Mirror: Enabling Proofs of Data Replication and Retrievability in the Cloud

Mirror: Enabling Proofs of Data Replication and Retrievability in the Cloud
复制标题

DOI:
--
复制
发表时间:
2016-08
期刊:
--
影响因子:
--
通讯作者:
Frederik Armknecht;Ludovic Barman;J. Bohli;Ghassan O. Karame
Frederik Armknecht;Ludovic Barman;J. Bohli;Ghassan O. Karame
中科院分区:
其他
文献类型:
--
作者:
Frederik Armknecht;Ludovic Barman;J. Bohli;Ghassan O. Karame

文献摘要

被引文献

相似文献

可检索性证明(POR)和数据拥有(PDP)是使云提供商能够证明数据正确存储在云中的加密协议。PDP最近得到了扩展,使用户能够在单个协议中检查是否还存储了其他文件副本。然而,为了进行多副本PDP,用户需要自己处理、构造和上传他们的数据副本。这会给服务提供商和用户带来额外的带宽开销,也会给提供商带来新的安全风险。也就是说,由于上传的文件通常是加密的,所以提供商不能识别上传的内容是否确实是副本。这限制了供应商可用的商业模式,因为例如,用于存储副本的降低的成本可能被上传不同文件的用户滥用--同时声称它们是副本。在本文中,我们解决这个问题,并提出了一种新的解决方案,证明数据复制和检索在云中,镜像,它允许转移的负担,构建副本的云提供商本身,从而符合当前的云模型。我们表明,镜像是安全的恶意用户和合理的云提供商。最后,我们实现了一个基于镜像的原型,并在一个真实的云环境中评估其性能。我们的评估结果表明,我们的建议会对用户和云提供商产生可容忍的开销。
Proofs of Retrievability (POR) and Data Possession (PDP) are cryptographic protocols that enable a cloud provider to prove that data is correctly stored in the cloud. PDP have been recently extended to enable users to check in a single protocol that additional file replicas are stored as well. To conduct multi-replica PDP, users are however required to process, construct, and upload their data replicas by themselves. This incurs additional bandwidth overhead on both the service provider and the user and also poses new security risks for the provider. Namely, since uploaded files are typically encrypted, the provider cannot recognize if the uploaded content are indeed replicas. This limits the business models available to the provider, since e.g., reduced costs for storing replicas can be abused by users who upload different files-while claiming that they are replicas. In this paper, we address this problem and propose a novel solution for proving data replication and retrievability in the cloud, Mirror, which allows to shift the burden of constructing replicas to the cloud provider itself-thus conforming with the current cloud model. We show that Mirror is secure against malicious users and a rational cloud provider. Finally, we implement a prototype based on Mirror, and evaluate its performance in a realistic cloud setting. Our evaluation results show that our proposal incurs tolerable overhead on the users and the cloud provider.