<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">81399</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2026.081399</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Blockchain-Based Transparent Certificateless Data Integrity Auditing with Enhanced Tag Security</article-title>
<alt-title alt-title-type="left-running-head">Blockchain-Based Transparent Certificateless Data Integrity Auditing with Enhanced Tag Security</alt-title>
<alt-title alt-title-type="right-running-head">Blockchain-Based Transparent Certificateless Data Integrity Auditing with Enhanced Tag Security</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Zhang</surname><given-names>Chao</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Zhong</surname><given-names>Weidong</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Wang</surname><given-names>Xu An</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-4" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Jiang</surname><given-names>Weiwei</given-names></name><xref ref-type="aff" rid="aff-2">2</xref><xref rid="cor1" ref-type="corresp">&#x002A;</xref><email>jww@bupt.edu.cn</email></contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western"><surname>Wang</surname><given-names>Ziteng</given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-6" contrib-type="author">
<name name-style="western"><surname>Tian</surname><given-names>Miao</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-7" contrib-type="author">
<name name-style="western"><surname>Ling</surname><given-names>Jianhong</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-8" contrib-type="author">
<name name-style="western"><surname>Du</surname><given-names>Hangjiang</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-9" contrib-type="author">
<name name-style="western"><surname>Duan</surname><given-names>Yunhui</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<aff id="aff-1"><label>1</label><institution>School of Cryptographic Engineering, Engineering University of People&#x2019;s Armed Police</institution>, <addr-line>Xi&#x2019;an</addr-line>, <country>China</country></aff>
<aff id="aff-2"><label>2</label><institution>School of Information and Communication Engineering, Beijing University of Posts and Telecommunications</institution>, <addr-line>Beijing</addr-line>, <country>China</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Weiwei Jiang. Email: <email>jww@bupt.edu.cn</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2026</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>15</day><month>06</month><year>2026</year>
</pub-date>
<volume>88</volume>
<issue>2</issue>
<elocation-id>37</elocation-id>
<history>
<date date-type="received">
<day>03</day>
<month>03</month>
<year>2026</year>
</date>
<date date-type="accepted">
<day>14</day>
<month>05</month>
<year>2026</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2026 The Authors. Published by Tech Science Press.</copyright-statement>
<copyright-year>2026</copyright-year>
<copyright-holder>The Authors</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_81399.pdf"></self-uri>
<abstract>
<p>The integrity risks posed by data outsourcing in cloud storage have driven the development of remote data integrity auditing (RDIA) technologies. However, traditional schemes rely on trusted third-party auditors (TPAs), leading to potential collusion and single-point failure vulnerabilities. The integration of blockchain alleviates these issues through decentralization and transparency, yet existing blockchain-based certificateless auditing schemes still suffer from security flaws in the tag generation phase. Addressing the tag forgery vulnerability in Miao et al.&#x2019;s scheme, which stems from the absence of random parameters in the hash function input, this paper proposes a lightweight enhancement mechanism: incorporating a random factor into the hash input during tag generation to ensure dynamic unforgeability of tags. While retaining the efficiency advantages of the original framework, the improved scheme achieves resistance against tag forgery, proof forgery, and collusion attacks under the Computational Diffie-Hellman (CDH) and Discrete Logarithm (DL) hardness assumptions, validated through rigorous formal proofs. Experimental performance analysis demonstrates that the proposed enhanced scheme introduces negligible computational overhead, providing a secure, practical, and transparent auditing solution for multi-cloud storage environments.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Blockchain</kwd>
<kwd>tag security</kwd>
<kwd>certificateless cryptography</kwd>
<kwd>data integrity auditing</kwd>
<kwd>cloud storage</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>Engineering University of PAP&#x2019;s Funding for Education and Teaching Program</funding-source>
<award-id>Wjx2025069</award-id>
</award-group>
<award-group id="awg2">
<funding-source>Engineering University of PAP&#x2019;s Funding for Basic and Cutting-Edge Innovation Grant</funding-source>
<award-id>Wjy202520</award-id>
</award-group>
<award-group id="awg3">
<funding-source>Stability Program of National Key Laboratory of Security Communication</funding-source>
<award-id>WD202513</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>In the era of vigorous development of the digital economy, data has become a core strategic asset driving technological innovation, decision-making and value creation. As a critical infrastructure supporting the explosive growth of massive data, cloud storage is deeply integrated into the business processes of modern enterprises and the digital life of individual users by virtue of its outstanding scalability, low-cost advantages and cross-platform convenient access. Cloud storage not only greatly alleviates the pressure on local storage resources, but also realizes real-time global data collaboration and sharing, delivering unprecedented convenience. However, this outsourced storage mode with separated data ownership and management rights significantly reduces users&#x2019; direct physical control over cloud data while creating value, and triggers a series of severe security risks. Among these challenges, ensuring data integrity stands out as the most essential and critical issue. After data is uploaded to the cloud, users have to rely entirely on the cloud service provider (CSP) to guarantee data accuracy and consistency. Nevertheless, cloud data is highly vulnerable to loss, corruption and malicious tampering due to non-human factors such as hardware failures and system vulnerabilities, as well as human threats including internal operational negligence and external malicious attacks. For highly sensitive data such as financial transaction records, medical archives and intellectual property documents, any minor damage to data integrity may lead to catastrophic consequences. Therefore, achieving efficient and reliable integrity verification for outsourced data without compromising the convenience of cloud storage has become a research hotspot attracting widespread attention from both academia and industry. Remote Data Integrity Auditing (RDIA) technology has emerged to address this demand. Its core principle is as follows: resource-constrained Data Owners (DOs) can entrust a Trusted Third-Party Auditor (TPA) to initiate periodic or on-demand auditing challenges to the Cloud Server (CS) through lightweight cryptographic protocols. The TPA verifies the proof returned by the cloud server and determines the integrity and credibility of outsourced data without downloading the complete raw data. Since Ateniese et al. first proposed the pioneering Provable Data Possession (PDP) model, numerous optimized schemes supporting dynamic data updates, privacy preservation and multi-cloud collaboration have been proposed in this field. Although the functional capabilities of remote data integrity auditing frameworks have become increasingly mature, the commonly adopted centralized third-party auditing architecture suffers from fundamental security bottlenecks. On the one hand, third-party auditing nodes are prone to single points of failure, which directly affects the overall availability of auditing services. On the other hand, the inescapable risk of collusion attacks between auditors and cloud servers persists. Once the two collude, the auditor may leak challenge information in advance and forge verification results, rendering the entire auditing mechanism invalid and seriously undermining user trust in data integrity. To completely eliminate reliance on trusted third-party auditors, researchers have introduced blockchain technology to reconstruct remote data integrity auditing architectures. Under the assumption that most nodes are honest, blockchain features decentralization, immutability and traceability, providing a novel and feasible solution for constructing a truly trusted auditing system. Based on this architecture, smart contracts deployed on the blockchain can automatically complete core operations throughout the entire process, including audit challenge generation, proof verification and on-chain result storage. This reduces dependence on centralized intermediaries to a certain extent and builds a more reliable auditing execution environment. Meanwhile, to simplify key management, avoid the high lifecycle overhead of complex certificates in the traditional Public Key Infrastructure (PKI), and resolve the inherent key escrow vulnerability of Identity-Based Cryptography (IBC), the Certificateless Cryptography (CLC) scheme has emerged as a competitive alternative. It strikes a favorable balance between key management complexity and security, requiring no digital certificates and eliminating the security hazard that the Key Generation Center (KGC) fully controls users&#x2019; private keys. Against this research background, Miao et al. proposed a blockchain-based transparent certificateless data integrity auditing scheme in recent years. This scheme replaces traditional centralized third-party auditors with smart contracts to achieve openness, fairness and automation of auditing procedures, effectively overcoming the inherent defects of traditional public key and identity-based cryptosystems, and holding promising application prospects in multi-cloud storage scenarios. Nevertheless, in-depth analysis reveals potential security flaws in the core data tag generation module of this scheme. In its tag construction algorithm, the hash input for binding data block metadata only contains static or semi-static public parameters such as file names, block indices and public keys, while lacking critical dynamic random factors. Under the Chosen Message Attack (CMA) model, a malicious cloud server can generate forged tags through offline precomputation, bypass the integrity verification mechanism, and conduct covert data tampering attacks. Targeting the above security vulnerabilities, this paper proposes a lightweight improved scheme with enhanced tag security. The core design is concise and efficient: a dynamic random parameter <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mi mathvariant="bold-italic">T</mml:mi></mml:math></inline-formula> is introduced into the hash operation during tag generation to ensure the uniqueness and unpredictability of each data tag, fundamentally improving the resistance to relevant attacks. The main contributions of this paper are summarized as follows: 1. This paper accurately identifies and formally analyzes the security flaws of existing schemes. It systematically dissects the tag forgery vulnerabilities in Miao&#x2019;s scheme, strictly defines three types of adversaries with different capabilities and their attack targets under standard cryptographic adversary models, and clarifies the optimization direction for subsequent security enhancement design. 