Certificateless signature cross-file-block-level updating duplicate removal and mixed auditing method

Through cross-file block-level update deduplication and hybrid audit methods without certificate signature, the deduplication and data integrity problems in cloud storage systems are solved, efficient data block-level dynamic update and deduplication are achieved, certificate overhead and communication overhead are reduced, and user keys are supported to efficiently update, and system flexibility and efficiency are improved.

CN120429302AActive Publication Date: 2025-08-05SUQIAN COLLEGE

Patent Information

Application Number
CN202510513981.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-08-05
Estimated Expiration
2045-04-23

AI Technical Summary

Technical Problem

In existing cloud storage systems, deduplication solutions rely on traditional PKI or identity-based signatures, resulting in large certificate overhead or key hosting problems. The blockchain implementation of deduplication solutions has a large communication overhead and does not support dynamic data operations. The block deduplication across files cannot be reasonably solved, resulting in difficulty for users to upload and maintain repeatedly.

Method used

The cross-file block-level update deduplication and hybrid audit method without certificate signature is adopted. The system parameters and user identity keys are generated through the key generation center, combined with dynamic index tables and partial encryption, and dynamic updates and deduplications are realized at block-level, supporting hybrid audits of explicit ciphertexts to reduce communication and storage overhead.

Benefits of technology

It realizes data integrity protection, privacy protection, dynamic updates and deduplication across file block levels, reduces certificate overhead and communication overhead, supports efficient update of user keys, and improves system flexibility and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120429302A_ABST
    Figure CN120429302A_ABST
Patent Text Reader

Abstract

The invention discloses a cross-file-block-level updating, deduplication and hybrid auditing method of a certificateless signature. The method comprises the following steps of system initialization, identity key generation, first data file processing, auditing generation and verification, subsequent file uploading processing, data-block-level dynamic and identity key updating. According to the method, the newly designed duplicate removal and dynamic index table are combined, the certificateless signature and the message locking encryption strategy are utilized, the certificate overhead is reduced, the key escrow problem is also avoided, and meanwhile, in the initial file processing stage and the subsequent file processing stage, the privacy protection of the user data is realized by utilizing the partial encryption strategy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a cross-file block-level update deduplication and hybrid auditing method without certificate signature. Background Art

[0002] Cloud storage, a data hosting service favored by businesses and individual users, provides a convenient way for users to continuously upload data to cloud servers and access it on-demand. Despite the existence of a variety of popular cloud storage services on the market, data integrity issues remain a serious problem. This is because users typically do not keep local copies of their data. Once the data on the cloud server is damaged or lost, it may result in irreparable losses. Therefore, data integrity auditing has emerged, allowing users or authorized third parties to verify the integrity of data in cloud storage at any time. By analyzing the audit evidence returned by the server, it can be determined whether the data in the cloud storage is authentically and completely held by the server. Currently, audit research mainly focuses on the public audit field of single-file storage, covering aspects such as data sharing, privacy protection, and dynamic data management.

[0003] At the same time, in order to reduce users' payment for storage space and the storage overhead of cloud servers, audit schemes that support deduplication have been proposed. Most schemes rely on data hash as encryption key, allowing the same data block to be encrypted into the same ciphertext to achieve the purpose of deduplication. Although there are some audit schemes that achieve the purpose of deduplication, they have the following defects: (1) Most schemes are either built on traditional PKI or identity-based signatures. Therefore, the performance of the scheme is limited due to excessive certificate overhead or it faces key custody issues, which makes it difficult to apply. (2) Some audit schemes that rely on blockchain to achieve deduplication require all relevant tags to be uploaded to the cloud server and blockchain at the same time. Multiple interactions in the data processing stage result in high communication overhead. In addition, the security of the blockchain itself will also pose a threat to the scheme. In addition, it is almost impossible for blockchain-based audit schemes to support dynamic data operations because once stored in the blockchain, it will be difficult to change the data. (3) Current deduplication methods always default to deduplication across users and files, and fail to provide a reasonable solution for deduplication of blocks within a single file with duplicate content. They often simply deduplicate all file blocks for all users on the cloud server. This model doesn't meet data isolation requirements and can't satisfy all users' need to maintain their own data blocks. It also fails to prevent users from repeatedly uploading duplicate data blocks and tags. Furthermore, existing deduplication solutions assume that there are no duplicate blocks within the initially uploaded single file, or simply remove duplicates, making subsequent access and maintenance difficult for users. Summary of the Invention

[0004] In order to solve the above technical problems, the present invention proposes a cross-file block-level update deduplication and hybrid audit method without certificate signature, which realizes the functions of integrity protection, data privacy protection, cross-file data block-level dynamic update, cross-file block-level deduplication, plaintext and ciphertext hybrid audit, and user key update.

[0005] In order to achieve the above object, the technical solution of the present invention is as follows:

[0006] The cross-file block-level update deduplication and hybrid auditing method without certificate signature includes the following steps:

[0007] System initialization: The key generation center generates the system public parameters paras and the master private key msk;

[0008] Identity key generation: The user interacts with the key generation center to obtain the identity private key dk U , and choose the secret parameters As part of the private key, calculate the public key pk U With the private key sk U ;

[0009] First data file processing: User processes the first file F 1 Processing includes checking for duplication, dividing blocks, encryption, calculating block labels, block labels and file labels, and creating a deduplication and dynamic index table. The deduplication and dynamic index table stores the block label of each non-duplicate data block, the file label of the file where the data block is located, and the index set of the data block in the file where the data block is located. The cloud server checks the file signature and the legitimacy of the block label and then stores the data set and the deduplication and dynamic index table. The local computer only stores the deduplication and dynamic index table.

