Skip to content
Open access

Privacy-preserving secure data sharing in edge-cloud collaborative environments

Aug 2026 · Journal of King Saud University: Computer and Information Sciences · Vol 38 · 0 citations · 36 references

TL;DR

A privacy-preserving, secure data-sharing framework tailored for edge-cloud collaborative architectures that minimizes the computational overhead on the terminal side while safeguarding user privacy, and effectively reduces the overhead associated with user joining and revocation within the same group.

Abstract

In cloud computing environments, data sharing serves as a foundational enabler of collaborative operations across heterogeneous terminals. However, such sharing introduces critical challenges–including privacy leakage, inadequate data security, inflexible access control policies, and substantial computational latency. To address these limitations, this paper proposes a privacy-preserving, secure data-sharing framework tailored for edge-cloud collaborative architectures. Relative to conventional approaches, the proposed framework delivers three principal advancements: (1) User Privacy Protection: We design a secure query-matching algorithm that protects plaintext query keywords during data access. The Cloud Server (CS) performs matching over encrypted trapdoors without directly learning the queried keywords. (2) Computational Efficiency Improvement: Edge Servers (ESs) perform outsourced ciphertext transformation using user-specific transformation keys. The terminal only performs a lightweight local operation to recover the resource. This approach minimizes the computational overhead on the terminal side while safeguarding user privacy, and effectively reduces the overhead associated with user joining and revocation within the same group. (3) Fine-Grained, Policy-Driven Access Control: A cryptographically enforced, attribute- and keyword-aware access control mechanism is implemented, supporting precise, context-sensitive authorization decisions via encrypted keyword search and semantic matching–thereby enhancing both the security posture and operational flexibility of data access control.

Read PDF

Similar papers

Review Open access Aug 2026

A Survey on Privacy-Preserving Techniques for Cloud Data Processing Using Homomorphic Encryption and Federated Learning

This paper presents a structured review of privacy-preserving data processing techniques for cloud environments built on HE and FL, individually and in hybrid combination, and identifies promising directions for future research.

Shivendra Shukla, C. S. Gautam, Divyansh Tiwari · 0 citations
Aug 2026

A flexible privacy-preserving framework for instant messaging in mobile social networks

A flexible privacy-preserving framework that combines the scalability of broadcast encryption with the fine-grained access control of Attribute-Based Encryption through a novel pseudo-layer encryption model, and achieves confidentiality, forward and backward secrecy, and collusion resistance.

Seyyed Mohammad Safi, Mahnaz Rafie, Sarina Sadat Mirmohammadi · 0 citations
Open access Aug 2026

Integrity Checking Mechanism for PrivacyPreserved Auditing of Cloud Shared-Data

A viable, privacy-friendly auditing framework of clouds which guarantees the end-toend encrypted verification without sacrificing the efficiency is presented.

Deepshikha Chaturvedi, Vidyullata Devmane, Shashikant S. Radke et al. · 0 citations
Open access Aug 2026

SC-DAC: a robust partially and fully access control mechanism for secure cloud data in outsourced environments

This study proposes a novel approach to secure cloud data access control called the Robust Mechanism for Secure Cloud Data Access Control (SC-DAC), which combines advanced cryptographic techniques such as Ciphertext-Policy Attribute-Based Encryption (CP-ABE) and Hybrid Public Key Encryption.

Haqi Khalid, S. Hashim, Mohammed Abdul Majeed · 1 citation
Open access Aug 2026

An efficient lattice-based identity-based proxy Re-encryption scheme with direct revocation for cloud storage

As cloud storage becomes increasingly commonplace alongside the expansion of data sharing practices, how to achieve secure data sharing and user revocation while ensuring data confidentiality has become a key issue. Proxy re-encryption enables ciphertext originally designated for one user to be transformed by a semi-trusted proxy for another user, while identity-based encryption offers a simplified approach to key administration. However, most existing frameworks employ bilinear pairings, which suffer from susceptibility to quantum threats, and generally lack efficient revocation mechanisms. To tackle these challenges, we present an identity-based directly revocable proxy re-encryption scheme (IBPRE-DR) based on the Learning With Errors (LWE) assumption. This scheme enables data owners to directly revoke user permissions without requiring a key generation center (KGC) to frequently update user keys, supporting immediate and dynamic access control. The mechanism uses a complete subtree algorithm to achieve efficient revocation. Additionally, a dual-key mechanism distinguishes re-encryption keys from decryption keys, effectively resisting collusion attacks and further enhancing data security. Furthermore, the private key length for each user remains fixed, supporting multi-bit encryption. We present a formal definition of IBPRE-DR’s security, along with a standard-model security proof. To the best of our knowledge, this is the first lattice-based identity-based proxy re-encryption scheme that integrates direct user revocation under the standard LWE assumption. Both experimental results and theoretical analysis confirm the scheme’s effectiveness and feasibility.

Juanjuan Li, Mingming Jiang, Yuyan Guo · 0 citations
Open access 2026

Cryptography-Enhanced Data Spaces: Secure Cross-Domain Data Sharing via IDS Connectors

: Data spaces enable controlled data sharing across organizations while preserving data sovereignty through policy-based governance mechanisms. Frameworks such as the International Data Spaces (IDS) provide standardized infrastructures for secure data exchange; however, they lack native mechanisms for performing computations on confidential data and for securely combining datasets across domains. In current implementations, datasets typically need to be decrypted before analysis, which limits the applicability of data spaces in privacy-sensitive environments and restricts the potential for cross-domain data fusion. To address this limitation, this paper presents an architecture implemented within the TRUSTEE platform that enables privacy-preserving computation on encrypted datasets hosted by IDS connectors. The proposed approach integrates homomorphic encryption (HE) workflows with standard data space connector infrastructures, allowing analytical operations to be performed directly on encrypted data while preserving existing governance and policy enforcement mechanisms. As a result, raw datasets remain protected within the provider environment throughout the computation lifecycle, and only the final computation results are shared with authorized participants. The proposed architecture is validated through a proof-of-concept demonstrating encrypted data fusion across multiple domains using TRUSTEE and IDS-based infrastructures. The evaluation confirms the feasibility, interoperability, and practical applicability of the approach for enabling secure secondary use of data and privacy-preserving cross-domain analytics in federated data space environments.

Saneea Malik, Gabriella Laatikainen, Ilkka Niskanen et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.