Cloud storage integrity verification method, device and equipment and readable storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA MOBILE INFORMATION TECHNOLOGY CO LTD
- Filing Date
- 2026-04-08
- Publication Date
- 2026-08-07
AI Technical Summary
[0003]本申请实施例提供一种云存储完整性的验证方法、装置、设备及可读存储介质,解决现有技术中在第三方审计者与云服务提供商之间的信道被掌握后,如何对数据进行云存储完整性验证,避免数据泄漏和被修改的问题
[0053]第七方面,还提供一种计算机程序产品,包括计算机指令,所述计算机指令被处理器执行时实现如第一方面所述的云存储完整性的验证方法,或者实现如第二方面所述的云存储完整性的验证方法。
Smart Images

Figure CN122533787A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of data security technology, specifically relating to a method, apparatus, device, and readable storage medium for verifying the integrity of cloud storage. Background Technology
[0002] Existing privacy-preserving cloud auditing solutions for cloud storage primarily involve remote auditing, allowing data owners (DOs) to audit data without downloading the entire dataset. In remote auditing, the cloud service provider (CSP) responds to random challenges from a third-party auditor (TPA) by providing an integrity certificate. The TPA verifies the certificate and feeds back the audit results to the DO. To reduce the burden on local storage, DOs typically do not retain a local copy of their data after uploading the dataset, only retaining its hash value or metadata tag. Because the random challenges initiated by the TPA in remote auditing are determined by the TPA, once the channel between the TPA and the CSP is compromised, a curious TPA can repeatedly issue the same challenge to certain specific data blocks. This not only allows them to detect potential modifications based on changes in the integrity certificate but also to infer the approximate time of the modification, leading to data leakage and modification. Summary of the Invention
[0003] This application provides a method, apparatus, device, and readable storage medium for verifying the integrity of cloud storage, addressing the problem in the prior art of how to verify the integrity of data in cloud storage after the channel between a third-party auditor and the cloud service provider has been compromised, thus preventing data leakage and modification.
[0004] Firstly, a method for verifying the integrity of cloud storage is provided, applied to third-party auditing devices, the method comprising:
[0005] Upon receiving a cloud audit request for the dataset to be audited initiated by the data-owning device, random challenge data for the dataset to be audited is generated, and the random challenge data is sent to the cloud server storing the dataset to be audited.
[0006] Upon receiving the random integrity proof result for the dataset to be audited sent by the cloud server, a first hash verification aggregate value is generated based on the random verification parameters in the random integrity proof result, and the first hash verification aggregate value is compared and verified with the second hash verification aggregate value in the random integrity proof result to obtain a first verification result.
[0007] Based on the first verification result, the verification result of the cloud storage integrity of the dataset to be audited is returned to the data-owning device.
[0008] Optionally, the cloud storage integrity verification method, wherein generating random challenge data for the dataset to be audited includes:
[0009] For each data block in the dataset to be audited, a random challenge number is generated for that data block based on the label of the data block carried in the cloud audit request.
[0010] Based on the identity identifier of the data-owning device and the identity identifier of the dataset to be audited carried in the cloud audit request, as well as the label and random challenge number of the data block, random challenge data of the dataset to be audited is generated.
[0011] Optionally, in the cloud storage integrity verification method, before generating the first hash check aggregate value based on the random verification parameters in the random integrity proof result, the method further includes:
[0012] Based on the properties of the bilinear group, the labels of the dataset to be audited in the random integrity proof result are verified to obtain a second verification result;
[0013] If the second verification result indicates that the verification is successful, then a first hash verification aggregate value is generated based on the random verification parameters in the random integrity proof result.
[0014] Optionally, the cloud storage integrity verification method, wherein generating a first hash verification aggregate value based on the random verification parameters in the random integrity proof result includes:
[0015] For each data block in the dataset to be audited, a challenge verification value for the data block is generated based on the random verification parameter in the random integrity proof result and the random challenge number of the data block in the random challenge data.
[0016] A first aggregate signature factor is generated based on the challenge verification value of the data block, the identity identifier of the data-owning device, and the label of the dataset to be audited;
[0017] Based on the mapping result obtained by bilinear mapping of the first aggregate signature factor and the mapping result obtained by bilinear mapping of the complete proof aggregate data in the random integrity proof result, a first bilinear random mapping value is obtained.
[0018] A first hash check aggregate value is generated based on the first bilinear random mapping value and the integrity check value of the data block.
[0019] Optionally, the cloud storage integrity verification method, wherein generating a first aggregate signature factor based on the challenge check value of the data block, the identity identifier of the data-owning device, and the label of the dataset to be audited, includes:
[0020] Based on the challenge verification value of the data block, a weighted aggregation is performed on the identity identifier of the data-owning device, the label of the data block, and the hash value of the dataset label to be audited; and a weighted aggregation is performed on the integrity verification value of the data block and the identity label of the data sector in the data block to generate a first aggregated signature factor.
[0021] Secondly, a method for verifying the integrity of cloud storage is also provided, applied to a cloud server, the method comprising:
[0022] Upon obtaining random challenge data of the dataset to be audited sent by a third-party auditing device, a second hash verification aggregate value is generated based on randomly selected random verification parameters;
[0023] Based on the random verification parameters, the label of the dataset to be audited, the second hash verification aggregate value, and the complete proof aggregate data, the random integrity proof result of the dataset to be audited is obtained, and the random integrity proof result is sent to the third-party auditing device.
[0024] Optionally, the cloud storage integrity verification method, wherein generating a second hash verification aggregate value based on randomly selected random verification parameters includes:
[0025] For each data block in the dataset to be audited, a challenge verification value for the data block is generated based on randomly selected random verification parameters and the random challenge number of the data block in the random challenge data.
[0026] Based on the challenge check value of each data block, obtain the integrity check value of each data block in each data sector;
[0027] A second hash verification aggregate value is generated based on the hash function, the second bilinear random mapping value, and the integrity verification value of the data block in each data sector.
[0028] Optionally, the cloud storage integrity verification method further includes:
[0029] If the uniqueness verification of the random challenge number of the data block in the random challenge data is successful, the random challenge parameters are obtained;
[0030] Based on the primary randomization label of the data sector in the data block and the random challenge parameter, the secondary randomization label of the data sector is obtained;
[0031] The complete proof aggregate data is obtained based on the second aggregate signature factor, the quadratic randomization label, and the random exponentiation result of the generator in the bilinear group.
[0032] Optionally, the cloud storage integrity verification method further includes:
[0033] The second aggregate signature factor is generated based on the first bilinear credential parameters and the label of the data block.
[0034] Optionally, the cloud storage integrity verification method further includes:
[0035] The data to be audited is obtained from the data blocks uploaded by the device and the tags of the data blocks;
[0036] The tag of the data block is obtained based on the identity identifier of the cloud server, the public key of the data ownership device, and the label of the data block.
