以多鏈結雜湊於證明違約中達成有效率的證據收集
No Thumbnail Available
Date
2014
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
在雲端儲存空間中,對於使用者與服務提供者之間保持雙方不可否認性是非常重要的。根據證明違約(POV),可以讓服務提供者證明自己是無辜的以及讓使用者證明自己沒有過失,證明方法是根據使用者附上電子簽章的請求以及服務提供者維護資料在一個明確的狀態雙方所留下來的證據。使用者每次請求都會和服務提供者交換證據。這些證據是被單一鏈結雜湊所串連起來的,所以客戶端裝置可以只儲存最後一個證據,而且裡面包含著最後一個鏈結雜湊。服務提供者保留所有的證據以供稽核。
C&L scheme在不需要廣播最後一個證據或者保留證據的情況下達成了時段性證明違約,然而儘管存取動作是對同一帳戶下的不同檔案它仍然無法支援同步存取,因為所有證據都必須串聯成單一鏈結雜湊。我們解決C&L scheme中的這個問題,藉由應用多鏈結雜湊來達成檔案的同步存取。
A POV scheme enables a user or a service provider to produce a precise proof of either the occurrence of the violation of properties or the innocence of the service provider. These proofs are based on attestations, which are signed messages that bind the users to the requests they make and the service provider to maintaining the data in a certain state. Users and the service provider exchange attestations for every request. These attestations are chain hashed so that the client device of the user only has to store the last attestation it received, which contains the last chain hash. The service provider keeps all the attestations, so that they can be used when auditing (or proving) is required. While the C&L scheme can achieve epoch-based POV without the need for client devices to broadcast the latest attestation or keep all the attestations, it cannot support concurrent accesses even though these operations access different files because all the server-side attestations need to be combined into a single chain. We solve this problem by employing multiple chains of hash to provide concurrent file accesses in a single account.
A POV scheme enables a user or a service provider to produce a precise proof of either the occurrence of the violation of properties or the innocence of the service provider. These proofs are based on attestations, which are signed messages that bind the users to the requests they make and the service provider to maintaining the data in a certain state. Users and the service provider exchange attestations for every request. These attestations are chain hashed so that the client device of the user only has to store the last attestation it received, which contains the last chain hash. The service provider keeps all the attestations, so that they can be used when auditing (or proving) is required. While the C&L scheme can achieve epoch-based POV without the need for client devices to broadcast the latest attestation or keep all the attestations, it cannot support concurrent accesses even though these operations access different files because all the server-side attestations need to be combined into a single chain. We solve this problem by employing multiple chains of hash to provide concurrent file accesses in a single account.
Description
Keywords
雲端儲存, 雲端安全, 不可否認性, 證明違約, 服務階層協定, Cloud Storage, Cloud Security, nonrepudiation, proof of violation, SLA, service-level agreement