A method for improving the security of a blockchain-based trusted outsourcing cloud audit
By introducing blockchain technology into the cloud audit system and adopting technologies such as PoS consensus mechanism and VRF, a trusted outsourced cloud audit solution was designed. This solution addresses the security and fairness issues of the cloud audit system, achieves an efficient and transparent audit process, and enhances user trust and data security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-29
- Publication Date
- 2026-03-27
AI Technical Summary
Existing cloud audit systems suffer from security, scalability, and fairness issues, and the untrustworthiness of third-party audit institutions affects user data security and the accuracy of audit results.
By combining cloud auditing with blockchain and employing technologies such as PoS consensus mechanism, VRF, and SMPC, a blockchain-based trusted outsourced cloud auditing solution is designed. Through smart contracts, automated auditing and reward mechanisms are implemented to ensure the randomness and impartiality of auditors.
It improves the security and transparency of cloud auditing, prevents malicious attacks, enhances user trust, reduces auditing costs, and ensures the authenticity and integrity of data.
Smart Images

Figure CN116707953B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, and in particular to a method for improving security of trusted outsourcing cloud audit based on blockchain. BACKGROUND
[0002] With the wide use of cloud computing and cloud storage, more and more data owners are willing to outsource their massive data to remote cloud servers, thereby effectively avoiding the heavy burden of storing and managing massive data on local physical storage media. Although cloud storage has great advantages, due to the separation of data ownership and management, cloud storage inevitably faces some serious security challenges.
[0003] In traditional cloud audit schemes, the cloud service provider generally provides relevant cloud services, and the user generates operation logs or uploads local files to the cloud server for storage when using the cloud services, and serves as a voucher for future audit work. However, in fact, the authenticity and reliability of these data are questionable, that is, the cloud service provider is not completely trustworthy, therefore, a trusted third-party audit institution needs to be introduced, but in real life, it is difficult to establish a completely fair and just third-party audit institution, and the security of user data and the accuracy of audit results will be affected.
[0004] The concept of third-party auditors was first proposed by Wang et al., in their scheme, the third-party auditors can represent the user to verify the data, and help the user to save the calculation and storage overhead caused by the audit. However, in this scheme, the third-party auditors are assumed to be a completely trusted third party, so this scheme cannot deal with the situation that the third-party auditors are not trusted. In the subsequent research of Wang et al., they adopted a random masking technology on the basis of the previous scheme, which can ensure that the third-party auditors cannot infer the user's original data from the information required for the audit. However, although the third-party auditors have been widely used in subsequent audit schemes, they still have some shortcomings that cannot be ignored. SUMMARY
[0005] The present application provides a method for improving the security of trusted outsourcing cloud audit based on blockchain, which aims to solve the problems of security, scalability and fairness existing in the existing cloud audit system based on blockchain. The present application realizes an efficient blockchain consensus mechanism, ensures the rights and interests and randomness of participants, thereby improving the overall performance and credibility of the blockchain system, as described in detail below:
[0006] A method for improving the security of trusted outsourcing cloud audit based on blockchain, the method comprises:
[0007] The cloud audit is combined with the block chain, a verifiable random function, a secure multi-party computing technology, a security method of trusted outsourcing cloud audit based on the block chain is provided; anyone can access and verify the data stored therein, and an automatic audit and reward mechanism is realized through the smart contract technology;
[0008] A unbiased random selection algorithm for auditors is provided by using the PoS consensus mechanism, the cryptography tool VRF capable of generating a verifiable random number, the secure multi-party computing and the encrypted random number seed technology, so as to ensure the randomness of selecting independent auditors from the block chain.
[0009] The unbiased random selection algorithm for auditors includes seed generation and block person random selection.
[0010] Further, the seed generation is:
[0011] 1) Each participant generates his own private key sk i and public key pk i , and broadcasts the public key pk i to other nodes;
[0012] 2) Each participant generates a random value r using a consensus algorithm as his own private input input i ;
[0013] 3) Each participant signs the private input using his own private key signature i , and sends the signature to other nodes;
[0014] 4) After receiving the signatures of other nodes, each participant verifies the legality of the signatures, sorts all legal signatures according to certain rules, and broadcasts the sorted results to other nodes;
[0015] 5) All participants jointly verify the sorted signature list, and convert it into a public random number using the SMPC algorithm as part of the seed.