[0037] Optionally, the cloud storage integrity verification method further includes:
[0038] Generate a certificate for the cloud server based on the public key of the cloud server;
[0039] The first bilinear credential parameters are obtained based on the private key and certificate of the cloud server.
[0040] Optionally, the cloud storage integrity verification method further includes:
[0041] The data includes the tags of the dataset to be audited uploaded by the device.
[0042] The tag of the dataset to be audited is obtained by the data-owning device based on the identity tag of the dataset to be audited, randomization parameters, identity tags of data sectors in data blocks of the dataset to be audited, identity identifier of the dataset to be audited, and time information;
[0043] The identity label of the dataset to be audited is obtained by the data-owning device based on the data-owning device's certificate, the data-owning device's private key, the data-owning device's identity identifier, and the identity identifier of the dataset to be audited.
[0044] Thirdly, a cloud storage integrity verification device is also provided, which is applied to third-party auditing equipment. The device includes:
[0045] The first generation module is used to generate random challenge data for the dataset to be audited when a cloud audit request for the dataset to be audited is initiated by the data-owning device, and send the random challenge data to the cloud server storing the dataset to be audited.
[0046] The comparison module is used to, upon receiving the random integrity proof result sent by the cloud server for the dataset to be audited, generate a first hash verification aggregate value based on the random verification parameters in the random integrity proof result, and compare the first hash verification aggregate value with the second hash verification aggregate value in the random integrity proof result to obtain a first verification result;
[0047] The return module is used to return the verification result of the cloud storage integrity of the dataset to be audited to the data-owning device based on the first verification result.
[0048] Fourthly, a cloud storage integrity verification device is also provided, applied to a cloud server, the device comprising:
[0049] The second generation module is used to generate a second hash verification aggregate value based on randomly selected random verification parameters when it obtains random challenge data of the dataset to be audited sent by a third-party auditing device.
[0050] The sending module is used to obtain the random integrity proof result of the dataset to be audited based on the random verification parameters, the label of the dataset to be audited, the second hash verification aggregate value, and the complete proof aggregate data, and send the random integrity proof result to the third-party auditing device.
[0051] Fifthly, a cloud storage integrity verification device is also provided, comprising: a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the processor executes the program or instructions to implement the cloud storage integrity verification method as described in the first aspect, or to implement the cloud storage integrity verification method as described in the second aspect.
[0052] In a sixth aspect, a computer-readable storage medium is also provided, on which a computer program is stored, which, when executed by a processor, implements the cloud storage integrity verification method as described in the first aspect, or implements the cloud storage integrity verification method as described in the second aspect.
[0053] In a seventh aspect, a computer program product is also provided, including computer instructions that, when executed by a processor, implement the cloud storage integrity verification method as described in the first aspect, or implement the cloud storage integrity verification method as described in the second aspect.
[0054] Compared with existing technologies, this application provides a method, apparatus, device, and readable storage medium for verifying the integrity of cloud storage. When a third-party auditing device receives a cloud audit request for a dataset to be audited initiated by a data-owning device, it generates random challenge data for the dataset to be audited and sends the random challenge data to the cloud server storing the dataset. The cloud server receives the random challenge data, generates a second hash verification aggregation value based on randomly selected random verification parameters, and obtains the random integrity proof result of the dataset to be audited based on the second hash verification aggregation value. This re-randomizes the random challenge data, preventing challenge replay attacks, and sends the random integrity proof result to the third-party auditing device. The third-party auditing device generates a first hash verification aggregate value based on the random verification parameters in the random integrity proof result, and compares the first hash verification aggregate value with the second hash verification aggregate value in the random integrity proof result to obtain a first verification result. Based on the first verification result, it returns the verification result of the cloud storage integrity of the dataset to be audited to the data ownership device. In this way, the third-party auditing device can verify the cloud storage integrity of the dataset to be audited. Moreover, by rerandomizing the random challenge data through the cloud server, challenge replay attacks can be avoided, as well as data leakage and modification problems can be avoided after the channel between the third-party auditing device and the cloud server is controlled. Attached Figure Description
[0055] Figure 1 This is a model diagram of the application system for the cloud storage integrity verification method described in the embodiments of this application;
[0056] Figure 2 This is a flowchart illustrating one implementation of the cloud storage integrity verification method described in the embodiments of this application;
[0057] Figure 3 This is a flowchart illustrating a cloud storage integrity verification method according to one embodiment of this application;
[0058] Figure 4 This is a flowchart illustrating another implementation of the cloud storage integrity verification method described in the embodiments of this application;
[0059] Figure 5 This is a flowchart illustrating a cloud storage integrity verification method according to another embodiment of this application;
[0060] Figure 6 This is a schematic diagram of a module of a cloud storage integrity verification device according to one embodiment of this application;
[0061] Figure 7 This is a schematic diagram of a module of a cloud storage integrity verification device according to another embodiment of this application;
[0062] Figure 8 This is a hardware block diagram of the cloud storage integrity verification device described in the embodiments of this application. Detailed Implementation
[0063] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0064] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and are not used to describe a specified order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same class, not limited in number; for example, a first object can be one or more. Furthermore, in the specification and claims, "and" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0065] This application provides a method for verifying the integrity of cloud storage, which is essentially an auditing method for the integrity of privacy datasets stored in a cloud storage environment.
[0066] Figure 1 This is a model diagram of the application system for the cloud storage integrity verification method described in the embodiments of this application. For example... Figure 1 As shown in the embodiments of this application, the application system of the cloud storage integrity verification method is the cloud storage integrity verification system, which will be referred to as the system below. The system includes four entities: data ownership device, third-party audit device, cloud server, and system manager, which correspond to four entity types: DO, TPA, CSP, and system administrator (SA).
[0067] In this system, the data-owning device is a resource-constrained device that can upload datasets to a cloud server to alleviate the burden on local storage. A third-party auditing device, employed by the data-owning device, can issue random integrity challenges to the cloud server, verify the random integrity proof results returned by the cloud server, and report the verification results of cloud storage integrity—i.e., the audit results—to the data-owning device. The cloud server possesses powerful storage and computing capabilities, providing data storage services to the data-owning device; in this system, the cloud server providing cloud storage services to the data-owning device is defined as the designated cloud server of the data-owning device, and will be referred to as the cloud server in the following text. The system manager is responsible for issuing certificates to assign legitimate identities to other entities; only entities holding valid certificates can access the system.
[0068] The man-in-the-middle (MitM) attack succeeds in the above process because the homomorphic property of homomorphic verifiable tags (HVTs) allows any entity with access to all HVTs to forge random integrity proof results. To address this issue, the homomorphic property of HVTs is temporarily disabled in this embodiment of the application, and the generation of random integrity proof results is performed... This property is restored in time. Specifically, embodiments of this application allow data-owning devices to generate HVTs by embedding the identity information of a cloud server. After the data-owning device deletes the local backup, only the cloud server can restore the homomorphic property and generate a valid random integrity proof result. In this way, the embodiments of this application provide a random integrity proof result. It introduces unforgeability, thereby preventing MitM attacks.