2. An efficient and universal security repair mechanism is designed. The improved scheme only adds a single hash operation to the original tag generation process, resulting in extremely low computational and communication overhead. Under established security assumptions, it can resist various attacks including tag forgery, proof forgery and multi-party collusion, possessing high engineering practical value. 3. Rigorous formal security proofs are provided. Based on the Computational Diffie-Hellman (CDH) and Discrete Logarithm (DL) hardness assumptions, strict reduction proofs are conducted to verify that the improved scheme satisfies core security properties such as Existential Unforgeability under Chosen Message Attacks (EUF-CMA) and auditing correctness. 4. Comprehensive performance evaluations are conducted. Multiple comparative experiments are carried out to quantitatively measure the operational overhead of the proposed scheme. Horizontal comparisons with baseline schemes verify the efficiency and feasibility of the proposed scheme in real multi-cloud storage environments. The remainder of this paper is organized as follows. <xref ref-type="sec" rid="s2">Section 2</xref> reviews related work. <xref ref-type="sec" rid="s3">Section 3</xref> introduces preliminary knowledge and the system model. <xref ref-type="sec" rid="s4">Section 4</xref> reviews the original scheme in detail and identifies its security defects. <xref ref-type="sec" rid="s5">Section 5</xref> elaborates on the specific design of the improved scheme. <xref ref-type="sec" rid="s6">Section 6</xref> analyzes the correctness of the proposed scheme. <xref ref-type="sec" rid="s7">Section 7</xref> presents formal security proofs. <xref ref-type="sec" rid="s8">Section 8</xref> demonstrates experimental simulations and performance evaluation results. <xref ref-type="sec" rid="s9">Section 9</xref> concludes the full text and prospects future research directions.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Work</title>
<p>The development of remote data integrity auditing technology has witnessed a complete evolution from centralization to decentralization, static verification to dynamic updating, and single-function design to multi-objective collaboration. Combined with representative domestic and international research achievements, this chapter systematically reviews the research progress of two mainstream directions: traditional centralized auditing and blockchain-based decentralized auditing.</p>
<sec id="s2_1">
<label>2.1</label>
<title>Traditional Public Auditing Schemes</title>
<p>The rapid popularization of cloud storage relies on standardized definitions and systematic architectural research. Mell and Grance [<xref ref-type="bibr" rid="ref-1">1</xref>] released the authoritative cloud computing definition formulated by the National Institute of Standards and Technology (NIST), clarifying the basic service modes and core characteristics of cloud computing. Armbrust et al. [<xref ref-type="bibr" rid="ref-2">2</xref>] comprehensively summarized the overall architecture, technical advantages and potential risks of cloud computing, laying a theoretical foundation for subsequent research on outsourced storage. With the large-scale migration of enterprise and user data to the cloud, security issues caused by the separation of data ownership and storage rights have become increasingly prominent. Hashizume et al. [<xref ref-type="bibr" rid="ref-3">3</xref>] systematically sorted out various security threats in cloud computing scenarios and pointed out that data integrity damage is a critical security risk that urgently needs to be addressed. The foundational work in the field of data integrity auditing was initiated by the Provable Data Possession (PDP) model proposed by Ateniese et al. [<xref ref-type="bibr" rid="ref-4">4</xref>]. Leveraging homomorphic authenticators, this scheme realizes lightweight remote data verification without downloading complete files, pioneering the research paradigm of public auditing. However, the original PDP scheme only supports static data verification and cannot repair corrupted data. To address this limitation, Juels and Kaliski [<xref ref-type="bibr" rid="ref-5">5</xref>] proposed the Proof of Retrievability (PoR) model. Combined with error-correcting coding technology, it supports the recovery of partially corrupted data while completing integrity auditing. On this basis, Shacham and Waters [<xref ref-type="bibr" rid="ref-6">6</xref>] constructed a streamlined and efficient PoR protocol under standard model assumptions, greatly reducing the communication overhead of auditing. In practical cloud service scenarios, users frequently modify, insert and delete cloud data. To meet the demand for dynamic data, Wang et al. [<xref ref-type="bibr" rid="ref-7">7</xref>] designed a public auditing scheme supporting full-dimensional dynamic updates by combining Merkle Hash Trees, enabling iterative data updates and real-time integrity verification. Facing the needs of multi-user collaborative office in cloud sharing scenarios, Yuan and Yu [<xref ref-type="bibr" rid="ref-8">8</xref>] proposed a multi-user-oriented integrity detection protocol to optimize the collaborative editing and joint auditing process of shared data. For distributed multi-cloud storage architectures, Wang et al. [<xref ref-type="bibr" rid="ref-9">9</xref>] adopted a fragmented distributed data storage strategy and built a high-fault-tolerant cross-cloud auditing mechanism to improve the operational reliability of heterogeneous cloud storage systems. Ali et al. [<xref ref-type="bibr" rid="ref-10">10</xref>] summarized the technical framework, mainstream models and existing limitations of outsourced data auditing in the form of reviews, and comprehensively combed the development context of traditional auditing technologies. Privacy preservation and lightweight design are two core optimization directions for traditional auditing schemes. Wang et al. [<xref ref-type="bibr" rid="ref-11">11</xref>] introduced data blinding and random masking technologies to construct a privacy-preserving public auditing scheme, effectively preventing the leakage of users&#x2019; sensitive data during auditing. Targeting resource-constrained scenarios such as mobile terminals and edge devices, Yoosuf and Anitha [<xref ref-type="bibr" rid="ref-12">12</xref>] proposed a lightweight dual auditing protocol LDuAP, which streamlines complex cryptographic operations to adapt to the computing power constraints of low-power devices. Zheng et al. [<xref ref-type="bibr" rid="ref-13">13</xref>] reviewed the development status of blockchain, providing theoretical support for decentralized auditing. Yue et al. [<xref ref-type="bibr" rid="ref-14">14</xref>] conducted research on data integrity verification in edge-cloud collaboration scenarios, further enriching the cross-domain storage security auditing system. Huang et al. [<xref ref-type="bibr" rid="ref-15">15</xref>] constructed a collaborative cloud data auditing architecture based on distributed collaboration ideas. From the perspective of auditing behavior constraint, Miao et al. [<xref ref-type="bibr" rid="ref-16">16</xref>] designed an incentive-based auditing protocol to restrain the negative behavior of auditing nodes. Liu et al. [<xref ref-type="bibr" rid="ref-17">17</xref>] optimized on-chain auditing processes by adopting blockchain expansion technology. Zhang et al. [<xref ref-type="bibr" rid="ref-18">18</xref>] focused on multi-replica storage scenarios and proposed a decentralized and efficient multi-replica auditing scheme. Zhu et al. [<xref ref-type="bibr" rid="ref-19">19</xref>] designed a universal dynamic auditing service framework for cloud outsourced data. Yang and Jia [<xref ref-type="bibr" rid="ref-20">20</xref>] further improved dynamic auditing protocols to enhance auditing security and efficiency in complex cloud environments. Zhou et al. [<xref ref-type="bibr" rid="ref-21">21</xref>] constructed a quantum-resistant cloud data PDP scheme by integrating lattice cryptography. Yang et al. [<xref ref-type="bibr" rid="ref-22">22</xref>] designed a lightweight provable data possession scheme specifically for mobile terminals. Li et al. [<xref ref-type="bibr" rid="ref-23">23</xref>] realized privacy-preserving remote data integrity detection by integrating identity-based cryptography. Yuan et al. [<xref ref-type="bibr" rid="ref-24">24</xref>] combined identity-based cryptography with blockchain to achieve cross-environment trusted data verification. Li et al. [<xref ref-type="bibr" rid="ref-25">25</xref>] built a blockchain-assisted batch public auditing mechanism for big data scenarios. Xu et al. [<xref ref-type="bibr" rid="ref-26">26</xref>] realized privacy-friendly data auditing in consortium blockchain scenarios based on zero-knowledge proofs. Chang et al. [<xref ref-type="bibr" rid="ref-27">27</xref>] optimized the efficiency of multi-replica verification in multi-cloud architectures to improve cross-cloud storage auditing performance. Li and Hu [<xref ref-type="bibr" rid="ref-28">28</xref>] designed a smart contract-driven multi-party collaborative auditing mechanism for multiple audit participants. Tahir et al. [<xref ref-type="bibr" rid="ref-29">29</xref>] proposed a lightweight blockchain-based security authentication and data auditing framework for the Internet of Medical Things. Nevertheless, most public auditing schemes rely on a trusted third-party auditor (TPA), and inherent security risks such as single point of failure of auditing nodes and collusion between cloud servers and auditors cannot be fundamentally eliminated.</p>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>Blockchain-Based Public Auditing Schemes</title>
