<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">63964</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2025.063964</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Blockchain-Based Electronic Health Passport for Secure Storage and Sharing of Healthcare Data</article-title>
<alt-title alt-title-type="left-running-head">Blockchain-Based Electronic Health Passport for Secure Storage and Sharing of Healthcare Data</alt-title>
<alt-title alt-title-type="right-running-head">Blockchain-Based Electronic Health Passport for Secure Storage and Sharing of Healthcare Data</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Maravi</surname><given-names>Yogendra P. S.</given-names></name><email>yogendra@rgpv.ac.in</email></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Mishra</surname><given-names>Nishchol</given-names></name></contrib>
<aff id="aff-1"><institution>School of Information Technology, Rajiv Gandhi Proudyogiki Vishwavidyalaya</institution>, <addr-line>Bhopal, 462033</addr-line>, <country>India</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Yogendra P. S. Maravi. Email: <email>yogendra@rgpv.ac.in</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2025</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>19</day><month>05</month><year>2025</year>
</pub-date>
<volume>83</volume>
<issue>3</issue>
<fpage>5517</fpage>
<lpage>5537</lpage>
<history>
<date date-type="received">
<day>30</day>
<month>1</month>
<year>2025</year>
</date>
<date date-type="accepted">
<day>24</day>
<month>3</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2025 The Authors.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_63964.pdf"></self-uri>
<abstract>
<p>The growing demand for international travel has highlighted the critical need for reliable tools to verify travelers&#x2019; healthcare status and meet entry requirements. Personal health passports, while essential, face significant challenges related to data silos, privacy protection, and forgery risks in global sharing. To address these issues, this study proposes a blockchain-based solution designed for the secure storage, sharing, and verification of personal health passports. This innovative approach combines on-chain and off-chain storage, leveraging searchable encryption to enhance data security and optimize blockchain storage efficiency. By reducing the storage burden on the blockchain, the system ensures both the secure handling and reliable sharing of sensitive personal health data. An optimized consensus mechanism streamlines the process into two stages, minimizing communication complexity among nodes and significantly improving the throughput of the blockchain system. Additionally, the introduction of advanced aggregate signature technology accommodates multi-user scenarios, reducing computational overhead for signature verification and enabling swift identification of malicious forgers. Comprehensive security analyses validate the system&#x2019;s robustness and reliability. Simulation results demonstrate notable performance improvements over existing solutions, with reductions in computational overhead of up to 49.89% and communication overhead of up to 25.81% in multi-user scenarios. Furthermore, the optimized consensus mechanism shows substantial efficiency gains across varying node configurations. This solution represents a significant step toward addressing the pressing challenges of health passport management in a secure, scalable, and efficient manner.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Blockchain</kwd>
<kwd>healthcare and machine learning</kwd>
<kwd>healthcare device data</kwd>
<kwd>health passport</kwd>
<kwd>computational overhead</kwd>
<kwd>signature verification</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>With the continuous development of society, the demand for international travel, academic exchanges, and medical tourism has increased significantly. However, inconsistencies in healthcare regulations across countries have led to challenges in verifying travelers&#x2019; health status. In recent years, fraudulent health passports [<xref ref-type="bibr" rid="ref-1">1</xref>] and medical data breaches have emerged as serious threats to public health and data privacy. For example, in 2021, Europol reported the dismantling of multiple fraudulent COVID-19 vaccine passport networks operating across Europe, where counterfeit certificates were sold on the black market to bypass travel restrictions. Similarly, in 2022, a massive healthcare data breach in the United States exposed sensitive patient records, affecting over 10 million individuals. These incidents highlight the vulnerabilities in current digital health documentation and the risks associated with central storage architectures, which are susceptible to cyberattacks and unauthorized data access [<xref ref-type="bibr" rid="ref-2">2</xref>]. Traditional paper-based health passports are prone to forgery, and digital records suffer from data silos and privacy issues. To address these challenges, we propose a blockchain-based health passport system integrating on-chain and off-chain storage, searchable encryption, and an optimized consensus mechanism for enhanced security, privacy, and efficiency.</p>
<p>However, there are huge differences in disease prevention measures and requirements in different countries and regions, resulting in differences in entry and exit health standards. In this context, many countries and regions have formulated strict Healthcare and machine learning policies to ensure public health and safety [<xref ref-type="bibr" rid="ref-3">3</xref>,<xref ref-type="bibr" rid="ref-4">4</xref>]. In this context, personal health passports have become a powerful tool that can be used to confirm the health status of travelers and meet the health entry requirements of different countries and regions. Personal health passports can contain Healthcare and machine learning information and vaccination records for effective management and monitoring of Healthcare and machine learning [<xref ref-type="bibr" rid="ref-5">5</xref>]. Traditional paper health passports can be traced back to the &#x201C;health pass&#x201D; issued during the European plague pandemic in the 15th century, which was intended to exempt travellers from quarantine measures. However, traditional paper health passports have the hidden danger of being easily forged and tampered with, leading to problems of insecurity and credibility. Especially in the digital age, the mobility and vulnerability of information further exacerbate these problems. In this context, some countries and international organizations have successively launched electronic health passports or health passports to allow work and travel abroad without compromising personal or Healthcare and machine learning. With the introduction of electronic health passports, the privacy leakage of personal information has become increasingly prominent. Traditional central storage architectures often Healthcare device data on third-party platforms. Once the third party is hacked or colluded with malicious attackers, the privacy and security of users will be difficult to guarantee [<xref ref-type="bibr" rid="ref-6">6</xref>]. Therefore, the protection of Healthcare device data and the management of privacy risks have become urgent issues to be addressed. At the same time, the Healthcare device data of various medical institutions and even countries are not interoperable, resulting in the formation of &#x201C;information islands&#x201D;, which greatly limits the sharing of health passports around the world. Blockchain technology has been introduced into the field of smart medical care [<xref ref-type="bibr" rid="ref-7">7</xref>&#x2013;<xref ref-type="bibr" rid="ref-9">9</xref>] by many scholars due to its inherent advantages such as difficulty in tampering, transparency and decentralization, bringing new possibilities for the management and verification of health passports [<xref ref-type="bibr" rid="ref-10">10</xref>]. However, the contradiction between the low throughput and efficiency of traditional blockchains and the high efficiency required by the actual application scenarios of health passports has not been resolved. Secondly, although searchable encryption technology allows users to Healthcare device data and upload it to the cloud server and retrieve ciphertext [<xref ref-type="bibr" rid="ref-11">11</xref>], users often use resource-constrained mobile devices, which cannot meet the large cryptographic computing burden brought by existing solutions. While cloud-based systems are widely used for health data storage, they rely on centralized architectures, making them vulnerable to single points of failure, unauthorized access, and large-scale data breaches. Additionally, centralized models struggle with interoperability, limiting seamless data exchange across healthcare institutions. In contrast, blockchain offers tamper-proof records through cryptographic hashing, decentralized control to eliminate reliance on third parties, and transparent yet privacy-preserving verification via smart contracts. Unlike cloud systems, blockchain ensures data integrity, where modifications are impossible without consensus, significantly reducing forgery risks in health passports. To address these difficulties, this article suggests a system for storing, sharing, and verifying personal health passports that is based on the blockchain. The main contributions of this work are as follows:
<list list-type="simple">
<list-item><label>1.</label><p>Hybrid On-Chain and Off-Chain Storage Optimization: The proposed approach integrates searchable encryption with a hybrid storage model, where only the index is stored on the blockchain while encrypted healthcare data is securely managed in the Interplanetary File System (IPFS). This reduces on-chain storage overhead, enhances query efficiency, and enables scalable and privacy-preserving healthcare data management, addressing the limitations of conventional blockchain-based healthcare systems.</p></list-item>
<list-item><label>2.</label><p>Efficient Multi-User Authentication via Optimized Aggregate Signatures: To support scalable and secure multi-user verification, the system employs an enhanced aggregate signature scheme, which reduces computational overhead for signature verification. Additionally, our approach introduces a rapid tracing mechanism for detecting malicious forgers, significantly improving security and fraud detection in healthcare data verification.</p></list-item>
<list-item><label>3.</label><p>High-Throughput Two-Stage Weak Consensus Mechanism: The study optimizes the weak consensus algorithm to improve blockchain throughput and scalability. Unlike traditional PBFT-based consensus methods, our two-stage process significantly reduces communication complexity while maintaining strong security guarantees, making it more suitable for real-time healthcare applications.</p></list-item>
<list-item><label>4.</label><p>Comprehensive Security and Performance Evaluation: The proposed system undergoes rigorous security validation, ensuring confidentiality, integrity, and resistance to forgery attacks. Extensive performance comparisons demonstrate up to a 49.89% reduction in computational overhead and a 25.81% decrease in communication costs, showcasing superior efficiency and robustness over existing blockchain-based healthcare frameworks.</p></list-item>
</list></p>
<p>The structure of this paper is as follows: <xref ref-type="sec" rid="s2">Section 2</xref> discusses review of existing research, highlighting strengths, identifying gaps. <xref ref-type="sec" rid="s3">Section 3</xref> represents essential concepts and theories needed to understand the proposed research. <xref ref-type="sec" rid="s4">Section 4</xref> describes the system architecture, components, and their interactions. <xref ref-type="sec" rid="s5">Section 5</xref> discloses the detailed design and implementation strategies of the proposed solution. In <xref ref-type="sec" rid="s6">Section 6</xref>, evaluation of system security against vulnerabilities and potential threats is mentioned. <xref ref-type="sec" rid="s7">Section 7</xref> introduces the assessment of system performance using metrics and comparative results. Finally, <xref ref-type="sec" rid="s8">Section 8</xref> concludes with findings, research contributions, and future work suggestions.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Work</title>
<p>As a decentralized database [<xref ref-type="bibr" rid="ref-12">12</xref>], blockchain technology has been widely used in Healthcare and machine learning, financial services, and supply chain management [<xref ref-type="bibr" rid="ref-13">13</xref>]. In response to the sharing and verification of personal health passports, scholars have proposed many blockchain-based solutions. Demirbaga et al. [<xref ref-type="bibr" rid="ref-14">14</xref>] implement the Healthcare and Internet of Things (IoT) enable Healthcare device data management application GreenPass based on blockchain technology. Although the applications of Healthcare and machine learning status survey function was mentioned, its system model and detailed solution details were not introduced in depth. Jafari et al. [<xref ref-type="bibr" rid="ref-15">15</xref>] proposed a government-managed blockchain to store COVID-19 vaccination certificates, emphasizing the use of biometric authentication to enhance user anonymity and privacy protection. Ait Bennacer et al. [<xref ref-type="bibr" rid="ref-1">1</xref>] proposed a digital health passport based on a private chain, which contains antibody test results and timestamps, but private chains are not suitable for international entry and exit scenarios. Zarour et al. [<xref ref-type="bibr" rid="ref-16">16</xref>] proposed a solution VacciFi takes into account the general Healthcare device data protection regulation (GDPR), and the architecture is scalable. At the same time, the solution is committed to using a permissioned blockchain to ensure the availability, traceability, and integrity of Healthcare and machine learning information, but the solution fails to deal well with internal attacks. Guerar et al. [<xref ref-type="bibr" rid="ref-17">17</xref>] proposed a global architecture that uses blockchain to verify and distribute different health passports. Rajtar et al. [<xref ref-type="bibr" rid="ref-18">18</xref>] proposed an online passport system to report citizens&#x2019; Healthcare and machine learning status. The scheme uses the user&#x2019;s biometric information (such as iris scan) to uniquely identify each user, while the blockchain stores the user&#x2019;s Healthcare and machine learning information such as historical medical records. A blockchain-based system for storing and exchanging immunization records was developed in this study [<xref ref-type="bibr" rid="ref-19">19</xref>]. Data traceability is ensured by storing the immunization records on the blockchain. Another benefit of mutual authentication is that it ensures the Healthcare device data&#x2019;s integrity and non-repudiation [<xref ref-type="bibr" rid="ref-20">20</xref>]. Consensus algorithms are an important component of blockchain systems and affect the overall operating efficiency of blockchain systems [<xref ref-type="bibr" rid="ref-21">21</xref>]. Among the most popular consensus algorithms currently in use are the Byzantine fault tolerance (BFT) protocol [<xref ref-type="bibr" rid="ref-22">22</xref>], proof of collateral [<xref ref-type="bibr" rid="ref-23">23</xref>], proof of assets [<xref ref-type="bibr" rid="ref-24">24</xref>], and proof of work [<xref ref-type="bibr" rid="ref-25">25</xref>]. When it comes to consortium chains, most consensus algorithms employ practical byzantine fault tolerance (PBFT) [<xref ref-type="bibr" rid="ref-21">21</xref>] consensus. Nevertheless, the network and the amount of time it takes for a message to reach agreement in the entire system are external elements that are bound to impact PBFT, being a strong consistency consensus mechanism. Consequently, wait times for individual nodes in a P2P network to reach consensus are similarly lengthened. Obviously, the global health passport information chain must have extremely high requirements for the throughput of the blockchain, which is difficult to meet with the traditional PBFT consensus mechanism. Therefore, it is very important to choose a consensus mechanism that is suitable for the current solution. Zhou et al. [<xref ref-type="bibr" rid="ref-26">26</xref>] proposed a weak consistency BFT consensus method by weakening the requirement for strong consistency in the consensus process. This method is based on an asynchronous BFT algorithm and only guarantees the relative position of the messages received and agreed upon by each node, without requiring the message order of each node to be completely consistent, thereby achieving consistency of the entire system, which also greatly improves the throughput of the entire blockchain. This solution improves the weak consistency BFT consensus method and further improves the efficiency. In summary, although scholars have proposed solutions to the sharing and verification problems of health passports, the existing solutions store a large amount of Healthcare device data in the blockchain, which increases the burden on blockchain nodes and reduces the efficiency of the overall solution. Especially in multi-user scenarios, frequent verification operations will further increase the time cost of the solution [<xref ref-type="bibr" rid="ref-27">27</xref>]. At the same time, for scenarios such as health passports that require frequent updates and verification of information, the existing solutions fail to fully consider the low throughput of traditional blockchains and cannot handle many user requests in a short period of time, thus affecting the real-time and accuracy of Healthcare and machine learning information. Therefore, there is an urgent need to seek a more efficient and sustainable method to improve the efficiency of the solution while ensuring security, and it should be able to take into account multiple dimensions such as confidentiality, integrity and multi-user scenarios. In order to more intuitively show the difference between our scheme and traditional schemes, our scheme is compared with some representative schemes [<xref ref-type="bibr" rid="ref-18">18</xref>] from multiple dimensions.</p>
</sec>
<sec id="s3">
<label>3</label>
<title>Preliminary Knowledge</title>
<sec id="s3_1">
<label>3.1</label>
<title>Bilinear Mapping</title>
<p>Suppose that <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:msub><mml:mi>G</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula> are two prime-order multiplicative cyclic groups, with <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:mi>g</mml:mi></mml:math></inline-formula> being the generator of <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula>. Then, <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:msub><mml:mi>G</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula> is a bilinear map <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:mi>e</mml:mi><mml:mo>:</mml:mo><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mi>G</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula>, and it possesses the three attributes listed below [<xref ref-type="bibr" rid="ref-28">28</xref>,<xref ref-type="bibr" rid="ref-29">29</xref>].
