A Multi-copy-based Dynamic Auditing and Encrypted Deduplication Method and System for Fog Storage

The integration of VMHT and UMLE with RSA signature verification in fog storage systems addresses high computational overhead and inefficient fault localization, enabling efficient data integrity auditing and dynamic updates with rapid fault recovery across multiple copies.

CN119602940BActive Publication Date: 2025-07-15NANKAI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411475254.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-22
Publication Date
2025-07-15
Estimated Expiration
2044-10-22

AI Technical Summary

Technical Problem

Existing fog storage systems have high computational overhead during data integrity audit and deduplication, complex certificate management and limitations of single-replica scenarios, making it difficult to recover data after audit failure.

Method used

The variable Merkle tree is combined with the RSA signature verification mechanism, and the threshold proxy resignature and updateable message lock encryption technology are used, and the dynamic Bloom filter is combined for efficient fault location and data update, supporting data block ciphertext-label consistency in multiple replica scenarios.

Benefits of technology

It reduces computing overhead, improves data update efficiency, and achieves fast and accurate fault location and data recovery in multiple replica scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119602940B_ABST
    Figure CN119602940B_ABST
Patent Text Reader

Abstract

The present invention discloses a multi-copy based fog storage dynamic auditing and encrypted deduplication system and its method. The system includes: a data preprocessing module, a user layer, a key generation module, a fog storage module, a data auditing module, a data PoW verification module, a data fault location module, and a data update module. The data preprocessing module obtains public system parameters by constructing a multiplicative cyclic group of quadratic residue moduli. The fog storage module determines the user type by searching for the uploaded data file through fog nodes. The data auditing module audits the variable Merkle hash tree and the tag set in the fog storage module by constructing a multi-copy scenario and locates the fault after the audit fails. The data update module dynamically modifies the variable Merkle hash tree and the tags in the fog storage module and the data auditing module through a message lock encryption algorithm. The user layer downloads files from the fog storage module and decrypts them to obtain the plaintext of the data blocks. The invention combines a variable Merkle hash tree with an RSA signature verification mechanism to achieve data integrity auditing and PoW verification, solves the complex certificate management problem in the combination of existing data deduplication and auditing technologies, and solves the technical problem of high computational overhead.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of fog computing data privacy protection, and in particular relates to a multi-copy-based fog storage dynamic auditing and encrypted deduplication method and system. Background Art

[0002] In recent years, fog storage has provided convenient services for users, but many security problems have also emerged, among which the data integrity problem is particularly important. In particular, more and more people have paid attention to the storage overhead problem in the data integrity auditing process. Some inventions focus on combining data deduplication with data integrity auditing to ensure data integrity while reducing the storage overhead of the system, especially combining the proof of data ownership (PoW) with the provable data possession (PDP). However, most solutions often ignore the computational overhead and complex certificate management in the data auditing and deduplication processes. How to solve the large computational overhead and complex certificate management is a problem worthy of discussion. Further, most inventions only support the application scenario of single-copy, which is not conducive to recovering damaged data blocks in case of audit failure. How to achieve an efficient fault location function after audit failure is also worthy of in-depth study.

[0003] Traditional inventions generate different ciphertexts for the same file data block. After the audit fails, the TPA can only perform a binary search copy verification on the challenged tag set to locate the faulty copy node. However, a large number of bilinear pairs are required in the verification process, resulting in a high computational overhead. The present invention utilizes the consistency of the data block ciphertext and the tag. Once the TPA discovers that the audit fails, a dynamic Bloom filter is used for efficient data fault location. It should be noted that the model of the present invention is different from traditional inventions. In traditional inventions, all users share a file, and updates must be synchronized among multiple users. In the model of the present invention, all users independently own the same file, and the update of one user should not affect other users. That is, when there are multiple owners of the original file, the replica nodes should store both the original version and the updated version of the file simultaneously. Summary of the Invention

[0004] Aiming at the technical problems existing in the prior art, the present invention provides a multi-copy-based fog storage dynamic auditing and encrypted deduplication method and system. The invention combines PoW with data integrity auditing by using a variable Merkle tree and an RSA signature verification mechanism, solves the technical problems in the combination of existing data deduplication and auditing technologies that use bilinear pairing verification operations and require complex certificate management and high computational overhead; at the same time, the invention utilizes threshold-based proxy re-signature, enabling each replica node to cooperate to generate a re-signature key, ensuring that the data remains associated with the user after deduplication in a multi-copy scenario, and solving the technical problems in the existing inventions that combine deduplication and auditing, mostly considering single-copy scenarios, but not considering the multi-copy scenario is more suitable for auditing large file systems in the case of restoring data after auditing failure; and the invention combines updatable message-locked encryption (UMLE) technology with a variable Merkle hash tree (VMHT) to achieve efficient data updates, solving the problem of high computational overhead in the dynamic auditing function of the existing technology. Existing inventions need to recalculate the ciphertext and tags of data blocks in data dynamic updates, which greatly increases the computational overhead and requires a complex key management process; furthermore, the present invention has the consistency of data block ciphertext and tags, and can combine a dynamic Bloom filter to quickly locate faulty replica nodes and data blocks. During the fault location process, in the case of auditing verification failure, the damaged data blocks and tags can be quickly and accurately located.

