On Security of an Identity-Based Dynamic Data Auditing Protocol for Big Data Storage

Xiong Li, Shanpeng Liu, Rongxing Lu, Xiaosong Zhang · IEEE Transactions on Big Data · 2020

In this article, we point out the security weakness of Shanget al.’s identity-based dynamic data auditing protocol for big data storage. Specifically, we identify that their protocol is vulnerable to a secret key reveal attack, i.e., the service provider (SP) can reveal the secret key of the data owner (DO) from the stored data. Further, SP can also generate a proof to pass the challenge of TPA (third party auditor) even if all block and tag pairs have been deleted. We hope that by identifying these design flaws, similar weaknesses can be avoided in future designs.

Read the paper · More papers on PaperTik