A Dynamic Update Cloud Auditing Method Based on Chameleon Hash Function
Through a dynamic update cloud audit method based on the chameleon hash function, the editable blockchain and Merkel hash tree are used to solve the problems of high costs and entity trust in cloud storage, and efficiently audit massive data and dynamically updated medical data.
Patent Information
- Application Number
- CN202411028281.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-30
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2044-07-30
AI Technical Summary
The existing cloud storage auditing solutions rely on third-party audit agencies, which have high costs and entity trust problems, and it is difficult to efficiently audit massive data and dynamically updated medical data.
The dynamic update cloud audit method based on the chameleon hash function is adopted. Through the initialization, data upload, data audit and block editing stages, editable blockchain and Merkel hash tree are used for data verification and update, avoiding relying on third-party audit institutions and achieving efficient data auditing.
It realizes efficient audit of massive data and supports dynamic updates of system users without relying on third-party audit agencies, protects user data security, and reduces costs and entity trust risks.
Smart Images

Figure CN119011225B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly relates to a dynamic update cloud audit method based on a chameleon hash function. Background Art
[0002] Cloud Storage is an online storage mode, that is, data is stored on multiple virtual servers hosted by a third party. This mode can be applied in fields such as online education, intelligent healthcare, intelligent government affairs, and team collaboration. In the medical field of electronic medical records, medical images, and experimental data storage, cloud storage services can achieve centralized management and sharing of medical data, provide data backup and recovery services for medical institutions, and ensure the security of patient data, which has received wide attention. However, storing medical data on a single server will face the potential risks of data loss or tampering, and when sharing and synchronizing data between multiple systems and applications, data inconsistency may occur. Some scholars have proposed cloud audit services that check and record operations on stored data. Traditional cloud audit services need to rely on a third-party auditor (TPA), which has high costs and entity trust issues. In addition, existing audit schemes use bilinear mapping verification, which has problems of low efficiency and high overhead. At the same time, as the patient data in medical institutions increases, traditional audit schemes cannot audit dynamically updated data. To sum up, intelligent healthcare needs to be improved in terms of data storage security, consistency, efficiency, and audit after data update. Summary of the Invention
[0003] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a dynamic update cloud audit method based on a chameleon hash function, aiming to prevent the loss of user data while implementing a low-cost and highly efficient and fast integrity audit scheme for dynamic updates.
[0004] The purpose of the present invention is achieved by the following technical solutions:
[0005] A dynamic update cloud audit method based on a chameleon hash function, comprising:
[0006] Initialization stage: System users initialize system parameters, generate and broadcast a genesis block to an editable blockchain network, and cloud storage service providers (CSPs) and all users generate public-private key pairs for corresponding functions.
[0007] Data upload stage: System users upload encrypted medical data to the cloud storage service provider (CSP) side and add a new block to the editable blockchain network.
[0008] Data Audit Phase: The auditor calculates and returns the storage proof Proof on the editable blockchain through the corresponding block of medical data. rbc ; The system user sends an audit challenge to the cloud storage service provider CSP, and at the same time commissions an auditor to audit the medical data and generate challenge information; after receiving the challenge, the cloud storage service provider CSP decrypts the medical data file, constructs a Merkle hash tree MHT and returns the storage proof Proof in the cloud server to the system user. csp The system user verifies the bilinear mapping and then compares the MHT value Root of the corresponding block in the editable blockchain. rbc with the MHT root Root constructed by the cloud server. csp to check if they are equal;
[0009] Block Editing Phase: When the patient's medical data file changes, update the content involved in the cloud storage service provider CSP and the editable blockchain network.
[0010] Furthermore, the initialization phase includes:
[0011] 1) Select a Gap Diffie-Hellman group G of prime order p and a multiplicative cyclic group G T , generate a bilinear mapping e: G×G→G T , where the generator of G is g, select hash functions and H3: {0, 1} * →G, select random functions and
[0012] 2) Generate the public and private key pair (pk ch , sk ch ) of the chameleon hash function, that is, select the private key and calculate the public key pk ch : y = g x ; Generate the public parameters Calculate the hash value h0 of the genesis block B0 = H2(pp||v0), where v0 is a random number to let the block go on the chain; Broadcast the genesis block B0 = (h0, v0, pp) to the editable blockchain network;
[0013] 3) The cloud storage service provider CSP generates a public and private key pair (cpk, csk) for file encryption and decryption and a public and private key pair (spk′, ssk′) for signature;
[0014] 4) All users generate random public and private key pairs (spk, ssk), and then select a random value as the partial private key, and calculate the partial public key ψ = g β, form the private key sk = (β, ssk) and the public key pk = (ψ, spk); generate the public and private key pair (sk′, pk′) for the auditor to sign.
[0015] Furthermore, the data upload phase includes:
[0016] 1) Divide the medical data file F into n fixed-size data blocks ω i , that is, F = ω1, ω2,..., ω i ,..., ω n , i ∈ (1, n); use the public key cpk of the cloud storage service provider CSP to encrypt the data block ω i to obtain the secret value e i , that is, e i = Encrypt cpk (ω i ); select a random value ρ ← G, and calculate the signature σ i of the secret value e i , that is
[0017] 2) Upload the encrypted file F′ = e1, e2,..., e i ,..., e n , and the signature σ i to the cloud storage service provider CSP; locally store the mapping index of the file F and σ i for subsequent file reconstruction;
[0018] 3) Calculate the tag of the secret value in the order of the uploaded data blocks, that is, δ i = H3(e i ), and broadcast the user identification number U ID and the tag set δ = {δ i} as a transaction to the editable blockchain network;
[0019] 4) Other data owners act as data verification checkers. The data verification checkers form all the tags δ in the tag set δ i to form a Merkle hash tree MHT and obtain the root value m i ;
[0020] 5) The data verification checker selects an adaptation value and calculates the chameleon hash function value of the current file F i corresponding to the block B i : where h i-1 = H2(ch i-1 , v i-1 ), and add the new block B i = (h i-1 , chi , m i , r i , s i ) to an editable blockchain network.
[0021] Furthermore, the data auditing phase includes:
[0022] 1) The auditor locates the medical data F of the system user through the user identification number U ID and the corresponding block B i of the blockchain, obtains Root by establishing an MHT i , and returns Proof rbc to the system user, where Proof rbc = {Root rbc , sig rbc (H3(Root sk′ ))}; rbc
[0023] 2) The system user sends an auditing challenge to the cloud storage service provider CSP, and at the same time entrusts an auditor to audit the medical data and generate a challenge, i.e., chal = {z, l1, l2} 1≤z≤n , where
[0024] 3) After receiving the challenge, the cloud storage service provider CSP first calculates the index and the coefficient Subsequently, it decrypts the medical data file e i to ω i , calculates the aggregated signature as
[0025] 4) The cloud storage service provider CSP calculates the tag of the secret value e i and constructs a Merkle hash tree MHT to obtain the Merkle hash tree root value Root csp , and returns Proof csp = { σ, Root csp , sig ssk′ (H3(Root csp ))} to the system user;
[0026] 5) After receiving Proof rbc and Proof csp , the system user checks the bilinear mapping where If it holds, then verify If all hold, the audit passes.
[0027] Furthermore, the block editing stage includes:
[0028] 1) The system user redownloads the patient data file, modifies it, and uploads the latest data file;
[0029] 2) When updating the content of the block with the modified data block number π, the system user broadcasts the label of the new data block e′ π ; after receiving it, the data verification checker replaces the label and constructs an MHT to generate a new Merkle hash tree root value m′ π ;
[0030] 3) The data verification checker calculates the long-term trapdoor key k π = s π + H1(h π-1 || m π , r π )·x π mod p, where (s π , r π ) is the original fitness value, h π-1 is the hash value of the previous block, m π is the root value of the MHT of this block, and x π is the public key of the chameleon hash function; subsequently, a temporary trapdoor key is selected to calculate s′ π = k π - H1(h π-1 || m′ π , r′ π )·x π mod p, where m′ π is the new MHT root value, and a new block corresponding to block B π =(h π-1 , ch π , m π , r π , s π ) is B′ π =(h π-1 , ch π , m′ π , r′ π , s′ π ).
