节点文献

云存储环境下的数据完整性审计方法研究

Research on Data Integrity Auditing Technology for Cloud Storage

【作者】 王硕;

【导师】 刘振鹏;

【作者基本信息】 河北大学 , 网络空间安全, 2024, 硕士

【摘要】 随着云存储技术的不断发展和信息的日益公开化,越来越多的用户或企业选择将自己的数据存储在云端,以节约维护管理成本,亦为用户之间的数据共享需求创造便利条件。与此同时,云存储技术由于自身特性所引发的敏感数据泄露、数据丢失、非法访问等一系列安全隐患,也成为制约其自身发展的关键因素。为了确保云端数据是否被完好存储,研究人员提出了云数据审计机制。然而,目前大部分方案审计效率并不理想,且应用场景单一,无法对审计安全和数据共享做到很好的兼顾。针对现有方案中的审计效率和共享安全等关键问题进行研究,本文主要工作如下:(1)在共享环境中,现有方案在审计时往往针对整个数据集,且无法支持用户的实时动态撤销,使得文件的审计效率和访问安全都无法得到充分的保证。本文提出了一种基于区块链和文件预测的共享数据审计方案。一方面,设计了一种轻量级的签名算法,以支持在无源数据的参与下实现实时的组成员撤销和文件签名的动态更新。另一方面,引入了文件预测算法,通过分析文件的访问时间、访问频率以及用户的访问偏好等指标,计算并过滤仍处于有效审计期的文件,最终得到有效审计文件集。文件预测算法能够在最大程度上确保一个文件只有在必要时才对其进行验证,以减少资源浪费。经安全分析和性能评估表明,方案能够充分保证组用户的撤销安全并提高数据审计效率。(2)在数据外包场景中,冗余备份是云存储中用来保证数据高可用的重要方法,但现有方案的计算开销却往往与副本数量呈正比。针对这一问题,本文提出了一种基于分层默克尔哈希树的动态数据完整性审计方案。一方面,利用双线性映射和椭圆曲线的性质,在数据上传到云端之前对副本签名进行局部聚合,以抵消其余副本所带来的额外开销,使副本数量与审计效率无关。另一方面,增加默克尔哈希树叶子结点数据关联量以减小树的规模,优化默克尔哈希树节点排列方式,并引入局部权威认证节点,以缩短认证路径长度。实验结果表明,方案能够有效提高数据审计效率和更新效率。

【Abstract】 With the continuous development of cloud storage technology and the increasing disclosure of information,more and more users or enterprises choose to store their data in the cloud to save maintenance and management costs and create convenient conditions for data sharing needs among users.At the same time,a series of security risks such as sensitive data leakage,data loss,and illegal access caused by the characteristics of cloud storage technology have also become key factors restricting its development.To ensure that cloud data is stored intact,researchers have proposed a cloud data audit mechanism.However,the audit efficiency of most current solutions is not ideal,and their application scenarios are single,making it impossible to take both audit security and data sharing into consideration.Given key issues such as audit efficiency and sharing security in existing solutions,this article conducts research from the following two aspects:(1)In the shared environment,existing solutions often target the entire data set when performing audits,and cannot support real-time dynamic revocation by users,making the audit efficiency and access security of files unable to be fully guaranteed.This paper proposes a shared data integrity auditing scheme based on blockchain and file prediction.On the one hand,we design a lightweight signature algorithm to support real-time group member revocation and dynamic update of file signatures with the participation of passive data.On the other hand,the solution introduces a file prediction algorithm.By analyzing indicators such as file access time,access frequency,and user access preferences,it calculates and filters files that are still in the effective audit period,and finally obtains an effective audit file set.The file prediction algorithm can ensure to the greatest extent that a file is verified only when necessary to reduce unnecessary waste of resources.Security analysis and performance evaluation indicate that the scheme can fully ensure the revocation security of group users and improve data auditing efficiency.(2)Redundant backup is an important method in cloud storage to ensure high data availability,but the computing overhead of existing solutions is often proportional to the number of copies.To address this problem,this paper proposes a dynamic data integrity auditing scheme based on hierarchical merkle hash tree.On the one hand,we use the properties of bilinear mapping and elliptic curves to locally aggregate replica signatures in advance to offset the additional overhead caused by the remaining replicas,making the number of replicas irrelevant to audit efficiency.On the other hand,increasing the amount of leaf node data association in the Merkel hash tree to reduce the size of the tree,optimizing the arrangement of Merkel hash tree nodes,and introducing local authoritative authentication nodes to shorten the length of the authentication path.The experimental results indicate that the scheme can effectively improve the efficiency of data auditing and updating.

  • 【网络出版投稿人】 河北大学
  • 【网络出版年期】2024年 12期
  • 【分类号】TP333;TP309
节点文献中: