Xiaodong Yang, LI Ruiting, Songyu Li, Na Wang, Caifen Wang
With the rapid growth of cloud storage user scale, there are dual challenges of resource waste and security hazards in massive data storage: on the one hand, redundant data exacerbates storage overhead; on the other hand, unauthorized access exacerbates the possibility of data leakage or tampering. To this end, this paper designs a shared data auditing scheme that supports fine-grained access control and cloud deduplication. First, combining Random Convergent Encryption (RCE), Proof-of-Ownership (PoW) technology, and introducing a certificate-less cryptosystem to securely deduplicate data in the cloud while eliminating certificate management and key escrow risks. Second, the data is encrypted using Ciphertext-Policy Attribute-Based Encryption (CP-ABE) technology, and only authorized users can decrypt the data based on attribute matching, which can effectively resist the risk of data leakage due to unauthorized access. At the same time, we designate an auditor to carry out data integrity auditing to prevent malicious audit behavior. Finally, Security and performance evaluations show that the scheme we’ve proposed is quite efficient and competitive.