Subversion-Resistant Password-Protected Encryption Scheme for Secure Deduplicated Cloud Storage
Researchers have developed a novel approach to secure deduplicated cloud storage, addressing the limitations of existing password-protected encryption schemes. The proposed method, SR-PPE, employs a signature-based authentication mechanism, an enhanced distributed partially oblivious pseudorandom function, and a Merkle tree-based challenge-response mechanism to ensure strong security and practical efficiency.
Key Takeaways:
- SR-PPE enables subversion-resistant password-protected encryption for deduplicated cloud storage by providing a secure and efficient solution for authentication and key generation.
- The scheme uses a signature-based authentication mechanism, which eliminates the need for per-user credentials and password-hardening keys, reducing storage overhead and computational cost.
- The enhanced distributed partially oblivious pseudorandom function ensures secure key generation and resists password-guessing attacks by binding computation to users' identities.
- A Merkle tree-based challenge-response mechanism enables efficient authentication across multiple servers, reducing the risk of subversion attacks.
- The reverse firewall deployed between users and externals prevents subversion attacks by generating unbiased randomness and re-randomizing outgoing messages.
- The security analysis under multiple adversary models shows that SR-PPE provides strong security, while the evaluation of communication, computation, and storage costs shows practical efficiency.
- The research has been peer-reviewed and published in the Journal of Information Security and Applications.
Statistics:
- 94: The issue number of the Journal of Information Security and Applications where the research was published.
- 2025: The year in which the research was conducted and published.
- 4: The number of security limitations addressed by SR-PPE.
- 3: The number of adversary models used in the security analysis.
- 1: The number of reverse firewall deployed between users and externals.
Sources:
- VerticalNews, "Study Findings from Central China Normal University Provide New Insights into Information and Data Encoding and Encryption (Towards Subversion-resistant Password-protected Encryption for Deduplicated Cloud Storage)" (2025).
- Journal of Information Security and Applications, "Towards Subversion-resistant Password-protected Encryption for Deduplicated Cloud Storage" (2025, Vol. 94).
- NewsRx LLC, "Study Findings from Central China Normal University Provide New Insights into Information and Data Encoding and Encryption (Towards Subversion-resistant Password-protected Encryption for Deduplicated Cloud Storage)" (2025, November 4).