[0031] Furthermore, the proof process of the bilinear mapping is as follows:
[0032] Given: ψ = g β , chal = {z, l1, l2} 1≤z≤n ,
[0033] Proof process:
[0034] The beneficial effects of the present invention are as follows:
[0035] Compared with the existing audit schemes, the present invention overcomes several major difficulties in traditional cloud data storage auditing: 1) In the traditional cloud audit scheme, cloud storage relies on a single CSP, and it is easy to lose the medical data of system users; 2) The mainstream audit schemes rely on third-party audit institutions, and there are problems of high cost and entity trust; 3) The existing audit schemes usually can only audit part of the data, and their performance is poor when auditing massive data; 4) The current audit schemes are difficult to cope with the update of the medical data of system users, and improvement is still needed in terms of dynamic update support.
[0036] Compared with the existing cloud audit schemes that support dynamic data update, the present invention: 1) can protect the medical data stored by system users; 2) can audit medical data without relying on third-party audit institutions; 3) can efficiently audit massive data; 4) can audit the dynamically updated medical data of system users. Brief Description of the Drawings
[0037] Figure 1 It is a system model diagram of the dynamic update cloud audit method based on the chameleon hash function according to the present invention;
[0038] Figure 2 It is the structure of a Merkle Hash Tree (MHT);
[0039] Figure 3 It is a schematic structural diagram of an editable blockchain. Detailed Embodiments
[0040] Next, in combination with the embodiments, the technical solutions of the present invention will be described clearly and completely. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts shall fall within the protection scope of the present invention.
[0041] Refer to Figures 1 - 3 , the present invention provides a technical solution:
[0042] The object of the present invention is achieved through the following technical solutions:
[0043] A dynamic update cloud audit method based on the chameleon hash function, the system model diagram is as Figure 1 shown, including:
[0044] S1: Initialization Phase: The system user initializes the system parameters, generates and broadcasts the genesis block to the editable blockchain network, and the cloud storage service provider CSP and all users generate public-private key pairs for corresponding functions; In this embodiment, the initialization phase includes:
[0045] 1) Select a Gap Diffie-Hellman group G of prime order p and a multiplicative cyclic group G T to generate a bilinear mapping e: G×G→G T , where the generator of G is g, and select hash functions and H3: {0, 1} * →G, select random functions and
[0046] 2) Generate the public-private key pair (pk ch , sk ch ) of the chameleon hash function, that is, select the private key and calculate the public key pk ch : y = g x ; Generate the public parameters Calculate the hash value h0 = H2(pp||v0) of the genesis block B0, where v0 is a random number for the block to be chained; Broadcast the genesis block B0 = (h0, v0, pp) to the editable blockchain network;
[0047] 3) The cloud storage service provider CSP generates a public-private key pair (cpk, csk) for file encryption and decryption and a public-private key pair (spk′, ssk′) for signature;
[0048] 4) All users generate random public-private key pairs (spk, ssk), and then select a random value as the partial private key, and calculate the partial public key ψ = g β , forming the private key sk = (β, ssk) and the public key pk = (ψ, spk); Generate the public-private key pair (sk′, pk′) for the auditor to sign.
[0049] S2: Data Upload Phase: The system user uploads the encrypted medical data to the cloud storage service provider CSP side and adds a new block to the editable blockchain network; In this embodiment, the data upload phase includes:
[0050] 1) Divide the medical data file F into n fixed-size data blocks ω i , that is, F = ω1, ω2,..., ω i ,..., ω n , i ∈ (1, n); Use the public key cpk of the cloud storage service provider CSP to encrypt the data block ω i to obtain the secret value ei , i.e., e i = Encrypt cpk (ω i ); Select a random value ρ ← G, and calculate the signature σ of the secret value e i ; i , i.e.,
[0051] 2) Upload the encrypted file F' = e1, e2,..., e i ,..., e n , and the signature σ i to the cloud storage service provider CSP; Locally store the mapping index of the file F and σ i for subsequent file reconstruction;
[0052] 3) Calculate the tag of the secret value in the order of the uploaded data blocks, i.e., δ i = H3(e i ), and broadcast the user identification number U ID , the tag set δ = {δ i} as a transaction to the editable blockchain network;
[0053] 4) Other data owners act as data verification verifiers. The data verification verifiers form all the tags δ in the tag set δ i into a Merkle hash tree MHT and obtain the root value m i ; In some specific embodiments, the Merkle hash tree MHT structure formed by eight transaction data values is as shown in Figure 2 , and finally the root value m i of the Merkle hash tree MHT is generated;
[0054] 5) The data verification verifier selects an adaptation value and calculates the chameleon hash function value of the current file F i corresponding to the block B i : where h i-1 = H2(ch i-1 , v i-1 ), and add the new block B i = (h i-1 , ch i , m i , r i , s i ) to the editable blockchain network.