[0010] Audit generation and verification: A third-party auditor initiates an audit challenge on behalf of the user and sends a random challenge to the cloud server. The cloud server calculates the corresponding integrity audit evidence and returns it to the third-party auditor, who then verifies the audit evidence.

[0011] Subsequent file upload processing: User is the subsequent file F 2 The non-duplicate data blocks in the data are divided into blocks, encrypted, and the deduplication and dynamic index tables are updated, the block labels and file labels are calculated, and the data set is uploaded to the cloud server; a new sequence number set is inserted in the row corresponding to the block label in the deduplication and dynamic index table for the duplicate data blocks, and the set corresponding to the non-duplicate blocks and the updated deduplication and dynamic index table are uploaded to the cloud server;

[0012] Data block-level dynamics: Users process data locally and interact with the cloud server to update block tags, file tags, block tags, deduplication, and dynamic index tables;

[0013] Identity key update: The user sends the identity and the current system timestamp to the key generation center to obtain a new identity key And calculate the block tag update factor, and send the block tag update factor to the cloud server for authenticator update.

[0014] Preferably, the system initialization specifically includes the following steps:

[0015] ① Choose two multiplicative cyclic groups G1 and G2 of order q, and select a computable bilinear pairing e that satisfies e:G1×G1→G2, where q is a large prime number;

[0016] ② Select one generator of G1 as g, and select four hash functions, H1: {0,1} * →G1, H2: H3: {0,1} * →{0,1} * , H4: {0,1} * →G1, where

[0017] ③The key generation center selects secret parameters And calculate the system public key Y = g γ ∈G1;

[0018] ④ The output system public parameters are paras = {G1, G2, e, q, g, H1, H2, H3, H4, Y}, and the master private key msk = γ is secretly held by the key generation center.

[0019] Preferably, the identity key generation specifically includes the following steps:

[0020] ①Assume that the user's identity is id U ∈{0,1} * , change id U And the current system timestamp TS1∈{0,1} * Send to the key generation center to obtain the identity key;

[0021] ②When receiving {id U ,TS1}, the key generation center calculates the identity key dk U =H1(id U ||TS1) γ , the key generation center will use the user identity key dk U Sent to users via private channels;

[0022] ③Users calculate Verify DK U If the validity is passed, U accepts the identity private key dk UIf the request is not accepted, the user will resend the request to the key generation center;

[0023] ④User randomly selects secret parameters As part of the private key, and calculate your own public key U saves your own private key And publish your own public key W U .

[0024] Preferably, the first data file processing specifically includes the following steps:

[0025] ①The user will first file F 1 Divide into N 1 data blocks Each block has the same length, s|q|, where s is the number of partitions of each block, and each partition is |q| bits long; check N 1 Is there a duplicate block in the block? Remove the duplicates and then reorder them to form a number M 1 A collection of data blocks Λ 1 Each data block in Record it in the original file F 1 The corresponding block number set in The corresponding repetition numbers are Keep in original file F 1 The data blocks that appear for the first time in the . in At the same time M 1 ≤N 1 as well as

[0026] ② The user will file 1 Divide into two sets Λ 1 The set of data blocks that can be made public in Λ 1 The set of data blocks that need to be encrypted in the file Λ 1 Perform partial encryption and obtain the data block set as Where E is the symmetric encryption algorithm AES;

[0027] ③The user divides the encrypted block into s areas, namely in And calculate the block label as and file tags

[0028] ④ The user creates a deduplication and dynamic index table DDIT, which records all unique data blocks corresponding to the original file F 1 The index position in the data block for each unique Record a corresponding tuple in Represents a data block Corresponding to the original file F 1 The set of index numbers;

[0029] ⑤The user randomly selects s secret parameters Used to aggregate the data in the corresponding area of the block when the block tag is generated, and calculate s public values Used for subsequent audit evidence verification and subsequent calculation of block tags Get the complete set of block tags

[0030] ⑥The user sets the data set {id U ,TS1,C 1 ,Φ 1} and DDIT are uploaded to the cloud server together, and only DDIT is saved locally. When the cloud server uses DDIT to verify If it fails, the cloud server refuses to store the data and notifies the user. If it passes, the consistency between the data block and the tag is further verified: If true, the cloud server stores the corresponding data set; otherwise, the cloud server refuses to store and notifies the user.

[0031] Preferably, the audit generation and verification specifically includes the following steps:

[0032] ① The third-party auditor generates a random challenge Q = {j c ,θ j}, where j c ∈J c , J c For the integer set [1, M 1 ] Randomly select a set of c integers, It is from The user sends the random challenge Q to the cloud server.

[0033] ② The cloud server generates audit evidence P = {{μ k} 1≤k≤s ,σ}, where data evidence Label evidence The cloud server sends the audit evidence P to the third-party auditor;

[0034] ③ A third-party auditor confirms the integrity of the data on the cloud server by verifying whether the following formula is true: If the equation holds true, it proves that the data integrity on the cloud server has passed the test.

