引用本文:殷新春,王经纬,宁建廷.支持高效数据所有权共享的动态云存储审计方案.软件学报,2025,36(7):3306-3320
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 855次   下载 1781 本文二维码信息
码上扫一扫!
分享到: 微信 更多
支持高效数据所有权共享的动态云存储审计方案
殷新春1,2,3, 王经纬1, 宁建廷4,5
1.扬州大学 信息工程学院, 江苏 扬州 225127;2.扬州大学广陵学院, 江苏 扬州 225000;3.广东省信息安全技术重点实验室, 广东 广州 510275;4.福建师范大学 计算机与网络空间安全学院, 福建 福州 350007;5.信息安全国家重点实验室 (中国科学院 信息工程研究所), 北京 100093
摘要:
云存储审计技术的出现为存储在云中的数据提供了可靠的安全保障, 数据拥有者可以轻易地验证存储在云中数据的完整性. 然而, 云服务器中可能存储着海量的数据, 目前的云存储审计方案在进行数据完整性验证以及数据所有权变更时均需花费大量的计算开销. 为了缓解该问题并提高云存储审计方案的实用性, 提出一种支持高效数据所有权共享的动态云存储审计方案. 在计算开销方面, 构造一种高效的验证结构可以聚合数据验证信息, 免去大量计算开销较高的双线性配对运算. 基于变色龙哈希函数易于制造新碰撞的特性设计高效的数据所有权共享机制, 共享数据所有权只需更新对应用户的密钥即可, 无需修改云服务器中存储的密文. 此外, 方案还提供了数据细粒度共享、密态数据验证以及数据动态修改功能. 安全性分析和性能分析表明, 方案可以在保证数据安全的同时不对方案的运行效率产生影响, 具有较高的实用性.
关键词:  云存储审计  云计算  数据所有权共享  批量验证  数据共享
DOI:10.13328/j.cnki.jos.007216
分类号:TP309
基金项目:国家自然科学基金(62102090, 62032005, 61972094, 61902070); 福建省科协第二届青年人才托举工程; 广东省信息安全技术重点实验室开放基金(2020B1212060078)
Dynamic Cloud Storage Auditing Scheme with Efficient Data Ownership Sharing
YIN Xin-Chun1,2,3, WANG Jing-Wei1, NING Jian-Ting4,5
1.College of Information Engineering, Yangzhou University, Yangzhou 225127, China;2.Guangling College of Yangzhou University, Yangzhou 225000, China;3.Guangdong Provincial Key Laboratory of Information Security Technology, Guangzhou 510275, China;4.College of Computer and Cyber Security, Fujian Normal University, Fuzhou 350007, China;5.State Key Laboratory of Information Security (Institute of Information Engineering, Chinese Academy of Sciences), Beijing 100093, China
Abstract:
Cloud storage auditing guarantees the security of data stored in the cloud, enabling data owners to easily verify the integrity of data. However, a vast amount of data in the cloud can lead to significant computational overhead during cloud storage auditing when verifying data integrity and modifying data ownership. To solve this problem as well as provide practical solutions, this study proposes a dynamic auditing scheme for cloud storage with efficient data ownership sharing. An efficient validation structure is constructed to aggregate information for data verification, avoiding a large number of bilinear pairing operations that incur high computational costs. An efficient mechanism for data ownership sharing is designed based on the chameleon hash function’s ability to generate new collisions. It allows updating the secret key of the corresponding user for shared data ownership without modifying the ciphertexts stored in the cloud. In addition, the proposed scheme achieves fine-grained data sharing, encrypted data auditing, and dynamic data modification. The security and performance analyses show that the proposed scheme ensures the security of data in the cloud without affecting its performance, which means it is a practical scheme.
Key words:  cloud storage auditing  cloud computing  data ownership sharing  batch auditing  data sharing