[0055] Cloud Service Providers (CSPs) can effectively manage the remote data of data uploaders, saving local storage space. In this work, dual CSPs are adopted to ensure the secure storage of data, avoiding the risk of data loss caused by single point of failure attacks.
[0056] S3: Data auditing phase: The auditor calculates and returns Proof through the corresponding blocks of medical data rbc ; The system user sends an auditing challenge to the cloud storage service provider CSP, and at the same time commissions an auditor to audit the medical data and generate challenge information; After receiving the challenge, the cloud storage service provider CSP decrypts the medical data file, constructs a Merkle hash tree MHT and returns Root to the system user csp , and the system user compares Root rbc and Root csp to check if they are equal; In this embodiment, the data auditing phase includes:
[0057] 1) The auditor locates the block B ID corresponding to the medical data F i of the system user through the user identification number U i , obtains Root rbc by establishing MHT, and returns Proof rbc to the system user, where Proof rbc = {Root bc , sig sk′ (H3(Root bc ))};
[0058] 2) The system user sends an auditing challenge to the cloud storage service provider CSP, and at the same time commissions an auditor to audit the medical data and generate a challenge, i.e., chal = {z, l1, l2} 1≤z≤n , where
[0059] 3) After receiving the challenge, the cloud storage service provider CSP first calculates the index and the coefficient Then decrypts the medical data file e i to ω i , calculates The aggregated signature is
[0060] 4) The cloud storage service provider CSP calculates the tag of the secret value e i and constructs a Merkle hash tree MHT to obtain the Merkle hash tree root value Root csp , and returns Proof csp = { σ, Root csp , sig ssk′ (H3(Root csp ))} to the system user;
[0061] 5) After the system user receives Proof rbc and Proof csp , check the bilinear mapping where If it holds, then verify If all hold, the audit passes.
[0062] Among them, the proof process of the bilinear mapping is as follows:
[0063] Given: ψ = g β , chal = {z, l1, l2} 1≤z≤n ,
[0064] Proof process:
[0065] To reduce the high cost and entity trust problems brought by TPA auditing, the present invention uses blockchain technology to design a new public auditing scheme to replace TPA, and audits by constructing the structure of a Merkle Hash Tree (MHT), which speeds up the auditing efficiency and reduces the auditing overhead. e , MHT) to conduct the audit, which speeds up the audit efficiency and reduces the audit overhead.
[0066] S4: Block editing stage: When the medical data file of the patient changes, update the content involved in the cloud storage service provider CSP and the editable blockchain network. In this embodiment, the block editing stage specifically includes:
[0067] 1) The system user redownloads the patient data file, modifies it, and uploads the latest data file;
[0068] 2) When updating the content of the block with the modified data block number π, the system user broadcasts the label of the new data block e′ π ; after receiving it, the data verification checker replaces the label and constructs an MHT to generate a new Merkle hash tree root value m′ π ;
[0069] 3) The data verification checker calculates the long-term trapdoor key k π = s π + H1(h π-1 ||m π , r π )·x π mod p, where (sπ , r π ) is the original fitness value, h π-1 is the hash value of the previous block, m π is the root value of the MHT of this block, x π is the public key of the chameleon hash function; then select the temporary trapdoor key Calculate s′ π = k π - H1(h π-1 || m′ π , r′ π )·x π mod p, where m′ π is the new MHT root value, generating the corresponding block B π = (h π-1 , ch π , m π , r π , s π ) of the new block is B′ π = (h π-1 , ch π , m′ π , r′ π , s′ π ).
[0070] The structure of the editable blockchain network is as Figure 3 shown, where Block Hash h i is the hash value of the block, that is, the chameleon hash value ch of the block i and the random number Nonce v on the chain of the block i are hashed; the chameleon hash value ch of the block i is the chameleon hash calculation of the block hash value h of the previous block i-1 , the MHT root value m of the current block i and the fitness value (s i , r i ) of the chameleon hash function, where (s i , r i ) the fitness value is to adjust this pair of values so that the chameleon hash function can produce the same output through different inputs; Hash.Pre h i-1 is the hash value of the previous block.
[0071] The present invention introduces an editable blockchain based on the chameleon hash function to support auditing updated data, solving the auditing problem brought about by the increase in patient data.
[0072] Compared with existing audit schemes, the present invention overcomes several major difficulties in traditional cloud data storage auditing: 1) Cloud storage in traditional cloud audit schemes relies on a single CSP, making it easy to lose the medical data of system users; 2) Mainstream audit schemes rely on third-party audit institutions, presenting problems of high cost and entity trust; 3) Existing audit schemes usually can only audit partial data, and their performance is poor when auditing massive data; 4) Current audit schemes are difficult to cope with the update of system users' medical data, and improvement is still needed in terms of dynamic update support.
[0073] Compared with existing cloud audit schemes that support dynamic data update, the present invention: 1) can protect the medical data stored by system users; 2) can audit medical data without relying on third-party audit institutions; 3) can efficiently audit massive data; 4) can audit the dynamically updated medical data of system users.
[0074] The above are only the preferred embodiments of the present invention. It should be understood that the present invention is not limited to the form disclosed herein, should not be regarded as excluding other embodiments, but can be used in various other combinations, modifications, and environments, and can be changed within the scope of the concept described herein through the above teachings or the techniques or knowledge in related fields. Any changes and modifications made by those skilled in the art without departing from the spirit and scope of the present invention shall fall within the protection scope of the appended claims of the present invention.
Claims
1. A dynamic update cloud auditing method based on a chameleon hash function, characterized in that, Including: Initialization phase: The system user initializes the system parameters, generates and broadcasts the genesis block to the editable blockchain network, and the cloud storage service provider CSP and all users generate public-private key pairs for corresponding functions. The initialization phase includes: Select a Gap Diffie-Hellman group \(G\) of prime order \(p\) and a multiplicative cyclic group \(G\) T , and generate a bilinear map \(e: G\times G\rightarrow G\) T , where the generator of \(G\) is \(g\), and select hash functions \(H_1\): \(H_2\): and \(H_3:\{0,1\}\) * \(\rightarrow G\), and select random functions and All users generate random public-private key pairs (spk, ssk), and then select a random value as a partial private key, and calculate the partial public key ψ = g β , to form the private key sk = (β, ssk) and the public key pk = (ψ, spk); generate the public-private key pair (sk′, pk′) for the auditor to sign; Data upload phase: The system user uploads the encrypted medical data to the cloud storage service provider CSP side and adds a new block to the editable blockchain network. The data upload phase includes: Divide the medical data file F into n fixed - size data blocks ω i , that is, F = ω1, ω2, …, ω i , …, ω n , where i ∈ (1, n); Use the public key cpk of the cloud storage service provider CSP to encrypt the data block ω i to obtain the secret value e i , that is, e i = Encrypt cpk (ω l ); Select a random value ρ ← G, and calculate the signature σ l of the secret value e i , that is Data audit phase: The auditor calculates and returns the storage proof Proof on the editable blockchain through the corresponding block of medical data tbc ; The system user sends an audit challenge to the cloud storage service provider CSP, and at the same time entrusts an auditor to audit the medical data and generate challenge information; After receiving the challenge, the cloud storage service provider CSP decrypts the medical data file, constructs a Merkle hash tree MHT and returns the storage proof Proof in the cloud server to the system user csp , After the system user verifies the bilinear mapping, it then compares the MHT value Root of the corresponding block in the editable blockchain rbc with the MHT root Root constructed by the cloud server csp to check if they are equal; The data audit phase includes: 1) The auditor uses the user ID U ID Positioning system user medical data F i The corresponding block B i , by establishing MHT to obtain Root rbc , and returns Proof rbc To system users, where Proof rbc ={Root rbc ,sig sk′ (H3(Root rbc ))}; 2) The system user sends an audit challenge to the cloud storage provider (CSP), and simultaneously commissions an auditor to audit the medical data and generate a challenge, i.e., chal = {z, l1, l2} 1≤z≤n , where 3) After the cloud storage service provider CSP receives the challenge, it first calculates the index and the coefficient Subsequently, it decrypts the medical data file e i to ω i , and calculates The aggregated signature is 4) Cloud storage service provider CSP calculates the secret value e i 's label and constructs a Merkle hash tree MHT to obtain the Merkle hash tree root value Root csp , and returns to the system user; 5) The system user receives the Proof rb and the Proof csp After that, check the bilinear mapping where If it holds, then verify If all hold, the audit passes; Block editing phase: When the patient's medical data file changes, update the content involved in the cloud storage service provider CSP and the editable blockchain network.
