WO2016180495A1 - A method for storing data in a cloud and a network for carrying out the method - Google Patents

A method for storing data in a cloud and a network for carrying out the method Download PDF

Info

Publication number
WO2016180495A1
WO2016180495A1 PCT/EP2015/060641 EP2015060641W WO2016180495A1 WO 2016180495 A1 WO2016180495 A1 WO 2016180495A1 EP 2015060641 W EP2015060641 W EP 2015060641W WO 2016180495 A1 WO2016180495 A1 WO 2016180495A1
Authority
WO
WIPO (PCT)
Prior art keywords
cloud
data file
replicas
functions
storing
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/EP2015/060641
Other languages
French (fr)
Inventor
Jens-Matthias Bohli
Ghassan KARAME
Frederik Armknecht
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Universitaet Mannheim
NEC Europe Ltd
Original Assignee
Universitaet Mannheim
NEC Europe Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Universitaet Mannheim, NEC Europe Ltd filed Critical Universitaet Mannheim
Priority to US15/572,795 priority Critical patent/US10498819B2/en
Priority to PCT/EP2015/060641 priority patent/WO2016180495A1/en
Publication of WO2016180495A1 publication Critical patent/WO2016180495A1/en
Anticipated expiration legal-status Critical
Priority to US16/579,897 priority patent/US10873631B2/en
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network
    • H04L67/1097Protocols in which an application is distributed across nodes in the network for distributed storage of data in networks, e.g. transport arrangements for network file system [NFS], storage area networks [SAN] or network attached storage [NAS]
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/07Responding to the occurrence of a fault, e.g. fault tolerance
    • G06F11/16Error detection or correction of the data by redundancy in hardware
    • G06F11/20Error detection or correction of the data by redundancy in hardware using active fault-masking, e.g. by switching out faulty elements or by switching in spare elements
    • G06F11/2053Error detection or correction of the data by redundancy in hardware using active fault-masking, e.g. by switching out faulty elements or by switching in spare elements where persistent mass storage functionality or persistent mass storage control functionality is redundant
    • G06F11/2056Error detection or correction of the data by redundancy in hardware using active fault-masking, e.g. by switching out faulty elements or by switching in spare elements where persistent mass storage functionality or persistent mass storage control functionality is redundant by mirroring
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F3/00Input arrangements for transferring data to be processed into a form capable of being handled by the computer; Output arrangements for transferring data from processing unit to output unit, e.g. interface arrangements
    • G06F3/06Digital input from, or digital output to, record carriers, e.g. RAID, emulated record carriers or networked record carriers
    • G06F3/0601Interfaces specially adapted for storage systems
    • G06F3/0602Interfaces specially adapted for storage systems specifically adapted to achieve a particular effect
    • G06F3/0614Improving the reliability of storage systems
    • G06F3/0619Improving the reliability of storage systems in relation to data integrity, e.g. data losses, bit errors
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F3/00Input arrangements for transferring data to be processed into a form capable of being handled by the computer; Output arrangements for transferring data from processing unit to output unit, e.g. interface arrangements
    • G06F3/06Digital input from, or digital output to, record carriers, e.g. RAID, emulated record carriers or networked record carriers
    • G06F3/0601Interfaces specially adapted for storage systems
    • G06F3/0628Interfaces specially adapted for storage systems making use of a particular technique
    • G06F3/0646Horizontal data movement in storage systems, i.e. moving data in between storage devices or systems
    • G06F3/065Replication mechanisms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/12Applying verification of the received information
    • H04L63/123Applying verification of the received information received data contents, e.g. message integrity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/06Protocols specially adapted for file transfer, e.g. file transfer protocol [FTP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network
    • H04L67/1095Replication or mirroring of data, e.g. scheduling or transport for data synchronisation between network nodes
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3271Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/008Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols involving homomorphic encryption