[0016] The block person random selection is:
[0017] 1) At the beginning of each time period, all participants will be divided into several groups, each group containing one block person and multiple backup block persons, the backup block persons need to calculate their shares in the block chain through the FTS mechanism, and send them together with their identity information to the network;
[0018] 2) Before the election of the block, the VRF generator generates a random number, which can only be verified by the owner of the VRF generator, and others cannot predict, calculates a signature and a proof to verify the correctness of the signature, and broadcasts them to the whole network together with the identity information of each candidate block;
[0019] 3) At the beginning of the next time period, each node verifies the VRF signature and proof to determine which candidate block has the qualification of block, and if the verification is successful, the candidate block can become the next block;
[0020] 4) Once the next block is determined, the node will broadcast a proposal containing specific information to the network, including the transaction to be packaged and the hash value of the last block.
[0021] The beneficial effects of the technical scheme provided by the application are:
[0022] 1、The application uses the decentralized characteristics of blockchain technology to propose a trusted outsourcing audit scheme based on blockchain; the scheme protects the security and integrity of the audit data, allows anyone to access and verify the data stored therein, realizes automatic audit and reward mechanism through smart contract and other technologies, and improves the efficiency and accuracy of the audit;
[0023] 2、The application adopts PoS (Proof of Stake) consensus mechanism, a cryptographic tool VRF (Verifiable Random Function) that can generate verifiable random numbers, secure multi-party computation, encrypted random number seed and other technologies, and proposes an unbiased random selection algorithm for auditors to ensure the randomness of selecting independent auditors from the blockchain and avoid possible unfair or collusion behavior.
[0024] These technologies guarantee the rights and privacy of honest participants, prevent malicious behavior and attacks, and have undergone extensive security analysis and verification, the application limits the ability of attackers through appropriate randomness and voting mechanism, thereby ensuring the security of distributed consensus, and solves the problem of fork through the rule of selecting the longest chain, avoiding fork attack and double spending.
[0025] The proposal of the cloud audit committee has important significance for the development of blockchain technology and the application of cloud audit, enhances the trust and confidence of enterprises and cloud users, and promotes the wide application of blockchain technology. Through the blockchain technology, the data security, the transparency of the audit process, the support of real-time audit, the improvement of the audit credibility and the reduction of the audit cost are improved, which provides strong guarantee for the credibility and reliability of cloud computing services. BRIEF DESCRIPTION OF DRAWINGS
[0026] Figure 1To cloud audit scheme model;
[0027] Figure 2 To generate a flowchart for the audit committee on the blockchain;
[0028] Figure 3 To randomly select an auditor algorithm. DETAILED DESCRIPTION
[0029] In order to make the purpose, technical scheme and advantages of the present application more clear, the embodiments of the present application are further described in detail below.
[0030] In order to effectively supervise the auditors, some audit schemes design for users to audit the behavior of auditors, for example: after each verification, the auditor is required to record the data used in the audit process, so that the user can verify the effectiveness of the behavior of the auditor. The scheme proposed by Armknecht et al. requires the behavior of the auditor to be verified, for example: record the audit process.
[0031] The Ouroboros protocol is a provably secure proof-of-stake protocol, which is the protocol used by the Cardano blockchain. The core technology of this protocol is the Proof of Stake (PoS) consensus mechanism, which is different from the Proof of Work (PoW) mechanism used by Bitcoin. In the PoS mechanism, the nodes that verify blockchain transactions participate by holding a certain amount of tokens, rather than obtaining rewards by solving complex mathematical problems as in the PoW mechanism. The Ouroboros protocol is an efficient, secure and reliable consensus protocol that provides a strong foundation for the Cardano blockchain.
[0032] In order to overcome the shortcomings of the prior art, the main purpose of the embodiments of the present application is to solve the problem of the credibility of the third party in the cloud audit process, to combine cloud audit with blockchain, to use verifiable random function (VRF), secure multi-party computation (SMPC) and other technologies, to propose a security method for trusted outsourcing cloud audit based on blockchain, greatly improving the credibility and quality of cloud services, while protecting the privacy and security of users.
