{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T01:57:27Z","timestamp":1783475847483,"version":"3.55.0"},"reference-count":51,"publisher":"MDPI AG","issue":"5","license":[{"start":{"date-parts":[[2023,2,27]],"date-time":"2023-02-27T00:00:00Z","timestamp":1677456000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100002383","name":"King Saud University","doi-asserted-by":"publisher","award":["Researchers Supporting Project number (RSPD2023R521)"],"award-info":[{"award-number":["Researchers Supporting Project number (RSPD2023R521)"]}],"id":[{"id":"10.13039\/501100002383","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>With continuous advancements in Internet technology and the increased use of cryptographic techniques, the cloud has become the obvious choice for data sharing. Generally, the data are outsourced to cloud storage servers in encrypted form. Access control methods can be used on encrypted outsourced data to facilitate and regulate access. Multi-authority attribute-based encryption is a propitious technique to control who can access encrypted data in inter-domain applications such as sharing data between organizations, sharing data in healthcare, etc. The data owner may require the flexibility to share the data with known and unknown users. The known or closed-domain users may be internal employees of the organization, and unknown or open-domain users may be outside agencies, third-party users, etc. In the case of closed-domain users, the data owner becomes the key issuing authority, and in the case of open-domain users, various established attribute authorities perform the task of key issuance. Privacy preservation is also a crucial requirement in cloud-based data-sharing systems. This work proposes the SP-MAACS scheme, a secure and privacy-preserving multi-authority access control system for cloud-based healthcare data sharing. Both open and closed domain users are considered, and policy privacy is ensured by only disclosing the names of policy attributes. The values of the attributes are kept hidden. Characteristic comparison with similar existing schemes shows that our scheme simultaneously provides features such as multi-authority setting, expressive and flexible access policy structure, privacy preservation, and scalability. The performance analysis carried out by us shows that the decryption cost is reasonable enough. Furthermore, the scheme is demonstrated to be adaptively secure under the standard model.<\/jats:p>","DOI":"10.3390\/s23052617","type":"journal-article","created":{"date-parts":[[2023,2,28]],"date-time":"2023-02-28T02:01:51Z","timestamp":1677549711000},"page":"2617","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":29,"title":["Secured and Privacy-Preserving Multi-Authority Access Control System for Cloud-Based Healthcare Data Sharing"],"prefix":"10.3390","volume":"23","author":[{"given":"Reetu","family":"Gupta","sequence":"first","affiliation":[{"name":"School of Computer Science and Information Technology, Devi Ahilya Vishwavidyalaya, Indore 452001, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Priyesh","family":"Kanungo","sequence":"additional","affiliation":[{"name":"School of Computer Science and Information Technology, Devi Ahilya Vishwavidyalaya, Indore 452001, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nirmal","family":"Dagdee","sequence":"additional","affiliation":[{"name":"SKITM College, Indore 452020, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4170-3146","authenticated-orcid":false,"given":"Golla","family":"Madhu","sequence":"additional","affiliation":[{"name":"Department of Information Technology, VNR Vignana Jyothi Institute of Engineering and Technology, Hyderabad 500090, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6435-5738","authenticated-orcid":false,"given":"Kshira Sagar","family":"Sahoo","sequence":"additional","affiliation":[{"name":"Department of CSE, SRM University, Amaravati 522240, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8116-4733","authenticated-orcid":false,"given":"N. Z.","family":"Jhanjhi","sequence":"additional","affiliation":[{"name":"School of Computer Science, SCS Taylors University, Subang Jaya 47500, Malaysia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6019-7245","authenticated-orcid":false,"given":"Mehedi","family":"Masud","sequence":"additional","affiliation":[{"name":"Department of Computer Science, College of Computers and Information Technology, Taif University, Taif 21944, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nabil Sharaf","family":"Almalki","sequence":"additional","affiliation":[{"name":"Department of Special Education, College of Education, King Saud University, Riyadh 145111, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5595-4280","authenticated-orcid":false,"given":"Mohammed A.","family":"AlZain","sequence":"additional","affiliation":[{"name":"Department of Information Technology, College of Computers and Information Technology, Taif University, Taif 21944, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,2,27]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"253","DOI":"10.5455\/aim.2019.27.253-258","article-title":"Security requirements of internet of things-based healthcare system: A survey study","volume":"27","author":"Nasiri","year":"2019","journal-title":"Acta Inform. Med."