[0069] Furthermore, to defend against Challenge Replay Attacks (CRAs) from semi-honest third-party auditing devices, this application proposes a challenge generation method called re-randomization challenge. CRAs succeed because the selection of the challenged data block and the challenge coefficient are entirely determined by the third-party auditing device. However, allowing the cloud server to control the challenged data block is impractical, as it might intentionally select an intact data block. This application employs a solution where the challenge coefficient is jointly determined by the cloud server and the third-party auditing device. In this case, by changing the challenge coefficient, even when facing the same challenge, the cloud server will return a different random integrity proof result.
[0070] Figure 2 This is a flowchart illustrating one implementation of the cloud storage integrity verification method described in the embodiments of this application.
[0071] like Figure 2 As shown, the method includes steps 1 to 13, where steps 1 to 3 are the first stage, which completes the initialization work, including the generation of bilinear group, master private key, master public key and collision-resistant hash function and the release of system parameters.
[0072] Steps 4 to 7 constitute the second stage. The data-owning device or cloud server generates a private key and a public key, and applies to the system manager for registration. The system manager generates a certificate based on the public key of the data-owning device or cloud server and returns it. The registrant (i.e., the data-owning device or cloud server) verifies the validity of the certificate to confirm whether the registration is successful.
[0073] Steps 8 through 13 constitute the third stage. The data-owning device outsources the data to the cloud server. First, to protect data privacy, the data-owning device encrypts the outsourced data and divides the local encrypted dataset into multiple parts. The data-owning device generates dataset tags and embeds the cloud server's identity identifier into the tags of the data blocks based on the cloud server's identity identifier and public key. Subsequently, only the cloud server can generate random integrity proof results. Afterward, the data-owning device outsources the dataset tags, encrypted data blocks, and tags of the encrypted data blocks to the cloud server, deleting the original data locally. This identity-embedded tag generation method effectively reduces the risk of MitM attacks.
[0074] Specifically, the data ownership device generates tags for data blocks. At that time, a cloud server-based identity identifier will be embedded. and public key Calculate the parameters of the second bilinear voucher as follows:
[0075] ;
[0076] parameters The following formula is used to generate the labels for the data blocks:
[0077] .
[0078] This allows the data block's label to be directly associated with the cloud server's identity information. When generating the proof, the cloud server needs to calculate the first bilinear credential parameters. And based on the first bilinear voucher parameters Labels for data blocks Processing is performed to obtain the second aggregate signature factor. .in, This is the private key of the cloud server, held only by the cloud server itself. Because... The computation must rely on the private key of the cloud server, and the subsequently generated random integrity proof result Based on Further deduction reveals that other entities, unable to obtain the cloud server's private key, are unable to generate the correct first bilinear credential parameters. and the corresponding second aggregate signature factor Therefore, it is impossible to generate a valid random integrity proof result.
[0079] It should be noted that steps 1 to 13 above are the process by which the data-owning device uploads the dataset to be audited to the cloud server in this embodiment of the application.
[0080] The following is a detailed explanation of each of the above steps:
[0081] Step 1, the system manager determines the security parameters. Generate a bilinear group ,in It is a prime number. There are two respectively Factorial cyclic group, where The subscript refers to the base. It is the input group of a bilinear mapping. yes Generators; The subscript refers to the target. It is the output group of the bilinear mapping; It is a bilinear mapping ;
[0082] Step 2, System Manager randomly selects As the master private key Based on the generator and the master private key Obtain the master key in Indicates less than The set of non-zero positive integers, excluding 0;
[0083] Step 3, (1) The system manager defines the following collision-resistant hash function:
[0084] ; ; ; ; ; ; ;
[0085] in, Indicates numbers smaller than prime numbers The set of non-negative integers is also a prime field;
[0086] (1) The system manager defines a pseudo-random function. ;
[0087] (1) The System Manager publishes the following system parameters:
[0088] ;
[0089] Step 4: Given data, identify the device. ,in The maximum bit length of the identity identifier. express A set consisting of bit strings, i.e., 0- The set of numbers in the range -1;
[0090] Data ownership device randomly selected As a private key Based on the generator and private key Obtain the public key ,in Indicates identity identifier The data contains random numbers selected by the device. Indicates identity identifier The data possesses the device's public key;
[0091] Step 5, use System Manager , , and The certificate for the device is generated based on a defined anti-collision hash function. And send it to the data-owning device;
[0092] Step 6, Data Ownership Device Usage Equation Verify the certificate; if the equation holds true, it means the data-owning device registration is successful. Based on the properties of the bilinear group, the following formula can be obtained:
[0093] ;
[0094] Step 7, cloud server, based on identity identifier Repeat steps 1 to 6 above to obtain the private key for the cloud service. Public key and certificates ;
[0095] Step 8: The data-owning device will transfer the dataset (i.e., the dataset to be audited, as described below) to the data-owning device. Named And split the dataset into Data blocks Each data block includes Data sectors, represented as ,in Indicates the first The first data block One data sector;
[0096] Step 9: The data-owning device randomly selects auxiliary variables. ,calculate ,in , For randomization parameters, It's a label that carries identity;
[0097] Step 10, the data ownership device identifies itself based on its identity. and private key ,generate Individual elements: ,in A unique identifier generated for the identity binding of the j-th data sector, i.e., the identity label of the data sector. Give Add a randomization factor, i.e. To randomize the labels and avoid predictable or forged tags;
[0098] Step 11, the data owner sets the dataset label, as follows:
[0099] ,in For timestamps;
[0100] Step 12, the data ownership device identifies itself based on the cloud server's identity. and public key For each data block Generate labels, i.e., labels for data blocks. , means as follows:
[0101] ,in It is the label of the data block in the dataset;
[0102] Calculate the bilinear mappings and multiply them to obtain the parameters of the second bilinear voucher, as shown below:
[0103] ,in Indicates to Perform exponentiation calculation, exponent It is an auxiliary variable randomly selected in step 9;
[0104] Here, the data has the device's tag in the data block. Embedded cloud server identity identifier and public key This serves as the random integrity proof result obtained for subsequent integrity verification of the dataset to be audited by the cloud server. It introduces non-forgeability, prevents MitM attacks, effectively compensates for the security vulnerabilities of remote auditing solutions, and thus avoids MitM from modifying and destroying the privacy-sensitive data of the data-owning device.
[0105] Step 13, the data-owning device labels the dataset. Data blocks and data block labels Upload to the cloud server, and retain the dataset labels only locally. and delete local data blocks. and data block labels .
[0106] Figure 3 This is a flowchart illustrating a cloud storage integrity verification method according to one embodiment of this application. Figure 3 As shown in the figure, this application provides a method for verifying the integrity of cloud storage, applied to a third-party auditing device. The method includes:
[0107] Step 301: Upon receiving a cloud audit request for the dataset to be audited initiated by the data-owning device, generate random challenge data for the dataset to be audited. The random challenge data is then sent to the cloud server storing the dataset to be audited. ;
[0108] Here, the third-party auditing device sending the random challenge data to the cloud server means that the third-party auditing device is sending a CRA to the cloud server.
[0109] Step 302: After obtaining the random integrity proof result for the dataset to be audited sent by the cloud server. In the case of the aforementioned random integrity proof result Random verification parameters in Generate the first hash verification aggregate value and aggregate the first hash verification value With the aforementioned random integrity proof results The second hash check aggregate value A comparative verification was conducted to obtain the first verification result;
[0110] In this embodiment of the application, based on the result of the random integrity proof... Random verification parameters in Regenerate the hash verification aggregate value, i.e., the first hash verification aggregate value. and aggregate the first hash verification value With the aforementioned random integrity proof results The second hash check aggregate value A comparative verification was conducted, and the first verification result was obtained.
[0111] It should be noted that both the first hash check aggregate value and the second hash check aggregate value are used to compress the integrity check value and bilinear random mapping value of the data blocks in the dataset to be audited. Therefore, the first hash check aggregate value can be called the first hash check compressed value, and the second hash check aggregate value can be called the second hash check compressed value.
[0112] Step 303: Based on the first verification result, return the verification result of the cloud storage integrity of the dataset to be audited to the data-owning device.
[0113] In this embodiment of the application, if the first verification result indicates that the verification is successful, the verification result of the cloud storage integrity of the dataset to be audited is returned to the data ownership device as data integrity, for example, the verification result is represented by 1; if the first verification result indicates that the verification is unsuccessful, the verification result of the cloud storage integrity of the dataset to be audited is returned to the data ownership device as data incomplete or data tampered with, for example, the verification result is represented by 0.
[0114] The cloud storage integrity verification method described in this application involves a third-party auditing device generating random challenge data. And send the random challenge data to the cloud server storing the dataset to be audited. This involves initiating a random challenge. The cloud server receives the data for this random challenge. That is, to receive the random challenge, one can use randomly selected verification parameters. and random challenge data Random challenge number of data blocks in Generate the challenge test value of the data block. To achieve re-randomization of the challenge, a new random challenge is generated, and then the cloud server uses the test value of this challenge. Generate random integrity proof results This can protect against CRAs from semi-honest third-party auditing equipment, i.e., avoid CRAs.
[0115] Figure 4 This is a flowchart illustrating another embodiment of the cloud storage integrity verification method described in this application. The above-mentioned return of the cloud storage integrity verification result of the dataset to be audited to the data ownership device corresponds to... Figure 4 Step 21 in the process.
[0116] In one implementation, optionally, random challenge data is generated for the dataset to be audited. ,include:
[0117] For each data block in the dataset to be audited, the data block number carried in the cloud audit request is used as the basis for the audit. Generate a random challenge number for the data block. ;
[0118] The data carried in the cloud audit request identifies the device. and the identity identifier of the dataset to be audited and the label of the data block. and Random Challenge Generate random challenge data for the dataset to be audited. .
[0119] In this embodiment of the application, the third-party auditing device first identifies the labels of the data blocks in the dataset to be audited. Generate a random challenge number for the data block. ,in , is a non-empty subset , It is based on the identification of the device through data. and labels of the dataset to be audited Selected; then, based on the data, the device is identified. and the identity identifier of the dataset to be audited and the label of the data block. and Random Challenge Random challenge data of the dataset to be audited is obtained. , means as follows:
[0120] ;
[0121] The third-party auditing device will randomly challenge the dataset to be audited. Send to the cloud server.
[0122] The random challenge data that generated the above-mentioned dataset to be audited corresponds to... Figure 4 Steps 14 and 15 in the process.
[0123] In one implementation method, optionally, based on the result of the random integrity proof... Random verification parameters in Generate the first hash verification aggregate value Previously, the method also included:
[0124] Based on the properties of bilinear groups, the proof of the random integrity is presented. Labels of the dataset to be audited Perform verification to obtain a second verification result;
[0125] If the second verification result indicates that the verification passed, then according to the random integrity proof result... Random verification parameters in Generate the first hash verification aggregate value .
[0126] In this embodiment, the third-party auditing device first labels the dataset to be audited based on the nature of the two-line group. Verification is performed, that is, verifying the correctness or legality. This is done using the following formula:
[0127] ;
[0128] In the left side of the above formula, the labels of the dataset to be audited are... Public key of the data-owning device Data context hash generator exponentiation Substitution Figure 2 Bilinear mapping in step 1 If the dataset to be audited is labeled If the data is forged or the data parameters are tampered with, the mapping result on the left side of the above equation will be abnormal.
[0129] The right side of the above equation contains the identity hash of the device that owns the data. With the system's master public key Substitute into bilinear mapping If the data possesses the device's public key. If the data is invalid or the identity hash has been tampered with, the mapping result on the right will be abnormal. Therefore, third-party auditing devices possess the device's identity identifier based on the data. and public key Validation can detect the labels of the dataset to be audited. The validity of the result is specifically verified using the following formula:
[0130] .
[0131] The above-mentioned second verification result corresponds to Figure 4 Step 19 in the process.
[0132] Next, if the second verification result indicates that the verification passed, the third-party auditing device will proceed according to the random integrity proof result. Random verification parameters in Generate the first hash verification aggregate value .
[0133] In one implementation method, optionally, the random integrity proof result is used as the basis. Random verification parameters in Generate the first hash verification aggregate value ,include:
[0134] For each data block in the dataset to be audited, based on the result of the random integrity proof... Random verification parameters in and the random challenge data The random challenge number of the data block in the middle Generate the challenge verification value of the data block. ;
[0135] Based on the challenge verification value of the data block Data ownership device identification and labels of the dataset to be audited Generate the first aggregate signature factor ;
[0136] According to the first aggregate signature factor The mapping result obtained by performing bilinear mapping, and the result of the random integrity proof. Complete proof aggregate data in The mapping result obtained by performing a bilinear mapping yields the first bilinear random mapping value. ;
[0137] According to the first bilinear random mapping value and the integrity check value of the data block Generate the first hash verification aggregate value .
[0138] In this embodiment, the third-party auditing device uses a mapping function to generate a challenge verification value for each data block in the dataset to be audited. , Based on the challenge verification value of the data block Data ownership device identification and labels of the dataset to be audited Generate the first aggregate signature factor .
