Attribute-Based Encryption in Cloud Computing Security
Summary
Attribute-Based Encryption (ABE) has emerged as a pivotal cryptographic paradigm for ensuring confidentiality and fine-grained access control in cloud environments. By associating user attributes with encryption keys and embedding access policies directly into ciphertexts, ABE allows data owners to specify which combinations of attributes—such as role, department or clearance level—are required for decryption. This model addresses the challenge of securely sharing sensitive information across distributed and multi-tenant cloud platforms without relying on trusted intermediaries. Recent advances have focused on improving scalability through multi-authority arrangements, enabling cross-domain interactions and decentralised key management. Practical implementations increasingly exploit computation outsourcing to edge or fog nodes, reducing the burden on resource-constrained devices. Nevertheless, key challenges remain: efficient attribute revocation, policy expressiveness versus performance overhead, and verifiable decryption to guard against malicious or faulty transformation by untrusted servers. Real-world use cases span healthcare records, IoT telemetry and enterprise data sharing, underlining the global significance of adaptable, policy-driven encryption schemes that reconcile rigorous security guarantees with the elastic demands of modern cloud infrastructures.
Research from Nature Portfolio
No recent Nature Portfolio content available.
Attribute-Based Encryption in Cloud Computing Security publication trend
The graph below shows the total number of articles in attribute-based encryption in cloud computing security across all publications each year (not limited to Nature Index journals).
Technical terms
Attribute-Based Encryption (ABE): A public-key encryption model in which access to encrypted data is governed by logical policies over user attributes rather than by specific identities.
Ciphertext-Policy ABE (CP-ABE): ABE variant where the data owner embeds an access policy into the ciphertext, and only users whose attributes satisfy that policy can decrypt.
Outsourced Decryption: A technique that delegates the computationally intensive parts of decryption to an untrusted server, returning a transformed ciphertext that the user then converts to plaintext using a lightweight key operation.
Fine-Grained Access Control: A security mechanism that enforces granular authorisation rules, enabling specific combinations of attributes to dictate data access rights.
References
- A Survey on Attribute-Based Encryption Schemes Suitable for the Internet of Things. IEEE Internet of Things Journal (2022).
- Secure Data Access Control With Ciphertext Update and Computation Outsourcing in Fog Computing for Internet of Things. IEEE Access (2017).
- Verifiable Outsourced Decryption of Attribute‐Based Encryption with Constant Ciphertext Length. Security and Communication Networks (2017).
About these summaries
This Nature Research Intelligence Topic summary is created with the cited references and a large language model. We take care to ground generated text with facts, and have systems in place to gain human feedback on the overall quality of the process in line with our AI principles. We strive to create accurate and useful summaries for people unfamiliar with the research topic and that supports this goal. These pages are a beta release and will be updated as we learn how best to help people gain value from a research topic summary.
Turn complex research questions into confident strategic decisions
When you're under pressure to set direction, justify investment, or understand your competitive position, you need more than raw data — you need trusted insights you can act on.
Benchmark your performance against global peers using robust, methodologically sound analysis.
Combine quantitative metrics with qualitative expert insight to uncover strengths, gaps and emerging opportunities.
Gain tailored, decision-ready recommendations aligned to your strategic priorities.
Talk to us to learn more about our data dashboards and bespoke strategy reports.
Grow research skills, confidence and careers with training built for every stage of the research lifecycle.
Developed with Nature Portfolio journal Editors and internationally renowned experts. Discover three ways to learn:
Self-paced, online courses in convenient bite-sized units, covering key skills across scientific writing, publishing, grant writing, data analysis, and more.
Expert trainer-led workshops with hands-on exercises and real-time feedback across core research skills, delivered via interactive group sessions.
Editor-led workshops combining core principles in writing and publishing, personalised 1:1 feedback from Nature Portfolio Editors and hands-on exercises.
Explore course catalogues and workshop agendas, enquire about the options or request institutional pricing.