[0005] To solve the problems of the existing technology, the present invention adopts the following technical solutions:

[0006] A multi-copy-based fog storage dynamic auditing and encrypted deduplication system, the system includes: a data preprocessing module, a user layer, a key generation module, a fog storage module, a data auditing module, a data PoW verification module, a data fault location module, and a data update module; where:

[0007] The data preprocessing module obtains public system parameters by constructing a multiplicative cyclic group of quadratic residue moduli;

[0008] The fog storage module determines the user type by searching for the uploaded data file through fog nodes; including:

[0009] The user layer uploads the ciphertext CT of the plaintext data block with updated message-locked encryption, and the fog node calculates ID CT , and checks whether the fog storage module already has this ID CT ; if it exists, it is a second-time upload user, otherwise it is a first-time upload user; where:

[0010] If it is the first-time uploading user, the key generation module generates a public key for the TPA and configures a re-signature key and a message-derived key for the first-time uploading user; meanwhile, the user layer uploads a variable Merkle hash tree related to the data block and the tag set to the fog storage module; the fog storage module performs a PoW verification on the second-time uploading user to verify its ownership of the data block; and the key generation module configures a message-derived key and a re-signature key for the second-time uploading user.

[0011] The data auditing module aggregates the data block ciphertext and the tag copy through a proxy re-signature algorithm with thresholds, and the TPA audits the aggregated result; the TPA performs a fault query and location after the audit of the fog storage module fails.

[0012] The data update module dynamically modifies the variable Merkle hash tree and the tag set in the fog storage module and the data auditing module through an updated message lock encryption algorithm.

[0013] The user layer downloads the file from the fog storage module and decrypts it to obtain the plaintext of the data block.

[0014] Further, the user layer uploads the data block with a variable hash tree and the tag set in the first-time uploading user file to the fog storage module, including:

[0015] Generate the plaintext data block according to the following formula by transferring the file:

[0016] F = F[1] || F[2] || … || F[n],

[0017] Initialize and establish a variable hash tree for the plaintext data block according to the following algorithm:

[0018] Initialization

[0019] Set que = null

[0020] Set F1 ← F such that F1 = {F[Pr(sh, n)[1]], …, F[Pr(sh, n)[n]]}

[0021] Set F′ = k I |k2|…|k n , x = 1, y = n + 1

[0022] Construct a relevant information set for the leaf nodes of the variable hash tree according to the following algorithm;

[0023]

[0024] Construct non - leaf nodes of the variable hash tree according to the following algorithm;

[0025]

[0026] Construct the master key kk of the root node of the variable hash tree for non - leaf nodes according to the following algorithm mas

[0027] F′ = kk′1|kk′2|…|kk′ L

[0028] kk mas = H0(F′), CT y = Enc(kk mas , F′)

[0029] Create the attribute group of the root node v

[0030] <y, 1, 1, υ n′-1· ln+υn ′-2· ln, 2, CT n′ 〉

[0031] Repeat the operations in lines 33 - 34

[0032] return A VMHT v, kk mas , c1, c2, …, c x , CT n+1 , CT n+2 , …CT y

[0033] The ciphertext of each leaf node of the variable hash tree in the user layer Generate the hash value h i = H(c i );

[0034] Establish the calculation label for each leaf node according to the following formula;

[0035]

[0036] Send the variable - type Merkle hash tree and the label of each leaf node to the fog storage module together.

[0037] Furthermore, the specific algorithm of the data audit module randomly selects different non - leaf nodes from the variable hash tree, parses which leaf nodes the non - leaf node consists of, and then generates the challenge c i ; The TPA sends the challenge c i to each fog node respectively;

[0038] The specific algorithm of the data audit module is that the fog storage module retrieves each challenge c iThe corresponding leaf nodes; search for the challenged data block tags according to the set of challenged data blocks r1, and aggregate the data block ciphertexts with the corresponding tags; at the same time, aggregate the generated aggregate tags from different fog nodes; the fog storage module generates a proof and sends it to the data audit module;

[0039] The specific algorithm of the data audit module: the TPA calculates the hash value of the ciphertext data block Then calculate the verification information; the TPA judges whether the data blocks and their tags stored on the fog storage module are complete through the verification equation.

