Enabling Multi-Client Authorization in Dynamic SSE
Seydina Ousmane Diallo, Maryline Laurent, Nesrine Kaaniche

TL;DR
This paper introduces MASSE, a dynamic multi-client searchable encryption scheme with attribute-based access control, enabling scalable, privacy-preserving searches with efficient updates and revocation in cloud environments.
Contribution
MASSE extends the OXT framework to support multi-client, attribute-based access control with dynamic updates, revocation, and formal security proofs, improving scalability and privacy over existing solutions.
Findings
MASSE achieves fast query generation and retrieval times.
It outperforms existing solutions like OXT in scalability and efficiency.
The scheme maintains forward and backward privacy under defined leakage profiles.
Abstract
Outsourcing encrypted data to the cloud creates a fundamental tension between data privacy and functional searchability. Current Searchable Symmetric Encryption (SSE) solutions frequently have significant limitations, such as excessive metadata leakage, or a lack of fine-grained access control. These issues restrict the scalability of secure searches in real-world applications where multiple clients require different levels of authorization. Our paper proposes MASSE, a dynamic multi-client SSE scheme incorporating attribute-based access control, which expands the OXT framework. With MASSE, clients are restricted sto searching for keywords authorized by their specific attribute sets, and the server remains unaware of the keywords and attributes. MASSE supports practical dynamic updates to documents, and client authorizations, including revocation, without requiring reencryption of the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCryptography and Data Security · Cloud Data Security Solutions · Access Control and Trust