<p>To solve the trust dilemma of centralized third-party auditing, blockchain technology with decentralization, immutability and traceability has been gradually applied in the field of cloud data auditing. Miao et al. [<xref ref-type="bibr" rid="ref-30">30</xref>] constructed a transparent certificateless cloud storage auditing scheme, which completely replaces centralized third-party auditors with smart contracts to realize full-process auditing automation. Nweje [<xref ref-type="bibr" rid="ref-31">31</xref>] illustrated the application value of blockchain in security auditing, traceability and tamper resistance, and pointed out the development trend of decentralized auditing technology. Based on blockchain auditing, Li et al. [<xref ref-type="bibr" rid="ref-32">32</xref>] integrated encrypted deduplication technology to reduce cloud storage costs while ensuring data integrity. Zhu et al. [<xref ref-type="bibr" rid="ref-33">33</xref>] proposed a lightweight certificateless auditing scheme without third-party auditors, which further reduces system overhead and realizes lightweight decentralized auditing. From the perspective of data compliance supervision, Wang et al. [<xref ref-type="bibr" rid="ref-34">34</xref>] built a GDPR-compliant blockchain auditing framework to meet the standardized management requirements of data security. Shen et al. [<xref ref-type="bibr" rid="ref-35">35</xref>] combined keyword search with remote auditing to realize rapid positioning and dynamic verification of cloud files. Tu et al. [<xref ref-type="bibr" rid="ref-36">36</xref>] optimized traditional multi-replica auditing algorithms to improve the efficiency and stability of redundant data verification in multi-cloud environments. Kumar and Bandanadam [<xref ref-type="bibr" rid="ref-37">37</xref>] introduced an improved ElGamal encryption algorithm to strengthen the encryption protection capability of blockchain auditing systems and enhance the attack resistance in decentralized storage scenarios. In recent years, research has been further advanced to promote the engineering implementation of auditing systems and adapt to complex application environments. Wang et al. [<xref ref-type="bibr" rid="ref-38">38</xref>] proposed the SStore provable data auditing platform, which significantly optimizes the overall system operational efficiency while guaranteeing security, and advances the development of auditing mechanisms toward platformization and practical application. Liu et al. [<xref ref-type="bibr" rid="ref-39">39</xref>] introduced a file access prediction mechanism in the shared data auditing scenario, combining data behavior analysis with integrity verification to improve audit response efficiency. With the continuous evolution of blockchain auditing technology, research priorities have gradually expanded to privacy protection, deduplication mechanisms and functional expansion. Zhang et al. [<xref ref-type="bibr" rid="ref-40">40</xref>] integrated blockchain with privacy-preserving deduplication technology, which reduces redundant storage overhead while realizing data integrity verification. Targeting the multi-replica dynamic data environment, Zhou et al. [<xref ref-type="bibr" rid="ref-41">41</xref>] designed a certificate-based multi-replica auditing scheme supporting data updates, which enhances system reliability and improves dynamic adaptability. Miao et al. [<xref ref-type="bibr" rid="ref-42">42</xref>] further expanded the auditing functions and proposed a blockchain-assisted provable data possession scheme supporting multi-keyword search, realizing the integration of data retrieval and integrity verification. Vijayakumar et al. [<xref ref-type="bibr" rid="ref-43">43</xref>] introduced a fair payment mechanism into the blockchain auditing system, combining data deduplication with economic incentives to improve the sustainable operation capability of the system. For special application scenarios, Xu et al. [<xref ref-type="bibr" rid="ref-44">44</xref>] proposed an auditing mechanism balancing privacy protection and transparent deduplication for UAV cloud storage environments, providing new ideas for data security in resource-constrained scenarios. Some existing certificateless blockchain auditing schemes attempt to reduce or replace the centralized third-party auditor (TPA), and achieve satisfactory performance in operational efficiency, privacy protection and scalability. However, they generally ignore the anti-forgery design of data verification tags. The tag generation process lacks dynamic random factors, enabling malicious cloud servers to precompute offline and forge legitimate tags. Focusing on this core security defect, this paper optimizes the tag generation algorithm on the basis of existing mainstream certificateless blockchain auditing schemes, and proposes an improved auditing scheme with lightweight features and high security.</p>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>Preliminary Knowledge and Background</title>
<sec id="s3_1">
<label>3.1</label>
<title>Bilinear Pairing</title>
<p>Let <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula> be an additive cyclic group and <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mi>T</mml:mi></mml:msub></mml:math></inline-formula> be a multiplicative cyclic group, both of prime order <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:mi>q</mml:mi></mml:math></inline-formula>, where the Discrete Logarithm Problem (DLP) in <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula> is intractable. A bilinear pairing is a function <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:mi>e</mml:mi><mml:mo>:</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mo>&#x00D7;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mi>T</mml:mi></mml:msub></mml:math></inline-formula> satisfying:<list list-type="bullet">
<list-item>
<p><bold>Bilinearity:</bold> For any <inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>Q</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula> and <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:mi>a</mml:mi><mml:mo>,</mml:mo><mml:mi>b</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>a</mml:mi><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>b</mml:mi><mml:mi>Q</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>Q</mml:mi><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>.</p></list-item>
<list-item>
<p><bold>Non-degeneracy:</bold> There exist <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>Q</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula> such that <inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>Q</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2260;</mml:mo><mml:msub><mml:mn>1</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mi>T</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> (<inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:msub><mml:mn>1</mml:mn><mml:mrow><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mi>T</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> is the identity element of <inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mi>T</mml:mi></mml:msub></mml:math></inline-formula>).</p></list-item>
<list-item>
<p><bold>Computability:</bold> An efficient algorithm exists to compute <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>Q</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> for any <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>Q</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula>.</p></list-item>
</list></p>
<p>Throughout this paper, <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:mi>z</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> denotes the master secret key held by the Key Generation Center (KGC), and the corresponding system public key is defined as
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>z</mml:mi><mml:mi>P</mml:mi><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:mi>P</mml:mi></mml:math></inline-formula> is the generator of the additive cyclic group <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula>. This definition is used consistently in the tag generation, proof generation, and proof verification algorithms.</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Hard Computational Problems</title>
<sec id="s3_2_1">
<label>3.2.1</label>
<title>Computational Diffie-Hellman (CDH) Problem</title>
<p>Given <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:mi>P</mml:mi></mml:math></inline-formula>, <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mi>a</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula>, <inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:mi>b</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> (<inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:mi>a</mml:mi><mml:mo>,</mml:mo><mml:mi>b</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> unknown), it is computationally infeasible for a Probabilistic Polynomial-Time (PPT) adversary to compute <inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula>.</p>
</sec>
<sec id="s3_2_2">
<label>3.2.2</label>
<title>Discrete Logarithm (DL) Assumption</title>
<p>Given a generator <inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:mi>P</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula> and <inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:mi>Q</mml:mi><mml:mo>=</mml:mo><mml:mi>a</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> (where <inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:mi>a</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> is unknown), a PPT adversary cannot compute <inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:mi>a</mml:mi></mml:math></inline-formula> with non-negligible probability.</p>
</sec>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>System Model</title>
<p>The role definitions of each entity are shown in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>: The core entities of the scheme and their core functional responsibilities are clearly defined as follows, with a clear distinction between the functional boundaries of the Third-Party Auditor (TPA) and blockchain smart contracts:
<list list-type="simple">
<list-item>
<label>KGC</label>
<p>Key Generation Center: A semi-trusted entity responsible for generating system-level public parameters and partial private keys for Data Owners (DOs) and strictly abides by the certificateless cryptography design principle&#x2014;no full control over the user&#x2019;s complete private key&#x2014;to avoid the key escrow vulnerability of Identity-based Cryptography (IBC).</p>
</list-item>
<list-item>
<label>DO</label>
<p>Data Owner: The legitimate owner of the data with limited local storage and computing resources. The DO divides the data into blocks, generates enhanced tags using the modified tag generation algorithm, and uploads the data/tags to the CS. It delegates auditing tasks to the TPA and monitors the audit logs on the blockchain.</p></list-item>
<list-item>
<label>TPA</label>
<p>A professional computing entity with strong cryptographic computing capabilities, serving as an auxiliary verification entity for the scheme. Its core functions include performing high-efficiency professional proof verification calculations based on the challenge information and proof data on the blockchain; conducting off-chain recheck of the audit results generated by the smart contract to ensure verification accuracy; and sending early warnings for abnormal audit results (such as data tampering) to the DO and other relevant entities.</p></list-item>
<list-item>
<label>CS</label>
<p>Cloud Server: A storage service provider with abundant resources responsible for storing the DO&#x2019;s data and tags. When challenged by the TPA, the CS generates integrity proofs using the stored data and tags.</p>
</list-item>
<list-item>
<label>Blockchain</label>
<p>The core decentralized execution entity of the auditing scheme, responsible for the core on-chain auditing logic and data storage. Its core functions include generating decentralized and tamper-proof audit challenge information based on the DO&#x2019;s secret value and timestamp; receiving the integrity proof submitted by the CS; providing the verification equation and basic computing support for proof verification; recording all audit processes (challenge generation, proof submission) and final results on the blockchain; and ensuring the immutability and public traceability of audit logs through the blockchain&#x2019;s consensus mechanism.</p></list-item>
</list></p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>System model diagram.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_81399-fig-1.tif"/>
</fig>
<sec id="s3_3_1">
<title>Decentralization of the Auditing Process</title>
<p>The scheme proposed in this paper realizes the complete decentralization of the cloud storage data integrity auditing process, breaking the dependence on the centralized TPA in traditional remote data integrity auditing schemes. In this scheme, the TPA is only an optional auxiliary computing entity that provides professional cryptographic computing capability support for the auditing process, and its existence does not affect the essential decentralized characteristics of the scheme.</p>
