Intrusion-Resilient Public Auditing Protocol for Data Storage in Cloud Computing

Intrusion-Resilient Public Auditing Protocol for Data Storage in Cloud Computing
复制标题

DOI:
10.1007/978-3-319-93638-3_23
复制
发表时间:
2018-07
期刊:
--
影响因子:
--
通讯作者:
Yan Xu;R. Ding;Jie Cui;Hong Zhong
Yan Xu;R. Ding;Jie Cui;Hong Zhong
中科院分区:
其他
文献类型:
--
作者:
Yan Xu;R. Ding;Jie Cui;Hong Zhong

文献摘要

被引文献

相似文献

云存储审计是一项重要的服务,它为云服务器中的客户端数据提供完整性检查。然而,如果客户端的审计密钥被暴露,恶意云服务器可以篡改甚至丢弃客户端的数据而不被发现。在本文中,我们提出了一个入侵弹性的公共审计协议,可以减少所造成的损害,密钥暴露。在我们的协议中,审计秘密密钥由客户端管理的第三方审计员(TPA)的帮助下,谁不能计算客户端的审计秘密密钥。我们的协议将存储在云上的文件的生命周期分为几个时间段,每个时间段进一步分为几个刷新周期。我们证明了我们的协议是安全的(即,后向安全性和前向安全性)对抗对手,只要客户端和TPA在不同的刷新周期中被危及。当客户端和TPA在相同的刷新周期内受到损害时,我们的协议仍然捕获前向安全性。
Cloud storage auditing is a crucial service that provides integrity checking for clients’ data in the cloud server. However, if the client’s auditing secret key is exposed, the malicious cloud server can tamper even throw away the client’s data without being detected. In this paper, we propose an intrusion-resilient public auditing protocol that can reduce the damage caused by key exposure. In our protocol, the auditing secret key is managed by the client with the help of a third party auditor (TPA), who cannot compute the client’s auditing secret key. Our protocol divides the lifetime of file stored on cloud into several time periods, and each time period is further divided into several refreshing periods. We show that our protocol is secure (i.e., backward security and forward security) against the adversary as long as the client and TPA are compromised in different refreshing period. Our protocol still captures the forward security when the client and TPA are compromised in the same refreshing period.