2. The dynamic update cloud auditing method based on the chameleon hash function according to claim 1, wherein: The initialization phase further includes: Generate the public and private key pairs (pk ch , sk ch ) of the chameleon hash function, that is, select the private key and calculate the public key pk ch : y = g x ; generate the common parameters Calculate the hash value h0 = H2(pp||v0) of the genesis block B0, where v0 is the random number for the block to be chained; broadcast the genesis block B0 = (h0, v0, pp) to the editable blockchain network; The cloud storage service provider CSP generates a public-private key pair (cpk, csk) for file encryption and decryption and a public-private key pair (spk′, ssk′) for signature.
3. The dynamic update cloud auditing method based on the chameleon hash function according to claim 2, characterized in that: The data upload phase further includes: Upload the encrypted file F ′ = e1, e2, …, e i , …, e n , and the signature σ i to the cloud storage provider CSP; locally store the mapping index of the file F and σ i for subsequent file reconstruction; Calculate the tag of the secret value in the order of the uploaded data blocks, i.e., δ i = H3(e i ), and broadcast the user identity number U ID , the tag set δ = {δ i} to the editable blockchain network as a transaction; Other data owners act as data verification checkers, and the data verification checkers will include all the tags δ in the tag set δ i form and then form a Merkle hash tree MHT and obtain the root value m i ; The data verification verifier selects the fitness value Calculate the current file F i Corresponding block B i The chameleon hash function value of: Where h i-1 = H2(ch i-1 , v i-1 ), Add the new block B i =(h i-1 , ch i , m i , r i , s i ) to the editable blockchain network.
4. The dynamic update cloud auditing method based on the chameleon hash function according to claim 3, wherein: The block editing phase includes: 1) The system user redownloads the patient data file, modifies it, and uploads the latest data file. 2) When updating and modifying the content of the block with the block number π, the system user broadcasts the new data block e′ π 's label; after receiving it, the data verification checker replaces the label and constructs an MHT to generate a new Merkle hash tree root value m′ π ; 3) The data verification checker calculates the long-term trapdoor key k of the block π = s π + H1(h π-1 || m π , r π ) · x π mod p, where (s π , r π ) is the original fitness value, h π-1 is the hash value of the previous block, m π is the root value of the MHT of this block, x π is the public key of the chameleon hash function; subsequently, a temporary trapdoor key is selected to calculate s' π = k π - H1(h π-1 || m' π , r' π ) · x π mod p, where m' π is the new MHT root value, generating a new block B π = (h π-1 , ch π , m π , r π , s π ) as B' π = (h π-1 , ch π , m' π , r' π , s' π ).
5. The dynamic update cloud auditing method based on the chameleon hash function according to claim 3, characterized in that: The proof process of the bilinear mapping is as follows: Given: ψ = g β , chal = {z, l1, l2} 1≤z≤n , Proof process:
Citation Information
Patent Citations
Medical cloud storage public auditing method of anonymous identity based on blockchain technology
CN109639420A
Cloud data integrity dynamic verification method and system based on chameleon hash algorithm
CN117424717A