[0033] The rapid development of cloud computing technology and cloud storage technology brings convenience to a large number of users, but since the data is transferred from the local server to the cloud storage platform, the user loses direct control over the data, which can bring many security problems. Because the trust between the user and the cloud service provider is limited, both parties may violate the contract for their own interests, especially when conflicts arise between the two parties, the existence of a third-party audit institution is necessary. However, the third-party audit institution is not completely trustworthy, and they may also make false audit results for their own interests.
[0034] Blockchain technology can solve these problems because it provides a decentralized, verifiable, and tamper-proof way of storing data. By recording the audit data of cloud service providers on the blockchain, the authenticity and integrity of the data can be ensured. At the same time, since the blockchain is decentralized, anyone can access and verify the data stored in it, making the entire audit process more transparent and trustworthy.
[0035] The provable security of the embodiments of the present invention is based on the following techniques:
[0036] Firstly, time is divided into multiple periods, each containing multiple rounds. Each period has different committee members and block nodes to reduce the chances of attackers and increase the security of the system. Secondly, an audit committee election mechanism is used to select auditors, and the audit committee members are elected based on the amount of rights they hold and randomness to ensure that the selected committee has sufficient rights and diversity to prevent potential attacks.
[0037] The embodiments of the present invention also provide formal security proofs, which use cryptography and mathematical methods to prove that the protocol is secure under a specific security model. These proofs ensure that the system is secure against attackers with different attack capabilities. Finally, the embodiments of the present invention use PoS as a consensus algorithm, VRF random function, Follow-the-Satoshi algorithm, and secure multi-party computation to ensure the randomness, transparency, and credibility of cloud auditor selection, reducing the trust barriers between cloud service providers and customers.
[0038] The specific techniques applied are as follows:
[0039] (1) PoS (Proof-of-Stake) mechanism: PoS mechanism is a consensus mechanism based on proof of stake, participants can participate in the consensus process of the network by holding a certain amount of tokens, and have the opportunity to be selected as validators to obtain new token rewards. This mechanism reduces the possibility of malicious participants participating in consensus, as attackers need to control a large number of tokens to attack the system.
[0040] (2) Follow-the-Satoshi algorithm: used to elect block producers in the blockchain. The basic idea of this algorithm is that when electing block producers, accounts that already hold a certain amount of tokens are given priority, as these accounts have higher reputation and contribution in the blockchain network. Specifically, the FTS algorithm resists decentralization attacks, in which attackers try to control the block generation process by controlling a sufficient number of ADA. By using token holdings as a basis for selecting block producers, the FTS algorithm makes it difficult for attackers to control the block generation process by requiring them to control a large portion of the tokens. This increases the cost and difficulty of attacks.
[0041] (3) VRF (Verifiable Random Function): VRF is a verifiable random function used to elect random block producers. In blockchain, it prevents malicious participants from obtaining undue benefits by manipulating random numbers. At the same time, the characteristics of VRF ensure that the generated random numbers are unpredictable and verifiable, providing a trusted foundation for the normal operation of the protocol.
[0042] (4) SMPC (Secure Multiparty Computation): SMPC is a secure computing process used to perform calculations among participants in the blockchain network, ensuring the correctness and integrity of the results and protecting the privacy of participants from leakage. Through SMPC, participants can jointly audit and verify, ensuring the privacy protection and security of the cloud audit process.
[0043] (5) Iteration of consensus algorithm: The consensus algorithm organizes participants through iterations of time periods, each containing block producers and backup block producers. The election of the block producer set is completed through the voting and random election of participants in the previous time period. Through the iteration of the consensus algorithm, the stability and security of the system are ensured.
[0044] The application of these security technologies helps to improve the security of the blockchain system, protect privacy and prevent malicious attacks. They ensure the fairness of the audit, reduce the risk of centralization, and provide users with reliable and secure audit services, enhancing the security and credibility of the entire system.
[0045] The unbiased random selection algorithm based on blockchain consists of two parts: the generation of seed (speed) and the random selection of block producers (auditors).
[0046] Multiple block producers use SMPC technology to generate seeds, where each block producer only knows its own private input, and the calculation result can only be obtained by all block producers together, so as to ensure the security and privacy of the calculation process. The seed needs to be generated before each block pool is formed and used as one of the inputs of the VRF random function calculation, so as to ensure the randomness and unpredictability of the election of block producers in the next block pool. The generation of the seed is a key step in the random selection of block producers, which directly affects which block candidates in the blockchain will be eligible to participate in the production of blocks.
