International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News item: 26 September 2022

Bin Liu, Antonis Michalas, Bogdan Warinschi
ePrint Report ePrint Report
In this paper, we follow the line of existing study on cryptographic enforcement of Role-Based Access Control (RBAC). Inspired by the study of the relation between the existing security definitions for such system, we identify two different types of attacks which cannot be captured by the existing ones. Therefore, we propose two new security definitions towards the goal of appropriately modelling cryptographic enforcement of Role-Based Access Control policies and study the relation between our new definitions and the existing ones. In addition, we show that the cost of supporting dynamic policy update is inherently expensive by presenting two lower bounds for such systems which guarantee correctness and secure access.
Expand

Additional news items may be found on the IACR news page.