Comments on “SCLPV: Secure Certificateless Public Verification for Cloud-Based Cyber-Physical-Social Systems Against Malicious Auditors”

Feng Wang, Li Xu, Wei Gao · IEEE Transactions on Computational Social Systems · 2018

With the development of cloud storage, how to protect the integrity of the data stored in the cloud becomes the clients’ major concern. Recently, Zhang et al. proposed a certificateless data integrity auditing scheme for cloud-assisted cyber-physical-social systems. However, we find that their scheme has some security flaws, i.e., if a client outsources a file with$m$blocks data and tags, the cloud server can store only one block of them, and pass the integrity auditing of the auditor. We refer to this attack as storing one block attack. Then, we give an improved scheme to amend these flaws.

Read the paper · More papers on PaperTik