Computer ScienceMedicine

F. Alshahrani, Bander A. Alzahrani, M. Ramzan

2026.2.28KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS

DOI: 10.3837/tiis.2026.02.019

Abstract

Named data networking (NDN) is the leading information-centric networking (ICN) architecture in academic research. It has emerged as a promising foundation for modern systems, including Internet of Things (IoT) platforms, cloud infrastructures, and large-scale distributed environments. This is due to its support for features such as in-network caching and content-centric data retrieval. However, NDN still faces major security challenges, particularly the lack of fine-grained access control and persistent privacy risks associated with sensitive data. This work addresses these weaknesses by introducing a comprehensive security framework grounded in zero trust access control (ZTAC) principles and specifically tailored for NDN-based healthcare environments. Building on the core ZTAC pillars: (a) continuous verification, (b) micro-segmentation, (c) least-privilege access, and (d) privacy protection, we propose a novel access control scheme. The proposed scheme relies on two incorporated techniques: (a) attribute-based access control (ABAC), and (b) proxy re-encryption (PRE), which enables dynamic, policy-driven authorization while securely delegating decryption rights only to eligible users. The proposed solution reduces round-trip time by up to 78.8% compared to existing approaches while maintaining strong scalability across large network sizes, high traffic loads, and growing content volumes. It preserves more than 94% accuracy in both access success and denial rates under heavy load. It improves inference resistance by over 13.5% compared to the baseline NDN, demonstrating strong privacy protection and robust performance. Overall, this framework delivers an efficient, secure, scalable, and privacy-preserving foundation for modern healthcare systems built on NDN.

Citation format

ALSHAHRANI, F.; ALZAHRANI, Bander A.; RAMZAN, M. Zero trust access control framework for NDN-based healthcare systems using attribute-based access control and proxy re-encryption. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2026, 20: 1037–1065.