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"293","DOI":"10.1007\/s10586-020-03106-1","article-title":"Privacy preservation in e-health cloud: Taxonomy, privacy requirements, feasibility analysis, and opportunities","volume":"24","author":"Kanwal","year":"2021","journal-title":"Clust. Comput."},{"key":"ref_3","unstructured":"Goyal, V., Pandey, O., Sahai, A., and Waters, B. (November, January 30). Attribute-based encryption for fine-grained access control of encrypted data. Proceedings of the 13th ACM Conference on Computer and Communications Security, Alexandria, VA, USA."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Bethencourt, J., Sahai, A., and Waters, B. (2007, January 20\u201323). Ciphertext-policy attribute-based encryption. Proceedings of the 2007 IEEE Symposium on Security and Privacy (SP\u201907), Berkeley, CA, USA.","DOI":"10.1109\/SP.2007.11"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"2271","DOI":"10.1109\/TKDE.2011.78","article-title":"Improving security and efficiency in attribute-based data sharing","volume":"25","author":"Hur","year":"2011","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"344","DOI":"10.1016\/j.jss.2016.12.018","article-title":"Fine-grained access control system based on fully outsourced attribute-based encryption","volume":"125","author":"Zhang","year":"2017","journal-title":"J. Syst. Softw."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"2062","DOI":"10.1109\/TIFS.2018.2809679","article-title":"Combining data owner-side and cloud-side access control for encrypted cloud storage","volume":"13","author":"Xue","year":"2018","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"123430","DOI":"10.1109\/ACCESS.2020.3004897","article-title":"HTAC: Fine-grained policy-hiding and traceable access control in mHealth","volume":"8","author":"Li","year":"2020","journal-title":"IEEE Access"},{"key":"ref_9","unstructured":"Cheung, L., and Newport, C. (October, January 2). Provably secure ciphertext policy ABE. Proceedings of the 14th ACM Conference on Computer and Communications Security, Alexandria, VA, USA."},{"key":"ref_10","unstructured":"Gupta, R., Kanungo, P., and Dagdee, N. (2019). International Conference on Advanced Computing Networking and Informatics 2019, Springer."},{"key":"ref_11","unstructured":"Sahai, A., and Waters, B. (2005, January 22\u201326). Fuzzy identity-based encryption. Proceedings of the Annual International Conference on the Theory and Applications of Cryptographic Techniques, Aarhus, Denmark."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Waters, B. (2011, January 6\u20139). Ciphertext-policy attribute-based encryption: An expressive, efficient, and provably secure realization. Proceedings of the Public Key Cryptography\u2013PKC 2011: 14th International Conference on Practice and Theory in Public Key Cryptography, Taormina, Italy.","DOI":"10.1007\/978-3-642-19379-8_4"},{"key":"ref_13","unstructured":"Chase, M. (2007, January 21\u201324). Multi-authority attribute based encryption. Proceedings of the Theory of Cryptography Conference, Amsterdam, The Netherlands."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Chase, M., and Chow, S.S. (2009, January 9\u201313). Improving privacy and security in multi-authority attribute-based encryption. Proceedings of the 16th ACM Conference on Computer and Communications Security, Chicago, IL, USA.","DOI":"10.1145\/1653662.1653678"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Liu, Z., Cao, Z., Huang, Q., Wong, D.S., and Yuen, T.H. (2011, January 12\u201314). Fully secure multi-authority ciphertext-policy attribute-based encryption without random oracles. Proceedings of the European Symposium on Research in Computer Security, Leuven, Belgium.","DOI":"10.1007\/978-3-642-23822-2_16"},{"key":"ref_16","unstructured":"Lewko, A., and Waters, B. (2011, January 15\u201319). Decentralizing attribute-based encryption. Proceedings of the Advances in Cryptology\u2013EUROCRYPT 2011: 30th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Tallinn, Estonia."