An Identity-Based Cloud Storage Integrity Detection Method and System on Lattices

By adopting the identity authentication method of grid cryptography in cloud storage, the problem of traditional public key cryptography being cracked by quantum computing and data information leakage is solved, and the security and data privacy protection against quantum computing are achieved.

CN119892511BActive Publication Date: 2025-07-01NANJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510368968.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-07-01
Estimated Expiration
2045-03-27

AI Technical Summary

Technical Problem

The traditional public key cryptography system faces the risk of being cracked by quantum computers, and there is a problem of user data leakage during third-party public audits.

Method used

Using cryptography, identity-based cloud storage integrity detection method, the system parameters are generated through the key generation center PKG, and the private keys of the user and the cloud server are generated. The user blocks the data files and signs them, and uploads them to the cloud server. The third-party public audit TPA uses two-time masking technology to ensure that the user's data information is not leaked during the verification process.

Benefits of technology

Effectively resist quantum computing attacks, improve computing efficiency, reduce computing costs, ensure privacy protection of data information, and prevent cloud servers from forging legal proofs through third-party audits.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119892511B_ABST
    Figure CN119892511B_ABST
Patent Text Reader

Abstract

The present invention proposes a lattice-based identity-based cloud storage integrity detection method and system. Using lattice cryptography technology, system parameters are generated according to the key generation center PKG. The private keys of the user User and the cloud server CS are generated by the PKG to complete key distribution. User divides the data file into smaller data blocks, signs them, and sends them to CS for storage to complete data upload. Due to the small data blocks, the computational efficiency of the new method is improved. According to the audit request sent by User, the third-party public auditor TPA sends challenge information, CS returns proof information and is verified by TPA. Through two masking techniques, the data information of the user is not leaked during the verification process. The method proposed by the present invention is based on the difficult problems on the lattice, can effectively resist quantum computing attacks and ensure the robustness of the scheme.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data storage, and in particular, to an identity-based cloud storage integrity detection method and system on a lattice. Background Art

[0002] In 2007, the proposal of the Provable Data Possession (PDP) model provided a theoretical basis for data integrity and availability, enabling users to verify the integrity of their data without directly accessing it. In the same year, the concept and formal model of Proof of Retrievability (POR) were proposed. The sentinel-based POR verification mechanism can not only identify whether remote data is damaged but also recover damaged data files. Although the PDP and POR models provide effective solutions for data integrity and availability verification, the auditing work of these models needs to be completed by users themselves, which will impose a burden on resource-constrained users. To reduce the computational burden of users, subsequent research proposed the Third Party Auditing (TPA) mechanism, allowing the TPA to verify the integrity of data stored in a cloud server on behalf of the user. Without downloading the data, the user can rely on the audit results of the TPA to confirm the integrity of the data.

[0003] In addition, with the development of quantum computers, the traditional public key cryptosystem faces the risk of being cracked by quantum computers, thus threatening the security of the above auditing schemes. To address this challenge, Post-Quantum Cryptography (PQC) has gradually become a research hotspot. Among them, lattice cryptography has attracted much attention due to its strong security and computational efficiency. The Small Integer Solution (SIS) and Learning With Errors (LWE) problems on lattices are still considered difficult in the context of quantum computing, giving lattice cryptography significant advantages in resisting quantum computing attacks.

[0004] Identity-based cryptosystems have, to a certain extent, solved the problem of high-cost certificate management based on PKI technology. In identity-based cryptosystem solutions, the identity of a user, such as name, ID number, email address, etc., is regarded as the public key, while the private key of the user is generated by the PKG for the user. Existing lattice-based cloud storage integrity detection schemes are usually based on the small integer solution problem on ideal lattices, enabling the scheme to maintain high security in a quantum computing environment. And a new tag generation algorithm and private key extraction algorithm are designed, where the user calculates the file block tags using the private key. The design of this scheme does not consider the problem of data information leakage during the integrity proof process. In view of the defects of existing cloud storage integrity auditing schemes, the existing technology proposes a new lattice-based identity-based remote data integrity auditing protocol. The scheme supports third-party public auditing and does not disclose the information of the user's stored data during the auditing process. Through the research of existing schemes, it is found that they cannot provide privacy protection for messages during the authentication process. The cloud server can forge a legal proof and pass the verification of the third-party public audit without completely storing the data uploaded by the user. Summary of the Invention