Definitions

  • the present invention relates to a method for storing data in a cloud. Further, the present invention relates to a network for carrying out the method for storing data in a cloud.
  • Cloud services have become an integral part of our lives as they promise a convenient means for users to access and store their data from multiple devices.
  • the cloud also promises a cost-effective alternative for small and medium enterprises to offer their services without the need for huge upfront investments, e.g., to ensure high service availability.
  • SLAs Service Level Agreements
  • Availability is typically ensured by means of full replication. Replicas are typically stored onto different servers, thus ensuring data availability in spite of server failure.
  • storage services such as Amazon S3 and Google FS provide such resiliency against a maximum two concurrent failures; here, users are typically charged according to the required redundancy level.
  • the aforementioned object is accomplished by a method for storing data in a cloud, comprising the following steps:
  • a network for carrying out the method for storing data in a cloud comprising:
  • a transmitting device for transmitting to the cloud: at least one data file to be stored together with a predefined number t of replicas of the at least one data file within the cloud, at least one authentication tag corresponding to the at least one data file and t functions that can be configured to take at least a predefined time to compute;
  • a storing device for storing the at least one data file within the cloud
  • a generating device for generating the t replicas of the at least one data file based on the t solutions of the t functions and the at least one data file within the cloud, wherein each function is used for at least one replica of the at least one data file;
  • a storing device for storing the t replicas within the cloud.
  • the invention it has been recognized that it is possible to generate replicas in a cloud without preprocessing all the replicas prior to transmitting the replicas to the cloud.
  • only the at least one data file has to be transmitted to the cloud and the generation of replicas will be performed within the cloud under consideration of at least one authentication tag corresponding to the at least one data file.
  • the generating of the predefinable number t of replicas is based on t solutions of t functions and the at least one data file within the cloud, wherein each function corresponds to or is used for at least one replica of the at least one data file.
  • the t functions can be configured to take at least a predefined time to compute, wherein this time can be adapted to the time necessary for generating the replicas.
  • the inventive method for storing data in a cloud provides a basis for an efficient verification process regarding integrity for all replicas.
  • an easy and secure use of cloud services is provided by the claimed invention.
  • the t functions each can be not parallelizable. This ensures that these functions need essentially the predefined time for being computed.
  • the functions can not significantly profit from additional hardware within the cloud.
  • the t functions can comprise exponent E. Such a function will take a certain time to compute, wherein the required time can be adapted by the size of the parameter E.
  • the function can comprise a one-way function, such as a one-way hash function.
  • the t functions can be time-lock puzzles.
  • Such a time-lock puzzle is a function that can be configured to take at least a certain time to compute. Typically such functions can not be parallelized.
  • Such time-lock puzzles can be used during the generation of replicas.
  • the at least one or each puzzle can be based on exponentiation modulo a composite number or on RSA, Rivest Shamir Adleman. Additionally or alternatively at least one or each puzzle can exhibit a trapdoor based on the Euler totient function. The use of puzzles based on RSA and exhibiting a trapdoor based on the Euler totient function enables users to verify the puzzle efficiently, irrespective of the puzzle difficulty.
  • At least one or each puzzle can be based on finding a pre-image of a one-way function.
  • at least one or each puzzle can be based on inverting a one-way function, such as a one-way hash function. Additionally or alternatively the one-way function can be inverted by creating random nonces and evaluating the one-way function until a solution of the puzzle is found.
  • the t functions can be constructed in different ways. According to an embodiment the functions can be constructed that each solution has the same size of the at least one data file. Alternatively or additionally each solution can represent a replica of the at least one data file. Alternatively or additionally the functions can be constructed in a way that each solution can be efficiently verified.
  • a processed file comprising the at least one data file and the at least one authentication tag can be provided and transmitted to the cloud. Thus, a pair of data file and authentication tag can be provided for simply storing data in the cloud.
  • a challenge can be issued for blocks contained across all replicas.
  • the cloud can compute a response to the challenge under consideration of the at least one authentication tag and the data file and replicas stored. Such a response can be transmitted to the user for verification.
  • the time it takes for the cloud to respond can be measured. Usually this time must be smaller than the expected time to compute the function. Otherwise, the user will not accept the response.
  • the response can be verified under use of a trapdoor function to ensure that all replicas are stored. This provides a simple and secure proving of data replication in the cloud.
  • proof of integrity for at least one or all replicas can be performed by means of a challenge-response protocol, e.g. according to the above mentioned challenge-response proceeding.
  • proof of integrity for at least one or all replicas can be performed by use of a homomorphic nature of the authentication tag or authentication tags.
  • a compact challenge-response protocol can be provided on the basis of this homomorphic nature of the authentication tag or authentication tags.
  • a novel solution for storing data in a cloud is provided which goes beyond existing MRV solutions and enables users to efficiently verify the integrity of all their data replicas.
  • users need to process/upload their original files only once irrespective of the replication undergone by their data.
  • Our solution nevertheless provides comparable security to existing provably secure MRV schemes.
  • Embodiments of the construction of file tags use homomorphic authentication codes in order to produce compact homomorphic proofs, allowing to batch the verification of blocks pertaining to multiple replicas.