<p>The blockchain smart contract is designed with a complete and independent audit verification logic, which integrates all core functions required for the auditing process: it can independently generate decentralized challenge information without relying on any centralized entity, can execute the proof verification equation according to the pre-deployed code logic, and can store the audit results and logs on the blockchain in an immutable manner. Even if the TPA is completely removed from the system, each blockchain node can complete the full process of data integrity auditing (challenge generation<inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>proof reception<inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>proof verification<inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>result recording) through the deployed smart contract, and the audit results generated by the smart contract still have the properties of correctness, immutability and public verifiability.</p>
<p>The TPA&#x2019;s participation in the auditing process is only to improve the efficiency of audit verification: for large-scale multi-cloud storage auditing scenarios, the cryptographic computing of proof verification will bring a certain load to the blockchain nodes; the TPA with strong professional computing capabilities can undertake the heavy proof verification calculation work, and feed back the verification results to the blockchain for on-chain recording, which effectively reduces the computing load of blockchain nodes and improves the overall throughput of the auditing system. Whether the TPA is involved or not, the core decentralized audit logic of the scheme remains unchanged, which fully guarantees the decentralization and trustworthiness of the auditing process.</p>
</sec>
</sec>
<sec id="s3_4">
<label>3.4</label>
<title>Threat Model</title>
<sec id="s3_4_1">
<label>3.4.1</label>
<title>Fundamentals and Assumptions of Threat Modeling</title>
<p>This paper adopts the standard cryptographic adversary model, considering Probabilistic Polynomial-Time (PPT) adversaries. We conduct security analysis based on the following key assumptions:<list list-type="bullet">
<list-item>
<p><bold>Blockchain Security Assumption:</bold> The blockchain network itself is secure, and its consensus mechanism can ensure the immutability and final consistency of the ledger. Smart contract code is assumed to be correctly implemented without vulnerabilities.</p></list-item>
<list-item>
<p><bold>KGC Trust Assumption:</bold> The Key Generation Center (KGC) is modeled as an &#x201C;honest-but-curious&#x201D; entity, meaning it will honestly execute the protocol but may attempt to infer user data or private keys using the partial private key information it holds.</p></list-item>
<list-item>
<p><bold>Communication Security Assumption:</bold> All communication channels (including KGC-DO, DO-CS, DO-TPA, etc.) are assumed to be secure. Adversaries can only obtain information by eavesdropping or tampering with channel contents, but cannot directly access secret keys.</p></list-item>
<list-item>
<p><bold>Computational Assumption:</bold> Based on the Computational Diffie-Hellman (CDH) and Discrete Logarithm (DL) hardness assumptions, it is believed that these mathematical problems cannot be solved within polynomial time.</p></list-item>
</list></p>
</sec>
<sec id="s3_4_2">
<label>3.4.2</label>
<title>Formalized Description of Adversary Capabilities and Attack Goals</title>
<p>To enhance the rigor of security analysis, we formally define three types of PPT adversaries with distinct capabilities and clear attack goals based on the certificateless cryptography adversary model and the characteristics of blockchain-based auditing systems:<list list-type="simple">
<list-item>
<label>&#x2022;</label>
<p><bold>Type I Adversary </bold><inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula><bold>:</bold></p>
<p><bold>Capabilities (Formalized):</bold>
<list list-type="simple">
<list-item>
<label>1.</label>
<p>Cannot access the KGC&#x2019;s master key <inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:mi>z</mml:mi></mml:math></inline-formula> (i.e., <inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:msub><mml:mi>A</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x2209;</mml:mo><mml:mrow><mml:mi>&#x1D4A6;</mml:mi></mml:mrow></mml:math></inline-formula>, where <inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:mrow><mml:mi>&#x1D4A6;</mml:mi></mml:mrow></mml:math></inline-formula> denotes the set of entities with master key access).</p></list-item>
<list-item>
<label>2.</label>
<p>Has the authority to replace the Data Owner&#x2019;s (DO&#x2019;s) public key <inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:mi>P</mml:mi><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> with any arbitrary value <inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:mi>P</mml:mi><mml:msubsup><mml:mi>K</mml:mi><mml:mrow><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> (i.e., <inline-formula id="ieqn-37"><mml:math id="mml-ieqn-37"><mml:mi mathvariant="normal">&#x2200;</mml:mi><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-38"><mml:math id="mml-ieqn-38"><mml:msub><mml:mi>A</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> can output <inline-formula id="ieqn-39"><mml:math id="mml-ieqn-39"><mml:mi>P</mml:mi><mml:msubsup><mml:mi>K</mml:mi><mml:mrow><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> to replace the original <inline-formula id="ieqn-40"><mml:math id="mml-ieqn-40"><mml:mi>P</mml:mi><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula>).</p></list-item>
<list-item>
<label>3.</label>
<p>Can fully control one or more malicious Cloud Servers (CSs), enabling it to tamper with stored data blocks <inline-formula id="ieqn-41"><mml:math id="mml-ieqn-41"><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, forge tags <inline-formula id="ieqn-42"><mml:math id="mml-ieqn-42"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>, and manipulate the proof generation process.</p></list-item>
<list-item>
<label>4.</label>
<p>Can eavesdrop on all public channel communications, including system public parameters <inline-formula id="ieqn-43"><mml:math id="mml-ieqn-43"><mml:mi>p</mml:mi><mml:mi>p</mml:mi></mml:math></inline-formula>, user public keys <inline-formula id="ieqn-44"><mml:math id="mml-ieqn-44"><mml:mi>P</mml:mi><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula>, uploaded data tags <inline-formula id="ieqn-45"><mml:math id="mml-ieqn-45"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, and on-chain audit logs (challenge seeds, proofs, results).</p></list-item>
<list-item>
<label>5.</label>
<p>Can perform polynomial-time queries, including:</p></list-item>
<list-item>
<p>Partial key query: For any identity <inline-formula id="ieqn-46"><mml:math id="mml-ieqn-46"><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2260;</mml:mo><mml:mi>I</mml:mi><mml:msubsup><mml:mi>D</mml:mi><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> (target identity), query the KGC&#x2019;s partial private key <inline-formula id="ieqn-47"><mml:math id="mml-ieqn-47"><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mi>I</mml:mi><mml:mi>D</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>;</p></list-item>
<list-item>
<p>Tag query: For any data block <inline-formula id="ieqn-48"><mml:math id="mml-ieqn-48"><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and identity <inline-formula id="ieqn-49"><mml:math id="mml-ieqn-49"><mml:mi>I</mml:mi><mml:mi>D</mml:mi></mml:math></inline-formula>, query the corresponding tag <inline-formula id="ieqn-50"><mml:math id="mml-ieqn-50"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> generated by the DO.</p></list-item>
</list></p></list-item>
<list-item>
<p><bold>Attack Goal:</bold> Without obtaining the DO&#x2019;s complete private key <inline-formula id="ieqn-51"><mml:math id="mml-ieqn-51"><mml:mi>S</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and original data blocks <inline-formula id="ieqn-52"><mml:math id="mml-ieqn-52"><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-53"><mml:math id="mml-ieqn-53"><mml:msub><mml:mi>A</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> aims to forge a valid tag <inline-formula id="ieqn-54"><mml:math id="mml-ieqn-54"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> for a tampered data block <inline-formula id="ieqn-55"><mml:math id="mml-ieqn-55"><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2260;</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> such that the tag passes the TPA&#x2019;s verification (i.e., <inline-formula id="ieqn-56"><mml:math id="mml-ieqn-56"><mml:mtext>Verify</mml:mtext><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:msubsup><mml:mi>K</mml:mi><mml:mrow><mml:mi>I</mml:mi><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mtext>Accept</mml:mtext></mml:math></inline-formula>), thereby bypassing the integrity auditing mechanism.</p></list-item>
<list-item>
<label>&#x2022;</label>
<p><bold>Type II Adversary </bold><inline-formula id="ieqn-57"><mml:math id="mml-ieqn-57"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula>:</p></list-item>
<list-item>
<p><bold>Capabilities (Formalized):</bold>
<list list-type="simple">
<list-item>
<label>1.</label>
<p>Can access the KGC&#x2019;s master key <inline-formula id="ieqn-58"><mml:math id="mml-ieqn-58"><mml:mi>z</mml:mi></mml:math></inline-formula> (i.e., <inline-formula id="ieqn-59"><mml:math id="mml-ieqn-59"><mml:msub><mml:mi>A</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi>&#x1D4A6;</mml:mi></mml:mrow></mml:math></inline-formula>), enabling it to compute the partial private key <inline-formula id="ieqn-60"><mml:math id="mml-ieqn-60"><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>z</mml:mi><mml:msub><mml:mi>H</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mtext>ID</mml:mtext><mml:mo>,</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> for any user identity <inline-formula id="ieqn-61"><mml:math id="mml-ieqn-61"><mml:mtext>ID</mml:mtext></mml:math></inline-formula>.</p></list-item>
<list-item>
<label>2.</label>
<p>Cannot modify the DO&#x2019;s public key <inline-formula id="ieqn-62"><mml:math id="mml-ieqn-62"><mml:mi>P</mml:mi><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> (i.e., <inline-formula id="ieqn-63"><mml:math id="mml-ieqn-63"><mml:mi>P</mml:mi><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> is fixed once generated by the DO).</p></list-item>
<list-item>
<label>3.</label>
<p>Can collude with the CS to tamper with stored data, forge tags, and manipulate audit proofs.</p></list-item>
<list-item>
<label>4.</label>
<p>Can eavesdrop on all public and private channel communications (including the partial private key <inline-formula id="ieqn-64"><mml:math id="mml-ieqn-64"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> transmitted from KGC to DO).</p></list-item>
<list-item>
<label>5.</label>
<p>Can perform polynomial-time queries, including:</p></list-item>
<list-item>
<p>Secret key query: For any identity <inline-formula id="ieqn-65"><mml:math id="mml-ieqn-65"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2260;</mml:mo><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, query the complete private key <inline-formula id="ieqn-66"><mml:math id="mml-ieqn-66"><mml:msub><mml:mtext>Sk</mml:mtext><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>;</p></list-item>