[0139] Using bilinear mapping The mapping result is obtained, including: based on the first aggregate signature factor. With the initial commitment of the data inverse After the association operation, the random integrity proof result is applied. The second hash check aggregate value The weighted mapping result, and the complete proof aggregate data. with group generators The mapping results; based on the above two mapping results, the first bilinear random mapping value is obtained. , represented as .
[0140] Traversing data sectors Based on the challenge check value of the data block and random challenge parameters Obtain each of the data blocks Integrity check value of the j-th data sector .
[0141] According to the first bilinear random mapping value and the integrity check value of all data blocks in the dataset to be audited. Using a collision-resistant hash function Generate the first hash verification aggregate value .
[0142] In one implementation, optionally, the challenge check value of the data block and the identity identifier of the data-owning device are used. and labels of the dataset to be audited Generate the first aggregate signature factor, including:
[0143] Based on the challenge verification value of the data block The device that owns the data has an identity identifier. The label of the data block and the labels of the dataset to be audited The hash values are weighted and aggregated; and the integrity verification value of the data block is calculated. and the identity tags of the data sectors in the data block Perform weighted aggregation to generate the first aggregation signature factor. .
[0144] In this embodiment, a collision-resistant hash function is used. The device has an identity identifier based on the data. The label of the data block and labels of the dataset to be audited , obtain hash value and according to the challenge check value of the data block. Perform weighted aggregation; and, verify the integrity of the data block. and the identity tags of the data sectors in the data block Perform weighted aggregation to generate a first aggregated signature factor that aggregates the identity and integrity of the data blocks. , means as follows:
[0145] .
[0146] The above generates the first hash verification aggregate value. correspond Figure 4 Step 20 in the process.
[0147] Here, the rationale for comparing and verifying the generated first hash check aggregate value with the second hash check aggregate value in the received random integrity proof result is explained. The rationale is given by the following equation: if the data is complete, the equation holds; otherwise, the equation does not hold.
[0148] ;
[0149] in, It is the second aggregate signature factor, which merges the signature credentials of multiple data blocks; It is a secondary randomization label for data sectors, adding audit random numbers to the data block labels to prevent forgery; It provides complete proof of aggregate data, integrating multiple parameters; It is an auxiliary random seed; It is the second bilinear random mapping value, which transforms private random numbers into publicly verifiable mapping values; It is the aggregate signature factor recalculated by the auditor to verify parameter consistency; It is a data commitment, relating to the initial state of the data; It is the hash check aggregate value, the integrity check value of the compressed data block, and the first bilinear random mapping value; It is the first bilinear random mapping value calculated by the third-party auditing equipment, used to derive the second bilinear random mapping value. equivalence; It is the integrity check value of the data block, reflecting the integrity of the data block; It is a random challenge number for a data block, bound to a specific data block; These are random verification parameters that limit the scope of the audit. It is the identity identifier of the device that owns the data, binding the data ownership.
[0150] Third-party auditing equipment can verify data integrity using the above formula. By leveraging the multiplicative and exponential properties of bilinear mappings, data integrity verification is transformed into a derivation of parameter self-consistency. Through this derivation... = It can verify the cloud server generated , , The parameters are logically consistent, have not been tampered with, and the data block signatures, tags, randomization factors, and system parameters are legally associated. This process does not require access to the original data, thus protecting data privacy.
[0151] Specifically:
[0152] ;
[0153] as well as:
[0154] .
[0155] Figure 5 This is a flowchart illustrating a cloud storage integrity verification method according to another embodiment of this application. Figure 5 As shown in the figure, this application provides a method for verifying the integrity of cloud storage, applied to a cloud server, the method comprising:
[0156] Step 501: Obtain random challenge data of the dataset to be audited sent by the third-party auditing device. In this case, based on randomly selected random verification parameters Generate the second hash check aggregate value ;
[0157] Step 502, according to the random verification parameters Labels of the dataset to be audited The second hash verification aggregate value and complete proof aggregate data Obtain the random integrity proof result of the dataset to be audited. And send the random integrity proof result to the third-party auditing device. .
[0158] In this embodiment of the application, the random verification parameters are obtained. Labels of the dataset to be audited The second hash verification aggregate value Complete proof of aggregate data Proof of random integrity .
[0159] Specifically, obtain the labels of the dataset to be audited. The second hash verification aggregate value Complete proof of aggregate data Integrity check values of all data blocks in each data sector and the random verification parameters Proof of random integrity In one implementation, optionally, the verification parameters are based on randomly selected random verification parameters. Generate the second hash check aggregate value ,include:
[0160] For each data block in the dataset to be audited, according to randomly selected random verification parameters and the random challenge data The random challenge number of the data block in the middle Generate the challenge test value of the data block. ;
[0161] Based on the challenge test value of each data block Obtain the integrity check value of each data block in each data sector. ;
[0162] Based on the anti-collision hash function and the second bilinear random mapping value and the integrity check value of the data block in each data sector Generate the second hash check aggregate value .
[0163] In this embodiment, a pseudo-random function is used, based on randomly selected random verification parameters. and the random challenge data The random challenge number of the data block in the middle Generate the challenge test value of the data block. .
[0164] Randomly select auxiliary seed Obtain the second bilinear random mapping value Then, the integrity check value of the data block in each data sector is... When both hashes are input into the anti-collision hash function, a second hash check aggregate value is generated. .
[0165] The above generates the second hash verification aggregate value. correspond Figure 4 Step 17 in the process.
[0166] The cloud storage integrity verification method described in this application involves a third-party auditing device generating random challenge data. And send the random challenge data to the cloud server storing the dataset to be audited. This involves initiating a random challenge. The cloud server receives the data for this random challenge. That is, to receive the random challenge, one can use randomly selected verification parameters. and random challenge data Random challenge number of data blocks in Generate the challenge test value of the data block. To achieve re-randomization of the challenge, a new random challenge is generated, and then the cloud server uses the test value of this challenge. Generate random integrity proof results This can protect against CRAs from semi-honest third-party auditing equipment, i.e., avoid CRAs.
[0167] In one embodiment, optionally, the method further includes:
[0168] Random challenge number for data blocks in the random challenge data If the uniqueness verification passes, obtain random challenge parameters. ;
[0169] Based on the randomization label of the data sector in the data block and the random challenge parameters The secondary randomized label of the data sector is obtained. ;
[0170] Based on the second aggregate signature factor and the secondary randomization label The complete proof aggregate data is obtained by using the random exponentiation results of the generators in the bilinear group. .
[0171] In this embodiment of the application, the cloud server verifies the random challenge number of the data block in the random challenge data. If the uniqueness verification passes, a random challenge parameter is randomly selected. and random validation parameters ,correspond Figure 4 Step 16 in the process.
[0172] Based on the randomization label of the data sector in the data block and the random challenge parameters Calculate the second randomized label It is the label of the data sector, corresponding to Figure 4 Step 17 in the process.
