Subversion-Resistant Password-Protected Encryption Scheme for Secure Deduplicated Cloud Storage

Researchers have developed a novel approach to secure deduplicated cloud storage, addressing the limitations of existing password-protected encryption schemes. The proposed method, SR-PPE, employs a signature-based authentication mechanism, an enhanced distributed partially oblivious pseudorandom function, and a Merkle tree-based challenge-response mechanism to ensure strong security and practical efficiency.

Key Takeaways:

  • SR-PPE enables subversion-resistant password-protected encryption for deduplicated cloud storage by providing a secure and efficient solution for authentication and key generation.
  • The scheme uses a signature-based authentication mechanism, which eliminates the need for per-user credentials and password-hardening keys, reducing storage overhead and computational cost.
  • The enhanced distributed partially oblivious pseudorandom function ensures secure key generation and resists password-guessing attacks by binding computation to users' identities.
  • A Merkle tree-based challenge-response mechanism enables efficient authentication across multiple servers, reducing the risk of subversion attacks.
  • The reverse firewall deployed between users and externals prevents subversion attacks by generating unbiased randomness and re-randomizing outgoing messages.
  • The security analysis under multiple adversary models shows that SR-PPE provides strong security, while the evaluation of communication, computation, and storage costs shows practical efficiency.
  • The research has been peer-reviewed and published in the Journal of Information Security and Applications.

Statistics:

  • 94: The issue number of the Journal of Information Security and Applications where the research was published.
  • 2025: The year in which the research was conducted and published.
  • 4: The number of security limitations addressed by SR-PPE.
  • 3: The number of adversary models used in the security analysis.
  • 1: The number of reverse firewall deployed between users and externals.

Sources:

  • VerticalNews, "Study Findings from Central China Normal University Provide New Insights into Information and Data Encoding and Encryption (Towards Subversion-resistant Password-protected Encryption for Deduplicated Cloud Storage)" (2025).
  • Journal of Information Security and Applications, "Towards Subversion-resistant Password-protected Encryption for Deduplicated Cloud Storage" (2025, Vol. 94).
  • NewsRx LLC, "Study Findings from Central China Normal University Provide New Insights into Information and Data Encoding and Encryption (Towards Subversion-resistant Password-protected Encryption for Deduplicated Cloud Storage)" (2025, November 4).