<list-item>
<p>Tag query: For any data block <inline-formula id="ieqn-67"><mml:math id="mml-ieqn-67"><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and identity <inline-formula id="ieqn-68"><mml:math id="mml-ieqn-68"><mml:mtext>ID</mml:mtext></mml:math></inline-formula>, query the corresponding tag <inline-formula id="ieqn-69"><mml:math id="mml-ieqn-69"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>.</p></list-item>
</list></p></list-item>
<list-item>
<p><bold>Attack Goal:</bold> Without obtaining the DO&#x2019;s local private key <inline-formula id="ieqn-70"><mml:math id="mml-ieqn-70"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-71"><mml:math id="mml-ieqn-71"><mml:msub><mml:mi>A</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula> aims to forge a valid tag <inline-formula id="ieqn-72"><mml:math id="mml-ieqn-72"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> for a tampered data block <inline-formula id="ieqn-73"><mml:math id="mml-ieqn-73"><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> or collude with the CS to generate a forged audit proof that passes verification, thereby achieving undetectable data tampering.</p></list-item>
<list-item>
<label>&#x2022;</label>
<p><bold>Type III Adversary </bold><inline-formula id="ieqn-74"><mml:math id="mml-ieqn-74"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula>:</p></list-item>
<list-item>
<p><bold>Capabilities (Formalized):</bold>
<list list-type="simple">
<list-item>
<label>1.</label>
<p>Represents a collusive alliance consisting of one or more malicious CSs and blockchain miners.</p></list-item>
<list-item>
<label>2.</label>
<p>Can tamper with stored data blocks <inline-formula id="ieqn-75"><mml:math id="mml-ieqn-75"><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and tags <inline-formula id="ieqn-76"><mml:math id="mml-ieqn-76"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> on the CS, and forge integrity proofs <inline-formula id="ieqn-77"><mml:math id="mml-ieqn-77"><mml:msup><mml:mtext>proof</mml:mtext><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msup><mml:mi>&#x03BC;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msup><mml:mover><mml:mi>W</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>.</p></list-item>
<list-item>
<label>3.</label>
<p>Can manipulate blockchain challenge generation by colluding with miners:</p></list-item>
<list-item>
<p>Biasing challenge block selection (e.g., avoiding tampered blocks by manipulating pseudorandom permutation <inline-formula id="ieqn-78"><mml:math id="mml-ieqn-78"><mml:msub><mml:mi>&#x03C0;</mml:mi><mml:mrow><mml:mtext>key</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula>);</p></list-item>
<list-item>
<p>Delaying or modifying on-chain challenge seeds <inline-formula id="ieqn-79"><mml:math id="mml-ieqn-79"><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> (within the limits of blockchain consensus latency).</p></list-item>
<list-item>
<label>4.</label>
<p>Can access all system public parameters, user public information, and on-chain data (audit logs, transaction records).</p></list-item>
<list-item>
<label>5.</label>
<p>Cannot access the DO&#x2019;s private key <inline-formula id="ieqn-80"><mml:math id="mml-ieqn-80"><mml:msub><mml:mtext>Sk</mml:mtext><mml:mrow><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> or KGC&#x2019;s master key <inline-formula id="ieqn-81"><mml:math id="mml-ieqn-81"><mml:mi>z</mml:mi></mml:math></inline-formula>.</p></list-item>
</list></p></list-item>
<list-item>
<p><bold>Attack Goal:</bold> After tampering with data blocks (modification, insertion, deletion), <inline-formula id="ieqn-82"><mml:math id="mml-ieqn-82"><mml:msub><mml:mi>A</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula> aims to generate a forged audit proof <inline-formula id="ieqn-83"><mml:math id="mml-ieqn-83"><mml:msup><mml:mtext>proof</mml:mtext><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> that passes the TPA&#x2019;s verification (i.e., <inline-formula id="ieqn-84"><mml:math id="mml-ieqn-84"><mml:mtext>ProofVerify</mml:mtext><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mi>p</mml:mi><mml:mo>,</mml:mo><mml:msup><mml:mtext>proof</mml:mtext><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mtext>Accept</mml:mtext></mml:math></inline-formula>), and manipulate on-chain challenge information to evade detection, thereby concealing data integrity breaches.</p></list-item>
</list></p>
<p>The improved scheme also needs to address the following additional threats:<list list-type="bullet">
<list-item>
<p><bold>Tag Forgery Attack:</bold> Adversaries use precomputed static hash values <inline-formula id="ieqn-85"><mml:math id="mml-ieqn-85"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mtext>fname</mml:mtext><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mtext>id</mml:mtext><mml:mi>i</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> to forge valid tags for tampered data. Formally, given <inline-formula id="ieqn-86"><mml:math id="mml-ieqn-86"><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mtext>fname</mml:mtext><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mtext>id</mml:mtext><mml:mi>i</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> (precomputed offline), the adversary constructs <inline-formula id="ieqn-87"><mml:math id="mml-ieqn-87"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mtext>id</mml:mtext><mml:mi>i</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>p</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and submits <inline-formula id="ieqn-88"><mml:math id="mml-ieqn-88"><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mi>P</mml:mi></mml:math></inline-formula> to pass verification.</p></list-item>
<list-item>
<p><bold>Collusion Attack:</bold> Malicious CSs collude with miners to generate biased challenge information (e.g., avoiding tampered challenge blocks) and use forged tags to pass verification.</p></list-item>
<list-item>
<p><bold>Privacy Leakage:</bold> Adversaries infer sensitive data patterns (e.g., file structure, block importance) from static hash inputs <inline-formula id="ieqn-89"><mml:math id="mml-ieqn-89"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mtext>fname</mml:mtext><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mtext>id</mml:mtext><mml:mi>i</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Formally, given a sequence of hash values <inline-formula id="ieqn-90"><mml:math id="mml-ieqn-90"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, the adversary infers the correlation between <inline-formula id="ieqn-91"><mml:math id="mml-ieqn-91"><mml:msub><mml:mtext>id</mml:mtext><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and data sensitivity, leading to privacy breaches.</p></list-item>
</list></p>
</sec>
</sec>
<sec id="s3_5">
<label>3.5</label>
<title>Design Goals</title>
<p>The design goals of the proposed scheme are as follows:<list list-type="bullet">
<list-item>
<p><bold>Audit Correctness:</bold> If the valid proof generated by the CS passes TPA verification, the stored data must be intact (i.e., consistent with the data uploaded by the DO).</p></list-item>
<list-item>
<p><bold>Privacy Protection:</bold> During the auditing process, the TPA, CS, and other entities cannot access the DO&#x2019;s plaintext data or sensitive identity information.</p></list-item>
<list-item>
<p><bold>Collusion Resistance:</bold> The scheme resists collusion among any combination of entities (such as TPA-CS, CS-miners, KGC-CS) to prevent data tampering or manipulation of audit results.</p></list-item>
<list-item>
<p><bold>Transparency:</bold> All auditing processes (challenge generation, proof submission, verification) and results are recorded on the blockchain, ensuring public verifiability and tamper-proofing.</p></list-item>
<list-item>
<p><bold>Tag Unforgeability:</bold> Even if system parameters and public information are known, no PPT adversary can forge a valid tag for a data block without obtaining the DO&#x2019;s private key and real data.</p></list-item>
</list></p>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Review of the Original Scheme</title>
<sec id="s4_1">
<label>4.1</label>
<title>Process Overview</title>
<p>The scheme proposed by Miao et al. is based on certificateless cryptography and blockchain smart contracts, aiming to achieve decentralized, transparent, and TPA-free data integrity auditing. Its core idea is: using smart contracts to replace traditional TPAs for challenge generation; utilizing certificateless signatures to avoid PKI certificate management and IBC key escrow issues; and recording all audit logs on the chain to ensure traceability and immutability. The system auditing process includes:<disp-formula id="ueqn-2"><mml:math id="mml-ueqn-2" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:mrow><mml:mtext>Setup</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mrow><mml:mtext>PartialKeyGen</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mrow><mml:mtext>KeyGen</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mrow><mml:mtext>TagGen</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mrow><mml:mtext>Challenge (on-chain)</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mrow><mml:mtext>ProofGen</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mrow><mml:mtext>ProofVerify</mml:mtext></mml:mrow><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Tag Generation Algorithm (TagGen)</title>
<p>The most critical phase of this scheme is tag generation. For a file <inline-formula id="ieqn-92"><mml:math id="mml-ieqn-92"><mml:mi>M</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, the DO randomly selects <inline-formula id="ieqn-93"><mml:math id="mml-ieqn-93"><mml:mi>r</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> and computes <inline-formula id="ieqn-94"><mml:math id="mml-ieqn-94"><mml:mi>T</mml:mi><mml:mo>=</mml:mo><mml:mi>r</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula>. For each data block <inline-formula id="ieqn-95"><mml:math id="mml-ieqn-95"><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, computes the tag:<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>pk</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>r</mml:mi><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>fname</mml:mtext></mml:mrow><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-96"><mml:math id="mml-ieqn-96"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> is the KGC-generated partial private key, <inline-formula id="ieqn-97"><mml:math id="mml-ieqn-97"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> is the DO&#x2019;s local private key, <inline-formula id="ieqn-98"><mml:math id="mml-ieqn-98"><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula id="ieqn-99"><mml:math id="mml-ieqn-99"><mml:msub><mml:mtext>pk</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mi>P</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-100"><mml:math id="mml-ieqn-100"><mml:mi>T</mml:mi><mml:mo>=</mml:mo><mml:mi>r</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> is the random parameter. The DO uploads <inline-formula id="ieqn-101"><mml:math id="mml-ieqn-101"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msubsup><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:msubsup></mml:math></inline-formula> and <inline-formula id="ieqn-102"><mml:math id="mml-ieqn-102"><mml:mi>T</mml:mi></mml:math></inline-formula> to the CS.</p>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>Challenge and Verification Mechanism</title>