[0005] Aiming at the risk that traditional public key cryptosystems are vulnerable to being cracked by quantum computers and the problem of user data information leakage existing in the third-party public auditing process, the present invention proposes a lattice-based identity-based cloud storage integrity detection method and system to solve the problems raised in the above background technology. The technical solutions provided by the present invention are as follows:

[0006] In a first aspect, the present invention proposes a lattice-based identity-based cloud storage integrity detection method, including the following steps:

[0007] S1, in the form of lattice cryptography, the key generation center PKG generates system parameters, and according to the system parameters, the key generation center PKG generates the private keys of the user User and the cloud server CS;

[0008] S2, the user User divides the data file into blocks and signs it, and uploads it to the cloud server CS;

[0009] S3, the user User issues an audit request, the third-party public audit TPA generates and issues challenge information, the cloud server CS generates and returns proof information and is verified by the third-party public audit TPA. The verification process uses the double masking technique. By whether two equations and two inequalities hold, the integrity of the data is judged. The verification formulas are as follows:

[0010]

[0011] Among them, B is the public key of user User, and Q is the public key of cloud server CS; q, n, and m are system parameters generated by key generation center PKG, where q is a prime number, n and m are two integers, ω is the time complexity related to n; mod is the remainder function;

[0012] σ is a parameter in the process of user User signing the data file, satisfying the inequality is the system master private key T A orthogonal basis norm;

[0013] {u' c ,e c ,ω,value,Q'} is the proof information generated and returned by cloud server CS, where u' c = u c + ξH2(ω), m i is the data block after the data file is segmented, {s1,...,s n} is a set defined by third-party public auditor TPA. For any element in the set, a random matrix c i is generated to produce challenge information, and ξ is a short vector generated by cloud server CS after receiving the challenge information, used to introduce errors; e i is the tag of data block m i ; value = β + ξH2(ω), β is the short vector generated in the process of user User signing the data block; Q' = Q·β;

[0014] h' c = Cλ' c , where C = (α1,α2,...,α n ) T , α j = H3(B||τ||j), j ≤ n, τ is the tag of the data file;

[0015] H1, H2, and H3 are all hash functions selected by key generation center PKG.

[0016] Preferably, the process of key generation center PKG generating system parameters is as follows:

[0017] S111, select two prime numbers q and p, two integers m, n, and a real number ζ, where p << q, poly and ω represent the time complexity related to n, satisfying the following relationship:

[0018] m, ζ = poly(n)

[0019] m ≥ 2nlogq

[0020]

[0021] S112, The key generation center PKG selects four hash functions, which are respectively represented as follows:

[0022]

[0023] S113, The key generation center PKG uses the trapdoor generation algorithm to generate the matrix and the lattice basis T A , A is the system public parameter, and T A is the master private key of the system.

[0024] Preferably, the key generation process is as follows:

[0025] S121, According to the system parameters, the user User and the cloud server CS respectively send the identity information id u and id s to the key generation center PKG, and the key generation center PKG generates the public key B of the user User and the public key Q of the cloud server CS, which are represented as:

[0026]

[0027] S122, The key generation center PKG uses the NewBasisDel algorithm to generate the private keys T id and T Q of the user User and the cloud server CS, which are represented as:

[0028] T id = NewBasisDel(A, R u , T A , s)

[0029] T Q = NewBasisDel(A, R s , T A , s)

[0030] NewBasisDel is a probabilistic polynomial time algorithm, and the parameter s satisfies the inequality and

[0031] S123, The key generation center PKG sends the private keys to the user User and the cloud server CS respectively through a secure channel for storage.

[0032] Preferably, the process of the user User splitting and signing the data file and uploading it to the cloud server CS is as follows:

[0033] S21. The user User adopts any digital signature algorithm, and its signature public and private keys are (spk, ssk) respectively. The short vector is generated by using the SamplePre algorithm β satisfies B·β = 0, which is expressed as:

[0034] β = SamplePre(B, T id , 0, σ)

[0035] SamplePre is also a probabilistic polynomial-time algorithm, and the parameter σ satisfies the inequality

[0036] S22. Calculate Q′ = Q·β. The user User divides the data file F into data blocks, that is Use the signature private key ssk to generate a signature for the message name‖Q’. name is the data file name, and the label τ of the data file F is set to name||Q′||Sig ssk (name||Q′). The user User calculates

[0037] S23. For the data block Combine its own public key B with the public key Q of the cloud server and calculate The user User calculates the inner product And set h i =(h i1 , h i2 ,…, h in );

[0038] S24. The user User calculates the label e i of the data block m i = SamplePre(B, T id , h i , σ). The parameter σ satisfies the inequality The label set of all data blocks Finally, {φ, F, Q′, τ, β} is sent to the cloud server, and the locally stored file F is deleted.

