DocumentCode
2078823
Title
Policy Privacy in Cryptographic Access Control
Author
Ferrara, Anna Lisa ; Fachsbauer, Georg ; Liu, Bin ; Warinschi, Bogdan
fYear
2015
fDate
13-17 July 2015
Firstpage
46
Lastpage
60
Abstract
Cryptographic access control offers selective access to encrypted data via a combination of key management and functionality-rich cryptographic schemes, such as attribute-based encryption. Using this approach, publicly available meta-data may inadvertently leak information on the access policy that is enforced by cryptography, which renders cryptographic access control unusable in settings where this information is highly sensitive. We begin to address this problem by presenting rigorous definitions for policy privacy in cryptographic access control. For concreteness we set our results in the model of Role-Based Access Control (RBAC), where we identify and formalize several different flavors of privacy, however, our framework should serve as inspiration for other models of access control. Based on our insights we propose a new system which significantly improves on the privacy properties of state-of-the-art constructions. Our design is based on a novel type of privacy-preserving attribute-based encryption, which we introduce and show how to instantiate. We present our results in the context of a cryptographic RBAC system by Ferrara et al. (CSF´13), which uses cryptography to control read access to files, while write access is still delegated to trusted monitors. We give an extension of the construction that permits cryptographic control over write access. Our construction assumes that key management uses out-of-band channels between the policy enforcer and the users but eliminates completely the need for monitoring read/write access to the data.
Keywords
Access control; Encryption; Monitoring; Privacy; Public key;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Security Foundations Symposium (CSF), 2015 IEEE 28th
Conference_Location
Verona, Italy
Type
conf
DOI
10.1109/CSF.2015.11
Filename
7243724
Link To Document