| 本文已被:浏览 855次 下载 1781次 |
 码上扫一扫! |
|
|
| 支持高效数据所有权共享的动态云存储审计方案 |
|
殷新春1,2,3, 王经纬1, 宁建廷4,5
|
|
1.扬州大学 信息工程学院, 江苏 扬州 225127;2.扬州大学广陵学院, 江苏 扬州 225000;3.广东省信息安全技术重点实验室, 广东 广州 510275;4.福建师范大学 计算机与网络空间安全学院, 福建 福州 350007;5.信息安全国家重点实验室 (中国科学院 信息工程研究所), 北京 100093
|
|
| 摘要: |
| 云存储审计技术的出现为存储在云中的数据提供了可靠的安全保障, 数据拥有者可以轻易地验证存储在云中数据的完整性. 然而, 云服务器中可能存储着海量的数据, 目前的云存储审计方案在进行数据完整性验证以及数据所有权变更时均需花费大量的计算开销. 为了缓解该问题并提高云存储审计方案的实用性, 提出一种支持高效数据所有权共享的动态云存储审计方案. 在计算开销方面, 构造一种高效的验证结构可以聚合数据验证信息, 免去大量计算开销较高的双线性配对运算. 基于变色龙哈希函数易于制造新碰撞的特性设计高效的数据所有权共享机制, 共享数据所有权只需更新对应用户的密钥即可, 无需修改云服务器中存储的密文. 此外, 方案还提供了数据细粒度共享、密态数据验证以及数据动态修改功能. 安全性分析和性能分析表明, 方案可以在保证数据安全的同时不对方案的运行效率产生影响, 具有较高的实用性. |
| 关键词: 云存储审计 云计算 数据所有权共享 批量验证 数据共享 |
| DOI:10.13328/j.cnki.jos.007216 |
| 分类号:TP309 |
| 基金项目:国家自然科学基金(62102090, 62032005, 61972094, 61902070); 福建省科协第二届青年人才托举工程; 广东省信息安全技术重点实验室开放基金(2020B1212060078) |
|
| Dynamic Cloud Storage Auditing Scheme with Efficient Data Ownership Sharing |
|
YIN Xin-Chun1,2,3, WANG Jing-Wei1, NING Jian-Ting4,5
|
|
1.College of Information Engineering, Yangzhou University, Yangzhou 225127, China;2.Guangling College of Yangzhou University, Yangzhou 225000, China;3.Guangdong Provincial Key Laboratory of Information Security Technology, Guangzhou 510275, China;4.College of Computer and Cyber Security, Fujian Normal University, Fuzhou 350007, China;5.State Key Laboratory of Information Security (Institute of Information Engineering, Chinese Academy of Sciences), Beijing 100093, China
|
| Abstract: |
| Cloud storage auditing guarantees the security of data stored in the cloud, enabling data owners to easily verify the integrity of data. However, a vast amount of data in the cloud can lead to significant computational overhead during cloud storage auditing when verifying data integrity and modifying data ownership. To solve this problem as well as provide practical solutions, this study proposes a dynamic auditing scheme for cloud storage with efficient data ownership sharing. An efficient validation structure is constructed to aggregate information for data verification, avoiding a large number of bilinear pairing operations that incur high computational costs. An efficient mechanism for data ownership sharing is designed based on the chameleon hash function’s ability to generate new collisions. It allows updating the secret key of the corresponding user for shared data ownership without modifying the ciphertexts stored in the cloud. In addition, the proposed scheme achieves fine-grained data sharing, encrypted data auditing, and dynamic data modification. The security and performance analyses show that the proposed scheme ensures the security of data in the cloud without affecting its performance, which means it is a practical scheme. |
| Key words: cloud storage auditing cloud computing data ownership sharing batch auditing data sharing |