[0047] The seed generation process mainly includes the following steps:
[0048] 1) Each participant generates its own private key sk iand public key pk i and public key pk i to other nodes;
[0049] 2) Each participant uses a consensus algorithm to generate a random value r as their private input input i ;
[0050] 3) Each participant uses their private key to sign the private input signature i and sends the signature to other nodes;
[0051] 4) After receiving the signatures from other nodes, each participant verifies the legitimacy of the signatures, sorts all legitimate signatures according to certain rules, and broadcasts the sorted results to other nodes;
[0052] 5) All participants jointly verify the sorted signature list and use the SMPC algorithm to convert it into a public random number as part of the seed.
[0053] Third-party auditors are composed of block producers of the blockchain, who are responsible for cloud auditing and verifying transactions and states of the blockchain. The generation of block producers is based on random selection, and their participation can improve the security and credibility of the blockchain. FTS and VRF mechanisms are two very important components, FTS is used to calculate the stake of each candidate block producer in the blockchain, which helps to ensure that the selection of block producers is fair, and VRF is used to select candidate block producers and ensure that the selection of each candidate block producer is random.
[0054] The random selection process of block producers includes the following main steps:
[0055] 1) At the beginning of each time period, all participants will be divided into several groups, each group containing one block producer (auditor) and multiple candidate block producers (candidates). These candidate block producers need to calculate their stake in the blockchain through the FTS mechanism and send it together with their identity information to the network.
[0056] 2) Before the election of block producers, the VRF generator generates a random number, which can only be verified by the owner of the VRF generator, and cannot be predicted by others. Calculate the random number and the identity information of each candidate block producer to generate a signature and a proof, which can be used to verify the correctness of the signature, and broadcast them to the entire network.
[0057] 3) At the beginning of the next time period, each node verifies the VRF signature and proof to determine which candidate block producers are eligible to produce a block. If the verification is successful, the candidate block producer can become the next block producer.
[0058] 4) Once the next block producer is determined, the node will broadcast a proposal containing specific information to the network, including the transactions to be packaged and the hash value of the previous block.
[0059] Through this secure and unbiased random selection algorithm scheme, it ensures that the selection process of block producers in the blockchain system is fair, random and secure. This scheme improves the security and credibility of the blockchain and reduces the possibility of potential attacks. At the same time, by using technologies such as SMPC, FTS algorithm and VRF mechanism, the privacy and data security of participants are protected. Such a secure scheme provides a solid foundation for the reliable operation and trusted audit of the blockchain.
[0060] There are mainly 3 entities in this scheme:
[0061] 1. Cloud user (CS): Cloud users can be individuals, enterprises, organizations, etc. with a relatively large amount of data to store and need to ensure data security. Cloud users may upload their data to cloud servers for storage due to limited computing and storage resources, or to save storage and management costs, etc. and require to know whether their data is still secure and complete at regular intervals.
[0062] 2. Cloud service provider (CSP): Cloud service providers are enterprises or organizations that provide cloud computing services. They can provide various types of cloud computing services to users, providing virtualized resources to users to provide powerful computing power and huge storage space.
[0063] 3. Audit Committee (AS): The members of the audit committee are block producers selected on the blockchain network according to certain rules and standards, and each block producer has equal power. It can accept audit information broadcast in the network and then choose whether to participate in the audit task.
[0064] Next, the specific execution process of the cloud audit scheme is described in detail. This scheme includes the following five stages:
[0065] (1) Initialization: In this stage, the user will make preliminary preparations for uploading data, including selecting a series of computing parameters and generating user keys, etc.
[0066] (2) Data storage: The user pre-processes the data to be uploaded, including data chunking, calculating data tags, and auditing auxiliary information, and then uploads the data to the cloud storage server.
[0067] (3) Data auditing: The auditing committee selects a challenge value and initiates a challenge to the cloud storage server.
[0068] (4) Data possession proof: After receiving the challenge, the cloud storage server calculates the corresponding data possession proof and provides it to the auditing committee.
[0069] (5) Data verification: Multiple auditors in the auditing committee independently verify the data and obtain verification results, and vote through the smart contract to determine the final verification result.
