ESPOON: Enforcing Encrypted Security Policies in Outsourced Environments
Muhammad Rizwan Asghar, Mihaela Ion, Giovanni Russello, Bruno, Crispo

TL;DR
ESPOON introduces a method for enforcing security policies in untrusted outsourced environments by separating policies from enforcement mechanisms and minimizing information leakage, enhancing confidentiality and flexibility.
Contribution
The paper presents ESPOON, a novel approach that enforces security policies without revealing sensitive policy details or requester attributes in untrusted environments.
Findings
Effective policy enforcement with minimal information leakage
Separation of policies from enforcement mechanisms improves flexibility
Applicable in outsourced environments with confidentiality concerns
Abstract
The enforcement of security policies in outsourced environments is still an open challenge for policy-based systems. On the one hand, taking the appropriate security decision requires access to the policies. However, if such access is allowed in an untrusted environment then confidential information might be leaked by the policies. Current solutions are based on cryptographic operations that embed security policies with the security mechanism. Therefore, the enforcement of such policies is performed by allowing the authorised parties to access the appropriate keys. We believe that such solutions are far too rigid because they strictly intertwine authorisation policies with the enforcing mechanism. In this paper, we want to address the issue of enforcing security policies in an untrusted environment while protecting the policy confidentiality. Our solution ESPOON is aiming at providing…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCryptography and Data Security · Cloud Data Security Solutions · Access Control and Trust
