Efficient Authenticated Fine-Grained Access Engine for Encrypted Data in Mobile Edge Cloud
Abstract
1. Introduction
- This work constructs a novel policy-oriented functional signcryption scheme ePoFSC for secure edge-cloud data sharing. Unlike traditional CP-ABE designs that append independent commitments or signatures after encryption, ePoFSC leverages signcryption to simultaneously enforce policy-based data encryption, legitimate publisher binding, and standardized requester-side verification. This integrated design effectively addresses the inherent deficiencies of commitment-based schemes in publisher authentication and anti-forgery capability against commitment regeneration and public-key-only forgery attacks.
- This paper introduces a pre-online trapdoor auditing and caching mechanism. Edge nodes first validate the legitimacy of requester trapdoors generated from authorized credentials and cache verified trapdoors for repeated access. This pre-processing eliminates attribute-dependent transformation materials in online requests, enabling constant-time complexity for , , and request header construction independent of . Experimental results show that, with , ePoFSC reduces requester package size by 83.19%, 88.09%, 74.41%, and 74.06% and cuts request-generation RAM consumption by 84.97%, 89.65%, 75.24%, and 75.73%, compared with CfpComOD-WatersCPABE, CfpComOD-RWCPABE, AOD-MACPABE, and FTV-AOD-DR-CP-ABE, respectively.
- ePoFSC optimizes outsourced decryption by internalizing pairing exponent operations, achieving constant computational complexity for all expensive pairing and exponentiation operations in the phase. Only lightweight policy-dependent group multiplications are retained, which fundamentally differentiates ePoFSC from baseline OD-CP-ABE schemes that require policy-scalable heavy cryptographic operations on edge proxies. Evaluations on 30 ciphertext retrieval tasks show that ePoFSC reduces end-to-end retrieval latency over several state-of-the-art methods, achieving comprehensive performance superiority in both the encryption and data recovery phases.
- A novel number-th encoding method is adopted to support repeated reuse of policy nodes, which removes the single-use constraint of traditional access policy designs while preserving unique hash preimages for each control point. Combined with disk-persistent secondary encryption and a dynamic revocation list, the proposed scheme prevents unauthorized permission bypassing and illegal usage of leaked, expired, or revoked authorization credentials.
- We formally prove the security of ePoFSC under sIND-uCI-RCCA, Pu-SUF-aCMA, and Id-SUF-aCMA security models, which formally validate the scheme’s data confidentiality, publisher-side unforgeability, and requester traceability. Extensive experiments on the BLS12-381 curve and practical evaluations on a medical-image sharing dataset containing 36,961 dermoscopic images further verify that ePoFSC achieves lightweight request processing and outsourced decryption, with superior performance in request size, memory overhead, and end-to-end latency compared with state-of-the-art schemes.
2. Related Works
3. Preliminaries
3.1. Bilinear Pairing
- (Symmetric): .
- (Asymmetric): , and .
3.2. Monotone Boolean Formula for Access Control
4. Scheme Definition and Construction
4.1. Participant and Threat Model
- Trusted Authority (TA). The TA serves as the root trusted entity of the entire system. It is responsible for initializing global cryptographic parameters, preserving the system master secret, distributing fine-grained permission decryption keys for data requesters (DRs), and maintaining and updating the key revocation list. In this work, the TA is assumed to be fully trustworthy and immune to adversarial corruption. Its core security obligations include strictly preserving the confidentiality of the master secret key , binding each issued user key to a legitimate attribute permission set, and reliably publishing real-time revocation information to support permission management.
- Data Publisher (DP). The DP acts as the legitimate data owner and data source for outsourced sharing. It generates personalized publisher key pairs, formulates dedicated access policies for individual data objects, executes policy-aware functional signcryption operations, and uploads authenticable encrypted ciphertexts to the cloud-enabled data space. The DP is trusted in terms of the authenticity and correctness of its own published data. Nevertheless, the public identity of the DP must be rigorously verified by DRs during local unsigncryption. The primary security threats targeting the DP include ciphertext forgery and verification component tampering. The proposed scheme is required to guarantee rigorous data source authenticity and unforgeability to defend against malicious source substitution attacks.