  • the user could create the required t replicas of his files, and construct the corresponding verification tags for each replica such that the proofs generated by the cloud for each replica can be combined in a way similar to Curtmola, R., Khan, O., Burns, R. C, and Ateniese, G. MR-PDP: Multiple-Replica Provable Data Possession, in ICDCS (2008), pp. 41 1 -420.
  • this alternative incurs considerable overhead on the users as it requires them to upload and pre-process all the replicas.
  • a time-lock puzzle is a function f that can be configured to take at least a certain time to compute. Typically, the function cannot be parallelized, so that it cannot significantly profit from additional hardware. In our solution, the time-lock puzzle can be used during the generation of replicas.
  • the user can store only his original files, along with the corresponding block authentication tags similar to existing POR/PDP schemes.
  • the user outsources t compact time-lock puzzles to the cloud provider, each puzzle corresponding to one replica of the file.
  • the puzzles can be constructed in such a way that (i) they require noticeable time to be solved by the cloud provider using modern hardware, e.g. 10-100 seconds, (ii) their solution is or can be used to create a replicated file with the same size of the original file, and (iii) their solution can be efficiently verified by the puzzle creator, typically much faster, e.g. ⁇ 1 second.
  • the t replicas are given by the solution of the puzzle or can be derived by combining blocks from the original file with each of the t puzzle solutions.
  • our solution ensures that users can leverage the authentication tags created to verify that the cloud provider indeed stores all replicas in a compact challenge-response protocol.
  • This puzzle is based on RSA and exhibits a trapdoor based on the Euler totient function, which enables users to verify the puzzle efficiently, irrespective of the puzzle difficulty.
  • Rivest's puzzle can be easily combined with our homomorphic tags to support batch verification of all replicas.
  • Rivest's puzzle is based on modular exponentiation. Modular Multiplication is an inherently sequential process. The running time of the fastest known algorithm for modular exponentiation is linear in the size of the exponent. Although the provider might try to parallelize the computation of the puzzle, the parallelization advantage is expected to be negligible.
  • the cloud stores the file, and computes t solutions for each puzzle instance.
  • the cloud constructs t replicas by combining the t puzzle solutions with the original file.
  • the user issues a challenge for blocks contained across all replicas.
  • the cloud computes a response from the challenge, the authentication tags created by the users, and the actual replica blocks that are stored.
  • the user measures the time it takes for the cloud to respond and efficiently verifies the response of the cloud using a trapdoor function to ensure that all replicas are stored.
  • the response is correctly verified and the response of the cloud takes below a threshold amount of time, the user is convinced that the cloud hosts all the replicas correctly. Otherwise, the user suspects that the cloud is cheating.
  • Fig. 1 is showing an embodiment of a method for storing data according to the present invention.
  • Fig. 1 shows an embodiment of a method for storing data in a cloud, including storage of a data file with creation of two replicas.
  • a challenge/response protocol is triggered by a user.
  • Fig. 1 summarizes the main operations and model assumed in embodiments of the invention:
  • the user has a file f, computes tags for a proof of retrievability and includes data needed for computing the replicas, i.e. a challenge for a time-lock function.
  • the server receives the file, the tags and the replication data and starts to transform the file for the replica storage.
  • the user is able to challenge the storage provider to obtain a proof that all replicas are stored.
  • n blocks each s sectors long, thus there are n * s sectors: m for 1 ⁇ i ⁇ n and1 ⁇ j ⁇ s.
  • the user samples the values that are necessary for verification. More precisely, the user generates n values of ZN, i.e. secreti ... secret n ⁇ - ZN and s elements of ⁇ ⁇ ( ⁇ ) , i.e, CM, . . . , a s ⁇ - ⁇ ( ⁇ ). Finally, the user computes for each i, 1 ⁇ i ⁇ n:
  • the user can compute the tags additively as
  • the user stores secret- ⁇ , . . . , secretn , CM, . . . , a s and keeps it secret.
  • We define the processed file as the pairs of the file bocks and the tags (m i; - 1 ⁇ j ⁇ s, a t 1 ⁇ i ⁇ n).
  • the processed file is uploaded to the server S.
  • the user For creating replicas of the file the user creates a large exponent E > N, as an instance of a function that takes a certain time to compute, i.e. a time-lock puzzle.
  • the required time can be adapted by the size of the parameter E.
  • the users chooses s random numbers p-i , . . . , p s ⁇ ZN for each copy the user would like to have stored.
  • the server S stores the file and the tags and begins now to create the replicas of M to increase the redundancy.
  • the numbers p are pairwise different primes.
  • the puzzle is creating a larger vector or matrix than the original file and the replica is constructed by combining multiple entries of the puzzle solution with a sector in the file.
  • £ is larger than the number of sectors in the file. Then multiple of those entries are combined with a message sector, denoted by a set of indices /.
  • the metadata meta can encode further information, such as the position of the sector in the file.
  • the protocol For the verification process, the protocol generates a random challenge of the used proof of retrievability scheme of size x.
  • the verifier picks a random x-element subset I of the set of blocks ⁇ 1 , . . . , n ⁇ , and for each i ⁇ I, a random element v, ⁇ - ⁇ ( ⁇ ) is sampled.
  • the challenge sent to the server S is the set ⁇ (i, vi) ⁇ iei of size x.
  • the server computes the response for all replicas and transmits it to the user.
  • the response comprises several parts: for the file and each replica of the file and in addition for the tags. •
  • tags are created in an additive way
  • the user obtains the response and checks if indeed all replicas are stored.
  • the check is
  • the user measures the time it takes the server to compute the response. This time must be smaller than the expected time to compute the puzzle. Otherwise, the user will not accept the response.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Human Computer Interaction (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • Quality & Reliability (AREA)
  • Storage Device Security (AREA)