[0173] According to the second aggregate signature factor All secondary randomized labels product and the result of random exponentiation of generators in the bilinear group Obtain the complete proof aggregate data. ,correspond Figure 4 Step 18 in the process.
[0174] In one embodiment, optionally, the method further includes:
[0175] According to the label of the data block And the first bilinear certificate parameter Generate the second aggregate signature factor .
[0176] In this embodiment, a bilinear mapping is used, based on the identity identifier of the cloud server. Private key ,Certificate and randomization parameters Obtain the parameters of the first bilinear voucher. .
[0177] According to the label of the data block And the first bilinear certificate parameter Aggregate them to generate the second aggregate signature factor. ,correspond Figure 4 Step 17 in the process.
[0178] In one embodiment, optionally, the method further includes:
[0179] The data to be acquired includes data blocks and tags from the dataset to be audited uploaded by the device. ;
[0180] The label of the data block It is based on the identity identifier of the cloud server. and the public key of the data-owning device and the label of the data block Obtained. Here, in the label of the data block. The identity identifier of the cloud server is embedded in it. The result of proving random integrity. The introduction of non-forgeability prevents MitM attacks, effectively mitigating security vulnerabilities in remote auditing solutions and thus avoiding MitM's modification and destruction of privacy-sensitive data on the data-owning device.
[0181] It should be noted that obtaining the tags of the data blocks... The process is as follows Figure 2 Step 12 has already been explained above and will not be repeated here.
[0182] In one embodiment, optionally, the method further includes:
[0183] Generate a certificate for the cloud server based on the public key of the cloud server;
[0184] The first bilinear credential parameters are obtained based on the private key and certificate of the cloud server.
[0185] In one embodiment, optionally, the method further includes:
[0186] The data to be audited is obtained from the tags uploaded by the device. ;
[0187] Among them, the labels of the dataset to be audited The data-owning device is identified by the identity tag of the dataset to be audited. Randomization parameters Identity tags of data sectors in data blocks within the dataset to be audited The identity identifier of the dataset to be audited And the time information t is obtained, where the time information includes the timestamp t;
[0188] The identity tags of the dataset to be audited The data ownership device is based on the data ownership device's certificate and the data ownership device's private key. The data contains the device's identity identifier. and the identity identifier of the dataset to be audited Obtained.
[0189] It should be noted that the process of obtaining the labels of the dataset to be audited and the identity labels of the dataset to be audited has been explained above and will not be repeated here.
[0190] Here, for Figure 4 To summarize steps 14 to 21, which constitute the fourth stage, the data-owning device initiates a cloud audit request, and a third-party auditing device reviews the data integrity on its behalf. The third-party auditing device generates random challenge data, and the cloud server generates a random integrity proof result based on randomly selected verification parameters. This prevents the third-party auditing device from launching a challenge replay attack to determine whether the user has legitimately modified the data. The third-party auditing device verifies the obtained random integrity proof result and relays it to the data-owning device.
[0191] The randomness introduced in this application's embodiment for integrity proof against third-party auditing devices effectively prevents challenge replay attacks, preventing third-party auditing devices from gaining access to data and protecting device privacy through replay challenges. Cloud servers also need to incorporate randomness, such as random challenge parameters, random verification parameters, and auxiliary random seeds, so that the final random integrity proof result is random and unpredictable for third-party auditing devices. Third-party auditing devices cannot infer changes in cloud storage data based on this, thus causing replay challenges to fail.
[0192] Therefore, the above four stages in this application embodiment realize the system construction, identity authentication, data outsourcing and cloud auditing processes in cloud storage. Under the premise of effectively completing cloud auditing, it can prevent MitM attacks, challenge replay attacks and other behaviors from threatening the security of cloud storage systems, thereby improving the security and privacy of cloud storage systems.
[0193] In summary, the cloud storage integrity verification method described in this application verifies the cloud storage integrity of the dataset to be audited. It also proposes temporarily disabling the homomorphic property of HVTs (Host Virtualization Tests) and restoring it when generating random integrity proof results, allowing the data-owning device to generate HVTs by embedding the cloud server's identity. After the data-owning device deletes the local backup, only the cloud server can restore the homomorphic property and generate a valid random integrity proof result. This approach introduces unforgeability into the random integrity proof result, preventing MitM attacks, effectively mitigating security vulnerabilities in remote auditing schemes, and avoiding MitM modifications and damage to user privacy-sensitive data.
[0194] Specifically, MitM attackers monitor the interactions between the data-owning device, third-party auditing devices, and the cloud server, and forge random integrity proof results to conceal their attack. In this embodiment, the data-owning device is required to embed the cloud server's public key and identity identifier when generating the tag, binding the data tag and the cloud server's public and private keys based on a bilinear mapping. This ensures that the party generating the random integrity proof result must also use the cloud server's private key to pass verification. Since the cloud server's private key is not publicly available and is known only to the cloud server itself, even if MitM intercepts the information, it cannot forge the random integrity proof result.
[0195] Furthermore, this application embodiment allows the cloud server and third-party auditing equipment to jointly determine the challenge coefficient. In this case, even for the same challenge, by changing the challenge coefficient, the cloud server generates a challenge verification value based on randomly selected random verification parameters, realizing re-randomization of the challenge and forming a new random challenge. Then, based on this challenge verification value, a different random integrity proof result is generated and returned, thereby preventing CRA, improving the security of the cloud auditing solution, protecting user modification privacy, and preventing third-party auditing equipment from violating user privacy and making it impossible for them to infer user modification behavior.
[0196] Specifically, in this application embodiment, the randomness to be proven is not solely determined by the third-party auditing device; randomness must also be introduced into the cloud server, ensuring that the final proof is random and unpredictable for the third-party auditing device. Consequently, the third-party auditing device cannot determine the changes in cloud storage data blocks and therefore cannot implement CRA.
[0197] like Figure 6 As shown in the illustration, this application also provides a cloud storage integrity verification device, applied to third-party auditing equipment, the device comprising:
[0198] The first generation module 601 is used to generate random challenge data for the dataset to be audited when a cloud audit request for the dataset to be audited is initiated by the data-owning device, and send the random challenge data to the cloud server storing the dataset to be audited.
[0199] The comparison module 602 is used to, upon receiving the random integrity proof result sent by the cloud server for the dataset to be audited, generate a first hash verification aggregate value based on the random verification parameters in the random integrity proof result, and compare and verify the first hash verification aggregate value with the second hash verification aggregate value in the random integrity proof result to obtain a first verification result;
[0200] The return module 603 is used to return the verification result of the cloud storage integrity of the dataset to be audited to the data-owning device based on the first verification result.
[0201] Optionally, in the cloud storage integrity verification method, the first generation module 601 is specifically used for:
[0202] For each data block in the dataset to be audited, a random challenge number is generated for that data block based on the label of the data block carried in the cloud audit request.
[0203] Based on the identity identifier of the data-owning device and the identity identifier of the dataset to be audited carried in the cloud audit request, as well as the label and random challenge number of the data block, random challenge data of the dataset to be audited is generated.
[0204] Optionally, in the cloud storage integrity verification method, the apparatus further includes:
[0205] The verification module is used to verify the labels of the dataset to be audited in the random integrity proof result based on the properties of the bilinear group, and obtain a second verification result;
[0206] The comparison module 602 is specifically used to generate a first hash verification aggregate value based on the random verification parameters in the random integrity proof result if the second verification result indicates that the verification is successful.
[0207] Optionally, in the cloud storage integrity verification method, the comparison module 602 includes:
[0208] The first generation unit is used to generate a challenge verification value for each data block in the dataset to be audited, based on the random verification parameters in the random integrity proof result and the random challenge number of the data block in the random challenge data.
[0209] The second generation unit is used to generate a first aggregate signature factor based on the challenge verification value of the data block, the identity identifier of the data ownership device, and the label of the dataset to be audited;
[0210] The mapping unit is used to obtain a first bilinear random mapping value by performing a bilinear mapping on the mapping result obtained by performing a bilinear mapping on the complete proof aggregate data in the random integrity proof result.
[0211] The third generation unit is used to generate a first hash check aggregate value based on the first bilinear random mapping value and the integrity check value of the data block.
[0212] Optionally, in the cloud storage integrity verification method, the second generation unit is specifically used for:
[0213] Based on the challenge verification value of the data block, a weighted aggregation is performed on the identity identifier of the data-owning device, the label of the data block, and the hash value of the dataset label to be audited; and a weighted aggregation is performed on the integrity verification value of the data block and the identity label of the data sector in the data block to generate a first aggregated signature factor.
[0214] It should be noted that the apparatus provided in this application embodiment can implement all the method steps implemented in the above-mentioned cloud storage integrity verification method embodiment applied to third-party auditing equipment, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0215] like Figure 7 As shown in the illustration, this application also provides a cloud storage integrity verification device, applied to a cloud server, the device comprising:
[0216] The second generation module 701 is used to generate a second hash verification aggregate value based on randomly selected random verification parameters when it obtains random challenge data of the dataset to be audited sent by a third-party auditing device.
[0217] The sending module 702 is used to obtain the random integrity proof result of the dataset to be audited based on the random verification parameters, the label of the dataset to be audited, the second hash verification aggregate value, and the complete proof aggregate data, and to send the random integrity proof result to the third-party auditing device.
[0218] Optionally, in the cloud storage integrity verification method, the second generation module 701 is specifically used for:
[0219] For each data block in the dataset to be audited, a challenge verification value for the data block is generated based on randomly selected random verification parameters and the random challenge number of the data block in the random challenge data.
[0220] Based on the challenge check value of each data block, obtain the integrity check value of each data block in each data sector;
[0221] A second hash verification aggregate value is generated based on the hash function, the second bilinear random mapping value, and the integrity verification value of the data block in each data sector.
[0222] Optionally, in the cloud storage integrity verification method, the apparatus further includes:
[0223] The first obtaining module is used to obtain random challenge parameters when the uniqueness verification of the random challenge number of the data block in the random challenge data is passed;
[0224] The randomization module is used to obtain the secondary randomization label of the data sector based on the primary randomization label of the data sector in the data block and the random challenge parameter;
[0225] The second obtaining module is used to obtain the complete proof aggregate data based on the second aggregate signature factor, the quadratic randomization label, and the random exponentiation result of the generator in the bilinear group.
[0226] Optionally, in the cloud storage integrity verification method, the apparatus further includes:
[0227] The third generation module is used to generate the second aggregate signature factor based on the first bilinear voucher parameters and the label of the data block.
[0228] Optionally, in the cloud storage integrity verification method, the apparatus further includes:
[0229] The first acquisition module is used to acquire data blocks and tags of the data blocks in the dataset to be audited uploaded by the data ownership device;
[0230] The tag of the data block is obtained based on the identity identifier of the cloud server, the public key of the data ownership device, and the label of the data block.
[0231] Optionally, in the cloud storage integrity verification method, the apparatus further includes:
[0232] The fourth generation module is used to generate a certificate for the cloud server based on the public key of the cloud server;
[0233] The third obtaining module is used to obtain the first bilinear credential parameters based on the private key and certificate of the cloud server.
[0234] Optionally, in the cloud storage integrity verification method, the apparatus further includes:
[0235] The second acquisition module is used to acquire the tags of the auditable dataset uploaded by the data ownership device;
[0236] The tag of the dataset to be audited is obtained by the data-owning device based on the identity tag of the dataset to be audited, randomization parameters, identity tags of data sectors in data blocks of the dataset to be audited, identity identifier of the dataset to be audited, and time information;
[0237] The identity label of the dataset to be audited is obtained by the data-owning device based on the data-owning device's certificate, the data-owning device's private key, the data-owning device's identity identifier, and the identity identifier of the dataset to be audited.
[0238] It should be noted that the apparatus provided in this application embodiment can implement all the method steps implemented in the above-mentioned cloud storage integrity verification method embodiment applied to cloud server, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0239] This application also provides a cloud storage integrity verification device, such as... Figure 8 As shown, it includes:
[0240] The processor 801, memory 802, transceiver 803, and a program or instructions stored in the memory 802 and executable on the processor 801; when the processor 801 executes the program or instructions, it implements the various processes of the above-described cloud storage integrity verification method embodiment and achieves the same technical effect. To avoid repetition, it will not be described again here.
[0241] The transceiver 803 is used to receive and send data under the control of the processor 801.
[0242] Among them, Figure 8 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically connecting various circuits of one or more processors represented by processor 801 and memory represented by memory 802. The bus architecture can also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 803 can be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. For different user equipment, the user interface 804 can also be an interface capable of connecting external or internal devices, including but not limited to keypads, displays, speakers, microphones, joysticks, etc.
[0243] The processor 801 is responsible for managing the bus architecture and general processing, while the memory 802 can store the data used by the processor 801 when performing operations.
[0244] This application also provides a computer-readable storage medium storing a computer program. When executed by a processor, the computer program implements the various processes of the above-described cloud storage integrity verification method embodiments and achieves the same technical effects. To avoid repetition, it will not be described again here. The computer-readable storage medium may include read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk, etc.
[0245] This application also provides a computer program product, including computer instructions. When the computer instructions are executed by a processor, they implement the various processes of the above-described cloud storage integrity verification method embodiment and achieve the same technical effect. To avoid repetition, they will not be described again here.
[0246] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0247] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0248] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.
