The document presents a novel approach for privacy-preserving delegated access control in public clouds through a two-layer encryption (TLE) method. This approach allows for coarse-grained encryption by data owners and fine-grained encryption by the cloud, minimizing user communication and computation costs while ensuring data confidentiality and privacy. The proposed system addresses existing challenges in attribute-based access control (ABAC) over encrypted data and optimally decomposes access control policies to enhance security and efficiency.