Published November 13, 2022 | Version v1
Conference paper Open

Cryptographic Role-Based Access Control, Reconsidered

  • 1. Tampere University of Technology, Tampere, Finland
  • 2. University of Bristol, Bristol, UK

Description

In this paper, we follow the line of existing study on cryptographic enforcement of Role-Based Access Control (RBAC). Inspired by the study of the relation between the existing security definitions for such system, we identify two different types of attacks which cannot be captured by the existing ones. Therefore, we propose two new security definitions towards the goal of appropriately modelling cryptographic enforcement of Role-Based Access Control policies and study the relation between our new definitions and the existing ones. In addition, we show that the cost of supporting dynamic policy update is inherently expensive by presenting two lower bounds for such systems which guarantee correctness and secure access.

Files

2022-1268.pdf

Files (425.9 kB)

Name Size Download all
md5:ff3580b243632c22c38d1973d3d4053c
425.9 kB Preview Download

Additional details

Funding

European Commission
HARPOCRATES - Federated Data Sharing and Analysis for Social Utility 101069535