[0035] Preferably, the subsequent file upload process specifically includes the following steps:

[0036] ① The user will follow up with the file F 2 Divide into N 2 data blocks Each block has s regions, which are reordered after removing duplicates to form a number of M 2 A collection of data blocks Λ 2 Each data block in the original file F 2 The corresponding block number set in Right now in At the same time M 2 ≤N 2 as well as

[0037] ② The user will file 2 Divide into two sets Λ 2 The collection of data blocks disclosed in Λ 2 The set of data blocks that need to be encrypted in the file Λ 2 Perform partial encryption and obtain the data block set as

[0038] ③The user divides the encrypted block into s areas, namely in And calculate the block label as and file tags

[0039] ④Users use tf 2 as well as Retrieve DDIT,

[0040] 1) If a duplicate file tag is detected, it means that the subsequent file is completely duplicated with the user's previous file, and no further processing will be performed;

[0041] 2) tf 2 No repetition and for Indicates the subsequent file F 2 Any block in, j is the block number, If there is no duplicate in DDIT, insert M at the end of the table. 2 Row Record in

[0042] Representation Block Corresponding to the original subsequent file F 2 The set of index numbers;

[0043] 3)tf 2 No repetition There are some repetitions, which can be handled in two ways:

[0044] Then in Add the corresponding line For non-repeating blocks, insert at the end of the table Travel Notes

[0045] record Indicates the number of non-repeating blocks;

[0046] ⑤For step ④1), the user does not perform any subsequent processing; for step ④2), the user calculates The user will collect {C 2 ,Φ 2} and the updated DDIT are uploaded to the cloud server. After the cloud server verifies the consistency of the data block and the label, it stores the corresponding data set and updates the DDIT. Otherwise, the cloud server refuses to store and notifies the user. For step ④3), the user needs to calculate the authenticator for the non-repeated block and upload it together with the ciphertext set and the updated DDIT to the cloud server. After the cloud server verifies the consistency of the data block and the label, it stores the corresponding data set and updates the DDIT. Otherwise, the cloud server refuses to store and notifies U.

[0047] Preferably, the data block level dynamics specifically includes the following steps:

[0048] ①Data modification: Assume that the user modifies the content of a data block n to Let n be numbered x in the unique set Λ. If n belongs to a publicly available data block, no processing is done, which can be expressed as: If it is a data block that needs to be encrypted, encrypt it: Here, it is used to represent the partially encrypted file data blocks. For the publicly available data blocks, Directly equivalent to the original data block For the data blocks that need to be encrypted, With the original data block The relationship is Continue to divide into s areas, namely User computed old block tags and new block tags The user uses t to obtain the corresponding sequence number set X from DDITχ And the file tag tf, which is divided into two cases:

[0049] 1) If |X χ |=1, then calculate the file signature update factor and new file tags use as well as Replace tf and t, and the user calculates the block label update factor caused by the change of block content The user will Upload to the cloud server together, when the cloud server uses verify Correctness: If it fails, the cloud server will reject it and notify the user; if it passes, the cloud server will calculate Use simultaneously Replace c with Replace t with Replace tf;

[0050] 2) If |X χ |≠1, that is, the modified block forms a new block, namely |X ν |=1,υ is the modified Corresponding serial number, calculate the file signature update factor and new file tags use Replace tf and add a tuple to the end of the table And the set X corresponding to t χ Update to X χ \{χ}, user-calculated block label update factor The user will Upload to the cloud server together, when the cloud server uses verify Correctness: If it fails, the cloud server will reject it and notify the user; if it passes, the cloud server will calculate Store separately as well as use Replace tf and add a tuple to the end of the table And the set X corresponding to t χ Update to X χ \{χ};

[0051] ③ When inserting a data block, the block number is added to the end of the unique data block set. When deleting a data block, the block numbers of all blocks remain unchanged. The operation process is similar to that of updating a data block. It supports fine-grained updates, and users can modify the content of each area of each block. The update process is equivalent to data modification 1).

[0052] Preferably, the identity key update specifically includes the following steps:

[0053] User's identity ID U and the current system timestamp Sent to the key generation center to obtain the identity key. When the key generation center receives Afterwards, calculate the new identity key The key generation center will generate the new identity key It is sent to users through a private channel, and users calculate verify If the validity is passed, the user accepts the identity private key If the request is not accepted, the user will resend the request to the key generation center;

[0054] User computed block label update factor and will Sent to the cloud server, which updates the block label of the corresponding user file Indicates the block label update factor due to user identity key update.

[0055] Based on the above technical solution, the beneficial effects of the present invention are:

[0056] 1) Data integrity assurance: By issuing integrity challenges to the cloud server during the audit, it is possible to detect whether the cloud server actually holds a copy of the data block without having a local copy of the data block, thereby achieving data integrity protection;

[0057] 2) Hybrid plaintext and ciphertext auditing: Unlike traditional methods that fully encrypt entire files, this scheme allows encryption of certain data blocks containing private information. By combining encryption technology with certificateless signatures, this scheme enables hybrid plaintext and ciphertext auditing of multiple files.

[0058] 3) Data privacy protection: Message-locked encryption is used to encrypt private data blocks. Without proof of possession of the original data blocks, entities other than group users cannot infer the plaintext information.

