Cloud storage service deduplication data sharing auditing method and system based on block chain

By adopting a blockchain-based deduplicable data sharing audit method in the cloud storage system, the problems of high data audit cost and relying on trusted third parties in the existing technology are solved, and efficient and fair data sharing audit and deduplication are achieved, reducing audit overhead and improving data security.

CN120068098APending Publication Date: 2025-05-30NANJING UNIV OF SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510001852.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-02
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing cloud storage data audit and deduplication methods have high costs, relying on trusted third parties, and the cost of repeated audits and auditing small amounts of data shared by multiple users.

Method used

Using blockchain-based cloud storage services, data sharing auditing methods can be deduplicated. Through the steps of system initialization, key sharing, user data upload, data audit and shared audit, data deduplication and auditing can be realized, reducing dependence on trusted third parties.

Benefits of technology

It realizes fair and efficient data sharing audit, reduces audit overhead, improves the work efficiency of third-party auditors, and enhances data security and transparency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068098A_ABST
    Figure CN120068098A_ABST
Patent Text Reader

Abstract

The invention discloses a block chain-based cloud storage service deduplication data sharing auditing method and system. The system comprises a user, a cloud storage service provider, a third-party accountant, a block chain node and a system administrator. The method comprises the steps that firstly, a system administrator generates system parameters and issues the system parameters to a block chain; then, users find partners through the block chain, all the partners obtain a unified public and private key pair by executing a key exchange protocol on the block chain, and a file uploading process is executed; then, a third-party auditor assists the user in checking data integrity, and an auditing log is generated for the user to supervise and examine; and finally, the user finds a partner and delegates the audit tasks of the two parties to a third-party auditor for combined audit. According to the method, sharing auditing of the deduplicated data of the cloud storage system is realized, auditing overhead is reduced, auditing efficiency is improved, autonomy and independence of the system are improved, and security guarantee of the data is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of blockchain technology and data auditing technology, and in particular to a deduplication data sharing auditing method and system for cloud storage services based on blockchain. Background Art

[0002] In today's digital age, all enterprises have an increasing demand for low-cost data backup, storage, and protection, and due to the enhanced use of mobile technology, the demand for data processing generated by them is also increasing, making cloud storage services widely adopted because of their ability to provide low-cost and highly scalable storage capabilities anytime and anywhere. With the wide application of cloud storage technology, its security and performance issues have attracted more and more attention. Since cloud storage service providers may maliciously or accidentally damage users' data, remote data auditing mechanisms are one of the simplest and most effective security solutions, which can help check the integrity of outsourced data. In addition, since nearly 75% of the outsourced data are duplicate copies, and the deduplication technology can reduce storage costs and improve the operating efficiency of the system, it is widely used in various business environments.

[0003] Currently, there are mainly the following methods for data auditing and data deduplication of cloud storage: The first method is to preprocess the user's data before uploading it to the service provider to obtain verification metadata. This method enables users to remotely check data integrity without relying on local copies, but fails to fully combine the characteristics of a large number of duplicate data existing in the cyberspace, resulting in low efficiency of remote data auditing and data deduplication; The second method is to use an encrypted client with proof of cloud storage ownership for deduplication. This method can efficiently deduplicate data in cloud storage while ensuring data ownership and integrity, but the data owner will independently generate verification metadata for duplicate file checking, increasing unnecessary overhead; The third method is the deduplicable dynamic storage proof method used in a multi-user environment. This method avoids the rapid expansion of verification metadata by sharing verification metadata among multiple tenants, but relies on a trusted third-party auditor (TPA) to assist users in auditing. To improve the working efficiency of the TPA, batch verification and batch auditing and other schemes are usually adopted. However, since the workload of the TPA in each audit challenge is independent of the number of files to be checked, users must pay the same fee for each challenge, which is relatively costly for users who only store a small amount of data. Therefore, it is necessary to study how to achieve cross-user shared auditing and allow users to share their own audit processes with others to further reduce the workload of the TPA and the audit fees of users.

[0004] In summary, the existing deduplicated data auditing methods mainly face several problems such as high costs of traditional auditing methods, reliance on trusted third parties, repeated auditing of multi-user shared data, and excessive costs when auditing a small amount of data. Therefore, it is necessary to design a deduplicated data auditing method for cloud storage systems that can achieve trusted and efficient deduplication without relying on trusted third-party auditors, support shared auditing. Summary of the Invention

[0005] The purpose of the present invention is to provide a fair and efficient deduplicated data sharing auditing method and system for cloud storage systems that can protect outsourced data from privacy leakage and brute-force attacks, reduce auditing overhead, improve the working efficiency of the TPA, have a high transparency in the auditing process, and high data security guarantee.

[0006] The technical solution to achieve the purpose of the present invention is: a deduplicated data sharing auditing method for cloud storage services based on blockchain, including the following steps:

[0007] Step 1, system initialization: The system administrator generates system parameters, constructs a secure system based on bilinear mapping, and publishes the system parameter Para to the blockchain;

[0008] Step 2, key sharing: The user u who hopes to achieve sharded auditing i finds a partner u through the blockchain j , u i , u j obtains a unified public-private key pair (PK, SK) = (g SK , SK) by executing a key exchange protocol on the blockchain;

[0009] Step 3, user data upload: If there is no potential duplicate file of the data file F to be uploaded in the cloud storage service provider SP, the user u i executes the initial upload process; otherwise, the user u i executes the subsequent upload process;

[0010] Step 4, data auditing: The third-party auditor TPA uses the challenge-response model to assist the user in checking data integrity, and the interaction records between the third-party auditor TPA and the cloud storage service provider SP on the blockchain constitute the audit log Log for the user to supervise and review;

[0011] Step 5, shared auditing: The user u who needs to upload the data file F i finds a partner u j , entrusts the audit tasks of both parties to the third-party auditor TPA, the third-party auditor TPA conducts a combined audit, and the users u i and u j reduce the auditing cost and at the same time achieve integrity verification.