Abstract

For providing an easy and secure use of cloud services a method for storing data in a cloud is claimed, comprising the following steps: providing at least one data file to be stored together with a predefined number t of replicas of the at least one data file within the cloud, at least one authentication tag corresponding to the at least one data file and t functions that can be configured to take at least a predefined time to compute; transmitting the at least one data file, the at least one authentication tag and the t functions to the cloud; storing the at least one data file within the cloud; computing t solutions of the t functions within the cloud; generating the t replicas of the at least one data file based on the t solutions of the t functions and the at least one data file within the cloud, wherein each function is used for at least one replica of the at least one data file; and storing the t replicas within the cloud. Further, an according network for carrying out the method is claimed.

Description

A METHOD FOR STORING DATA IN A CLOUD AND A NETWORK FOR CARRYING OUT THE METHOD
The present invention relates to a method for storing data in a cloud. Further, the present invention relates to a network for carrying out the method for storing data in a cloud.
Cloud services have become an integral part of our lives as they promise a convenient means for users to access and store their data from multiple devices. The cloud also promises a cost-effective alternative for small and medium enterprises to offer their services without the need for huge upfront investments, e.g., to ensure high service availability. Currently, most cloud storage services guarantee service and data availability in their Service Level Agreements, SLAs. Availability is typically ensured by means of full replication. Replicas are typically stored onto different servers, thus ensuring data availability in spite of server failure. Currently, storage services such as Amazon S3 and Google FS provide such resiliency against a maximum two concurrent failures; here, users are typically charged according to the required redundancy level.
Nevertheless, none of today's cloud providers accept any liability for data loss in their SLAs. This makes users reluctant when using cloud services due to concerns with respect to the integrity of their outsourced data. To remedy this, the literature features a number of solutions that enable users to remotely verify the integrity of stored data. Examples include Proofs of Retrievability, POR, see Shacham, H., and Waters, B. Compact Proofs of Retrievability, in ASIACRYPT (2008), pp. 90- 107, which provide end-clients with the assurance that the data is available in its entirety, and Proofs of Data Possession, PDP, see Ateniese, G., Burns, R. C, Curtmola, R., Herring, J., Kissner, L., Peterson, Z. N. J., and Song, D. X. Provable data possession at untrusted stores, in ACM Conference on Computer and Communications Security (2007), pp. 598-609, which enable a client to verify that its stored data has not undergone any modifications, among others. These schemes have been recently extended to support the remote integrity verification of multi-replicas, MRV, see Curtmola, R., Khan, O., Burns, R. C, and Ateniese, G. MR-PDP: Multiple-Replica Provable Data Possession, in ICDCS (2008), pp. 41 1 - 420; MRV enables users to verify that they are getting the value of their money by verifying the replication status and the integrity of their replicated data. All existing MRV solutions share a similar system model, requiring the users themselves to create replicas of their files, appropriately pre-process the replicas, e.g., to create authentication tags, and finally store all processed replicas onto the cloud. Clearly, existing MRV solutions incur considerable burden on the users, who are required to appropriately pre-process and upload all the replicas. For example, in order to store a 10 GB file with a replication factor of 4, a user has to process and upload almost 40 GB of content. We argue that these limitations severely hinder the large-scale integration of MRV techniques in existing clouds.
It is an object of the present invention to improve and further develop a method for storing data in a cloud and a network for carrying out this method for providing an easy and secure use of cloud services. In accordance with the invention, the aforementioned object is accomplished by a method for storing data in a cloud, comprising the following steps:
- providing at least one data file to be stored together with a predefined number t of replicas of the at least one data file within the cloud, at least one authentication tag corresponding to the at least one data file and t functions that can be configured to take at least a predefined time to compute;
- transmitting the at least one data file, the at least one authentication tag and the t functions to the cloud;
- storing the at least one data file within the cloud;
- computing t solutions of the t functions within the cloud;
- generating the t replicas of the at least one data file based on the t solutions of the t functions and the at least one data file within the cloud, wherein each function is used for at least one replica of the at least one data file; and - storing the t replicas within the cloud.
Further, the aforementioned object is accomplished by a network for carrying out the method for storing data in a cloud, comprising:
- a transmitting device for transmitting to the cloud: at least one data file to be stored together with a predefined number t of replicas of the at least one data file within the cloud, at least one authentication tag corresponding to the at least one data file and t functions that can be configured to take at least a predefined time to compute;
- a storing device for storing the at least one data file within the cloud;
- a computing device for computing t solutions of the t functions within the cloud;
- a generating device for generating the t replicas of the at least one data file based on the t solutions of the t functions and the at least one data file within the cloud, wherein each function is used for at least one replica of the at least one data file; and
- a storing device for storing the t replicas within the cloud.
According to the invention it has been recognized that it is possible to generate replicas in a cloud without preprocessing all the replicas prior to transmitting the replicas to the cloud. Concretely, according to the invention only the at least one data file has to be transmitted to the cloud and the generation of replicas will be performed within the cloud under consideration of at least one authentication tag corresponding to the at least one data file. For providing data availability with high reliability the generating of the predefinable number t of replicas is based on t solutions of t functions and the at least one data file within the cloud, wherein each function corresponds to or is used for at least one replica of the at least one data file. The t functions can be configured to take at least a predefined time to compute, wherein this time can be adapted to the time necessary for generating the replicas. The inventive method for storing data in a cloud provides a basis for an efficient verification process regarding integrity for all replicas. Thus, an easy and secure use of cloud services is provided by the claimed invention. According to an embodiment of the invention the t functions each can be not parallelizable. This ensures that these functions need essentially the predefined time for being computed. The functions can not significantly profit from additional hardware within the cloud. Alternatively or additionally the t functions can comprise exponent E. Such a function will take a certain time to compute, wherein the required time can be adapted by the size of the parameter E. Alternatively or additionally the function can comprise a one-way function, such as a one-way hash function. According to a further embodiment the t functions can be time-lock puzzles. Such a time-lock puzzle is a function that can be configured to take at least a certain time to compute. Typically such functions can not be parallelized. Such time-lock puzzles can be used during the generation of replicas. According to a further embodiment the at least one or each puzzle can be based on exponentiation modulo a composite number or on RSA, Rivest Shamir Adleman. Additionally or alternatively at least one or each puzzle can exhibit a trapdoor based on the Euler totient function. The use of puzzles based on RSA and exhibiting a trapdoor based on the Euler totient function enables users to verify the puzzle efficiently, irrespective of the puzzle difficulty.
