DocumentCode :
1845940
Title :
Efficient simultaneous privately and publicly verifiable robust provable data possession from elliptic curves
Author :
Hanser, Christian ; Slamanig, Daniel
Author_Institution :
Institute for Applied Information Processing and Communications (IAIK), Graz University of Technology (TUG), Inffeldgasse 16a, 8010 Graz, Austria
fYear :
2013
fDate :
29-31 July 2013
Firstpage :
1
Lastpage :
12
Abstract :
When outsourcing large sets of data to the cloud, it is desirable for clients to efficiently check, whether all outsourced data is still retrievable at any later point in time without requiring to download all of it. Provable data possession (PDP)/proofs of retrievability (PoR), for which various constructions exist, are concepts to solve this issue. Interestingly, by now, no PDP/PoR scheme leading to an efficient construction supporting both private and public verifiability simultaneously is known. In particular, this means that up to now all PDP/PoR schemes either allow public or private verifiability exclusively, since different setup procedures and metadata sets are required. However, supporting both variants simultaneously seems interesting, as publicly verifiable schemes are far less efficient than privately verifiable ones. In this paper, we propose the first simultaneous privately and publicly verifiable (robust) PDP protocol, which allows the data owner to use the more efficient private verification and anyone else to run the public verification algorithm. Our construction, which is based on elliptic curves, achieves this, as it uses the same setup procedure and the same metadata set for private and public verifiability. We provide a rigorous security analysis and prove our construction secure in the random oracle model under the assumption that the elliptic curve discrete logarithm problem is intractable. We give detailed comparisons with the most efficient existing approaches for either private or public verifiability with our proposed scheme in terms of storage and communication overhead, as well as computational effort for the client and the server. Our analysis shows that for choices of parameters, which are relevant for practical applications, our construction outperforms all existing privately and publicly verifiable schemes significantly. This means, that even when our construction is used for either private or public verifiability alone, it still - utperforms the most efficient constructions known, which is particularly appealing in the public verifiability setting.
Keywords :
Elliptic curves; Games; Protocols; Robustness; Security; Servers; ECDLP; Elliptic Curves; Outsourced Storage; Proofs of Retrievability; Provable Data Possession; Provable Security; Remote Data Checking; Simultaneous Public and Private Verifiability;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security and Cryptography (SECRYPT), 2013 International Conference on
Conference_Location :
Reykjavik, Iceland
Type :
conf
Filename :
7223152
Link To Document :
بازگشت