{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,7]],"date-time":"2025-10-07T06:11:19Z","timestamp":1759817479663,"version":"build-2065373602"},"reference-count":58,"publisher":"Frontiers Media SA","license":[{"start":{"date-parts":[[2025,10,7]],"date-time":"2025-10-07T00:00:00Z","timestamp":1759795200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["frontiersin.org"],"crossmark-restriction":true},"short-container-title":["Front. Blockchain"],"abstract":"<jats:p>Since the rise of the Internet, several IT services and applications have become widely accessible, making cloud computing a vital solution for its deployment for corporate and personal use. Additionally, the Internet of Things (IoT) has accelerated large-scale data generation, e.g., for monitoring applications in medical and industrial environments. Cloud computing and IoT are seamlessly integrated: IoT devices generate data later stored and accessed in the cloud, enabling efficient data use across multiple applications and processing models. Consequently, cloud services are increasingly being used for outsourcing the high processing and storage requirements demanded by IoT applications. While this integration offers significant advantages, it also presents major data security challenges, particularly concerning the confidentiality and access control of outsourced sensitive data. It is especially relevant because cloud service providers are typically assumed to be honest but curious and, hence, untrustworthy. In this context, Ciphertext-Policy Attribute-Based Encryption (CP-ABE) can successfully enforce complex access control over outsourced data. It is achieved by encrypting it using fine-grained access policies and delegating access control to decryption keys dependent on end-user attributes. Although CP-ABE offers several advantages, its wide adoption and efficient deployment in practical applications is still hindered by some issues. One of the major concerns involves the strong dependency on a centralized trusted authority setting and managing CP-ABE\u2019s access control policies and attribute sets. This dependency represents a single point of failure that threatens the system\u2019s continuous operation. In this paper, we eliminate CP-ABE\u2019s dependency on a single trusted authority by adopting a decentralization strategy relying on blockchain\u2019s main features. Therefore, we propose a blockchain-based approach to distribute among multiple peers the users\u2019 secret keys generation and management tasks performed by the trusted authority, solving CP-ABE\u2019s centralization problem. By combining blockchain, CP-ABE, and Elliptic Curve Integrated Encryption Scheme (ECIES), we ensure the confidentiality of CP-ABE critical components regardless of their heterogeneous privacy requirements. We evaluated our proposal considering a case study in the eHealth domain, whose results confirm its deployment feasibility in practical applications, where confidentiality and access control hold while resiliency and the system\u2019s continuous operation are achieved.<\/jats:p>","DOI":"10.3389\/fbloc.2025.1622270","type":"journal-article","created":{"date-parts":[[2025,10,7]],"date-time":"2025-10-07T05:34:40Z","timestamp":1759815280000},"update-policy":"https:\/\/doi.org\/10.3389\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Blockchain-based decentralization approach for Ciphertext-Policy Attribute-Based Encryption schemes"],"prefix":"10.3389","volume":"8","author":[{"given":"Melissa Brigitthe","family":"Hinojosa-Cabello","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rocio","family":"Aldeco-Perez","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Miguel","family":"Morales-Sandoval","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jose Juan","family":"Garcia-Hernandez","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1965","published-online":{"date-parts":[[2025,10,7]]},"reference":[{"key":"B1","unstructured":"Algorand parameter tables\n          \n          \n          2025"},{"key":"B2","article-title":"Algorand consensus","year":"2024"},{"key":"B3","article-title":"Attribute-based encryption for attribute-based authentication, authorization, storage, and transmission in distributed storage systems","author":"Alston","year":"2017"},{"key":"B4","doi-asserted-by":"publisher","first-page":"1298","DOI":"10.1007\/s00145-018-9280-5","article-title":"Updating key size estimations for pairings","volume":"32","author":"Barbulescu","year":"2019","journal-title":"J. Cryptol."},{"key":"B5","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1109\/SP.2007.11","article-title":"Ciphertext-policy attribute-based encryption","volume-title":"2007 IEEE symposium on security and privacy (SP \u201907)","author":"Bethencourt","year":"2007"},{"key":"B6","article-title":"Blockchain-based distributed attribute based encryption","author":"Bramm","year":"2018"},{"key":"B7","doi-asserted-by":"crossref","first-page":"16002","DOI":"10.1007\/978-3-032-01881-6_1","article-title":"Registered ABE and adaptively-secure broadcast encryption from succinct LWE","volume-title":"In Advances in Cryptology -- CRYPTO 2025","author":"Champion","year":"2025"},{"key":"B8","doi-asserted-by":"crossref","first-page":"515","DOI":"10.1007\/978-3-540-70936-7_28","article-title":"Multi-authority attribute based encryption","volume-title":"Theory of cryptography conference","author":"Chase","year":"2007"},{"key":"B9","first-page":"121","article-title":"Improving privacy and security in multi-authority attribute-based encryption","volume-title":"Proceedings of the 16th ACM conference on computer and communications security","author":"Chase","year":"2009"},{"key":"B10","doi-asserted-by":"publisher","first-page":"747","DOI":"10.1109\/TSC.2023.3349305","article-title":"A lightweight authentication-driven trusted management framework for iot collaboration","volume":"17","author":"Cheng","year":"2024","journal-title":"IEEE Trans. Serv. Comput."},{"key":"B11","doi-asserted-by":"crossref","first-page":"456","DOI":"10.1145\/1315245.1315302","article-title":"Provably secure ciphertext policy Abe","volume-title":"Proceedings of the 14th ACM conference on computer and communications security","author":"Cheung","year":"2007"},{"key":"B12","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1109\/CONISOFT58849.2023.00013","article-title":"On the formal verification of smart contracts","volume-title":"2023 11th international conference in software engineering research and innovation (CONISOFT)","author":"D\u00e1vila","year":"2023"},{"key":"B13","article-title":"Pbft vs proof-of-authority: applying the cap theorem to permissioned blockchain","author":"De Angelis","year":"2018"},{"key":"B14","doi-asserted-by":"publisher","first-page":"1524222","DOI":"10.3389\/fbloc.2025.1524222","article-title":"Exploring the decentralized science ecosystem: insights on organizational structures, technologies, and funding","volume":"8","author":"D\u00edaz","year":"2025","journal-title":"Front. Blockchain"},{"key":"B15","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1109\/RIVF55975.2022.10013886","article-title":"A blockchain-based approach and attribute-based encryption for healthcare record data exchange","volume-title":"2022 RIVF international conference on computing and communication technologies (RIVF)","author":"Do Hoang","year":"2022"},{"key":"B16","doi-asserted-by":"publisher","first-page":"5784","DOI":"10.1109\/tvt.2020.2967099","article-title":"Trustaccess: a trustworthy secure ciphertext-policy and attribute hiding access control scheme based on blockchain","volume":"69","author":"Gao","year":"2020","journal-title":"IEEE Trans. Veh. Technol."},{"key":"B17","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1145\/3132747.3132757","article-title":"Algorand: scaling byzantine agreements for cryptocurrencies","volume-title":"Proceedings of the 26th symposium on operating systems principles","author":"Gilad","year":"2017"},{"key":"B18","unstructured":"NIST recommendation for key management\n          \n          \n            \n              Giry\n              D.\n            \n          \n          \n          2020"},{"key":"B19","doi-asserted-by":"crossref","first-page":"89","DOI":"10.1145\/1180405.1180418","article-title":"Attribute-based encryption for fine-grained access control of encrypted data","volume-title":"Proceedings of the 13th ACM conference on computer and communications security","author":"Goyal","year":"2006"},{"key":"B20","doi-asserted-by":"crossref","DOI":"10.1007\/3-540-38424-3_32","volume-title":"How to time-stamp a digital document","author":"Haber","year":"1991"},{"key":"B21","article-title":"An attribute-based encryption scheme for storage, sharing and retrieval of digital documents in the cloud","author":"Hinojosa-Cabello","year":"2020","journal-title":"Master\u2019s thesis, Cinvestav"},{"key":"B22","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/ENC56672.2022.9882941","article-title":"Novel constructions for ciphertext-policy attribute-based searchable encryption","volume-title":"2022 IEEE Mexican international conference on computer science (ENC)","author":"Hinojosa-Cabello","year":"2022"},{"key":"B23","volume-title":"Towards secure and intelligent diagnosis: deep learning and blockchain technology for computer-aided diagnosis