《计算机应用》唯一官方网站 ›› 2025, Vol. 45 ›› Issue (4): 1249-1255.DOI: 10.11772/j.issn.1001-9081.2024050605

• 网络空间安全 • 上一篇    下一篇

基于格的后量子无证书公共审计方案

马海峰1(), 蔡杰伟1, 薛庆水1, 杨家海2, 韩静1, 卢子譞1   

  1. 1.上海应用技术大学 计算机科学与信息工程学院,上海 201418
    2.清华大学 网络科学与网络空间研究院,北京 100084
  • 收稿日期:2024-05-14 修回日期:2024-07-22 接受日期:2024-07-26 发布日期:2024-08-20 出版日期:2025-04-10
  • 通讯作者: 马海峰
  • 作者简介:蔡杰伟(1998—),男,广东潮州人,硕士研究生,主要研究方向:格密码、云计算安全
    薛庆水(1971—),男,山东济南人,教授,博士,CCF会员,主要研究方向:网络空间安全
    杨家海(1966—),男,浙江丽水人,教授,博士生导师,博士,主要研究方向:互联网网络管理、网络测量安全
    韩静(2000—),女,江苏扬州人,硕士研究生,主要研究方向:网络安全、隐私保护
    卢子譞(1998—),男,新疆克拉玛依人,硕士研究生,主要研究方向:网络安全、数字签名。
  • 基金资助:
    国家电网资助项目(SGHAXTOOWWJS2200033)

Post-quantum certificateless public audit scheme based on lattice

Haifeng MA1(), Jiewei CAI1, Qingshui XUE1, Jiahai YANG2, Jing HAN1, Zixuan LU1   

  1. 1.School of Computer Science and Information Engineering,Shanghai Institute of Technology,Shanghai 201418,China
    2.Institute for Network Sciences and Cyberspace,Tsinghua University,Beijing 100084,China
  • Received:2024-05-14 Revised:2024-07-22 Accepted:2024-07-26 Online:2024-08-20 Published:2025-04-10
  • Contact: Haifeng MA
  • About author:CAI Jiewei, born in 1998, M. S. candidate. His research interests include lattice-based cryptography, cloud computing security.
    XUE Qingshui, born in 1971, Ph. D., professor. His research interests include cyberspace security.
    YANG Jiahai, born in 1966, Ph. D., professor. His research interests include internet network management, network measurement security.
    HAN Jing, born in 2000, M. S. candidate. Her research interests include network security, privacy protection.
    LU Zixuan, born in 1998, M. S. candidate. His research interests include network security, digital signature.
  • Supported by:
    State Grid Project(SGHAXTOOWWJS2200033)

摘要:

对存储在云服务器上的数据进行周期性的审计,是确保存储在云上数据的安全性和完整性的核心策略,它可以有效识别和应对可能存在的数据篡改或丢失的风险。然而传统的公共审计方案存在证书管理问题或密钥托管等问题,进而在数据的查询和动态修改过程中存在隐私泄露问题;此外,随着量子计算技术的不断发展,传统公钥体制下的公共审计方案面临被量子计算机破解的严重威胁。为了解决以上问题,提出一种基于格的后量子无证书公共审计方案。首先,使用无证书公钥密码体制,以解决传统公共审计方案中的证书管理和密钥托管问题;其次,在数据查询和动态修改过程中,数据拥有者(DO)无需提供具体的数据块信息,从而保证DO的隐私;最后,采用格密码学的技术抵抗量子计算机的攻击。理论分析和实验对比结果验证了所提方案可以抵御恶意攻击并保证DO操作的隐私,同时在标签生成方面具备更高的效率。

关键词: 格, 云存储, 公共审计, 无证书密码学, 后量子安全

Abstract:

Periodic audit of data stored on cloud servers is a core strategy to ensure the security and integrity of cloud-stored data. It can identify and address the risks of data tampering or loss effectively. However, traditional public audit schemes suffer from issues such as certificate management or key escrow, leading to privacy leak problem during data querying and dynamic modification. Furthermore, with the continuous development of quantum computing technology, public audit schemes based on traditional public key systems face serious threats of being cracked by quantum computers. To address the above issues, a post-quantum certificateless public audit scheme based on lattice was proposed. Firstly, a certificateless public key cryptosystem was used to solve the certificate management and key escrow problems in traditional public audit schemes. Secondly, during data querying and dynamic modification processes, Data Owners (DO) were not required to provide specific data block information, thereby ensuring the privacy of the DO. Finally, lattice cryptography technology was employed to resist attacks from quantum computers. Theoretical analysis and experimental comparison results demonstrate that the proposed scheme can resist malicious attacks while ensuring the privacy of DO operations, and it achieves higher efficiency in label generation.

Key words: lattice, cloud storage, public audit, certificateless cryptography, post-quantum security

中图分类号: