西安电子科技大学学报 ›› 2023, Vol. 50 ›› Issue (5): 132-141.doi: 10.19665/j.issn1001-2400.20230107

• 网络空间安全 • 上一篇    下一篇

一种改进的短签名云数据审计方案

崔圆佑1,2(),王绪安1(),郎讯3(),涂正1(),苏昀暄1()   

  1. 1.武警工程大学 密码工程学院,陕西 西安 710000
    2.武警安徽总队,安徽 合肥 230000
    3.武警贵州总队,贵州 贵阳 550000
  • 收稿日期:2022-11-02 出版日期:2023-10-20 发布日期:2023-11-21
  • 通讯作者: 王绪安
  • 作者简介:崔圆佑(1995—),男,武警安徽总队某部硕士研究生,E-mail:jshmcuiyuanyou@163.com;|郎 讯(1990—),男,武警贵州总队某部助理工程师,E-mail:langapf@163.com;|涂 正(1998—),男,武警工程大学硕士研究生,E-mail:tutu_2248@163.com;|苏昀暄(1996—),男,武警工程大学硕士研究生,E-mail:2633389084@qq.com
  • 基金资助:
    国家自然科学基金(62172436);陕西省自然科学基金(2023-JC-YB-584);武警工程大学基础前沿创新项目(WJY202313)

Improved short-signature based cloud data audit scheme

CUI Yuanyou1,2(),WANG Xu’an1(),LANG Xun3(),TU Zheng1(),SU Yunxuan1()   

  1. 1. College of Cryptographic Engineering,Engineering University of PAP,Xi’an 710000,China
    2. Anhui Corps of PAP,Hefei 230000,China
    3. Guizhou Corps of PAP,Guiyang 550000,China
  • Received:2022-11-02 Online:2023-10-20 Published:2023-11-21
  • Contact: Xu’an WANG

摘要:

随着物联网的发展,云存储数据产生了爆发式的增长,有效验证存储在云存储服务提供商上数据的完整性成为了一个重要问题。为解决已知的基于BLS短签名的数据完整性审计方案计算效率不高的问题,2019年ZHU等设计了基于ZSS短签名的数据完整性审计方案。但ZHU等的方案在挑战阶段生成的证据在运算上存在正确性问题,并且能对其进行重放攻击或者利用双线性映射特征进行攻击,从而通过第三方审计者的审计。通过改进挑战阶段证据的计算方法,优化验证阶段第三方审计者用于验证证据的双线性对等式,提出了优化的基于ZSS短签名的云数据审计方案。证明了改进后方案的正确性,弥补了原方案中存在的不足,同时分析了方案的安全性。改进的方案中不仅包括第三方审计者在内的攻击者无法恢复出用户数据,而且可以抵抗包括恶意云存储服务提供商在内的攻击者的重放攻击和伪造攻击。通过数值分析发现,计算开销变化不大,通信代价降低,比原方案提供了更好的计算准确性。

关键词: 短签名, 云存储, 云安全, 持有性证明

Abstract:

With the development of the Internet of Things,Cloud storage has experienced an explosive growth.Effective verification of the integrity of data stored on the Cloud storage service providers(CSP) has become an important issue.In order to solve the problem that the existing data integrity audit scheme based on the BLS short signature is inefficient,ZHU et al.designed a data integrity audit scheme based on the ZSS short signature in 2019.However,this paper points out that the proof generated by ZHU et al.'s scheme in the challenge phase is incorrect and can be subjected to replay attacks or attacked by using a bilinear map,so as to pass the audit of a third party auditor(TPA).Then,this paper proposes an improved cloud audit scheme based on the short signature by improving the calculation method of proof in the challenge stage and optimizing the equations used by the third party auditor in the verification stage for verifying proof.This paper proves the correctness of the improved scheme,compensates for the shortcomings in the original scheme,and analyzes the security of the scheme.The improved scheme not only can make attackers including the third party auditor unable to recover users’ data,but also can resist replay attacks and forgery attacks of attackers including malicious cloud storage service providers.Through numerical analysis,it is found that the computational cost did not change much,and that the communication cost decreased,thus providing a better computational accuracy than the original scheme.

Key words: short signature, cloud storage, cloud security, data possession proof

中图分类号: 

  • TP309.7