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Li, M., Yu, S., Ren, K., and Lou, W. (2010, January 7\u20139). Securing personal health records in cloud computing: Patient-centric and fine-grained data access control in multi-owner settings. Proceedings of the International Conference on Security and Privacy in Communication Systems, Singapore.","DOI":"10.1007\/978-3-642-16161-2_6"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Ibraimi, L., Asim, M., and Petkovi\u0107, M. (2009, January 24\u201326). Secure management of personal health records by applying attribute-based encryption. Proceedings of the 6th International Workshop on Wearable, Micro, and Nano Technologies for Personalized Health, Oslo, Norway.","DOI":"10.1109\/PHEALTH.2009.5754828"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"384","DOI":"10.1109\/TPDS.2013.38","article-title":"Decentralized access control with anonymous authentication of data stored in clouds","volume":"25","author":"Ruj","year":"2013","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1790","DOI":"10.1109\/TIFS.2013.2279531","article-title":"DAC-MACS: Effective data access control for multiauthority cloud storage systems","volume":"8","author":"Yang","year":"2013","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Gardiyawasam Pussewalage, H.S., and Oleshchuk, V.A. (2017, January 21\u201323). A distributed multi-authority attribute based encryption scheme for secure sharing of personal health records. Proceedings of the 22nd ACM on Symposium on Access Control Models and Technologies, Indianapolis, IN, USA.","DOI":"10.1145\/3078861.3078880"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Ibraimi, L., Tang, Q., Hartel, P., and Jonker, W. (2009, January 13\u201315). Efficient and provable secure ciphertext-policy attribute-based encryption schemes. Proceedings of the International Conference on Information Security Practice and Experience, Xi\u2019an, China.","DOI":"10.1007\/978-3-642-00843-6_1"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"45","DOI":"10.1016\/j.cose.2016.02.002","article-title":"Secure, efficient and revocable multi-authority access control system in cloud storage","volume":"59","author":"Li","year":"2016","journal-title":"Comput. Secur."},{"key":"ref_24","first-page":"1647","article-title":"Constant Ciphertext Size Multi-Authority Attribute-based Scheme without Key Escrow","volume":"21","author":"Hu","year":"2020","journal-title":"J. Internet Technol."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"389","DOI":"10.1007\/s12243-018-00702-6","article-title":"Fine-grained multi-authority access control in IoT-enabled mHealth","volume":"74","author":"Li","year":"2019","journal-title":"Ann. Telecommun."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Ma, C., Ge, A., and Zhang, J. (2018, January 28\u201330). Fully secure decentralized ciphertext-policy attribute-based encryption in standard model. Proceedings of the International Conference on Information Security and Cryptology, Seoul, Republic of Korea.","DOI":"10.1007\/978-3-030-14234-6_23"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Nishide, T., Yoneyama, K., and Ohta, K. (2008, January 3\u20136). Attribute-based encryption with partially hidden encryptor-specified access structures. Proceedings of the International Conference on Applied Cryptography and Network Security, New York, NY, USA.","DOI":"10.1007\/978-3-540-68914-0_7"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Lai, J., Deng, R.H., and Li, Y. (2012, January 2\u20134). Expressive CP-ABE with partially hidden access structures. Proceedings of the 7th ACM Symposium on Information, Computer and Communications Security, Seoul, Republic of Korea.","DOI":"10.1145\/2414456.2414465"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Li, J., Huang, Q., Chen, X., Chow, S.S., Wong, D.S., and Xie, D. (2011, January 22\u201324). Multi-authority ciphertext-policy attribute-based encryption with accountability. Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, Hong Kong, China.","DOI":"10.1145\/1966913.1966964"},{"key":"ref_30","first-page":"665","article-title":"Improving privacy and security in decentralized ciphertext-policy attribute-based encryption","volume":"10","author":"Han","year":"2014","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_31","unstructured":"Pedersen, T.P. (1992, January 16\u201320). Non-interactive and information-theoretic secure verifiable secret sharing. Proceedings of the Annual International Cryptology Conference, Santa Barbara, CA, USA."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Chen, X., Li, J., Wong, D.S., and Li, H. (2013, January 8\u201310). Anonymous attribute-based encryption supporting efficient decryption test. Proceedings of the 8th ACM SIGSAC Symposium on Information, Computer and Communications Security, Hangzhou, China.","DOI":"10.1145\/2484313.2484381"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Chen, J., and Ma, H. (July, January 27). Privacy-preserving decentralized access control for cloud storage systems. Proceedings of the 2014 IEEE 7th International Conference on Cloud Computing, Anchorage, AK, USA.","DOI":"10.1109\/CLOUD.2014.74"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"340","DOI":"10.1109\/TDSC.2006.54","article-title":"OACerts: Oblivious attribute certificates","volume":"3","author":"Li","year":"2006","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"243","DOI":"10.1007\/s00500-016-2330-8","article-title":"Multi-authority attribute-based encryption access control scheme with policy hidden for cloud storage","volume":"22","author":"Zhong","year":"2018","journal-title":"Soft Comput."