[0012] Furthermore, the system initialization described in Step 1 is as follows:

[0013] Step 1.1: Based on the security parameter λ, the system administrator selects three multiplicative cyclic groups G 1 , G 2 and G T of order p, and constructs a bilinear mapping e: G 1 ×G 2 →G T ;

[0014] Step 1.2: The system administrator selects a random element v ∈ G 1 and the generator g of G 2 , defines two collision-resistant hash functions H: {0, 1} * →G 1 and h: {0, 1} * →Z p to generate some necessary metadata; defines a short hash function SH: {0, 1} * →{0, 1} S to generate short hash values for searching potential duplicate files; defines two pseudorandom functions π 1 : and π 2 : to generate indices and coefficients for challenge data blocks;

[0015] Step 1.3: The system administrator selects a symmetric encryption algorithm E() / D() and an additive homomorphic encryption algorithm Enc() / Dec() to ensure the security of outsourced data;

[0016] Step 1.4: The system administrator publishes the system parameters Para = {G 1 , G 2 , G T , g, v, e, H, h, π 1 , π 2} to the blockchain.

[0017] Furthermore, the key sharing described in Step 2 is as follows:

[0018] Step 2.1: When user u i needs to upload the data file F, the system first calculates the short hash value sh = SH(F) of the file and checks whether there is a duplicate copy in the cloud storage service provider SP. If no identical sh is found, the initial upload process is executed; otherwise, the cloud storage service provider SP finds all potential duplicate file sets and requests the owner u j of the set to use the hash value hj = h(F j ) and u i Execute the SPAKE2 protocol using the hash value h = h(F), and finally each u j obtains the session key key' j , while u i obtains a set of session keys When and only when h is equal to h j , the session key key j is equal to key' j ;

[0019] Step 2.2, each user u j extends the length of key' using a pseudorandom function and divides key' j into key' j || ket' jL , then u jR sends key' j and (SK jL + key' j ) to the cloud storage service provider SP, where SK jR is the encryption key of file F j ; j

[0020] Step 2.3, for each key j , u i extends and divides it into key j || key jL using the same method as u jR , then u i sends the homomorphic encryption public key pk, {key jL} and {Enc(pk, key jR + r)} to SP, where r is an element randomly selected from the plaintext group;

[0021] Step 2.4, after receiving these messages, the cloud storage service provider SP checks whether there exists an index j such that key jL = key' jL . If such an index j exists, the cloud storage service provider SP calculates x using homomorphic encryption and sends it back to u i , where the calculation formula of x is:

[0022]

[0023] Step 2.5, u i obtains the encryption key SK = Dec(sk, x) + r and the public key PK = g SK .​

[0024] Furthermore, the user data upload described in step 3 is specifically as follows:

[0025] Step 3.1: If there is no potential duplicate file of the data file F to be uploaded in the cloud storage service provider SP, then u i Execute the initial upload process, u i Randomly select an encryption key And calculate its public key PK = g SK And α = v SK , then u i Encrypt the file F as C = E(SK,F) = c 1 ||…||c n , and for each data block c i Calculate the audit authentication symbol σ i :

[0026] Where M i = H(PK||i), 1 ≤ i ≤ n

[0027] Finally, u i Upload {C, {σ i}, α, PK} to the cloud storage service provider SP, delete the local data but retain (SK, PK);

[0028] Step 3.2: If there is a potential duplicate file of the data file F to be uploaded in the cloud storage service provider SP, then u i Execute the subsequent upload process, u i Use the encryption key SK obtained from the SPAKE2 protocol to calculate the ciphertext C and the authentication symbol {σ i}, C = E(SK,F) = c 1 ||…||c n , Where M i = H(PK||i), 1 ≤ i ≤ n; then u i Upload {C, {σ i}, α, PK} to the cloud storage service provider SP. The cloud storage service provider SP checks whether the outsourced data has been stored on the server. If not, the cloud storage service provider SP locally stores the outsourced data {sh, PK, α, C, {σ i}} and creates an index {sh, CS} on the blockchain for subsequent deduplication; otherwise, the cloud storage service provider SP deletes the duplicate data and returns an access link.

[0029] Furthermore, the data audit described in step 4 is specifically as follows:

[0030] Step 4.1. The third-party auditor TPA selects three random numbers to generate an audit challenge Chal = (z, r 1 , r 2 ) and publishes it on the blockchain, where z ∈ [1, n],

[0031] Step 4.2. According to Chal, the cloud storage service provider SP calculates the index a w = π 1 (w, r 1 ) and the coefficient b w = π 2 (w, r 2 ) for the w-th challenged data block, where w ∈ [1, z]; then the cloud storage service provider SP generates an integrity proof proof = (R, μ, σ) and sends it to the blockchain, where:

[0032]

[0033] Step 4.3. After the third-party auditor TPA receives the integrity proof proof from the blockchain, it executes a verification algorithm to check the integrity of the data. The formula is as follows:

[0034]

[0035] If the above formula holds, the algorithm outputs result = 1, indicating that the cloud storage service provider SP has passed the audit; otherwise, the algorithm outputs result = 0, indicating that the user data has been corrupted;

[0036] Step 4.4. The third-party auditor TPA publishes the audit result on the blockchain. The interaction records between the third-party auditor TPA and the cloud storage service provider SP on the blockchain form an audit log Log = {chalt, proof, result}, which is available for users to supervise and review.

