On the security of a dynamic-hash-table based public auditing protocol
Jianhong Zhang, Shuai Liu, Jian Mao · 2016
Cloud-based data storage is a popular cloud services. It can alleviate data management burden of data owner. However, after data file is transferred to the cloud, data owner is not able to physical dominate these outsourced data file. To efficiently ensure these data intact, several ReD-based integrity checking schemes were presented to ensure data integrity. Due to periodical checking, many data integrity checking schemes makes that the verifier takes high computational cost or communication overhead to verify data intactness. This results in a heavy burden for some schemes. Recently, to ensure secure cloud storage, a dynamic-hash-Table based public auditing protocol was put forward to achieve data privacy protection and data dynamics. An outstanding feature of the protocol is to significantly decease computational cost and communication cost in terms of cloud server and the verifier. Very regretfully, in this work, we will point out that their protocol is not secure. Our attack enables a malicious cloud server to arbitrarily delete or alter the outsourced data without being inspected by the verifier. And We analyze the reason to produce such attack and give a advice to fix the problem. Finally, we also point out that their protocol still exist a security threat: malicious auditor attack, and analyze the corresponding reason to produce such threat.