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"563","DOI":"10.1109\/JIOT.2016.2571718","article-title":"An efficient and fine-grained big data access control scheme with privacy-preserving policy","volume":"4","author":"Yang","year":"2016","journal-title":"IEEE Internet Things J."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"53698","DOI":"10.1109\/ACCESS.2018.2871170","article-title":"A lightweight policy preserving EHR sharing scheme in the cloud","volume":"6","author":"Ying","year":"2018","journal-title":"IEEE Access"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"2130","DOI":"10.1109\/JIOT.2018.2825289","article-title":"Security and privacy in smart health: Efficient policy-hiding attribute-based access control","volume":"5","author":"Zhang","year":"2018","journal-title":"IEEE Internet Things J."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"831","DOI":"10.2298\/CSIS180830029Y","article-title":"Privacy-preserving multi-authority attribute-based encryption with dynamic policy updating in PHR","volume":"16","author":"Yan","year":"2019","journal-title":"Comput. Sci. Inf. Syst."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"141","DOI":"10.1016\/j.comnet.2018.01.036","article-title":"Phoabe: Securely outsourcing multi-authority attribute based encryption with policy hidden for cloud assisted iot","volume":"133","author":"Belguith","year":"2018","journal-title":"Comput. Netw."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"33202","DOI":"10.1109\/ACCESS.2019.2902040","article-title":"Hidden ciphertext policy attribute-based encryption with fast decryption for personal health record system","volume":"7","author":"Zhang","year":"2019","journal-title":"IEEE Access"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Chinnasamy, P., Deepalakshmi, P., Dutta, A.K., You, J., and Joshi, G.P. (2021). Ciphertext-Policy Attribute-Based Encryption for Cloud Storage: Toward Data Privacy and Authentication in AI-Enabled IoT System. Mathematics, 10.","DOI":"10.3390\/math10010068"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Sing, R., Bhoi, S.K., Panigrahi, N., Sahoo, K.S., Jhanjhi, N., and AlZain, M.A. (2022). A Whale Optimization Algorithm Based Resource Allocation Scheme for Cloud-Fog Based IoT Applications. Electronics, 11.","DOI":"10.3390\/electronics11193207"},{"key":"ref_44","first-page":"2647","article-title":"A resource management algorithm for virtual machine migration in vehicular cloud computing","volume":"67","author":"Pande","year":"2021","journal-title":"Comput. Mater. Contin."},{"key":"ref_45","first-page":"87","article-title":"Privacy Preserving Attribute-Based Encryption with Conjunctive Keyword Search for E-health Records in Cloud","volume":"13","author":"Najafi","year":"2021","journal-title":"ISC Int. J. Inf. Secur."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"e29108","DOI":"10.2196\/29108","article-title":"Privacy Preservation in Patient Information Exchange Systems Based on Blockchain: System Design Study","volume":"24","author":"Lee","year":"2022","journal-title":"J. Med. Internet Res."},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Crampton, J., and Pinto, A. (2014, January 19\u201322). Attribute-based encryption for access control using elementary operations. Proceedings of the 2014 IEEE 27th Computer Security Foundations Symposium, Vienna, Austria.","DOI":"10.1109\/CSF.2014.17"},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1155\/2020\/8861114","article-title":"Offline\/online outsourced attribute-based encryption with partial policy hidden for the internet of things","volume":"2020","author":"Yan","year":"2020","journal-title":"J. Sens."},{"key":"ref_49","unstructured":"Boneh, D., Goh, E.J., and Nissim, K. (2005). Theory of Cryptography Conference, Cambridge, MA, USA, 10\u201312 February 2005, Springer."},{"key":"ref_50","unstructured":"Lewko, A., Okamoto, T., Sahai, A., Takashima, K., and Waters, B. (June, January 30). Fully secure functional encryption: Attribute-based encryption and (hierarchical) inner product encryption. Proceedings of the Annual International Conference on the Theory and Applications of Cryptographic Techniques, Monaco and Nice, France."},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"De Caro, A., and Iovino, V. (July, January 28). jPBC: Java pairing based cryptography. Proceedings of the 2011 IEEE Symposium on Computers and Communications (ISCC), Kerkyra, Greece.","DOI":"10.1109\/ISCC.2011.5983948"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/5\/2617\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T18:43:49Z","timestamp":1760121829000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/5\/2617"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,2,27]]},"references-count":51,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2023,3]]}},"alternative-id":["s23052617"],"URL":"https:\/\/doi.org\/10.3390\/s23052617","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,2,27]]}}}