详细信息
面向团队场景的无证书云数据完整性授权审计方案研究
Certificateless Cloud Data Integrity Authorization Audit Scheme for Team Scenario
文献类型:期刊文献
中文题名:面向团队场景的无证书云数据完整性授权审计方案研究
英文题名:Certificateless Cloud Data Integrity Authorization Audit Scheme for Team Scenario
作者:刘易齐[1];徐贤[1];龙宇[2]
机构:[1]华东理工大学信息科学与工程学院,上海200237;[2]上海交通大学计算机科学与工程系,上海200240
年份:2025
卷号:48
期号:12
起止页码:2948
中文期刊名:计算机学报
外文期刊名:Chinese Journal of Computers
收录:;北大核心:【北大核心2023】;
基金:上海市2024年度“科技创新行动计划”(Nos.24BC3200500,24BC3200300)资助。
语种:中文
中文关键词:云存储;数据完整性审计;授权审计;团队场景;数据隐私
外文关键词:cloud storage;data integrity audit;authorization audit;team scenario;data privacy
摘要:在云存储技术飞速发展的环境下,大量用户可以将自己的数据上传至云服务器,从而节省本地存储空间。云服务器可能存在数据丢损风险,因此引入第三方审计员进行云数据完整性审计是很有必要的措施。在团队场景的审计任务中,现有研究方案主要集中于支持完整性审计和用户撤销操作。然而,审计员的审计操作可能会泄露用户的数据隐私信息,并非所有用户都希望任意审计员审计其数据。为此,我们提出了一个面向团队场景的无证书云数据完整性授权审计方案。该方案通过共用陷门实现了审计员的授权及变更,采用随机盲化因子对审计证明进行盲化处理,保护了用户的数据隐私。在安全性分析中,所提方案满足正确性、隐私保护性、数据标签的不可伪造性等特性。实验分析表明,我们的方案支持多用户高效批量验证,与传统的本地用户更新标签方案相比分别将更换授权审计者和处理用户撤销的时间降低至0.1%和46%左右,有效节省了计算耗费。
With the rapid advancement of cloud storage technology,an increasing number of users are leveraging cloud servers to store massive volumes of data,thereby significantly reducing the demand for local storage resources.While cloud storage offers substantial benefits in terms of scalability and accessibility,it also introduces potential risks such as data corruption or loss due to server failures,malicious attacks,or operational errors.To mitigate these risks,the introduction of third-party auditors has been widely recognized as an effective mechanism to verify the integrity of remotely stored data.In team scenarios,where multiple users collaboratively store and manage shared data,the need for reliable integrity auditing becomes even more critical.Existing research in the field has predominantly focused on designing schemes that support public integrity auditing and efficient user revocation.These approaches allow an external auditor to periodically check whether the cloud server correctly retains the users'data without requiring local data retrieval.However,a significant drawback of such methods is that the auditing process may potentially expose sensitive information related to the users'data.Since the audit proofs often involve metadata generated from the original data,malicious or curious auditors could infer private information through repeated audit interactions.Moreover,in a collaborative team setting,not all users may be willing to allow arbitrary auditors to access their data.To address these challenges,we develop a novel certificateless cloud data integrity authorization audit scheme that is specifically designed for team scenarios.This approach differs from traditional methods that rely on public key infrastructure,as our certificateless framework removes the necessity for complex certificate management and simultaneously avoids key escrow problems.The proposed scheme is built around two key technical contributions.Firstly,it incorporates a shared trapdoor mechanism that enables dynamic authorization and revocation of auditors.This mechanism ensures that changes in auditor assignments can be handled efficiently.Secondly,the scheme utilizes random blinding factors to obscure the audit proof during the verification phase.This design effectively prevents auditors from gaining the actual content of the stored data,thereby safeguarding user privacy.In the security analysis part of our work,we provide proofs that the proposed scheme meets several critical security requirements,including correctness and privacy.Correctness guarantees that all properly generated proofs will be validated successfully.Privacy ensures that any leakage of sensitive information to auditors during the auditing process is prevented.Furthermore,it offers unforgeability of data tags,meaning that even a malicious cloud server cannot create valid authentication tags for data blocks that have been altered or compromised.Experimental evaluations indicate that our scheme supports efficient batch verification for multiple users.Compared to conventional approaches where users must locally update metadata during user revocation or auditor changes,our method significantly reduces computational overhead.Specifically,the time required for changing authorized auditors is reduced to approximately 0.1%of that required by traditional local user update methods,while the time for processing user revocation is cut down to about 46%.These improvements make the scheme highly practical for team-based cloud storage systems.
参考文献:
正在载入数据...
