of queries as follows:</p></list-item>
</list>
<list list-type="simple">
<list-item><p>&#x2013; <italic>TK</italic> Query: The adversary <inline-formula id="ieqn-192"><mml:math id="mml-ieqn-192"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> submits an attribute set <italic>S</italic> to the challenger <inline-formula id="ieqn-193"><mml:math id="mml-ieqn-193"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula>. If the adversary <inline-formula id="ieqn-194"><mml:math id="mml-ieqn-194"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> has been queried the cloud-assisted transformation key <italic>TK</italic> before, then <inline-formula id="ieqn-195"><mml:math id="mml-ieqn-195"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> returns the previous <italic>TK</italic>. Otherwise, the challenger <inline-formula id="ieqn-196"><mml:math id="mml-ieqn-196"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> returns the cloud-assisted transformation key as follows:</p></list-item>
</list>
<list list-type="simple">
<list-item><label>(1)</label><p>The challenger <inline-formula id="ieqn-197"><mml:math id="mml-ieqn-197"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula>picks <inline-formula id="ieqn-198"><mml:math id="mml-ieqn-198"><mml:msup><mml:mrow><mml:mi>d</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>k</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mo>&#x2208;</mml:mo></mml:mrow><mml:mrow><mml:mi>R</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:msubsup><mml:mi>Z</mml:mi><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup></mml:math></inline-formula>.</p></list-item>
<list-item><label>(2)</label><p>The challenger <inline-formula id="ieqn-199"><mml:math id="mml-ieqn-199"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> randomly chooses a number <inline-formula id="ieqn-200"><mml:math id="mml-ieqn-200"><mml:mrow><mml:msub><mml:mrow><mml:mi>u</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup></mml:math></inline-formula> for each attribute <italic>i</italic> &#x2208; <italic>S</italic>, and computes <inline-formula id="ieqn-201"><mml:math id="mml-ieqn-201"><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>K</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>K</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>K</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-202"><mml:math id="mml-ieqn-202"><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>K</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>+</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msubsup><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>&#x03C9;</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>u</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-203"><mml:math id="mml-ieqn-203"><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>K</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>u</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>.</p></list-item>
<list-item><label>(3)</label><p>The challenger <inline-formula id="ieqn-204"><mml:math id="mml-ieqn-204"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> returns <inline-formula id="ieqn-205"><mml:math id="mml-ieqn-205"><mml:mi>T</mml:mi><mml:mi>K</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>T</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>K</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>S</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>v</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mrow><mml:msup><mml:mrow><mml:mi>d</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msup></mml:mrow><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>t</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>v</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo>,</mml:mo><mml:mi>v</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> to the adversary <inline-formula id="ieqn-206"><mml:math id="mml-ieqn-206"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>and adds tuple (<italic>TK</italic>,<italic>UK</italic>) to the list <italic>TKList</italic>.</p></list-item>
</list>
<list list-type="simple">
<list-item><p>&#x2013; <italic>UK</italic> Query. The adversary <inline-formula id="ieqn-207"><mml:math id="mml-ieqn-207"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> submits an attribute set <italic>S</italic> to the challenger <inline-formula id="ieqn-208"><mml:math id="mml-ieqn-208"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula>. If the adversary <inline-formula id="ieqn-209"><mml:math id="mml-ieqn-209"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> has been queried for the user decryption key <italic>UK</italic> before, then <inline-formula id="ieqn-210"><mml:math id="mml-ieqn-210"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> returns the previous <italic>UK</italic>, otherwise, the challenger <inline-formula id="ieqn-211"><mml:math id="mml-ieqn-211"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> makes <italic>TK</italic> Query to get <italic>TK</italic> and <italic>UK</italic>, and finally returns the <italic>UK</italic>.</p></list-item>
<list-item><p>&#x2013; <inline-formula id="ieqn-212"><mml:math id="mml-ieqn-212"><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>s</mml:mi><mml:mi>f</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> Query. In this phase, <inline-formula id="ieqn-213"><mml:math id="mml-ieqn-213"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> runs the <inline-formula id="ieqn-214"><mml:math id="mml-ieqn-214"><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>s</mml:mi><mml:mi>f</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>P</mml:mi><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:mi>T</mml:mi><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mi>K</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mi>C</mml:mi><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msup></mml:math></inline-formula> algorithm to transform the complicated ciphertext <italic>CT</italic> to a simplified ciphertext <italic>CT</italic><sup><italic>&#x2032;</italic></sup> by leveraging the cloud-assisted transformation key <italic>TK</italic> obtained in <italic>TK</italic> Query.</p></list-item>
</list>
<list list-type="bullet">
<list-item>
<p><bold>Challenge.</bold> The adversary <inline-formula id="ieqn-215"><mml:math id="mml-ieqn-215"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> submits two messages <inline-formula id="ieqn-216"><mml:math id="mml-ieqn-216"><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-217"><mml:math id="mml-ieqn-217"><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> with the same length and an access policy tree <inline-formula id="ieqn-218"><mml:math id="mml-ieqn-218"><mml:mrow><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula> to the challenger <inline-formula id="ieqn-219"><mml:math id="mml-ieqn-219"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula>. The challenger <inline-formula id="ieqn-220"><mml:math id="mml-ieqn-220"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> randomly picks a bit <italic>coin</italic> &#x2208;{0, 1}, and responds to the challenging ciphertext <inline-formula id="ieqn-221"><mml:math id="mml-ieqn-221"><mml:mi>C</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula> as follows:</p></list-item>
</list>
<list list-type="simple">
<list-item><label>1)</label><p>Let <inline-formula id="ieqn-222"><mml:math id="mml-ieqn-222"><mml:mrow><mml:msub><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>r</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>, where the node <italic>root</italic> is the root node of <inline-formula id="ieqn-223"><mml:math id="mml-ieqn-223"><mml:mrow><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>, and compute <inline-formula id="ieqn-224"><mml:math id="mml-ieqn-224"><mml:mrow><mml:msub><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> for each leaf node <italic>x</italic> by using the first step in <italic>Encrypt</italic>(<italic>PP</italic>, <italic>T</italic>, <italic>M</italic>) &#x2192; <italic>CT</italic> algorithm of the PVOD-ABE.</p></list-item>
<list-item><label>2)</label><p>Compute <inline-formula id="ieqn-225"><mml:math id="mml-ieqn-225"><mml:msubsup><mml:mi>C</mml:mi><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>C</mml:mi><mml:mrow><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msubsup><mml:mi>C</mml:mi><mml:mrow><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mn>2</mml:mn></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> for each leaf node <italic>x</italic>, where <inline-formula id="ieqn-226"><mml:math id="mml-ieqn-226"><mml:msubsup><mml:mi>C</mml:mi><mml:mrow><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-227"><mml:math id="mml-ieqn-227"><mml:msubsup><mml:mi>C</mml:mi><mml:mrow><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mn>2</mml:mn></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mrow><mml:msubsup><mml:mrow><mml:mi>r</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>q</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>, and <inline-formula id="ieqn-228"><mml:math id="mml-ieqn-228"><mml:mrow><mml:msubsup><mml:mrow><mml:mi>r</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup></mml:mrow></mml:math></inline-formula> can be obtained by making queries <inline-formula id="ieqn-229"><mml:math id="mml-ieqn-229"><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>&#x03C9;</mml:mi><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Here, <inline-formula id="ieqn-230"><mml:math id="mml-ieqn-230"><mml:msubsup><mml:mi>&#x03C9;</mml:mi><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>t</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Let <inline-formula id="ieqn-231"><mml:math id="mml-ieqn-231"><mml:mrow><mml:msup><mml:mrow><mml:mi>S</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula> denote the set of leaf nodes in the access tree <inline-formula id="ieqn-232"><mml:math id="mml-ieqn-232"><mml:mrow><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>.</p></list-item>
<list-item><label>3)</label><p>Compute <inline-formula id="ieqn-233"><mml:math id="mml-ieqn-233"><mml:msubsup><mml:mi>C</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x2295;</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>H</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>R</mml:mi></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>r</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:msubsup><mml:mi>C</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>v</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>r</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msup></mml:mrow><mml:mo>=</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>3</mml:mn></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>r</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msubsup></mml:math></inline-formula>.</p></list-item>
<list-item><label>4)</label><p>Return <inline-formula id="ieqn-234"><mml:math id="mml-ieqn-234"><mml:mi>C</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow><mml:mo>,</mml:mo><mml:msubsup><mml:mi>C</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msubsup><mml:mi>C</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msubsup><mml:mi>C</mml:mi><mml:mrow><mml:mi>x</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msubsup><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow><mml:mrow><mml:mi>x</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>S</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> to the adversary <inline-formula id="ieqn-235"><mml:math id="mml-ieqn-235"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>.</p></list-item>
</list></p>
<p>Note that the adversary <inline-formula id="ieqn-236"><mml:math id="mml-ieqn-236"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> cannot simultaneously make the <italic>TK</italic> Query and the <italic>UK</italic> Query on the attribute sets that satisfy the challenging access structures <inline-formula id="ieqn-237"><mml:math id="mml-ieqn-237"><mml:mrow><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>.