<list list-type="simple">
<list-item><label>1.</label><p>Bilinearity: for all <inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:mi>u</mml:mi><mml:mo>,</mml:mo><mml:mi>v</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:mi>a</mml:mi><mml:mo>,</mml:mo><mml:mi>b</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mi>Z</mml:mi><mml:mi>&#x03C1;</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>u</mml:mi><mml:mi>a</mml:mi></mml:msup><mml:mo>,</mml:mo><mml:msup><mml:mi>v</mml:mi><mml:mi>b</mml:mi></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>u</mml:mi><mml:mo>,</mml:mo><mml:mi>v</mml:mi><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>.</p></list-item>
<list-item><label>2.</label><p>Non-degeneracy: <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>u</mml:mi><mml:mo>,</mml:mo><mml:mi>v</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2260;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>.</p></list-item>
<list-item><label>3.</label><p>Computability: for all <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:mi>u</mml:mi><mml:mo>,</mml:mo><mml:mi>v</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> can be efficiently computed.</p></list-item>
</list></p>
<p>If bilinear maps and group operations in <inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> are efficiently computable, then <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:msub><mml:mi>G</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula> is said to be a bilinear group. It is worth noting that the mapping <inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:mi>e</mml:mi></mml:math></inline-formula> is symmetric, that is, <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mi>a</mml:mi></mml:msup><mml:mo>,</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mi>b</mml:mi></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>g</mml:mi><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mi>b</mml:mi></mml:msup><mml:mo>,</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mi>a</mml:mi></mml:msup><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>.</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Computing the Diffie-Hellman Problem</title>
<p>Given <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>x</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mi>p</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>G</mml:mi></mml:math></inline-formula>, and <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, there is no feasible algorithm that can calculate <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:mi>x</mml:mi><mml:mi>y</mml:mi><mml:mi>p</mml:mi></mml:math></inline-formula> through <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi></mml:math></inline-formula>, that is, there is no algorithm that can complete the calculation task within an achievable time complexity [<xref ref-type="bibr" rid="ref-30">30</xref>].</p>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Determine the Diffie-Hellman Problem</title>
<p>Given <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>x</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:mi>Z</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>G</mml:mi></mml:math></inline-formula>, and <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, there is no feasible algorithm that can determine whether the equation <inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:mi>Z</mml:mi><mml:mo>=</mml:mo><mml:mi>x</mml:mi><mml:mi>y</mml:mi><mml:mi>P</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">m</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">d</mml:mi><mml:mtext>&#x00A0;</mml:mtext><mml:mi mathvariant="normal">p</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is true through <inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>x</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mi>p</mml:mi></mml:math></inline-formula> and <italic>Z</italic>, that is, it is impossible to find an algorithm that can complete the calculation task within the achievable time complexity [<xref ref-type="bibr" rid="ref-31">31</xref>].</p>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>System Model</title>
<p>This section first focuses on the system model and entity functions, and then gives the threat model established in this paper and the security goals of the model.</p>
<sec id="s4_1">
<label>4.1</label>
<title>System Model and Entity Functions</title>
<p>The solution model of this paper is shown in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>. It is assumed that each medical institution in each country acts as a consortium chain node and cooperates to maintain a consortium chain. The scheme includes six entities: users, medical institutions, IPFS, consortium chain, customs, and key generation center (KGC). Here is the key process of the interaction: The system initialization is the first thing that KGC finishes and distributes the public and private key pairs of each entity; then, the medical institution generates a health passport for the user; finally, the health passport ciphertext is uploaded to IPFS, and the keyword index and signature are uploaded to the consortium chain as a transaction. When the user needs to visit the doctor again or go abroad, the user generates a query trapdoor and initiates a request to the consortium chain. The consortium chain returns the document storage identifier to IPFS or provides the verification result to the customs, thereby completing the passport update and verification operation.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>System model</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63964-fig-1.tif"/>
</fig>
<p><list list-type="simple">
<list-item><label>1.</label><p><bold>User:</bold> The user registers a personal health passport to go to a medical institution for treatment or go abroad for customs inspection. At the same time, multiple users can form a travel group or academic exchange group to complete multi-user verification during the inspection.</p></list-item>
<list-item><label>2.</label><p><bold>Medical institution:</bold> Generate or update a personal health passport after providing medical services to the user, and encrypt the Healthcare device data and store it in IPFS. Finally, generate a keyword index for the passport and upload it to the consortium chain as a transaction.</p></list-item>
<list-item><label>3.</label><p><bold>IPFS:</bold> IPFS is a decentralized file storage network used to store the encrypted Healthcare device data of personal health passports generated by medical institutions.</p></list-item>
<list-item><label>4.</label><p><bold>Alliance chain:</bold> Each country selects medical institution representatives to form alliance chain nodes to jointly complete the release and consensus of transactions. Furthermore, it is the responsibility of the alliance chain to return the result of the passport verification process to customs or to query the ciphertext storage index using the user-generated trapdoor.</p></list-item>
<list-item><label>5.</label><p><bold>Customs:</bold> Customs staff need to obtain the verification results of the alliance chain on the user&#x2019;s passport.</p></list-item>
<list-item><label>6.</label><p><bold>KGC:</bold> In charge of creating all entities&#x2019; partial private keys and system settings.</p></list-item>
</list></p>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Threat Model</title>
<p>The threat model established in this paper is as follows.
<list list-type="simple">
<list-item><label>1.</label><p>The alliance chain node may send invalid search results to the user after receiving a search request to save computational resources.</p></list-item>
<list-item><label>2.</label><p>The IPFS storage network is forthright and inquisitive. Although it can faithfully carry out the user&#x2019;s commands, it will use data like keyword indexes supplied by the user to make assumptions.</p></list-item>
</list></p>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>Security Goal</title>
<p>Assuming that all blockchain nodes and customs inspectors are semi-honest parties, attackers may eavesdrop on communications between users and other entities. Based on this assumption, this paper proposes the following security goals.
<list list-type="simple">
<list-item><label>1.</label><p><bold>Confidentiality:</bold> Health passport data contains users&#x2019; personal privacy information, and there may be a risk of leakage during sharing. Therefore, ensuring the confidentiality of health passport of Healthcare device data becomes one of the goals of this scheme.</p></list-item>
<list-item><label>2.</label><p><bold>Traceability and non-repudiation:</bold> In order to resolve disputes between doctors and patients and possible liability issues after medical treatment, the scheme should be able to effectively prevent malicious attackers from tampering with health passport data records. Therefore, the scheme is required to have traceability (non-repudiation after tracing) and the characteristics of being difficult to tamper with.</p></list-item>
<list-item><label>3.</label><p><bold>Non-forgeability:</bold> When customs conduct epidemic prevention inspections, malicious attackers may forge the health passports of legitimate users to deceive inspectors. Therefore, the scheme is required to prevent attackers from forging health passports.</p></list-item>
</list></p>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Solution Design</title>
<p>In order to solve the privacy leakage problem faced by the current health passport in the process of sharing and verification, as well as the problem that the blockchain throughput is low and cannot match the real-time performance of smart medical care, this section gives a specific solution design. The solution considers the multi-user scenario where users travel in groups, and divides the solution into two scenarios: single user and multi-user. The solution mainly includes four stages: system initialization, health passport encryption and storage, health passport update, and health passport verification. The symbols are shown in <xref ref-type="table" rid="table-1">Table 1</xref>.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Explanation of symbols</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Parameter</th>
<th>Meaning</th>
</tr>
</thead>
<tbody>
<tr>
<td>SK</td>
<td>Master key</td>
</tr>
<tr>
<td>CP</td>
<td>Public parameters</td>
</tr>
<tr>
<td><inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td>User public and private key pair</td>
</tr>
<tr>
<td><inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>Personal health passport</td>
</tr>
<tr>
<td><inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:msub><mml:mi>P</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>Health passport ciphertext</td>
</tr>
<tr>
<td><inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>User signature</td>
</tr>
<tr>
<td><inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:mi>P</mml:mi><mml:mi>U</mml:mi><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>Health passport number</td>
</tr>
<tr>
<td><inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:msub><mml:mi>I</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>Keyword index</td>
</tr>
<tr>
<td><inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>x</mml:mi><mml:mi>f</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>Ciphertext retrieval identifier</td>
</tr>
<tr>
<td><inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:msub><mml:mi>T</mml:mi><mml:mi>c</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>Transaction</td>
</tr>
<tr>
<td>SToken</td>
<td>Search trapdoor</td>
</tr>
<tr>
<td><inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:mi>&#x03B4;</mml:mi></mml:math></inline-formula></td>
<td>Aggregate signature</td>
</tr>
<tr>
<td>index</td>
<td>Block sequence number</td>
</tr>
<tr>
<td>OID</td>
<td>Block node number</td>
</tr>
<tr>
<td>M</td>
<td>Packaged transaction</td>
</tr>
<tr>
<td>D</td>
<td>Message summary</td>
</tr>
<tr>
<td>NID</td>
<td>Node Identifier</td>
</tr>
</tbody>
</table>
</table-wrap>
<sec id="s5_1">
<label>5.1</label>
<title>System Initialization</title>
<p>In this stage, the key generation center generates system parameters and public and private key pairs of each entity.</p>
<sec id="s5_1_1">
<label>5.1.1</label>
<title>System Establishment</title>
<p>Input security parameter <inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:mi>&#x03BB;</mml:mi></mml:math></inline-formula>, the Key Generation Center (KGC) selects two multiplicative cyclic groups <inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:msub><mml:mi>G</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula> of order <inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:mi>p</mml:mi></mml:math></inline-formula>, defines bilinear map <inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:mi>e</mml:mi><mml:mo>:</mml:mo><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mi>G</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula>, where the generator of <inline-formula id="ieqn-37"><mml:math id="mml-ieqn-37"><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> is <inline-formula id="ieqn-38"><mml:math id="mml-ieqn-38"><mml:mi>g</mml:mi></mml:math></inline-formula>. Randomly select <inline-formula id="ieqn-39"><mml:math id="mml-ieqn-39"><mml:mi>s</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>p</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, set the master key <inline-formula id="ieqn-40"><mml:math id="mml-ieqn-40"><mml:mi>S</mml:mi><mml:mi>K</mml:mi><mml:mo>=</mml:mo><mml:mi>s</mml:mi></mml:math></inline-formula>, and calculate:
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mi>s</mml:mi></mml:msup><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>Select six collision-resistant hash functions <inline-formula id="ieqn-41"><mml:math id="mml-ieqn-41"><mml:msub><mml:mi>H</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>:</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:msup><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo></mml:msup><mml:mo>&#x00D7;</mml:mo><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>p</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>,</mml:mo><mml:mspace width="1em" /><mml:msub><mml:mi>H</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>:</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:msup><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo></mml:msup><mml:mo>&#x00D7;</mml:mo><mml:msubsup><mml:mi>G</mml:mi><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:msubsup><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>p</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>,</mml:mo><mml:mspace width="1em" /><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>:</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:msup><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>p</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>,</mml:mo><mml:mspace width="1em" /><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo>:</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mi>G</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>4</mml:mn></mml:msub><mml:mo>:</mml:mo><mml:msub><mml:mi>G</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>,</mml:mo><mml:mspace width="1em" /><mml:msub><mml:mi>H</mml:mi><mml:mn>5</mml:mn></mml:msub><mml:mo>:</mml:mo><mml:msubsup><mml:mi>G</mml:mi><mml:mn>2</mml:mn><mml:mn>2</mml:mn></mml:msubsup><mml:mo>&#x00D7;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:msup><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:msup><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mi>n</mml:mi></mml:msup></mml:math></inline-formula>, and publish the public parameter <italic>CP</italic> as follows:
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:mi>C</mml:mi><mml:mi>P</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>,</mml:mo><mml:mi>e</mml:mi><mml:mo>,</mml:mo><mml:mi>S</mml:mi><mml:mi>K</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>4</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>5</mml:mn></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>.</mml:mo></mml:math></disp-formula></p>
</sec>
<sec id="s5_1_2">
<label>5.1.2</label>
<title>Generate Partial Keys</title>
<p>Based on the master key<italic>SK</italic> and user identity <inline-formula id="ieqn-42"><mml:math id="mml-ieqn-42"><mml:mi>I</mml:mi><mml:mi>D</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:msup><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo></mml:msup></mml:math></inline-formula>, KGC randomly selects <inline-formula id="ieqn-43"><mml:math id="mml-ieqn-43"><mml:msub><mml:mi>r</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>p</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, and calculates:
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:msub><mml:mi>R</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>r</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="1em" /><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mspace width="1em" /><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>r</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>KGC sends the partial private key <inline-formula id="ieqn-44"><mml:math id="mml-ieqn-44"><mml:msub><mml:mi>D</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> to user <inline-formula id="ieqn-45"><mml:math id="mml-ieqn-45"><mml:mi>i</mml:mi></mml:math></inline-formula> through a secure channel.</p>
</sec>
<sec id="s5_1_3">
<label>5.1.3</label>
<title>Generate a Complete Public-Private Key Pair</title>
<p>User <inline-formula id="ieqn-46"><mml:math id="mml-ieqn-46"><mml:mi>i</mml:mi></mml:math></inline-formula> randomly selects <inline-formula id="ieqn-47"><mml:math id="mml-ieqn-47"><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>p</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, and calculates:
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:msub><mml:mi>X</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>Generate a complete public key <inline-formula id="ieqn-48"><mml:math id="mml-ieqn-48"><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>X</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and a private key <inline-formula id="ieqn-49"><mml:math id="mml-ieqn-49"><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>.</p>
</sec>
<sec id="s5_1_4">
<label>5.1.4</label>
<title>Other Entities in the System</title>
<p>Other entities in the system generate their own public-private key pairs according to the above steps. The public-private key pairs of hospital <inline-formula id="ieqn-50"><mml:math id="mml-ieqn-50"><mml:mi>h</mml:mi></mml:math></inline-formula> and alliance chain node <italic>C</italic> are represented as:
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>X</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mspace width="1em" /><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>
<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>c</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mi>c</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>X</mml:mi><mml:mi>c</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mspace width="1em" /><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>c</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>c</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>c</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
</sec>
</sec>
<sec id="s5_2">
<label>5.2</label>
<title>Health Passport Encryption and Storage</title>
<p>After the user&#x2019;s first visit, the medical institution generates a health passport for the user and stores the passport ciphertext of Healthcare device data on IPFS. Then, the relevant keyword index, user signature, and ciphertext retrieval identifier are uploaded to the alliance chain as a transaction. The alliance chain node is responsible for packaging these transactions and executing the improved weak consensus mechanism to ensure that the transaction is successfully recorded on the chain.</p>
<list list-type="simple">
<list-item><label>1.</label><p><bold>User Visit:</bold> After user <inline-formula id="ieqn-51"><mml:math id="mml-ieqn-51"><mml:mi>i</mml:mi></mml:math></inline-formula> visits hospital <inline-formula id="ieqn-52"><mml:math id="mml-ieqn-52"><mml:mi>h</mml:mi></mml:math></inline-formula>, hospital <inline-formula id="ieqn-53"><mml:math id="mml-ieqn-53"><mml:mi>h</mml:mi></mml:math></inline-formula> generates a health passport for user <inline-formula id="ieqn-54"><mml:math id="mml-ieqn-54"><mml:mi>i</mml:mi></mml:math></inline-formula>, including the user&#x2019;s personal information, health passport number <inline-formula id="ieqn-55"><mml:math id="mml-ieqn-55"><mml:mi>P</mml:mi><mml:mi>U</mml:mi><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and visit information. The visit information includes the visit time, visit location, and personal medical records.</p></list-item>
<list-item><label>2.</label><p><bold>Passport Encryption:</bold> Hospital <inline-formula id="ieqn-56"><mml:math id="mml-ieqn-56"><mml:mi>h</mml:mi></mml:math></inline-formula> randomly selects a secret value <inline-formula id="ieqn-57"><mml:math id="mml-ieqn-57"><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>p</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, calculates:
<disp-formula id="eqn-7"><label>(7)</label><mml:math id="mml-eqn-7" display="block"><mml:msub><mml:mi>A</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mi>X</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mspace width="1em" /><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>P</mml:mi><mml:mi>U</mml:mi><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:msub><mml:mi>B</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-58"><mml:math id="mml-ieqn-58"><mml:msub><mml:mi>B</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>k</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mtext>passport</mml:mtext></mml:math></inline-formula>, and the ciphertext of the health passport is:
<disp-formula id="eqn-8"><label>(8)</label><mml:math id="mml-eqn-8" display="block"><mml:msub><mml:mi>C</mml:mi><mml:mrow><mml:msub><mml:mi>P</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>A</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>B</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>.</mml:mo></mml:math></disp-formula></p>
</list-item>
<list-item><label>3.</label><p><bold>Passport Storage:</bold> The passport ciphertext <inline-formula id="ieqn-59"><mml:math id="mml-ieqn-59"><mml:msub><mml:mi>C</mml:mi><mml:mrow><mml:msub><mml:mi>P</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> is uploaded to IPFS, and the corresponding ciphertext retrieval identifier <inline-formula id="ieqn-60"><mml:math id="mml-ieqn-60"><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>x</mml:mi></mml:math></inline-formula> is returned.</p></list-item>
<list-item><label>4.</label><p><bold>Passport Signature: </bold>The user randomly selects <inline-formula id="ieqn-61"><mml:math id="mml-ieqn-61"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>p</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, and calculates the private key <inline-formula id="ieqn-62"><mml:math id="mml-ieqn-62"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> of user <inline-formula id="ieqn-63"><mml:math id="mml-ieqn-63"><mml:mi>i</mml:mi></mml:math></inline-formula>. The user signature <inline-formula id="ieqn-64"><mml:math id="mml-ieqn-64"><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>V</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is computed as the signature of user <inline-formula id="ieqn-65"><mml:math id="mml-ieqn-65"><mml:mi>i</mml:mi></mml:math></inline-formula> on the passport.</p></list-item>
<list-item><label>5.</label><p><bold>Transaction Upload:</bold> Hospital <inline-formula id="ieqn-66"><mml:math id="mml-ieqn-66"><mml:mi>h</mml:mi></mml:math></inline-formula> uses the health passport number <inline-formula id="ieqn-67"><mml:math id="mml-ieqn-67"><mml:mi>P</mml:mi><mml:mi>U</mml:mi><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> to generate the keyword index <inline-formula id="ieqn-68"><mml:math id="mml-ieqn-68"><mml:msub><mml:mi>I</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>5</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>P</mml:mi><mml:mi>U</mml:mi><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2225;</mml:mo><mml:mi>P</mml:mi><mml:mi>U</mml:mi><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, combines the signature <inline-formula id="ieqn-69"><mml:math id="mml-ieqn-69"><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and the ciphertext retrieval identifier index, and constructs the transaction:</p>
<p><disp-formula id="eqn-9"><label>(9)</label><mml:math id="mml-eqn-9" display="block"><mml:msub><mml:mi>T</mml:mi><mml:mi>c</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>I</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>x</mml:mi><mml:mi>f</mml:mi></mml:msub><mml:mo>.</mml:mo></mml:math></disp-formula>Finally, the hospital uploads the transaction <inline-formula id="ieqn-70"><mml:math id="mml-ieqn-70"><mml:msub><mml:mi>T</mml:mi><mml:mi>c</mml:mi></mml:msub></mml:math></inline-formula> to the consortium chain. The transaction structure is shown in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>.</p>
</list-item>
<list-item><label>6.</label><p><bold>Alliance Chain Consensus:</bold> The alliance chain nodes receive the transaction <inline-formula id="ieqn-71"><mml:math id="mml-ieqn-71"><mml:msub><mml:mi>T</mml:mi><mml:mi>c</mml:mi></mml:msub></mml:math></inline-formula> uploaded by the hospital, reach consensus on it through the improved weak consensus mechanism, and package it on the chain. The specific scheme of the improved consensus mechanism is as follows:
<list list-type="simple">
<list-item><label>(a)</label><p>Transaction <inline-formula id="ieqn-72"><mml:math id="mml-ieqn-72"><mml:msub><mml:mi>T</mml:mi><mml:mi>c</mml:mi></mml:msub></mml:math></inline-formula> is submitted to the alliance chain and broadcast in the P2P network composed of each hospital node.</p></list-item>
<list-item><label>(b)</label><p>When a node <italic>A</italic> receives the transaction <inline-formula id="ieqn-73"><mml:math id="mml-ieqn-73"><mml:msub><mml:mi>T</mml:mi><mml:mi>c</mml:mi></mml:msub></mml:math></inline-formula> sent by the client, the node first verifies the signature and integrity of <inline-formula id="ieqn-74"><mml:math id="mml-ieqn-74"><mml:msub><mml:mi>T</mml:mi><mml:mi>c</mml:mi></mml:msub></mml:math></inline-formula>, and then stores the transaction in the local transaction pool. When the number of transactions to be stored reaches the preset interval, the node packages the transaction and writes it into a new block, generating a prepare message <inline-formula id="ieqn-75"><mml:math id="mml-ieqn-75"><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:mtext>Prepare</mml:mtext><mml:mo>,</mml:mo><mml:mtext>index</mml:mtext><mml:mo>,</mml:mo><mml:mtext>OID</mml:mtext><mml:mo>,</mml:mo><mml:mi>M</mml:mi><mml:mo>,</mml:mo><mml:mi>D</mml:mi><mml:mo>,</mml:mo><mml:mtext>proof</mml:mtext><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> for the new block, and broadcasts the <monospace>Prepare</monospace> message to the P2P network. Among them, <inline-formula id="ieqn-76"><mml:math id="mml-ieqn-76"><mml:mtext>index</mml:mtext></mml:math></inline-formula> is the ordered sequence number of the block generated by the current node, <inline-formula id="ieqn-77"><mml:math id="mml-ieqn-77"><mml:mtext>OID</mml:mtext></mml:math></inline-formula> is the node number that generates this block, <italic>M</italic> is the packaged transaction, <italic>D</italic> is the message digest, and Proof is the proof that node <italic>A</italic> has inserted the block into the local chain.</p></list-item>
<list-item><label>(c)</label><p>Assume that another random node <italic>B</italic> receives the <monospace>Prepare</monospace> message from node <italic>A</italic> that generated this message. The node will check that the <monospace>Prepare</monospace> message is authentic and signed. Once the validation is approved, a <monospace>commit</monospace> message <inline-formula id="ieqn-78"><mml:math id="mml-ieqn-78"><mml:mo fence="false" stretchy="false">&#x27E8;</mml:mo><mml:mtext>Commit</mml:mtext><mml:mo>,</mml:mo><mml:mtext>index</mml:mtext><mml:mo>,</mml:mo><mml:mi>D</mml:mi><mml:mo>,</mml:mo><mml:mtext>OID</mml:mtext><mml:mo>,</mml:mo><mml:mtext>NID</mml:mtext><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> is generated. Only the summary <italic>D</italic> of the message is broadcast, and <inline-formula id="ieqn-79"><mml:math id="mml-ieqn-79"><mml:mtext>NID</mml:mtext></mml:math></inline-formula> is the node that communicated with the P2P network by sending a <monospace>Commit</monospace> message.</p></list-item>
<list-item><label>(d)</label><p>When node <italic>B</italic> receives <inline-formula id="ieqn-80"><mml:math id="mml-ieqn-80"><mml:mn>2</mml:mn><mml:mi>f</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> messages sent by other nodes, it indicates that the transaction has reached a consensus within the consensus node and can be put on the chain. In addition to adding the latest block to its local chain, the node verifies that the index of blocks and the block numbers generated by other nodes are incremented in order to achieve relative consistency between the blocks generated by each node.</p></list-item>
</list></p></list-item>
</list>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Transaction structure</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63964-fig-2.tif"/>
</fig>
</sec>
<sec id="s5_3">
<label>5.3</label>
<title>Update of Health Passport</title>
<p>When users visit the doctor again, they need to obtain passport data, which is updated and stored by the medical institution. The steps are as follows:
<list list-type="simple">
<list-item><label>1.</label><p><bold>Generate Trapdoor:</bold> User <inline-formula id="ieqn-81"><mml:math id="mml-ieqn-81"><mml:mi>i</mml:mi></mml:math></inline-formula> randomly selects the secret value <inline-formula id="ieqn-82"><mml:math id="mml-ieqn-82"><mml:msub><mml:mi>l</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>p</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, and <inline-formula id="ieqn-83"><mml:math id="mml-ieqn-83"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> as the query trapdoor. User <inline-formula id="ieqn-84"><mml:math id="mml-ieqn-84"><mml:mi>i</mml:mi></mml:math></inline-formula> submits <inline-formula id="ieqn-85"><mml:math id="mml-ieqn-85"><mml:mi>S</mml:mi><mml:mi>T</mml:mi><mml:mi>o</mml:mi><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>n</mml:mi></mml:math></inline-formula> to the alliance chain node and initiates a search request.</p></list-item>
<list-item><label>2.</label><p><bold>Data Retrieval:</bold> After receiving the request, the alliance chain node C verifies whether the conditions <inline-formula id="ieqn-86"><mml:math id="mml-ieqn-86"><mml:msub><mml:mi>I</mml:mi><mml:mi>K</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>5</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mfrac><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:msubsup><mml:mi>&#x03C4;</mml:mi><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mi>x</mml:mi><mml:mi>c</mml:mi></mml:msub></mml:mrow></mml:msubsup></mml:mfrac><mml:mo>,</mml:mo><mml:msub><mml:mi>X</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2225;</mml:mo><mml:mi>P</mml:mi><mml:mi>U</mml:mi><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> holds. The node extracts the index <inline-formula id="ieqn-87"><mml:math id="mml-ieqn-87"><mml:mi>f</mml:mi></mml:math></inline-formula> in the corresponding transaction, searches for the ciphertext <inline-formula id="ieqn-88"><mml:math id="mml-ieqn-88"><mml:msub><mml:mi>C</mml:mi><mml:mrow><mml:msub><mml:mi>P</mml:mi><mml:mi>r</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> from IPFS, and returns it to the user.</p></list-item>
<list-item><label>3.</label><p><bold>Decryption and Verification:</bold> The user calculates the Healthcare and machine learning document data as:
<disp-formula id="eqn-10"><label>(10)</label><mml:math id="mml-eqn-10" display="block"><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:msub><mml:mi>B</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mrow><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>A</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>P</mml:mi><mml:mi>U</mml:mi><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mfrac></mml:mrow></mml:msup></mml:mrow></mml:mfrac><mml:mo>.</mml:mo></mml:math></disp-formula></p>
</list-item>
<list-item><label>4.</label><p><bold>Medical Treatment and Update:</bold> After the medical institution provides medical services, it updates the user&#x2019;s health passport of Healthcare device data and stores it back on the chain.</p></list-item>
</list></p>
</sec>
<sec id="s5_4">
<label>5.4</label>
<title>Verification of Health Passport</title>
<sec id="s5_4_1">
<label>5.4.1</label>
<title>Single User Verification</title>
<p>To address the higher computational overhead in single-user scenarios, we propose optimizations to enhance efficiency while maintaining security.
