On the Security of A Remote Cloud Storage Integrity Checking Protocol

12/01/2019
by   Faen Zhang, et al.
0

Data security and privacy is an important but challenging problem in cloud computing. One of the security concerns from cloud users is how to efficiently verify the integrity of their data stored on the cloud server. Third Party Auditing (TPA) is a new technique proposed in recent years to achieve this goal. In a recent paper (IEEE Transactions on Computers 62(2): 362-375 (2013)), Wang et al. proposed a highly efficient and scalable TPA protocol and also a Zero Knowledge Public Auditing protocol which can prevent offline guessing attacks. However, in this paper, we point out several security weaknesses in Wang et al's protocols: first, we show that an attacker can arbitrarily modify the cloud data without being detected by the auditor in the integrity checking process, and the attacker can achieve this goal even without knowing the content of the cloud data or any verification metadata maintained by the cloud server; secondly, we show that the Zero Knowledge Public Auditing protocol cannot achieve its design goal, that is to prevent offline guessing attacks.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/01/2019

Zero knowledge proofs for cloud storage integrity checking

With the wide application of cloud storage, cloud security has become a ...
research
04/16/2020

A Secure and Improved Multi Server Authentication Protocol Using Fuzzy Commitment

Very recently, Barman et al. proposed a multi-server authentication prot...
research
04/15/2020

Distributed Data Verification Protocols in Cloud Computing

Recently, storage of huge volume of data into Cloud has become an effect...
research
10/05/2020

Why Older Adults (Don't) Use Password Managers

Password managers (PMs) are considered highly effective tools for increa...
research
04/02/2019

On the Analysis of the Revocable-Storage Identity-Based Encryption Scheme

Cloud computing can provide a flexible way to effectively share data amo...
research
05/21/2020

SafeComp: Protocol For Certifying Cloud Computations Integrity

We define a problem of certifying computation integrity performed by som...
research
04/13/2021

Practical Pitfalls for Security in OPC UA

In 2006, the OPC Foundation released the first specification for OPC Uni...

Please sign up or login with your details

Forgot password? Click here to reset