On the Security of Privacy-Preserving Cross-Domain Authentication and Data Deduplication Protocol
Jianhong Zhang, Zian Yan, Menglong Wu, Qijia Zhang · 2021 7th Annual International Conference on Network and Information Systems for Computers (ICNISC) · 2021
Recently, Yang et al. proposed a privacy-preserving cross-domain data deduplication scheme in cloud (IEEE Transactions on Big Data, DOI 10.1109/TBDATA.2017.2721444) to achieve both privacy-preserving and data availability and to resist brute-force attacks. Their scheme was claimed to resist the brute-force attack from Cloud Server Provider. Unfortunately, in this work, we analyze the security of Yang et al. scheme, analysis indicates that their scheme can be brute-force attack, therefore, their scheme is insecure. After analyzing the reasons to produce such an attack, we suggest an improved method to overcome such an attack.