<list list-type="simple">
<list-item><label>1.</label><p><bold>Generate a Trapdoor:</bold> The user generates a query trapdoor based on the health passport number <italic>PUID</italic> and initiates a request to the alliance chain to retrieve the user&#x2019;s signature.</p></list-item>
<list-item><label>2.</label><p><bold>Obtain Signature:</bold> Upon receiving the request, the alliance chain node verifies the keyword index <italic>IK</italic> in the transaction <inline-formula id="ieqn-89"><mml:math id="mml-ieqn-89"><mml:msub><mml:mi>T</mml:mi><mml:mi>c</mml:mi></mml:msub></mml:math></inline-formula> using:
<disp-formula id="eqn-11"><label>(11)</label><mml:math id="mml-eqn-11" display="block"><mml:mi>I</mml:mi><mml:mi>K</mml:mi><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>5</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mfrac><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:msubsup><mml:mi>&#x03C4;</mml:mi><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mi>x</mml:mi><mml:mi>c</mml:mi></mml:msub></mml:mrow></mml:msubsup></mml:mfrac><mml:mo>,</mml:mo><mml:msub><mml:mi>X</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2225;</mml:mo><mml:mi>P</mml:mi><mml:mi>U</mml:mi><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>If valid, the node retrieves and returns the corresponding user signature <inline-formula id="ieqn-90"><mml:math id="mml-ieqn-90"><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>.</p></list-item>
<list-item><label>3.</label><p><bold>Optimize Signature Verification:</bold> Instead of performing full bilinear pairing operations, which are computationally expensive, we optimize single-user verification by:
<list list-type="bullet">
<list-item>
<p><bold>Precomputing Pairing Results:</bold> Frequently used cryptographic values are cached to reduce redundant computations.</p></list-item>
<list-item>
<p><bold>Lightweight Hash-Based Authentication:</bold> Combining a lightweight hash function with elliptic curve signatures to minimize verification overhead.</p></list-item>
<list-item>
<p><bold>Hybrid Storage Strategy:</bold> Leveraging off-chain verification for certain non-critical attributes while keeping essential verification on-chain to reduce transaction load.</p></list-item>
</list></p></list-item>
<list-item><label>4.</label><p><bold>Verify Signature:</bold> The alliance chain node calls the verification smart contract and computes:
<disp-formula id="eqn-12"><label>(12)</label><mml:math id="mml-eqn-12" display="block"><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>V</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>P</mml:mi><mml:mrow><mml:mi>p</mml:mi><mml:mi>u</mml:mi><mml:mi>b</mml:mi></mml:mrow><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>X</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>U</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>If the condition holds, the user&#x2019;s passport status is validated and returned to the customs staff.</p></list-item>
</list></p>
<p>While hybrid on-chain and off-chain storage has been explored in previous studies, our approach introduces key optimizations that enhance efficiency and security. Unlike conventional models that rely on basic off-chain storage, we integrate searchable encryption with IPFS, ensuring that only encrypted data is stored off-chain while a lightweight index remains on-chain for efficient retrieval. This design reduces on-chain storage overhead, minimizes blockchain transaction costs, and accelerates query response times. Additionally, our approach optimizes multi-user verification and retrieval, as demonstrated in our experimental results, showing lower communication overhead and improved scalability in contrast to existing hybrid storage techniques.</p>
</sec>
<sec id="s5_4_2">
<label>5.4.2</label>
<title>Multi-User Verification</title>
<p>To improve verification efficiency, when group users (such as international travel groups, academic exchange groups, etc.) plan to travel abroad or conduct international exchanges, the team aggregates signatures to accept the customs Healthcare and machine learning status check.</p>
</sec>
<sec id="s5_4_3">
<label>5.4.3</label>
<title>Obtaining Personal Signatures</title>
<p><inline-formula id="ieqn-91"><mml:math id="mml-ieqn-91"><mml:mi>n</mml:mi></mml:math></inline-formula> users in the group generate query traps based on their passport numbers to retrieve their respective signatures <inline-formula id="ieqn-92"><mml:math id="mml-ieqn-92"><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> (<inline-formula id="ieqn-93"><mml:math id="mml-ieqn-93"><mml:mn>1</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>n</mml:mi></mml:math></inline-formula>). The process is consistent with <xref ref-type="sec" rid="s4_1">Section 4.1</xref>.</p>
</sec>
<sec id="s5_4_4">
<label>5.4.4</label>
<title>Generate Aggregate Signature</title>
<p>The aggregator in the team calculates the hash set <inline-formula id="ieqn-94"><mml:math id="mml-ieqn-94"><mml:mtext>Hash</mml:mtext><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mtext>hash</mml:mtext><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mtext>hash</mml:mtext><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mtext>hash</mml:mtext><mml:mi>n</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> based on the signature set <inline-formula id="ieqn-95"><mml:math id="mml-ieqn-95"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-96"><mml:math id="mml-ieqn-96"><mml:msub><mml:mtext>hash</mml:mtext><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mtext>hash</mml:mtext><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>V</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mspace width="1em" /><mml:mn>1</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>n</mml:mi><mml:mo>.</mml:mo></mml:math></inline-formula> Let <inline-formula id="ieqn-97"><mml:math id="mml-ieqn-97"><mml:mi>t</mml:mi><mml:mo>=</mml:mo><mml:msub><mml:mtext>hash</mml:mtext><mml:mi>n</mml:mi></mml:msub></mml:math></inline-formula>, and get the aggregate signature <inline-formula id="ieqn-98"><mml:math id="mml-ieqn-98"><mml:mi>&#x03B4;</mml:mi><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo></mml:math></inline-formula> and initiate a verification request to the consortium chain.</p>
</sec>
<sec id="s5_4_5">
<label>5.4.5</label>
<title>Verify the Aggregate Signature</title>
<p>The consortium chain node calls the verification smart contract and calculates <inline-formula id="ieqn-99"><mml:math id="mml-ieqn-99"><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-100"><mml:math id="mml-ieqn-100"><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> for all <inline-formula id="ieqn-101"><mml:math id="mml-ieqn-101"><mml:mn>1</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>n</mml:mi></mml:math></inline-formula>. It verifies that
<disp-formula id="eqn-13"><label>(13)</label><mml:math id="mml-eqn-13" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mi>t</mml:mi><mml:mo>=</mml:mo></mml:mtd><mml:mtd><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.470em" minsize="2.470em">(</mml:mo></mml:mrow></mml:mstyle><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.470em" minsize="2.470em">(</mml:mo></mml:mrow></mml:mstyle><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.470em" minsize="2.470em">(</mml:mo></mml:mrow></mml:mstyle><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.470em" minsize="2.470em">(</mml:mo></mml:mrow></mml:mstyle><mml:mi>e</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">(</mml:mo></mml:mrow></mml:mstyle><mml:msub><mml:mi>R</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>P</mml:mi><mml:mrow><mml:mi>p</mml:mi><mml:mi>b</mml:mi></mml:mrow><mml:mrow><mml:msub><mml:mi>t</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msubsup><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>X</mml:mi><mml:mn>1</mml:mn><mml:mrow><mml:msub><mml:mi>b</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">)</mml:mo></mml:mrow></mml:mstyle><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">(</mml:mo></mml:mrow></mml:mstyle><mml:msubsup><mml:mi>U</mml:mi><mml:mn>1</mml:mn><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">)</mml:mo></mml:mrow></mml:mstyle><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.470em" minsize="2.470em">)</mml:mo></mml:mrow></mml:mstyle><mml:mo>+</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi>e</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">(</mml:mo></mml:mrow></mml:mstyle><mml:msub><mml:mi>R</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>P</mml:mi><mml:mrow><mml:mi>p</mml:mi><mml:mi>b</mml:mi></mml:mrow><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msubsup><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>X</mml:mi><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">)</mml:mo></mml:mrow></mml:mstyle><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">(</mml:mo></mml:mrow></mml:mstyle><mml:msubsup><mml:mi>U</mml:mi><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">)</mml:mo></mml:mrow></mml:mstyle><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.470em" minsize="2.470em">)</mml:mo></mml:mrow></mml:mstyle><mml:mo>+</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>+</mml:mo><mml:mi>e</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">(</mml:mo></mml:mrow></mml:mstyle><mml:msub><mml:mi>R</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>P</mml:mi><mml:mrow><mml:mi>p</mml:mi><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>n</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>X</mml:mi><mml:mi>n</mml:mi><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">)</mml:mo></mml:mrow></mml:mstyle><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.470em" minsize="2.470em">)</mml:mo></mml:mrow></mml:mstyle><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.470em" minsize="2.470em">)</mml:mo></mml:mrow></mml:mstyle><mml:mo>,</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>holds. If true, it means that the passport status of the users in the group is normal, and the result is returned to the customs staff; if not, it means that there are malicious users in the group and someone has forged the health passport. To find malicious users, for <inline-formula id="ieqn-102"><mml:math id="mml-ieqn-102"><mml:mn>1</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>n</mml:mi></mml:math></inline-formula>, calculate
<disp-formula id="eqn-14"><label>(14)</label><mml:math id="mml-eqn-14" display="block"><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>hash</mml:mtext></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>P</mml:mi><mml:mrow><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>X</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>U</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>in sequence. Determine whether <inline-formula id="ieqn-103"><mml:math id="mml-ieqn-103"><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mtext>hash</mml:mtext><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is true. If the equation is not true, the passport status of user <inline-formula id="ieqn-104"><mml:math id="mml-ieqn-104"><mml:mi>i</mml:mi></mml:math></inline-formula> is abnormal.</p>
</sec>
</sec>
</sec>
<sec id="s6">
<label>6</label>
<title>Security Analysis</title>
<sec id="s6_1">
<label>6.1</label>
<title>Correctness</title>
<p><list list-type="simple">
<list-item><label>1.</label><p><bold>Retrieval Correctness:</bold> For the equation <inline-formula id="ieqn-105"><mml:math id="mml-ieqn-105"><mml:msub><mml:mi>I</mml:mi><mml:mi>K</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>5</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mfrac><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:msubsup><mml:mi>&#x03C4;</mml:mi><mml:mi>&#x03BB;</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:mfrac><mml:mo>,</mml:mo><mml:msub><mml:mi>X</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mtext>PUID</mml:mtext><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> in step (2) in <xref ref-type="sec" rid="s4_3">Section 4.3</xref>, the derivation process is shown in <xref ref-type="disp-formula" rid="eqn-15">Eq. (15)</xref>:
<disp-formula id="eqn-15"><label>(15)</label><mml:math id="mml-eqn-15" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:msub><mml:mi>H</mml:mi><mml:mn>5</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mfrac><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mrow><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:msub><mml:mi>x</mml:mi><mml:mn>4</mml:mn></mml:msub></mml:mrow></mml:mfrac><mml:mo>,</mml:mo><mml:msub><mml:mi>X</mml:mi><mml:mn>4</mml:mn></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>PUID</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:msub><mml:mi>H</mml:mi><mml:mn>5</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mfrac><mml:mrow><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>PUID</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mfrac></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>X</mml:mi><mml:mi>c</mml:mi><mml:mrow><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup></mml:mrow><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mi>t</mml:mi></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow></mml:msup></mml:mfrac><mml:mo>,</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mi>t</mml:mi></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>PUID</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:msub><mml:mi>H</mml:mi><mml:mn>5</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mfrac><mml:mrow><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>PUID</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mfrac><mml:mn>1</mml:mn><mml:msup><mml:mi>x</mml:mi><mml:mn>2</mml:mn></mml:msup></mml:mfrac></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mi>x</mml:mi></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mi>t</mml:mi></mml:msup></mml:mrow><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mi>i</mml:mi></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mi>x</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow></mml:msup></mml:mfrac><mml:mo>,</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mi>x</mml:mi></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>PUID</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:msub><mml:mi>H</mml:mi><mml:mn>5</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>PUID</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>PUID</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:msub><mml:mi>I</mml:mi><mml:mi>&#x03BA;</mml:mi></mml:msub><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
</list-item>
<list-item><label>2.</label><p><bold>Decryption Correctness:</bold> For step (3) in <xref ref-type="sec" rid="s5_3">Section 5.3</xref>, where the passport is given as <inline-formula id="ieqn-106"><mml:math id="mml-ieqn-106"><mml:mfrac><mml:msub><mml:mi>B</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mrow><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>A</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mtext>PUID</mml:mtext><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mfrac></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:mfrac></mml:math></inline-formula> in step (3) of <xref ref-type="sec" rid="s5_3">Section 5.3</xref>, the derivation process is shown in <xref ref-type="disp-formula" rid="eqn-16">Eq. (16)</xref>:
<disp-formula id="eqn-16"><label>(16)</label><mml:math id="mml-eqn-16" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:msub><mml:mrow><mml:mtext>passport</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:mtd><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:msub><mml:mi>B</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mrow><mml:mi>e</mml:mi><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>A</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>PUID</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mfrac></mml:mrow></mml:msup></mml:mrow></mml:mfrac><mml:mo>=</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mfrac><mml:mrow><mml:mi>k</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mrow><mml:mtext>passport</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>X</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>PUID</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mfrac></mml:mrow></mml:msup></mml:mrow></mml:mfrac><mml:mo>=</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mfrac><mml:mrow><mml:mi>k</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mrow><mml:mtext>passport</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>X</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>PUID</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mfrac></mml:mrow></mml:msup></mml:mrow></mml:mfrac><mml:mo>=</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mfrac><mml:mrow><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>PUID</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>PUID</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mfrac></mml:mrow></mml:msup></mml:mrow></mml:mfrac><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mrow><mml:mtext>passport</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
</list-item>
<list-item><label>3.</label><p><bold>Signature Correctness:</bold> For the equation in <xref ref-type="sec" rid="s5_4_1">Section 5.4.1</xref>, <inline-formula id="ieqn-107"><mml:math id="mml-ieqn-107"><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>V</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>X</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>U</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></inline-formula> the detailed derivation and proof are shown in <xref ref-type="disp-formula" rid="eqn-18">Eq. (18)</xref>:
<disp-formula id="eqn-17"><label>(17)</label><mml:math id="mml-eqn-17" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>V</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>&#x03B1;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:msub><mml:mi>&#x03BC;</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>r</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi mathvariant="normal">&#x2032;</mml:mi><mml:mi>H</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>&#x210F;</mml:mi><mml:mrow><mml:msub><mml:mi>x</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mrow></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03BC;</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>r</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>x</mml:mi><mml:mi>j</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03BD;</mml:mi><mml:mi>j</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>s</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>X</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>U</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>P</mml:mi><mml:mrow><mml:mrow><mml:mtext>p</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:mrow><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>P</mml:mi><mml:mrow><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>X</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>U</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B1;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
</list-item>
<list-item><label>4.</label><p><bold>Aggregate Signature Correctness:</bold> For the equation in <xref ref-type="sec" rid="s5_4_2">Section 5.4.2</xref>:</p>
<p><disp-formula id="eqn-18"><label>(18)</label><mml:math id="mml-eqn-18" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:mi>t</mml:mi><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.470em" minsize="2.470em">(</mml:mo></mml:mrow></mml:mstyle><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.470em" minsize="2.470em">(</mml:mo></mml:mrow></mml:mstyle><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.470em" minsize="2.470em">(</mml:mo></mml:mrow></mml:mstyle><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.047em" minsize="2.047em">(</mml:mo></mml:mrow></mml:mstyle><mml:mi>e</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">(</mml:mo></mml:mrow></mml:mstyle><mml:msub><mml:mi>R</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>P</mml:mi><mml:mrow><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msubsup><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>X</mml:mi><mml:mn>1</mml:mn><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">)</mml:mo></mml:mrow></mml:mstyle><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">(</mml:mo></mml:mrow></mml:mstyle><mml:msubsup><mml:mi>U</mml:mi><mml:mn>1</mml:mn><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">)</mml:mo></mml:mrow></mml:mstyle><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.047em" minsize="2.047em">)</mml:mo></mml:mrow></mml:mstyle></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mo>+</mml:mo><mml:mi>e</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">(</mml:mo></mml:mrow></mml:mstyle><mml:msub><mml:mi>R</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>P</mml:mi><mml:mrow><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:mrow></mml:msubsup><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>X</mml:mi><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:msub><mml:mi>t</mml:mi><mml:mn>4</mml:mn></mml:msub></mml:mrow></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">)</mml:mo></mml:mrow></mml:mstyle><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">(</mml:mo></mml:mrow></mml:mstyle><mml:msubsup><mml:mi>U</mml:mi><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>z</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">)</mml:mo></mml:mrow></mml:mstyle><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.470em" minsize="2.470em">)</mml:mo></mml:mrow></mml:mstyle><mml:mo>&#x22EF;</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mo>+</mml:mo><mml:mi>e</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">(</mml:mo></mml:mrow></mml:mstyle><mml:msub><mml:mi>R</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>P</mml:mi><mml:mrow><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>L</mml:mi><mml:mi>n</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>X</mml:mi><mml:mi>n</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>n</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">)</mml:mo></mml:mrow></mml:mstyle><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">(</mml:mo></mml:mrow></mml:mstyle><mml:msubsup><mml:mi>U</mml:mi><mml:mi>n</mml:mi><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mi>n</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">)</mml:mo></mml:mrow></mml:mstyle><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="2.470em" minsize="2.470em">)</mml:mo></mml:mrow></mml:mstyle><mml:mo>,</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>The proof process is similar to the verification of signature correctness.</p></list-item>
</list></p>
</sec>
<sec id="s6_2">
<label>6.2</label>
<title>Confidentiality</title>
<p>In this scheme, the user&#x2019;s public key is used to encrypt the health passport data, and only those with the corresponding private key can decrypt the data. The encrypted health passport data is stored on IPFS, ensuring that even if IPFS is compromised by hackers, the attackers cannot obtain valid data. Additionally, the KGC only retains part of the private key <inline-formula id="ieqn-108"><mml:math id="mml-ieqn-108"><mml:msub><mml:mi>D</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>, while the complete private key <inline-formula id="ieqn-109"><mml:math id="mml-ieqn-109"><mml:msub><mml:mrow><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">k</mml:mi></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is generated by the user, enhancing data confidentiality.</p>
</sec>
<sec id="s6_3">
<label>6.3</label>
<title>Traceability and Non-Repudiation</title>
<p>This scheme relies on the immutable nature of blockchain. The index and signature of the user&#x2019;s passport are uploaded to the consortium blockchain, and each transaction includes the identity identifier of the transaction creator, <inline-formula id="ieqn-110"><mml:math id="mml-ieqn-110"><mml:msub><mml:mrow><mml:mi mathvariant="normal">I</mml:mi><mml:mi mathvariant="normal">D</mml:mi></mml:mrow><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula>. If there is an issue with the user&#x2019;s health status, it can be traced back to the relevant medical institution. Moreover, the hospital&#x2019;s signature <inline-formula id="ieqn-111"><mml:math id="mml-ieqn-111"><mml:msub><mml:mi>sig</mml:mi><mml:mi>b</mml:mi></mml:msub></mml:math></inline-formula> included in the transaction prevents the hospital from denying the facts.</p>
</sec>
<sec id="s6_4">
<label>6.4</label>
<title>Unforgeability</title>
<p>Before uploading the transaction to the consortium blockchain, the user signs the health passport using their private key. Malicious attackers cannot obtain the user&#x2019;s private key, making it impossible to forge valid signatures. Invalid signatures cannot pass the verification equation: <inline-formula id="ieqn-112"><mml:math id="mml-ieqn-112"><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>V</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow><mml:mi>k</mml:mi></mml:msubsup><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>X</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>U</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>g</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></inline-formula> thereby ensuring the unforgeability of the health passport.</p>
</sec>
</sec>
<sec id="s7">
<label>7</label>
<title>Performance Analysis</title>
<p>This section first compares the functions of this scheme with related health passport schemes; then analyzes the computational overhead of this scheme from a theoretical perspective and compares it with existing schemes; finally, evaluates the performance of the scheme through simulation experiments.</p>
<sec id="s7_1">
<label>7.1</label>
<title>Functional Comparison</title>
<p>The functional comparison between the proposed scheme and other health passport schemes [<xref ref-type="bibr" rid="ref-10">10</xref>] is shown in <xref ref-type="table" rid="table-2">Table 2</xref>. As can be seen from <xref ref-type="table" rid="table-2">Table 2</xref>, all schemes achieve confidentiality and integrity. The schemes in reference [<xref ref-type="bibr" rid="ref-32">32</xref>] cannot guarantee the non-repudiation of data; the scheme in reference [<xref ref-type="bibr" rid="ref-18">18</xref>] does not consider the problem of health passport forgery; the schemes in reference [<xref ref-type="bibr" rid="ref-33">33</xref>] achieve the above functions well, but cannot provide efficient health passport verification in multi-person scenarios. The proposed scheme achieves these functions well.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Feature comparison</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Function</th>
<th>[<xref ref-type="bibr" rid="ref-10">10</xref>]</th>
<th>[<xref ref-type="bibr" rid="ref-32">32</xref>]</th>
<th>[<xref ref-type="bibr" rid="ref-33">33</xref>]</th>
<th>[<xref ref-type="bibr" rid="ref-18">18</xref>]</th>
<th>[<xref ref-type="bibr" rid="ref-34">34</xref>]</th>
<th>Proposed solution</th>
</tr>
</thead>
<tbody>
<tr>
<td>Confidentiality</td>
<td><inline-formula id="ieqn-113"><mml:math id="mml-ieqn-113"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-114"><mml:math id="mml-ieqn-114"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-115"><mml:math id="mml-ieqn-115"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-116"><mml:math id="mml-ieqn-116"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-117"><mml:math id="mml-ieqn-117"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-118"><mml:math id="mml-ieqn-118"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>Traceability</td>
<td><inline-formula id="ieqn-119"><mml:math id="mml-ieqn-119"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-120"><mml:math id="mml-ieqn-120"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-121"><mml:math id="mml-ieqn-121"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-122"><mml:math id="mml-ieqn-122"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-123"><mml:math id="mml-ieqn-123"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-124"><mml:math id="mml-ieqn-124"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>Integrity</td>
<td><inline-formula id="ieqn-125"><mml:math id="mml-ieqn-125"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-126"><mml:math id="mml-ieqn-126"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-127"><mml:math id="mml-ieqn-127"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-128"><mml:math id="mml-ieqn-128"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-129"><mml:math id="mml-ieqn-129"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-130"><mml:math id="mml-ieqn-130"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>Non-repudiation</td>
<td><inline-formula id="ieqn-131"><mml:math id="mml-ieqn-131"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-132"><mml:math id="mml-ieqn-132"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-133"><mml:math id="mml-ieqn-133"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-134"><mml:math id="mml-ieqn-134"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-135"><mml:math id="mml-ieqn-135"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-136"><mml:math id="mml-ieqn-136"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>Unforgeable</td>
<td><inline-formula id="ieqn-137"><mml:math id="mml-ieqn-137"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-138"><mml:math id="mml-ieqn-138"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-139"><mml:math id="mml-ieqn-139"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-140"><mml:math id="mml-ieqn-140"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-141"><mml:math id="mml-ieqn-141"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-142"><mml:math id="mml-ieqn-142"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>Multi-person scenario</td>
<td><inline-formula id="ieqn-143"><mml:math id="mml-ieqn-143"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-144"><mml:math id="mml-ieqn-144"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-145"><mml:math id="mml-ieqn-145"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-146"><mml:math id="mml-ieqn-146"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-147"><mml:math id="mml-ieqn-147"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-148"><mml:math id="mml-ieqn-148"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s7_2">
<label>7.2</label>
<title>Computational Overhead</title>
