SESIV:安全高效的基于智能合约的外包数据完整性验证

IF 3.7 2区 计算机科学 Q2 COMPUTER SCIENCE, INFORMATION SYSTEMS
Partha Sarathi Chakraborty, Somanath Tripathy
{"title":"SESIV:安全高效的基于智能合约的外包数据完整性验证","authors":"Partha Sarathi Chakraborty,&nbsp;Somanath Tripathy","doi":"10.1016/j.jisa.2025.104121","DOIUrl":null,"url":null,"abstract":"<div><div>Securing remote data storage is a serious concern in cloud computing. Though it provides cost-saving benefits for data owners, it poses security risks due to losing physical control over data. As a result, ensuring data integrity through auditing services becomes essential while preserving privacy. Therefore, researchers propose many public data auditing schemes using third-party auditors to alleviate computational burdens on the user side. However, a concern in the public auditing approach is the susceptibility to malicious behaviour of third-party auditors, which might compromise the accuracy and timeliness of auditing results. Existing solutions built upon RSA signatures and bilinear pairings often incur substantial computation and communication costs, rendering their integrity verification models inefficient and impractical. Recent proposals have used blockchain technology for public auditing schemes to address these challenges. This work presents a secure and efficient privacy-preserving data integrity verification model using smart contract, for outsourced data. Further, we extend the proposed scheme to support multiple owners, batch integrity verification, and dynamic auditing. The proposed scheme leverages digital signatures and public-key cryptography to ensure data integrity and secure authentication. The key aspect of the proposed scheme is to validate data integrity with minimal computational overhead for the auditor with a verification time of 0.143 ms (independent of the number of shard messages <span><math><mi>n</mi></math></span> and number of challenge blocks <span><math><mi>c</mi></math></span>), which is 33.33% lower than that of WWH scheme. The security analysis and implementation result show that the proposed scheme is secure and efficient.</div></div>","PeriodicalId":48638,"journal":{"name":"Journal of Information Security and Applications","volume":"93 ","pages":"Article 104121"},"PeriodicalIF":3.7000,"publicationDate":"2025-06-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"SESIV: Secure and efficient smart contract based integrity verification of outsourced data\",\"authors\":\"Partha Sarathi Chakraborty,&nbsp;Somanath Tripathy\",\"doi\":\"10.1016/j.jisa.2025.104121\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><div>Securing remote data storage is a serious concern in cloud computing. Though it provides cost-saving benefits for data owners, it poses security risks due to losing physical control over data. As a result, ensuring data integrity through auditing services becomes essential while preserving privacy. Therefore, researchers propose many public data auditing schemes using third-party auditors to alleviate computational burdens on the user side. However, a concern in the public auditing approach is the susceptibility to malicious behaviour of third-party auditors, which might compromise the accuracy and timeliness of auditing results. Existing solutions built upon RSA signatures and bilinear pairings often incur substantial computation and communication costs, rendering their integrity verification models inefficient and impractical. Recent proposals have used blockchain technology for public auditing schemes to address these challenges. This work presents a secure and efficient privacy-preserving data integrity verification model using smart contract, for outsourced data. Further, we extend the proposed scheme to support multiple owners, batch integrity verification, and dynamic auditing. The proposed scheme leverages digital signatures and public-key cryptography to ensure data integrity and secure authentication. The key aspect of the proposed scheme is to validate data integrity with minimal computational overhead for the auditor with a verification time of 0.143 ms (independent of the number of shard messages <span><math><mi>n</mi></math></span> and number of challenge blocks <span><math><mi>c</mi></math></span>), which is 33.33% lower than that of WWH scheme. The security analysis and implementation result show that the proposed scheme is secure and efficient.</div></div>\",\"PeriodicalId\":48638,\"journal\":{\"name\":\"Journal of Information Security and Applications\",\"volume\":\"93 \",\"pages\":\"Article 104121\"},\"PeriodicalIF\":3.7000,\"publicationDate\":\"2025-06-24\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of Information Security and Applications\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2214212625001589\",\"RegionNum\":2,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q2\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Information Security and Applications","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2214212625001589","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

摘要

确保远程数据存储的安全是云计算中的一个重要问题。虽然它为数据所有者提供了节省成本的好处,但由于失去了对数据的物理控制,它带来了安全风险。因此,在保护隐私的同时,通过审计服务确保数据完整性变得至关重要。因此,研究人员提出了许多使用第三方审计员的公共数据审计方案,以减轻用户端的计算负担。然而,公开审计方法的一个问题是容易受到第三方审计员恶意行为的影响,这可能会损害审计结果的准确性和及时性。现有的基于RSA签名和双线性对的解决方案通常会产生大量的计算和通信成本,使其完整性验证模型效率低下且不切实际。最近的提案已经将区块链技术用于公共审计计划,以应对这些挑战。本工作为外包数据提供了一种使用智能合约的安全高效的保护隐私的数据完整性验证模型。此外,我们扩展了该方案以支持多所有者、批量完整性验证和动态审计。该方案利用数字签名和公钥加密技术来确保数据完整性和安全认证。该方案的关键在于以最小的计算开销对审计员进行数据完整性验证,验证时间为0.143 ms(与分片消息数n和挑战块数c无关),比WWH方案低33.33%。安全性分析和实现结果表明,该方案安全、高效。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
SESIV: Secure and efficient smart contract based integrity verification of outsourced data
Securing remote data storage is a serious concern in cloud computing. Though it provides cost-saving benefits for data owners, it poses security risks due to losing physical control over data. As a result, ensuring data integrity through auditing services becomes essential while preserving privacy. Therefore, researchers propose many public data auditing schemes using third-party auditors to alleviate computational burdens on the user side. However, a concern in the public auditing approach is the susceptibility to malicious behaviour of third-party auditors, which might compromise the accuracy and timeliness of auditing results. Existing solutions built upon RSA signatures and bilinear pairings often incur substantial computation and communication costs, rendering their integrity verification models inefficient and impractical. Recent proposals have used blockchain technology for public auditing schemes to address these challenges. This work presents a secure and efficient privacy-preserving data integrity verification model using smart contract, for outsourced data. Further, we extend the proposed scheme to support multiple owners, batch integrity verification, and dynamic auditing. The proposed scheme leverages digital signatures and public-key cryptography to ensure data integrity and secure authentication. The key aspect of the proposed scheme is to validate data integrity with minimal computational overhead for the auditor with a verification time of 0.143 ms (independent of the number of shard messages n and number of challenge blocks c), which is 33.33% lower than that of WWH scheme. The security analysis and implementation result show that the proposed scheme is secure and efficient.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
Journal of Information Security and Applications
Journal of Information Security and Applications Computer Science-Computer Networks and Communications
CiteScore
10.90
自引率
5.40%
发文量
206
审稿时长
56 days
期刊介绍: Journal of Information Security and Applications (JISA) focuses on the original research and practice-driven applications with relevance to information security and applications. JISA provides a common linkage between a vibrant scientific and research community and industry professionals by offering a clear view on modern problems and challenges in information security, as well as identifying promising scientific and "best-practice" solutions. JISA issues offer a balance between original research work and innovative industrial approaches by internationally renowned information security experts and researchers.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信