h1

h2

h3

h4

h5
h6
http://join2-wiki.gsi.de/foswiki/pub/Main/Artwork/join2_logo100x88.png

Privacy-preserving kidney exchange



Verantwortlichkeitsangabevorgelegt von Malte Breuer, M.Sc. RWTH

ImpressumAachen : RWTH Aachen University 2024

Umfang1 Online-Ressource : Illustrationen


Dissertation, RWTH Aachen University, 2024

Veröffentlicht auf dem Publikationsserver der RWTH Aachen University


Genehmigende Fakultät
Fak01

Hauptberichter/Gutachter
;

Tag der mündlichen Prüfung/Habilitation
2024-08-16

Online
DOI: 10.18154/RWTH-2024-08605
URL: https://publications.rwth-aachen.de/record/993101/files/993101.pdf

Einrichtungen

  1. Lehr- und Forschungsgebiet IT-Sicherheit (123520)
  2. Fachgruppe Informatik (120000)

Inhaltliche Beschreibung (Schlagwörter)
graph algorithms (frei) ; healthcare security (frei) ; kidney exchange (frei) ; privacy (frei) ; secure multi-party computation (frei) ; simulation (frei)

Thematische Einordnung (Klassifikation)
DDC: 004

Kurzfassung
Chronisches Nierenversagen hat sich zu einer der häufigsten natürlichen Todesursachen in unserer Gesellschaft entwickelt. Eine Möglichkeit der Behandlung ist die Transplantation einer Niere von einem Lebenspender. Ein Problem, welches eine solche Lebendspende häufig verhindert, ist, dass der potentielle Spender medizinisch nicht kompatibel zum Patienten ist. Eine Lösung für dieses Problem ist Nierenspendertausch. Dabei tauscht der Patient seinen inkompatiblen Spender mit einem anderen Patienten, welcher auch einen inkompatiblen Spender hat. Heutzutage gibt es in vielen Ländern bereits Systeme, welche den Nierenspendertausch für Patienten organisieren. Diese operieren häufig auf nationaler Ebene. Krankenhäuser können dabei ihre Patienten mit deren inkompatiblen Spendern bei einer zentralen Plattform registrieren. Diese Plattform berechnet dann mögliche Tauschkonstellationen zwischen den Patienten und Lebendspendern. Dieser Ansatz birgt jedoch signifikante Sicherheitsrisiken, welche die existierenden Systeme anfällig für Manipulation und Korruption machen. Das Hauptproblem besteht darin, dass der Betreiber der zentralen Plattform alleine verantwortlich für die Berechnung der Tauschkonstellationen ist. Das bedeutet, dass der Betreiber zum Beispiel die Berechnung so manipulieren kann, dass gewisse Patienten bevorzugt behandelt werden. Dadurch wird der Betreiber nicht nur anfällig für Korruption, sondern die Plattform wird auch zu einem sehr attraktivem Ziel für Angreifer mit der Absicht die Berechnung der Tauschkonstellationen zu manipulieren. Dies wird sogar noch dadurch verstärkt, dass die sensitiven Daten vieler Patienten und Spender bei der Plattform vorliegen. Daher betrifft jeder Angriff, welcher zu einem Datenleck führt, direkt die sensitiven Daten von vielen Patienten und Spendern. Das Hauptziel dieser Arbeit ist die Entwicklung eines privatsphäre-wahrenden Ansatzes für ein System zum Nierenspendertausch, welches resistent gegen Manipulation und Korruption ist und die sensitiven Daten der Patienten und Spenderschützt. Wir stellen ein Modell eines solchen privatsphäre-wahrenden Systems vor, bei dem die Berechnung der Tauschkonstellationen verteilt von mehreren Berechnungsparteiendurchgeführt wird. Dieses Modell garantiert, dass eine einzelne Berechnungspartei weder in der Lage ist, die Berechnung zu manipulieren, noch Informationen über die sensitiven Daten der Patienten und Spender zu erlangen. Dazu nutzen wir sichere Mehrparteienberechnung. Dieses kryptografische Verfahren erlaubt es mehreren Parteien eine Funktion auf ihren privaten Eingaben zu berechnen, so dass jede Partei nur ihre eigene Eingabe und Ausgabe erfährt, sowie die Informationen, welche davon abgeleitet werden können. Der wichtigste Beitrag dieser Arbeit ist die Entwicklung von Protokollen zur sicheren Mehrparteienberechnung, welche die effiziente Berechnung von Tauschkonstellationen zwischen Patienten und Lebendspendern ermöglichen. Wir evaluieren die Laufzeit unserer Protokolle und zeigen, dass unser effizientestes Protokoll für die in der Praxis zu erwartende Anzahl an Patienten und Spendern skaliert. Basierend darauf simulieren wir die Verwendung unserer Protokolle als Teil unseres privatsphäre-wahrenden Modells. Unsere Simulationen zeigen, dass unser Modell im Laufe der Zeit eine vergleichbare Anzahl an Transplantationen ermöglicht, wie die existierenden Systeme, welche anfällig für Manipulation und Korruption sind. Somit kann unser privatsphäre-wahrender Ansatz die meisten bestehenden Systeme für Nierenspendertausch mit geringen oder sogar vernachlässigbaren Auswirkungen auf die Anzahl der Transplantationen im Laufe der Zeit ersetzen und damit die Sicherheitsgarantien beim Nierenspendertausch deutlich erhöhen.

