The document proposes a shared authority based privacy-preserving authentication protocol (SAPA) for cloud storage to address privacy issues when users request to share access to each other's authorized data fields.
The SAPA allows for shared access authority through an anonymous access request matching mechanism that considers authentication, data anonymity, user privacy, and forward security. It also uses attribute based access control for users to only access their own data fields and proxy re-encryption for temporary data sharing among users.
The protocol is designed to enhance user privacy during access requests by not revealing a user's interests or access desires, whether or not they receive access permissions. It aims to simultaneously provide data access control, shared access authority, and privacy preservation