Privacy preserving cloud data auditing with efficient key update

Privacy preserving cloud data auditing with efficient key update
复制标题

DOI:
10.1016/j.future.2016.09.003
复制
发表时间:
2018
期刊:
Future Gener. Comput. Syst.
影响因子:
--
通讯作者:
Yannan Li;Yong Yu;Bo Yang;Geyong Min;H. Wu
Yannan Li;Yong Yu;Bo Yang;Geyong Min;H. Wu
中科院分区:
其他
文献类型:
--
作者:
Yannan Li;Yong Yu;Bo Yang;Geyong Min;H. Wu

文献摘要

被引文献

相似文献

数据完整性对于基于云的存储服务非常重要,云用户不再实际拥有他们的外包文件。已经提出了许多数据审计机制来解决这个问题。然而,如何有效地更新云用户的秘密审计密钥以及与这些密钥相关联的认证者时,数字证书在PKI系统中过期是一个关键问题。本文提出了一种用于云数据安全审计的具有零知识隐私的密钥更新和认证者演化机制,该机制结合了零知识证明系统、代理重签名和同态线性认证器。我们用最先进的Shacham-Waters审计方案实例化我们的建议。当云用户需要更新密钥时,无需下载整个文件并重新生成所有的认证器,只需下载一个文件标签,使用新的私钥计算出重新签名的密钥,并将新的文件标签和一些验证信息上传到云服务器,用户在更新阶段承担的工作量最小。这种方法在保持所需安全性的同时,大大降低了通信和计算成本。我们形式化的安全模型的零知识数据隐私的审计方案在密钥更新的上下文中,并证明了所提出的建设的合理性和零知识隐私。最后,我们开发了一个原型实现的协议,证明了该建议的实用性。
Data integrity is extremely important for cloud based storage services, where cloud users no longer have physical possession of their outsourced files. A number of data auditing mechanisms have been proposed to solve this problem. However, how to efficiently update a cloud user’s secret auditing key as well as the authenticators those keys are associated with when the digital certificate expires in the PKI system is a critical issue. In this paper, we propose a key-updating and authenticator-evolving mechanism with zero-knowledge privacy of the stored files for secure cloud data auditing, which incorporates zero knowledge proof systems, proxy re-signatures and homomorphic linear authenticators. We instantiate our proposal with the state-of-the-art Shacham–Waters auditing scheme. When the cloud user needs to update his key, instead of downloading the entire file and re-generating all the authenticators, the user can simply download one single file tag, work out a re-signing key with the new private key and upload the new file tag together with some verification information to the cloud server, in which the user undertakes the least amount of the workload in the updating phase. This approach dramatically reduces the communication and computation cost while maintaining the desirable security. We formalize the security model of zero knowledge data privacy for auditing schemes in the key-updating context and prove the soundness and zero-knowledge privacy of the proposed construction. Finally, we develop a prototype implementation of the protocol which demonstrates the practicality of the proposal.