Chronic kidney disease has become one of the most common causes of natural death in our modern society. The preferred treatment for chronic kidney disease is the transplant of a kidney from a living donor, who is typically a close friend or relative of the patient. An impediment that prevents such a living donation is that the found living donor is sometimes not medically compatible with the patient. Kidney exchange enables a patient to still receive a kidney transplant in such a situation by exchanging the living donor with other patients. Nowadays, many countries have centralized systems that organize kidney exchange, often on a nationwide scale. Hospitals can register their associated pairs of patients and medically incompatible donors with a central platform, which then tries to find potential exchanges among all registered pairs of patients and donors. Such a centralized kidney exchange system, however, harbors severe security risks that make the central platform susceptible to manipulation and corruption. The core issue is that the operator of the platform alone is responsible for the entire computation of the exchanges. This, for example, allows the platform operator to manipulate the computation such that a particular patient is treated with priority. This does not only make the platform operator susceptible to corruption but it also makes the platform a prime target for high impact attacks aimed at manipulating the computation of exchanges. The central platform becomes an even more attractive target for attackers as it stores the sensitive data of many patients and donors. Thus, any attack that leads to a data breach has a direct impact on the privacy of the sensitive data of many individuals. The main research goal of this thesis is to develop an alternative approach for kidney exchange that is resistant to manipulation and corruption, and protects the sensitive data of the involved patients and donors. To this end, we propose the model of a privacy-preserving kidney exchange system that follows a decentralized approach, where the computation of exchanges is distributed among a set of so-called computing peers. This model ensures that a computing peer is neither able to manipulate the computation of the exchanges nor to learn any information on the sensitive data of the involved patients and donors. We achieve this by using a cryptographic technique called secure multi-party computation. This allows a set of parties to compute a functionality on their private inputs such that each party only learns its own input and output and what can be deduced from both. The core contribution of this thesis is then the development of secure multi-party computation protocols that enable the computing peers to efficiently compute the exchanges for a set of patients and their associated medically incompatible donors. We evaluate the run time of all our protocols and show that our most efficient protocol scales for the large numbers of patients and donors that are to be expected in practice. Thereupon, we simulate the use of our most efficient protocols in our model of a privacy-preserving kidney exchange system over time using real-world data. Our simulations show that the number of transplants achieved over time in our privacy-preserving model is comparable to the number of transplants achieved in the model that is implemented by the existing kidney exchange systems that are susceptible to manipulation and corruption. Thus, our model allows for the replacement of most existing kidney exchange systems at a small or sometimes even negligible impact on the number of transplants over time, while significantly increasing the security guarantees compared to the existing systems.

OpenAccess:
Download fulltext PDF
(additional files)

Dokumenttyp
Dissertation / PhD Thesis

Format
online

Sprache
English

Externe Identnummern
HBZ: HT030852246

Interne Identnummern
RWTH-2024-08605
Datensatz-ID: 993101

Beteiligte Länder
Germany

 GO


OpenAccess

QR Code for this record

The record appears in these collections:
Document types > Theses > Ph.D. Theses
Publication server / Open Access
Faculty of Computer Science (Fac.9)
Public records
Publications database
120000
123520

 Record created 2024-09-17, last modified 2025-11-10


OpenAccess:
Download fulltext PDF
(additional files)
Rate this document:

Rate this document:
1
2
3
 
(Not yet reviewed)