[0059] 4) Dynamic block-level updates across file data: Through a designed deduplication and dynamic index table, combined with a certificateless signature and authenticator generation mechanism, users can dynamically operate on multiple file blocks, while minimizing the computational overhead on both the local client and the cloud server.

[0060] 5) Local cross-file block-level deduplication: This uses the hash value generated from the block content as a block-level deduplication tag, and then uses the block tag to calculate the file tag. This allows users to deduplicate multiple files locally at the block level. By recording the index location of unique blocks, users are prevented from uploading duplicate data one after another, reducing communication between users and cloud servers and cloud server storage overhead. This also does not affect users' subsequent maintenance of blocks with identical content but different indexes.

[0061] 6) Supports efficient user key updates: When the identity key expires or the user wants to actively update it, by sending the block label update factor to the cloud server, the cloud server can quickly implement block label conversion, that is, converting the block signature signed by the previous private key to the corresponding block signature under the new private key, and the local computing and communication overhead is a very small constant. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] Figure 1 The diagram is a schematic diagram of the interactions among entities in a cross-file block-level update deduplication and hybrid auditing method without certificate signature in an embodiment. DETAILED DESCRIPTION

[0063] The technical solutions in the embodiments of the present invention will be described clearly and completely below with reference to the accompanying drawings in the embodiments of the present invention.

[0064] This embodiment provides a cross-file block-level update deduplication and hybrid audit method without certificate signature. The method involves four entities. Figure 1 , as shown below:

[0065] User (U) needs to outsource multiple data files to a cloud server for storage. During the first file upload phase, a deduplication and dynamic index table needs to be created and maintained during the update phase.

[0066] Third-party auditor (TPA): Initiates audit challenges to the cloud server on behalf of user U during the audit phase and verifies the returned audit evidence;

[0067] Cloud Server (CS): This server has ample storage space and computing power. It is responsible for checking and storing uploaded data, responding to challenges initiated by the TPA, maintaining deduplication and dynamic index tables according to user requirements during the data update phase, and converting cloud storage labels during the key update phase.

[0068] Key Generation Center (KGC): Generates public keys and identity keys for users during system initialization, and generates new identity keys for users when their keys are updated.

[0069] The interaction process between the four entities in this embodiment is as follows: (1) U sends its identity identifier to KGC to obtain the identity key dk U , and choose the secret parameters As part of the private key, calculate your own public key pk U With the private key sk U ; (2) U for the first data document F 1 Processing includes dividing blocks, partial encryption, calculating block labels and file labels, creating a deduplication and dynamic index table DDIT, and uploading data to CS. CS checks the file signature and the legitimacy of the block labels before storing them. (3) In the subsequent file upload phase, U divides the non-duplicate data blocks into blocks, encrypts them, updates the deduplication and dynamic index table, calculates block labels and file labels, and uploads the data set to CS. For duplicate data blocks, a new sequence number set is inserted in the corresponding row of the block label in the table, and then the set corresponding to the non-duplicate blocks and the latest deduplication and dynamic index table are uploaded to the cloud server. (4) In the audit interaction phase, TPA initiates an audit challenge on behalf of user U and sends a random challenge Q to the cloud server CS. CS then calculates the corresponding integrity audit evidence P and returns it to TPA. TPA verifies the audit evidence P. (5) In the data dynamic phase, U processes locally and then interacts with CS to update the block labels, file labels, block labels and deduplication and dynamic index table. (6) In the key update phase, U sends the identity and the current system timestamp to KGC to obtain a new identity key. And calculate the authenticator update factor Send it to CS for authenticator update. The process is detailed as follows:

[0070] (1) System initialization: KGC generates system public parameters paras and master private key msk.

[0071] ① Choose two multiplicative cyclic groups G1 and G2 of order q, and select a computable bilinear pairing, e:G1×G1→G2, where q is a large prime number.

[0072] ② Select one generator of G1 as g, and select four hash functions, H1: {0,1} * →G1,H2: H3: {0,1} * →{0,1} * , H4: {0,1} * →G1, where

[0073] ③KGC selects secret parameters And calculate the system public key Y = g γ ∈G1;

[0074] ④ The public parameters of the output system are paras = {G1, G2, e, q, g, H1, H2, H3, H4, Y}, and msk = γ is held secretly by KGC.

[0075] (2) Identity key generation: User U interacts with KGC to obtain the identity private key and calculates its own private key and public key.

[0076] ①Assume that the identity of user U is id U ∈{0,1} * , change id U And the current system timestamp TS1∈{0,1} * Sent to KGC to obtain the identity key.

[0077] ②When receiving {id U ,TS1}, KGC calculates the identity key dk U =H1(id U ||TS1) γ KGC will use the user identity key dk U Sent to U via private channel.

[0078] ③U is calculated Verify DK U If the validity is passed, U accepts the identity private key dk U If the request is not accepted, U will resend the request to KGC.

[0079] ④U randomly selects secret parameters As part of your private key, and calculate the public key U saves your own private key And publish your own public key W U .

[0080] (3) First data file processing: User U processes the first data file F 1 Processing (superscript 1 indicates the first data file that needs to be outsourced by user U, followed by the subsequent uploaded file F 2 To make a distinction, for ease of understanding, F 1 The numbers involved will be marked in the upper right corner 1), including checking for duplicates, dividing blocks, encrypting, calculating block labels, block labels and file labels, uploading to CS, etc.

