ESPOON$_{{ERBAC}}$: Enforcing Security Policies In Outsourced Environments
Muhammad Rizwan Asghar, Mihaela Ion, Giovanni Russello, Bruno Crispo

TL;DR
This paper introduces ESPOON_ERBAC, a system for enforcing role-based access control policies in outsourced data environments while maintaining data confidentiality and limiting information leakage.
Contribution
It proposes a novel encrypted RBAC enforcement mechanism suitable for untrusted outsourced environments, addressing privacy concerns and supporting complex user management.
Findings
Implemented ESPOON_ERBAC with limited performance overhead
Demonstrated feasibility of encrypted RBAC enforcement in practice
Ensured minimal information leakage to service providers
Abstract
Data outsourcing is a growing business model offering services to individuals and enterprises for processing and storing a huge amount of data. It is not only economical but also promises higher availability, scalability, and more effective quality of service than in-house solutions. Despite all its benefits, data outsourcing raises serious security concerns for preserving data confidentiality. There are solutions for preserving confidentiality of data while supporting search on the data stored in outsourced environments. However, such solutions do not support access policies to regulate access to a particular subset of the stored data. For complex user management, large enterprises employ Role-Based Access Controls (RBAC) models for making access decisions based on the role in which a user is active in. However, RBAC models cannot be deployed in outsourced environments as they rely…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCryptography and Data Security · Access Control and Trust · Privacy-Preserving Technologies in Data