<list list-type="bullet">
<list-item>
<p><bold>Query Phase II.</bold> The adversary <inline-formula id="ieqn-238"><mml:math id="mml-ieqn-238"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> still can launch the queries adaptively as <bold>Query Phase I</bold> except for the two queries below:</p></list-item>
</list>
<list list-type="simple">
<list-item><label>1)</label><p>The adversary <inline-formula id="ieqn-239"><mml:math id="mml-ieqn-239"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> cannot simultaneously make the <italic>TK</italic> Query and the <italic>UK</italic> Query on the attribute sets that satisfy the challenging access structures <inline-formula id="ieqn-240"><mml:math id="mml-ieqn-240"><mml:mrow><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>.</p></list-item>
<list-item><label>2)</label><p>If the adversary <inline-formula id="ieqn-241"><mml:math id="mml-ieqn-241"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> has made the <italic>TK</italic> Query, he/she cannot make the <italic>UK</italic> Query on the attribute sets that satisfy the challenging access structures <inline-formula id="ieqn-242"><mml:math id="mml-ieqn-242"><mml:mrow><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula> and vice versa.</p></list-item>
</list>
<list list-type="bullet">
<list-item>
<p><bold>Guess.</bold> Finally, the adversary <inline-formula id="ieqn-243"><mml:math id="mml-ieqn-243"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> outputs a guess <italic>coin</italic><sup><italic>&#x2032;</italic></sup> for <italic>coin</italic>. If <italic>coin</italic><sup><italic>&#x2032;</italic></sup> &#x003D; <italic>coin</italic> holds, the challenger <inline-formula id="ieqn-244"><mml:math id="mml-ieqn-244"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> outputs &#x201C;1&#x201D;, otherwise, outputs &#x201C;0&#x201D;.</p></list-item>
</list></p>
<p>According to the <italic>UserDecrypt</italic> algorithm, it is easy to get <inline-formula id="ieqn-245"><mml:math id="mml-ieqn-245"><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>p</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mrow><mml:msup><mml:mrow><mml:mi>g</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>r</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, that is, if <inline-formula id="ieqn-246"><mml:math id="mml-ieqn-246"><mml:mi>R</mml:mi><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>g</mml:mi><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:msup><mml:mrow><mml:mi>a</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula>, the <inline-formula id="ieqn-247"><mml:math id="mml-ieqn-247"><mml:mi>C</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula> is the valid ciphertext of <inline-formula id="ieqn-248"><mml:math id="mml-ieqn-248"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, therefore, based on the response from the adversary <inline-formula id="ieqn-249"><mml:math id="mml-ieqn-249"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula>, the challenger <inline-formula id="ieqn-250"><mml:math id="mml-ieqn-250"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> can determine whether <inline-formula id="ieqn-251"><mml:math id="mml-ieqn-251"><mml:mi>R</mml:mi><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>g</mml:mi><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:msup><mml:mrow><mml:mi>a</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula> holds or not.</p>
<p>Additionally, there is no failure case in the security game, therefore, if <inline-formula id="ieqn-252"><mml:math id="mml-ieqn-252"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> can break the proposed scheme with non-negligible probability <inline-formula id="ieqn-253"><mml:math id="mml-ieqn-253"><mml:mi>&#x03B5;</mml:mi></mml:math></inline-formula>, we can conclude that <inline-formula id="ieqn-254"><mml:math id="mml-ieqn-254"><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow></mml:math></inline-formula> can also decide if <inline-formula id="ieqn-255"><mml:math id="mml-ieqn-255"><mml:mi>R</mml:mi><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>g</mml:mi><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:msup><mml:mrow><mml:mi>a</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula> holds or not with the same non-negligible probability <inline-formula id="ieqn-256"><mml:math id="mml-ieqn-256"><mml:mi>&#x03B5;</mml:mi></mml:math></inline-formula>. In other words, DBDHP could be solved. However, it is a paradox to the well accepted DBDH problem. Therefore, the advantage of adversary <inline-formula id="ieqn-257"><mml:math id="mml-ieqn-257"><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow></mml:math></inline-formula> breaking the proposed scheme is negligible and our scheme achieves CPA security.</p>
<fig id="fig-11">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_26321-fig-11.tif"/>
</fig>
<p><bold>Proof.</bold> According to the traceability and immutability properties of the blockchain, the integrity and consistency of the shared data in our scheme can be guaranteed. During the data sharing process, the deployed smart contracts compare the hash value of ciphertext <italic>CT</italic> returned by the cloud server in transformation authenticate information <italic>Authen</italic>2 with the hash value retrieved from the hash list pointed by the pointer <italic>link</italic> in blockchain to verify the integrity and consistency of the shared data. If the above two hash values are equal, it can ensure that the returned shared data is consistent with the requested shared data and the integrity of the shared data is not compromised. In addition, the smart contracts verify the validation of the transformed ciphertext by checking whether the equation <inline-formula id="ieqn-258"><mml:math id="mml-ieqn-258"><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>m</mml:mi><mml:mrow><mml:msup><mml:mrow><mml:mi>p</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:msup><mml:mrow><mml:mi>&#x03B1;</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mi>&#x03B2;</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>C</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> holds or not. Therefore, our scheme can satisfy the property of completeness.</p>
<fig id="fig-12">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_26321-fig-12.tif"/>
</fig>
<p><bold>Proof.</bold> Assume that the cloud server does not collusion with the data user DU, the cloud server will provide the cloud-assisted transformation service of the ciphertext of the data owner DU within the valid period. In other words, according to the proof of Theorem 6.1, if the data owner DU is not within the valid period, even if the data user DU has made the <italic>UK</italic> Query and obtained the user decryption key <italic>UK</italic>, he/she is forbidden to launch the <inline-formula id="ieqn-259"><mml:math id="mml-ieqn-259"><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>s</mml:mi><mml:mi>f</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> Query either, thereby ensuring that the data user DU who is not within the valid period cannot obtain the desired data. In this sense, our scheme realizes the user revocation. In addition, different from most of the existing user revocation schemes, our scheme does not require the system to perform the complicated ciphertext re-encryption and key update operations. Therefore, the proposed BC-PC-Share scheme can achieve the property of efficient key revocation.</p>
</sec>
</sec>
<sec id="s7">
<label>7</label><title>Performance Evaluation</title>
<p>In this section, we provide the performance evaluation of our proposed BC-PC-Share scheme <italic>vs</italic>. three existing relevant attribute-based data sharing schemes proposed in [<xref ref-type="bibr" rid="ref-19">19</xref>,<xref ref-type="bibr" rid="ref-40">40</xref>,<xref ref-type="bibr" rid="ref-41">41</xref>]. The concrete comparison is divided into three terms. Firstly, we make a comparison of the security properties among the proposed BC-PC-Share scheme and that of schemes in [<xref ref-type="bibr" rid="ref-19">19</xref>,<xref ref-type="bibr" rid="ref-40">40</xref>,<xref ref-type="bibr" rid="ref-41">41</xref>]. Secondly, the complexity analyses in terms of computation cost and storage overhead are presented. Thirdly, we perform the efficiency analysis by a numerical simulation experiment.</p>
<sec id="s7_1">
<label>7.1</label><title>Comparison of Properties</title>
<p>In this subsection, we make a comparison of the security properties among the proposed BC-PC-Share scheme and that of schemes in [<xref ref-type="bibr" rid="ref-19">19</xref>,<xref ref-type="bibr" rid="ref-40">40</xref>,<xref ref-type="bibr" rid="ref-41">41</xref>] in terms of the properties of access control, blockchain-based, sharing consistency, ciphertext transformation, and time-controlled access, and the comparison results are summarized in <xref ref-type="table" rid="table-1">Table 1</xref>. All the schemes in [<xref ref-type="bibr" rid="ref-19">19</xref>,<xref ref-type="bibr" rid="ref-40">40</xref>,<xref ref-type="bibr" rid="ref-41">41</xref>] support the property of the fine-grained access control. In addition, the scheme in [<xref ref-type="bibr" rid="ref-40">40</xref>] can support the properties of the fine-grained access control, blockchain-based, and ciphertext transformation, but fails to support the properties of sharing consistency and time-controlled access. The scheme in [<xref ref-type="bibr" rid="ref-41">41</xref>] can support the properties of fine-grained access control and blockchain-based, but fails to support the properties of sharing consistency, ciphertext transformation, and time-controlled access. The comparison results in <xref ref-type="table" rid="table-1">Table 1</xref> validate that only the proposed BC-PC-Share scheme satisfies all the desired security features and is more promising and suitable for secure medical data sharing in multiple receiver scenarios.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption><title>Comparison of security properties</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Property</th>