[0081] ① User U first copies the first file F 1 Divide into N 1data blocks Each block has the same length, s|q|, where s is the number of partitions of each block, and each partition is |q| bits long. Then check N 1 Is there a duplicate block in the block? Remove the duplicates and then reorder them to form a number M 1 A collection of data blocks Λ 1 Each data block in Record it in the original file F 1 The corresponding block number set in The corresponding repetition numbers are This is retained in the original file F 1 The data blocks that appear for the first time in the . in At the same time M 1 ≤N 1 as well as

[0082] ②U will file Λ 1 Divide into two sets Λ 1 The set of data blocks that can be made public in Λ 1 The set of data blocks that need to be encrypted in the file Λ 1 Perform partial encryption and obtain the data block set as E uses the popular symmetric encryption algorithm AES.

[0083] ③U divides the encrypted block into s areas, namely in And calculate the block label as and file tags When U downloads any block If the data is meaningful, it can be read directly. If it is meaningless, it can be decrypted using the decryption algorithm E to obtain the plain text. (This block is encrypted.) Due to the lack of a hash value calculated from the original plaintext, the original plaintext cannot be retrieved, thus protecting data privacy. Compared to existing methods that encrypt the entire file, this also reduces the overhead of encryption and decryption.

[0084] ④U creates a deduplication and dynamic index table DDIT (Deduplication and Dynamic Index Table), which records all unique data blocks corresponding to the original file F 1 The index position in the data block is unique. Record a corresponding tuple in Representation Block Corresponding to the original file F 1 For ease of understanding, here we take an original file F with 8 blocks. 1 As an example (the corresponding file label is tf 1 , assuming that the 1st block is repeated with the 3rd block, the 2nd block is repeated with the 4th and 5th block, the 6th block is repeated with the 7th block, and the 8th block is not repeated), give the corresponding relationship between the blocks before and after processing. Note that although the blocks are further divided into zones to reduce the number of data blocks, in order to reduce computing and communication overhead, the subsequent operations in this article still use the block level as the basic unit of data processing. In addition, DDIT is stored on the local end, and the user end can directly rely on this table to achieve file-level and block-level deduplication. There is no need for existing deduplication methods to require file tags and block tags to be uploaded to the cloud server, and the cloud server will perform deduplication judgment. In this way, user data is streamlined before uploading, avoiding users from uploading duplicate data to the CS and saving communication overhead. At the same time, relying on this table, this article allows users to perform dynamic maintenance operations on data, which will be described in subsequent steps. Note that the first column in Table 1 does not belong to the DDIT table. It is only presented here for clarity of description. The DDIT content only contains the following two columns.

[0085] Table 1

[0086]

[0087] ⑤U randomly selects s secret parameters And calculate s public values The block labels are then calculated Get the complete tag set That is, for N 1 The original file of blocks finally generates M 1 For files with high duplication, M 1 will be much smaller than N 1 ,At this stage, our scheme significantly improves the performance by reducing the number of data blocks and ,labels, while utilizing the DDIT designed in this paper to ensure ,block-level updates and data deduplication.

[0088] ⑥U will set {id U ,TS1,C 1 ,Φ 1} and DDIT are uploaded to the cloud server CS, and then only DDIT is saved locally. If it fails, CS refuses to store and notifies U. If it passes, it further verifies the consistency between the data block and the tag: If true, CS stores the corresponding data set. Otherwise, CS refuses to store and notifies U.

[0089] (4) Audit generation and verification: TPA generates a random challenge Q and sends it to CS. CS generates the corresponding audit evidence P and returns it to TPA. TPA verifies the legitimacy of P to determine the integrity of the data stored on CS.

[0090] ①TPA generates random challenge Q={j c ,θ j}. c ∈J c , J c For the integer set [1, M 1 ] Randomly select a set of c integers, It is from U sends the random challenge Q to CS.

[0091] ②CS generates audit evidence P={{μ k} 1≤k≤s ,σ}, where CS sends proof P to TPA.

[0092] ③TPA confirms the integrity of the data on the CS by verifying whether the following formula is true: If the equation holds, "TRUE" is output, proving that the data integrity on the CS has passed the test, otherwise "FALSE" is output. This application supports public auditing (ie, the audit verification process does not require the user's secret information).

[0093] (5) Subsequent file upload processing: User U processes subsequent document F 2 Here we assume that F 2 For subsequent documents that need to be uploaded, so that they can be uploaded together with the first document F 1 Make a distinction.

[0094] ①U first data file F 2 Divide into N 2 data blocks Each block has s regions. After removing duplicates, they are reordered to form a number of M 2 A collection of data blocks Λ 2 Each data block in the original file F 2 The corresponding block number set in Right now in At the same time M 2 ≤N 2 as well as

[0095] ②U will file Λ 2 Divide into two sets Λ 2 The set of data blocks that can be made public in Λ 2 The set of data blocks that need to be encrypted in the file Λ 2 Perform partial encryption and obtain the data block set as

[0096] ③U divides the encrypted block into s areas, namely in And calculate the block label as and file tags

[0097] ④U uses tf 2 as well as Retrieve DDIT,

[0098] 1) If a duplicate file tag is found, it means that the file is exactly the same as a previous file of the user, and no further processing is performed.

[0099] 2) tf 2 No repetition and for Indicates the subsequent file F 2 Any block in, j is the block number, If there is no duplicate in DDIT, insert M at the end of the table. 2 Row Record in Representation Block Corresponding to the original file F 2 For ease of understanding, we still use an original file F with 8 blocks. 1 As an example, suppose F 2 Contains four data blocks Assume that the first block is repeated with the fourth block, and the second block is repeated with the third block. Refer to Table 2, and the table is updated as follows:

[0100] Table 2

[0101]

[0102]

[0103] 3)tf 2 No repetition but There are some repetitions, which can be divided into two cases: for repeated blocks (assuming Then in Add the corresponding line Like this In addition to storing the original Also stored For non-repeating blocks, insert at the end of the table Row Record ( Indicates the number of non-repeated blocks). For ease of understanding, here we still use an original file with 8 blocks. As an example, suppose the following file Assume that only block 1 and block 4 are duplicates, and as well as

[0104] Refer to Table 3, and the table is updated as follows:

[0105] Table 3

[0106]

[0107] ⑤For ④1), U does not undergo subsequent processing; for ④2), U calculates U will set {C 2 ,Φ 2} and the updated DDIT are uploaded to CS. When CS verifies the consistency of the data block and the tag, it stores the corresponding data set and updates the DDIT. Otherwise, CS refuses to store and notifies U. For ④3), U needs to calculate the authenticator for the non-repeated block and upload it to CS together with the ciphertext set and the updated DDIT. When CS verifies the consistency of the data block and the tag, it stores the corresponding data set and updates the DDIT. Otherwise, CS refuses to store and notifies U. Since the tag generation part is highly similar to step (3), it will not be repeated here.

[0108] (6) Data block level dynamics: U sends a data update request req to CS, CS performs dynamic operations on the specified block and updates DDIT, while signing the newly calculated file. Return to U, U according to And the file signature tf previously stored locally 1 The check is performed. If the verification passes, the DDIT is updated. If not, the CS is asked to respond again. Because the solution supports block-level operations across files, the update here is not limited to the first file, so the 1 is not marked in the upper right corner of this part.

[0109] ① Data modification: Assume that U needs to modify the content of one of the data blocks n to (Assume that the sequence number of n in the unique set Λ is x.) If n belongs to a publicly available data block, no processing is performed, which is expressed as: If it is a data block that needs to be encrypted, encrypt it: Here, it is used to represent the partially encrypted file data blocks. For the publicly available data blocks, Directly equivalent to the original data block For the data blocks that need to be encrypted, With the original data block The relationship is Continue to divide into s areas, namely U calculates old block labels and new block tags U uses t to obtain the corresponding sequence number set X from DDIT χ And the file tag tf. The following is divided into two cases:

[0110] 1) If |X χ |=1, then calculate the update factor and new file tags use as well as Replace tf and t. Next, U calculates the block label update factor due to the change of block content Finally, U will dataset Upload to the cloud server CS together. When CS uses verify Correctness: If not, CS rejects and notifies U. If established, CS calculates Use simultaneously Replace c with Replace t with Replace tf.

[0111] 2) If |X χ |≠1, that is, the modified block forms a new block, namely |X ν |=1(υ is the modified Calculate the file block label update factor and new file tags use Replace tf and add a tuple to the end of the table And the set X corresponding to t χ Update to X χ \{χ}. Next, U calculates the block label update factor Finally, U will dataset Upload to CS together. When CS uses

[0112] verify Correctness: If not, CS rejects and notifies U. If established, CS calculates Store separately as well as use Replace tf and add a tuple to the end of the table And the set X corresponding to t χ Update to X χ \{χ}.

[0113] ② The data block insertion (note that only the block number is added to the end of the unique data block set) and data block deletion processes (all block numbers remain unchanged) are basically the same as the data update operation, so they are ignored here. In addition, this solution also supports fine-grained updates, that is, users can modify the content of each area of each block. This process is equivalent to the data modification in case 1).

[0114] (7) Identity key update: If user U's key expires or the identity key is exposed, U can help KGC to update the corresponding identity private key dk U , and calculate the identity private key update factor and will Sent to CS to update the block label.

[0115] Assume that the identifier is id U User U wants to update the identity key. U will use id U and the current system timestamp Sent to KGC to obtain the identity key. Afterwards, KGC calculates the new identity key KGC will use the new identity key Send it to U through a private channel. U calculates verify If the validity is passed, U accepts the identity private key If it fails, U will resend the request to KGC. U calculates the block label update factor. and will Send to CS, CS updates the signature here It represents the block label update factor caused by the user identity key update, which is different from the block label update factor caused by the change of block content. That is, during the key update phase, the computation and communication overhead on the user's local side is minimal and constant, while the time-consuming block label conversion operation is completed by the CS. Therefore, this solution is suitable for performance-constrained local terminals.

[0116] The above description is merely a preferred implementation of the certificateless, cross-file block-level update deduplication and hybrid auditing method disclosed herein and is not intended to limit the scope of protection of the embodiments of this specification. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of this specification shall be included within the scope of protection of the embodiments of this specification.

