DOI: 10.1002/cpe.70963 ISSN: 1532-0626

An Improved Secure Blockchain‐Based Remote Patient Monitoring System With Role‐Based Access Control Using IPFS

Hoc Minh Le, Özgür Öksüz

ABSTRACT

This work presents a privacy‐preserving remote healthcare system that integrates blockchain technology with a root seed‐based pseudonymization mechanism and lightweight cryptographic controls. Addressing the privacy risks of public ledgers and the limited computational resources of medical IoT devices, the proposed system focuses strictly on identity unlinkability and metadata‐linkage prevention against public observers while maintaining zero‐encryption plaintext data pipelines to optimize downstream machine learning and data mining utilities. Instead of storing raw data on‐chain, it generates a sequence of deterministic pseudonyms derived from a secret root seed generated at registration and stored in the patient's local secure storage. To protect sensitive health information in the current prototype, the IPFS payload stores nonidentifying sensor readings in plaintext (without patient EOA, pseudonym, or name), while the blockchain stores only metadata (CIDs, timestamps) keyed by one‐time pseudonym identifiers. Metadata and Role‐Based Access Control (RBAC) are managed via smart contracts on the BNB Smart Chain, ensuring that only authorized medical professionals can relink and access a patient's historical data. In the proposed system, instead of , where is the number of the patient's transactions, the patient and the matched doctor only share and store information, allowing the doctor to monitor all of the patient's transactions. In addition, once a doctor is revoked from the system, the new doctor is given only (instead of ) information to retrieve all transaction history of the patient. This system architecture incorporates a relaying mechanism to prevent linkage via transaction gas funding. Experimental results on BNB Smart Chain Testnet show that the framework achieves unlinkability and identity privacy for public observers—preventing record linkage to a single patient—while authorized doctors can correctly relink and retrieve records; in our functional tests (one hundred uploads), all retrieved records matched the original inputs (0 mismatch). In addition, the proposed system allows machine learning or data mining analysis of patients' data because it does not apply confidentiality encryption in the current prototype.