首页> 外文OA文献 >Improved security of a dynamic remote data possession checking protocol for cloud storage
【2h】

Improved security of a dynamic remote data possession checking protocol for cloud storage

机译:改进了用于云存储的动态远程数据拥有检查协议的安全性

摘要

Cloud storage offers the users with high quality and on-demand data storage services and frees them from the burden of maintenance. However, the cloud servers are not fully trusted. Whether the data stored on cloud are intact or not becomes a major concern of the users. Recently, Chen et al. proposed a remote data possession checking protocol to address this issue. One distinctive feature of their protocol support data dynamics, meaning that users are allowed to modify, insert and delete their outsourced data without the need to re-run the whole protocol. Unfortunately, in this paper, we find that this protocol fails to achieve its purpose since it is vulnerable to forgery attack and replace attack launched by a malicious server. Specifically, we show how a malicious cloud server can deceive the user to believe that the entire file is well-maintained by using the meta-data related to the file alone, or with only part of the file and its meta-data. Then, we propose an improved protocol to fix the security flaws and formally proved that our proposal is secure under a well-known security model. In addition, our improvement keeps all the desirable features of the original protocol.
机译:云存储为用户提供了高质量和按需数据存储服务,使他们免于维护负担。但是,云服务器不受完全信任。存储在云中的数据是否完整成为用户的主要问题。最近,Chen等。提出了一种远程数据拥有检查协议来解决此问题。其协议的一项独特功能支持数据动态性,这意味着允许用户修改,插入和删除其外包数据,而无需重新运行整个协议。不幸的是,在本文中,我们发现此协议无法实现其目的,因为它容易受到伪造攻击并替换恶意服务器发起的攻击。具体来说,我们展示了恶意云服务器如何通过仅使用与文件有关的元数据或仅与文件及其元数据的一部分有关的元数据来欺骗用户,以认为整个文件得到了很好的维护。然后,我们提出了一种改进的协议来修复安全漏洞,并正式证明了我们的提议在众所周知的安全模型下是安全的。此外,我们的改进保留了原始协议的所有理想功能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号