Claims

1. A cross-file block-level update deduplication and hybrid auditing method without certificate signature, characterized by: The steps include: System initialization: The key generation center generates the system public parameters paras and the master private key msk; Identity key generation: The user interacts with the key generation center to obtain the identity private key dk U , and choose the secret parameter ω U As part of the private key, calculate the public key pk U With the private key sk U ; First data file processing: User processes the first file F 1 Processing includes checking for duplication, dividing blocks, encryption, calculating block labels, block labels and file labels, and creating a deduplication and dynamic index table. The deduplication and dynamic index table stores the block label of each non-duplicate data block, the file label of the file where the data block is located, and the index set of the data block in the file where the data block is located. The cloud server checks the file signature and the legitimacy of the block label and then stores the data set and the deduplication and dynamic index table. The local computer only stores the deduplication and dynamic index table. Audit generation and verification: A third-party auditor initiates an audit challenge on behalf of the user and sends a random challenge to the cloud server. The cloud server calculates the corresponding integrity audit evidence and returns it to the third-party auditor, who then verifies the audit evidence. Subsequent file upload processing: User is the subsequent file F 2 The non-duplicate data blocks in the data are divided into blocks, encrypted, and the deduplication and dynamic index tables are updated, the block labels and file labels are calculated, and the data set is uploaded to the cloud server; a new sequence number set is inserted in the row corresponding to the block label in the deduplication and dynamic index table for the duplicate data blocks, and the set corresponding to the non-duplicate blocks and the updated deduplication and dynamic index table are uploaded to the cloud server; Data block-level dynamics: Users process data locally and interact with the cloud server to update block tags, file tags, block tags, deduplication, and dynamic index tables; Identity key update: The user sends the identity and the current system timestamp to the key generation center to obtain a new identity key And calculate the block tag update factor, and send the block tag update factor to the cloud server for authenticator update.

2. The cross-file block-level update deduplication and hybrid auditing method without certificate signature according to claim 1 is characterized in that: The system initialization specifically includes the following steps: ① Choose two multiplicative cyclic groups G1 and G2 of order q, and select a computable bilinear pairing e that satisfies e:G1×G1→G2, where q is a large prime number; ② Select one generator of G1 as g, and select four hash functions, H1: {0,1} * →G1, H2: H3: {0,1} * →{0,1} * , H4: {0,1} * →G1, where ③The key generation center selects secret parameters And calculate the system public key Y = g γ ∈G1; ④ The output system public parameters are paras = {G1, G2, e, q, g, H1, H2, H3, H4, Y}, and the master private key msk = γ is secretly held by the key generation center.

3. The cross-file block-level update deduplication and hybrid auditing method without certificate signature according to claim 1 is characterized in that: The identity key generation specifically includes the following steps: ①Assume that the user's identity is id U ∈{0,1} * , change id U And the current system timestamp TS1∈{0,1} * Send to the key generation center to obtain the identity key; ②When receiving {id U ,TS1}, the key generation center calculates the identity key dk U =H1(id U ||TS1) γ , the key generation center will use the user identity key dk U Sent to users via private channels; ③Users calculate Verify DK U If the validity is passed, U accepts the identity private key dk U If the request is not accepted, the user will resend the request to the key generation center; ④User randomly selects secret parameters As part of the private key, and calculate your own public key U saves your own private key And publish your own public key W U .

4. The cross-file block-level update deduplication and hybrid auditing method without certificate signature according to claim 1 is characterized in that: The first data file processing specifically includes the following steps: ①The user will first file F 1 Divide into N 1 data blocks Each block has the same length, s|q|, where s is the number of partitions of each block, and each partition is |q| bits long; check N 1 Is there a duplicate block in the block? Remove the duplicates and then reorder them to form a number M 1 A collection of data blocks Λ 1 Each data block in Record it in the original file F 1 The corresponding block number set in The corresponding repetition numbers are Keep in original file F 1 The data blocks that appear for the first time in the . in At the same time M 1 ≤N 1 as well as ② The user will file 1 Divide into two sets Λ 1 The set of data blocks that can be made public in Λ 1 The set of data blocks that need to be encrypted in the file Λ 1 Perform partial encryption and obtain the data block set as Where E is the symmetric encryption algorithm AES; ③The user divides the encrypted block into s areas, namely in And calculate the block label as and file tags ④ The user creates a deduplication and dynamic index table DDIT, which records all unique data blocks corresponding to the original file F 1 The index position in the data block for each unique Record a corresponding tuple in Represents a data block Corresponding to the original file F 1 The set of index numbers; ⑤The user randomly selects s secret parameters Used to aggregate the data in the corresponding area of the block when the block tag is generated, and calculate s public values Used for subsequent audit evidence verification and subsequent calculation of block tags Get the complete set of block tags ⑥The user sets the data set {id U ,TS1,C 1 ,Φ 1 } and DDIT are uploaded to the cloud server together, and only DDIT is saved locally. When the cloud server uses DDIT to verify If it fails, the cloud server refuses to store the data and notifies the user. If it passes, the consistency between the data block and the tag is further verified: If true, the cloud server stores the corresponding data set; otherwise, the cloud server refuses to store and notifies the user.

5. The cross-file block-level update deduplication and hybrid auditing method without certificate signature according to claim 1 is characterized in that: The audit generation and verification specifically includes the following steps: ① The third-party auditor generates a random challenge Q = {j c ,θ j }, where j c ∈J c , J c For the integer set [1, M 1 ] Randomly select a set of c integers, It is from The user sends the random challenge Q to the cloud server. ② The cloud server generates audit evidence P = {{μ k } 1≤k≤s ,σ}, where data evidence Label evidence The cloud server sends the audit evidence P to the third-party auditor; ③ A third-party auditor confirms the integrity of the data on the cloud server by verifying whether the following formula is true: If the equation holds true, it proves that the data integrity on the cloud server has passed the test.