systems","author":"Hosseinzadeh","year":"2021"},{"key":"B24","doi-asserted-by":"publisher","first-page":"1198","DOI":"10.3390\/sym11101198","article-title":"A review of blockchain architecture and consensus protocols: use cases, challenges, and solutions","volume":"11","author":"Ismail","year":"2019","journal-title":"Symmetry"},{"key":"B25","doi-asserted-by":"publisher","first-page":"1544770","DOI":"10.3389\/fbloc.2025.1544770","article-title":"Revolutionizing the energy sector: exploring diversified blockchain platforms for a sustainable future","volume":"8","author":"Jayavarma","year":"2025","journal-title":"Front. Blockchain"},{"key":"B26","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1155\/2021\/6693731","article-title":"A research survey on applications of consensus protocols in blockchain","volume":"2021","author":"Kaur","year":"2021","journal-title":"Secur. Commun. Netw."},{"key":"B27","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1016\/j.jnca.2018.02.009","article-title":"Attribute based encryption in cloud computing: a survey, gap analysis, and future directions","volume":"108","author":"Kumar","year":"2018","journal-title":"Netw. Comput. Appl."},{"key":"B28","first-page":"568","article-title":"Decentralizing attribute-based encryption","volume-title":"Annual international conference on the theory and applications of cryptographic techniques","author":"Lewko","year":"2011"},{"key":"B29","doi-asserted-by":"publisher","first-page":"194","DOI":"10.1109\/tdsc.2016.2550437","article-title":"Attribute-based access control for icn naming scheme","volume":"15","author":"Li","year":"2016","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"B30","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1109\/trustcom.2016.0055","article-title":"Dynamic attribute-based access control in cloud storage systems","author":"Liu","year":"2016","journal-title":"IEEE Trustcom\/BigDataSE\/ISPA"},{"key":"B31","doi-asserted-by":"publisher","first-page":"112","DOI":"10.1016\/j.jnca.2018.01.016","article-title":"Practical attribute-based encryption: outsourcing decryption, attribute revocation and policy updating","volume":"108","author":"Liu","year":"2018","journal-title":"J. Netw. Comput. Appl."},{"key":"B32","doi-asserted-by":"publisher","first-page":"110766","DOI":"10.1016\/j.comnet.2024.110766","article-title":"An enhanced traceable access control scheme based on multi-authority cp-abe for cloud-assisted e-health system","volume":"254","author":"Liu","year":"2024","journal-title":"Comput. Netw."},{"key":"B33","doi-asserted-by":"publisher","first-page":"10821","DOI":"10.1109\/tii.2023.3241618","article-title":"Be-trdss: blockchain-Enabled secure and efficient traceable-revocable data-sharing scheme in industrial internet of things","volume":"19","author":"Ma","year":"2023","journal-title":"IEEE Trans. Industrial Inf."},{"key":"B34","doi-asserted-by":"publisher","first-page":"1102","DOI":"10.1007\/978-3-319-61273-7_5","article-title":"Challenges with assessing the impact of NFS advances on the security of pairing-based cryptography","volume":"2016","author":"Menezes","year":"2016","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"B35","doi-asserted-by":"crossref","first-page":"120","DOI":"10.1109\/SFFCS.1999.814584","article-title":"Verifiable random functions","volume-title":"40th annual symposium on foundations of computer science (cat. No. 99CB37039)","author":"Micali","year":"1999"},{"key":"B36","volume-title":"Applied statistics and probability for engineers","author":"Montgomery","year":"2013"},{"key":"B37","first-page":"20","article-title":"Distributed attribute-based encryption","volume-title":"International conference on information security and cryptology","author":"M\u00fcller","year":"2008"},{"key":"B38","article-title":"A peer-to-peer electronic cash system","author":"Nakamoto","year":"2008"},{"key":"B39","first-page":"305","article-title":"In search of an understandable consensus algorithm","volume-title":"USENIX annual technical conference (USENIX ATC 14)","author":"Ongaro","year":"2014"},{"key":"B40","article-title":"Blockchain: que es y Como funciona esta tecnologia","author":"Pastorino","year":"2022"},{"key":"B41","doi-asserted-by":"publisher","first-page":"101854","DOI":"10.1016\/j.sysarc.2020.101854","article-title":"A blockchain-based access control scheme with multiple attribute authorities for secure cloud data sharing","volume":"112","author":"Qin","year":"2021","journal-title":"J. Syst. Archit."},{"key":"B42","first-page":"33","article-title":"La blockchain: fundamentos, aplicaciones y relacion con otras tecnologias disruptivas","volume":"405","author":"Retamal","year":"2017","journal-title":"Econ. Ind."