<p>To compare the computational overhead, we conducted simulation experiments using a desktop PC equipped with Windows 10, an Intel Core i3-10100 CPU running at 3.60 GHz, and 16 GB of RAM. The evaluation focuses on health passport retrieval and signature verification, which are the primary computationally intensive stages in our proposed scheme. <xref ref-type="table" rid="table-3">Table 3</xref> presents the execution time for key cryptographic operations.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Execution time of the operation</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Symbol</th>
<th>Operation</th>
<th>Execution time/ms</th>
</tr>
</thead>
<tbody>
<tr>
<td><inline-formula id="ieqn-149"><mml:math id="mml-ieqn-149"><mml:msub><mml:mi>T</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>Hash function operation</td>
<td>0.04</td>
</tr>
<tr>
<td><inline-formula id="ieqn-150"><mml:math id="mml-ieqn-150"><mml:msub><mml:mi>T</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>Point multiplication operation</td>
<td>0.07</td>
</tr>
<tr>
<td><inline-formula id="ieqn-151"><mml:math id="mml-ieqn-151"><mml:msub><mml:mi>T</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>Exponential operation</td>
<td>10.56</td>
</tr>
<tr>
<td><inline-formula id="ieqn-152"><mml:math id="mml-ieqn-152"><mml:msub><mml:mi>T</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>Bilinear operation</td>
<td>4.98</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>We benchmarked our approach against existing blockchain-based healthcare authentication schemes, specifically those in references [<xref ref-type="bibr" rid="ref-18">18</xref>,<xref ref-type="bibr" rid="ref-33">33</xref>,<xref ref-type="bibr" rid="ref-34">34</xref>]. The computational overhead comparison is provided in <xref ref-type="table" rid="table-4">Table 4</xref>, where n represents the number of users. Reference [<xref ref-type="bibr" rid="ref-32">32</xref>] was excluded from this comparison as it does not provide detailed computational metrics.</p>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Computational cost comparison</title>
</caption>
<table>
<colgroup>
<col/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>Scheme</th>
<th align="center">Computational overhead of retrieval phase</th>
<th align="center">Computational overhead of signature verification phase</th>
<th align="center">Total</th>
</tr>
</thead>
<tbody>
<tr>
<td>Zero-knowledge [<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td><inline-formula id="ieqn-153"><mml:math id="mml-ieqn-153"><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>5</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>m</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>e</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-154"><mml:math id="mml-ieqn-154"><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>5</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>m</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>e</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-155"><mml:math id="mml-ieqn-155"><mml:mn>6</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>10</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>m</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>6</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>c</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>4</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula></td>
</tr>
<tr>
<td>Hierarchical Attribute [<xref ref-type="bibr" rid="ref-11">11</xref>]</td>
<td><inline-formula id="ieqn-156"><mml:math id="mml-ieqn-156"><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>e</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-157"><mml:math id="mml-ieqn-157"><mml:mn>2</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>m</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>e</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-158"><mml:math id="mml-ieqn-158"><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>m</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>4</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>e</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>4</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula></td>
</tr>
<tr>
<td>Single user (Proposed)</td>
<td><inline-formula id="ieqn-159"><mml:math id="mml-ieqn-159"><mml:mn>2</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>m</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>4</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>e</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-160"><mml:math id="mml-ieqn-160"><mml:mn>4</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>m</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>e</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-161"><mml:math id="mml-ieqn-161"><mml:mn>5</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>m</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>4</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>c</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>4</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula></td>
</tr>
<tr>
<td>Multi user (Proposed)</td>
<td><inline-formula id="ieqn-162"><mml:math id="mml-ieqn-162"><mml:mn>2</mml:mn><mml:msub><mml:mi>T</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>T</mml:mi><mml:mi>m</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>4</mml:mn><mml:msub><mml:mi>T</mml:mi><mml:mi>e</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>T</mml:mi><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-163"><mml:math id="mml-ieqn-163"><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>m</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>e</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mi>n</mml:mi><mml:msub><mml:mi>T</mml:mi><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-164"><mml:math id="mml-ieqn-164"><mml:mo stretchy="false">(</mml:mo><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:msub><mml:mi>T</mml:mi><mml:mi>h</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:msub><mml:mi>T</mml:mi><mml:mi>m</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>3</mml:mn><mml:mi>n</mml:mi><mml:mo>+</mml:mo><mml:mn>4</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:msub><mml:mi>T</mml:mi><mml:mi>c</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mi>n</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:msub><mml:mi>T</mml:mi><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-3">Figs. 3</xref>&#x2013;<xref ref-type="fig" rid="fig-5">5</xref> compare the computational overhead at several levels. <xref ref-type="fig" rid="fig-3">Fig. 3</xref> shows the computational overhead during the health passport retrieval stage. The x-axis represents the number of users, while the y-axis shows the time taken (in milliseconds) for data retrieval. The comparison includes our proposed scheme against prior methods [<xref ref-type="bibr" rid="ref-34">34</xref>] and [<xref ref-type="bibr" rid="ref-33">33</xref>]. Lower computational overhead indicates a more efficient retrieval process.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Computational overhead at the retrieval stage</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63964-fig-3.tif"/>
</fig><fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Computational overhead at the signature verification stage</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63964-fig-4.tif"/>
</fig><fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Total computational overhead</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63964-fig-5.tif"/>
</fig>
<p>The systems mentioned in reference [<xref ref-type="bibr" rid="ref-34">34</xref>] have lower computational overheads than the scheme in the single-user case, but they aren&#x2019;t as good as the method in the multi-user situation. The difference will widen as the number of users increases. Unlike earlier techniques, which necessitate retrieving each user&#x2019;s health passport individually, the aggregate signature technology introduced in this paper&#x2019;s scheme simply requires one retrieval. The retrieval stage&#x2019;s computing overhead increases with the number of users. During the signature verification stage, <xref ref-type="fig" rid="fig-4">Fig. 4</xref> shows the computational overhead of the technique. In the single-user scenario, the computational cost of the signature verification in this paper&#x2019;s technique is higher than in reference [<xref ref-type="bibr" rid="ref-33">33</xref>], but it&#x2019;s about the same as in reference [<xref ref-type="bibr" rid="ref-18">18</xref>]. This paper&#x2019;s approach, which is applicable to both single- and multiple-user scenarios, has lower computing cost during the signature verification stage compared to the scheme in reference [<xref ref-type="bibr" rid="ref-33">33</xref>]. Reason being, compared to the scheme in reference [<xref ref-type="bibr" rid="ref-18">18</xref>], the signature verification procedure of the scheme in reference [<xref ref-type="bibr" rid="ref-34">34</xref>] and this paper&#x2019;s scheme reduces one bilinear operation, slightly lowering the computational overhead of signature verification. Also, the suggested technique has a small benefit over the solution in the literature [<xref ref-type="bibr" rid="ref-33">33</xref>] since it reduces 2 multiplication processes.</p>
<p><xref ref-type="fig" rid="fig-5">Fig. 5</xref> is for the scheme&#x2019;s total computing cost. With a maximum optimization of 49.89%, the suggested method clearly outperforms the current system in terms of overall computing cost in the multi-user situation. The reason behind this is that the suggested system takes into account the possibility of merging complex calculations (like bilinear mapping and exponential operations) when the user group performs retrieval and verification, in contrast to the present scheme. Combining the calculation processes for a single user with those for a multi-user scenario allows for the realization of calculation merging in the latter. Despite this, in the single-user scenario, the computational cost of the proposed scheme will be higher than other existing schemes. However, in the multi-user scenario, from the Healthcare device data retrieval stage to the verification stage, other existing schemes clearly have higher computational costs than the proposed scheme (<xref ref-type="fig" rid="fig-3">Figs. 3</xref>&#x2013;<xref ref-type="fig" rid="fig-5">5</xref>). Consequently, the suggested approach is better suited to situations involving international communication or foreign travel due to its greater efficiency advantage in real applications. An adversarial actor might potentially falsify a valid user&#x2019;s health passport within the scheme, rendering the signature verification ineffective. Finding the malicious forger after signature verification fails requires re-obtaining and confirming each user&#x2019;s signature individually.</p>

</sec>
<sec id="s7_3">
<label>7.3</label>
<title>Consensus Overhead</title>
<p>To evaluate the efficiency of the improved weak consensus algorithm proposed in this paper, simulations of the PBFT algorithm [<xref ref-type="bibr" rid="ref-35">35</xref>], the weak consensus algorithm, and the improved weak consensus algorithm were conducted using Java as the programming language. The simulations modeled a P2P network environment with <inline-formula id="ieqn-165"><mml:math id="mml-ieqn-165"><mml:mn>4</mml:mn><mml:mrow><mml:mo>&#x223C;</mml:mo></mml:mrow><mml:mn>64</mml:mn></mml:math></inline-formula> nodes communicating via different WebSocket ports. Each experiment was repeated 10 times, and the average result was taken as the final outcome. The experiments were performed on a laptop computer running Windows 11, equipped with an AMD Ryzen 7 5800H CPU and 16 GB of RAM. The throughput of the blockchain was measured in terms of the number of transactions per second (TPS), which is the number of transactions that can be added to the chain per second. TPS is defined as:</p>
<p><disp-formula id="eqn-19"><label>(19)</label><mml:math id="mml-eqn-19" display="block"><mml:mrow><mml:mtext>TPS</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:msub><mml:mi>T</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mi>t</mml:mi></mml:mfrac><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-166"><mml:math id="mml-ieqn-166"><mml:mi>t</mml:mi></mml:math></inline-formula> represents the time and <inline-formula id="ieqn-167"><mml:math id="mml-ieqn-167"><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:msub><mml:mi>T</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> is the number of transactions added to the chain within time <inline-formula id="ieqn-168"><mml:math id="mml-ieqn-168"><mml:mi>t</mml:mi></mml:math></inline-formula>. This paper compares the traditional PBFT algorithm, the weak consensus algorithm, and the improved weak consensus algorithm. The comparison of consensus efficiency is shown in <xref ref-type="fig" rid="fig-6">Fig. 6</xref>. The throughput of the PBFT consensus algorithm drops as the number of nodes grows, as shown in <xref ref-type="fig" rid="fig-6">Fig. 6</xref>. In this research, we present an improved weak consensus algorithm that outperforms the PBFT method [<xref ref-type="bibr" rid="ref-21">21</xref>] and the weak consensus algorithm [<xref ref-type="bibr" rid="ref-18">18</xref>] in terms of throughput at low node densities. While doing so, it still performs well when the number of nodes is large. The improved weak consensus algorithm only needs two stages to reach consensus, which greatly reduces the communication complexity of reaching consensus between nodes and improves the throughput of the entire blockchain system.</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Comparison of consensus efficiency</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63964-fig-6.tif"/>
</fig>
</sec>
<sec id="s7_4">
<label>7.4</label>
<title>Communication Overhead</title>
<p>Assuming that the length of the index, trapdoor, hash value, and key pair is 256 bits, the length of the health passport data ciphertext is 512 bits, the length of the signature is 1024 bits, the length of the ID is 128 bits, and the length of the timestamp is 64 bits, the communication overhead in the storage phase is shown in <xref ref-type="fig" rid="fig-7">Fig. 7</xref>. In the health passport data storage phase, the solution in reference [<xref ref-type="bibr" rid="ref-34">34</xref>] needs to send 1984 bits, the solution in reference [<xref ref-type="bibr" rid="ref-33">33</xref>] needs to send 1792 bits, and the solution in this paper only needs to send 1664 bits; in the retrieval phase, the communication overhead is shown in <xref ref-type="fig" rid="fig-8">Fig. 8</xref>. The solution in reference [<xref ref-type="bibr" rid="ref-34">34</xref>] needs to send 1984 bits, the solution in reference [<xref ref-type="bibr" rid="ref-33">33</xref>] needs to send 1536 bits, and the solution in this paper only needs to send 1280 bits. Compared with the solutions in reference [<xref ref-type="bibr" rid="ref-34">34</xref>], the communication overhead of the solution in this paper is smaller, with the highest optimization of 25.81%, which is attributed to the reduction of unnecessary transmission (such as timestamps and keys).</p>
<fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>Comparison of communication overhead in storage phase</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63964-fig-7.tif"/>
</fig><fig id="fig-8">
<label>Figure 8</label>
<caption>
<title>Comparison of communication overhead in the retrieval phase</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_63964-fig-8.tif"/>
