{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,30]],"date-time":"2025-12-30T17:58:06Z","timestamp":1767117486549,"version":"build-2065373602"},"reference-count":39,"publisher":"MDPI AG","issue":"11","license":[{"start":{"date-parts":[[2021,10,30]],"date-time":"2021-10-30T00:00:00Z","timestamp":1635552000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Managing and controlling access to the tremendous data in Cloud storage is very challenging. Due to various entities engaged in the Cloud environment, there is a high possibility of data tampering. Cloud encryption is being employed to control data access while securing Cloud data. The encrypted data are sent to Cloud storage with an access policy defined by the data owner. Only authorized users can decrypt the encrypted data. However, the access policy of the encrypted data is in readable form, which results in privacy leakage. To address this issue, we proposed a reinforcement hiding in access policy over Cloud storage by enhancing the Ciphertext Policy Attribute-based Encryption (CP-ABE) algorithm. Besides the encryption process, the reinforced CP-ABE used logical connective operations to hide the attribute value of data in the access policy. These attributes were converted into scrambled data along with a ciphertext form that provides a better unreadability feature. It means that a two-level concealed tactic is employed to secure data from any unauthorized access during a data transaction. Experimental results revealed that our reinforced CP-ABE had a low computational overhead and consumed low storage costs. Furthermore, a case study on security analysis shows that our approach is secure against a passive attack such as traffic analysis.<\/jats:p>","DOI":"10.3390\/fi13110279","type":"journal-article","created":{"date-parts":[[2021,11,1]],"date-time":"2021-11-01T22:21:08Z","timestamp":1635805268000},"page":"279","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Towards Virtuous Cloud Data Storage Using Access Policy Hiding in Ciphertext Policy Attribute-Based Encryption"],"prefix":"10.3390","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5026-1925","authenticated-orcid":false,"given":"Siti Dhalila","family":"Mohd Satar","sequence":"first","affiliation":[{"name":"Department of Communication Technology and Networks, Universiti Putra Malaysia (UPM), Serdang 43400, Selangor, Malaysia"},{"name":"Centre of Computer Science Study, Universiti Sultan Zainal Abidin, Kampus Besut, Besut 22200, Terengganu, Malaysia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Masnida","family":"Hussin","sequence":"additional","affiliation":[{"name":"Department of Communication Technology and Networks, Universiti Putra Malaysia (UPM), Serdang 43400, Selangor, Malaysia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8079-1791","authenticated-orcid":false,"given":"Zurina Mohd","family":"Hanapi","sequence":"additional","affiliation":[{"name":"Department of Communication Technology and Networks, Universiti Putra Malaysia (UPM), Serdang 43400, Selangor, Malaysia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohamad Afendee","family":"Mohamed","sequence":"additional","affiliation":[{"name":"Centre of Computer Science Study, Universiti Sultan Zainal Abidin, Kampus Besut, Besut 22200, Terengganu, Malaysia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2021,10,30]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"22313","DOI":"10.1109\/ACCESS.2017.2757844","article-title":"A Security Model for Preserving the Privacy of Medical Big Data in a Healthcare Cloud Using a Fog Computing Facility with Pairing-Based Cryptography","volume":"5","author":"Rahman","year":"2017","journal-title":"IEEE Access"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"37","DOI":"10.1016\/j.jnca.2018.02.009","article-title":"Attribute based encryption in cloud computing: A survey, gap analysis, and future directions","volume":"108","author":"Kumar","year":"2018","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"634","DOI":"10.1108\/ICS-07-2016-0051","article-title":"To cloud or not to cloud: How risks and threats are affecting cloud adoption decisions","volume":"25","author":"Kajiyama","year":"2017","journal-title":"Inf. Comput. Secur."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"165155","DOI":"10.1109\/ACCESS.2019.2953227","article-title":"Reliable Access Control for Mobile Cloud Computing (MCC) With Cache-Aware Scheduling","volume":"7","author":"Jamal","year":"2019","journal-title":"IEEE Access"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"465","DOI":"10.1016\/j.procs.2017.06.124","article-title":"A Comprehensive Survey on Security in Cloud Computing","volume":"110","author":"Ramachandra","year":"2017","journal-title":"Procedia Comput. Sci."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"387","DOI":"10.1109\/JSYST.2019.2911391","article-title":"Improving Security and Privacy Attribute Based Data Sharing in Cloud Computing","volume":"14","author":"Zhang","year":"2019","journal-title":"IEEE Syst. J."