},{"key":"B43","first-page":"457","article-title":"Fuzzy identity-based encryption","author":"Sahai","year":"2005"},{"key":"B44","first-page":"495","article-title":"Cryptography in blockchain","volume-title":"19th international conference, Saint Petersburg, Russia, July 1\u20134, 2019, proceedings, part II 19","author":"Storublevtcev","year":"2019"},{"key":"B45","doi-asserted-by":"publisher","first-page":"419","DOI":"10.1145\/6041.6074","article-title":"Distributed operating systems","volume":"17","author":"Tanenbaum","year":"1985","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"B46","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1007\/978-3-642-19379-8_4","article-title":"Ciphertext-policy attribute-based encryption: an expressive, efficient, and provably secure realization","volume-title":"Public key cryptography \u2013 PKC 2011","author":"Waters","year":"2011"},{"key":"B47","doi-asserted-by":"publisher","first-page":"1495984","DOI":"10.3389\/fbloc.2025.1495984","article-title":"Improved blockchain-based ecdsa batch verification scheme","volume":"8","author":"Wu","year":"2025","journal-title":"Front. Blockchain"},{"key":"B48","first-page":"45","volume-title":"Do you need a blockchain?","author":"W\u00fcst","year":"2018"},{"key":"B49","doi-asserted-by":"publisher","first-page":"1432","DOI":"10.1109\/comst.2020.2969706","article-title":"A survey of distributed consensus protocols for blockchain networks","volume":"22","author":"Xiao","year":"2020","journal-title":"IEEE Commun. Surv. & Tutorials"},{"key":"B50","doi-asserted-by":"publisher","first-page":"1691","DOI":"10.3390\/electronics12071691","article-title":"An improved multi-authority attribute access control scheme base on blockchain and elliptic curve for efficient and secure data sharing","volume":"12","author":"Xie","year":"2023","journal-title":"Electronics"},{"key":"B51","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.IR.8202","article-title":"Blockchain technology overview","author":"Yaga","year":"2018","journal-title":"Tech. Rep."},{"key":"B52","doi-asserted-by":"publisher","first-page":"10812","DOI":"10.3390\/app122110812","article-title":"Blockchain-based multiple authorities attribute-based encryption for ehr access control scheme","volume":"12","author":"Yang","year":"2022","journal-title":"Appl. Sci."},{"key":"B53","doi-asserted-by":"publisher","first-page":"100199","DOI":"10.1016\/j.hcc.2024.100199","article-title":"An attribute-based access control scheme using blockchain technology for iot data protection","volume":"4","author":"Yang","year":"2024","journal-title":"High-Confidence Comput."},{"key":"B54","doi-asserted-by":"publisher","first-page":"1213","DOI":"10.1109\/tem.2020.2966643","article-title":"Enabling attribute revocation for fine-grained access control in blockchain-iot systems","volume":"67","author":"Yu","year":"2020","journal-title":"IEEE Trans. Eng. Manag."},{"key":"B55","doi-asserted-by":"publisher","first-page":"10556","DOI":"10.3390\/su131910556","article-title":"An attribute-based access control for iot using blockchain and smart contracts","volume":"13","author":"Zaidi","year":"2021","journal-title":"Sustainability"},{"key":"B56","doi-asserted-by":"crossref","DOI":"10.1088\/1742-6596\/1168\/3\/032077","article-title":"Research on the application of cryptography on the blockchain","author":"Zhai","year":"2019"},{"key":"B57","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1145\/3528416.3530228","article-title":"Patient-centered cross-enterprise document sharing and dynamic consent framework using consortium blockchain and ciphertext-policy attribute-based encryption","volume-title":"Proceedings of the 19th ACM international conference on computing frontiers","author":"Zhang","year":"2022"},{"key":"B58","first-page":"547","article-title":"Efficient access-control in the iiot through attribute-based encryption with outsourced decryption","author":"Ziegler","year":"2020"}],"container-title":["Frontiers in Blockchain"],"original-title":[],"link":[{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fbloc.2025.1622270\/full","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,7]],"date-time":"2025-10-07T05:34:47Z","timestamp":1759815287000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fbloc.2025.1622270\/full"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,7]]},"references-count":58,"alternative-id":["10.3389\/fbloc.2025.1622270"],"URL":"https:\/\/doi.org\/10.3389\/fbloc.2025.1622270","relation":{},"ISSN":["2624-7852"],"issn-type":[{"value":"2624-7852","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,7]]},"article-number":"1622270"}}