[0040] Furthermore, the data audit module performs a failure query and localization process on the variable Merkle hash tree and tag set in the fog storage module after an audit failure; including:

[0041] Map the ciphertexts of the audit challenge block set stored in the data audit module to the dynamic filter DBF in turn, and input the ciphertext set of the copies stored in the fog storage module into the DBF for query. If it can be queried, it means it is correct, otherwise it is a faulty data block; where:

[0042] Input the ciphertext set of the corresponding leaf nodes in the challenge set where the verification fails. Locate the correct ciphertext of the leaf nodes stored in the data audit module, and map the correct ciphertext to the static filter through hashing; including finding an executable static filter in the current state. If not, create a new static Bloom filter; otherwise, map the ciphertext to the static filter SBF; n r Represents the current capacity of the SBF. Once mapped to one of the bitmaps, +1;

[0043] Traverse u SBFs and perform query operations;

[0044] Map the ciphertext copies of the leaf nodes to be verified to u SBFs in turn; perform k - time hash mapping on the ciphertext copies of the leaf nodes to be verified. If the search is successful, the mapped value is 1. When the cumulative mapped value is k, it means that the ciphertext of this leaf node can be queried, that is, this copy is correct.

[0045] Furthermore, the data update module dynamically modifies the variable Merkle hash tree and tags related to the data blocks in the fog storage module and the data audit module through the message lock encryption algorithm; including:

[0046] Modification operation: The user layer sends the index i of the data block to be updated to fog i Send the index i of the data block to be updated; fog i Find the data block, and record the path v from the leaf node where the i - th data block is located to the root node path [2 h , …, v path[i]; simultaneously find the tag T corresponding to the data block to be modified i ; the fog storage module sends the path information to the user layer; the user layer uses the main key kk mas to decrypt the node ciphertext on this path, and iteratively decrypts to finally obtain F[i], and modifies it to F[i] * ; the user layer calculates the modified variable hash tree main key through the message lock encryption algorithm and the tag T' of the modified data block i ; finally, the user layer sends T' i , the new path information v' path [2 h , ……, v' path [i] and the updated version number vv are packaged and sent to the fog storage module together; at the same time, the user layer retains the version number vv locally; the fog storage module saves all versions before and after the update, and each user controls their own version; the data audit module generates a new challenge C' based on the updated variable hash tree i , and the fog storage module generates the corresponding proof' = {AGGT″, AGGT′1, μ′} according to C' i ; the data audit module generates the verification information VI' and AGGT″, and executes the equation to determine whether the data block is complete;

[0047] Addition operation: The user layer sends the data block m to be added to the fog storage module i ; after receiving the index i, the fog storage module records the path v from the node where the i-th data block is located to the root node path [2 h , …, v path [f]; and sends the path information to the user layer; the user layer decrypts and adds this data block, and calculates the updated ciphertext c' i and the tag T' i , and then recalculates the modified variable hash tree main key The user layer sends the new path information v' from this data block to the root node path [2 h , …, v' path [2 h + 1], the data block information c', i T', i the updated version number vv are sent to the fog storage module together; the user layer retains vv locally; the fog storage module adds a new data block before the i-th data block, and records the above-mentioned updated leaf node information; updates the information of each node on the path;

[0048] Deletion operation: The user layer sends the index f of the data block to be deleted to the fog storage module; after receiving the index f, fog i finds the path v from the node where the f-th data block is located to the root node path [2 h , …, v path [f]; the fog storage module sends the node information on the path to the user layer; the user layer calculates the main key of the variable hash tree after deleting the data block Since the f-th data block needs to be deleted, the user layer calculates the new path information v' from this data block to the root node path [2 h , …, v' path [parent(i)]; the user layer packs v' path [2 h , …, v' path [parent(i)] and the updated version number vv together and sends them to the fog storage module; the user layer retains vv locally; the fog storage module deletes the data block and its ciphertext c i , and updates the node information on the path.

[0049] Beneficial effects

[0050] Compared with the traditional technical solution, the beneficial effects brought by the present invention are as follows:

[0051] Most of the existing inventions that combine data deduplication and auditing technology are based on verification operations of bilinear pairing and require complex certificate management, but their computational overhead is relatively high. The present invention provides a solution that combines PoW and data integrity auditing based on VMHT and RSA signature verification mechanism to reduce the computational overhead.

[0052] In the existing scenarios that combine deduplication and auditing, most consider the single-copy scenario. However, for the situation of recovering data after auditing failure, the multi-copy scenario is more suitable for auditing large file systems. In order to ensure that the data remains associated with the user after deduplication in the multi-copy scenario, the present invention uses threshold-based proxy re-signature to enable each replica node to cooperate in generating the re-signature key.

