Zhang Jindan, Ogiela Urszula, Taniar David, Nedjah Nadia
Xianyang Vocational & Technical College, Xianyang, Shaanxi, China.
AGH University of Science and Technology, Institute of Computer Science, Krakow, Poland.
Math Biosci Eng. 2023 Feb 22;20(5):7905-7921. doi: 10.3934/mbe.2023342.
Cloud storage has become a crucial service for many users who deal with big data. The auditing scheme for cloud storage is a mechanism that checks the integrity of outsourced data. Cloud storage deduplication is a technique that helps cloud service providers save on storage costs by storing only one copy of a file when multiple users outsource the same file to cloud servers. However, combining storage auditing and deduplication techniques can be challenging. To address this challenge, in 2019 Hou et al. proposed a cloud storage auditing scheme with deduplication that supports different security levels of data popularity. This proposal is interesting and has practical applications. However, in this paper, we show that their proposal has a flaw: the cloud or other adversaries can easily forge the data block's authenticators, which means the cloud can delete all the outsourced encrypted data blocks but still provide correct storage proof for the third-party auditor. Based on Hou et al.'s scheme, we propose an improved cloud storage auditing scheme with deduplication and analyze its security. The results show that the proposed scheme is more secure.
云存储已成为许多处理大数据的用户的一项关键服务。云存储审计方案是一种检查外包数据完整性的机制。云存储重复数据删除技术是一种通过在多个用户将同一文件外包给云服务器时仅存储一份文件副本,帮助云服务提供商节省存储成本的技术。然而,将存储审计和重复数据删除技术相结合可能具有挑战性。为应对这一挑战,2019年侯等人提出了一种支持不同数据流行度安全级别的带重复数据删除功能的云存储审计方案。该提议很有趣且具有实际应用价值。然而,在本文中,我们表明他们的提议存在一个缺陷:云或其他对手可以轻松伪造数据块的认证器,这意味着云可以删除所有外包的加密数据块,但仍能为第三方审计师提供正确的存储证明。基于侯等人的方案,我们提出了一种改进的带重复数据删除功能的云存储审计方案,并分析了其安全性。结果表明,所提出的方案更安全。