Skip to content
Conference Open access

A Framework for Context-Aware Read Authorization over Encrypted Data

2026 · International Conference on Security and Cryptography · pp. 121-132 · 0 citations · 17 references
Computer Science

TL;DR

Contextual Reading ACE (CR-ACE), a framework for enforcing context-dependent read authorization without a trusted reference monitor, is introduced and it is proved that it achieves contextual payload privacy, sender anonymity, sanitization security under context, and correct enforcement of both global and context-dependent authorization in the non-collusion model.

Abstract

: Many security and privacy-sensitive systems must control access to encrypted data based on dynamic operational context, such as workflow stage, safety mode, or emergency conditions. Data producers cannot anticipate which context will apply at processing time, and the component observing context cannot be trusted with plaintext or policy structure. Existing mechanisms, including Access Control Encryption (ACE), assume that all authorization-relevant information is fixed at encryption time, and offer no mechanism to incorporate context that becomes available only after the data has been produced and forwarded. We introduce Contextual Reading ACE (CR-ACE), a framework for enforcing context-dependent read authorization without a trusted reference monitor. An honest-but-curious intermediary sanitizes sender ciphertexts and attaches public contextual attributes while remaining oblivious to message contents, principal identities, and authorization logic. Receivers locally enforce authorization as the conjunction of the global ACE policy and a contextual predicate embedded in their key material. We formalize a security model for CR-ACE, provide a construction and prove that it achieves contextual payload privacy, sender anonymity, sanitization security under context, and correct enforcement of both global and context-dependent authorization in our non-collusion model.

Read PDF

Similar papers

Conference Aug 2026

A Security-Level-Aware KP-ABE Scheme with Attribute Revocation and Verifiable Outsourced Decryption for Intelligent Cloud Systems

Intelligent cloud systems are increasingly used to support AI model training, inference services, and cross-domain data collaboration among cloud platforms, edge devices, and organizations. In such environments, data objects such as training samples, inference records, model files, and sensitive user information are fr...

Ping Kang, Song-Lin Gou, Ke-Qin Tang et al. · 0 citations
Open access 2026

SecuAudit: Integrity-Preserving Metadata Compliance Auditing for Secure Data Circulation in MCP-Enabled AI Agents

Security analysis demonstrates that SecuAudit can effectively resist data forgery, metadata tampering, and sub-threshold collusion attacks under the defined threat model, and establishes a feasible framework for secure data circulation under the evaluated deployment assumptions.

Yufa Shi, Jia-Xing Hu, Li-Peng Wang et al. · 0 citations
#artificial intelligence Review Sep 2026

Zero-Trust Authorization and Discovery for Enterprise MCP

LLM agents translate natural-language context, which may include attacker-controlled text, into privileged tool calls, so authorization must remain effective even when an agent is prompt-injected or adversarially steered. The Model Context Protocol (MCP) has become a widely adopted interface for this boundary, yet its...

Huang-Jian Li, Yu-Wei Wang, Srinivasan Manoharan · 1 citation
#artificial intelligence Review Sep 2026

From Review to Authorization: Key-Isolated Threshold Signing for LLM Agents

Autonomous LLM agents can turn untrusted content into effectful actions such as payments and permission changes. If the same process interprets this content and controls a reusable signing credential, prompt injection can cross the judgment boundary and reach execution authority. We present KITA, a review-to-authorizat...

Yu Zheng, Qi-Zhi Zhang · 1 citation
Preprint Aug 2026

Beyond Object Authentication: Context-Closed Post-Quantum Authentication for the WebPKI

Post-quantum migration increases WebPKI authentication cost, but authenticating a compressed certificate object does not by itself preserve the mutable authorization context under which a relying party accepts it. We formalize \emph{context closure}: the authenticated projection accepted by a verifier must determine th...

Anis Bkakria · 0 citations
Aug 2026

A flexible privacy-preserving framework for instant messaging in mobile social networks

A flexible privacy-preserving framework that combines the scalability of broadcast encryption with the fine-grained access control of Attribute-Based Encryption through a novel pseudo-layer encryption model, and achieves confidentiality, forward and backward secrecy, and collusion resistance.

Seyyed Mohammad Safi, Mahnaz Rafie, Sarina Sadat Mirmohammadi · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.