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"74","DOI":"10.1016\/j.future.2014.06.004","article-title":"A hybrid solution for privacy preserving medical data sharing in the cloud environment","volume":"43\u201344","author":"Yang","year":"2015","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"102","DOI":"10.14419\/ijet.v7i3.28.20978","article-title":"Data Privacy and Integrity Issues Scheme in Cloud Computing: A Survey","volume":"7","author":"Satar","year":"2018","journal-title":"Int. J. Eng. Technol."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1016\/j.ins.2016.12.034","article-title":"Cryptography and Data Security in Cloud Computing","volume":"387","author":"Yan","year":"2017","journal-title":"Inf. Sci."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Somani, U., Lakhani, K., and Mundra, M. (2010, January 28\u201330). Implementing digital signature with RSA encryption algorithm to enhance the Data Security of cloud in Cloud Computing. Proceedings of the 2010 First International Conference On Parallel, Distributed and Grid Computing (PDGC 2010), Solan, India.","DOI":"10.1109\/PDGC.2010.5679895"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Lai, J., Deng, R.H., and Li, Y. (2012, January 2\u20134). Expressive CP-ABE with partially hidden access structures. Proceedings of the 7th ACM Symposium on Information, Computer and Communications Security, Seoul, Korea.","DOI":"10.1145\/2414456.2414465"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"296","DOI":"10.1016\/j.jesit.2015.11.005","article-title":"Two-phase hybrid cryptography algorithm for wireless sensor networks","volume":"2","author":"Rizk","year":"2015","journal-title":"J. Electr. Syst. Inf. Technol."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"751","DOI":"10.1016\/j.procs.2016.07.286","article-title":"Optimized Public Auditing and Data Dynamics for Data Storage Security in Cloud Computing","volume":"93","author":"Singh","year":"2016","journal-title":"Procedia Comput. Sci."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"175","DOI":"10.1016\/j.procs.2016.03.023","article-title":"Homomorphic Encryption for Security of Cloud Data","volume":"79","author":"Potey","year":"2016","journal-title":"Procedia Comput. Sci."},{"key":"ref_15","first-page":"393","article-title":"Cloud-Based Secure Healthcare Framework by using Enhanced Ciphertext Policy Attribute-Based Encryption Scheme","volume":"12","author":"Satar","year":"2021","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"24","DOI":"10.1007\/s41019-017-0046-0","article-title":"Data Privacy Protection Mechanisms in Cloud","volume":"3","author":"Singh","year":"2017","journal-title":"Data Sci. Eng."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"50","DOI":"10.1016\/j.sysarc.2017.03.002","article-title":"Access control based privacy preserving secure data sharing with hidden access policies in cloud","volume":"75","author":"Sabitha","year":"2017","journal-title":"J. Syst. Arch."},{"key":"ref_18","unstructured":"Sahai, A., and Waters, B. (2021, October 15). Fuzzy Identity-Based Encryption. Lecture Notes in Computer Science, Available online: https:\/\/eprint.iacr.org\/2004\/086.pdf."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Bethencourt, J., Sahai, A., and Waters, B. (2007, January 20\u201323). Ciphertext-policy attribute-based encryption. Proceedings of the 2007 IEEE Symposium on Security and Privacy (SP\u201907), Berkeley, CA, USA.","DOI":"10.1109\/SP.2007.11"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"64","DOI":"10.14419\/ijet.v7i2.15.11215","article-title":"Current Issues in Ciphertext Policy-Attribute Based Scheme for Cloud Computing: A Survey","volume":"7","author":"Muhammad","year":"2018","journal-title":"Int. J. Eng. Technol."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"99","DOI":"10.1016\/j.neucom.2016.06.100","article-title":"Secure and efficient querying over personal health records in cloud computing","volume":"274","author":"Liu","year":"2018","journal-title":"Neurocomputing"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Khuntia, S., and Kumar, P.S. (2018, January 10\u201312). New Hidden Policy CP-ABE for Big Data Access Control with Privacy-preserving Policy in Cloud Computing. Proceedings of the 2018 9th International Conference on Computing, Communication and Networking Technologies (ICCCNT), Bengaluru, India.","DOI":"10.1109\/ICCCNT.2018.8493698"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"33202","DOI":"10.1109\/ACCESS.2019.2902040","article-title":"Hidden Ciphertext Policy Attribute-Based Encryption with Fast Decryption for Personal Health Record System","volume":"7","author":"Zhang","year":"2019","journal-title":"IEEE Access"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Li, C., Zhang, Y., and Xie, E.Y. (2019). When an attacker meets a cipher-image in 2018: A year in review. J. Inf. Secur. Appl., 48.","DOI":"10.1016\/j.jisa.2019.102361"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"116","DOI":"10.1016\/j.ins.2018.11.031","article-title":"Revocable attribute-based encryption with decryption key exposure resistance and ciphertext delegation","volume":"479","author":"Xu","year":"2018","journal-title":"Inf. Sci."