The document presents a novel semi-anonymous privilege control scheme called AnonyControl for cloud data access, which enhances both data privacy and user identity privacy while addressing existing limitations in attribute-based encryption. AnonyControl decentralizes authority to limit identity leakage and manages access operations in a fine-grained manner, while AnonyControl-F achieves full anonymity by completely preventing identity leakage. The proposed schemes are claimed to be secure under the decisional bilinear Diffie–Hellman assumption and have been evaluated for feasibility.