A cloud storage data integrity auditing method based on the national cryptographic standard SM9

CN117220893BActive Publication Date: 2026-08-14FUJIAN NORMAL UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-10-20
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

遗憾的是目前典型的标识基云存储数据完整性审计方案大都依赖国外密码算法,相关设计缺乏自主可控性

Benefits of technology

[0036]本发明核心算法为国密SM9数字签名算法,属于标识密码算法,在保证自主可控性的同时省去了复杂的证书管理问题;同时通过增加少量云端存储代价大幅降低块标签生成过程中的指数运算次数,用户端标签生成过程更加简洁高效。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117220893B_ABST
    Figure CN117220893B_ABST
Patent Text Reader

Abstract

This invention proposes an efficient cloud storage data integrity auditing method based on the national cryptographic standard SM9, comprising the following steps: Step A: According to security parameters, the Key Generation Center (KGC) runs the system initialization algorithm to generate public system parameters; Step B: The Key Generation Center (KGC) executes the key generation algorithm of the national cryptographic standard SM9, sets the user identity as the public key, and extracts the user's private key based on it; Step C: The user divides the file into blocks and generates file tags and data block tags, then sends the divided file, file tags, and data block tags to the cloud service provider (CSP); Step D: The third-party auditor (TPA) constructs a random challenge and sends it to the cloud service provider (CSP); Step E: The cloud service provider (CSP) calculates evidence based on the challenge and returns it to the third-party auditor (TPA); Step F: The third-party auditor (TPA) audits the file integrity. This invention eliminates the complex certificate management issues, making the user-side tag generation process simpler and more efficient.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security storage technology in cloud computing, and in particular to a cloud storage data integrity auditing method based on the national cryptographic standard SM9. Background Technology

[0002] With the rapid development of IoT technology, more and more data is being collected and processed through various devices. However, storing this data directly locally is costly and inconvenient for users. To effectively save costs and increase access flexibility, users often choose to outsource massive amounts of data to cloud servers, retaining no copies locally. Clearly, while cloud storage brings convenience, it also deprives users of complete control over their data. Therefore, achieving integrity auditing of cloud data has become a hot research topic in the field of cloud computing.

[0003] In 2003, Deswarte et al. proposed the concept of remote data integrity auditing, the core idea of ​​which is to directly use the hash value of the data as the basis for data integrity auditing. During data integrity auditing, the third-party auditor (TPA) needs to download all the data from the cloud server, calculate its hash value, and compare it with the original hash value to determine the data integrity, a method with low efficiency. In 2007, Ateniese et al. proposed the concept of Provable Data Possession (PDP) and provided a specific design for the PDP scheme based on the RSA cryptosystem. Compared to traditional methods, PDP's auditing process uses random sampling to probabilistically determine the integrity of the audited data, significantly improving auditing efficiency. In the same year, Juels and Kaliski proposed a Proof of Retrievability (POR) scheme, which also supports data integrity auditing. In 2009, Ateniese et al. demonstrated that homomorphic verifiable tags (HVT) can be used to implement data integrity auditing in cloud storage. To further optimize the computation and communication costs in the auditing process, Shacham and Waters constructed an efficient HVT using BLS signatures in 2013 and presented an improved PDP scheme.

[0004] To avoid the cumbersome key and certificate management problems of traditional public-key cryptography systems, Israeli scientist Adi Shamir, one of the inventors of the RSA algorithm, proposed the concept of Identity-Based Cryptography (IBC) in 1984. Identity-based cryptography uses a user's identifier (such as email address, mobile phone number, QQ number, etc.) as the public key, eliminating the need for verifying digital certificates and exchanging public keys, making the security system easier to deploy and manage. In 2014, Wang et al. proposed an identity-based remote data integrity auditing scheme suitable for public clouds, effectively optimizing key and certificate management. In 2016, Zhang et al. implemented identity-based cloud data integrity auditing that supports user revocation using a new key generation strategy and private key update technology. Subsequently, many scholars have conducted a series of studies and explorations on identity-based data integrity auditing schemes. Unfortunately, most typical identity-based cloud storage data integrity auditing schemes currently rely on foreign cryptographic algorithms, and the related designs lack independent controllability.

[0005] In 2016, the State Cryptography Administration of China released SM9, an identifier cryptography algorithm based on bilinear pairing. Its signature algorithm effectively achieves identity verification in digital systems and ensures data integrity and authenticity, while avoiding complex key and certificate management issues. Clearly, designing a cloud storage data integrity auditing method based on the national cryptographic standard SM9 to meet real-world needs has significant theoretical and practical value.