[0053] Most efficient auditing inventions often support the function of dynamic update of data blocks. How to achieve efficient update based on the Message-Locked Encryption (MLE) algorithm is a question worthy of consideration. UMLE has high update efficiency at the data block level and is adapted to the VMHT structure used in the present invention. Therefore, the update efficiency of the present invention is relatively high.

[0054] Meanwhile, once an incomplete set of data blocks is audited, it is also important to recover the complete data blocks. The present invention sets multiple fog nodes to store ciphertext copies and tag copies of data blocks for fault recovery. Traditional inventions generate different ciphertexts for the same file data blocks. After an audit fails, the TPA can only perform a binary search copy verification on the challenged set of tags to locate the faulty copy node. However, a large number of bilinear pairings are required in the verification process, resulting in a high computational overhead. The present invention utilizes the consistency of data block ciphertexts and tags. Once the TPA detects an audit failure, a dynamic Bloom filter is used for efficient data fault location. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] Figure 1 is a system model diagram of the present invention;

[0056] Figure 2 is a flowchart of the data upload phase

[0057] Figure 3 is a VMHT structure diagram related to the present invention;

[0058] Figure 4 is a UMLE encryption process diagram related to the present invention;

[0059] Figure 5 is a UMLE update process diagram of the present invention; DETAILED DESCRIPTION OF THE INVENTION

[0060] The following is an explanation of the present invention in conjunction with the attached Figures 1 - 5 The present invention is described as follows:

[0061] Most existing inventions that combine PoW and PDP use bilinear pairing operations to verify the data ownership of the second uploaded user and the integrity of the data blocks stored on the fog nodes. However, the multiple uses of modular exponentiation and bilinear pairing increase the computational overhead of the system, which will impose a heavy computational burden on the system. At the same time, complex key management also increases the burden on the system. In view of this, the present invention provides a multi-copy-based fog storage dynamic design and encryption deduplication system and its method, which greatly reduces the computational overhead in the PoW and PDP processes, reduces the computational cost of PoW while improving the auditing efficiency. Most efficient auditing inventions often support the function of dynamic data block updates. How to achieve efficient updates based on MLE is a question worth considering. UMLE is efficient in block-level updates and is also compatible with the tree structure used in the present invention. Therefore, the present invention uses MLE technology to encrypt data blocks so that exactly the same data blocks can generate exactly the same ciphertext, thereby ensuring the consistency of the data block ciphertext and the data block tag. To deduplicate data block tags, a message-derived key is used to generate data block tags, and only the first uploaded user needs to generate data block tags. At the same time, once an incomplete data block set is audited, how to recover the complete data blocks is also very important. The present invention sets up multiple fog nodes to store data block ciphertext copies and tag copies for fault recovery. The following is the technical solution adopted by the present invention:

[0062] Step 1: System initialization: Generate a multiplicative cyclic group based on quadratic residue modulus and public system parameters;

[0063] Specifically include: Setup(1 λ )→P: Define secure key large primes p′, q′. The KGC calculates the RSA modulus N = pq, where p = 2p′ + 1, q = 2q′ + 1 (both are large primes). Define a multiplicative cyclic group QR based on the quadratic residue modulus N N , where g is the generator of QR N . Define a SHA1 hash function, a h: Select a pseudo-random function, π2: Define a collision-resistant hash algorithm H, H0, input 1 λ , output H: {0, 1} * →Z N , H0: {0, 1} * →{0, 1} λ . Define the public system parameters P = {g, N, h, π2, H, H0}.

[0064] Step 2: Determine whether it is the user's first upload: The fog node determines whether the user is an initial upload user or a second upload user by searching for the data files uploaded by the user. The system generates a re-signature key pair for the user. If the user is uploading for the second time, the user will prove its ownership of the data block through the PoW protocol with the fog node. The system generates a derived key based on the data block information for the user, and then generates a re-signature key for the user;

[0065] Specifically, assume that user U now wants to upload a file to the fog node fog i . In the data upload stage, as shown in Table 1. U encrypts the plaintext data block using a message lock to obtain the ciphertext CT, and fog i calculates ID CT and checks whether it already has this ID CT . If it exists, it means that U is uploading for the first time; otherwise, it is a second upload. If U is uploading for the first time, the KGC generates a public-private key pair for U through the algorithm in Step 3. U constructs the data block into a VMHT and uploads the generated tags to fog i . The system generates a re-signature key pair for U through the algorithm in Step 3. If U is uploading for the second time, U will prove its ownership of the data block through the PoW protocol with fog i , and the system generates a derived key MK based on the data block information for U through the algorithm in Step 3, and then generates a re-signature key for U according to the algorithm in Step 3.