[0039] Preferably, the challenge information generated by the third-party public audit TPA includes:

[0040] The third-party public audit TPA defines the set I = {s j}(1 ≤ j ≤ n) and s1 ≤ … ≤ s n , For any element i in the set I, a matrix is randomly selected Generate the challenge information chal = {τ, i, c i} i∈I, and send the challenge information to the cloud server CS.

[0041] Preferably, the proof information returned by the cloud server CS includes:

[0042] Based on the received challenge information, the cloud server CS selects data blocks {m i} i∈I and the corresponding tags {e i} i∈I and calculates randomly select a vector Generate a short vector ξ using the SamplePre algorithm, expressed as:

[0043] ξ = SamplePre(Q, T Q , ω, σ)

[0044] The cloud server CS calculates value = β + ξH2(ω), u c ′ = u c + ξH2(ω), and generates proof information Proof = {τ, u c ′, e c , ω, value, Q′} and sends it to the third-party public auditor TPA.

[0045] Preferably, the verification process of the third-party public auditor TPA includes:

[0046] S31, after receiving the proof information from the cloud server CS, the third-party public auditor TPA uses the user User's signature public key spk to verify the legality of the tag τ. If it is legal, continue the verification;

[0047] S32, calculate α j = H3(B || τ || j), let C = (α1, α2,..., α n ) T ;

[0048] S33, calculate Calculate h c ′ = Cλ c ′;

[0049] S34, verify whether the equations Be c = h c ′ (mod q) and Q · value = Q′ + ωH2(ω) hold, and whether the inequalities and hold; if all hold, the third-party public auditor TPA accepts the evidence and deems the information legal; otherwise, the proof information is illegal and the integrity of the stored data is damaged.

[0050] In a second aspect, the present invention proposes a lattice-based identity-based cloud storage integrity detection system, including the following modules:

[0051] A key distribution module, which is used to generate private keys for a user User and a cloud server CS by a key generation center PKG according to system parameters generated by the key generation center PKG, and complete key distribution;

[0052] A data upload module, which is used to block and sign a data file according to the user User and upload it to the cloud server CS;

[0053] A verification module, which is used to issue an audit request according to the user User, the third-party public auditor TPA issues challenge information, the cloud server CS returns proof information and is verified by the third-party public auditor TPA. Through two masking techniques, it is ensured that the user's data information is not leaked during the verification process.

[0054] Compared with the prior art, the beneficial effects achieved by the present invention are as follows:

[0055] The method of the present invention is based on the ISIS problem and the SIS problem on the lattice, and can effectively resist quantum computing attacks; by dividing the file into data blocks, the data blocks are smaller, the computing efficiency is improved, and the computing cost is reduced; during the third-party audit process, through two masking techniques, it is ensured that the user's data information is not leaked during the verification process, providing privacy protection for messages, and preventing the cloud server from forging legal proofs to pass the public verification of the third-party audit when the user's uploaded data is not completely saved. The method proposed by the present invention has correctness, privacy, robustness, and anti-quantum security. Description of the Drawings

[0056] The drawings are used to provide further understanding of the present invention, and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention, and do not constitute a limitation to the present invention. In the drawings:

[0057] Figure 1 is a schematic model diagram of the system of the present invention;

[0058] Figure 2 is an interactive schematic diagram of the algorithm of the present invention. Detailed Embodiments

[0059] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0060] Please refer to Figure 1 - Figure 2 , the present invention provides a technical solution:

[0061] Embodiment 1:

[0062] An identity-based cloud storage integrity detection method on a lattice, as Figure 1 shown, includes the following steps:

[0063] S1. In the form of lattice cryptography, a key generation center PKG generates system parameters. According to the system parameters, the key generation center PKG generates private keys for a user User and a cloud server CS.

[0064] The process of the key generation center PKG generating system parameters is as follows:

[0065] S111. Select two prime numbers q and p, two integers m, n, and a real number ζ, where p << q, poly and ω represent the time complexity related to n, and satisfy the following relationships:

[0066] m, ζ = poly(n)

[0067] m ≥ 2nlogq

[0068]

[0069] S112. The key generation center PKG selects four hash functions, which are respectively represented as follows:

[0070]

[0071] S113. The key generation center PKG uses a trapdoor generation algorithm to generate matrices and lattice basis T A , A is the system public parameter, T A is the master private key of the system.

[0072] The process of the key generation center PKG generating keys is as follows:

[0073] S121. According to the system parameters, the user User and the cloud server CS respectively send identity information id u and id s to the key generation center PKG, and the key generation center PKG generates a public key B for the user User and a public key Q for the cloud server CS, which are represented as:

[0074]

[0075]

[0076] Hash function There are multiple selection methods, such as the common and more secure SHA-1 algorithm, SHA-256 algorithm, SM3 algorithm, etc. By calling these algorithms, a hash value of a certain length can be obtained. The following method can be used to generate an m×m column matrix: taking the matrix R u as an example, construct an upper triangular matrix with all diagonal elements being 1, and then fill in the obtained hash value in sequence, and fill the remaining part with 0.

[0077] S122, the key generation center PKG uses the NewBasisDel algorithm to generate the private keys T id 、T Q of the user User and the cloud server CS, which are expressed as:

[0078] T id =NewBasisDel(A,R u ,T A ,s)

[0079] T Q =NewBasisDel(A,R s ,T A ,s)

[0080] NewBasisDel is a probabilistic polynomial time algorithm, and the parameter s satisfies the inequality and T id 、T Q are respectively and short lattice bases.

[0081] S123, the key generation center PKG sends the private keys to the user User and the cloud server CS respectively through a secure channel for storage.

[0082] S2, the user User divides the data file into blocks and signs it, and uploads it to the cloud server CS. The specific process is as follows:

[0083] S21, the user User uses any digital signature algorithm, and its signature public and private keys are (spk, ssk) respectively. The SamplePre algorithm is used to generate a short vector β that satisfies B·β = 0, which is expressed as:

[0084] β=SamplePre(B,T id ,0,σ)

[0085] The SamplePre algorithm first selects a random vector that satisfies B·β = 0 by linear algebra. Then, the algorithm SampleD(T id ,σ,-β) is used to obtain a vector that conforms to the Gaussian distribution Sample d, where the parameter σ satisfies the inequality The vector e ∈ D is obtained from the equation e = β + d n .

[0086] S22, calculate Q′ = Q·β, and the user User divides the data file F into data blocks, namely Generate a signature for the message name‖Q’ using the signature private key ssk, where name is the data file name, and set the tag τ of the data file F = name||Q′||Sig ssk (name||Q′), and the user User calculates

[0087] S23, for the data block Combine its own public key B with the public key Q of the cloud server and calculate The user User calculates the inner product and set h i =(h i1 ,h i2 ,…,h in );

[0088] S24, the user User calculates the tag e i of the data block m i =SamplePre(B,T id ,h i ,σ), where the parameter σ satisfies the inequality The tag set of all data blocks Finally, {φ,F,Q′,τ,β} is sent to the cloud server, and the locally stored file F is deleted.

[0089] S3, as Figure 2 shown, the user User issues an audit request, the third-party public auditor TPA generates and issues challenge information, the cloud server CS generates and returns proof information and is verified by the third-party public auditor TPA, and the verification process uses the two-mask technology. Specifically, in the data integrity verification phase, the third-party public auditor TPA determines the data integrity by whether two equations and two inequalities hold.

[0090] The third-party public auditor TPA generates challenge information including:[[]]

[0091] The third-party public auditor TPA defines the set I = {s j}(1 ≤ j ≤ n) and s1 ≤ … ≤ s n , For any element i in the set I, randomly select a matrix Generate the challenge information chal = {τ,i,c i}i∈I , and send the challenge information to the cloud server CS.

[0092] The cloud server CS returns the proof information including:

[0093] The cloud server CS selects data blocks {m i} i∈I and the corresponding tags {e i} i∈I and calculates Randomly select a vector Use the SamplePre algorithm to generate a short vector ξ, expressed as:

[0094] ξ = SamplePre(Q, T Q , ω, σ)

[0095] The cloud server CS calculates value = β + ξH2(ω), u c ′ = u c + ξH2(ω), and Generates the proof information Proof = {τ, u c ′, e c , ω, value, Q′} and sends it to the third-party public auditor TPA.

[0096] Among them, the vector ξ introduces an error to the values of β and u c . Due to the difficulty of the LWE problem in lattice cryptography, at this time, the third-party public auditor TPA cannot calculate the data blocks through the proof information, thus ensuring the privacy protection of the user User's information.

[0097] The verification process of the third-party public auditor TPA includes:

[0098] S31, after receiving the proof information from the cloud server CS, the third-party public auditor TPA uses the user User's signature public key spk to verify the legitimacy of the tag τ. If it is legitimate, continue the verification;

[0099] S32, calculate α j = H3(B || τ || j), let C = (α1, α2,..., α n ) T ;

[0100] S33, calculate Calculate h c ′ = Cλ c ′;

[0101] S34, verify the equation Be c = h cWhether ′(modq) and Q·value = Q′+ωH2(ω) hold, and whether the inequalities and hold; if all hold, the third-party public audit TPA accepts the evidence and deems the information legal; otherwise, it proves that the information is illegal and the integrity of the stored data is damaged.

[0102] From the ISIS problem and SIS problem in lattice cryptography, if the cloud server CS does not completely store the data file F uploaded by the user User and its signature set φ, first select e c and the value of ω, the above verification equation can be transformed into and u c ’ is a small value. To calculate the value of u c ’ through this equation, that is, the ISIS problem, is computationally infeasible. Therefore, it is ensured that the cloud server can only pass the verification of the TPA when it completely stores the data file uploaded by the user and its signature set, preventing the cloud server from forging the proof.

[0103] Embodiment 2:

[0104] An identity-based cloud storage integrity detection system on a lattice, as Figure 1 shown, includes the following modules:

[0105] The key distribution module is used to generate the private keys of the user User and the cloud server CS by the key generation center PKG according to the system parameters generated by the key generation center PKG to complete the key distribution;

[0106] The data upload module is used to block and sign the data file according to the user User and upload it to the cloud server CS;

[0107] The verification module is used to issue an audit request according to the user User, the third-party public audit TPA issues challenge information, the cloud server CS returns proof information and is verified by the third-party public audit TPA. Through two masking techniques, it is ensured that the user's data information is not leaked during the verification process.

[0108] Those skilled in the art can clearly understand that each implementation can be realized by means of software plus a necessary general hardware platform, and of course, it can also be realized by hardware. Based on such an understanding, the above technical solution, in essence, or the part that contributes to the existing technology can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disc, etc., and includes several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0109] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions recorded in the foregoing embodiments or perform equivalent replacements on some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A cloud storage integrity detection method based on identity on a grid, characterized in that: The following steps are involved: S1, the key generation center PKG generates system parameters in the form of a lattice password, and based on the system parameters, the key generation center PKG generates the private keys of the user User and the cloud server CS; S2, user User divides the data file into blocks, signs it, and uploads it to the cloud server CS; S3, user User issues an audit request, the third-party public audit TPA generates and issues a challenge message, the cloud server CS generates and returns the proof information and is verified by the third-party public audit TPA. The verification process uses double masking technology to determine the integrity of the data by checking whether two equations and two inequalities are true or not. The verification formula is as follows: Among them, B is the public key of user User, and Q is the public key of cloud server CS; q, n and m are system parameters generated by the key generation center PKG, where q is a prime number, n and m are two integers, ω is the time complexity related to n; mod is the modulo function; σ is the parameter used by the user to sign the data file, satisfying the inequality Is the system master private key T A The orthogonalized basis norm of ; {u' c ,e c ,ω,value,Q'} is generated by the cloud server CS and returns the proof information, where u' c =u c +ξH2(ω), m i is the data block after the data file is divided into blocks, {s1,...,s n } is a set defined by the third-party public audit TPA. For any element in the set, a matrix c is randomly selected. i Generate challenge information, ξ is a short vector generated by the cloud server CS after receiving the challenge information, which is used to introduce errors; e i is the data block m i label; value = β + ξH2(ω), β is the short vector generated by the user User in the process of signing the data block; Q' = Q·β; h' c =Cλ' c , where C = (α1, α2, ..., α n ) T , α j =H3(B‖τ‖j), j≤n, τ is the label of the data file; H1, H2 and H3 are hash functions selected by the key generation center PKG.

2. According to claim 1, a cloud storage integrity detection method based on identity on a grid is characterized in that: The process of the key generation center PKG generating system parameters is as follows: S111, select two prime numbers q and p, two integers m and n, and a real number ζ, where p<<q, poly and ω represent the time complexity related to n, and satisfy the following relationship: m,ζ=poly(n) m ≥ 2nlogq S112, the key generation center PKG selects four hash functions, which are respectively expressed as follows: S113, the key generation center PKG uses the trapdoor generation algorithm to generate the matrix Passive Base T A , A is the system common parameter, T A Is the master private key of the system.

3. The identity-based cloud storage integrity detection method according to claim 2, characterized in that: The key generation process is: S121, according to the system parameters, the user User and the cloud server CS respectively send the identity information id u and id s It is sent to the key generation center PKG, which generates the public key B of the user User and the public key Q of the cloud server CS, expressed as: S122, the key generation center PKG uses the NewBasisDel algorithm to generate the private key T of the user User and the cloud server CS id , T Q , expressed as: T id =NewBasisDel(A,R u ,T A ,s) T Q =NewBasisDel(A,R s ,T A ,s) NewBasisDel is a probabilistic polynomial time algorithm with parameter s satisfying the inequality and S123, the key generation center PKG sends the private key to the user User and the cloud server CS through a secure channel for storage.

4. The identity-based cloud storage integrity detection method according to claim 3 is characterized in that: The process of user User dividing the data file into blocks, signing it, and uploading it to the cloud server CS is as follows: S21, user User uses any digital signature algorithm, whose signature public and private keys are (spk, ssk) respectively, and uses SamplePre algorithm to generate a short vector β satisfies B·β=0, which can be expressed as: β=SamplePre(B,T id ,0,s) SamplePre is also a probabilistic polynomial time algorithm, and the parameter σ satisfies the inequality S22, calculate Q′=Q·β, user User divides the data file F into data blocks, i.e. Use the signature private key ssk to generate a signature for the message name‖Q', where name is the data file name, and set the label τ = name||Q′||Sig ssk (name||Q′), user calculation S23, for data blocks Combine your own public key B with the cloud server's public key Q to calculate User User calculates the inner product h ij =<λ i ,α j >, 1≤j≤n, and let h i =(h i1 ,h i2 ,…,h in ); S24, user User calculates data block m i Tags i =SamplePre(B,T id ,h i ,σ), the parameter σ satisfies the inequality The label set of all data blocks Finally, {φ,F,Q′,τ,β} is sent to the cloud server and the locally stored file F is deleted.

5. The identity-based cloud storage integrity detection method according to claim 4, characterized in that: The third-party public audit TPA generates challenge information including: Third-party public audit TPA definition set I = {s j }(1≤j≤n) and s1≤…≤s n , For any element i in set I, randomly select a matrix Generate challenge information chal = {τ,i,c i } i∈I , and sends the challenge information to the cloud server CS.

6. The identity-based cloud storage integrity detection method according to claim 5, characterized in that: The cloud server CS returns the certification information including: The cloud server CS selects the data block {m i } i∈I And the corresponding label {e i } i∈I And calculate Randomly select a vector The SamplePre algorithm is used to generate a short vector ξ, which is expressed as: ξ=SamplePre(Q,T Q (oh,s) Cloud server CS calculates value = β + ξH2(ω), u c ′=u c +ξH2(ω), and Generate proof information Proof = {τ,u c ′,e c ,ω,value,Q′} is sent to the third-party public auditor TPA.

7. The identity-based cloud storage integrity detection method according to claim 6, characterized in that: The third-party public audit TPA verification process includes: S31, after receiving the certification information from the cloud server CS, the third-party public auditor TPA uses the user User signature public key spk to verify the legitimacy of the label τ. If it is legal, it continues to verify; S32, calculate α j =H3(B||τ||j), let C=(α1,α2,…,α n ) T ; S33, calculation Calculate h c ′=Cλ c ′; S34, verify equation Be c =h c ′(modq) and Q·value=Q′+ωH2(ω) hold, and the inequality and Whether it is true; if both are true, the third-party public auditor TPA accepts the evidence and believes that the information is legal; otherwise, it is proved that the information is illegal and the integrity of the stored data is damaged.

8. A cloud storage integrity detection system based on identity on a grid, the system implementing the detection method according to any one of claims 1 to 7, characterized in that: Includes the following modules: The key distribution module is used to generate the private keys of the user User and the cloud server CS according to the system parameters generated by the key generation center PKG, and complete the key distribution; The data upload module is used to divide and sign the data files according to the user User and upload them to the cloud server CS; The verification module is used to issue an audit request based on the user User, the third-party public audit TPA issues a challenge message, the cloud server CS returns the proof information and is verified by the third-party public audit TPA. Through the double masking technology, it is ensured that the user's data information is not leaked during the verification process.

Citation Information

Patent Citations

  • Cloud storage data common auditing method possessing secret key leakage resistance characteristic

    CN105791321A

  • Searchable encryption and multi-user expansion method without secure channel supporting privacy protection

    CN117499021A