TY - JOUR
T1 - Identity-Based Remote Data Integrity Checking with Perfect Data Privacy Preserving for Cloud Storage
AU - Yu, Yong
AU - Au, Man Ho
AU - Ateniese, Giuseppe
AU - Huang, Xinyi
AU - Susilo, Willy
AU - Dai, Yuanshun
AU - Min, Geyong
N1 - Publisher Copyright:
© 2005-2012 IEEE.
PY - 2017/4
Y1 - 2017/4
N2 - Remote data integrity checking (RDIC) enables a data storage server, say a cloud server, to prove to a verifier that it is actually storing a data owner's data honestly. To date, a number of RDIC protocols have been proposed in the literature, but most of the constructions suffer from the issue of a complex key management, that is, they rely on the expensive public key infrastructure (PKI), which might hinder the deployment of RDIC in practice. In this paper, we propose a new construction of identity-based (ID-based) RDIC protocol by making use of key-homomorphic cryptographic primitive to reduce the system complexity and the cost for establishing and managing the public key authentication framework in PKI-based RDIC schemes. We formalize ID-based RDIC and its security model, including security against a malicious cloud server and zero knowledge privacy against a third party verifier. The proposed ID-based RDIC protocol leaks no information of the stored data to the verifier during the RDIC process. The new construction is proven secure against the malicious server in the generic group model and achieves zero knowledge privacy against a verifier. Extensive security analysis and implementation results demonstrate that the proposed protocol is provably secure and practical in the real-world applications.
AB - Remote data integrity checking (RDIC) enables a data storage server, say a cloud server, to prove to a verifier that it is actually storing a data owner's data honestly. To date, a number of RDIC protocols have been proposed in the literature, but most of the constructions suffer from the issue of a complex key management, that is, they rely on the expensive public key infrastructure (PKI), which might hinder the deployment of RDIC in practice. In this paper, we propose a new construction of identity-based (ID-based) RDIC protocol by making use of key-homomorphic cryptographic primitive to reduce the system complexity and the cost for establishing and managing the public key authentication framework in PKI-based RDIC schemes. We formalize ID-based RDIC and its security model, including security against a malicious cloud server and zero knowledge privacy against a third party verifier. The proposed ID-based RDIC protocol leaks no information of the stored data to the verifier during the RDIC process. The new construction is proven secure against the malicious server in the generic group model and achieves zero knowledge privacy against a verifier. Extensive security analysis and implementation results demonstrate that the proposed protocol is provably secure and practical in the real-world applications.
KW - Cloud storage
KW - data integrity
KW - identity-based cryptography
KW - privacy preserving
UR - http://www.scopus.com/inward/record.url?scp=85014919981&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=85014919981&partnerID=8YFLogxK
U2 - 10.1109/TIFS.2016.2615853
DO - 10.1109/TIFS.2016.2615853
M3 - Article
AN - SCOPUS:85014919981
SN - 1556-6013
VL - 12
SP - 767
EP - 778
JO - IEEE Transactions on Information Forensics and Security
JF - IEEE Transactions on Information Forensics and Security
IS - 4
M1 - 7586112
ER -