Intrusion-resilient public cloud auditing scheme with authenticator update

Intrusion-resilient public cloud auditing scheme with authenticator update
复制标题

具有身份验证器更新的抗入侵公共云审计方案

DOI:
10.1016/j.ins.2019.09.080
复制
发表时间:
2020
影响因子:
8.1
通讯作者:
Zhong Hong
Zhong Hong
中科院分区:
计算机科学1区
文献类型:
--
作者:
Xu Yan;Sun Song;Cui Jie;Zhong Hong

文献摘要

相似文献

密钥暴露弹性云存储审计可以在密钥暴露前后创建安全的云存储。但是,恶意云服务器仍然可以篡改甚至丢弃在密钥暴露期间上传的客户端文件而不被检测到。为了解决这个问题,我们提出了一种抗入侵的公共云审计方案,该方案定期更新审计认证器,以防止恶意云使用暴露的密钥篡改这些文件。此外,我们的方案是安全的,除非客户和TPA(第三方审计师)在同一时间段内受到损害。这与Yu等人在TIFS 2017中提出的方案不同,如果客户端和TPA在不同时期受到损害,则该方案不安全。最后,该方案可以保护客户端的文件隐私,防止恶意TPA恢复文件。安全性分析和实验结果表明,该方案的安全性和性能是可以接受的。
Key-exposure resilient cloud storage auditing can create a secure cloud storage during before and after the key-exposure period. However, the malicious cloud server can still tamper with and even discard the client’s files which are uploaded during the key-exposure period without being detected. So as to cope with this problem, we propose an intrusion-resilient public cloud auditing scheme, in which auditing authenticators are updated periodically to prevent the malicious cloud from tampering with these files using the exposed key. In addition, our scheme is secure unless the client and TPA (Third Party Auditor) are compromised in the same time period. This is different from Yu et al.’s scheme proposed in TIFS 2017, which is not secure if the client and TPA are compromised in different periods. Finally, the scheme can protect the client’s file privacy, and prevent a curious TPA from recovering the file. The security analysis and the results of the experiment indicate that the security and performance of the scheme are acceptable.