[0066]

[0067] Table 1

[0068] Step 3: Generate keys for the user: Generate a message-derived key and a re-signature key for the user who uploads for the first time. Generate a re-signature key and a message-derived key for the user who uploads for the second time;

[0069] User U inputs the security parameter 1 λ , and the KGC generates a key pair (pk, sk) for U. The KGC generates the public key pk = e and the private key sk = s for the user, such that es ≡ 1 (mod p′q′). Where e is a random and secure large prime number. In addition, the user selects another as the secret value. Let the plaintext data block F = F[1]||F[2]||…||F[n]. If the user is uploading data for the first time, then the KGC needs to calculate the message-derived key for U where k ∈ [1, n]. The KGC then calculates the corresponding message-derived public key If the user is uploading for the second time, then the user needs to perform PoW authentication and calculate MK.

[0070] The user U who uploads for the first / second time calculates the re-signature key, such that fog i (assuming there are p fog nodes in total, i ∈ [1, p]) can provide a valid proof based on the private key of U to the TPA. The KGC calculates the re-signature key RK for U i =(d, h1), where d = s·(MK i ) -1 + r, h1 = r·u. r is a random number in the group The system constructs the function F(x) = ur + a1x + a2x N +…+ a 2 on Z t-1 x t-1 , and the user U calculates the polynomial values F(1), F(2), …, F(n) (assuming there are n fog nodes in total), where F(0) = ur. U distributes i to each fog node fog through a secure channel as its private key, and the public key of fog i is The secret value F(0) = h1 can be recovered only when at least t fog nodes cooperate.

[0071] Step 4: Data upload: The user who uploads for the first time uploads the VMHT based on the file data blocks and the tag set to the fog nodes;

[0072] Initialize VMHT:, this algorithm is executed by the user U. The user who uploads for the first time inputs the plaintext of the data block. First, Algorithm 1 inputs the file data blocks F = F[1]||F[2]||…||F[n], and outputs the variable Merkle hash tree VMHT. Among them, lines 1 - 4 of the code define the initialization stage of the VMHT. In the third line, F′ is calculated through k i = H0(F1[i]). Lines 5 - 13 describe the construction of the leaf nodes in the VMHT. Each leaf node contains a tuple, and the UMLE algorithm is used to generate the ciphertext of the data block to facilitate the subsequent update of the data block. Lines 14 - 38 of the code construct the non-leaf nodes in the VMHT. First, the UMLE algorithm is used to generate the ciphertext of the data block, and then it is judged whether the number of child nodes owned by the non-leaf node is 2 or 3. Then the non-leaf nodes are iteratively generated. Finally, lines 39 - 40 introduce the master key for generating the root node of the VMHT, as shown in Table 2.

[0073]

[0074] Table 2

[0075] U first generates the hash value h for the ciphertext of each leaf node i = H(c i)。Next, U calculates the label for each leaf node U sends the variable Merkle hash tree VMHT and the label of each leaf node to fog together i . U sends the public key pk and VMHT V to the TPA.

[0076] Step Five: Data Audit: The TPA audits the VMHT and the label set stored on the fog nodes;

[0077] It includes three sub-algorithms Challenge, ProofGen, and Auditing from TPA; specifically: Challenge: As shown in the second line of the code, the TPA randomly selects non-leaf nodes at different levels from the tree and parses which leaf nodes the non-leaf node consists of (corresponding to lines 5-9 of the code). The TPA takes these leaf nodes as challenge blocks (line 17 of the code), and the TPA then randomly selects a seed d2 from the group . Thus, C i ={D i , S i , l, r, ln, d2}. The TPA sends C i to each fog i respectively. For each j ∈ [1, ll1], the TPA selects b j =π2(j, d2) and sends it to fog i , as shown in Table 3.

[0078]

[0079] Table 3

[0080] ProofGen: As shown in the algorithm in Table 4, fog i retrieves the corresponding leaf nodes in each challenge C i (corresponding to lines 1-5 of the code). Next, fog Figure 4 searches for the labels of the challenged data blocks according to the set of challenged data blocks r1 (corresponding to line 6 of the code), calculates the aggregated label i In addition, fog Figure 4 calculates the set of ciphertexts of the challenged data blocks The last fog node fog i calculates and aggregates the aggregated labels from different fog nodes to generate n fog and sends fog i sends to the TPA.

[0081] Table 4

[0082]

[0083] Auditing from TPA: As shown in the algorithm in Table 5, the TPA calculates the hash value of the ciphertext data block , thus calculating the verification information: After the TPA receives the proof sent by fog i , it sends T to U again, and U calculates and generates The TPA obtains The TPA determines whether the data block and its tag are complete by verifying the following equation:

[0084]

[0085] Table 5

[0086]

[0087] Step 6: Perform PoW verification on the users uploaded for the second time: The fog node performs PoW verification on the users uploaded for the second time;

[0088] If the ID of the user CT shows that it already exists, which means the user is uploading the file for the second time. Then, in order to prove the ownership of the file, the user will execute the PoW protocol with fog i . The specific process is as follows:

[0089] ChalGen: Similar to the challenge generation process of auditing, fog i randomly selects a seed d2 from the group . From this, a challenge C i = l, r, ln, d3 is formed.

