DOI: 10.1002/cpe.70871 ISSN: 1532-0626

Ownership‐Unaware and Deduplicated Integrity Auditing for Cloud Storage

Wenchao Wang, Bo Zhao, Haining Yang, Jing Qin, Jixin Ma

ABSTRACT

Integrity auditing with data deduplication enables integrity verification of outsourced data on an untrusted cloud server while deduplicating identical data so that only a copy is stored for multiple clients. However, deriving the authenticator key from the file breaks the binding between the file and its owner. Conversely, generating authenticators under clients' secret keys leads to vulnerability to rogue public‐key attacks, or auditing costs that increase with the number of clients sharing the same file. In addition, existing schemes may reveal file ownership relationships to auditors or external adversaries, leading to privacy leakage. To address these problems, we propose an ownership‐unaware integrity auditing scheme with data deduplication. In our scheme, the cloud server stores only an aggregate authenticator and an aggregate public key for the same data. Meanwhile, both the proof generation and verification overheads remain independent of the number of clients. Moreover, our scheme hides client file ownership privacy from auditors and external adversaries. The security of our scheme can be reduced to the CDH assumption. In addition, performance evaluation indicates that the auditing cost remains constant regardless of the number of clients sharing the same file, making the scheme suitable for cloud storage systems.

More from our Archive