[0006] In summary, the technical problem to be solved by this invention is to overcome the dependence of existing cloud storage data integrity auditing schemes on foreign cryptographic algorithms and to build an independent and controllable cloud storage data integrity auditing system. Summary of the Invention

[0007] This invention proposes an efficient cloud storage data integrity auditing method based on the national cryptographic standard SM9. The core algorithm is the national cryptographic standard SM9 digital signature algorithm, which belongs to the identifier cryptographic algorithm. While ensuring independent controllability, it eliminates the complex certificate management problem. At the same time, by increasing the cloud storage cost slightly, it significantly reduces the number of exponential operations in the block tag generation process, making the user-end tag generation process simpler and more efficient.

[0008] The present invention adopts the following technical solution.

[0009] A highly efficient cloud storage data integrity auditing method based on the national cryptographic standard SM9, the method comprising the following steps:

[0010] Step A: Based on the security parameters, the Key Generation Center (KGC) runs the system initialization algorithm to generate public system parameters, i.e., the public parameters of the key management system.

[0011] Step B: According to the publicly available parameters of the system, the Key Generation Center (KGC) executes the SM9 key generation algorithm to set the user's identity as the public key and extract the user's private key based on it.

[0012] Step C: Based on the system's public parameters, the user's public and private keys, the file and its attribute information, the user divides the file into blocks and generates file tags and data block tags. Then, the user sends the divided file, file tags and data block tags to the cloud service provider CSP.

[0013] Step D: Based on the publicly available system parameters, file attribute information, and related additional information, the third-party auditor TPA constructs a random challenge and sends it to the cloud service provider CSP.

[0014] Step E: Based on publicly available system parameters, files stored in the cloud, file tags, and data block tags, the cloud service provider (CSP) challenges computational evidence and returns it to the third-party auditor (TPA).

[0015] Step F: Based on the publicly available system parameters, challenges, and corresponding evidence, the third-party auditor TPA audits the completeness of the documentation.

[0016] The detailed steps of step A are as follows:

[0017] Step A.1: The Key Generation Center (KGC) runs the system initialization algorithm based on security parameters. Select Cyclic subgroups and its generators , Cyclic subgroups and its generators and a bilinear mapping Bilinear operations are implemented using 256-bit BN elliptic curves, and a cyclic group is selected. generator Select three collision-resistant hash functions , , , For model The ring of integer residue classes;

[0018] Step A.2: The Key Generation Center (KGC) is randomly selected. As the system's master private key And calculate the system master public key. and group elements in =e( );

[0019] Step A.3: The Key Generation Center (KGC) publishes the system's public parameters. ;

[0020] The detailed steps of step B are as follows: Based on the publicly available system parameters The Key Generation Center (KGC) executes the SM9 national cryptographic standard for key generation and sets the user's public key. User private key The specific calculation process is as follows , , ,in This represents a single-byte identifier for the encrypted private key generation function, selected and published by the Key Generation Center (KGC), ultimately leading to the user's public-private key pair. ;

[0021] In step C, based on the publicly available system parameters... Named Files In this data block , , Private key Users first from Random selection random elements and order Then perform the following operations:

[0022] (1) Document tag generation: Execute the national cryptographic SM9 digital signature algorithm and randomly select ,calculate , ,based on Calculate integers ,calculate ,calculate elements Thus obtain Finally, set the file tag to ;

[0023] (2) Data block label generation: For data blocks The user generates its corresponding block tag:

[0024] ,

[0025] in ;

[0026] (3) Data upload to the cloud: The user uploads the split file File tags and data block labels Upload to the cloud service provider (CSP), and then delete redundant local information;

[0027] The detailed steps of step D are as follows: Based on the publicly available system parameters The third-party auditor, TPA, randomly selects a non-empty subset. and corresponding random elements ,in Set the challenge as and the filename ,User ID Send to cloud service provider CSP;

[0028] The detailed steps of step E are as follows: Based on the publicly available system parameters ,User ID ,document File tags Data block labels and challenges Cloud service provider CSP computing evidence And send it to a third-party auditor. ,in , ;

[0029] The detailed steps of step F are as follows: Based on the publicly available system parameters User public key File tags Data block labels ,challenge and evidence The third-party auditor, TPA, conducts verification. The verification process is as follows:

[0030] The first step is to calculate sequentially. , , , , = , Determine the equation If the condition is not met, the verification fails; otherwise, proceed to the second step.

