--- res: bibo_abstract: - Cryptographic access control offers selective access to encrypted data via a combination of key management and functionality-rich cryptographic schemes, such as attribute-based encryption. Using this approach, publicly available meta-data may inadvertently leak information on the access policy that is enforced by cryptography, which renders cryptographic access control unusable in settings where this information is highly sensitive. We begin to address this problem by presenting rigorous definitions for policy privacy in cryptographic access control. For concreteness we set our results in the model of Role-Based Access Control (RBAC), where we identify and formalize several different flavors of privacy, however, our framework should serve as inspiration for other models of access control. Based on our insights we propose a new system which significantly improves on the privacy properties of state-of-the-art constructions. Our design is based on a novel type of privacy-preserving attribute-based encryption, which we introduce and show how to instantiate. We present our results in the context of a cryptographic RBAC system by Ferrara et al. (CSF'13), which uses cryptography to control read access to files, while write access is still delegated to trusted monitors. We give an extension of the construction that permits cryptographic control over write access. Our construction assumes that key management uses out-of-band channels between the policy enforcer and the users but eliminates completely the need for monitoring read/write access to the data.@eng bibo_authorlist: - foaf_Person: foaf_givenName: Anna foaf_name: Ferrara, Anna foaf_surname: Ferrara - foaf_Person: foaf_givenName: Georg foaf_name: Fuchsbauer, Georg foaf_surname: Fuchsbauer foaf_workInfoHomepage: http://www.librecat.org/personId=46B4C3EE-F248-11E8-B48F-1D18A9856A87 - foaf_Person: foaf_givenName: Bin foaf_name: Liu, Bin foaf_surname: Liu - foaf_Person: foaf_givenName: Bogdan foaf_name: Warinschi, Bogdan foaf_surname: Warinschi bibo_doi: 10.1109/CSF.2015.11 dct_date: 2015^xs_gYear dct_language: eng dct_publisher: IEEE@ dct_title: Policy privacy in cryptographic access control@ ...