Authors:
Nesrine Kaaniche
and
Maryline Laurent
Affiliation:
SAMOVAR, CNRS, Telecom SudParis, University Paris-Saclay, Member of the Chair Values and Policies of Personal Information, Paris and France
Keyword(s):
Multi-level Access Control, Ciphertext-policy Attribute-based Encryption, Flexible Access Policies, Data Secrecy.
Related
Ontology
Subjects/Areas/Topics:
Access Control
;
Applied Cryptography
;
Cryptographic Techniques and Key Management
;
Data and Application Security and Privacy
;
Data Engineering
;
Data Protection
;
Databases and Data Security
;
Information and Systems Security
;
Internet Technology
;
Security Protocols
;
Web Information Systems and Technologies
Abstract:
With the emergence of decentralized systems and distributed infrastructures, access control to outsourced data becomes more complex, as it should be flexible and distinguishable among users with different access rights. In this paper, we present SABE, a Selective Attribute-based Encryption scheme, as a new threshold multi-level access control mechanism based on an original use of attribute based encryption schemes. Our proposal is multi-fold. First, it ensures fine-grained access control, supporting multi-security levels with respect to different granted access privileges for each outsourced data file. Second, SABE is proven secure against selective non-adaptive chosen ciphertext attacks in the generic group model. Third, our construction is proven to provide efficient processing and communication complexities, compared to most closely related schemes.