Encrypted data deduplication is an important technique for eliminating duplicate copies of repeating data, and has been widely used in cloud storage to save storage space and network bandwidth. Recently, several deduplication schemes solving the privacy-preserving problem of dynamic ownership management have been proposed. However, these schemes suffer from low efficiency when the cloud user joining and revocation frequently go on, especially in the absence of a trusted third party. In this paper, we propose a novel server-side deduplication scheme for encrypted data in a hybrid cloud architecture, where a public cloud (Pub-CSP) manages the storage and a private cloud (Pri-CSP) plays a role as the data owner to perform deduplication and dynamic ownership management. Further, to mitigate the communication overhead we adopt a pre-verified accessing control approach to prevent the unauthorized cloud users from downloading data and use an initial uploader check mechanism to ensure only the first uploader needs to perform encryption. Our security analysis and performance evaluation demonstrate that our proposed scheme has better performance in terms of security, effectiveness, and practicability compared with other schemes.
翻译:加密数据解析是消除重复数据复制件的重要技术,并被广泛用于云层储存,以节省存储空间和网络带宽。最近,提出了若干解决动态所有权管理的隐私保护问题的解析计划。然而,当云层用户经常加入和撤销时,这些计划效率低,特别是在没有受信任的第三方的情况下。在本文中,我们提议在混合云结构中为加密数据建立一个全新的服务器-侧解析计划,公共云(Pub-CSP)管理存储和私人云(Pri-CSP)作为数据拥有者发挥作用,以进行解析和动态所有权管理。此外,为了减轻通信管理,我们采取了预先核实的访问控制办法,防止未经授权的云用户下载数据,并使用初始上传检查机制,仅确保第一次上载者需要进行加密。我们的安全分析和绩效评估表明,我们提议的计划在安全、有效性和可操作性方面与其他计划相比,在安全性、有效性和可操作性方面表现更好。