Skip to main navigation Skip to search Skip to main content

Cryptographic Technologies for Data Integrity Checking in Clouds

  • Yujue WANG

Student thesis: Doctoral Thesis

Abstract

Cloud storage system provides facilitative data storage and sharing services for distributed clients and thus is widely believed to be promising in reducing the clients’ local hardware and software maintenance burden of large-scale data storage. The integrity of the outsourced data may however be affected by the threats such as hardware failures and even intentional corruptions of the cloud storage server. To address such issues, a standard cryptographic primitive, Provable Data Possession (PDP), has been introduced to efficiently check integrity of the outsourced files and a number of con¬crete proposals have been presented so far. To promote its applications in real world, the goals of this thesis are to formalize advanced models of secure cloud storage in multi-user settings, along with proposals proved secure against the considered threats, as well as to make existing PDP schemes more affordable by the resource-constrained clients. Specifically, we achieve the following results.
1. We introduce and formalize the notion of group-oriented provable data possession (GPDP). In a GPDP, each file owner, after being authorized as a member by a group manager, can outsource the file to a group storage account maintained by an untrusted party, for example, a cloud storage server, while anyone can efficiently verify the integrity of the remotely stored files without seeing the files. The file owner’s identity privacy is preserved against the cloud server but the group manager can trace the one who outsourced any suspicious file for liability investigation. By novelly identifying and exploiting several useful properties, that is, homomorphic composability and homomorphic verifiability in some signatures, we propose a generic GPDP construction relying on the security of the underlying signature scheme and the hardness of the Static Diffie–Hellman (SDH) problem. Following the generic construction, we instantiate a concrete GPDP scheme with the well-known Boneh–Boyen short signature. Using the polynomial commitment technique, the proposed GPDP proposal is optimized with constant-size bandwidth consumption in proof of storage by the cloud server.
2. We propose a proxy data outsourcing (PDO) scheme. On one hand, our PDO scheme allows a client to authorize dedicated proxies to upload data to the cloud storage server on behalf of the client, for example, a company may authorize some employees to upload files to the company’s cloud account in a controllable way. On the other hand, in addition to regular integrity auditing as that in related schemes, the information about the origin, type and consistence of the outsourced files can also be publicly audited in our PDO scheme.
3. We securely offload existing PDP schemes. It is known that most existing PDP schemes pose a substantial number of expensive exponentiations on the clients, including the file owner outsourcing the files and the verifier periodically checking the integrity of the outsourced files. These labouring computations incur an obstacle for PDP schemes to be practically deployed, for example, some weak clients with constrained computation capacity may be interested in outsourcing files for online sharing or their limited storage space. To circumvent this obstacle, we first present a cryptographic tool to facilitate one to securely outsourcing general multi-base exponentiations to a single curious server. In comparison to the existing related tools, our proposal is advantageous with enhanced data privacy and more practical trust assumption. Specifically, outsourcing a single exponentiation can bring roughly twice the speed of local computation. By applying our tool, we propose the first proposal to offload PDP schemes at the client side.
4. We propose a batch PDP (BPDP) framework. Motivated by the fact that all existing schemes process the files to be outsourced in an inefficient serial paradigm, that is, generates the meta-data for file blocks one by one, we make the first effort to accelerate PDP with a batch file processing paradigm. First, we propose a batch PDP framework in a multi-replica cloud storage setting. BPDP allows both batch meta-data generation for all blocks and batch integrity auditing. Second, of independent interest, we present an efficient batch simultaneous exponentiation (BSE) algorithm which requires no pre-computation with extra storage or third-party assistance with communication latency. Third, following the BPDP framework and exploiting the proposed BSE algorithm, we instantiate a concrete BPDP scheme in multi-replica cloud storage.
5. We introduce and formalize an online/offline PDP (OOPDP) model. In OOPDP, the file processing process is divided into online and offline phases so that the online cost is as small as possible. We present a general framework to transform PDP schemes to OOPDP ones. The main challenges are that the existing PDP schemes have been designed in an ad hoc way and in security proof, the simulator has to convert the response to the OOPDP challenge into a response to the PDP challenge of the underlying scheme. We address these challenges by identifying two critical properties, that is, meta-data aggregatability and public meta-data expansibility. Our transformation is general enough and applicable to most existing PDP schemes. Illustratively, follow this framework, we instantiate three OOPDP schemes from representative CDH-/RSA-based PDP schemes. We also show an effective method to further reduce the computation and storage costs without degrading security, and in the resulting schemes, the online computation requires only light-weight operations, i.e., modular multiplications and additions, while the overall computation and storage costs are almost comparable to the underlying PDP schemes. Technically, we extend Chameleon hash function to aggregatable vector Chameleon hash (AVCH) which allows different hash values to be aggregated into a single one and plays a central role in the generic transformation and concrete instantiations.
Date of Award4 Aug 2015
Original languageEnglish
Awarding Institution
  • City University of Hong Kong
SupervisorShek Duncan WONG (Supervisor)

Cite this

'