Title of article :
Insecurity of an efficient privacy-preserving public auditing scheme for cloud data storage
Author/Authors :
Liu, Hongyu University of Electronic Science and Technology of China - School of Computer Science and Engineering, China , Chen, Leiting University of Electronic Science and Technology of China - School of Computer Science and Engineering, China , Davar, Zahra University of Wollongong - School of Computer Science and Software Engineering, Australia , Ramezanian Pour, Mohammad University of Wollongong - School of Computer Science and Software Engineering, Australia
From page :
473
To page :
482
Abstract :
Cloud storage has a long string of merits but at the same time,poses many challenges on data integrity and privacy. A cloud data auditing protocol,which enables a cloud server to prove the integrity of stored files to a verifier,is a powerful tool for secure cloud storage. Wang et al. proposed a privacy-preserving public auditing protocol,however,Worku et al. found the protocol is seriously insecure and proposed an improvement to remedy the weakness. In this paper,unfortunately,we demonstrate that the new protocol due to Worku et al. fails to achieve soundness and obtains merely limited privacy. Specifically,we show even deleting all the files of a data owner,a malicious cloud server is able to generate a response to a challenge without being caught by TPA in their enhanced but unrealistic security model. Worse still,the protocol is insecure even in a correct security model. For privacy,a dishonest verifier can tell which file is stored on the cloud. Solutions to efficient public auditing mechanisms with perfect privacy protection are still worth exploring.
Keywords :
Cloud storage , Data integrity , Privacy , preserving , Security analysis
Journal title :
Journal of J.UCS (Journal of Universal Computer Science)
Journal title :
Journal of J.UCS (Journal of Universal Computer Science)
Record number :
2715296
Link To Document :
بازگشت