[0031] The second step is to verify the following equation:

[0032] .

[0033] If the equation is true, the algorithm outputs 1, indicating that the evidence is valid and the cloud service provider CSP has stored all data blocks completely; otherwise, it outputs 0, indicating that the evidence is invalid and the cloud service provider CSP has not stored all data blocks completely.

[0034] The parameters in the method are defined as shown in the table below.

[0035] .

[0036] The core algorithm of this invention is the SM9 digital signature algorithm, which belongs to the identifier cryptography algorithm. While ensuring independent controllability, it eliminates the complex certificate management problem. At the same time, by increasing the cost of cloud storage, it significantly reduces the number of exponential operations in the block tag generation process, making the user-end tag generation process simpler and more efficient. Attached Figure Description

[0037] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments:

[0038] Appendix Figure 1 This is a flowchart illustrating the auditing method described in this invention;

[0039] Appendix Figure 2 This is a flowchart illustrating the execution of the auditing method described in this invention. Detailed Implementation

[0040] As shown in the figure, an efficient cloud storage data integrity auditing method based on the national cryptographic standard SM9 includes the following steps:

[0041] Step A: Based on the security parameters, the Key Generation Center (KGC) runs the system initialization algorithm to generate public system parameters, i.e., the public parameters of the key management system.

[0042] Step B: According to the publicly available parameters of the system, the Key Generation Center (KGC) executes the SM9 key generation algorithm to set the user's identity as the public key and extract the user's private key based on it.

[0043] Step C: Based on the system's public parameters, the user's public and private keys, the file and its attribute information, the user divides the file into blocks and generates file tags and data block tags. Then, the user sends the divided file, file tags and data block tags to the cloud service provider CSP.

[0044] Step D: Based on the publicly available system parameters, file attribute information, and related additional information, the third-party auditor TPA constructs a random challenge and sends it to the cloud service provider CSP.

[0045] Step E: Based on publicly available system parameters, files stored in the cloud, file tags, and data block tags, the cloud service provider (CSP) challenges computational evidence and returns it to the third-party auditor (TPA).

[0046] Step F: Based on the publicly available system parameters, challenges, and corresponding evidence, the third-party auditor TPA audits the completeness of the documentation.

[0047] The detailed steps of step A are as follows:

[0048] Step A.1: The Key Generation Center (KGC) runs the system initialization algorithm based on security parameters. Select Cyclic subgroups and its generators , Cyclic subgroups and its generators and a bilinear mapping Bilinear operations are implemented using 256-bit BN elliptic curves, and a cyclic group is selected. generator Select three collision-resistant hash functions , , , For model The ring of integer residue classes;

[0049] Step A.2: The Key Generation Center (KGC) is randomly selected. As the system's master private key And calculate the system master public key. and group elements in =e( );

[0050] Step A.3: The Key Generation Center (KGC) publishes the system's public parameters. ;

[0051] The detailed steps of step B are as follows: Based on the publicly available system parameters The Key Generation Center (KGC) executes the SM9 national cryptographic standard for key generation and sets the user's public key. User private key The specific calculation process is as follows , , ,in This represents a single-byte identifier for the encrypted private key generation function, selected and published by the Key Generation Center (KGC), ultimately leading to the user's public-private key pair. ;

[0052] In step C, based on the publicly available system parameters... Named Files In this data block , , Private key Users first from Random selection random elements and order Then perform the following operations:

[0053] (1) Document tag generation: Execute the national cryptographic SM9 digital signature algorithm and randomly select ,calculate , ,based on Calculate integers ,calculate ,calculate elements Thus obtain Finally, set the file tag to ;

[0054] (2) Data block label generation: For data blocks The user generates its corresponding block tag:

[0055] ,

[0056] in ;

[0057] (3) Data upload to the cloud: The user uploads the split file File tags and data block labels Upload to the cloud service provider (CSP), and then delete redundant local information;

[0058] The detailed steps of step D are as follows: Based on the publicly available system parameters The third-party auditor, TPA, randomly selects a non-empty subset. and corresponding random elements ,in Set the challenge as and the filename ,User ID Send to cloud service provider CSP;

[0059] The detailed steps of step E are as follows: Based on the publicly available system parameters ,User ID ,document File tags Data block labels and challenges Cloud service provider CSP computing evidence And send it to a third-party auditor. ,in , ;

[0060] The detailed steps of step F are as follows: Based on the publicly available system parameters User public key File tags Data block labels ,challenge and evidence The third-party auditor, TPA, conducts verification. The verification process is as follows:

[0061] The first step is to calculate sequentially. , , , , = , Determine the equation If the condition is not met, the verification fails; otherwise, proceed to the second step.