[0037] Furthermore, the shared audit described in Step 5 is as follows:

[0038] Step 5.1. The user u who needs to upload the data file F i posts a notice on the blockchain to find a partner u j ; then executes the Diffie-Hellman key exchange protocol to obtain a session key k through the blockchain; finally, calculates a unified public-private key pair {PK, SK} for the shared audit:

[0039] SK = h(k), PK = g SK

[0040] Step 5.2. The user u who needs to conduct a shared audit qCalculate the ciphertext C of each file F q respectively: q C = F(SK, F q ), and calculate the audit authentication symbol {σ qs} for each data block c qs :

[0041] (1) Divide the encrypted file C q into n parts: C q = c q1 || c q2 ||... || c qn ;

[0042] (2) Calculate the audit authentication symbol of each c qj : where 1 ≤ q ≤ d 1 , 1 ≤ s ≤ n, M qs = H(PK || q || s);

[0043] Step 5.3, User u q calculates the file label t q = h(F q ) and α = v SK , and User u q uploads {C q , {σ qs}, α, PK} to the SP. The files of all partners will be regarded as one file for inspection;

[0044] Step 5.4, The users participating in the shared audit entrust the audit task to the third - party auditor TPA, and sign the smart contract SC = {t q , t j , PK, coin q , coin j}, where coin q and coin j are the fees pre - agreed by u q and u j respectively for paying the third - party auditor TPA for audit services;

[0045] Step 5.5, The third - party auditor TPA generates the audit challenge Chal = (z, r 1 , r 2 ) and publishes it on the blockchain. The cloud storage service provider SP takes Chal and C 1 , C 2 as inputs, and calculates the index a w1 of the w - th challenged data block as a 1 = π 1 (w, r 1 ) mod d w2= π 1 (w, r 2 ) mod n and coefficient b w = π 2 (w, r 2 ) where w ∈ [1, z], and then the cloud storage service provider SP generates the integrity proof proof = (R, μ, σ) and sends it to the blockchain, where:

[0046]

[0047] Step 5.6. After receiving the integrity proof proof, the third-party auditor TPA executes the verification algorithm to check the integrity of the data. The formula is as follows:

[0048]

[0049] If the above equation holds, output result = 1, indicating that F q and F j are both available; otherwise, output result = 0, indicating that the user data has been corrupted.

[0050] A blockchain-based cloud storage service deduplication data sharing audit system, which is used to implement the blockchain-based cloud storage service deduplication data sharing audit method described above. The system includes users, cloud storage service providers SP, third-party auditors TPA, blockchain nodes, and system administrators;

[0051] The user is a cloud storage service user, outsources data to the cloud storage service provider SP, and hires a third-party auditor TPA to check the integrity of the outsourced data; the user encrypts the data before uploading and performs data deduplication operations with the cloud storage service provider SP;

[0052] The cloud storage service provider SP provides cloud storage services, helps users store data, and uses data deduplication technology to delete duplicate data; the cloud storage service provider SP may be untrusted, may discard the user's outsourced data to save costs, and may try to deceive the third-party auditor TPA and the user through integrity verification to hide the fact that the stored data is lost or damaged;

[0053] The third-party auditor TPA has computing resources, helps users audit data integrity, but is not completely trusted. The third-party auditor TPA may collude with the cloud storage service provider SP and does not perform integrity verification according to the user's requirements;

[0054] The blockchain node is a node in the blockchain network, responsible for maintaining blockchain data and processing blockchain transactions;

[0055] The system administrator is an entity responsible for generating certain system parameters.

[0056] A mobile terminal includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the method for deduplicated data sharing audit of the blockchain-based cloud storage service is implemented.

[0057] Compared with the prior art, the present invention has the following remarkable advantages: (1) By adopting blockchain technology and encrypted deduplication technology, it not only realizes fair and efficient data integrity audit based on client-side deduplication, but also can protect outsourced data from privacy leakage and brute-force attack; (2) In the case of multiple users, by using blockchain technology to overcome the trust boundary between unfamiliar users, it avoids multiple users from repeatedly auditing the jointly owned files, enabling users to share different data for audit, thereby reducing the audit overhead and improving the working efficiency of the TPA; (3) By using blockchain technology to record data audit logs, it monitors the behavior of the TPA during the entire data audit process, does not rely on a trusted TPA, improves the autonomy and independence of the system, and enhances the security guarantee of data. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] Figure 1 It is a structural block diagram of a deduplicated data sharing audit system for a blockchain-based cloud storage service according to the present invention.

[0059] Figure 2 It is a schematic flow diagram of key sharing in an embodiment of the present invention.

[0060] Figure 3 It is a schematic flow diagram of user data upload in an embodiment of the present invention.

[0061] Figure 4 It is a schematic flow diagram of data audit in an embodiment of the present invention.

[0062] Figure 5 It is a schematic flow diagram of shared audit in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0063] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0064] As Figure 1 shown, a deduplicated data sharing audit system for a blockchain-based cloud storage system according to the present invention includes users, a cloud storage service provider SP, a third-party auditor TPA, blockchain nodes, and a system administrator;

[0065] The user is a user of cloud storage services, outsourcing their data to a cloud storage service provider SP and hiring a third-party auditor TPA to check the integrity of the outsourced data; the user can encrypt the data before uploading it to ensure data privacy, and can perform data deduplication operations with the cloud storage service provider SP to reduce storage space and save storage costs;

[0066] The cloud storage service provider SP provides cloud storage services to help users store data, and can use deduplication technology to delete duplicate data; the cloud storage service provider SP may be an untrusted SP, and may discard the user's outsourced data in order to save costs, and try to deceive the TPA and the user through integrity verification to hide the fact that the stored data is lost or damaged;

[0067] The third-party auditor TPA has powerful computing resources to help users audit data integrity, but is not completely trusted. The TPA may collude with the cloud storage service provider SP and does not perform integrity verification according to the user's requirements;

[0068] The blockchain node is a node in the blockchain network, responsible for maintaining blockchain data and processing blockchain transactions;

[0069] The system administrator is an entity responsible for generating certain system parameters.

[0070] A method for auditing deduplicated data sharing in a blockchain-based cloud storage system according to the present invention includes the following steps:

[0071] Step 1, system initialization: The system administrator generates system parameters, constructs a secure system based on bilinear mapping, and publishes the system parameters Para to the blockchain;

[0072] Step 2, key sharing: The user u who hopes to achieve sharded auditing i finds partners u j , u i , u j obtains a unified public-private key pair (PK, SK) = (g SK , SK) by executing a key exchange protocol on the blockchain;

[0073] Step 3, user data upload: If there is no potential duplicate file of the data file F to be uploaded in the cloud storage service provider SP, then the user u i performs an initial upload process; otherwise the user u i performs a subsequent upload process;

[0074] Step 4, Data Audit: The third-party auditor TPA uses the challenge-response model to assist the user in checking data integrity, and the interaction records between the third-party auditor TPA and the cloud storage service provider SP on the blockchain constitute the audit log Log for the user to supervise and review;

[0075] Step 5, Shared Audit: The user u who needs to upload the data file F i finds a partner u j , entrusts the audit tasks of both parties to the third-party auditor TPA, and the third-party auditor TPA conducts a combined audit. The user u i and u j reduce the audit cost and achieve integrity verification at the same time.

[0076] As a specific example, in Step 1, System Initialization: The system administrator generates system parameters, constructs a security system based on bilinear mapping, and publishes the system parameters Para to the blockchain, as follows:

[0077] Step 1.1, Based on the security parameter λ, the system administrator selects three multiplicative cyclic groups G 1 , G 2 and G T of order p, and constructs a bilinear mapping e: G 1 ×G 2 →G T ;

[0078] Step 1.2, The system administrator selects a random element v ∈ G 1 and the generator g of G 2 , defines two collision-resistant hash functions H: {0,1} * →G 1 and h: {0,1} * →Z p to generate some necessary metadata; defines a short hash function SH: {0,1} * →{0,1} S to generate short hash values for searching potential duplicate files; defines two pseudorandom functions π 1 : and π 2 : to generate indexes and coefficients for challenge data blocks;

[0079] Step 1.3, The system administrator selects a symmetric encryption algorithm E() / D() and an additive homomorphic encryption algorithm Enc() / Dec() to ensure the security of the outsourced data;

[0080] Step 1.4, The system administrator sets the system parameters Para = {G 1 , G 2,G T ,g, v, e, H, h, π 1 ,π 2} Publish to the blockchain.

[0081] As a specific example, in step 2, key sharing: as Figure 2 shown, the user u who hopes to achieve sharding auditing i can find a partner u through the blockchain j , and they can all obtain a unified public-private key pair (PK, SK) = (g SK , SK) by executing a key exchange protocol on the blockchain, specifically as follows:

[0082] Step 2.1. When the user u i needs to upload the data file F, the system first calculates the short hash value sh = SH(F) of the file and checks whether there is a duplicate copy in the cloud storage service provider SP. If no identical sh is found, the initial upload process is executed; otherwise, SP finds all potential duplicate file sets and asks their owners u j to use the hash value h j = h(F j ) to execute the SPAKE2 protocol with u i using h = h(F). Eventually, each u j obtains the session key key' j , while u i obtains a set of session keys When and only when h is equal to h j , the session key key j is equal to key' j ;

[0083] Step 2.2. Each user u j uses a pseudorandom function to extend the length of key' j and divides it into key' jL || key' jR , then u j sends key' jL and (SK j + key' jR ) to SP, where SK j is the encryption key of the file F j ;

[0084] Step 2.3. For each key j , u i uses the same method as u j to extend and divide it into key jL || key jR, then u i sends its homomorphic encryption public key pk, {key jL}, and {Enc(pk, key jR +r)} to the SP, where r is an element randomly selected from the plaintext group;

[0085] Step 2.4: After receiving these messages, the SP checks whether there exists an index j such that key jL = key' jL . If such an index j exists, the SP calculates x using homomorphic encryption and sends it back to u i , where the calculation formula for x is:

[0086]

[0087] Step 2.5: u i obtains the encryption key SK = Dec(sk, x) + r and its public key PK = g SK by receiving the message from the SP, and then performs the subsequent upload process.

[0088] As a specific example, in Step 3, user data upload: As Figure 3 shown, if there is no potential duplicate file of the data file F to be uploaded in the SP, the user u i performs the initial upload process; otherwise, the user u i performs the subsequent upload process, specifically as follows:

[0089] Step 3.1: If there is no potential duplicate file of the data file F to be uploaded in the SP, then u i performs the initial upload process. u i randomly selects an encryption key and calculates its public key PK = g SK and α = v SK , then u i encrypts the file F as C = E(SK, F) = c 1 ||…||c n , and calculates the audit authenticator σ i for each data block c i :

[0090] where M i = H(PK||i), 1 ≤ i ≤ n;

[0091] Finally, u i uploads {C, {σ i}, α, PK} to the SP, deletes the local data but retains (SK, PK);

[0092] Step 3.2. If there is a potential duplicate file of the data file F to be uploaded in the SP, then u i Execute the subsequent upload process, u i Use the encryption key SK obtained from the SPAKE2 protocol to calculate the ciphertext C and the authenticator {σ i}, C = E(SK, F) = c 1 ||…||c n , where M i = H(PK||i), 1 ≤ i ≤ n; then u i Upload {C, {σ i}}, α, PK} to the SP. The SP checks whether the outsourced data has been stored on the server. If not, the SP locally stores the outsourced data {sh, PK, α, C, {σ i}} and creates an index {sh, CS} on the blockchain for subsequent deduplication; otherwise, the SP deletes the duplicate data and returns an access link.

[0093] As a specific example, in Step 4, data auditing: As Figure 4 shown, the third-party auditor TPA uses the challenge-response model to assist the user in checking data integrity, and the interaction records between the third-party auditor TPA and the cloud storage service provider SP on the blockchain constitute the audit log Log, which can be used by the user for supervision and review, as follows:

[0094] Step 4.1. The third-party auditor TPA selects three random numbers to generate the audit challenge Chal = (z, r 1 , r 2 ) and publishes it on the blockchain, where z ∈ [1, n],

[0095] Step 4.2. According to Chal, the SP calculates the index a w = π 1 (w, r 1 ) and the coefficient b w = π 2 (w, r 2 ) for the w-th challenged data block, where w ∈ [1, z]; then the SP generates the integrity proof proof = (R, μ, σ) and sends it to the blockchain, where:

[0096]

[0097] Step 4.3. After receiving the integrity proof proof from the blockchain, the TPA executes the verification algorithm to check the data integrity. The formula is as follows:

[0098]

[0099] If the above formula holds, the algorithm outputs result = 1 indicating that the SP has passed the audit; otherwise, the algorithm outputs result = 0 indicating that the user data has been corrupted;

[0100] Step 4.4, The TPA publishes the audit result on the blockchain. The interaction records between the TPA and the SP on the blockchain form the audit log Log = {chalt, proof, result}, which is available for users to supervise and review.

[0101] As a specific example, in Step 5, shared auditing: as Figure 5 shown, the user u who needs to upload the data file F i finds a partner u j , and entrusts the audit tasks of both parties to the TPA. The TPA conducts a combined audit. In this way, the users u i and u j reduce their audit costs and at the same time achieve reliable integrity verification, as follows:

[0102] Step 5.1, The user u who needs to upload the data file F i posts a notice on the blockchain to find a partner u j ; then executes the Diffie - Hellman key exchange protocol to obtain the session key k through the blockchain; finally, calculates the unified public - private key pair {PK, SK} for shared auditing:

[0103] SK = h(k), PK = g SK

[0104] Step 5.2, The users u who need to conduct shared auditing q respectively calculate the ciphertext C q of their respective files F q = E(SK, F q ), and calculate the audit authenticator {σ qs} for each data block c qs :

[0105] (1) Divide the encrypted file C q into n parts: C q = c q1 ||c q2 ||…||c qn ;

[0106] (2) Calculate the audit authenticator for each c qj : where 1 ≤ q ≤ d 1 , 1 ≤ s ≤ n, M qs = H(PK||q||s);

[0107] Step 5.3, user u q Calculate the file tag t q = h(F q ) and α = v SK , user u q uploads {C q , {σ qs}, α, PK} to the SP. The files of all partners will be regarded as one file for inspection;

[0108] Step 5.4, the users participating in the shared audit entrust the audit task to the TPA and sign the smart contract SC = {t q , t j , PK, coin q , coin j}, where coin q and coin j are the fees pre - agreed by u q and u j for paying the TPA for the audit service;

[0109] Step 5.5, the TPA generates the audit challenge Chal = (z, r 1 , r 2 ) and publishes it on the blockchain. The SP takes Chal and C 1 , C 2 as inputs and calculates the index a w1 = π 1 (w, r 1 ) mod d 1 , a w2 = π 1 (w, r 2 ) mod n and the coefficient b w = π 2 (w, r 2 ) for the w - th challenged data block, where w ∈ [1, z]. Then the SP generates the integrity proof proof = (R, μ, σ) and sends it to the blockchain, where:

[0110]

[0111] Step 5.6, after receiving the integrity proof proof, the TPA executes the verification algorithm to check the integrity of the data. The formula is as follows:

[0112]

[0113] If the above equation holds, it outputs result = 1 indicating F q and F jAll are available; otherwise, output result = 0, indicating that the user data has been damaged.

[0114] The present invention also provides a mobile terminal, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the method for deduplicating data sharing audit of the blockchain-based cloud storage service is implemented.

[0115] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0116] Embodiment

[0117] Combined with Figure 1 , the deduplicating data sharing audit system of the blockchain-based cloud storage system provided in this embodiment includes a user, a cloud storage service provider SP, a third-party auditor TPA, a blockchain node, and a system administrator;

[0118] The user is a cloud storage service user, outsourcing its data to the cloud storage service provider SP and hiring a third-party auditor TPA to check the integrity of the outsourced data; the user can encrypt the data before uploading to ensure data privacy and can perform data deduplication operations with the cloud storage service provider SP to reduce storage space and save storage costs;

[0119] The cloud storage service provider SP provides cloud storage services to help users store data and can use deduplication technology to delete duplicate data; the cloud storage service provider SP may be an untrusted SP, may discard the user's outsourced data to save costs, and may try to deceive the TPA and the user through integrity verification to hide the fact that the stored data is lost or damaged;

[0120] The third-party auditor TPA has powerful computing resources to help users audit data integrity but is not completely trusted. The TPA may collude with the cloud storage service provider SP and does not perform integrity verification according to the user's requirements;

[0121] The blockchain node is a node in the blockchain network, responsible for maintaining blockchain data and processing blockchain transactions;

[0122] The system administrator is an entity responsible for generating certain system parameters.

[0123] In the deduplicating data sharing audit of the blockchain-based cloud storage system provided in this embodiment, the descriptions of each symbol and the symbol are shown in Table 1:

[0124] Table 1 Descriptions of symbols and the symbol

[0125]

[0126]

[0127] Combine Figures 2 to 5 , the deduplicated data sharing audit method for the blockchain-based cloud storage system provided in this embodiment includes the following steps

[0128] Step 1, System initialization: The system administrator generates system parameters, constructs a secure system based on bilinear mapping, and publishes the system parameters Para to the blockchain, specifically as follows:

[0129] Step 1.1, Based on the security parameter λ, the system administrator selects three multiplicative cyclic groups G 1 , G 2 and G T , and constructs a bilinear mapping e: G 1 ×G 2 →G T ;

[0130] Step 1.2, The system administrator selects a random element v ∈ G 1 and the generator g of G 2 , defines two collision-resistant hash functions H: {0,1} * →G 1 and h: {0,1} * →Z p to generate some necessary metadata; defines a short hash function SH: {0,1} * →{0,1} S to generate short hash values for searching potential duplicate files; defines two pseudorandom functions π 1 : and π 2 : to generate indexes and coefficients for challenging data blocks;

[0131] Step 1.3, The system administrator selects a symmetric encryption algorithm E() / D() and an additive homomorphic encryption algorithm Enc() / Dec() to ensure the security of the outsourced data;

[0132] Step 1.4, The system administrator publishes the system parameters Para = {G 1 , G 2 , G T , g, v, e, H, h, π 1 , π 2} to the blockchain.

[0133] Step 2, Key sharing: The user u i who hopes to achieve sharded auditing can find a partner u j, they can all obtain a unified public-private key pair (PK, SK) = (g SK , SK) by executing a key exchange protocol on the blockchain, as follows:

[0134] Step 2.1: When user u i needs to upload the data file F, the system first calculates the short hash value sh = SH(F) of the file and checks in the cloud storage service provider SP whether there is a duplicate copy. If no identical sh is found, the initial upload process is executed; otherwise, SP finds all potential duplicate file sets and asks their owners u j to use the hash value h j = h(F j ) to execute the SPAKE2 protocol with u i using h = h(F), as follows:

[0135] (1) User u i selects an x ∈ R Z p , calculates X = g x , and defines X * = X · (M A ); User u h selects a y ∈ j Z R , calculates Y = g p , and defines y

[0136] (2) User u i exchanges X j and Y * with user u * ;

[0137] (3) User u i calculates and then outputs the session key key j = H(A, B, X * , Y * , h, K A ); User u J calculates K B = (X * / (M A h ) y , and then outputs the session key key' j = H(A, B, X * , Y * , h j , K B );

[0138] ​Finally, each u j obtains the session key key' j and u i obtains the set of session keys session key key j equals key' j if and only if h equals h j ;

[0139] Step 2.2. Each user u j uses a pseudorandom function to expand the length of key' j and divides it into key' jL ||key' jR Then u j sends key' jL and (SK j +key' jR ) to SP, where SK j is the encryption key of file F j ;

[0140] Step 2.3. For each key j u i uses the same method as u j to expand and divide it into key jL ||key jR Then u i sends its homomorphic encryption public key pk, {key jL} and {Enc(pk,key jR +r)} to SP, where r is an element randomly selected from the plaintext group;

[0141] Step 2.4. After receiving these messages, SP checks whether there exists an index j such that key jL key' jL If such an index j exists, then SP uses homomorphic encryption to calculate x and sends it back to u i where the calculation formula of x is:

[0142]

[0143] Step 2.5. u i obtains the encryption key SK = Dec(sk,x)+r and its public key PK = g SK by receiving the message from SP, and then executes the subsequent upload process.

[0144] Step 3. User data upload: If there is no potential duplicate file of the data file F to be uploaded in SP, then user u i executes the initial upload process; otherwise, user ui Perform the subsequent upload process as follows:

[0145] Step 3.1: If there is no potential duplicate file of the data file F to be uploaded in the SP, then u i Perform the initial upload process, u i Randomly select an encryption key and calculate its public key PK = g SK and α = v SK , then u i Encrypt the file F as C = E(SK,F) = c 1 ||…||c n , and for each data block c i Calculate the audit authentication symbol σ i :

[0146] where M i = H(PK||i), 1 ≤ i ≤ n;

[0147] Finally, u i Upload {C, {σ i}, α, PK} to the SP, delete the local data but retain (SK, PK);

[0148] Step 3.2: If there is a potential duplicate file of the data file F to be uploaded in the SP, then u i Perform the subsequent upload process, u i Use the encryption key SK obtained from the SPAKE2 protocol to calculate the ciphertext C and the authentication symbol {σ i}, C = E(SK,F) = c 1 ||…||c n , where M i = H(PK||i), 1 ≤ i ≤ n; then u i Upload {C, {σ i}, α, PK} to the SP. The SP checks whether the outsourced data has been stored on the server. If not, the SP locally stores the outsourced data {sh, PK, α, C, {σ i}} and creates an index {sh, CS} on the blockchain for subsequent deduplication; otherwise, the SP deletes the duplicate data and returns an access link.

[0149] Step 4: Data auditing: The third-party auditor TPA uses the challenge-response model to assist the user in checking data integrity, and the interaction records between the third-party auditor TPA and the cloud storage service provider SP on the blockchain constitute the audit log Log, which can be used for user supervision and review as follows:

[0150] Step 4.1: The third-party auditor TPA selects three random numbers to generate an audit challenge Chal = (z, r 1 , r 2 ) and publishes it on the blockchain, where z ∈ [1, n],

[0151] Step 4.2: According to Chal, the SP calculates the index a w = π 1 (w, r 1 ) and the coefficient b w = π 2 (w, r 2 ) for the w-th challenged data block, where w ∈ [1, z]; then the SP generates an integrity proof proof = (R, μ, σ) and sends it to the blockchain, where:

[0152]

[0153] Step 4.3: After the TPA receives the integrity proof proof from the blockchain, it executes a verification algorithm to check the integrity of the data. The formula is as follows:

[0154]

[0155] If the above formula holds, the algorithm outputs result = 1 indicating that the SP has passed the audit; otherwise, the algorithm outputs result = 0 indicating that the user data has been corrupted;

[0156] Step 4.4: The TPA publishes the audit result on the blockchain. The interaction records between the TPA and the SP on the blockchain form an audit log Log = {chalt, proof, result} for users to supervise and review.

[0157] Step 5: Shared audit: User u who needs to upload the data file F i finds a partner u j , entrusts their audit tasks to the TPA, and the TPA conducts a combined audit. In this way, user u i and u j reduce their audit costs and achieve reliable integrity verification, as follows:

[0158] Step 5.1: User u who needs to upload the data file F i posts a notice on the blockchain to find a partner u j ; then executes the Diffie-Hellman key exchange protocol to obtain a session key k through the blockchain; finally, calculates a unified public-private key pair {PK, SK} for the shared audit, as follows:

[0159] (1) It is set that in this shared audit, user u q and partner u j share d 1 files. Each user u q who wants to upload file F q selects a random number and calculates Partner u j selects a random number and calculates User u q posts a notice containing b q on the blockchain. u j posts a transaction containing b j in response to u q ;

[0160] (2) User u q and partner u j obtain the same session key

[0161] (3) Calculate the unified private key SK = h(k) and the public key PK = g SK ;

[0162] Step 5.2: The user u q who needs to conduct a shared audit calculates the ciphertext C q of their respective file F q = E(SK, F q ), and calculates the audit authenticator {σ qs} for each data block c qs :

[0163] (1) Divide the encrypted file C q into n parts: C q = c q1 ||c q2 ||…||c qn ;

[0164] (2) Calculate the audit authenticator for each c qj : where 1 ≤ q ≤ d 1 , 1 ≤ s ≤ n, M qs = H(PK||q||s);

[0165] Step 5.3: User u q calculates the file tag t q = h(F q ), and α = v SK . User u q uploads {C q , {σ qs, α, PK} is sent to the SP, and the files of all partners will be regarded as one file for inspection;

[0166] Step 5.4. The users participating in the shared audit entrust the audit task to the TPA and sign the smart contract SC = {t q , t j , PK, coin q , coin j} in which coin q and coin j are the u q and u j pre - agreed fees for paying the TPA for audit services;

[0167] Step 5.5. The TPA generates the audit challenge Chal=(z, r 1 , r 2 ) and publishes it on the blockchain. The SP takes Chal and C 1 , C 2 as inputs, and calculates the index a w1 =π 1 (w, r 1 ) mod d 1 , a w2 =π 1 (w, r 2 ) mod n and the coefficient b w =π 2 (w, r 2 ) for the w - th challenged data block, where w ∈ [1, z]. Then the SP generates the integrity proof proof=(R, μ, σ) and sends it to the blockchain, where:

[0168]

[0169] Step 5.6. After receiving the integrity proof proof, the TPA executes the verification algorithm to check the integrity of the data. The formula is as follows:

[0170]

[0171] If the above equation holds, it outputs result = 1 indicating that both F q and F j are available; otherwise it outputs result = 0, indicating that the user data has been corrupted.

[0172] To verify the security and feasibility of the present invention, the following analysis is carried out to prove that the information of μ c is not leaked to the TPA: μ is blinded by r as μ = μ c +rh(R) and R = α r, where r is randomly selected by SP and TPA is unaware of it. Based on the difficulty of discrete logarithm, TPA cannot derive the value of r from R, and TPA cannot obtain any information about μ from μ c and thus the privacy of μ c is guaranteed:

[0173]

[0174] Due to the confidentiality of the private key SK, even if TPA can calculate it cannot obtain any information about from it. Therefore, TPA cannot learn any information about the outsourced data from the integrity proof.

[0175] Therefore, the deduplication data sharing audit method in the blockchain-based cloud storage system of the present invention uses blockchain technology to record the behaviors of entities during data outsourcing and auditing. Therefore, the corresponding immutable records can not only be used to ensure the credibility of audit results, but also help to supervise unreliable third-party auditors, further enhancing the autonomy and independence of the system and increasing the security guarantee of data; using deduplication technology, the cloud storage service provider can delete duplicate data outsourced by users and only save one copy, thus reducing the storage burden; using the SPAKE2-based shared audit mechanism, multiple users can share the audit, reducing the audit cost of users and improving the audit efficiency of TPA.

[0176] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A blockchain-based cloud storage service deduplication data sharing audit method, characterized in that: The following steps are involved: Step 1: System initialization: The system administrator generates system parameters, builds a security system based on bilinear mapping, and publishes the system parameters Para to the blockchain; Step 2: Key sharing: User u who wants to implement shard audit i Find partners through blockchain j ,u i 、u j By executing the key exchange protocol on the blockchain, a unified public-private key pair (PK, SK) = (g SK ,SK); Step 3: User data upload: If there is no potential duplicate file of the data file F to be uploaded in the cloud storage service provider SP, user u i Perform the initial upload process; Otherwise user u i Execute the subsequent upload process; Step 4: Data Audit: The third-party auditor TPA uses a challenge-response model to assist users in checking data integrity, and the interaction records between the third-party auditor TPA and the cloud storage service provider SP on the blockchain constitute an audit log for user supervision and review; Step 5: Shared audit: User u who needs to upload data file F i Find a partner j , entrust the audit tasks of both parties to the third-party auditor TPA, and the third-party auditor TPA conducts a combined audit. User u i and u j Audit costs are reduced while enabling integrity verification.

2. The blockchain-based cloud storage service deduplication data sharing audit method according to claim 1 is characterized in that: The system initialization described in step 1 is as follows: Step 1.1: Based on the security parameter λ, the system administrator selects three multiplication cyclic groups G1, G2 and G T , construct a bilinear map e:G1×G2→G T ; Step 1.2: The system administrator selects a random element v∈G1 and a generator g of G2, and defines two collision-resistant hash functions H:{0,1} * →G1 and h:{0,1} * →Z p To generate some necessary metadata; define a short hash function SH: {0,1} * →{0,1} S To generate a short hash value for searching for potential duplicate files; define two pseudo-random functions and To generate indices and coefficients for the challenge data block; Step 1.3, the system administrator selects a symmetric encryption algorithm E() / D() and an additive homomorphic encryption algorithm Enc() / Dec() to ensure the security of outsourced data; Step 1.4: The system administrator sets the system parameter Para = {G1, G2, G T ,g,v,e,H,h,π1,π2} are published on the blockchain.

3. The blockchain-based cloud storage service deduplication data sharing audit method according to claim 1 is characterized in that: The key sharing described in step 2 is as follows: Step 2.1: When user u i When a data file F needs to be uploaded, the system first calculates the short hash value sh = SH(F) of the file and searches the cloud storage service provider SP for duplicate copies. If no identical sh is found, the initial upload process is performed; Otherwise, the cloud storage service provider SP finds all potential duplicate file sets and asks the owner of the collection u j Use the hash value h j =h(F j ) and u i Use the hash value h = h(F) to execute the SPAKE2 protocol, and finally each u j Get the session key' j , and u i Get the session key set If and only if h is equal to h j When the session key j Equal to key' j ; Step 2.2: Each user u j Extend key' using a pseudo-random function j length, and key' j Divide into key' jL ||key' jR , then u j Send key' jL and (SK j +key' jR ) to the cloud storage service provider SP, where SK j It is file F j The encryption key; Step 2.3: For each key j ,u i Use with j The same method is expanded and divided into keys jL ||key jR , then u i Send homomorphic encryption public key pk, {key jL } and {Enc(pk,key jR +r)} to SP, where r is a randomly selected element in the plaintext group; Step 2.4: After receiving these messages, the cloud storage service provider SP checks whether there is an index j such that key jL =key' jL , if such an index j exists, the cloud storage service provider SP computes x using homomorphic encryption and sends it back to u i , where x is calculated as: Step 2.5, u i By receiving the message from the cloud storage service provider SP, the encryption key SK = Dec(sk,x) + r and the public key PK = g SK .

4. The method for deduplicated data sharing auditing of a cloud storage service based on blockchain according to claim 1 is characterized in that: The user data upload described in step 3 is as follows: Step 3.1: If there is no potential duplicate file of the data file F to be uploaded in the cloud storage service provider SP, then u i Perform the initial upload process, u i Randomly select an encryption key And calculate its public key PK = g SK and α = v SK , then u i Encrypt file F to C = E (SK, F) = c1 || ... || c n , and for each data block c i Calculate the audit token σ i : Among them, M i =H(PK||i),1≤i≤n Finally u i {C,{σ i },α,PK} is uploaded to the cloud storage service provider SP, local data is deleted but (SK,PK) is retained; Step 3.2: If there are potential duplicate files of the data file F to be uploaded in the cloud storage service provider SP, then u i Execute the subsequent upload process, u i The encryption key SK obtained from the SPAKE2 protocol is used to calculate the ciphertext C and the authenticator {σ i }, C=E(SK,F)=c1||…||c n , Among them, M i =H(PK||i),1≤i≤n; then u i {C,{σ i },α,PK} is uploaded to the cloud storage service provider SP, and the cloud storage service provider SP checks whether the outsourced data has been stored on the server. If not, the cloud storage service provider SP stores the outsourced data locally {sh,PK,α,C,{σ i }} and create an index {sh,CS} on the blockchain for subsequent deduplication; otherwise, the cloud storage service provider SP deletes the duplicate data and returns an access link.

5. The blockchain-based cloud storage service deduplication data sharing audit method according to claim 1 is characterized in that: The data audit described in step 4 is as follows: Step 4.1: The third-party auditor TPA selects three random numbers to generate the audit challenge Chal = (z, r1, r2) and publishes it to the blockchain, where z∈[1,n], Step 4.2: According to Chal, the cloud storage service provider SP calculates the index a for the w-th challenged data block w =π1(w,r1) and coefficient b w =π2(w,r2), where w∈[1,z]; then the cloud storage service provider SP generates the integrity proof proof=(R,μ,σ) and sends it to the blockchain, where: Step 4.3: After receiving the proof of integrity from the blockchain, the third-party auditor TPA executes the verification algorithm to check the integrity of the data. The formula is as follows: If the above formula is true, the algorithm output result = 1, indicating that the cloud storage service provider SP has passed the audit; otherwise, the algorithm output result = 0, indicating that the user data has been destroyed; Step 4.4: The third-party auditor TPA publishes the audit results on the blockchain. The interaction records between the third-party auditor TPA and the cloud storage service provider SP on the blockchain constitute the audit log Log = {chalt, proof, result} for user supervision and review.

6. The blockchain-based cloud storage service deduplication data sharing audit method according to claim 1 is characterized in that: The shared audit described in step 5 is as follows: Step 5.1: User u who needs to upload data file F i Publish a notification on the blockchain to find partners j ; Then execute the Diffie-Hellman key exchange protocol and obtain the session key k through the blockchain; finally calculate the shared audit unified public-private key pair {PK, SK}: SK=h(k),PK=g SK Step 5.2: User u who needs to conduct shared audit q Calculate each file F separately q The ciphertext C q =E(SK,F q ), and for each data block c qs Calculate the audit authenticator {σ qs }: (1) Encrypt file C q Divide into n parts: C q =c q1 ||c q2 ||…||c qn ; (2) Calculate each c qj Audit certifier: Where 1≤q≤d1, 1≤s≤n, M qs =H(PK||q||s); Step 5.3, User u q Calculate file label t q =h(F q ) and α=v SK , user u q Upload q ,{σ qs },α,PK} to SP, all partners’ files will be considered as one file for inspection; Step 5.4: Users participating in the shared audit entrust the audit task to the third-party auditor TPA and sign the smart contract SC = {t q ,t j ,PK,coin q ,coin j }, where coin q 、coin j u q 、u j A pre-agreed payment for the audit services provided by the third-party auditor TPA; Step 5.5: The third-party auditor TPA generates an audit challenge Chal = (z, r1, r2) and publishes it to the blockchain. The cloud storage service provider SP takes Chal and C1, C2 as inputs and calculates the index a of the w-th challenged data block. w1 =π1(w,r1)modd1,a w2 =π1(w,r2)mod n and coefficient b w =π2(w,r2), where w∈[1,z], then the cloud storage service provider SP generates the integrity proof proof=(R,μ,σ) and sends it to the blockchain, where: Step 5.6: After receiving the proof, the third-party auditor TPA executes the verification algorithm to check the integrity of the data. The formula is as follows: If the above equation is true, the output result = 1, indicating that F q and F j All are available; otherwise, the output result = 0, indicating that the user data has been destroyed.

7. A blockchain-based cloud storage service with deduplication data sharing audit system, characterized in that: The system is used to implement the blockchain-based cloud storage service deduplication data sharing audit method described in any one of claims 1 to 6, and the system includes a user, a cloud storage service provider SP, a third-party auditor TPA, a blockchain node and a system administrator; The user is a cloud storage service user who outsources data to a cloud storage service provider SP and employs a third-party auditor TPA to check the integrity of the outsourced data; Users encrypt data before uploading it and perform data deduplication with the cloud storage service provider SP; The cloud storage service provider SP provides cloud storage services to help users store data and uses deduplication technology to delete duplicate data; the cloud storage service provider SP may be untrustworthy and may discard the user's outsourced data to save costs, and attempt to deceive the third-party auditor TPA and the user through integrity verification to hide the fact that the stored data is lost or damaged; The third-party auditor TPA has computing resources to help users audit data integrity, but is not completely trustworthy. The third-party auditor TPA may collude with the cloud storage service provider SP and fail to perform integrity verification according to the user's requirements; The blockchain node is a node in the blockchain network, responsible for maintaining blockchain data and processing blockchain transactions; The system administrator is the entity responsible for establishing certain system parameters.

8. A mobile terminal comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the blockchain-based cloud storage service deduplication data sharing audit method as described in any one of claims 1 to 6 is implemented.