Remote Data Possession Checking with Enhanced Security for Cloud Storage

Yong Yu,Yafang Zhang,Jianbing Ni,Man Ho Au,Lanxiang Chen,Hongyu Liu
DOI: https://doi.org/10.1016/j.future.2014.10.006
IF: 7.307
2015-01-01
Future Generation Computer Systems
Abstract:Cloud storage allows users to enjoy the on-demand and high quality data storage services without the load of local data maintenance. However, the cloud server providers are not fully trusted. Whether the data over cloud servers are intact becomes a major concern of data owners. To offer cloud users with the capacity of data integrity verification, recently, Chen proposed a remote data possession checking (RDPC) protocol from algebraic signatures which achieves many desirable features such as high efficiency, short length of challenges and responses, non-block verification. Unfortunately, in this paper, we find that the protocol is vulnerable to replay attack and deletion attack launched by a dishonest server. Specifically, the server can deceive the users to believe that their data are well hold by replaying a previous evidence or re-constructing the deleted data blocks from the corresponding tags in the integrity checking process, while their data have been partially discarded in fact. Then, we present an improved scheme to fix the security flaws of the original protocol. Both the theoretical analysis and the implementation results show that the improvement is secure and practical.
What problem does this paper attempt to address?