Secure Data Deduplication with Dynamic Ownership Management in Cloud Storage

Junbeom Hur, Dongyoung Koo, Youngjoo Shin, Kyungtae Kang

    Research output: Contribution to journalArticlepeer-review

    118 Citations (Scopus)

    Abstract

    In cloud storage services, deduplication technology is commonly used to reduce the space and bandwidth requirements of services by eliminating redundant data and storing only a single copy of them. Deduplication is most effective when multiple users outsource the same data to the cloud storage, but it raises issues relating to security and ownership. Proof-of-ownership schemes allow any owner of the same data to prove to the cloud storage server that he owns the data in a robust way. However, many users are likely to encrypt their data before outsourcing them to the cloud storage to preserve privacy, but this hampers deduplication because of the randomization property of encryption. Recently, several deduplication schemes have been proposed to solve this problem by allowing each owner to share the same encryption key for the same data. However, most of the schemes suffer from security flaws, since they do not consider the dynamic changes in the ownership of outsourced data that occur frequently in a practical cloud storage service. In this paper, we propose a novel server-side deduplication scheme for encrypted data. It allows the cloud server to control access to outsourced data even when the ownership changes dynamically by exploiting randomized convergent encryption and secure ownership group key distribution. This prevents data leakage not only to revoked users even though they previously owned that data, but also to an honest-but-curious cloud storage server. In addition, the proposed scheme guarantees data integrity against any tag inconsistency attack. Thus, security is enhanced in the proposed scheme. The efficiency analysis results demonstrate that the proposed scheme is almost as efficient as the previous schemes, while the additional computational overhead is negligible.

    Original languageEnglish
    Article number7490366
    Pages (from-to)3113-3125
    Number of pages13
    JournalIEEE Transactions on Knowledge and Data Engineering
    Volume28
    Issue number11
    DOIs
    Publication statusPublished - 2016

    Bibliographical note

    Funding Information:
    This work was supported by the National Research Foundation of Korea (NRF) grant funded by the Korea government (MSIP) (No. 2016R1A2A2A05005402). This work was also supported by the Institute for Information & communications Technology Promotion (IITP) grant funded by the Korea government (MSIP) (No. R0190-15-2011, Development of Vulnerability Discovery Technologies for IoT Software Security). D. Koo and K. Kang are the corresponding authors of this paper.

    Publisher Copyright:
    � 2016 IEEE.

    Keywords

    • Deduplication
    • cloud storage
    • encryption
    • proof-of-ownership
    • revocation

    ASJC Scopus subject areas

    • Information Systems
    • Computer Science Applications
    • Computational Theory and Mathematics

    Fingerprint

    Dive into the research topics of 'Secure Data Deduplication with Dynamic Ownership Management in Cloud Storage'. Together they form a unique fingerprint.

    Cite this