<p>Challenge generation is performed by smart contracts based on the secret value <inline-formula id="ieqn-103"><mml:math id="mml-ieqn-103"><mml:mtext>sv</mml:mtext></mml:math></inline-formula> submitted by the DO, timestamp <inline-formula id="ieqn-104"><mml:math id="mml-ieqn-104"><mml:mi>t</mml:mi></mml:math></inline-formula>, filename, etc., to generate pseudorandom seeds <inline-formula id="ieqn-105"><mml:math id="mml-ieqn-105"><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-106"><mml:math id="mml-ieqn-106"><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, which further determine the challenge block indices and weights.</p>
<p>Proof generation involves the CS aggregating the tags and data of the challenged blocks to generate <inline-formula id="ieqn-107"><mml:math id="mml-ieqn-107"><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B4;</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:mo>,</mml:mo><mml:mi>W</mml:mi><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Here, <inline-formula id="ieqn-108"><mml:math id="mml-ieqn-108"><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">p</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">b</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>z</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> denotes the system public key generated by the KGC during the Setup phase, where <inline-formula id="ieqn-109"><mml:math id="mml-ieqn-109"><mml:mi>z</mml:mi></mml:math></inline-formula> is the KGC&#x2019;s master secret key and <inline-formula id="ieqn-110"><mml:math id="mml-ieqn-110"><mml:mi>P</mml:mi></mml:math></inline-formula> is the generator of <inline-formula id="ieqn-111"><mml:math id="mml-ieqn-111"><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula>. The verification equation is:<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B4;</mml:mi><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>W</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>I</mml:mi></mml:mrow></mml:munder><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>pk</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>pk</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>I</mml:mi></mml:mrow></mml:munder><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>fname</mml:mtext></mml:mrow><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>.</mml:mo></mml:math></disp-formula></p>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Analysis of Attack</title>
<sec id="s5_1">
<label>5.1</label>
<title>Tag Forgery Attack</title>
<p>Adversaries (such as malicious CSs or external adversaries) know public parameters, filenames <inline-formula id="ieqn-112"><mml:math id="mml-ieqn-112"><mml:mtext>fname</mml:mtext></mml:math></inline-formula>, block <inline-formula id="ieqn-113"><mml:math id="mml-ieqn-113"><mml:msub><mml:mtext>id</mml:mtext><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, and user public keys <inline-formula id="ieqn-114"><mml:math id="mml-ieqn-114"><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>. Since the input of <inline-formula id="ieqn-115"><mml:math id="mml-ieqn-115"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mtext>fname</mml:mtext><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mtext>id</mml:mtext><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is completely static, adversaries can precompute this hash value offline, denoted as: <inline-formula id="ieqn-116"><mml:math id="mml-ieqn-116"><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mtext>fname</mml:mtext><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mtext>id</mml:mtext><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>.</p>
<p>It should be emphasized that a malicious CS cannot legitimately compute a fresh tag in the same way as the DO executes the TagGen algorithm, because the CS does not possess the DO&#x2019;s complete private key, especially the local secret key <inline-formula id="ieqn-117"><mml:math id="mml-ieqn-117"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> and the partial private key <inline-formula id="ieqn-118"><mml:math id="mml-ieqn-118"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>. Therefore, the term &#x201C;forged tag&#x201D; in this section does not refer to a normally generated cryptographic signature. Instead, it refers to an algebraically constructed or synthesized tag/proof component whose purpose is to satisfy the public verification equation by exploiting the linear structure of the original scheme.</p>
<p>The attack steps are as follows: The user uploads real data <inline-formula id="ieqn-119"><mml:math id="mml-ieqn-119"><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and tags <inline-formula id="ieqn-120"><mml:math id="mml-ieqn-120"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>; the malicious CS tampers with the data to <inline-formula id="ieqn-121"><mml:math id="mml-ieqn-121"><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2260;</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>; the CS attempts to construct a new tag/proof component <inline-formula id="ieqn-122"><mml:math id="mml-ieqn-122"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> to pass verification. Since <inline-formula id="ieqn-123"><mml:math id="mml-ieqn-123"><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is known, the CS can select any <inline-formula id="ieqn-124"><mml:math id="mml-ieqn-124"><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, set <inline-formula id="ieqn-125"><mml:math id="mml-ieqn-125"><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mi>P</mml:mi></mml:math></inline-formula>, and attempt to synthesize a forged tag/proof component with the following algebraic target form rather than compute a legitimate signature through TagGen:<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mrow><mml:mover><mml:mrow><mml:mo>=</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mtext>alg</mml:mtext></mml:mrow></mml:mrow></mml:mover></mml:mrow><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>The notation <inline-formula id="ieqn-126"><mml:math id="mml-ieqn-126"><mml:mrow><mml:mover><mml:mrow><mml:mo>=</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">l</mml:mi><mml:mi mathvariant="normal">g</mml:mi></mml:mrow></mml:mrow></mml:mover></mml:mrow></mml:math></inline-formula> indicates an algebraic relation required for satisfying the verification equation. It does not imply that the malicious CS can directly evaluate the secret-key-dependent terms <inline-formula id="ieqn-127"><mml:math id="mml-ieqn-127"><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-128"><mml:math id="mml-ieqn-128"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. In other words, <inline-formula id="ieqn-129"><mml:math id="mml-ieqn-129"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> is not a valid tag generated by the DO, but an algebraically synthesized object used in the forgery analysis.</p>
<p>In subsequent audits, the CS submits the corresponding forged proof components together with <inline-formula id="ieqn-130"><mml:math id="mml-ieqn-130"><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>. The <inline-formula id="ieqn-131"><mml:math id="mml-ieqn-131"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula> term in the verification equation still uses <inline-formula id="ieqn-132"><mml:math id="mml-ieqn-132"><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, and <inline-formula id="ieqn-133"><mml:math id="mml-ieqn-133"><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> matches <inline-formula id="ieqn-134"><mml:math id="mml-ieqn-134"><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>, so the equation may hold even if the data has been tampered with. In subsequent audits, the CS submits <inline-formula id="ieqn-135"><mml:math id="mml-ieqn-135"><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. The <inline-formula id="ieqn-136"><mml:math id="mml-ieqn-136"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula> term in the verification equation still uses <inline-formula id="ieqn-137"><mml:math id="mml-ieqn-137"><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, and <inline-formula id="ieqn-138"><mml:math id="mml-ieqn-138"><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> matches <inline-formula id="ieqn-139"><mml:math id="mml-ieqn-139"><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>, so the equation may hold even if the data has been tampered with.</p>
<p>Both the tag generation formula (<xref ref-type="disp-formula" rid="eqn-5">Eq. (5)</xref>) and the verification formula of the original scheme exhibit an obvious linear structural characteristic. Taking advantage of this linearity, a malicious CS can forge a valid tag by precomputing static hash values and constructing new random parameters without acquiring the data owner&#x2019;s local private key <inline-formula id="ieqn-140"><mml:math id="mml-ieqn-140"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>, the complete private key <inline-formula id="ieqn-141"><mml:math id="mml-ieqn-141"><mml:msub><mml:mtext>Sk</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, or the original data block <inline-formula id="ieqn-142"><mml:math id="mml-ieqn-142"><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>. The core algebraic derivation and attack steps are as follows:</p>
<p><bold>Attack Premise and Linear Structure Analysis:</bold></p>
<p>The tag generation formula of the original scheme is given by:<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>p</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>r</mml:mi><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>fname</mml:mtext></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula></p>
<p>The core verification equation of the original scheme is:<disp-formula id="ueqn-7"><mml:math id="mml-ueqn-7" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B4;</mml:mi><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>W</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>I</mml:mi></mml:mrow></mml:munder><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mtext>pk</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>pk</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>I</mml:mi></mml:mrow></mml:munder><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>fname</mml:mtext></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>where <inline-formula id="ieqn-143"><mml:math id="mml-ieqn-143"><mml:mi>&#x03B4;</mml:mi><mml:mo>=</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>I</mml:mi></mml:mrow></mml:munder><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-144"><mml:math id="mml-ieqn-144"><mml:msub><mml:mtext>pk</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mi>P</mml:mi></mml:math></inline-formula>, <inline-formula id="ieqn-145"><mml:math id="mml-ieqn-145"><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>z</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> (<inline-formula id="ieqn-146"><mml:math id="mml-ieqn-146"><mml:mi>z</mml:mi></mml:math></inline-formula> is the master key of the Key Generation Center (KGC)), and <inline-formula id="ieqn-147"><mml:math id="mml-ieqn-147"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>z</mml:mi><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>.</p>