<th>Scheme [<xref ref-type="bibr" rid="ref-19">19</xref>]</th>
<th>Scheme [<xref ref-type="bibr" rid="ref-40">40</xref>]</th>
<th>Scheme [<xref ref-type="bibr" rid="ref-41">41</xref>]</th>
<th>Ours</th>
</tr>
</thead>
<tbody>
<tr>
<td>Access control</td>
<td><italic><inline-formula id="ieqn-260"><mml:math id="mml-ieqn-260"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></italic></td>
<td><inline-formula id="ieqn-261"><mml:math id="mml-ieqn-261"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-262"><mml:math id="mml-ieqn-262"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-263"><mml:math id="mml-ieqn-263"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td>Blockchain-based</td>
<td><inline-formula id="ieqn-264"><mml:math id="mml-ieqn-264"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-265"><mml:math id="mml-ieqn-265"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-266"><mml:math id="mml-ieqn-266"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-267"><mml:math id="mml-ieqn-267"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td>Sharing public verification</td>
<td><inline-formula id="ieqn-268"><mml:math id="mml-ieqn-268"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-269"><mml:math id="mml-ieqn-269"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-270"><mml:math id="mml-ieqn-270"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-271"><mml:math id="mml-ieqn-271"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td>Ciphertext transformation</td>
<td><inline-formula id="ieqn-272"><mml:math id="mml-ieqn-272"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-273"><mml:math id="mml-ieqn-273"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-274"><mml:math id="mml-ieqn-274"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-275"><mml:math id="mml-ieqn-275"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td>Time-controlled access</td>
<td><inline-formula id="ieqn-276"><mml:math id="mml-ieqn-276"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-277"><mml:math id="mml-ieqn-277"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-278"><mml:math id="mml-ieqn-278"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-279"><mml:math id="mml-ieqn-279"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
<table-wrap-foot><fn>
<p>Note: <italic><inline-formula id="ieqn-280"><mml:math id="mml-ieqn-280"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></italic>: denotes that the specified scheme satisfy the corresponding property; <inline-formula id="ieqn-281"><mml:math id="mml-ieqn-281"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula>: denotes that the specified scheme does not satisfy the corresponding property.</p>
</fn>
</table-wrap-foot>
</table-wrap>
</sec>
<sec id="s7_2">
<label>7.2</label><title>Complexity Analysis</title>
<p>In this subsection, we perform the comparison in terms of computation cost and communication overhead, respectively. For the sake of the comparison, the notations and their meanings used in this subsection are summarized in <xref ref-type="table" rid="table-2">Table 2</xref>.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption><title>Notations and their meanings</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Notation</th>
<th>Meaning</th>
</tr>
</thead>
<tbody>
<tr>
<td><inline-formula id="ieqn-282"><mml:math id="mml-ieqn-282"><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>i</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td>The computational cost of one bilinear pairing operation</td>
</tr>
<tr>
<td><inline-formula id="ieqn-283"><mml:math id="mml-ieqn-283"><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td>The computational cost of one group exponentiation operation in <inline-formula id="ieqn-284"><mml:math id="mml-ieqn-284"><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-285"><mml:math id="mml-ieqn-285"><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td>The computational cost of one group multiplication operation in <inline-formula id="ieqn-286"><mml:math id="mml-ieqn-286"><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-287"><mml:math id="mml-ieqn-287"><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td>The computational cost of one group inverse operation in <inline-formula id="ieqn-288"><mml:math id="mml-ieqn-288"><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-289"><mml:math id="mml-ieqn-289"><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>h</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td>The computational cost of one general one-way hash function operation</td>
</tr>
<tr>
<td><inline-formula id="ieqn-290"><mml:math id="mml-ieqn-290"><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td>The number of attributes involved in the access policy</td>
</tr>
<tr>
<td><inline-formula id="ieqn-291"><mml:math id="mml-ieqn-291"><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td>The number of attributes involved in the user decryption key</td>
</tr>
<tr>
<td><italic>k</italic></td>
<td>The size of hash function</td>
</tr>
<tr>
<td><inline-formula id="ieqn-292"><mml:math id="mml-ieqn-292"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>Z</mml:mi></mml:mrow><mml:mrow><mml:mi>q</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td>The size of an element of <inline-formula id="ieqn-293"><mml:math id="mml-ieqn-293"><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>/<inline-formula id="ieqn-294"><mml:math id="mml-ieqn-294"><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>/<inline-formula id="ieqn-295"><mml:math id="mml-ieqn-295"><mml:mrow><mml:msub><mml:mrow><mml:mi>Z</mml:mi></mml:mrow><mml:mrow><mml:mi>q</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="table" rid="table-3">Table 3</xref> gives the comparison of the computation cost between the proposed BC-PC-Share scheme with the existing schemes in [<xref ref-type="bibr" rid="ref-19">19</xref>,<xref ref-type="bibr" rid="ref-40">40</xref>,<xref ref-type="bibr" rid="ref-41">41</xref>] and the comparison of communication overhead among them is briefly presented in <xref ref-type="table" rid="table-4">Table 4</xref>.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption><title>Comparison of computation cost</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Algorithm</th>
<th>Scheme [<xref ref-type="bibr" rid="ref-19">19</xref>]</th>
<th>Scheme [<xref ref-type="bibr" rid="ref-40">40</xref>]</th>
<th>Scheme [<xref ref-type="bibr" rid="ref-41">41</xref>]</th>
<th>Ours</th>
</tr>
</thead>
<tbody>
<tr>
<td>Encrypt</td>
<td><inline-formula id="ieqn-296"><mml:math id="mml-ieqn-296"><mml:mo stretchy="false">(</mml:mo><mml:mn>12</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>6</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>h</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-297"><mml:math id="mml-ieqn-297"><mml:mo stretchy="false">(</mml:mo><mml:mn>3</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:msub><mml:mi>T</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:msub><mml:mi>T</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>h</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-298"><mml:math id="mml-ieqn-298"><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:msub><mml:mi>T</mml:mi><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>h</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-299"><mml:math id="mml-ieqn-299"><mml:mo stretchy="false">(</mml:mo><mml:mn>3</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>h</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-300"><mml:math id="mml-ieqn-300"><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>s</mml:mi><mml:mi>f</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-301"><mml:math id="mml-ieqn-301"><mml:mo stretchy="false">(</mml:mo><mml:mn>4</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>i</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mn>2</mml:mn><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>z</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>T</mml:mi></mml:mrow></mml:munder><mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>d</mml:mi></mml:mrow><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>h</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-302"><mml:math id="mml-ieqn-302"><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>i</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>z</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>T</mml:mi></mml:mrow></mml:munder><mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>d</mml:mi></mml:mrow><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td>None</td>
<td><inline-formula id="ieqn-303"><mml:math id="mml-ieqn-303"><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>i</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>z</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>T</mml:mi></mml:mrow></mml:munder><mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>d</mml:mi></mml:mrow><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
</tr>
<tr>
<td>UserDecrypt</td>