[0090] ProofGen: U parses the corresponding challenged data blocks according to r2 and ll2, and calculates a j ∈ r2, $b j = π2(j, d3)$ for each j ∈ [1, ll1]. Then, U searches for the tags of the challenged data blocks according to the challenged data block set r1, and then generates an aggregated tag At the same time, U generates a subtree according to the challenge C i . Then U calculates In addition, U selects a random number rr ∈ Z N , and calculates Finally, U packs proof = {T, T1, μ, u} and the ciphertext of the corresponding subtree root node together to form P i and sends it to fogi . U sends the auxiliary information of the node to be verified and C i to fog together i .

[0091] PoW Auditing from fog i : fog i According to the challenged data blocks in chal (t) and the auxiliary information AAI sent by U, fog i retrieves these challenged blocks and generates the root node ciphertext CT′ root , and compares it with the stored root node ciphertext value CT root . If they are the same, continue to verify the aggregation tag. Otherwise, it means the verification fails, and fog i will fuzzily locate the set of damaged data blocks according to l and r of this data block. Once the root node ciphertexts are the same, fog i calculates the hash value of the data block ciphertext and calculates the verification information: U calculates and generates and sends it to fog i . fog i Judges U's ownership of the data copy by verifying the following equation and comparing whether the ciphertext values of the root nodes of the two subtrees are equal:

[0092]

[0093] If the verification is successful, it means U owns the data copy, and fog i stores its re-signature key RK. Otherwise, U is not the actual owner of the data copy. If U is the actual owner of the data copy, then the subsequent data integrity auditing process is the same as before.

[0094] Step Seven: Fault Location: If the data audit fails, the TPA locates the damaged data blocks and their tag copies;

[0095] When the TPA verification fails, it can locate which set of copies has failed. The present invention uses a dynamic Bloom filter (DBF). Once the audit result is a failure, the ciphertexts of the challenged block sets stored in the TPA can be mapped to the DBF in sequence, and the ciphertext sets of the copies stored in the fog nodes can be input into the DBF in sequence for query. If it can be queried, it means it is correct, otherwise it is a faulty data block. The same method is used to verify the data block tags.

[0096] As shown in Table 6, first, input the ciphertext set of the corresponding leaf nodes in the challenge set where the verification fails. The TPA locates the ciphertext of the correct leaf node stored thereon and maps the correct ciphertext to the SBF through hashing. The specific operations are as follows: Check whether there is an Active SBF in the current state. If not, create a new SBF and increment the value of u by 1. If there is, map the ciphertext to the Active SBF. n r Indicates the current capacity of the SBF, and +1 when mapping to one of the bitmaps.

[0097] Table 6

[0098]

[0099] As shown in Table 7, traverse the u SBFs and perform query operations. Map the ciphertext copies of the leaf nodes to be verified to the u SBFs in sequence. Perform k - time hashing mapping on the ciphertext copies of the leaf nodes to be verified. If the search is successful, the mapping value is 1. When the cumulative mapping value is k, it indicates that the ciphertext of this leaf node can be queried, that is, this copy is correct.

[0100] Table 7

[0101]

[0102] Step Eight: Dynamic Update: The user applies for dynamic update of the data block, and the fog node and the TPA use UMLE to update the data block and label stored thereon;

[0103] Modification Operation: When user U applies to modify the data block, it is necessary to complete the modification of the data block through the interaction with fog i The specific process is as follows: U sends the index i of the data block to be updated to fog i . fog i finds this data block and records the path v path [2 h , …, v path [i] (assuming the tree height is h) from the leaf node where the i - th data block is located to the root node. Then, fog i finds the label T i corresponding to the data block to be modified. Finally, fog i sends the path information to U. U decrypts the node ciphertext on this path using the main key kk mas and iteratively decrypts to finally obtain F[f], and modifies it to F[f] * . As shown by Figure 5 , U calculates the modified VMHT main key and the label T′ i of the modified data block through UMLE. Finally, U sends T′ i, the new path information v′ path [2 h , ……, v′ path [i] and the updated version number vv are packaged and sent to fog i . U will retain the version number vv locally. fog i saves all versions before and after the update, and each user controls their own version. TPA generates a new challenge C′ according to the updated VMHT i , fog i generates the corresponding proof′ = {AGGT″, AGGT′1, μ′} according to C′ i . TPA generates verification information VI′ and AGGT″, and executes the equation to determine whether the data block is complete.