<p>From an algebraic perspective, the tag <inline-formula id="ieqn-148"><mml:math id="mml-ieqn-148"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is a linear combination of several group elements, and the bilinearity of the pairing in the verification equation preserves this linear relationship. The attack analysis does not claim that the malicious CS can execute the legitimate TagGen algorithm. Instead, it shows that, because the <inline-formula id="ieqn-149"><mml:math id="mml-ieqn-149"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula> term is static and publicly reproducible, the adversary may attempt to algebraically synthesize proof components that satisfy the same pairing equation. In this sense, the vulnerability lies in the public verifiability of a linear equation whose static hash component is not bound to the dynamic randomness <inline-formula id="ieqn-150"><mml:math id="mml-ieqn-150"><mml:mi>T</mml:mi></mml:math></inline-formula>.</p>
<p>In addition, the original verification process does not explicitly check the uniqueness of the random parameter <inline-formula id="ieqn-151"><mml:math id="mml-ieqn-151"><mml:mi>T</mml:mi><mml:mo>=</mml:mo><mml:mi>r</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> or its binding with the initially uploaded tag set. This enables a malicious CS to introduce a new random parameter <inline-formula id="ieqn-152"><mml:math id="mml-ieqn-152"><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> in the forged proof and to align the corresponding <inline-formula id="ieqn-153"><mml:math id="mml-ieqn-153"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula>-related term in the verification equation.</p>
<p><bold>Specific Attack Steps and Algebraic Derivation:</bold>
<list list-type="order">
<list-item>
<p>Precompute the static hash value: Using the known public parameters <inline-formula id="ieqn-154"><mml:math id="mml-ieqn-154"><mml:mtext>fname</mml:mtext></mml:math></inline-formula>, <inline-formula id="ieqn-155"><mml:math id="mml-ieqn-155"><mml:msub><mml:mtext>id</mml:mtext><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, and <inline-formula id="ieqn-156"><mml:math id="mml-ieqn-156"><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>, the malicious CS precomputes <inline-formula id="ieqn-157"><mml:math id="mml-ieqn-157"><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mtext>fname</mml:mtext><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mtext>id</mml:mtext><mml:mi>i</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. This value is fixed and can be calculated offline in advance and stored for long-term use.</p></list-item>
<list-item>
<p>Tamper with the original data: After the user uploads the original data block <inline-formula id="ieqn-158"><mml:math id="mml-ieqn-158"><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, the corresponding tag <inline-formula id="ieqn-159"><mml:math id="mml-ieqn-159"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, and the random parameter <inline-formula id="ieqn-160"><mml:math id="mml-ieqn-160"><mml:mi>T</mml:mi><mml:mo>=</mml:mo><mml:mi>r</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> to the CS, the malicious CS tampers with the data block to <inline-formula id="ieqn-161"><mml:math id="mml-ieqn-161"><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2260;</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and needs to construct a new tag <inline-formula id="ieqn-162"><mml:math id="mml-ieqn-162"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> to make the tampered data pass the verification.</p></list-item>
<list-item>
<p><bold>Construct a new random parameter and synthesize a forged algebraic relation:</bold> The malicious CS randomly selects <inline-formula id="ieqn-163"><mml:math id="mml-ieqn-163"><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> and constructs a new random parameter <inline-formula id="ieqn-164"><mml:math id="mml-ieqn-164"><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mi>P</mml:mi></mml:math></inline-formula>. Then it attempts to synthesize a forged tag/proof component whose algebraic form is consistent with the original verification equation:
<disp-formula id="ueqn-8"><mml:math id="mml-ueqn-8" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mrow><mml:mover><mml:mrow><mml:mo>=</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mtext>alg</mml:mtext></mml:mrow></mml:mrow></mml:mover></mml:mrow><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
<p>Here, <inline-formula id="ieqn-165"><mml:math id="mml-ieqn-165"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> should not be understood as a legitimately computed signature. Since the malicious CS does not know <inline-formula id="ieqn-166"><mml:math id="mml-ieqn-166"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> or <inline-formula id="ieqn-167"><mml:math id="mml-ieqn-167"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>, it cannot execute the DO&#x2019;s TagGen algorithm. Instead, the expression only describes the algebraic target that the forged proof components must satisfy. The attack succeeds only if the adversary can make the submitted aggregate proof behave as if it were derived from such a tag under the public pairing verification equation.</p></list-item>
<list-item>
<p>Algebraic proof that the forged tag satisfies the verification equation:</p>
<p>When the audit challenge includes this data block, the malicious CS submits the forged tag <inline-formula id="ieqn-168"><mml:math id="mml-ieqn-168"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> and the new random parameter <inline-formula id="ieqn-169"><mml:math id="mml-ieqn-169"><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>. At this time, the aggregate tag in the verification process is <inline-formula id="ieqn-170"><mml:math id="mml-ieqn-170"><mml:msup><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>. Substituting <xref ref-type="disp-formula" rid="eqn-4">Eq. (4)</xref> into <inline-formula id="ieqn-171"><mml:math id="mml-ieqn-171"><mml:msup><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> yields:<disp-formula id="ueqn-9"><mml:math id="mml-ueqn-9" display="block"><mml:msup><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>p</mml:mi><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>Substituting <inline-formula id="ieqn-172"><mml:math id="mml-ieqn-172"><mml:msup><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> into the left-hand side (LHS) of the verification equation gives:<disp-formula id="ueqn-10"><mml:math id="mml-ueqn-10" display="block"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>According to the linearity of bilinear pairing <inline-formula id="ieqn-173"><mml:math id="mml-ieqn-173"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>A</mml:mi><mml:mo>+</mml:mo><mml:mi>B</mml:mi><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>A</mml:mi><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>B</mml:mi><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, the equation expands to:<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula></p>
<p>For the right-hand side (RHS) of the verification equation, the malicious CS substitutes <inline-formula id="ieqn-174"><mml:math id="mml-ieqn-174"><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> synchronously and sets <inline-formula id="ieqn-175"><mml:math id="mml-ieqn-175"><mml:msup><mml:mi>&#x03BC;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:mi>&#x03C9;</mml:mi><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> (<inline-formula id="ieqn-176"><mml:math id="mml-ieqn-176"><mml:mi>&#x03C9;</mml:mi></mml:math></inline-formula> is the blinding factor) with <inline-formula id="ieqn-177"><mml:math id="mml-ieqn-177"><mml:mi>W</mml:mi></mml:math></inline-formula> remaining in its original structure. The RHS expands to:<disp-formula id="eqn-7"><label>(7)</label><mml:math id="mml-eqn-7" display="block"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03BC;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>W</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>pk</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula></p>
<p>Equivalence derivations are performed for each term in <xref ref-type="disp-formula" rid="eqn-6">(6)</xref> and <xref ref-type="disp-formula" rid="eqn-7">(7)</xref>, respectively:<list list-type="simple">
<list-item><label>&#x25CF;</label>
<p>First term: Since<inline-formula id="ieqn-178"><mml:math id="mml-ieqn-178"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>z</mml:mi><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-179"><mml:math id="mml-ieqn-179"><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mi>p</mml:mi><mml:mi>u</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>z</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula>, we have
<disp-formula id="ueqn-13"><mml:math id="mml-ueqn-13" display="block"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mi>z</mml:mi><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>z</mml:mi><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03BC;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>W</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>The blinding factor <inline-formula id="ieqn-180"><mml:math id="mml-ieqn-180"><mml:mi>W</mml:mi></mml:math></inline-formula> can be flexibly constructed by the CS to ensure the strict establishment of this equation.</p></list-item>
<list-item><label>&#x25CF;</label>
<p>Second term: Since <inline-formula id="ieqn-181"><mml:math id="mml-ieqn-181"><mml:msub><mml:mtext>pk</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mi>P</mml:mi></mml:math></inline-formula>, we have
<disp-formula id="ueqn-14"><mml:math id="mml-ueqn-14" display="block"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>pk</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>.</mml:mo></mml:math></disp-formula></p></list-item>
<list-item><label>&#x25CF;</label>
<p>Third term: Since <inline-formula id="ieqn-182"><mml:math id="mml-ieqn-182"><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mi>P</mml:mi></mml:math></inline-formula>, we have
<disp-formula id="ueqn-15"><mml:math id="mml-ueqn-15" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>h</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p></list-item>
</list></p>
<p>In summary, <xref ref-type="disp-formula" rid="eqn-6">Eq. (6)</xref> is completely equivalent to <xref ref-type="disp-formula" rid="eqn-7">Eq. (7)</xref>, which means the forged tag <inline-formula id="ieqn-183"><mml:math id="mml-ieqn-183"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> can satisfy the verification equation of the original scheme. The malicious CS successfully conceals data tampering through tag forgery.</p></list-item>
</list></p>
</sec>
<sec id="s5_2">
<label>5.2</label>
<title>Data Block Modification and Replacement Attack</title>