Claims
1. A method for verifying the integrity of cloud storage, characterized in that, The method, applied to third-party auditing equipment, includes: Upon receiving a cloud audit request for the dataset to be audited initiated by the data-owning device, random challenge data for the dataset to be audited is generated, and the random challenge data is sent to the cloud server storing the dataset to be audited. Upon receiving the random integrity proof result for the dataset to be audited sent by the cloud server, a first hash verification aggregate value is generated based on the random verification parameters in the random integrity proof result, and the first hash verification aggregate value is compared and verified with the second hash verification aggregate value in the random integrity proof result to obtain a first verification result. Based on the first verification result, the verification result of the cloud storage integrity of the dataset to be audited is returned to the data-owning device.
2. The method according to claim 1, characterized in that, The random challenge data for generating the dataset to be audited includes: For each data block in the dataset to be audited, a random challenge number is generated for that data block based on the label of the data block carried in the cloud audit request. Based on the identity identifier of the data-owning device and the identity identifier of the dataset to be audited carried in the cloud audit request, as well as the label and random challenge number of the data block, random challenge data of the dataset to be audited is generated.
3. The method according to claim 1, characterized in that, Before generating the first hash check aggregate value based on the random verification parameters in the random integrity proof result, the method further includes: Based on the properties of the bilinear group, the labels of the dataset to be audited in the random integrity proof result are verified to obtain a second verification result; If the second verification result indicates that the verification is successful, then a first hash verification aggregate value is generated based on the random verification parameters in the random integrity proof result.
4. The method according to claim 2, characterized in that, Based on the random verification parameters in the random integrity proof result, a first hash verification aggregate value is generated, including: For each data block in the dataset to be audited, a challenge verification value for the data block is generated based on the random verification parameter in the random integrity proof result and the random challenge number of the data block in the random challenge data. A first aggregate signature factor is generated based on the challenge verification value of the data block, the identity identifier of the data-owning device, and the label of the dataset to be audited; Based on the mapping result obtained by bilinear mapping of the first aggregate signature factor and the mapping result obtained by bilinear mapping of the complete proof aggregate data in the random integrity proof result, a first bilinear random mapping value is obtained. A first hash check aggregate value is generated based on the first bilinear random mapping value and the integrity check value of the data block.
5. The method according to claim 4, characterized in that, Based on the challenge check value of the data block, the identity identifier of the data-owning device, and the label of the dataset to be audited, a first aggregate signature factor is generated, including: Based on the challenge verification value of the data block, a weighted aggregation is performed on the identity identifier of the data-owning device, the label of the data block, and the hash value of the dataset label to be audited; and a weighted aggregation is performed on the integrity verification value of the data block and the identity label of the data sector in the data block to generate a first aggregated signature factor.
6. A method for verifying the integrity of cloud storage, characterized in that, Applied to cloud servers, the method includes: When random challenge data of the dataset to be audited is obtained from the third-party auditing device, a second hash verification aggregate value is generated based on randomly selected random verification parameters; Based on the random verification parameters, the label of the dataset to be audited, the second hash verification aggregate value, and the complete proof aggregate data, the random integrity proof result of the dataset to be audited is obtained, and the random integrity proof result is sent to the third-party auditing device.
7. The method according to claim 6, characterized in that, Based on randomly selected verification parameters, a second hash verification aggregate value is generated, including: For each data block in the dataset to be audited, a challenge verification value for the data block is generated based on randomly selected random verification parameters and the random challenge number of the data block in the random challenge data. Based on the challenge check value of each data block, obtain the integrity check value of each data block in each data sector; A second hash verification aggregate value is generated based on the hash function, the second bilinear random mapping value, and the integrity verification value of the data block in each data sector.
8. The method according to claim 6, characterized in that, The method further includes: If the uniqueness verification of the random challenge number of the data block in the random challenge data is successful, the random challenge parameters are obtained; Based on the primary randomization label of the data sector in the data block and the random challenge parameter, the secondary randomization label of the data sector is obtained; The complete proof aggregate data is obtained based on the second aggregate signature factor, the quadratic randomization label, and the random exponentiation result of the generator in the bilinear group.
9. The method according to claim 8, characterized in that, The method further includes: The second aggregate signature factor is generated based on the first bilinear credential parameters and the label of the data block.
10. The method according to claim 9, characterized in that, The method further includes: The data to be audited is obtained from the data blocks uploaded by the device and the tags of the data blocks; The tag of the data block is obtained based on the identity identifier of the cloud server, the public key of the data ownership device, and the label of the data block.
11. The method according to claim 9, characterized in that, The method further includes: Generate a certificate for the cloud server based on the public key of the cloud server; The first bilinear credential parameters are obtained based on the private key and certificate of the cloud server.
12. The method according to claim 6, characterized in that, The method further includes: The data includes the tags of the dataset to be audited uploaded by the device. The tag of the dataset to be audited is obtained by the data-owning device based on the identity tag of the dataset to be audited, randomization parameters, identity tags of data sectors in data blocks of the dataset to be audited, identity identifier of the dataset to be audited, and time information; The identity label of the dataset to be audited is obtained by the data-owning device based on the data-owning device's certificate, the data-owning device's private key, the data-owning device's identity identifier, and the identity identifier of the dataset to be audited.
13. A cloud storage integrity verification device, characterized in that, Applied to third-party auditing equipment, the device includes: The first generation module is used to generate random challenge data for the dataset to be audited when a cloud audit request for the dataset to be audited is initiated by the data-owning device, and send the random challenge data to the cloud server storing the dataset to be audited. The comparison module is used to, upon receiving the random integrity proof result sent by the cloud server for the dataset to be audited, generate a first hash verification aggregate value based on the random verification parameters in the random integrity proof result, and compare and verify the first hash verification aggregate value with the second hash verification aggregate value in the random integrity proof result to obtain a first verification result; The return module is used to return the verification result of the cloud storage integrity of the dataset to be audited to the data-owning device based on the first verification result.
14. A cloud storage integrity verification device, characterized in that, The device, applied to a cloud server, includes: The second generation module is used to generate a second hash verification aggregate value based on randomly selected random verification parameters when it obtains random challenge data of the dataset to be audited sent by a third-party auditing device. The sending module is used to obtain the random integrity proof result of the dataset to be audited based on the random verification parameters, the label of the dataset to be audited, the second hash verification aggregate value, and the complete proof aggregate data, and send the random integrity proof result to the third-party auditing device.
15. A cloud storage integrity verification device, characterized in that, include: A processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the processor, when executing the program or instructions, implements the cloud storage integrity verification method as described in any one of claims 1 to 5, or implements the cloud storage integrity verification method as described in any one of claims 6 to 12.
16. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the cloud storage integrity verification method as described in any one of claims 1 to 5, or implements the cloud storage integrity verification method as described in any one of claims 6 to 12.
17. A computer program product, characterized in that, It includes computer instructions that, when executed by a processor, implement the cloud storage integrity verification method as described in any one of claims 1 to 5, or implement the cloud storage integrity verification method as described in any one of claims 6 to 12.