Comments on "Efficient Public Verification of Data Integrity for Cloud Storage Systems From Indistinguishability Obfuscation"

被引:1
作者
Peng, Su [1 ]
Zhao, Liang [1 ]
Kumar, Neeraj [2 ,3 ]
机构
[1] Shenyang Aerosp Univ, Sch Comp Sci, Shenyang 110136, Peoples R China
[2] Thapar Inst Engn & Technol, Dept Comp Sci & Engn, Patiala 147004, Punjab, India
[3] Univ Petr & Energy Studies, Sch Comp Sci, Dehra Dun 248007, Uttarakhand, India
基金
中国国家自然科学基金;
关键词
Cloud storage; data integrity; security analysis;
D O I
10.1109/TIFS.2021.3102413
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recently, Zhang et al. proposed a novel public data integrity verification scheme for the cloud storage using indistinguishability obfuscation (iO), and extend it to support batch verification and data dynamic operations (IEEE Transactions on Information Forensics and Security, vol. 12, no. 3, pp. 676-688, Mar. 2017). However, we find that the scheme has two flaws: (a) the self-checking of the uploaded blocks and tags in Store phase is not reliable, i.e., it is easy to generate invalid block-tag pairs without being detected; (b) the extended scheme for data dynamic operations suffers from a chosen message attack, i.e., if some uploaded blocks match a certain pattern, the cloud storage is able to replace any existing block by a forged one without being detected, which violates the scheme's security model. Then, we provide solutions to these problems while preserving all the desirable features of the original scheme.
引用
收藏
页码:4113 / 4116
页数:4
相关论文
共 2 条
[1]   Compact Proofs of Retrievability [J].
Shacham, Hovav ;
Waters, Brent .
JOURNAL OF CRYPTOLOGY, 2013, 26 (03) :442-483
[2]   Efficient Public Verification of Data Integrity for Cloud Storage Systems from Indistinguishability Obfuscation [J].
Zhang, Yuan ;
Xu, Chunxiang ;
Liang, Xiaohui ;
Li, Hongwei ;
Mu, Yi ;
Zhang, Xiaojun .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2017, 12 (03) :676-688