- Cloud-enabled Data Space (CeDS). The CeDS provides persistent and structured encrypted data storage and indexing services for cloud-edge sharing scenarios. It undertakes core tasks including unique ciphertext identifier allocation, secure storage of main ciphertexts and protected control ciphertexts, maintenance of global ciphertext index tables, synchronous updating of encrypted metadata to edge nodes, and response to valid data retrieval requests from edge handler nodes (EHNs). The CeDS follows the widely adopted honest-but-curious threat model. It strictly complies with predefined system workflows for data storage and metadata synchronization but may attempt to infer sensitive information, including plaintext content, embedded access policies, requester identities, and permission privileges, from stored ciphertexts and historical access records. Therefore, the designed scheme must prevent the CeDS from acquiring any recoverable plaintext information or valid decryption credentials.
- Edge Handler Nodes (EHNs). EHNs are regional edge service nodes deployed in proximity to end DRs, undertaking major request processing and outsourced decryption tasks. Their core functionalities cover encrypted control ciphertext caching, verified trapdoor storage, request legitimacy and freshness verification, revocation status checking, local control ciphertext activation, outsourced partial decryption execution, and return of partial decryption headers and encrypted payloads to authorized DRs. EHNs are modeled as semi-trusted and honest-but-curious entities. Although they correctly execute prescribed cryptographic algorithms, they may attempt to extract sensitive information from cached trapdoors, request proofs, access policies, and intermediate decryption results. In addition, EHNs are directly exposed to various network threats, including forged access requests, replay attacks, request flooding, and malformed trapdoor injection attacks.
- Data Requester (DR). DRs are resource-constrained mobile or edge end users who obtain fine-grained attribute decryption keys from the TA based on their legitimate access permissions. A valid DR generates standard access request proofs, completes auditable outsourced trapdoor registration, submits data access requests to nearby EHNs, and performs local final unsigncryption and integrity verification. Unlike the fully trusted TA, DRs are untrusted and classified into multiple states, including honest, expired, revoked, compromised, and unauthorized users. Malicious DRs can launch multiple adversarial behaviors, such as forging request proofs, replaying historical valid requests, colluding with semi-trusted edge/cloud nodes, leaking private transformation keys, and injecting malformed trapdoors to exhaust edge computing resources. Accordingly, the ePoFSC scheme integrates requester identity authentication, timestamp-based request freshness validation, rigorous trapdoor auditing, and dynamic key revocation mechanisms to address the above threats.
4.2. Syntax Definition
- : Global parameter initialization algorithm executed by the TA. Taking the security parameter as input, this algorithm outputs the global public parameter and the system master secret key .
- : Publisher key generation algorithm executed by the DP. This algorithm takes the global public parameter as input and outputs the key pair for the data publisher.
- : Fine-grained user key generation algorithm executed by the TA. Given a requester’s permission attribute set and the master secret key , this algorithm outputs the private permission key for the authorized data requester.
- : Policy-oriented functional signcryption algorithm executed by the DP. Taking the plaintext data m, global public parameter , publisher secret key , and access policy as inputs, this algorithm generates and outputs the signcrypted ciphertext .
- : Persistent encryption algorithm executed by the storage node x. This algorithm encrypts the control ciphertext for persistent disk storage and outputs the encrypted control ciphertext and the corresponding tag.
- : Ciphertext activation algorithm executed by the storage node x. This algorithm decrypts and recovers the original control ciphertext from the persistently encrypted version for authorized edge-side processing.
- : Request proof generation algorithm executed by the DR. Given the key components , current timestamp , and request information , this algorithm outputs a verifiable request proof and the temporary request key .
- : Request verification algorithm executed by EHNs. This algorithm validates the request proof correctness, timestamp freshness within the valid time window , and user revocation status according to the revocation list , and outputs a binary judgment bit 0 (reject) or 1 (accept).
- : Transformation key generation algorithm executed by the DR. This algorithm derives the outsourced transformation key from the user private key for subsequent edge trapdoor registration.
- : Trapdoor auditing algorithm executed by EHNs. The edge node verifies the validity of the submitted transformation key and outputs the cached valid trapdoor or rejects the invalid key by outputting ⊥.
- : Authenticated outsourced partial decryption algorithm executed by EHNs. With the cached valid trapdoor, verified request proof, timestamp, and ciphertext components, the edge node performs secure partial decryption and outputs the partial decrypted ciphertext or returns ⊥ for invalid requests.
- : Final unsigncryption and verification algorithm executed by the DR. The requester recovers the plaintext data and validates the publisher authenticity and data integrity, outputting the plaintext m or ⊥ if the verification fails.
- : Dynamic key revocation algorithm executed by the TA or authorized EHNs. This algorithm updates the global revocation list to invalidate expired, leaked, or compromised user key components.
4.3. Security Definition
4.3.1. Data Confidentiality
- An entity can successfully decrypt a ciphertext if and only if it holds a valid decryption key whose permission attribute set satisfies the corresponding access policy .
- The outsourced partial-decryption trapdoor and request proof leak no decryption privilege information. Specifically, any external party cannot decrypt the ciphertext by acquiring and , even if the party possesses attributes that satisfy the target access policy.
| Algorithm 1: |
| Input: Output: sIND-uCI-RCCA: . |
4.3.2. Data Authentication
| Algorithm 2: |
| Input: Output: Pu-SUF-aCMA: . |
4.3.3. Requester Traceability
| Algorithm 3: |
| Input: Output: Define two events Id-SUF-aCMA: . |
4.4. Concrete Construction
- . (1) . (2) Select a collision-resistant hash function with output length , and then construct a hash-to-integer function as well as a hash-to-curve function by using the Hash-to-Field Standard (RFC 9380 (https://datatracker.ietf.org/doc/rfc9380/) accessed on 30 June 2026). (3) Choose a pseudorandom permutation (PRP)-based symmetric encryption algorithm with key space , where encryption is defined as and decryption as (The PRP means that no PPT algorithm can break the encryption algorithm from the plaintext-ciphertext pair). (4) Define the maximum number of repeated functional points in each functional policy. (5) Sample random elements and define ; .
- . Sample the secret key as the private key, and derive the public key .
- . This algorithm is presented in Algorithm 4.
- . The algorithm is depicted in Algorithm 5. The policy-point number-th encoding sub-algorithm of Algorithm 5 is illustrated in Figure 6.
- . Choose the random encryption tag . Drive the key . Return .
- . Drive the key . Return .. This algorithm is expressed in Algorithm 6.. This algorithm is expressed in Algorithm 7.
- . Outsourced transformation key construction algorithm by DR expressed in Algorithm 8.
- . First conduct the to verify the freshness and validity of . Then execute the discriminant to audit each permission point in .If the logined trapdoor passes the auditing process, return the cached trapdoor , otherwise, return ⊥.
- . Outsourced decryption algorithm by request handler node. This algorithm is expressed in Algorithm 9.The correctness of the is expressed as:
- . Final unsigncryption algorithm by DR. Input the partial decrypted ciphertext , the retrieval key , the encrypted-data with the data proof and public key .Retrieval the data m: , . Then verify the decrypted data : ①; ② . If the verification passes, return ; otherwise, return ⊥.