According to a further embodiment at least one or each puzzle can be based on finding a pre-image of a one-way function. According to a further embodiment at least one or each puzzle can be based on inverting a one-way function, such as a one-way hash function. Additionally or alternatively the one-way function can be inverted by creating random nonces and evaluating the one-way function until a solution of the puzzle is found. The t functions can be constructed in different ways. According to an embodiment the functions can be constructed that each solution has the same size of the at least one data file. Alternatively or additionally each solution can represent a replica of the at least one data file. Alternatively or additionally the functions can be constructed in a way that each solution can be efficiently verified. Within a further embodiment a processed file comprising the at least one data file and the at least one authentication tag can be provided and transmitted to the cloud. Thus, a pair of data file and authentication tag can be provided for simply storing data in the cloud.
For proving data replication in the cloud a challenge can be issued for blocks contained across all replicas. Within such an embodiment the cloud can compute a response to the challenge under consideration of the at least one authentication tag and the data file and replicas stored. Such a response can be transmitted to the user for verification.
Within a further embodiment the time it takes for the cloud to respond can be measured. Usually this time must be smaller than the expected time to compute the function. Otherwise, the user will not accept the response.
Within a further embodiment the response can be verified under use of a trapdoor function to ensure that all replicas are stored. This provides a simple and secure proving of data replication in the cloud.
According to embodiments of the invention proof of integrity for at least one or all replicas can be performed by means of a challenge-response protocol, e.g. according to the above mentioned challenge-response proceeding. According to further embodiments of the invention proof of integrity for at least one or all replicas can be performed by use of a homomorphic nature of the authentication tag or authentication tags. A compact challenge-response protocol can be provided on the basis of this homomorphic nature of the authentication tag or authentication tags.
In this invention a novel solution for storing data in a cloud is provided which goes beyond existing MRV solutions and enables users to efficiently verify the integrity of all their data replicas. Notably, in our solution, users need to process/upload their original files only once irrespective of the replication undergone by their data. Our solution nevertheless provides comparable security to existing provably secure MRV schemes.
Various advantages of embodiments of the invention can be summarized as follows:
Embodiments of the construction of file tags use homomorphic authentication codes in order to produce compact homomorphic proofs, allowing to batch the verification of blocks pertaining to multiple replicas.
According to state-of-the-art, the user could create the required t replicas of his files, and construct the corresponding verification tags for each replica such that the proofs generated by the cloud for each replica can be combined in a way similar to Curtmola, R., Khan, O., Burns, R. C, and Ateniese, G. MR-PDP: Multiple-Replica Provable Data Possession, in ICDCS (2008), pp. 41 1 -420. As mentioned earlier, this alternative incurs considerable overhead on the users as it requires them to upload and pre-process all the replicas.
On the other hand, a naive solution where the cloud provider creates the replicas and their tags given the original file might be insecure since it gives considerable advantage for the provider to misbehave. In this case, the provider, e.g., could only store a single replica and construct the correct response on the fly for all other replicas when triggered by the user. Our solution bridges the gap between these two alternatives through the use of non-parallelizable time-lock puzzles. A time-lock puzzle is a function f that can be configured to take at least a certain time to compute. Typically, the function cannot be parallelized, so that it cannot significantly profit from additional hardware. In our solution, the time-lock puzzle can be used during the generation of replicas.
Namely, in our solution, the user can store only his original files, along with the corresponding block authentication tags similar to existing POR/PDP schemes. In addition, the user outsources t compact time-lock puzzles to the cloud provider, each puzzle corresponding to one replica of the file. The puzzles can be constructed in such a way that (i) they require noticeable time to be solved by the cloud provider using modern hardware, e.g. 10-100 seconds, (ii) their solution is or can be used to create a replicated file with the same size of the original file, and (iii) their solution can be efficiently verified by the puzzle creator, typically much faster, e.g. <1 second. The t replicas are given by the solution of the puzzle or can be derived by combining blocks from the original file with each of the t puzzle solutions. Here, our solution ensures that users can leverage the authentication tags created to verify that the cloud provider indeed stores all replicas in a compact challenge-response protocol.
By doing so, our solution guarantees that a cloud provider which does not correctly store the required number of replicas will be detected with overwhelming probability by users. Notably, our puzzle-based construct ensures that the time required by the provider to construct the replicas on the fly will be noticeable by users, and will provide evidence that the files are not appropriately replicated. Notice that a malicious provider could compute and store the solution of the t puzzles without effectively replicating files. We argue that this strategy is unlikely to be adopted by a rational provider since (i) our solution ensures that each puzzle solution cannot be compressed and has the same size as the original file and (ii) given the puzzle solutions, the computation of the file replicas can be efficiently performed. To do so, our primary embodiment leverages the time-lock puzzle by Rivest, see Rivest, R. L, Shamir, A., and Wagner, D. A. Time-lock puzzles and timed-release crypto, Tech. rep., Cambridge, MA, USA, 1996. The advantages of using Rivest's time lock puzzle are manyfold, namely:
• This puzzle is based on RSA and exhibits a trapdoor based on the Euler totient function, which enables users to verify the puzzle efficiently, irrespective of the puzzle difficulty.
• Since it is based on RSA, Rivest's puzzle can be easily combined with our homomorphic tags to support batch verification of all replicas. • Rivest's puzzle is based on modular exponentiation. Modular Multiplication is an inherently sequential process. The running time of the fastest known algorithm for modular exponentiation is linear in the size of the exponent. Although the provider might try to parallelize the computation of the puzzle, the parallelization advantage is expected to be negligible.
Embodiments of the present invention can show the following characteristics:
1) Combining the use of proofs of retrievability schemes with time-lock puzzles to construct proofs of replication schemes where users only upload one replica.
2) Computing proofs of integrity for all replicas in a single and compact challenge-response protocol by leveraging the homomorphic nature of our tags.
An embodiment of a method for storing data in a cloud can comprise the following steps:
For storing files and creating the replicas:
1) Processing the original file according to our solution, creating the authentication tokens, and t puzzle instances.
2) Sending the file, authentication tokens, puzzle instances to the cloud.
3) The cloud stores the file, and computes t solutions for each puzzle instance.
4) The cloud constructs t replicas by combining the t puzzle solutions with the original file.
For verifying the stored file and replicas:
5) The user issues a challenge for blocks contained across all replicas. The cloud computes a response from the challenge, the authentication tags created by the users, and the actual replica blocks that are stored.
The user measures the time it takes for the cloud to respond and efficiently verifies the response of the cloud using a trapdoor function to ensure that all replicas are stored.
If the response is correctly verified and the response of the cloud takes below a threshold amount of time, the user is convinced that the cloud hosts all the replicas correctly. Otherwise, the user suspects that the cloud is cheating.
Within embodiments of the invention users need to process/upload their original files only once irrespective of the replication undergone by their data; here, conforming with the current cloud model, the cloud provider appropriately constructs the replicas given the original user files and according to some predefined policy. Nevertheless, our solution allows users to efficiently verify the integrity of all data replicas, including those constructed by the service provider. By doing so, our solution tremendously reduces the communication costs of existing expensive MRV schemes where users are required to construct and upload the data replicas by themselves. We show, nevertheless, that our solution provides comparable security to existing provably secure MRV schemes; namely, we show that users of our solution can detect, with overwhelming probability, tampering with any of the replicas of their files.
There are several ways how to design and further develop the teaching of the present invention in an advantageous way. To this end it is to be referred to the following explanation of examples of embodiments of the invention, illustrated by the drawing. In the drawing
Fig. 1 is showing an embodiment of a method for storing data according to the present invention. Fig. 1 shows an embodiment of a method for storing data in a cloud, including storage of a data file with creation of two replicas. A challenge/response protocol is triggered by a user.
Fig. 1 summarizes the main operations and model assumed in embodiments of the invention:
• The user has a file f, computes tags for a proof of retrievability and includes data needed for computing the replicas, i.e. a challenge for a time-lock function.
• The server receives the file, the tags and the replication data and starts to transform the file for the replica storage.
• The user is able to challenge the storage provider to obtain a proof that all replicas are stored.
Further Embodiments
Computing tags:
To store a file M e {0, 1}*, the file is interpreted as n blocks, each s sectors long, thus there are n*s sectors: m for 1 <i<n and1≤j≤s. The user generates an RSA modulus N = pq by generating two primes p, q with a length according to the security parameter.
The user will then proceed to prepare the file by creating tags τ to produce as follows:
• The user samples the values that are necessary for verification. More precisely, the user generates n values of ZN, i.e. secreti ... secretn<- ZN and s elements of ΖΦ(Ν) , i.e, CM, . . . , as <- Ζφ(Ν). Finally, the user computes for each i, 1 < i < n:
σ,- = secret; *
j Π )
=l...S
As an alternative embodiment, the user can compute the tags additively as
Figure imgf000012_0001
The user stores secret-ι, . . . , secretn , CM, . . . , as and keeps it secret. We define the processed file as the pairs of the file bocks and the tags (mi;- 1≤j≤s, at 1 <i<n). The processed file is uploaded to the server S.
Creating replicas:
For creating replicas of the file the user creates a large exponent E > N, as an instance of a function that takes a certain time to compute, i.e. a time-lock puzzle. The required time can be adapted by the size of the parameter E.
1. In one embodiment, the users chooses s random numbers p-i , . . . , ps <≡ ZN for each copy the user would like to have stored. The server S stores the file and the tags and begins now to create the replicas of M to increase the redundancy. The sectors of the replicated copy is produced by multiplying the original sectors with coefficients generated from the RSA time-lock puzzle m*i,j = m,,\ -pp for i = 1 , . . . , n, j = 1 , . . . , s. That is in detail
Figure imgf000012_0002
2. In another embodiment, the numbers p, are pairwise different primes.
3. In another embodiment, only the exponent E is used and the message is directly raised to the power E:
Figure imgf000012_0003
m n.l 4. In another embodiment, the puzzle is creating a larger vector or matrix than the original file and the replica is constructed by combining multiple entries of the puzzle solution with a sector in the file. One embodiment of this idea is given by a vector with entries pEl with entries i = 1 ... £, so that the length
£ is larger than the number of sectors in the file. Then multiple of those entries are combined with a message sector, denoted by a set of indices /.
Figure imgf000013_0001
5. In another embodiment, the replica is given by a pre-image of the message under a one-way function, i.e. a replica for a sector m£y- is given by r such that
Figure imgf000013_0002
= rriij. The metadata meta can encode further information, such as the position of the sector in the file.
Verifying replicas:
For the verification process, the protocol generates a random challenge of the used proof of retrievability scheme of size x.
• With the suggested POR: The verifier picks a random x-element subset I of the set of blocks {1 , . . . , n}, and for each i ε I, a random element v, <- Ζφ(Ν) is sampled. The challenge sent to the server S is the set {(i, vi)}iei of size x.
The server computes the response for all replicas and transmits it to the user. The response comprises several parts: for the file and each replica of the file and in addition for the tags. • For each replica M*, the server computes a vector μ1, ... ,μ5 where μ] =
Figure imgf000014_0001
• For the tags σ = \[x k=i{aik j)Vk mod N
• In an alternative embodiment where the tags are created in an additive way, also the response is created additively, i.e. μί =∑x k=1 mik j - v_k mod N and σ =∑ =1\sigmai j · v_k mod N.
The user obtains the response and checks if indeed all replicas are stored. The check is made up by computing for each replica e = + ··· + vsEis and w = μ"1■ ... μ"" secret^ ... secret^. Depending of the replica algorithm the check is
w = σ Π?=Ι ΡΓ α' in case p was used or w = Ui ^'"' otherwise
The user measures the time it takes the server to compute the response. This time must be smaller than the expected time to compute the puzzle. Otherwise, the user will not accept the response.
Many modifications and other embodiments of the invention set forth herein will come to mind to the one skilled in the art to which the invention pertains having the benefit of the teachings presented in the foregoing description and the associated drawings. Therefore, it is to be understood that the invention is not to be limited to the specific embodiments disclosed and that modifications and other embodiments are intended to be included within the scope of the appended claims. Although specific terms are employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.

Claims

C l a i m s
1. A method for storing data in a cloud, comprising the following steps:
- providing at least one data file to be stored together with a predefined number t of replicas of the at least one data file within the cloud, at least one authentication tag corresponding to the at least one data file and t functions that can be configured to take at least a predefined time to compute;
- transmitting the at least one data file, the at least one authentication tag and the t functions to the cloud;
- storing the at least one data file within the cloud;
- computing t solutions of the t functions within the cloud;
- generating the t replicas of the at least one data file based on the t solutions of the t functions and the at least one data file within the cloud, wherein each function is used for at least one replica of the at least one data file; and
- storing the t replicas within the cloud.
2. A method according to claim 1 , wherein the t functions each are not parallelizable and/or comprise exponent E and/or comprise a one-way function.
3. A method according to claim 1 or 2, wherein the t functions are time-lock puzzles.
4. A method according to claim 3, wherein at least one or each puzzle is based on exponentiation modulo a composite number.
5. A method according to claim 3 or 4, wherein at least one or each puzzle exhibits a trapdoor based on the Euler totient function.
6. A method according to one of the claims 1 to 5, wherein at least one or each puzzle is based on finding a pre-image of a one-way function.
7. A method according to one of the claims 1 to 6, wherein each solution represents a replica of the at least one data file.
8. A method according to one of the claims 1 to 7, wherein each solution can be efficiently verified.
9. A method according to one of the claims 1 to 8, wherein a processed file comprising the at least one data file and the at least one authentication tag is provided and transmitted to the cloud.
10. A method according to one of the claims 1 to 9, wherein a challenge is issued for blocks contained across all replicas.
1 1. A method according to claim 10, wherein the cloud computes a response to the challenge under consideration of the at least one authentication tag and the data file and replicas stored.
12. A method according to claim 1 1 , wherein the time it takes for the cloud to respond is measured.
13. A method according to claim 1 1 or 12, wherein the response is verified under use of a trapdoor function to ensure that all replicas are stored.
14. A method according to one of the claims 1 to 13, wherein proof of integrity for at least one or all replicas is performed by means of a challenge-response protocol and/or by use of a homomorphic nature of the authentication tag or authentication tags.
15. A network for carrying out the method for storing data in a cloud according to any one of claims 1 to 14, comprising:
- a transmitting device for transmitting to the cloud: at least one data file to be stored together with a predefined number t of replicas of the at least one data file within the cloud, at least one authentication tag corresponding to the at least one data file and t functions that can be configured to take at least a predefined time to compute;
- a storing device for storing the at least one data file within the cloud; - a computing device for computing t solutions of the t functions within the cloud;
- a generating device for generating the t replicas of the at least one data file based on the t solutions of the t functions and the at least one data file within the cloud, wherein each function is used for at least one replica of the at least one data file; and
- a storing device for storing the t replicas within the cloud.
PCT/EP2015/060641 2015-05-13 2015-05-13 A method for storing data in a cloud and a network for carrying out the method Ceased WO2016180495A1 (en)

Priority Applications (3)

Application Number Priority Date Filing Date Title
US15/572,795 US10498819B2 (en) 2015-05-13 2015-05-13 Method for storing data in a cloud and network for carrying out the method
PCT/EP2015/060641 WO2016180495A1 (en) 2015-05-13 2015-05-13 A method for storing data in a cloud and a network for carrying out the method
US16/579,897 US10873631B2 (en) 2015-05-13 2019-09-24 Method for storing data in a cloud and network for carrying out the method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/EP2015/060641 WO2016180495A1 (en) 2015-05-13 2015-05-13 A method for storing data in a cloud and a network for carrying out the method

Related Child Applications (2)

Application Number Title Priority Date Filing Date
US15/572,795 A-371-Of-International US10498819B2 (en) 2015-05-13 2015-05-13 Method for storing data in a cloud and network for carrying out the method
US16/579,897 Continuation US10873631B2 (en) 2015-05-13 2019-09-24 Method for storing data in a cloud and network for carrying out the method

Publications (1)

Publication Number Publication Date
WO2016180495A1 true WO2016180495A1 (en) 2016-11-17

Family

ID=53373398

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/EP2015/060641 Ceased WO2016180495A1 (en) 2015-05-13 2015-05-13 A method for storing data in a cloud and a network for carrying out the method

Country Status (2)

Country Link
US (2) US10498819B2 (en)
WO (1) WO2016180495A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10528751B2 (en) 2017-04-13 2020-01-07 Nec Corporation Secure and efficient cloud storage with retrievability guarantees