</fig>
</sec>
<sec id="s7_5">
<label>7.5</label>
<title>Real-World Deployment</title>
<p>While our proposed blockchain-based health passport system offers significant security and efficiency advantages, real-world deployment presents several challenges:
<list list-type="simple">
<list-item><label>1.</label><p><bold>Cost and Infrastructure Requirements:</bold> Implementing blockchain-based solutions requires computational resources for consensus mechanisms, storage, and encryption operations. Healthcare institutions must invest in compatible hardware and software, which may pose financial constraints, especially in resource-limited regions.</p></list-item>
<list-item><label>2.</label><p><bold>Energy Consumption:</bold> Blockchain networks, particularly those using consensus mechanisms like PBFT, can be computationally intensive. Although our optimized weak consensus algorithm reduces communication overhead, further work is needed to explore energy-efficient blockchain frameworks suitable for large-scale healthcare adoption.</p></list-item>
<list-item><label>3.</label><p><bold>Regulatory Compliance:</bold> Ensuring compliance with healthcare data protection laws (e.g., GDPR, HIPAA) is critical. Blockchain&#x2019;s immutability raises challenges for data modification or removal requests, necessitating privacy-preserving mechanisms such as zero-knowledge proofs.</p></list-item>
<list-item><label>4.</label><p><bold>User Adoption and Usability:</bold> Medical professionals and travelers may require training to interact with blockchain-based health passport systems. A user-friendly interface and integration with existing electronic health record (EHR) [<xref ref-type="bibr" rid="ref-36">36</xref>] systems will be essential for seamless adoption.</p></list-item>
</list></p>
<p>Future research will focus on optimizing energy efficiency, cost-effectiveness, and regulatory adaptability to facilitate real-world deployment in healthcare environments.</p>
</sec>
</sec>
<sec id="s8">
<label>8</label>
<title>Conclusion</title>
<p>This paper addresses critical challenges in the global sharing of personal health passports, including &#x201C;information islands,&#x201D; inadequate privacy protection, and risks of forgery. To overcome these, a blockchain-based solution for health passport storage, sharing, and verification is proposed, integrating searchable encryption technology with blockchain to ensure secure, efficient, and scalable data management. The proposed scheme introduces an innovative combination of on-chain and off-chain storage using IPFS, enhancing storage optimization while maintaining reliability. Additionally, an improved aggregate signature mechanism is employed to facilitate efficient multi-user verification, while a two-stage weak consensus algorithm significantly improves blockchain throughput and reduces communication complexity. Through comprehensive security analysis and experimental validation, the scheme demonstrates notable advantages, achieving up to 49.89% optimization in computational overhead and up to 25.81% reduction in communication overhead in multi-user scenarios. However, challenges remain in single-user cases, where retrieval and signature verification overheads are higher than existing solutions. To address this, future research will explore lightweight cryptographic operations and hybrid storage mechanisms to enhance efficiency in low-volume transactions. Furthermore, ethical and legal considerations are paramount in blockchain-based healthcare systems. Our approach ensures compliance with GDPR and HIPAA by utilizing off-chain storage for sensitive data while maintaining secure on-chain references. To address blockchain immutability challenges, potential solutions include zero-knowledge proofs, revocable encryption, and hybrid blockchain governance models to uphold user privacy and the right to data modification. Future research will refine privacy-preserving techniques, regulatory adaptability, and energy-efficient consensus mechanisms to enhance scalability and real-world applicability. By addressing key concerns in security, privacy, efficiency, and ethical compliance, this work presents a robust and adaptable framework for secure health passport management, with significant potential for global healthcare data interoperability and secure international travel.</p>
</sec>
</body>
<back>
<ack>
<p>Not applicable.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>The authors received no specific funding for this study.</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>Yogendra P. S. Maravi drafted the manuscript, conducted the literature review, and implemented the proposed solution. Nishchol Mishra provided conceptualization, supervision, and manuscript review and editing. All authors reviewed the results and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>Data available on request from the authors.</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest to report regarding the present study.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ait Bennacer</surname> <given-names>S</given-names></string-name>, <string-name><surname>Aaroud</surname> <given-names>A</given-names></string-name>, <string-name><surname>Sabiri</surname> <given-names>K</given-names></string-name>, <string-name><surname>Rguibi</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Cherradi</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Design and implementation of a New Blockchain-based digital health passport: a Moroccan case study</article-title>. <source>Inform Med Unlocked</source>. <year>2022</year>;<volume>35</volume>(<issue>2</issue>):<fpage>101125</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.imu.2022.101125</pub-id>; <pub-id pub-id-type="pmid">36345287</pub-id></mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Raman</surname> <given-names>R</given-names></string-name>, <string-name><surname>Sahayaraj</surname> <given-names>KA</given-names></string-name>, <string-name><surname>Soni</surname> <given-names>M</given-names></string-name>, <string-name><surname>Nayak</surname> <given-names>NR</given-names></string-name>, <string-name><surname>Govindaraj</surname> <given-names>R</given-names></string-name>, <string-name><surname>Singh</surname> <given-names>NK</given-names></string-name></person-group>. <article-title>Semantic web techniques for clinical topic detection in health care</article-title>. <source>Comput Assist Methods Eng Sci</source>. <year>2024</year>;<volume>31</volume>(<issue>2</issue>):<fpage>139</fpage>&#x2013;<lpage>55</lpage>. doi:<pub-id pub-id-type="doi">10.24423/cames.2024.493</pub-id>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cao</surname> <given-names>K</given-names></string-name>, <string-name><surname>Cui</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Li</surname> <given-names>L</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>J</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>S</given-names></string-name></person-group>. <article-title>CPU-GPU cooperative QoS optimization of personalized digital healthcare using machine learning and swarm intelligence</article-title>. <source>IEEE/ACM Trans Comput Biol Bioinform</source>. <year>2024</year>;<volume>21</volume>(<issue>4</issue>):<fpage>521</fpage>&#x2013;<lpage>33</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TCBB.2022.3207509</pub-id>; <pub-id pub-id-type="pmid">36121951</pub-id></mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hendy</surname> <given-names>A</given-names></string-name>, <string-name><surname>Abdelaliem</surname> <given-names>SMF</given-names></string-name>, <string-name><surname>Osman</surname> <given-names>YM</given-names></string-name>, <string-name><surname>Al-Kurdi</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Zaher</surname> <given-names>A</given-names></string-name>, <string-name><surname>Hendy</surname> <given-names>A</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Understanding Nurses&#x2019; perspectives on electronic health records in Egypt: insights from a cross-sectional study</article-title>. <source>J Pediatr Nurs</source>. <year>2025</year>;<volume>80</volume>(<issue>7</issue>):<fpage>e255</fpage>&#x2013;<lpage>63</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.pedn.2025.01.002</pub-id>; <pub-id pub-id-type="pmid">39800614</pub-id></mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Nguyen</surname> <given-names>HS</given-names></string-name>, <string-name><surname>Voznak</surname> <given-names>M</given-names></string-name></person-group>. <article-title>A bibliometric analysis of technology in digital health: exploring health metaverse and visualizing emerging healthcare management trends</article-title>. <source>IEEE Access</source>. <year>2024</year>;<volume>12</volume>:<fpage>23887</fpage>&#x2013;<lpage>913</lpage>. doi:<pub-id pub-id-type="doi">10.1109/ACCESS.2024.3363165</pub-id>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Alrowais</surname> <given-names>F</given-names></string-name>, <string-name><surname>Mohamed</surname> <given-names>HG</given-names></string-name>, <string-name><surname>Al-Wesabi</surname> <given-names>FN</given-names></string-name>, <string-name><surname>Al Duhayyim</surname> <given-names>M</given-names></string-name>, <string-name><surname>Hilal</surname> <given-names>AM</given-names></string-name>, <string-name><surname>Motwakel</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Cyber attack detection in healthcare data using cyber-physical system with optimized algorithm</article-title>. <source>Comput Electr Eng</source>. <year>2023</year>;<volume>108</volume>(<issue>9</issue>):<fpage>108636</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.compeleceng.2023.108636</pub-id>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Singh</surname> <given-names>NK</given-names></string-name>, <string-name><surname>Tomar</surname> <given-names>DS</given-names></string-name>, <string-name><surname>Singh</surname> <given-names>RK</given-names></string-name></person-group>. <source>Blockchain-based privacy-protected reputation model for internet of vehicles</source>. In: <person-group person-group-type="editor"><string-name><surname>Kumar</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ahuja</surname> <given-names>NJ</given-names></string-name>, <string-name><surname>Kaushik</surname> <given-names>K</given-names></string-name>, <string-name><surname>Tomar</surname> <given-names>DS</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>SB</given-names></string-name></person-group>, editors. <source>Contributions to environmental sciences &#x00026; innovative business technology</source>. <publisher-loc>Singapore</publisher-loc>: <publisher-name>Springer Nature Singapore</publisher-name>; <year>2024</year>. p. <fpage>1</fpage>&#x2013;<lpage>22</lpage>. doi:<pub-id pub-id-type="doi">10.1007/978-981-97-0088-2_1</pub-id>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>George</surname> <given-names>M</given-names></string-name>, <string-name><surname>Chacko</surname> <given-names>AM</given-names></string-name></person-group>. <article-title>Health passport: a blockchain-based PHR-integrated self-sovereign identity system</article-title>. <source>Front Blockchain</source>. <year>2023</year>;<volume>6</volume>:<fpage>100001</fpage>. doi:<pub-id pub-id-type="doi">10.3389/fbloc.2023.1075083</pub-id>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rashid</surname> <given-names>MM</given-names></string-name>, <string-name><surname>Choi</surname> <given-names>P</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>SH</given-names></string-name>, <string-name><surname>Kwon</surname> <given-names>KR</given-names></string-name></person-group>. <article-title>Block-HPCT: blockchain enabled digital health passports and contact tracing of infectious diseases like COVID-19</article-title>. <source>Sensors</source>. <year>2022</year>;<volume>22</volume>(<issue>11</issue>):<fpage>1</fpage>&#x2013;<lpage>23</lpage>. doi:<pub-id pub-id-type="doi">10.3390/s22114256</pub-id>; <pub-id pub-id-type="pmid">35684876</pub-id></mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hasan</surname> <given-names>HR</given-names></string-name>, <string-name><surname>Salah</surname> <given-names>K</given-names></string-name>, <string-name><surname>Jayaraman</surname> <given-names>R</given-names></string-name>, <string-name><surname>Arshad</surname> <given-names>J</given-names></string-name>, <string-name><surname>Yaqoob</surname> <given-names>I</given-names></string-name>, <string-name><surname>Omar</surname> <given-names>M</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Blockchain-based solution for COVID-19 digital medical passports and immunity certificates</article-title>. <source>IEEE Access</source>. <year>2020</year>;<volume>8</volume>:<fpage>222093</fpage>&#x2013;<lpage>108</lpage>. doi:<pub-id pub-id-type="doi">10.1109/ACCESS.2020.3043350</pub-id>; <pub-id pub-id-type="pmid">34812373</pub-id></mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wei</surname> <given-names>J</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>W</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>X</given-names></string-name></person-group>. <article-title>Cost-effective and scalable data sharing in cloud storage using hierarchical attribute-based encryption with forward security</article-title>. <source>Int J Found Comput Sci</source>. <year>2017</year>;<volume>28</volume>(<issue>7</issue>):<fpage>843</fpage>&#x2013;<lpage>68</lpage>. doi:<pub-id pub-id-type="doi">10.1142/S0129054117500289</pub-id>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Mohd Shari</surname> <given-names>NF</given-names></string-name>, <string-name><surname>Malip</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Enhancing privacy and security in smart healthcare: a blockchain-powered decentralized data dissemination scheme</article-title>. <source>Internet Things</source>. <year>2024</year>;<volume>27</volume>(<issue>1</issue>):<fpage>101256</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.iot.2024.101256</pub-id>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ramzan</surname> <given-names>S</given-names></string-name>, <string-name><surname>Aqdus</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ravi</surname> <given-names>V</given-names></string-name>, <string-name><surname>Koundal</surname> <given-names>D</given-names></string-name>, <string-name><surname>Amin</surname> <given-names>R</given-names></string-name>, <string-name><surname>Al Ghamdi</surname> <given-names>MA</given-names></string-name></person-group>. <article-title>Healthcare applications using blockchain technology: motivations and challenges</article-title>. <source>IEEE Trans Eng Manag</source>. <year>2023</year>;<volume>70</volume>(<issue>8</issue>):<fpage>2874</fpage>&#x2013;<lpage>90</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TEM.2022.3189734</pub-id>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Demirbaga</surname> <given-names>U</given-names></string-name>, <string-name><surname>Aujla</surname> <given-names>GS</given-names></string-name></person-group>. <article-title>MapChain: a blockchain-based verifiable healthcare service management in IoT-based big data ecosystem</article-title>. <source>IEEE Trans Netw Serv