- . The corrupted DR revocation algorithm is conducted by the TA. It takes as input the previous revocation list and the revoked DR’s feature key , and outputs the updated revocation list .
| Algorithm 4: |
![]() |
| Algorithm 5: Policy-Controllable Signcryption |
![]() |
| Algorithm 6: |
| Input: Output: Randomly sample ; Extract timestamp ; Extract Compute ; Extract Return |
| Algorithm 7: |
![]() |
| Algorithm 8: |
![]() |
| Algorithm 9: |
![]() |
4.5. System Workflow
5. Security Theorems and Reductions
| Algorithm 10: Points Number-th Encoding Algorithm |
![]() |
6. Comparison and Evaluation
6.1. Theoretical Analysis
6.2. Simulation Evaluation
6.3. Real-World Scenario Evaluation
7. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
References
- Waters, B. Ciphertext-Policy Attribute-Based Encryption: An Expressive, Efficient, and Provably Secure Realization. In Proceedings of the Public Key Cryptography–PKC 2011, Taormina, Italy, 6–9 March 2011; Catalano, D., Fazio, N., Gennaro, R., Nicolosi, A., Eds.; Springer: Berlin/Heidelberg, Germany, 2011; pp. 53–70. [Google Scholar]
- Chen, J.; Gay, R.; Wee, H. Improved Dual System ABE in Prime-Order Groups via Predicate Encodings. In Proceedings of the Advances in Cryptology—EUROCRYPT 2015, Sofia, Bulgaria, 26–30 April 2015; Oswald, E., Fischlin, M., Eds.; Springer: Berlin/Heidelberg, Germany, 2015; pp. 595–624. [Google Scholar]
- Kim, S.; Lewi, K.; Mandal, A.; Montgomery, H.; Roy, A.; Wu, D.J. Function-Hiding Inner Product Encryption Is Practical. In Proceedings of the Security and Cryptography for Networks, Amalfi, Italy, 5–7 September 2018; Catalano, D., De Prisco, R., Eds.; Springer: Cham, Switzerland, 2018; pp. 544–562. [Google Scholar]
- Green, M.; Hohenberger, S.; Waters, B. Outsourcing the decryption of ABE ciphertexts. In Proceedings of the 20th USENIX Conference on Security, San Francisco, CA, USA, 8–12 August 2011; SEC’11. p. 34. [Google Scholar]
- Qin, B.; Deng, R.H.; Liu, S.; Ma, S. Attribute-based encryption with efficient verifiable outsourced decryption. IEEE Trans. Inf. Forensics Secur. 2015, 10, 1384–1393. [Google Scholar] [CrossRef] [Scilit]
- Ma, H.; Zhou, D.; Li, P.; Wang, X. EVOAC-HP: An Efficient and Verifiable Outsourced Access Control Scheme with Hidden Policy. Sensors 2023, 23, 4384. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Lai, J.; Deng, R.H.; Guan, C.; Weng, J. Attribute-based encryption with verifiable outsourced decryption. IEEE Trans. Inf. Forensics Secur. 2013, 8, 1343–1354. [Google Scholar] [CrossRef] [Scilit]
- Bethencourt, J.; Sahai, A.; Waters, B. Ciphertext-policy attribute-based encryption. In Proceedings of the 2007 IEEE Symposium on Security and Privacy (SP ’07), Berkeley, CA, USA, 20–23 May 2007; pp. 321–334. [Google Scholar] [CrossRef] [Scilit]
- Rouselakis, Y.; Waters, B. Practical constructions and new proof methods for large universe attribute-based encryption. In Proceedings of the 2013 ACM SIGSAC Conference on Computer & Communications Security, Berlin, Germany, 4–8 November 2013; CCS ’13. pp. 463–474. [Google Scholar] [CrossRef] [Scilit]
