Computer Science ›› 2020, Vol. 47 ›› Issue (10): 290-300.doi: 10.11896/jsjkx.191000111

Research and Development of Data Storage Security Audit in Cloud

BAI Li-fang1,2, ZHU Yue-fei1, LU Bin1   

  1. 1 School of Cyberspace Security,Information Engineering University,Zhengzhou 450000,China
    2 Cybersecurity Testing Engineering Technology Center,China Software Testing Center,Beijing 100048,China
  • Received:2019-10-17 Revised:2020-01-17 Online:2020-10-15 Published:2020-10-16
  • About author:BAI Li-fang,born in 1990,doctorial student,is a member of China Computer Federation.Her main research interests include cloud storage security and network security protocol.
    ZHU Yue-fei,born in 1964,Ph.D,professor,Ph.D supervisor.His main research interests include cryptography,data security and network security protocol.
  • Supported by:
    National Key R&D Program of China (2016YF0801601) and Young Scientists Fund Program of the National Natural Science Foundation of China(61601517)

Abstract: Compared with traditional storage,cloud storage can avoid repeated construction and maintenance of storage platform.Its storage capacity and performance scalability,non-binding geographical location and fee-on-demand service mode effectively optimize storage and social resource allocation.However,due to the separation of data ownership and management rights in cloud storage services,users pay more and more attention to the security and controllability of cloud data.Researchers at home and abroad have conducted a lot of studies on this.The security risks and security audit requirements of cloud data in each stage of its life cycle are discussed.The framework structure of mechanisms of cloud data storage security audit is constructed and the main evaluation index of the audit mechanism is proposed.This paper reviews the existing mechanisms of cloud data storage security audit,including data provable data possession mechanism,provable data retrievability mechanism,outsourcing storage regularity audit mechanism and storage location audit mechanism.Finally,the shortcomings of the existing cloud data storage security audit research from different perspectives and the direction for further research are pointed out.

Key words: Auditing framework, Cloud storage, Outsourcing storage regularity, Provable data possession, Provable data retrievability, Storage security auditing