[0062] The second step is to verify the following equation:

[0063] .

[0064] If the equation is true, the algorithm outputs 1, indicating that the evidence is valid and the cloud service provider CSP has stored all data blocks completely; otherwise, it outputs 0, indicating that the evidence is invalid and the cloud service provider CSP has not stored all data blocks completely.

[0065] The parameters in the method are defined as shown in the table below.

[0066] .

Claims

1. A cloud storage data integrity auditing method based on the national cryptographic standard SM9, characterized in that, The method includes the following steps: Step A: Based on the security parameters, the Key Generation Center (KGC) runs the system initialization algorithm to generate public system parameters; Step B: According to the publicly available parameters of the system, the Key Generation Center (KGC) executes the SM9 key generation algorithm to set the user's identity as the public key and extract the user's private key based on it. Step C: Based on the system's public parameters, the user's public and private keys, the file and its attribute information, the user divides the file into blocks and generates file tags and data block tags. Then, the user sends the divided file, file tags and data block tags to the cloud service provider CSP. Step D: Based on the publicly available system parameters, file attribute information, and related additional information, the third-party auditor TPA constructs a random challenge and sends it to the cloud service provider CSP. Step E: Based on the publicly available system parameters, files stored in the cloud, file tags, and data block tags, the cloud service provider CSP challenges the computational evidence and returns it to the third-party auditor TPA. Step F: Based on the publicly available system parameters, challenges, and corresponding evidence, the third-party auditor TPA audits the completeness of the documentation; The detailed steps of step A are as follows: Step A.1: The Key Generation Center (KGC) runs the system initialization algorithm based on security parameters. Select Cyclic subgroups and its generators , Cyclic subgroups and its generators and a bilinear mapping Bilinear operations are implemented using 256-bit BN elliptic curves, and a cyclic group is selected. generator Select three collision-resistant hash functions , , , For model The ring of integer residue classes; Step A.2: The Key Generation Center (KGC) is randomly selected. As the system's master private key And calculate the system master public key. and group elements in =e( ); Step A.3: The Key Generation Center (KGC) publishes the system's public parameters. ; The detailed steps of step B are as follows: Based on the publicly available system parameters The Key Generation Center (KGC) executes the SM9 national cryptographic standard for key generation and sets the user's public key. User private key The specific calculation process is as follows , , ,in This represents a single-byte identifier for the encrypted private key generation function, selected and published by the Key Generation Center (KGC), ultimately leading to the user's public-private key pair. ; The detailed steps of step C are as follows: Based on the publicly available system parameters Named Files In this data block , , Private key Users first from Random selection random elements and order Then perform the following operations: (1) Document tag generation: Execute the national cryptographic SM9 digital signature algorithm and randomly select ,calculate , ,based on Calculate integers ,calculate ,calculate elements Thus obtain Finally, set the file tag to ; (2) Data block label generation: For data blocks The user generates its corresponding block tag: , in ; (3) Data upload to the cloud: The user uploads the split file File tags and data block labels Upload to the cloud service provider (CSP), and then delete redundant local information; The detailed steps of step D are as follows: Based on the publicly available system parameters The third-party auditor, TPA, randomly selects a non-empty subset. and corresponding random elements ,in Set the challenge as and the filename ,User ID Send to cloud service provider CSP; The detailed steps of step E are as follows: Based on the publicly available system parameters ,User ID ,document File tags Data block labels and challenges Cloud service provider CSP computing evidence And send it to a third-party auditor. ,in , ; The detailed steps of step F are as follows: Based on the publicly available system parameters User public key File tags Data block labels ,challenge and evidence The third-party auditor, TPA, conducts verification. The verification process is as follows: The first step is to calculate sequentially. , , , , = , Determine the equation If the condition is not met, the verification fails; otherwise, proceed to the second step. The second step is to verify the following equation: If the equation is true, the algorithm outputs 1, indicating that the evidence is valid and the cloud service provider CSP has stored all data blocks completely. Otherwise, output 0, indicating that the evidence is invalid and the cloud service provider CSP did not fully store all data blocks.

Citation Information

Patent Citations

  • Cloud side data integrity verification and restoration method based on IDA

    CN106650503A