- Agrawal, S.; Chase, M. FAME: Fast Attribute-based Message Encryption. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Dallas, TX, USA, 30 October–3 November 2017; CCS ’17. pp. 665–682. [Google Scholar] [CrossRef] [Scilit]
- Chen, D.; Zhang, L.; Liao, Z.; Dai, H.N.; Zhang, N.; Shen, X.; Pang, M. Flexible and Fine-Grained Access Control for EHR in Blockchain-Assisted E-Healthcare Systems. IEEE Internet Things J. 2024, 11, 10992–11007. [Google Scholar] [CrossRef] [Scilit]
- Liu, C.; Hou, C.; Jiang, T.; Ning, J.; Qiao, H.; Wu, Y. FACOS: Enabling Privacy Protection Through Fine-Grained Access Control with On-Chain and Off-Chain System. IEEE Trans. Inf. Forensics Secur. 2024, 19, 7060–7074. [Google Scholar] [CrossRef] [Scilit]
- Lin, S.; Zhang, R.; Ma, H.; Wang, M. Revisiting Attribute-Based Encryption with Verifiable Outsourced Decryption. IEEE Trans. Inf. Forensics Secur. 2015, 10, 2119–2130. [Google Scholar] [CrossRef] [Scilit]
- Hahn, C.; Kwon, H.; Hur, J. Trustworthy delegation toward securing mobile healthcare cyber-physical systems. IEEE Internet Things J. 2018, 6, 6301–6309. [Google Scholar] [CrossRef] [Scilit]
- Hahn, C.; Kim, J. Verifiable Outsourced Decryption of Encrypted Data From Heterogeneous Trust Networks. IEEE Internet Things J. 2022, 9, 22559–22570. [Google Scholar] [CrossRef] [Scilit]
- Zhang, Z.; Huang, W.; Yang, L.; Liao, Y.; Zhou, S. A Stronger Secure Ciphertext Fingerprint-Based Commitment Scheme for Robuster Verifiable OD-CP-ABE in IMCC. IEEE Internet Things J. 2023, 10, 16531–16547. [Google Scholar] [CrossRef] [Scilit]
- Song, K.; Zhu, Z.; Yang, H.; Ni, T.; Xu, W. MobileKey: A Fast and Robust Key Generation System for Mobile Devices. In Proceedings of the Adjunct Proceedings of the 2022 ACM International Joint Conference on Pervasive and Ubiquitous Computing and the 2022 ACM International Symposium on Wearable Computers, Cambridge, UK, 11–15 September 2022; UbiComp/ISWC ’22 Adjunct. pp. 427–431. [Google Scholar] [CrossRef] [Scilit]
- Guo, D.; Cao, K.; Xiong, J.; Ma, D.; Zhao, H. A Lightweight Key Generation Scheme for the Internet of Things. IEEE Internet Things J. 2021, 8, 12137–12149. [Google Scholar] [CrossRef] [Scilit]
- Yu, L.; Nan, X.; Niu, S. A Privacy-Preserving Friend Matching Scheme Based on Attribute Encryption in Mobile Social Networks. Electronics 2024, 13, 2175. [Google Scholar] [CrossRef] [Scilit]
- Li, Q.; Wang, L.; Zhang, M. Efficient and Secure Medical Data Sharing: An Improved CP-ABE Scheme with Outsourced Decryption. Electronics 2026, 15, 1907. [Google Scholar] [CrossRef] [Scilit]
- Feng, Z.; Yang, W.; Hu, Y.; Yin, Y.; Ma, T.; Tian, X.; Deng, X. Blockchain-Enabled Lattice-Based Attribute-Based Searchable Encryption with Instant Revocation. Electronics 2026, 15, 2471. [Google Scholar] [CrossRef] [Scilit]
- Pióro, Ł.; Kanciak, K.; Zieliński, Z. Comparative Analysis of Attribute-Based Encryption Schemes for Special Internet of Things Applications. Electronics 2026, 15, 697. [Google Scholar] [CrossRef] [Scilit]
- Zhang, Z.; Zhou, S. A decentralized strongly secure attribute-based encryption and authentication scheme for distributed Internet of Mobile Things. Comput. Netw. 2021, 201, 108553. [Google Scholar] [CrossRef] [Scilit]
- Zhang, Z.; Huang, Y.; Huang, W.; Liao, Y.; Zhou, S. A Fully Auditable Data Propagation Scheme with Dynamic Vehicle Management for EC-ITS. IEEE Trans. Intell. Transp. Syst. 2024, 25, 7861–7877. [Google Scholar] [CrossRef] [Scilit]
- Galbraith, S.D.; Paterson, K.G.; Smart, N.P. Pairings for cryptographers. Discret. Appl. Math. 2008, 156, 3113–3121. [Google Scholar] [CrossRef] [Scilit]
- Uzunkol, O.; Kiraz, M.S. Still wrong use of pairings in cryptography. Appl. Math. Comput. 2018, 333, 467–479. [Google Scholar] [CrossRef] [Scilit]
- Beimel, A. Secure Schemes for Secret Sharing and Key Distribution. Ph.D. Thesis, Technion-Israel Institute of Technology, Haifa, Israel, 1996. [Google Scholar]
- Lewko, A.; Waters, B. Decentralizing Attribute-Based Encryption. In Proceedings of the Advances in Cryptology—EUROCRYPT 2011, Tallinn, Estonia, 15–19 May 2011; Paterson, K.G., Ed.; Springer: Berlin/Heidelberg, Germany, 2011; pp. 568–588. [Google Scholar]
- Anzai, R.; Sakamoto, J.; Yoshida, N.; Matsumoto, T. BLS12-381 Pairing Implementation with RAM Footprint Smaller than 4 KB. In Proceedings of the 2022 37th International Technical Conference on Circuits/Systems, Computers and Communications (ITC-CSCC), Phuket, Thailand, 5–8 July 2022; pp. 317–320. [Google Scholar] [CrossRef] [Scilit]
- Faz-Hernandez, A.; Scott, S.; Sullivan, N.; Wahby, R.S.; Wood, C.A. RFC 9380: Hashing to Elliptic Curves. 2023. Available online: https://www.rfc-editor.org/info/rfc9380/ (accessed on 30 June 2026).
















| Scheme | Multi-Use | Request Verify | Trapdoor Cache | Data Verify | Publisher Tracing | Revoke | ||
|---|---|---|---|---|---|---|---|---|
| [13] | ✔ | ✔ | ✘ | ✘ | ✔ | ✘ | ✘ | |
| [23] | ✔ | ✔ | ✔ | ✘ | ✔ | ✘ | ✘ | |
| [16] (Water) | ✔ | ✔ | ✘ | ✘ | ✔ | ✔ | ✘ | |
| [16] (RW) | ✔ | ✔ | ✘ | ✘ | ✔ | ✔ | ✘ | |
| [10] | ✘ | ✘ | ✘ | ✘ | ✘ | ✘ | ✘ | |
| [24] | ✔ | ✔ | ✔ | ✘ | ✔ | ✔ | ✔ | |
| [19] | ✔ | ✔ | ✘ | ✘ | ✔ | ✘ | ✘ | |
| [20] | ✘ | ✔ | ✘ | ✘ | ✘ | ✘ | ✔ | |
| ePoFSC (This work) | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ |
| Notations | Definition |
|---|---|
| Cryptographic collision-resistant hash functions | |
| A pseudorandom permutation (PRP) based symmetric encryption. | |
| Cryptographic master key and corresponding public parameters | |
| Key pair of DP | |
| Discrete permission set of DR | |
| Fine-grained decryption key | |
| MSP-encoding access boolean formula | |
| Predicate-encoding signcryption ciphertext, where is the symmetric encrypted data payload, is the policy-embedded controllable ciphertext, is the data proof. | |
| Policy predicate-encoding ciphertext | |
| , | Logined and cached trapdoor of DR |
| , | request proof and message |
| The partial decrypted ciphertext payload header |
| Notations | Meaning |
|---|---|
| Element size of group in | |
| A pairing operation of | |