<td><inline-formula id="ieqn-304"><mml:math id="mml-ieqn-304"><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>i</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>h</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-305"><mml:math id="mml-ieqn-305"><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>h</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-306"><mml:math id="mml-ieqn-306"><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>i</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>z</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>T</mml:mi></mml:mrow></mml:munder><mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>d</mml:mi></mml:mrow><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>v</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>h</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>h</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-307"><mml:math id="mml-ieqn-307"><mml:mn>1</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>u</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-4">
<label>Table 4</label>
<caption><title>Comparison of communication overhead</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Length</th>
<th>Scheme [<xref ref-type="bibr" rid="ref-19">19</xref>]</th>
<th>Scheme [<xref ref-type="bibr" rid="ref-40">40</xref>]</th>
<th>Scheme [<xref ref-type="bibr" rid="ref-41">41</xref>]</th>
<th>Ours</th>
</tr>
</thead>
<tbody>
<tr>
<td>CT</td>
<td><inline-formula id="ieqn-308"><mml:math id="mml-ieqn-308"><mml:mo stretchy="false">(</mml:mo><mml:mn>4</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-309"><mml:math id="mml-ieqn-309"><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-310"><mml:math id="mml-ieqn-310"><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-311"><mml:math id="mml-ieqn-311"><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>k</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td>TK</td>
<td><inline-formula id="ieqn-312"><mml:math id="mml-ieqn-312"><mml:mo stretchy="false">(</mml:mo><mml:mn>4</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-313"><mml:math id="mml-ieqn-313"><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td>None</td>
<td><inline-formula id="ieqn-314"><mml:math id="mml-ieqn-314"><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>Z</mml:mi></mml:mrow><mml:mrow><mml:mi>q</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></inline-formula></td>
</tr>
<tr>
<td>UK</td>
<td><inline-formula id="ieqn-315"><mml:math id="mml-ieqn-315"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>Z</mml:mi></mml:mrow><mml:mrow><mml:mi>q</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-316"><mml:math id="mml-ieqn-316"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>Z</mml:mi></mml:mrow><mml:mrow><mml:mi>q</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-317"><mml:math id="mml-ieqn-317"><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>G</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-318"><mml:math id="mml-ieqn-318"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi>Z</mml:mi></mml:mrow><mml:mrow><mml:mi>q</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap>
<p>From <xref ref-type="table" rid="table-3">Table 3</xref>, it can be observed that in the Encrypt phase, the computation cost on the data owner side in our scheme is much smaller than that of the schemes in [<xref ref-type="bibr" rid="ref-19">19</xref>,<xref ref-type="bibr" rid="ref-40">40</xref>]. And our scheme only adds one <inline-formula id="ieqn-319"><mml:math id="mml-ieqn-319"><mml:mrow><mml:msub><mml:mrow><mml:mi>T</mml:mi></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>p</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> compared with the scheme in [<xref ref-type="bibr" rid="ref-41">41</xref>]. In the phase of <inline-formula id="ieqn-320"><mml:math id="mml-ieqn-320"><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>s</mml:mi><mml:mi>f</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula>, the computation cost on the cloud server side in our scheme is much smaller than that of the scheme in [<xref ref-type="bibr" rid="ref-19">19</xref>], and is slightly higher than that of the scheme in [<xref ref-type="bibr" rid="ref-40">40</xref>] (i.e., more costly). In addition, as the scheme in [<xref ref-type="bibr" rid="ref-41">41</xref>] does not involve the <inline-formula id="ieqn-321"><mml:math id="mml-ieqn-321"><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>s</mml:mi><mml:mi>f</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:msub><mml:mrow><mml:mi>m</mml:mi></mml:mrow><mml:mrow><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> algorithm, its computation cost for the transform phase is represented as None. In the phase of UserDecrypt, the computation cost on the data user side of the schemes in [<xref ref-type="bibr" rid="ref-40">40</xref>] and ours is much smaller than that of the schemes in [<xref ref-type="bibr" rid="ref-19">19</xref>,<xref ref-type="bibr" rid="ref-41">41</xref>]. As presented in <xref ref-type="table" rid="table-4">Table 4</xref>, the size of the ciphertext, the transformation key, and the user decryption key in our scheme is relative smaller in overall compared with that of the schemes in [<xref ref-type="bibr" rid="ref-19">19</xref>,<xref ref-type="bibr" rid="ref-40">40</xref>,<xref ref-type="bibr" rid="ref-41">41</xref>].</p>

</sec>
<sec id="s7_3">
<label>7.3</label><title>Efficiency Analysis</title>
<p>The simulation experiment is implemented by a rapid cryptographic prototyping toolkit called Charm [<xref ref-type="bibr" rid="ref-42">42</xref>] with Python, and the operating system is Ubuntu 16.04 64-bit.</p>
<p>Note: considering that the specific implementation details of the blockchain may affect the efficiency of the scheme, but will not affect the security of the scheme, in our experiments, we do not simulate the operation of blockchain nodes. To deploy the scheme in specific blockchain application scenarios is our future research work. Besides, considering that the scheme in [<xref ref-type="bibr" rid="ref-19">19</xref>] is not based on blockchain, here, we only make simulation comparison of the three blockchain-based schemes of [<xref ref-type="bibr" rid="ref-40">40</xref>,<xref ref-type="bibr" rid="ref-41">41</xref>] and ours in terms of encryption time, transformation time and user decryption time.</p>
<p>A comparative study of the execution time of encryption phase, transformation phase, and userdecryption phase among the schemes in [<xref ref-type="bibr" rid="ref-40">40</xref>,<xref ref-type="bibr" rid="ref-41">41</xref>] and ours has been depicted in <xref ref-type="fig" rid="fig-3">Figs. 3</xref>&#x2013;<xref ref-type="fig" rid="fig-5">5</xref>, respectively.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption><title>Comparison of encryption time</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_26321-fig-3.tif"/>
</fig><fig id="fig-4">
<label>Figure 4</label>
<caption><title>Comparison of transformation time</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_26321-fig-4.tif"/>
</fig><fig id="fig-5">
<label>Figure 5</label>
<caption><title>Comparison of userdecryption time</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_26321-fig-5.tif"/>
</fig>
<p><xref ref-type="fig" rid="fig-3">Fig. 3</xref> illustrates the comparison of computation cost in the encryption phase. The change trend of computation cost in all the three schemes, [<xref ref-type="bibr" rid="ref-40">40</xref>,<xref ref-type="bibr" rid="ref-41">41</xref>] and ours, grows linearly with the number of attributes involved in the access policy. In addition, it is also can be seen that, with the amount of attributes involved in the access policy, the computation cost of scheme [<xref ref-type="bibr" rid="ref-40">40</xref>] is more costly than that of scheme [<xref ref-type="bibr" rid="ref-41">41</xref>] and ours. And the computation cost of scheme [<xref ref-type="bibr" rid="ref-41">41</xref>] is roughly equivalent with ours, and they both keep at a relatively low level.</p>

<p><xref ref-type="fig" rid="fig-4">Fig. 4</xref> illustrates the comparison of computation cost in the transformation phase, and it is not surprising to observe that the change trend of computational cost in scheme [<xref ref-type="bibr" rid="ref-41">41</xref>] grows linearly with the amount of attributes involved in the access policy, while it is constant in scheme [<xref ref-type="bibr" rid="ref-40">40</xref>] and ours because the transformation time in scheme [<xref ref-type="bibr" rid="ref-40">40</xref>] and ours does not grow with the number of attributes.</p>
<p><xref ref-type="fig" rid="fig-5">Fig. 5</xref> shows that the change trend of the computation cost in the userdecryption phase, and the change trend of the scheme in [<xref ref-type="bibr" rid="ref-40">40</xref>] and ours grows linearly with the number of attributes and only with a minor gap. Although the computation cost in our scheme is slightly higher than that of the scheme in [<xref ref-type="bibr" rid="ref-40">40</xref>], the former can support the public verification of the integrity and consistency of the shared data, and the latter cannot. Thus, our scheme is more promising and more practical than others.</p>
</sec>
</sec>
<sec id="s8">
<label>8</label><title>Conclusion</title>
<p>In this paper, we investigated the security issues of PHR data sharing and devised a system paradigm of the combination of cloud computing and consortium blockchain technology and proposed a feasible and promising solution to enhance the trustworthiness of each entity and fulfilled public verifiability, consistency, immutability, scalability and fine-grained PHR sharing in a multi-receiver setting. In addition, our scheme can achieve efficient user revocation and user decryption. The security analysis and simulation experiments conducted in this study demonstrated the security, scalability, and efficiency of the proposed BC-PC-Share scheme.</p>
</sec>
</body>
<back>
<ack>
<p>The authors are very grateful to the editors and reviewers for their constructive feedback and insightful suggestions.</p>
</ack>
<sec><title>Funding Statement</title>
<p>This work was supported by the <funding-source>Youth Doctoral Foundation of Gansu Education Committee</funding-source> under Grant No. <award-id>2022QB-176</award-id>.</p>
</sec>
<sec sec-type="COI-statement"><title>Conflicts of Interest</title>
<p>The authors declare that they have no conflicts of interest to report regarding the present study.</p>
</sec>
<ref-list content-type="authoryear"><title>References</title>
<ref id="ref-1"><label>1.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tang</surname>, <given-names>P. C.</given-names></string-name>, <string-name><surname>Ash</surname>, <given-names>J. S.</given-names></string-name>, <string-name><surname>Bates</surname>, <given-names>D. W.</given-names></string-name>, <string-name><surname>Overhage</surname>, <given-names>J. M.</given-names></string-name>, <string-name><surname>Sands</surname>, <given-names>D. Z.</given-names></string-name></person-group> (<year>2006</year>). <article-title>Personal health records: Definitions, benefits, and strategies for overcoming barriers to adoption</article-title>. <source>Journal of the American Medical Informatics Association</source><italic>,</italic> <volume>13</volume><italic>(</italic><issue>2</issue><italic>),</italic> <fpage>121</fpage>&#x2013;<lpage>126</lpage>. <pub-id pub-id-type="doi">10.1197/jamia.M2025</pub-id>; <pub-id pub-id-type="pmid">16357345</pub-id></mixed-citation></ref>
<ref id="ref-2"><label>2.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hylock</surname>, <given-names>R. H.</given-names></string-name>, <string-name><surname>Zeng</surname>, <given-names>X.</given-names></string-name></person-group> (<year>2019</year>). <article-title>A blockchain framework for patient-centered health records and exchange (healthchain): Evaluation and proof-of-concept study</article-title>. <source>Journal of Medical Internet Research</source><italic>,</italic> <volume>21</volume><italic>(</italic><issue>8</issue><italic>),</italic> <fpage>e13592</fpage>. <pub-id pub-id-type="doi">10.2196/13592</pub-id>; <pub-id pub-id-type="pmid">31471959</pub-id></mixed-citation></ref>
<ref id="ref-3"><label>3.</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Mell</surname>, <given-names>P.</given-names></string-name>, <string-name><surname>Grance</surname>, <given-names>T.</given-names></string-name></person-group> (<year>2011</year>). <article-title>The NIST definition of cloud computing</article-title>. <ext-link ext-link-type="uri" xlink:href="http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-145.pdf">http://nvlpubs.nist.gov/nistpubs/</ext-link> <ext-link ext-link-type="uri" xlink:href="http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-145.pdf">Legacy/SP/nistspecialpublication800-145.pdf</ext-link></mixed-citation></ref>
<ref id="ref-4"><label>4.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname>, <given-names>M.</given-names></string-name>, <string-name><surname>Yu</surname>, <given-names>S.</given-names></string-name>, <string-name><surname>Zheng</surname>, <given-names>Y.</given-names></string-name>, <string-name><surname>Ren</surname>, <given-names>K.</given-names></string-name>, <string-name><surname>Lou</surname>, <given-names>W.</given-names></string-name></person-group> (<year>2012</year>). <article-title>Scalable and secure sharing of personal health records in cloud computing using attribute-based encryption</article-title>. <source>IEEE Transactions on Parallel and Distributed Systems</source><italic>,</italic> <volume>24</volume><italic>(</italic><issue>1</issue><italic>),</italic> <fpage>131</fpage>&#x2013;<lpage>143</lpage>. <pub-id pub-id-type="doi">10.1109/TPDS.2012.97</pub-id></mixed-citation></ref>
<ref id="ref-5"><label>5.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Au</surname>, <given-names>M. H.</given-names></string-name>, <string-name><surname>Yuen</surname>, <given-names>T. H.</given-names></string-name>, <string-name><surname>Liu</surname>, <given-names>J. K.</given-names></string-name>, <string-name><surname>Susilo</surname>, <given-names>W.</given-names></string-name>, <string-name><surname>Huang</surname>, <given-names>X.</given-names></string-name> <etal>et al.</etal></person-group> (<year>2017</year>). <article-title>A general framework for secure sharing of personal health records in cloud system</article-title>. <source>Journal of Computer and System Sciences</source><italic>,</italic> <volume>90</volume><italic>(</italic><issue>11</issue><italic>),</italic> <fpage>46</fpage>&#x2013;<lpage>62</lpage>. <pub-id pub-id-type="doi">10.1016/j.jcss.2017.03.002</pub-id></mixed-citation></ref>
<ref id="ref-6"><label>6.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname>, <given-names>W.</given-names></string-name>, <string-name><surname>Wu</surname>, <given-names>Y.</given-names></string-name>, <string-name><surname>Xiong</surname>, <given-names>H.</given-names></string-name>, <string-name><surname>Qin</surname>, <given-names>Z.</given-names></string-name></person-group> (<year>2021</year>). <article-title>Accountable attribute-based encryption with public auditing and user revocation in the personal health record system</article-title>. <source>KSII Transactions on Internet and Information Systems (TIIS)</source><italic>,</italic> <volume>15</volume><italic>(</italic><issue>1</issue><italic>),</italic> <fpage>302</fpage>&#x2013;<lpage>322</lpage>.</mixed-citation></ref>
<ref id="ref-7"><label>7.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xhafa</surname>, <given-names>F.</given-names></string-name>, <string-name><surname>Feng</surname>, <given-names>J.</given-names></string-name>, <string-name><surname>Zhang</surname>, <given-names>Y.</given-names></string-name>, <string-name><surname>Chen</surname>, <given-names>X.</given-names></string-name>, <string-name><surname>Li</surname>, <given-names>J.</given-names></string-name></person-group> (<year>2015</year>). <article-title>Privacy-aware attribute-based phr sharing with user accountability in cloud computing</article-title>. <source>The Journal of Supercomputing</source><italic>,</italic> <volume>71</volume><italic>(</italic><issue>5</issue><italic>),</italic> <fpage>1607</fpage>&#x2013;<lpage>1619</lpage>.
<pub-id pub-id-type="doi">10.1007/s11227-014-1253-3</pub-id></mixed-citation></ref>
<ref id="ref-8"><label>8.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chen</surname>, <given-names>T. L.</given-names></string-name>, <string-name><surname>Liao</surname>, <given-names>Y. T.</given-names></string-name>, <string-name><surname>Chang</surname>, <given-names>Y. F.</given-names></string-name>, <string-name><surname>Hwang</surname>, <given-names>J. H.</given-names></string-name></person-group> (<year>2016</year>). <article-title>Security approach to controlling access to personal health records in healthcare service</article-title>. <source>Security and Communication Networks</source><italic>,</italic> <volume>9</volume><italic>(</italic><issue>7</issue><italic>),</italic> <fpage>652</fpage>&#x2013;<lpage>666</lpage>.
<pub-id pub-id-type="doi">10.1002/sec.1387</pub-id></mixed-citation></ref>
<ref id="ref-9"><label>9.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chen</surname>, <given-names>B.</given-names></string-name>, <string-name><surname>He</surname>, <given-names>D.</given-names></string-name>, <string-name><surname>Kumar</surname>, <given-names>N.</given-names></string-name>, <string-name><surname>Wang</surname>, <given-names>H.</given-names></string-name>, <string-name><surname>Choo</surname>, <given-names>K. K. R.</given-names></string-name></person-group> (<year>2021</year>). <article-title>A blockchain-based proxy re-encryption with equality test for vehicular communication systems</article-title>. <source>IEEE Transactions on Network Science and Engineering</source><italic>,</italic> <volume>8</volume><italic>(</italic><issue>3</issue><italic>),</italic> <fpage>2048</fpage>&#x2013;<lpage>2059</lpage>. <pub-id pub-id-type="doi">10.1109/TNSE.2020.2999551</pub-id></mixed-citation></ref>
<ref id="ref-10"><label>10.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lin</surname>, <given-names>C.</given-names></string-name>, <string-name><surname>He</surname>, <given-names>D.</given-names></string-name>, <string-name><surname>Huang</surname>, <given-names>X.</given-names></string-name>, <string-name><surname>Kumar</surname>, <given-names>N.</given-names></string-name>, <string-name><surname>Choo</surname>, <given-names>K. K. R.</given-names></string-name></person-group> (<year>2021</year>). <article-title>Bcppa: A blockchain-based conditional privacy-preserving authentication protocol for vehicular ad hoc networks</article-title>. <source>IEEE Transactions on Intelligent Transportation Systems</source><italic>,</italic> <volume>22</volume><italic>(</italic><issue>12</issue><italic>),</italic> <fpage>7408</fpage>&#x2013;<lpage>7420</lpage>. <pub-id pub-id-type="doi">10.1109/TITS.2020.3002096</pub-id></mixed-citation></ref>
<ref id="ref-11"><label>11.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chen</surname>, <given-names>L.</given-names></string-name>, <string-name><surname>Lee</surname>, <given-names>W. K.</given-names></string-name>, <string-name><surname>Chang</surname>, <given-names>C. C.</given-names></string-name>, <string-name><surname>Choo</surname>, <given-names>K. K. R.</given-names></string-name>, <string-name><surname>Zhang</surname>, <given-names>N.</given-names></string-name></person-group> (<year>2019</year>). <article-title>Blockchain based searchable encryption for electronic health record sharing</article-title>. <source>Future Generation Computer Systems</source><italic>,</italic> <volume>95</volume><italic>(</italic><issue>3</issue><italic>),</italic> <fpage>420</fpage>&#x2013;<lpage>429</lpage>.
<pub-id pub-id-type="doi">10.1016/j.future.2019.01.018</pub-id></mixed-citation></ref>
<ref id="ref-12"><label>12.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shi</surname>, <given-names>S.</given-names></string-name>, <string-name><surname>He</surname>, <given-names>D.</given-names></string-name>, <string-name><surname>Li</surname>, <given-names>L.</given-names></string-name>, <string-name><surname>Kumar</surname>, <given-names>N.</given-names></string-name>, <string-name><surname>Khan</surname>, <given-names>M. K.</given-names></string-name> <etal>et al.</etal></person-group> (<year>2020</year>). <article-title>Applications of blockchain in ensuring the security and privacy of electronic health record systems: A survey</article-title>. <source>Computers &#x0026; Security</source><italic>,</italic> <volume>97</volume><italic>(</italic><issue>5</issue><italic>),</italic> <fpage>101966</fpage>. <pub-id pub-id-type="doi">10.1016/j.cose.2020.101966</pub-id>; <pub-id pub-id-type="pmid">32834254</pub-id></mixed-citation></ref>
<ref id="ref-13"><label>13.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>McGhin</surname>, <given-names>T.</given-names></string-name>, <string-name><surname>Choo</surname>, <given-names>K. K. R.</given-names></string-name>, <string-name><surname>Liu</surname>, <given-names>C. Z.</given-names></string-name>, <string-name><surname>He</surname>, <given-names>D.</given-names></string-name></person-group> (<year>2019</year>). <article-title>Blockchain in healthcare applications: Research challenges and opportunities</article-title>. <source>Journal of Network and Computer Applications</source><italic>,</italic> <volume>135</volume><italic>(</italic><issue>1</issue><italic>),</italic> <fpage>62</fpage>&#x2013;<lpage>75</lpage>.
<pub-id pub-id-type="doi">10.1016/j.jnca.2019.02.027</pub-id></mixed-citation></ref>
<ref id="ref-14"><label>14.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname>, <given-names>H.</given-names></string-name>, <string-name><surname>Song</surname>, <given-names>Y.</given-names></string-name></person-group> (<year>2018</year>). <article-title>Secure cloud-based EHR system using attribute-based cryptosystem and blockchain</article-title>. <source>Journal of Medical Systems</source><italic>,</italic> <volume>42</volume><italic>(</italic><issue>8</issue><italic>),</italic> <fpage>152</fpage>. <pub-id pub-id-type="doi">10.1007/s10916-018-0994-6</pub-id>; <pub-id pub-id-type="pmid">29974270</pub-id></mixed-citation></ref>
<ref id="ref-15"><label>15.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xia</surname>, <given-names>Q.</given-names></string-name>, <string-name><surname>Sifah</surname>, <given-names>E. B.</given-names></string-name>, <string-name><surname>Smahi</surname>, <given-names>A.</given-names></string-name>, <string-name><surname>Amofa</surname>, <given-names>S.</given-names></string-name>, <string-name><surname>Zhang</surname>, <given-names>X.</given-names></string-name></person-group> (<year>2017</year>). <article-title>BBDS: Blockchain-based data sharing for electronic medical records in cloud environments</article-title>. <source>Information</source><italic>,</italic> <volume>8</volume><italic>(</italic><issue>2</issue><italic>),</italic> <fpage>44</fpage>. <pub-id pub-id-type="doi">10.3390/info8020044</pub-id></mixed-citation></ref>
<ref id="ref-16"><label>16.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname>, <given-names>H.</given-names></string-name>, <string-name><surname>Wang</surname>, <given-names>Q.</given-names></string-name>, <string-name><surname>He</surname>, <given-names>D.</given-names></string-name></person-group> (<year>2021</year>). <article-title>Blockchain-based private provable data possession</article-title>. <source>IEEE Transactions on Dependable and Secure Computing</source><italic>,</italic> <volume>18</volume><italic>(</italic><issue>5</issue><italic>),</italic> <fpage>2379</fpage>&#x2013;<lpage>2389</lpage>.</mixed-citation></ref>
<ref id="ref-17"><label>17.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhu</surname>, <given-names>L.</given-names></string-name>, <string-name><surname>Wu</surname>, <given-names>Y.</given-names></string-name>, <string-name><surname>Gai</surname>, <given-names>K.</given-names></string-name>, <string-name><surname>Choo</surname>, <given-names>K. K. R.</given-names></string-name></person-group> (<year>2019</year>). <article-title>Controllable and trustworthy blockchain-based cloud data management</article-title>. <source>Future Generation Computer Systems</source><italic>,</italic> <volume>91</volume><italic>(</italic><issue>99</issue><italic>),</italic> <fpage>527</fpage>&#x2013;<lpage>535</lpage>.
<pub-id pub-id-type="doi">10.1016/j.future.2018.09.019</pub-id></mixed-citation></ref>
<ref id="ref-18"><label>18.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname>, <given-names>Y.</given-names></string-name>, <string-name><surname>Deng</surname>, <given-names>R. H.</given-names></string-name>, <string-name><surname>Liu</surname>, <given-names>X.</given-names></string-name>, <string-name><surname>Zheng</surname>, <given-names>D.</given-names></string-name></person-group> (<year>2018</year>). <article-title>Blockchain based efficient and robust fair payment for outsourcing services in cloud computing</article-title>. <source>Information Sciences</source><italic>,</italic> <volume>462</volume><italic>(</italic><issue>4</issue><italic>),</italic> <fpage>262</fpage>&#x2013;<lpage>277</lpage>.
<pub-id pub-id-type="doi">10.1016/j.ins.2018.06.018</pub-id></mixed-citation></ref>
<ref id="ref-19"><label>19.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xiong</surname>, <given-names>H.</given-names></string-name>, <string-name><surname>Zhang</surname>, <given-names>H.</given-names></string-name>, <string-name><surname>Sun</surname>, <given-names>J.</given-names></string-name></person-group> (<year>2018</year>). <article-title>Attribute-based privacy-preserving data sharing for dynamic groups in cloud computing</article-title>. <source>IEEE Systems Journal</source><italic>,</italic> <volume>13</volume><italic>(</italic><issue>3</issue><italic>),</italic> <fpage>2739</fpage>&#x2013;<lpage>2750</lpage>. <pub-id pub-id-type="doi">10.1109/JSYST.2018.2865221</pub-id></mixed-citation></ref>
<ref id="ref-20"><label>20.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname>, <given-names>H.</given-names></string-name>, <string-name><surname>Yu</surname>, <given-names>K.</given-names></string-name>, <string-name><surname>Liu</surname>, <given-names>B.</given-names></string-name>, <string-name><surname>Feng</surname>, <given-names>C.</given-names></string-name>, <string-name><surname>Qin</surname>, <given-names>Z.</given-names></string-name> <etal>et al.</etal></person-group> (<year>2022</year>). <article-title>An efficient ciphertext-policy weighted attribute-based encryption for the internet of health things</article-title>. <source>IEEE Journal of Biomedical and Health Informatics</source><italic>,</italic> <volume>26</volume><italic>(</italic><issue>5</issue><italic>),</italic> <fpage>1949</fpage>&#x2013;<lpage>1960</lpage>. <pub-id pub-id-type="doi">10.1109/JBHI.2021.3075995</pub-id>; <pub-id pub-id-type="pmid">33905340</pub-id></mixed-citation></ref>
<ref id="ref-21"><label>21.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bao</surname>, <given-names>Y.</given-names></string-name>, <string-name><surname>Qiu</surname>, <given-names>W.</given-names></string-name>, <string-name><surname>Cheng</surname>, <given-names>X.</given-names></string-name></person-group> (<year>2022</year>). <article-title>Secure and lightweight fine-grained searchable data sharing for IoT-oriented and cloud-assisted smart healthcare system</article-title>. <source>IEEE Internet of Things Journal</source><italic>,</italic> <volume>9</volume><italic>(</italic><issue>4</issue><italic>),</italic> <fpage>2513</fpage>&#x2013;<lpage>2526</lpage>. <pub-id pub-id-type="doi">10.1109/JIOT.2021.3063846</pub-id></mixed-citation></ref>
<ref id="ref-22"><label>22.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname>, <given-names>H.</given-names></string-name>, <string-name><surname>Lan</surname>, <given-names>C.</given-names></string-name>, <string-name><surname>Fu</surname>, <given-names>X.</given-names></string-name>, <string-name><surname>Wang</surname>, <given-names>C.</given-names></string-name>, <string-name><surname>Li</surname>, <given-names>F.</given-names></string-name> <etal>et al.</etal></person-group> (<year>2020</year>). <article-title>A secure and lightweight fine-grained data sharing scheme for mobile cloud computing</article-title>. <source>Sensors</source><italic>,</italic> <volume>20</volume><italic>(</italic><issue>17</issue><italic>),</italic> <fpage>4720</fpage>. <pub-id pub-id-type="doi">10.3390/s20174720</pub-id>; <pub-id pub-id-type="pmid">32825602</pub-id></mixed-citation></ref>
<ref id="ref-23"><label>23.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname>, <given-names>A.</given-names></string-name>, <string-name><surname>Lin</surname>, <given-names>X.</given-names></string-name></person-group> (<year>2018</year>). <article-title>Towards secure and privacy-preserving data sharing in e-health systems via consortium blockchain</article-title>. <source>Journal of Medical Systems</source><italic>,</italic> <volume>42</volume><italic>(</italic><issue>8</issue><italic>),</italic> <fpage>1</fpage>&#x2013;<lpage>18</lpage>. <pub-id pub-id-type="doi">10.1007/s10916-018-0995-5</pub-id>; <pub-id pub-id-type="pmid">29956061</pub-id></mixed-citation></ref>
<ref id="ref-24"><label>24.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Thwin</surname>, <given-names>T. T.</given-names></string-name>, <string-name><surname>Vasupongayya</surname>, <given-names>S.</given-names></string-name></person-group> (<year>2019</year>). <article-title>Blockchain-based access control model to preserve privacy for personal health record systems</article-title>. <source>Security and Communication Networks</source><italic>,</italic> <volume>2019</volume><italic>(</italic><issue>5</issue><italic>),</italic> <fpage>8315614</fpage>. 
<pub-id pub-id-type="doi">10.1155/2019/8315614</pub-id></mixed-citation></ref>
<ref id="ref-25"><label>25.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cao</surname>, <given-names>S.</given-names></string-name>, <string-name><surname>Zhang</surname>, <given-names>G.</given-names></string-name>, <string-name><surname>Liu</surname>, <given-names>P.</given-names></string-name>, <string-name><surname>Zhang</surname>, <given-names>X.</given-names></string-name>, <string-name><surname>Neri</surname>, <given-names>F.</given-names></string-name></person-group> (<year>2019</year>). <article-title>Cloud-assisted secure eHealth systems for tamper-proofing EHR via blockchain</article-title>. <source>Information Sciences</source><italic>,</italic> <volume>485</volume><italic>(</italic><issue>3</issue><italic>),</italic> <fpage>427</fpage>&#x2013;<lpage>440</lpage>.
<pub-id pub-id-type="doi">10.1016/j.ins.2019.02.038</pub-id></mixed-citation></ref>
<ref id="ref-26"><label>26.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Nagasubramanian</surname>, <given-names>G.</given-names></string-name>, <string-name><surname>Sakthivel</surname>, <given-names>R. K.</given-names></string-name>, <string-name><surname>Patan</surname>, <given-names>R.</given-names></string-name>, <string-name><surname>Gandomi</surname>, <given-names>A. H.</given-names></string-name>, <string-name><surname>Sankayya</surname>, <given-names>M.</given-names></string-name> <etal>et al.</etal></person-group> (<year>2020</year>). <article-title>Securing e-health records using keyless signature infrastructure blockchain technology in the cloud</article-title>. <source>Neural Computing and Applications</source><italic>,</italic> <volume>32</volume><italic>(</italic><issue>3</issue><italic>),</italic> <fpage>639</fpage>&#x2013;<lpage>647</lpage>. <pub-id pub-id-type="doi">10.1007/s00521-018-3915-1</pub-id></mixed-citation></ref>
<ref id="ref-27"><label>27.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yang</surname>, <given-names>Z.</given-names></string-name>, <string-name><surname>Zhang</surname>, <given-names>H.</given-names></string-name>, <string-name><surname>Yu</surname>, <given-names>H.</given-names></string-name>, <string-name><surname>Li</surname>, <given-names>Z.</given-names></string-name>, <string-name><surname>Zhu</surname>, <given-names>B.</given-names></string-name> <etal>et al.</etal></person-group> (<year>2021</year>). <article-title>Attribute-based keyword search over the encrypted blockchain</article-title>. <source>Computer Modeling in Engineering &#x0026; Sciences</source><italic>,</italic> <volume>128</volume><italic>(</italic><issue>1</issue><italic>),</italic> <fpage>269</fpage>&#x2013;<lpage>282</lpage>.
<pub-id pub-id-type="doi">10.32604/cmes.2021.015210</pub-id></mixed-citation></ref>
<ref id="ref-28"><label>28.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Al Omar</surname>, <given-names>A.</given-names></string-name>, <string-name><surname>Bhuiyan</surname>, <given-names>M. Z. A.</given-names></string-name>, <string-name><surname>Basu</surname>, <given-names>A.</given-names></string-name>, <string-name><surname>Kiyomoto</surname>, <given-names>S.</given-names></string-name>, <string-name><surname>Rahman</surname>, <given-names>M. S.</given-names></string-name></person-group> (<year>2019</year>). <article-title>Privacy-friendly platform for healthcare data in cloud based on blockchain environment</article-title>. <source>Future Generation Computer Systems</source><italic>,</italic> <volume>95</volume><italic>(</italic><issue>10</issue><italic>),</italic> <fpage>511</fpage>&#x2013;<lpage>521</lpage>. <pub-id pub-id-type="doi">10.1016/j.future.2018.12.044</pub-id></mixed-citation></ref>
<ref id="ref-29"><label>29.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lu</surname>, <given-names>Y.</given-names></string-name></person-group> (<year>2019</year>). <article-title>The blockchain: State-of-the-art and research challenges</article-title>. <source>Journal of Industrial Information Integration</source><italic>,</italic> <volume>15</volume><italic>(</italic><issue>4</issue><italic>),</italic> <fpage>80</fpage>&#x2013;<lpage>90</lpage>. <pub-id pub-id-type="doi">10.1016/j.jii.2019.04.002</pub-id></mixed-citation></ref>
<ref id="ref-30"><label>30.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lin</surname>, <given-names>C.</given-names></string-name>, <string-name><surname>He</surname>, <given-names>D.</given-names></string-name>, <string-name><surname>Huang</surname>, <given-names>X.</given-names></string-name>, <string-name><surname>Khan</surname>, <given-names>M. K.</given-names></string-name>, <string-name><surname>Choo</surname>, <given-names>K. K. R.</given-names></string-name></person-group> (<year>2020</year>). <article-title>DCAP: A secure and efficient decentralized conditional anonymous payment system based on blockchain</article-title>. <source>IEEE Transactions on Information Forensics and Security</source><italic>,</italic> <volume>15</volume><italic>,</italic> <fpage>2440</fpage>&#x2013;<lpage>2452</lpage>. <pub-id pub-id-type="doi">10.1109/TIFS.2020.2969565</pub-id></mixed-citation></ref>
<ref id="ref-31"><label>31.</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Nakamoto</surname>, <given-names>S.</given-names></string-name></person-group> (<year>2008</year>). <article-title>Bitcoin: A peer-to-peer electronic cash system</article-title>. <ext-link ext-link-type="uri" xlink:href="https://bitcoin.org/bitcoin.pdf">https://bitcoin.org/bitcoin.pdf</ext-link></mixed-citation></ref>
<ref id="ref-32"><label>32.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Khan</surname>, <given-names>S. N.</given-names></string-name>, <string-name><surname>Loukil</surname>, <given-names>F.</given-names></string-name>, <string-name><surname>Ghedira-Guegan</surname>, <given-names>C.</given-names></string-name>, <string-name><surname>Benkhelifa</surname>, <given-names>E.</given-names></string-name>, <string-name><surname>Bani-Hani</surname>, <given-names>A.</given-names></string-name></person-group> (<year>2021</year>). <article-title>Blockchain smart contracts: Applications, challenges, and future trends</article-title>. <source>Peer-to-Peer Networking and Applications</source><italic>,</italic> <volume>14</volume><italic>(</italic><issue>5</issue><italic>),</italic> <fpage>2901</fpage>&#x2013;<lpage>2925</lpage>. <pub-id pub-id-type="doi">10.1007/s12083-021-01127-0</pub-id>; <pub-id pub-id-type="pmid">33897937</pub-id></mixed-citation></ref>
<ref id="ref-33"><label>33.</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Bethencourt</surname>, <given-names>J.</given-names></string-name>, <string-name><surname>Sahai</surname>, <given-names>A.</given-names></string-name>, <string-name><surname>Waters</surname>, <given-names>B.</given-names></string-name></person-group> (<year>2007</year>). <article-title>Ciphertext-policy attribute-based encryption</article-title>. <conf-name>2007 IEEE Symposium on Security and Privacy (SP&#x2019;07)</conf-name>, pp. <fpage>321</fpage>&#x2013;<lpage>334</lpage>. <publisher-loc>Berkeley, CA, USA</publisher-loc>, <publisher-name>IEEE</publisher-name>. 
