Enabling Efficient User Revocation in Identity-Based Cloud Storage Auditing for Shared Big Data

Enabling Efficient User Revocation in Identity-Based Cloud Storage Auditing for Shared Big Data
复制标题

DOI:
10.1109/tdsc.2018.2829880
复制
发表时间:
2020-05
影响因子:
7.3
通讯作者:
Yue Zhang;Jia Yu;Rong Hao;Cong Wang-;K. Ren
Yue Zhang;Jia Yu;Rong Hao;Cong Wang-;K. Ren
中科院分区:
计算机科学2区
文献类型:
--
作者:
Yue Zhang;Jia Yu;Rong Hao;Cong Wang-;K. Ren

文献摘要

被引文献

相似文献

云存储共享数据审计方案是指检查一组用户共享的云数据的完整性。此类方案通常支持用户撤销,因为用户可能会因各种原因而受到组成员身份变更的影响。以前,此类方案中用户撤销的计算开销与撤销用户拥有的文件块总数呈线性关系。然而,由于共享云数据量巨大,开销可能会成为沉重的负担。因此,如何减少用户撤销带来的计算开销成为实现实用云数据审计的关键研究挑战。在本文中,我们提出了一种新颖的存储审计方案,该方案可以实现高效的用户撤销,而与被撤销用户在云中拥有的文件块总数无关。这是通过探索一种新颖的密钥生成策略和新的私钥更新技术来实现的。使用这种策略和技术,我们只需更新非撤销组用户的私钥而不是撤销用户的身份验证器即可实现用户撤销。在认证器不更新的情况下,仍然可以正确地对被撤销的用户数据进行完整性审计。同时,所提出的方案基于基于身份的密码学,消除了传统公钥基础设施(PKI)系统中复杂的证书管理。通过分析和实验结果验证了所提出方案的安全性和效率。
Cloud storage auditing schemes for shared data refer to checking the integrity of cloud data shared by a group of users. User revocation is commonly supported in such schemes, as users may be subject to group membership changes for various reasons. Previously, the computational overhead for user revocation in such schemes is linear with the total number of file blocks possessed by a revoked user. The overhead, however, may become a heavy burden because of the sheer amount of the shared cloud data. Thus, how to reduce the computational overhead caused by user revocations becomes a key research challenge for achieving practical cloud data auditing. In this paper, we propose a novel storage auditing scheme that achieves highly-efficient user revocation independent of the total number of file blocks possessed by the revoked user in the cloud. This is achieved by exploring a novel strategy for key generation and a new private key update technique. Using this strategy and the technique, we realize user revocation by just updating the non-revoked group users’ private keys rather than authenticators of the revoked user. The integrity auditing of the revoked user's data can still be correctly performed when the authenticators are not updated. Meanwhile, the proposed scheme is based on identity-base cryptography, which eliminates the complicated certificate management in traditional Public Key Infrastructure (PKI) systems. The security and efficiency of the proposed scheme are validated via both analysis and experimental results.