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11245528B1 (en) 2018-11-19 2022-02-08 Protocol Labs, Inc. Protocols for decentralized networks
US11570001B1 (en) 2018-07-12 2023-01-31 Protocol Labs, Inc. Protocols for decentralized networks
US10554407B1 (en) 2018-07-12 2020-02-04 Protocol Labs, Inc. Protocols for decentralized networks
WO2020037654A1 (en) * 2018-08-24 2020-02-27 区链通网络有限公司 Blockchain data protection method, device and system, and computer-readable storage medium
CN112632638B (en) * 2020-12-24 2025-05-06 中国工商银行股份有限公司 A method and device for verifying the integrity of multi-copy data
GB202201951D0 (en) * 2022-02-15 2022-03-30 Nchain Licensing Ag Blockchain transaction

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CA2731954C (en) * 2008-07-25 2014-10-21 Roberto Tamassia Apparatus, methods, and computer program products providing dynamic provable data possession
US8346742B1 (en) * 2011-03-30 2013-01-01 Ari Juels Remote verification of file protections for cloud data storage
JP5876937B2 (en) * 2012-10-31 2016-03-02 株式会社日立製作所 Data retention verification system and method
EP3167569B1 (en) * 2014-09-30 2020-09-23 NEC Corporation Method and system for providing a secure update of code on a memory-constrained device

Non-Patent Citations (7)

* Cited by examiner, † Cited by third party
Title
ATENIESE, G.; BURNS, R. C.; CURTMOLA, R.; HERRING, J.; KISSNER, L.; PETERSON, Z. N. J.; SONG, D. X.: "Provable data possession at untrusted stores", ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2007, pages 598 - 609
AYAD F BARSOUM ET AL: "Provable Possession and Replication of Data over Cloud Servers", 30 October 2010 (2010-10-30), XP055240428, Retrieved from the Internet <URL:http://cacr.uwaterloo.ca/techreports/2010/cacr2010-32.pdf> [retrieved on 20160112] *
CURTMOLA, R.; KHAN, O.; BURNS, R. C.; ATENIESE, G.: "MR-PDP: Multiple-Replica Provable Data Possession", ICDCS, 2008, pages 411 - 420
MUKUNDAN RAGHUL ET AL: "Efficient integrity verification of replicated data in cloud using homomorphic encryption", DISTRIBUTED AND PARALLEL DATABASES, KLUWER, NL, vol. 32, no. 4, 24 June 2014 (2014-06-24), pages 507 - 534, XP035388814, ISSN: 0926-8782, [retrieved on 20140624], DOI: 10.1007/S10619-014-7151-0 *
RIVEST R L ET AL: "Time lock puzzles and timed release Crypto", INTERNET CITATION, 10 March 1996 (1996-03-10), XP002327209, Retrieved from the Internet <URL:http://theory.lcs.mit.edu/rivest/RivestShamirWagner-timelock.pdf> [retrieved on 20050504] *
RIVEST, R. L.; SHAMIR, A.; WAGNER, D. A.: "Time-lock puzzles and timed-release crypto", TECH. REP., 1996
SHACHAM, H.; WATERS, B.: "Compact Proofs of Retrievability", ASIACRYPT, 2008, pages 90 - 107

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10528751B2 (en) 2017-04-13 2020-01-07 Nec Corporation Secure and efficient cloud storage with retrievability guarantees

Also Published As

Publication number Publication date
US10873631B2 (en) 2020-12-22
US20180152513A1 (en) 2018-05-31
US20200021656A1 (en) 2020-01-16
US10498819B2 (en) 2019-12-03

Similar Documents

Publication Publication Date Title
US10873631B2 (en) Method for storing data in a cloud and network for carrying out the method
US10880310B2 (en) Method for proving retrievability of information
Shacham et al. Compact proofs of retrievability
Shacham et al. Compact proofs of retrievability
US20210271764A1 (en) Method for storing data on a storage entity
Armknecht et al. Mirror: Enabling proofs of data replication and retrievability in the cloud
Ateniese et al. Provable data possession at untrusted stores
Yu et al. Enhanced privacy of a remote data integrity-checking protocol for secure cloud storage
US10277395B2 (en) Cryptographic key-generation with application to data deduplication
Barsoum et al. Provable possession and replication of data over cloud servers
CN111066285A (en) Method for recovering public key based on SM2 signature
KR20230002941A (en) (EC)DSA Threshold Signature with Secret Sharing
Li et al. An efficient proof of retrievability with public auditing in cloud computing
WO2019110399A1 (en) Two-party signature device and method
EP3395031A1 (en) Method for storing data on a storage entity
CN112436938A (en) Digital signature generation method and device and server
EP3395032B1 (en) Method for providing a proof-of-retrievability
US20150023498A1 (en) Byzantine fault tolerance and threshold coin tossing
Cui et al. Proof of retrievability with public verifiability resilient against related‐key attacks
JP5448864B2 (en) Commitment system, master device, transmission device, reception device, commitment method, program, recording medium
Liu et al. TLARDA: Threshold Label-Aggregating Remote Data Auditing in Decentralized Environment
US12022003B2 (en) Safe use of legacy digital signatures in a post-quantum world
Omote et al. D2-POR: direct repair and dynamic operations in network coding-based proof of retrievability
Abraham et al. Proving possession and retrievability within a cloud environment: A comparative survey
Kopp et al. Publicly verifiable static proofs of storage: A novel scheme and efficiency comparisons

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15727893

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 15572795

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15727893

Country of ref document: EP

Kind code of ref document: A1