<pub-id pub-id-type="doi">10.1109/SP.2007.11</pub-id></mixed-citation></ref>
<ref id="ref-34"><label>34.</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Sahai</surname>, <given-names>A.</given-names></string-name>, <string-name><surname>Waters</surname>, <given-names>B.</given-names></string-name></person-group> (<year>2005</year>). <article-title>Fuzzy identity-based encryption</article-title>. In: <string-name><surname>Cramer</surname>, <given-names>R.</given-names></string-name> (Ed.) <conf-name>Lecture notes in computer science</conf-name>, vol. <volume>3494</volume>. <publisher-loc>Berlin, Heidelberg</publisher-loc>: <publisher-name>Springer</publisher-name>. <pub-id pub-id-type="doi">10.1007/11426639_27</pub-id></mixed-citation></ref>
<ref id="ref-35"><label>35.</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Goyal</surname>, <given-names>V.</given-names></string-name>, <string-name><surname>Pandey</surname>, <given-names>O.</given-names></string-name>, <string-name><surname>Sahai</surname>, <given-names>A.</given-names></string-name>, <string-name><surname>Waters</surname>, <given-names>B.</given-names></string-name></person-group> (<year>2006</year>). <article-title>Attribute-based encryption for fine-grained access control of encrypted data</article-title>. <conf-name>Proceedings of the 13th ACM Conference on Computer and Communications Security (CCS'06).</conf-name> pp. <fpage>89</fpage>&#x2013;<lpage>98</lpage>. <conf-loc>New York, NY, USA</conf-loc>, <comment>Association for Computing Machinery</comment>. 
<pub-id pub-id-type="doi">10.1145/1180405.1180418</pub-id></mixed-citation></ref>
<ref id="ref-36"><label>36.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yang</surname>, <given-names>J. J.</given-names></string-name>, <string-name><surname>Li</surname>, <given-names>J. Q.</given-names></string-name>, <string-name><surname>Niu</surname>, <given-names>Y.</given-names></string-name></person-group> (<year>2015</year>). <article-title>A hybrid solution for privacy preserving medical data sharing in the cloud environment</article-title>. <source>Future Generation Computer Systems</source><italic>,</italic> <volume>43</volume><italic>(</italic><issue>8</issue><italic>),</italic> <fpage>74</fpage>&#x2013;<lpage>86</lpage>.
<pub-id pub-id-type="doi">10.1016/j.future.2014.06.004</pub-id></mixed-citation></ref>
<ref id="ref-37"><label>37.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname>, <given-names>Y.</given-names></string-name>, <string-name><surname>He</surname>, <given-names>D.</given-names></string-name>, <string-name><surname>Choo</surname>, <given-names>K. K. R.</given-names></string-name></person-group> (<year>2018</year>). <article-title>BaDS: Blockchain-based architecture for data sharing with ABS and CP-ABE in IoT</article-title>. <source>Wireless Communications and Mobile Computing</source><italic>,</italic> <volume>2018</volume><italic>(</italic><issue>2</issue><italic>),</italic> <fpage>2783658</fpage>. 
<pub-id pub-id-type="doi">10.1155/2018/2783658</pub-id></mixed-citation></ref>
<ref id="ref-38"><label>38.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xu</surname>, <given-names>J.</given-names></string-name>, <string-name><surname>Xue</surname>, <given-names>K.</given-names></string-name>, <string-name><surname>Li</surname>, <given-names>S.</given-names></string-name>, <string-name><surname>Tian</surname>, <given-names>H.</given-names></string-name>, <string-name><surname>Hong</surname>, <given-names>J.</given-names></string-name> <etal>et al.</etal></person-group> (<year>2019</year>). <article-title>Healthchain: A blockchain-based privacy preserving scheme for large-scale health data</article-title>. <source>IEEE Internet of Things Journal</source><italic>,</italic> <volume>6</volume><italic>(</italic><issue>5</issue><italic>),</italic> <fpage>8770</fpage>&#x2013;<lpage>8781</lpage>.
<pub-id pub-id-type="doi">10.1109/JIOT.2019.2923525</pub-id></mixed-citation></ref>
<ref id="ref-39"><label>39.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lai</surname>, <given-names>J.</given-names></string-name>, <string-name><surname>Deng</surname>, <given-names>R. H.</given-names></string-name>, <string-name><surname>Guan</surname>, <given-names>C.</given-names></string-name>, <string-name><surname>Weng</surname>, <given-names>J.</given-names></string-name></person-group> (<year>2013</year>). <article-title>Attribute-based encryption with verifiable outsourced decryption</article-title>. <source>IEEE Transactions on Information Forensics and Security</source><italic>,</italic> <volume>8</volume><italic>(</italic><issue>8</issue><italic>),</italic> <fpage>1343</fpage>&#x2013;<lpage>1354</lpage>. 
<pub-id pub-id-type="doi">10.1109/TIFS.2013.2271848</pub-id></mixed-citation></ref>
<ref id="ref-40"><label>40.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zheng</surname>, <given-names>H.</given-names></string-name>, <string-name><surname>Shao</surname>, <given-names>J.</given-names></string-name>, <string-name><surname>Wei</surname>, <given-names>G.</given-names></string-name></person-group> (<year>2020</year>). <article-title>Attribute-based encryption with outsourced decryption in blockchain</article-title>. <source>Peer-to-Peer Networking and Applications</source><italic>,</italic> <volume>13</volume><italic>(</italic><issue>5</issue><italic>),</italic> <fpage>1643</fpage>&#x2013;<lpage>1655</lpage>. <pub-id pub-id-type="doi">10.1007/s12083-020-00918-1</pub-id></mixed-citation></ref>
<ref id="ref-41"><label>41.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ezhil Arasi</surname>, <given-names>V.</given-names></string-name>, <string-name><surname>Indra Gandhi</surname>, <given-names>K.</given-names></string-name>, <string-name><surname>Kulothungan</surname>, <given-names>K.</given-names></string-name></person-group> (<year>2022</year>). <article-title>Auditable attribute-based data access control using blockchain in cloud storage</article-title>. <source>The Journal of Supercomputing</source><italic>,</italic> <volume>78</volume><italic>(</italic><issue>8</issue><italic>),</italic> <fpage>10772</fpage>&#x2013;<lpage>10798</lpage>. 
<pub-id pub-id-type="doi">10.1007/s11227-021-04293-3</pub-id></mixed-citation></ref>
<ref id="ref-42"><label>42.</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Akinyele</surname>, <given-names>J. A.</given-names></string-name>, <string-name><surname>Garman</surname>, <given-names>C.</given-names></string-name>, <string-name><surname>Miers</surname>, <given-names>I.</given-names></string-name>, <string-name><surname>Pagano</surname>, <given-names>M. W.</given-names></string-name>, <string-name><surname>Rushanan</surname>, <given-names>M.</given-names></string-name> <etal>et al.</etal></person-group> (<year>2013</year>). <article-title>Charm: A framework for rapidly prototyping cryptosystems</article-title>. <source>Journal of Cryptographic Engineering</source><italic>,</italic> <volume>3</volume><italic>(</italic><issue>2</issue><italic>),</italic> <fpage>111</fpage>&#x2013;<lpage>128</lpage>.
<pub-id pub-id-type="doi">10.1007/s13389-013-0057-3</pub-id></mixed-citation></ref>
</ref-list>
</back>
</article>