SecureVault: Architecting a Privacy-First Cryptographic Layer for Multi-Cloud Data Governance
DOI:
https://doi.org/10.70917/ijcisim-2026-3488Keywords:
Cryptographic Data Privacy, Attribute-Based Encryption, Proxy Re-Encryption, Distributed Key Management, Multi-Cloud Access ControlAbstract
This paper presents a Privacy-Preserving Cryptographic Framework (PPCF) for fine-grained access control in heterogeneous multi-cloud storage environments. PPCF integrates three cryptographic primitives — Ciphertext-Policy Attribute-Based Encryption (CP-ABE), identity-based Proxy Re-Encryption (PRE), and threshold-based Distributed Key Generation (DKG) via Pedersen verifiable secret sharing — to eliminate centralised key escrow vulnerabilities. Access policies are embedded directly into ciphertexts as monotone Boolean formulas, enabling data-owner-defined control independent of online authority infrastructure. A hybrid AES-GCM-256/CP-ABE design confines ABE overhead to symmetric key material, while Reed-Solomon erasure coding ensures fault tolerance and data fragmentation across providers. Formal security reductions establish IND-CPA security under the DBDH assumption, with collusion and key recovery resistance. Empirical evaluation demonstrates a 37% reduction in computational overhead, key generation throughput of 682–847 keys/second, and sub-linear access latency scaling from 187 ms to 427 ms, confirming enterprise-grade deployability.