| A group multiplication/exponentiation operation of in | |
| A hash-to-curve operation of | |
| operation of the symmetric encryption | |
| , | Hash operations and |
| Max size of each function point | |
| Timestamp size | |
| The number of rows and columns of LSSS matrix | |
| The number of points in functional-points set | |
| Cardinality of the matching set I | |
| Output size of | |
| Size of permission point | |
| Size of identity | |
| Size of symmetrically encrypted data |
| Scheme | ||||||
|---|---|---|---|---|---|---|
| [23] | ||||||
| [16] (Waters) | - | |||||
| [16] (RW) | - | |||||
| [10] | - | - | - | |||
| [24] | ||||||
| ePoFSC |
| Environment | Setting |
|---|---|
| DR&DP | Xiaomi 13 smartphone powered by a Qualcomm Snapdragon 8 Gen 2 processor, equipped with 12 GB LPDDR5X RAM, and running the Android operating system. |
| EHN | Personal computer with an AMD Ryzen 7 8745H processor with Radeon 780M Graphics (3.80 GHz), 16 GB RAM, and Windows 11 25H2. |
| CeDS | AutoDL cloud server equipped with an Intel Xeon Platinum 8255C CPU and 40 GB RAM. |
| Scheme | 5 | 10 | 15 | 20 | 25 | 30 |
|---|---|---|---|---|---|---|
| CfpComOD-WatersCPABE [16] (ms) | 542.85 | 1049.38 | 1471.72 | 1946.18 | 2382.46 | 2993.67 |
| CfpComOD-RWCPABE [16] (ms) | 829.99 | 1449.46 | 2048.30 | 2786.64 | 3512.88 | 4143.51 |
| AOD-MACPABE [23] (ms) | 725.94 | 1170.12 | 1577.02 | 2001.18 | 2447.96 | 2744.27 |
| FTV-AOD-DR-CP-ABE [24] (ms) | 801.56 | 1389.43 | 1936.93 | 2467.57 | 2976.75 | 3558.17 |
| CP-FAME [10] (ms) | 231.66 | 496.57 | 756.52 | 996.69 | 1215.18 | 1456.24 |
| ePoFSC (ms) | 148.32 | 257.44 | 409.84 | 527.90 | 621.73 | 774.76 |
| Scheme | Tx. Delay (s) | Avg. Lat. (s) | Avg. Queue (s) | P95 Lat. (s) |
|---|---|---|---|---|
| CfpComOD-WatersCPABE [16] | 1668.98 | 5067.21 | 1991.98 | 7059.19 |
| CfpComOD-RWCPABE [16] | 1668.98 | 6515.33 | 3002.87 | 9518.21 |
| AOD-MACPABE [23] | 1670.87 | 4582.09 | 1797.28 | 6379.38 |
| FTV-AOD-DR-CP-ABE [24] | 1669.07 | 6620.59 | 2979.10 | 9599.69 |
| ePoFSC (This work) | 1669.36 | 3984.40 ↓ | 1377.29 ↓ | 5361.70 ↓ |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Zhang, Z.; Guo, J.; Shao, C.; Huang, W.; Zhou, S. Efficient Authenticated Fine-Grained Access Engine for Encrypted Data in Mobile Edge Cloud. Electronics 2026, 15, 2933. https://doi.org/10.3390/electronics15132933
Zhang Z, Guo J, Shao C, Huang W, Zhou S. Efficient Authenticated Fine-Grained Access Engine for Encrypted Data in Mobile Edge Cloud. Electronics. 2026; 15(13):2933. https://doi.org/10.3390/electronics15132933
Chicago/Turabian StyleZhang, Zhishuo, Jianding Guo, Caixing Shao, Wen Huang, and Shijie Zhou. 2026. "Efficient Authenticated Fine-Grained Access Engine for Encrypted Data in Mobile Edge Cloud" Electronics 15, no. 13: 2933. https://doi.org/10.3390/electronics15132933
APA StyleZhang, Z., Guo, J., Shao, C., Huang, W., & Zhou, S. (2026). Efficient Authenticated Fine-Grained Access Engine for Encrypted Data in Mobile Edge Cloud. Electronics, 15(13), 2933. https://doi.org/10.3390/electronics15132933







