Comments on “A Public Auditing Protocol With Novel Dynamic Structure for Cloud Data”

Xiong Li, Shanpeng Liu, Rongxing Lu · IEEE Transactions on Information Forensics and Security · 2020

In this paper, we discuss a security weakness of Shenet al.’s public auditing protocol for cloud data [IEEE Transactions on Information Forensics and Security, 12(10): 2402-2415, 2017.]. Specifically, we point out their protocol is vulnerable to a data privacy breach attack,i.e., an adversary, once he compromises the third-party auditor latently, can also obtain all data owners’ outsourced data by constructing appropriate challenges. As a result, it breaks the property of “privacy preserving”. We hope that by identifying this design flaw, similar weaknesses can be avoided in future designs.

Read the paper · More papers on PaperTik