On the Practicality of Cryptographically Enforcing Dynamic Access Control Policies in the Cloud
William C. Garrison III, Adam Shull, Steven A. Myers, Adam J. Lee
Abstract
The ability to enforce robust and dynamic access controls on cloud-hosted data while simultaneously ensuring confidentiality with respect to the cloud itself is a clear goal for many users and organizations. To this end, there has been much cryptographic research proposing the use of (hierarchical) identity-based encryption, attribute-based encryption, predicate encryption, functional encryption, and related technologies to perform robust and private access control on untrusted cloud providers. However, the vast majority of this work studies static models in which the access control policies being enforced do not change over time. This is contrary to the needs of most practical applications, which leverage dynamic data and/or policies. In this paper, we show that the cryptographic enforcement of dynamic access controls on untrusted platforms incurs computational costs that are likely prohibitive in practice. Specifically, we develop lightweight constructions for enforcing role-based access controls (i.e., RBAC0) over cloud-hosted files using identity-based and traditional public-key cryptography. This is done under a threat model as close as possible to the one assumed in the cryptographic literature. We prove the correctness of these constructions, and leverage real-world RBAC datasets and recent techniques developed by the access control community to experimentally analyze, via simulation, their associated computational costs. This analysis shows that supporting revocation, file updates, and other state change functionality is likely to incur prohibitive overheads in even minimally-dynamic, realistic scenarios. We identify a number of bottlenecks in such systems, and fruitful areas for future work that will lead to more natural and efficient constructions for the cryptographic enforcement of dynamic access controls. Our findings naturally extend to the use of more expressive cryptographic primitives (e.g., HIBE or ABE) and richer access control models (e.g., RBAC1 or ABAC).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- Ghostor: Toward a Secure Data-Sharing System from Decentralized TrustYuncong Hu, Sam Kumar, Raluca Ada PopaNSDI 2020 · 48 citations
- TimeCrypt: Encrypted Data Stream Processing at Scale with Cryptographic Access ControlLukas Burkhalter, Anwar Hithnawi, Alexander Viand, Hossein Shafagh et al.NSDI 2020 · 18 citations
- PACS: Privacy-Preserving Attribute-Driven Community Search over Attributed GraphsFangyuan Sun, Yaxi Yang, Jia Yu, Jianying ZhouNDSS 2026 · 1 citation
- Droplet: Decentralized Authorization and Access Control for Encrypted Data StreamsHossein Shafagh, Lukas Burkhalter, Sylvia Ratnasamy, Anwar HithnawiUSENIX Security 2020
Related papers
- SACK: Shielding Dynamic Attribute-based Access Control in Persistent Key-Value StoresYanjing Ren, Jingwei Li, Patrick LeeVLDB 2026
- Make Revocation Cheaper: Hardware-Based Revocable Attribute-Based EncryptionXiaoguo Li, Guomin Yang, Tao Xiang, Shengmin Xu et al.S&P 2024 · 19 citations
- Mix&Slice: Efficient Access Revocation in the CloudEnrico Bacis, Sabrina De Capitani di Vimercati, Sara Foresti, Stefano Paraboschi et al.CCS 2016 · 51 citations
- Fine-Grained Secure Attribute-Based EncryptionYuyu Wang, Jiaxin Pan, Yu ChenCRYPTO 2021 · 10 citations
- Towards Practical Oblivious JoinZhao Chang, Dong Xie, Sheng Wang, Feifei LiSIGMOD 2022 · 20 citations
