Encrypted data deduplication is an important technique for saving storage space and network bandwidth, which has been widely used in cloud storage. Recently, a number of schemes that solve the problem of data deduplication with dynamic ownership management have been proposed. However, these schemes suffer from low efficiency when the dynamic ownership changes a lot. To this end, in this paper, we propose a novel server-side deduplication scheme for encrypted data in a hybrid cloud architecture, where a public cloud (Pub-CSP) manages the storage and a private cloud (Pri-CSP) plays a role as the data owner to perform deduplication and dynamic ownership management. Further, to reduce the communication overhead we use an initial uploader check mechanism to ensure only the first uploader needs to perform encryption, and adopt an access control technique that verifies the validity of the data users before they download data. Our security analysis and performance evaluation demonstrate that our proposed server-side deduplication scheme has better performance in terms of security, effectiveness, and practicability compared with previous schemes. Meanwhile, our method can efficiently resist collusion attacks and duplicate faking attacks.
翻译:加密数据解析是保存存储空间和网络带宽的重要技术,在云层存储中广泛使用。最近,提出了若干解决数据与动态所有权管理发生重叠问题的计划。然而,当动态所有权发生很大变化时,这些计划效率较低。为此,我们在本文件中提议在混合云层结构中为加密数据建立一个全新的服务器-侧脱重叠计划,在混合云层结构中,公共云层(Pub-CSP)管理存储和私人云层(Pri-CSP)作为数据所有者发挥作用,以进行脱转和动态所有权管理。此外,为了减少通信间接费用,我们使用初始上传者检查机制确保只有第一个上传者需要进行加密,并采用访问控制技术,在数据下载前核实数据用户的有效性。我们的安全分析和性评估表明,我们提议的服务器-侧脱重叠计划在安全性、有效性和易懂性方面比以前的计划有更好的性能。同时,我们的方法可以有效抵制串联攻击和重复式攻击。