[0070] Since the smart contract is deployed on the blockchain, the blockchain's tamper-proof and transparent data features ensure that the smart contract cannot be modified once it is successfully deployed, ensuring the reliability of the audit. The consensus algorithm of the blockchain ensures the consistency and immutability of the audit results. Multiple nodes reach a consensus on the audit results through the consensus mechanism, preventing single-point failures and potential tampering risks. The honesty of the cloud auditors in the auditing committee is constrained by the Nash equilibrium principle in game theory, which ensures that they will not intentionally tamper with the data. Although the specific game theory content is not within the scope of this invention, it does not affect the novelty and creativity level of this solution. If the data in the cloud service provider is found to be damaged, the user is notified of the audit results so that the user can take corresponding measures subsequently. Through these security measures, this solution ensures the credibility and data security of cloud auditing, providing a secure and verifiable cloud auditing solution.
[0071] References
[0072] [1] Wang, Cong, et al. "Privacy-preserving public auditing for secure cloud storage." IEEE transactions on computers 62.2 (2011): 362-375.
[0073] [2] Zhang, Yuan, et al. "SCLPV: Secure certificateless public verification for cloud-based cyber-physical-social systems against malicious auditors." IEEE Transactions on Computational Social Systems 2.4 (2015): 159-170.
[0074] [3] Zhang, Yuan, et al. "Cryptographic public verification of data integrity for cloud storage systems." IEEE Cloud Computing 3.5 (2016): 44-52.
[0075] [4] Armknecht, Frederik, et al. "Outsourced proofs of retrievability." Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security. 2014.
[0076] [5] ZHOU H, OUYANG X, REN Z, et al. A Blockchain based Witness Model for
[0077] Trustworthy Cloud Service Level Agreement Enforcement [C / OL] / / IEEE INFOCOM 2019-IEEE Conference on Computer Communications. Paris, France: IEEE, 2019: 1567-1575 [2022-04-02].
[0078] Those skilled in the art can understand that the drawings are only schematic diagrams of a preferred embodiment, and the above-mentioned embodiment numbers of the application are only for description, not representing the advantages and disadvantages of the embodiments.
[0079] The above merely describes preferred embodiments of the present application and is not used to limit the present application, and any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A method for improving the security of a blockchain-based trusted outsourcing cloud audit, characterized in that, The method comprises: Combining cloud audit with blockchain, using verifiable random function and secure multi-party computation technology, a security method of trusted outsourcing cloud audit based on blockchain is proposed; anyone can access and verify the data stored therein, and an automatic audit and reward mechanism is realized through smart contract technology; A random selection algorithm for auditors is proposed to ensure the randomness of selecting independent auditors from the blockchain by using PoS consensus mechanism, cryptography tool VRF that can generate verifiable random numbers, secure multi-party computation and encrypted random seed technology; The random selection algorithm for auditors comprises seed generation and block person random selection; The seed generation comprises: 1) Each participant generates its own private key and public key and broadcasts the public key to the other nodes; 2) Each participant generates a random value using a consensus algorithm , as its private input ; 3) Each participant signs the private input using their own private key and sends the signature to the others Node; 4) After each participant receives the signature of other nodes, the legality of the signature is verified, all legal signatures are sorted according to certain rules, and the sorted result is broadcast to other nodes; 5) All participants jointly verify the sorted signature list, and convert it into a public random number as part of the seed using SMPC algorithm; The block person random selection comprises: 1) At the beginning of each time period, all participants will be divided into several groups, each group containing one block and multiple backup blocks, the backup blocks need to calculate their shares in the blockchain through FTS mechanism, and send them together with their identity information to the network; 2) Before the election of block, the VRF generator generates a random number, which can only be verified by the owner of the VRF generator, and others cannot predict, calculates the random number and the identity information of each backup block, generates a signature and a proof, and broadcasts them to the whole network; 3) At the beginning of the next time period, each node will verify the VRF signature and proof to determine which backup block has the qualification of block, if the verification is successful, the backup block can become the next block; 4) Once the next block is determined, the node will broadcast a proposal containing specific information to the network, including the transactions to be packaged and the hash value of the last block.
Citation Information
Patent Citations
Blockchain key management method, multi-person common signature method and electronic device
CN111639361A