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"53698","DOI":"10.1109\/ACCESS.2018.2871170","article-title":"A Lightweight Policy Preserving EHR Sharing Scheme in the Cloud","volume":"6","author":"Ying","year":"2018","journal-title":"IEEE Access"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"38273","DOI":"10.1109\/ACCESS.2018.2854600","article-title":"Efficient Compressed Ciphertext Length Scheme Using Multi-Authority CP-ABE for Hierarchical Attributes","volume":"6","author":"Zhang","year":"2018","journal-title":"IEEE Access"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"157","DOI":"10.1016\/j.jss.2017.10.020","article-title":"Large universe attribute based access control with efficient decryption in cloud storage system","volume":"135","author":"Fu","year":"2018","journal-title":"J. Syst. Softw."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Nishide, T., Yoneyama, K., and Ohta, K. (2008, January 3\u20136). Attribute-Based encryption with partially hidden encryptor-specified access structures. Proceedings of the International Conference on Applied Cryptography and Network Security, New York, NY, USA.","DOI":"10.1007\/978-3-540-68914-0_7"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"126","DOI":"10.1109\/TC.2013.200","article-title":"Efficient Privacy-Preserving Ciphertext-Policy Attribute Based-Encryption and Broadcast Encryption","volume":"64","author":"Zhou","year":"2015","journal-title":"IEEE Trans. Comput."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Tamizharasi, G.S., Balamurugan, B., and Gaffar, H.A. (2016, January 26\u201327). Privacy preserving ciphertext policy attribute based encryption scheme with efficient and constant ciphertextsize. Proceedings of the 2016 International Conference on Inventive Computation Technologies, Coimbatore, India.","DOI":"10.1109\/INVENTIVE.2016.7830099"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"365","DOI":"10.1109\/JSYST.2020.2996216","article-title":"An Expressive \u201cTest-Decrypt-Verify\u201d Attribute-Based Encryption Scheme with Hidden Policy for Smart Medical Cloud","volume":"15","author":"Hu","year":"2020","journal-title":"IEEE Syst. J."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"157","DOI":"10.1016\/j.comnet.2018.01.034","article-title":"An efficient and expressive ciphertext-policy attribute-based encryption scheme with partially hidden access structures, revisited","volume":"133","author":"Cui","year":"2018","journal-title":"Comput. Netw."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"453","DOI":"10.1016\/j.future.2019.03.008","article-title":"Partially policy-hidden attribute-based broadcast encryption with secure delegation in edge computing","volume":"97","author":"Xiong","year":"2019","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"2130","DOI":"10.1109\/JIOT.2018.2825289","article-title":"Security and Privacy in Smart Health: Efficient Access Control","volume":"5","author":"Zhang","year":"2018","journal-title":"IEEE Internet Things J."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"42","DOI":"10.1016\/j.ins.2016.04.015","article-title":"Ensuring attribute privacy protection and fast decryption for outsourced data security in mobile cloud computing","volume":"379","author":"Zhang","year":"2017","journal-title":"Inf. Sci."},{"key":"ref_37","first-page":"53","article-title":"Ciphertext-policy attribute-based encryption: An expressive, efficient, and provably secure realization","volume":"Volume 6571","author":"Waters","year":"2011","journal-title":"International Workshop on Public Key Cryptography"},{"key":"ref_38","unstructured":"Rosen, K.H. (2021, October 15). Discrete Mathematics and Its Applications. Available online: http:\/\/site.iugaza.edu.ps\/lalsaedi\/files\/2012\/01\/Kenneth_H._Rosen_-_Discrete_Mathematics_and_Its_Applications.pdf."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"2397","DOI":"10.1109\/TCSVT.2017.2707923","article-title":"XOR-Based Visual Cryptographic Schemes with Monotonously Increasing and Flawless Reconstruction Properties","volume":"28","author":"Shyu","year":"2017","journal-title":"IEEE Trans. Circuits Syst. Video Technol."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/13\/11\/279\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T07:23:41Z","timestamp":1760167421000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/13\/11\/279"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,10,30]]},"references-count":39,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2021,11]]}},"alternative-id":["fi13110279"],"URL":"https:\/\/doi.org\/10.3390\/fi13110279","relation":{},"ISSN":["1999-5903"],"issn-type":[{"type":"electronic","value":"1999-5903"}],"subject":[],"published":{"date-parts":[[2021,10,30]]}}}