Content-Moderated Bilateral Access Control for Privacy-Preserving Cloud Data Sharing Services
Abstract
Cloud computing facilitates scalable data sharing across multiple organizations and users, but also raises concerns about data privacy. Matchmaking encryption (ME) is a prominent technique that enforces bilateral access control in cloud services such as cloud marketplace, allowing both senders and receivers to specify policies for the encrypted data to be revealed. However, receivers may be at risk of being exposed to malicious or harmful content, thus undermining their trust in cloud service platforms. To this end, we introduce MBAC, a content-moderated bilateral access control framework for privacy-preserving cloud data sharing services, which allows receivers to acquire data from authentic senders while preserving their anonymity, and report malicious content in a verifiable manner, i.e., empowering the service provider to hold senders accountable. MBAC is built upon a novel primitive called franking broadcast ME (FBME), which generates a franking signature for the data by designating the service provider as the moderator to ensure accountability and deniability, and encrypts both the data and its franking signature while embedding the sender secret key for privacy and authenticity. We then present a concrete construction of FBME from key-private public key encryption, strongly unforgeable one time signature and non-interactive zero-knowledge proof. Formal security analysis and extensive experiments demonstrate that MBAC provides efficient bilateral access control and content moderation for cloud data sharing services.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.