6. The cross-file block-level update deduplication and hybrid auditing method without certificate signature according to claim 1 is characterized in that: The subsequent file upload process specifically includes the following steps: ① The user will follow up with the file F 2 Divide into N 2 data blocks Each block has s regions, which are reordered after removing duplicates to form a number of M 2 A collection of data blocks Λ 2 Each data block in the original file F 2 The corresponding block number set in Right now in At the same time M 2 ≤N 2 as well as ② The user will file 2 Divide into two sets Λ 2 The collection of data blocks disclosed in Λ 2 The set of data blocks that need to be encrypted in the file Λ 2 Perform partial encryption and obtain the data block set as ③The user divides the encrypted block into s areas, namely in And calculate the block label as and file tags ④Users use tf 2 as well as Retrieve DDIT, 1) If a duplicate file tag is found, it means that the subsequent file is a complete duplicate of the user's previous file, and no further processing will be performed; 2) tf 2 No repetition and for Indicates the subsequent file F 2 Any block in, j is the block number, If there is no duplicate in DDIT, insert M at the end of the table. 2 Row Record in Representation Block Corresponding to the original subsequent file F 2 The set of index numbers; 3)tf 2 No repetition There are some repetitions, which can be handled in two ways: Then in Add the corresponding line For non-repeating blocks, insert at the end of the table Row Record Indicates the number of non-repeating blocks; ⑤For step ④1), the user does not perform any subsequent processing; for step ④2), the user calculates The user will collect {C 2 ,Φ 2 } and the updated DDIT are uploaded to the cloud server. After the cloud server verifies the consistency of the data block and the label, it stores the corresponding data set and updates the DDIT. Otherwise, the cloud server refuses to store and notifies the user. For step ④3), the user needs to calculate the authenticator for the non-repeated block and upload it together with the ciphertext set and the updated DDIT to the cloud server. After the cloud server verifies the consistency of the data block and the label, it stores the corresponding data set and updates the DDIT. Otherwise, the cloud server refuses to store and notifies U.

7. The cross-file block-level update deduplication and hybrid auditing method without certificate signature according to claim 1 is characterized in that: The data block level dynamics specifically include the following steps: ①Data modification: Assume that the user modifies the content of a data block n to Let n be numbered x in the unique set Λ. If n belongs to a publicly available data block, no processing is done, which can be expressed as: If it is a data block that needs to be encrypted, encrypt it: Here, it is used to represent the partially encrypted file data blocks. For the publicly available data blocks, Directly equivalent to the original data block For the data blocks that need to be encrypted, With the original data block The relationship is Continue to divide into s areas, namely User computed old block tags and new block tags The user uses t to obtain the corresponding sequence number set X from DDIT χ And the file tag tf, which is divided into two cases: 1) If |X χ |=1, then calculate the file signature update factor and new file tags use as well as Replace tf and t, and the user calculates the block label update factor caused by the change of block content The user will Upload to the cloud server together, when the cloud server uses verify Correctness: If it fails, the cloud server rejects it and notifies the user; If passed, the cloud server calculates Use simultaneously Replace c with Replace t with Replace tf; 2) If |X χ |≠1, that is, the modified block forms a new block, namely |X ν |=1,υ is the modified Corresponding serial number, calculate the file signature update factor and new file tags use Replace tf and add a tuple to the end of the table And the set X corresponding to t χ Update to X χ \{χ}, user-calculated block label update factor The user will Upload to the cloud server together, when the cloud server uses verify Correctness: If it fails, the cloud server will reject it and notify the user; if it passes, the cloud server will calculate Store separately as well as use Replace tf and add a tuple to the end of the table And the set X corresponding to t χ Update to X χ \{χ}; ② When inserting a data block, the block number is added to the end of the unique data block set. When a data block is deleted, the block numbers of all blocks remain unchanged. The operation process is similar to that of updating a data block. It supports fine-grained updates, and users can modify the content of each area of each block. The update process is equivalent to data modification1).

8. The cross-file block-level update deduplication and hybrid auditing method without certificate signature according to claim 1 is characterized in that: The identity key update specifically includes the following steps: User's identity ID U and the current system timestamp Sent to the key generation center to obtain the identity key. When the key generation center receives Afterwards, calculate the new identity key The key generation center will generate the new identity key It is sent to users through a private channel, and users calculate verify If the validity is passed, the user accepts the identity private key If the request is not accepted, the user will resend the request to the key generation center; User computed block label update factor and will Sent to the cloud server, which updates the block label of the corresponding user file Indicates the block label update factor due to user identity key update.

Citation Information

Patent Citations

  • Method and system for supporting dense data deduplication and integrity verification

    CN109286490A

  • Cloud data sharing system and auditing system based on certificateless encryption

    CN115643098A

  • Lightweight ciphertext integrity auditing method and system capable of removing duplication

    CN116015630A

  • Communication of emergency medical data over a vulnerable system

    US20130024382A1

Cited By

  • Cross-cloud data deduplication and integrity auditing method and system supporting threshold signature

    CN121173562A

  • Cross-cloud data deduplication and integrity auditing method and system supporting threshold signature

    CN121173562B