Xiaobing Shi , Jiawen Wu , Yifan Xu , Zhimei Sui , Lifei Wei , Kai Zhang
{"title":"VMC2-PS: Blockchain-based multi-copy data Pub/Sub service with fine-grained access control for multi-cloud storage","authors":"Xiaobing Shi , Jiawen Wu , Yifan Xu , Zhimei Sui , Lifei Wei , Kai Zhang","doi":"10.1016/j.jisa.2025.104113","DOIUrl":null,"url":null,"abstract":"<div><div>Data Pub/Sub services provide a secure manner for publishers and subscribers to selectively share and receive data. Besides enabling privacy protection and anti-malicious propagation of data, blockchain-based multi-cloud storage schemes have recently been proposed. However, existing data Pub/Sub works fail to achieve the following features: (i) multi-copy and multi-cloud storage; (ii) ciphertext integrity verification; (iii) fine-grained bilateral access control. Therefore, we design a fine-grained and verifiable data Pub/Sub service, VMC<span><math><msup><mrow></mrow><mrow><mn>2</mn></mrow></msup></math></span>-PS, which implements multi-cloud multi-copy storage and ciphertext integrity verification with fine-grained bilateral access control. Technically, we perform attribute-based keyword search operations by the edge nodes and employ a dual-policy framework to define access/subscription policy. To realize integrity verification, we employ blockchain technology for ciphertext verification using the Merkle tree and store the ciphertext (copy) as blocks on multiple cloud servers. Moreover, we provide the security model and analyze the security of the solution, then evaluate its performance in real cloud environments. Especially, VMC<span><math><msup><mrow></mrow><mrow><mn>2</mn></mrow></msup></math></span>-PS runs 12<span><math><mo>×</mo></math></span> faster than relevant solutions in the data encryption phase (with the number of attributes is 50).</div></div>","PeriodicalId":48638,"journal":{"name":"Journal of Information Security and Applications","volume":"93 ","pages":"Article 104113"},"PeriodicalIF":3.8000,"publicationDate":"2025-06-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Information Security and Applications","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2214212625001504","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0
Abstract
Data Pub/Sub services provide a secure manner for publishers and subscribers to selectively share and receive data. Besides enabling privacy protection and anti-malicious propagation of data, blockchain-based multi-cloud storage schemes have recently been proposed. However, existing data Pub/Sub works fail to achieve the following features: (i) multi-copy and multi-cloud storage; (ii) ciphertext integrity verification; (iii) fine-grained bilateral access control. Therefore, we design a fine-grained and verifiable data Pub/Sub service, VMC-PS, which implements multi-cloud multi-copy storage and ciphertext integrity verification with fine-grained bilateral access control. Technically, we perform attribute-based keyword search operations by the edge nodes and employ a dual-policy framework to define access/subscription policy. To realize integrity verification, we employ blockchain technology for ciphertext verification using the Merkle tree and store the ciphertext (copy) as blocks on multiple cloud servers. Moreover, we provide the security model and analyze the security of the solution, then evaluate its performance in real cloud environments. Especially, VMC-PS runs 12 faster than relevant solutions in the data encryption phase (with the number of attributes is 50).
期刊介绍:
Journal of Information Security and Applications (JISA) focuses on the original research and practice-driven applications with relevance to information security and applications. JISA provides a common linkage between a vibrant scientific and research community and industry professionals by offering a clear view on modern problems and challenges in information security, as well as identifying promising scientific and "best-practice" solutions. JISA issues offer a balance between original research work and innovative industrial approaches by internationally renowned information security experts and researchers.