[0104] Addition operation: Similar to the process of modifying the data block. When a user wants to add a data block, they need to complete the addition of the data block through protocol interaction with fog i . The specific process is as follows: The user sends the data block m to be added to fog i . After fog i receives the index i, fog i records the path v from the node where the i-th data block is located to the root node i [2 path , …, v h [i]. Finally, fog path sends the path information to U. After U decrypts it, it adds the data block, calculates its ciphertext c′ i and the tag T′ i , and then recalculates the main key of the modified VMHT i . U sends the new path information v′ from this data block to the root node [2 path , …, v′ h [2 path +1], the data block information c′ h , T′ i , and the updated version number vv to fog i together. U will i retain vv locally. fog adds a new data block before the i-th data block and records its information set. fog i updates the information sets of each node on the path. i Deletion operation: When a user wants to delete a data block, they need to communicate with fog

[0105] i ​The interaction between them is to complete the deletion of data blocks. The specific process is as follows: The user sends the index i of the data block to be deleted to fog i After fog receives the index i, fog i finds the path v i from the node where the i-th data block is located to the root node path [2 h , …, v path [i]. Finally, fog sends the node information on the path to U. U calculates the main key of the VMHT after deleting the data block Since the f-th data block needs to be deleted, U calculates the new path information v' path [2 h , …, v' path [parent(i)]. Finally, U packs v' path [2 h , …, v' path [parent(i)] and the updated version number vv together and sends them to fog i . U retains vv locally. fog i deletes the data block and its ciphertext c i , and updates the node information on the path. The auditing process is the same as above

[0106] Step Nine: User Decryption: The user downloads the file from the fog node and decrypts it to obtain the plaintext;

[0107] As shown in Table 8; if the data blocks stored on fog i are complete, then U requests to download the data and decrypts it to obtain the plaintext. The decryption process is divided into the decryption of the data block key and the decryption of the data block ciphertext. The specific process is as follows: U inputs the main key kk mas of the root node, and the ciphertexts of each non-leaf node. It shows the process of gradually decrypting from the layer where the root node is located to the layer above the leaf node. The plaintext of the parent node obtained by decryption can be split into the keys of its respective child nodes, so as to obtain the plaintext of the child nodes, and this process is iterated. Finally, lines 9-12 judge whether the number of child nodes of the parent node is odd. If so, an additional key is split (i.e., when the number of nodes in the VMHT is 2 n +1). When U obtains k1, …, k n , it decrypts to obtain the data block plaintext through F i = Dec(k i , c i ), where i ∈ [1, n].

[0108] Table 8

[0109]

[0110] Although the present invention has been described above, the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative rather than restrictive. Under the inspiration of the present invention, those of ordinary skill in the art can also make many variations without departing from the gist of the present invention, and all of these fall within the scope of protection of the present invention.

Claims

1. A multi-copy based fog storage dynamic auditing and encrypted deduplication system, characterized in that; The system includes: a data preprocessing module, a user layer, a key generation module, a fog storage module, a data auditing module, a data PoW verification module, a data fault location module, and a data update module; where: The data preprocessing module obtains public system parameters by constructing a multiplicative cyclic group of quadratic residue moduli; The fog storage module determines the user type by searching for the uploaded data files through fog nodes; including: The user layer encrypts the ciphertext of the plaintext data block with the updated message lock and uploads it. The fog node calculates to check whether the fog storage module already has this If it exists, it is the second upload user; otherwise, it is the first upload user. Among them: If it is the first-time uploading user, the key generation module generates a public key for the TPA, configures a re-signature key and a message-derived key for the first-time uploading user; meanwhile, the user layer uploads the variable Merkle hash tree related to the data block and the tag set to the fog storage module; the fog storage module performs PoW verification on the second-time uploading user to verify its ownership of the data block; and the key generation module configures a message-derived key and a re-signature key for the second-time uploading user; The data auditing module aggregates the data block ciphertext and the tag copy through the proxy re-signature algorithm of the threshold, and the TPA audits the aggregated result; the TPA performs fault query and location after the audit of the fog storage module fails; The data update module dynamically modifies the variable Merkle hash tree and the tag set in the fog storage module and the data auditing module through the updated message lock encryption algorithm; The user layer downloads the file from the fog storage module and decrypts it to obtain the plaintext of the data block.

2. The multi-copy based fog storage dynamic auditing and encrypted deduplication system according to claim 1, wherein: The user layer uploads the data block with the variable hash tree and the tag set in the first-time uploading user file to the fog storage module; including: Generate plaintext data blocks: Initialize and establish a variable hash tree for the plaintext data block: Construct a relevant information set for the leaf nodes of the variable hash tree; Construct non-leaf nodes for the variable hash tree; Construct the master key of the variable hash tree root node for the non-leaf nodes; The user layer generates a hash value for the ciphertext of each leaf node of the variable hash tree; Establish the calculation tag for each leaf node; Send the variable Merkle hash tree and the tag of each leaf node to the fog storage module together.

