DocumentCode :
1362223
Title :
Enabling Public Auditability and Data Dynamics for Storage Security in Cloud Computing
Author :
Wang, Qian ; Wang, Cong ; Ren, Kui ; Lou, Wenjing ; Li, Jin
Author_Institution :
Dept. of Electr. & Comput. Eng., Illinois Inst. of Technol., Chicago, IL, USA
Volume :
22
Issue :
5
fYear :
2011
fDate :
5/1/2011 12:00:00 AM
Firstpage :
847
Lastpage :
859
Abstract :
Cloud Computing has been envisioned as the next-generation architecture of IT Enterprise. It moves the application software and databases to the centralized large data centers, where the management of the data and services may not be fully trustworthy. This unique paradigm brings about many new security challenges, which have not been well understood. This work studies the problem of ensuring the integrity of data storage in Cloud Computing. In particular, we consider the task of allowing a third party auditor (TPA), on behalf of the cloud client, to verify the integrity of the dynamic data stored in the cloud. The introduction of TPA eliminates the involvement of the client through the auditing of whether his data stored in the cloud are indeed intact, which can be important in achieving economies of scale for Cloud Computing. The support for data dynamics via the most general forms of data operation, such as block modification, insertion, and deletion, is also a significant step toward practicality, since services in Cloud Computing are not limited to archive or backup data only. While prior works on ensuring remote data integrity often lacks the support of either public auditability or dynamic data operations, this paper achieves both. We first identify the difficulties and potential security problems of direct extensions with fully dynamic data updates from prior works and then show how to construct an elegant verification scheme for the seamless integration of these two salient features in our protocol design. In particular, to achieve efficient data dynamics, we improve the existing proof of storage models by manipulating the classic Merkle Hash Tree construction for block tag authentication. To support efficient handling of multiple auditing tasks, we further explore the technique of bilinear aggregate signature to extend our main result into a multiuser setting, where TPA can perform multiple auditing tasks simultaneously. Extensive security and performance analysis show that the proposed schemes are highly efficient and provably secure.
Keywords :
cloud computing; cryptography; storage management; bilinear aggregate signature technique; block deletion; block insertion; block modification; block tag authentication; classic Merkle hash tree construction; cloud computing; data centers; data dynamics; data storage integrity; public auditability; storage security model; third party auditor; Cloud computing; Clouds; Data models; Memory; Protocols; Security; Servers; Data storage; cloud computing.; data dynamics; public auditability;
fLanguage :
English
Journal_Title :
Parallel and Distributed Systems, IEEE Transactions on
Publisher :
ieee
ISSN :
1045-9219
Type :
jour
DOI :
10.1109/TPDS.2010.183
Filename :
5611497
Link To Document :
بازگشت