Manag</source>. <year>2022</year>;<volume>19</volume>(<issue>4</issue>):<fpage>3896</fpage>&#x2013;<lpage>907</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TNSM.2022.3204851</pub-id>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jafari</surname> <given-names>AMH</given-names></string-name>, <string-name><surname>Patchmuthu</surname> <given-names>RK</given-names></string-name>, <string-name><surname>Tajuddin</surname> <given-names>STH</given-names></string-name></person-group>. <article-title>Immutable COVID-19 vaccination certificate using blockchain</article-title>. <source>Procedia Comput Sci</source>. <year>2024</year>;<volume>233</volume>(<issue>3</issue>):<fpage>194</fpage>&#x2013;<lpage>203</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.procs.2024.03.209</pub-id>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zarour</surname> <given-names>M</given-names></string-name>, <string-name><surname>Ansari</surname> <given-names>MTJ</given-names></string-name>, <string-name><surname>Alenezi</surname> <given-names>M</given-names></string-name>, <string-name><surname>Sarkar</surname> <given-names>AK</given-names></string-name>, <string-name><surname>Faizan</surname> <given-names>M</given-names></string-name>, <string-name><surname>Agrawal</surname> <given-names>A</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Evaluating the impact of blockchain models for secure and trustworthy electronic healthcare records</article-title>. <source>IEEE Access</source>. <year>2020</year>;<volume>8</volume>(<issue>X</issue>):<fpage>157959</fpage>&#x2013;<lpage>73</lpage>. doi:<pub-id pub-id-type="doi">10.1109/ACCESS.2020.3019829</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Guerar</surname> <given-names>M</given-names></string-name>, <string-name><surname>Migliardi</surname> <given-names>M</given-names></string-name>, <string-name><surname>Russo</surname> <given-names>E</given-names></string-name>, <string-name><surname>Khadraoui</surname> <given-names>D</given-names></string-name>, <string-name><surname>Merlo</surname> <given-names>A</given-names></string-name></person-group>. <article-title>SSI-MedRx: a fraud-resilient healthcare system based on blockchain and SSI</article-title>. <source>Blockchain: Res Appl</source>. <year>2024</year>;<fpage>100242</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.bcra.2024.100242</pub-id>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rajtar</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Patient passports and vulnerability: disjunctures in health policy instruments for people with rare diseases</article-title>. <source>Soc Sci Med</source>. <year>2025</year>;<volume>366</volume>(<issue>3</issue>):<fpage>117642</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.socscimed.2024.117642</pub-id>; <pub-id pub-id-type="pmid">39721171</pub-id></mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Moulahi</surname> <given-names>W</given-names></string-name>, <string-name><surname>Jdey</surname> <given-names>I</given-names></string-name>, <string-name><surname>Moulahi</surname> <given-names>T</given-names></string-name>, <string-name><surname>Alawida</surname> <given-names>M</given-names></string-name>, <string-name><surname>Alabdulatif</surname> <given-names>A</given-names></string-name></person-group>. <article-title>A blockchain-based federated learning mechanism for privacy preservation of healthcare IoT data</article-title>. <source>Comput Biol Med</source>. <year>2023</year>;<volume>167</volume>(<issue>3</issue>):<fpage>107630</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.compbiomed.2023.107630</pub-id>; <pub-id pub-id-type="pmid">37952305</pub-id></mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Seong</surname> <given-names>D</given-names></string-name>, <string-name><surname>Jung</surname> <given-names>S</given-names></string-name>, <string-name><surname>Bae</surname> <given-names>S</given-names></string-name>, <string-name><surname>Chung</surname> <given-names>J</given-names></string-name>, <string-name><surname>Son</surname> <given-names>DS</given-names></string-name>, <string-name><surname>Yi</surname> <given-names>BK</given-names></string-name></person-group>. <article-title>Fast healthcare interoperability resources (FHIR) based quality information exchange for clinical next-generation sequencing genomic testing: implementation study</article-title>. <source>J Med Internet Res</source>. <year>2021</year>;<volume>23</volume>(<issue>4</issue>):<fpage>1</fpage>&#x2013;<lpage>21</lpage>. doi:<pub-id pub-id-type="doi">10.2196/26261</pub-id>; <pub-id pub-id-type="pmid">33908889</pub-id></mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yang</surname> <given-names>N</given-names></string-name>, <string-name><surname>Tang</surname> <given-names>C</given-names></string-name>, <string-name><surname>Xiong</surname> <given-names>Z</given-names></string-name>, <string-name><surname>He</surname> <given-names>D</given-names></string-name></person-group>. <article-title>RCME: a reputation incentive committee consensus-based for matchmaking encryption in IoT healthcare</article-title>. <source>IEEE Trans Serv Comput</source>. <year>2024</year>;<volume>17</volume>(<issue>5</issue>):<fpage>2790</fpage>&#x2013;<lpage>806</lpage>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bharathi Murthy</surname> <given-names>CVNU</given-names></string-name>, <string-name><surname>Lawanya Shri</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Secure sharing architecture of personal healthcare data using private permissioned blockchain for telemedicine</article-title>. <source>IEEE Access</source>. <year>2024</year>;<volume>12</volume>:<fpage>106645</fpage>&#x2013;<lpage>57</lpage>. doi:<pub-id pub-id-type="doi">10.1109/ACCESS.2024.3436075</pub-id>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ren</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Yan</surname> <given-names>E</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>T</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Blockchain-based CP-ABE data sharing and privacy-preserving scheme using distributed KMS and zero-knowledge proof</article-title>. <source>J King Saud Univ Comput Inf Sci</source>. <year>2024</year>;<volume>36</volume>(<issue>3</issue>):<fpage>101969</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jksuci.2024.101969</pub-id>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Nyato</surname> <given-names>EJ</given-names></string-name>, <string-name><surname>Kimito</surname> <given-names>E</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>D</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Blockchain-integrated zero-knowledge proof system for privacy-preserving near-miss reporting in construction projects</article-title>. <source>Autom Constr</source>. <year>2024</year>;<volume>168</volume>(<issue>6</issue>):<fpage>105825</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.autcon.2024.105825</pub-id>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Singh</surname> <given-names>MK</given-names></string-name>, <string-name><surname>Pippal</surname> <given-names>SK</given-names></string-name>, <string-name><surname>Sharma</surname> <given-names>V</given-names></string-name></person-group>. <article-title>Lightweight blockchain mechanism for secure data transmission in healthcare system</article-title>. <source>Biomed Signal Process Control</source>. <year>2025</year>;<volume>102</volume>(<issue>5</issue>):<fpage>107411</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.bspc.2024.107411</pub-id>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhou</surname> <given-names>F</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Li</surname> <given-names>C</given-names></string-name>, <string-name><surname>Feng</surname> <given-names>X</given-names></string-name>, <string-name><surname>Yin</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>G</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Blockchain for digital healthcare: case studies and adoption challenges</article-title>. <source>Intell Med</source>. <year>2024</year>;<volume>4</volume>(<issue>4</issue>):<fpage>215</fpage>&#x2013;<lpage>25</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.imed.2024.09.001</pub-id>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>d&#x2019;Almeida</surname> <given-names>S</given-names></string-name>, <string-name><surname>Jamrozik</surname> <given-names>E</given-names></string-name>, <string-name><surname>Kerouedan</surname> <given-names>D</given-names></string-name>, <string-name><surname>Mossialos</surname> <given-names>E</given-names></string-name></person-group>. <article-title>Challenges of balancing international health and travel in a pandemic: lessons from the French Caribbean during COVID-19 passports</article-title>. <source>Lancet Reg Health Am</source>. <year>2022</year>;<volume>13</volume>(<issue>6</issue>):<fpage>100327</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.lana.2022.100327</pub-id>; <pub-id pub-id-type="pmid">35872664</pub-id></mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Abd-Alhalem</surname> <given-names>SM</given-names></string-name>, <string-name><surname>Marie</surname> <given-names>HS</given-names></string-name>, <string-name><surname>El-Shafai</surname> <given-names>W</given-names></string-name>, <string-name><surname>Altameem</surname> <given-names>T</given-names></string-name>, <string-name><surname>Rathore</surname> <given-names>RS</given-names></string-name>, <string-name><surname>Hassan</surname> <given-names>TM</given-names></string-name></person-group>. <article-title>Cervical cancer classification based on a bilinear convolutional neural network approach and random projection</article-title>. <source>Eng Appl Artif Intell</source>. <year>2024</year>;<volume>127</volume>(<issue>1</issue>):<fpage>107261</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.engappai.2023.107261</pub-id>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kim</surname> <given-names>TH</given-names></string-name>, <string-name><surname>Kumar</surname> <given-names>G</given-names></string-name>, <string-name><surname>Saha</surname> <given-names>R</given-names></string-name>, <string-name><surname>Alazab</surname> <given-names>M</given-names></string-name>, <string-name><surname>Buchanan</surname> <given-names>WJ</given-names></string-name>, <string-name><surname>Rai</surname> <given-names>MK</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>CASCF: certificateless aggregated signcryption framework for internet-of-things infrastructure</article-title>. <source>IEEE Access</source>. <year>2020</year>;<volume>8</volume>:<fpage>94748</fpage>&#x2013;<lpage>56</lpage>. doi:<pub-id pub-id-type="doi">10.1109/ACCESS.2020.2995443</pub-id>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yin</surname> <given-names>H</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>L</given-names></string-name>, <string-name><surname>Qiao</surname> <given-names>B</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>W</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Attribute-based searchable encryption with decentralized key management for healthcare data sharing</article-title>. <source>J Syst Archit</source>. <year>2024</year>;<volume>148</volume>(<issue>12</issue>):<fpage>103081</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.sysarc.2024.103081</pub-id>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shukla</surname> <given-names>S</given-names></string-name>, <string-name><surname>Thakur</surname> <given-names>S</given-names></string-name>, <string-name><surname>Hussain</surname> <given-names>S</given-names></string-name>, <string-name><surname>Breslin</surname> <given-names>JG</given-names></string-name>, <string-name><surname>Jameel</surname> <given-names>SM</given-names></string-name></person-group>. <article-title>Identification and authentication in healthcare internet-of-things using integrated fog computing based blockchain model</article-title>. <source>Internet Things</source>. <year>2021</year>;<volume>15</volume>(<issue>11</issue>):<fpage>100422</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.iot.2021.100422</pub-id>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>de Figueiredo</surname> <given-names>A</given-names></string-name>, <string-name><surname>Larson</surname> <given-names>HJ</given-names></string-name>, <string-name><surname>Reicher</surname> <given-names>SD</given-names></string-name></person-group>. <article-title>The potential impact of vaccine passports on inclination to accept COVID-19 vaccinations in the United Kingdom: evidence from a large cross-sectional survey and modeling study</article-title>. <source>eClinicalMedicine</source>. <year>2021</year>;<volume>40</volume>:<fpage>101109</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.eclinm.2021.101109</pub-id>; <pub-id pub-id-type="pmid">34522870</pub-id></mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Uvaliyeva</surname> <given-names>I</given-names></string-name>, <string-name><surname>Borozenets</surname> <given-names>D</given-names></string-name></person-group>. <chapter-title>Realization of conceptual model of IT-infrastructure of technology of differential diagnostics of clinical and hematological syndromes for health passport</chapter-title>. In: 2024<source>IEEE AITU: digital generation</source>. <publisher-loc>Astana, Kazakhstan</publisher-loc>: <publisher-loc>IEEE</publisher-loc>; <year>2024</year>. p. <fpage>174</fpage>&#x2013;<lpage>80</lpage>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shen</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>J</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Twenty-five years of evolution and hurdles in electronic health records and interoperability in medical research: comprehensive review</article-title>. <source>J Med Internet Res</source>. <year>2025</year>;<volume>27</volume>(<issue>8</issue>):<fpage>e59024</fpage>. doi:<pub-id pub-id-type="doi">10.2196/59024</pub-id>; <pub-id pub-id-type="pmid">39787599</pub-id></mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Riahi</surname> <given-names>K</given-names></string-name>, <string-name><surname>el Amine Brahmia</surname> <given-names>M</given-names></string-name>, <string-name><surname>Abouaissa</surname> <given-names>A</given-names></string-name>, <string-name><surname>Idoumghar</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Multi-task learning for PBFT optimisation in permissioned blockchains</article-title>. <source>Blockchain: Res Appl</source>. <year>2024</year>;<volume>5</volume>(<issue>3</issue>):<fpage>100206</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.bcra.2024.100206</pub-id>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ullah</surname> <given-names>F</given-names></string-name>, <string-name><surname>He</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zhu</surname> <given-names>N</given-names></string-name>, <string-name><surname>Wajahat</surname> <given-names>A</given-names></string-name>, <string-name><surname>Nazir</surname> <given-names>A</given-names></string-name>, <string-name><surname>Qureshi</surname> <given-names>S</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Blockchain-enabled EHR access auditing: enhancing healthcare data security</article-title>. <source>Heliyon</source>. <year>2024 Aug</year>;<volume>10</volume>(<issue>16</issue>):<fpage>e34407</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.heliyon.2024.e34407</pub-id>; <pub-id pub-id-type="pmid">39253236</pub-id></mixed-citation></ref>
</ref-list>
</back></article>