3. A multi-copy based fog storage dynamic auditing and encryption deduplication system according to claim 2, characterized in that: The specific algorithm of the data audit module randomly selects different non-leaf nodes from the variable hash tree, parses which leaf nodes the non-leaf node consists of, and then generates a challenge ; The TPA will challenge and send them to each fog node respectively; The specific algorithm of the data auditing module is that the fog storage module retrieves each challenge for the corresponding leaf node in it; According to the set of challenged data blocks search for the challenged data block tags, and aggregate the data block ciphertexts with the corresponding tags; At the same time, aggregate the generated aggregate tags from different fog nodes to generate a proof and send it to the data auditing module; Specific algorithm of the data audit module: The TPA calculates the hash value of the ciphertext data block , and then calculates the verification information; The TPA determines whether the data block and its tag stored on the fog storage module are complete through the verification equation.

4. A multi-copy based fog storage dynamic auditing and encrypted deduplication system according to claim 1, characterized in that: The process of the data auditing module performing fault query and location after the audit of the variable Merkle hash tree and the tag set in the fog storage module fails; including: Map the ciphertexts of the audit challenge block sets stored in the data auditing module to the dynamic filter DBF in sequence, and input the ciphertext sets of the copies stored in the fog storage module into the DBF for query in sequence. If a query is found, it means it is correct, otherwise it is a faulty data block; where: The ciphertext set of the corresponding leaf nodes in the challenge set where input verification fails. Locate the ciphertext of the correct leaf node stored thereon in the data audit module, and map the correct ciphertext to the static filter through hashing; including finding an executable static filter in the current state. If not, create a new static Bloom filter; otherwise, map the ciphertext to the static filter SBF through hashing. Indicates the current capacity of SBF, and increment by 1 once mapped to one of the bitmaps. Traverse SBFs and perform query operations; Map the ciphertext copies of the leaf nodes to be verified to SBFs in turn; perform hash mappings on the ciphertext of the leaf node copies to be verified. If the lookup is successful, the mapped value is 1. When the cumulative mapped value is , it indicates that the ciphertext of this leaf node is the one queried, that is, this copy is correct.

5. A multi-copy based fog storage dynamic auditing and encrypted deduplication system according to claim 1, characterized in that: The process of the data update module dynamically modifying the variable Merkle hash tree and the tag related to the data block in the fog storage module and the data auditing module through the message lock encryption algorithm; including: Modify operation: User level Send the index of the data block to be updated Find the data block and record the The path from the leaf node where the data block is located to the root node ; At the same time, find the label corresponding to the data block to be modified The fog storage module sends the path information to the user layer Use master key Decrypt the node ciphertext on the path, iterate the decryption and finally get , and change it to ; The user layer calculates the modified variable hash tree master key through the message lock encryption algorithm and the label of the modified data block ; Finally, the user layer will , New path information And the updated version number All of them are packaged and sent to the fog storage module; at the same time, the user layer , version number Keep it locally; the fog storage module saves all versions before and after the update, and each user controls their own version; the data audit module generates a new challenge based on the updated variable hash tree , the fog storage module is based on Generate the corresponding Generate verification information and , execute equation Determine whether the data block is complete; Addition operation: The user layer sends the data block to be added to the fog storage module ; After the fog storage module receives the index , it records the path from the node where the th data block is located to the root node and sends the path information to After decryption, add the data block, calculate the updated ciphertext and the tag , and then recalculate the main key of the modified variable hash tree Send the new path information from this data block to the root node , the data block information , the updated version number to the fog storage module together; The user layer will , be retained locally; The fog storage module adds a new data block before the th data block and records the updated leaf node information; Update the information of each node on the path; Deletion operation: The user layer sends the index of the data block to be deleted to the fog storage module ; After receiving the index the fog storage module finds the path from the node where the th data block is located to the root node and sends the node information on the path to the user layer; The user layer calculates the main key of the variable hash tree after deleting the data block Since the th data block needs to be deleted, the user layer calculates the new path information from this data block to the root node and packs and sends it together with the updated version number to the fog storage module; The user layer retains and locally; The fog storage module deletes the data block and its ciphertext and updates the node information on the path .

6. A multi-copy-based dynamic auditing and encrypted deduplication method for fog storage, characterized in that: The method is executed based on any one of claims 1-5.

Citation Information

Patent Citations

  • Block-level data de-duplication method for supporting dynamic ownership management in fog storage

    CN108776758A

  • Cloud data de-duplication method based on certificateless agent re-encryption

    CN110213042A