Block Tag Updatable Certificate-Based Integrity Auditing for Long-Term Cloud Storage

Jinzhu Cai, Futai Zhang, Wenjie Yang, Shaojun Yang · IEEE Internet of Things Journal · 2025

Cloud auditing enables remote data integrity verification without downloading the entire dataset, significantly advancing cloud storage services. In long-term usage scenarios, key exposure poses a critical challenge, as a compromised private key enables the cloud service provider (CSP) to forge tags for incorrect data. Although key updatable auditing protocols have been proposed to mitigate key exposure risks, most do not support tag updates triggered by key changes, allowing the CSP to still exploit the leaked historical key for tag forgery. In this article, we propose a block tag updatable certificate-based integrity auditing protocol for long-term cloud storage. By leveraging certificate-based cryptography, our protocol eliminates the need for costly secure channels. It supports simultaneous key and tag updates, ensuring that even with previous private key leaks, the CSP cannot forge valid tags under newly updated key-pairs. The protocol achieves high efficiency through: 1) 2-D data partitioning that reduces computational and storage overhead; 2) optimized tag generation requiring only one map-to-point hash function operation for multiple data blocks; 3) strategic delegation of computationally intensive tag update operations to the CSP; and 4) constant-time proof verification regardless of the number of challenged blocks. Security proofs and performance evaluations demonstrate that the protocol offers desirable security and efficiency, making it well-suited for long-term cloud storage.

Read the paper · More papers on PaperTik