<p>The user uploads a file <inline-formula id="ieqn-184"><mml:math id="mml-ieqn-184"><mml:mi>M</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-185"><mml:math id="mml-ieqn-185"><mml:msub><mml:mi>m</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> is a sensitive data block (such as financial records, medical information). The malicious CS intends to replace it with <inline-formula id="ieqn-186"><mml:math id="mml-ieqn-186"><mml:msubsup><mml:mi>m</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> (such as tampering with the amount or forging diagnostic results). If the original scheme&#x2019;s tag <inline-formula id="ieqn-187"><mml:math id="mml-ieqn-187"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> is used, directly replacing <inline-formula id="ieqn-188"><mml:math id="mml-ieqn-188"><mml:msub><mml:mi>m</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> with <inline-formula id="ieqn-189"><mml:math id="mml-ieqn-189"><mml:msubsup><mml:mi>m</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> will cause verification failure because <inline-formula id="ieqn-190"><mml:math id="mml-ieqn-190"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> is bound to the original <inline-formula id="ieqn-191"><mml:math id="mml-ieqn-191"><mml:msub><mml:mi>m</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula>. However, with the tag forgery capability described in <xref ref-type="sec" rid="s5_1">Section 5.1</xref>, the CS can delete the original <inline-formula id="ieqn-192"><mml:math id="mml-ieqn-192"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> and attempt to synthesize an algebraically forged tag/proof component <inline-formula id="ieqn-193"><mml:math id="mml-ieqn-193"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> bound to <inline-formula id="ieqn-194"><mml:math id="mml-ieqn-194"><mml:msubsup><mml:mi>m</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> according to the target relation in <xref ref-type="disp-formula" rid="eqn-4">Eq. (4)</xref>, rather than legitimately computing a new tag. It then submits <inline-formula id="ieqn-195"><mml:math id="mml-ieqn-195"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> and <inline-formula id="ieqn-196"><mml:math id="mml-ieqn-196"><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mi>P</mml:mi></mml:math></inline-formula> during the audit.</p>
<p>If the challenge generated by the smart contract includes block <inline-formula id="ieqn-197"><mml:math id="mml-ieqn-197"><mml:mi>k</mml:mi></mml:math></inline-formula>, the CS responds with the forged proof components. During verification, <inline-formula id="ieqn-198"><mml:math id="mml-ieqn-198"><mml:mi>&#x03BC;</mml:mi><mml:mo>=</mml:mo><mml:mi>&#x03C9;</mml:mi><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:msubsup><mml:mi>m</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>, <inline-formula id="ieqn-199"><mml:math id="mml-ieqn-199"><mml:mi>&#x03B4;</mml:mi><mml:mo>=</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>, and the pairing verification term <inline-formula id="ieqn-200"><mml:math id="mml-ieqn-200"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B4;</mml:mi><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is forced to match the right-hand side <inline-formula id="ieqn-201"><mml:math id="mml-ieqn-201"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>W</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:msub><mml:mi>h</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> under the algebraic structure of the original scheme. This process should be interpreted as algebraic synthesis for satisfying the verification equation, not as the normal computation of a valid signature by the malicious CS. Thus, the adversary can modify critical data without being detected.</p>
</sec>
<sec id="s5_3">
<label>5.3</label>
<title>Insertion Attack</title>
<p>The attacker independently generates a forged data block <inline-formula id="ieqn-202"><mml:math id="mml-ieqn-202"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula> (such as a malicious script, fake transaction record, etc.) and forges a reasonable block identifier <inline-formula id="ieqn-203"><mml:math id="mml-ieqn-203"><mml:msub><mml:mtext>id</mml:mtext><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula>; computes the hash value <inline-formula id="ieqn-204"><mml:math id="mml-ieqn-204"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mtext>fname</mml:mtext><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mtext>id</mml:mtext><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> for the forged block using public parameters. Since the input of <inline-formula id="ieqn-205"><mml:math id="mml-ieqn-205"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula> has no dynamic factors, the precomputed result is valid; randomly selects <inline-formula id="ieqn-206"><mml:math id="mml-ieqn-206"><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> and computes <inline-formula id="ieqn-207"><mml:math id="mml-ieqn-207"><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mi>P</mml:mi></mml:math></inline-formula>; then attempts to synthesize a forged tag/proof component whose algebraic target form is
<disp-formula id="ueqn-16"><mml:math id="mml-ueqn-16" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>&#x225C;</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mrow><mml:mtext>pk</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
<p>Again, <inline-formula id="ieqn-208"><mml:math id="mml-ieqn-208"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula> is not computed as a legitimate signature by the malicious CS, because the CS does not possess <inline-formula id="ieqn-209"><mml:math id="mml-ieqn-209"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> or <inline-formula id="ieqn-210"><mml:math id="mml-ieqn-210"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>. It only denotes the algebraic relation that the forged proof component attempts to emulate in order to satisfy the public verification equation.</p>
<p>When the challenge seed <inline-formula id="ieqn-211"><mml:math id="mml-ieqn-211"><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> of the smart contract selects <inline-formula id="ieqn-212"><mml:math id="mml-ieqn-212"><mml:msub><mml:mtext>id</mml:mtext><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula> through the pseudorandom permutation <inline-formula id="ieqn-213"><mml:math id="mml-ieqn-213"><mml:msub><mml:mi>&#x03C0;</mml:mi><mml:mrow><mml:mtext>key</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula>, the attacker computes <inline-formula id="ieqn-214"><mml:math id="mml-ieqn-214"><mml:mi>&#x03B4;</mml:mi><mml:mo>=</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:msub><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-215"><mml:math id="mml-ieqn-215"><mml:mi>&#x03BC;</mml:mi><mml:mo>=</mml:mo><mml:mi>&#x03C9;</mml:mi><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:msub><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula> according to the proof generation process; submits the proof <inline-formula id="ieqn-216"><mml:math id="mml-ieqn-216"><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B4;</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:mo>,</mml:mo><mml:mi>W</mml:mi><mml:mo>,</mml:mo><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Since <inline-formula id="ieqn-217"><mml:math id="mml-ieqn-217"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula> is precomputed valid and <inline-formula id="ieqn-218"><mml:math id="mml-ieqn-218"><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> matches <inline-formula id="ieqn-219"><mml:math id="mml-ieqn-219"><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>, the verification equation holds, and the system identifies the forged block as legitimate data. The format of the block identifier <inline-formula id="ieqn-220"><mml:math id="mml-ieqn-220"><mml:msub><mml:mtext>id</mml:mtext><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula> is consistent with the original scheme, passing the CS&#x2019;s metadata format verification; the static nature of the <inline-formula id="ieqn-221"><mml:math id="mml-ieqn-221"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula> input ensures the validity of <inline-formula id="ieqn-222"><mml:math id="mml-ieqn-222"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:mtext>fake</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula>, and tag forgery conforms to the mathematical structure of the original scheme; the pseudorandomness of challenge generation makes the probability of the forged block being selected the same as that of legitimate blocks, enabling the attacker to achieve the attack without manipulating the challenge process.</p>
</sec>
<sec id="s5_4">
<label>5.4</label>
<title>Deletion Attack</title>
<p>The attacker identifies and deletes the sensitive data block <inline-formula id="ieqn-223"><mml:math id="mml-ieqn-223"><mml:msub><mml:mi>m</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> and its original tag <inline-formula id="ieqn-224"><mml:math id="mml-ieqn-224"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula>, but does not modify the file metadata (such as the number of blocks, index range) to avoid triggering the CS&#x2019;s integrity verification; constructs a harmless data block <inline-formula id="ieqn-225"><mml:math id="mml-ieqn-225"><mml:msubsup><mml:mi>m</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> consistent with the format of the original data block (such as filling with random invalid characters, repeating the content of other legitimate blocks) to ensure the integrity of the file structure; precomputes <inline-formula id="ieqn-226"><mml:math id="mml-ieqn-226"><mml:msub><mml:mi>h</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mtext>fname</mml:mtext><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mtext>id</mml:mtext><mml:mi>k</mml:mi></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> corresponding to the original index <inline-formula id="ieqn-227"><mml:math id="mml-ieqn-227"><mml:msub><mml:mtext>id</mml:mtext><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> of the sensitive block; selects <inline-formula id="ieqn-228"><mml:math id="mml-ieqn-228"><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> and computes <inline-formula id="ieqn-229"><mml:math id="mml-ieqn-229"><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mi>P</mml:mi></mml:math></inline-formula>; then attempts to synthesize an algebraically forged tag/proof component
<disp-formula id="ueqn-17"><mml:math id="mml-ueqn-17" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:msubsup><mml:mi>m</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mi>k</mml:mi></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msub><mml:mrow><mml:mtext>pk</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2225;</mml:mo><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:msub><mml:mi>h</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p>
<p>This expression describes the algebraic target relation of the forged proof rather than a legitimate tag computation. The malicious CS cannot independently evaluate the secret-key-dependent terms, but it may exploit the static <inline-formula id="ieqn-230"><mml:math id="mml-ieqn-230"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula> input and the linear pairing equation to make the submitted proof appear valid. The attacker writes <inline-formula id="ieqn-231"><mml:math id="mml-ieqn-231"><mml:msubsup><mml:mi>m</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> and the corresponding forged proof component to the original storage location of <inline-formula id="ieqn-232"><mml:math id="mml-ieqn-232"><mml:msub><mml:mi>m</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula>, completing replacement-style deletion.</p>
<p>When the audit challenge includes <inline-formula id="ieqn-233"><mml:math id="mml-ieqn-233"><mml:msub><mml:mtext>id</mml:mtext><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula>, the attacker submits the proof generated by <inline-formula id="ieqn-234"><mml:math id="mml-ieqn-234"><mml:msubsup><mml:mi>m</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> and <inline-formula id="ieqn-235"><mml:math id="mml-ieqn-235"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>, the verification equation holds, and the audit result shows &#x201C;data intact&#x201D;, successfully concealing the sensitive data. After the attack, the metadata (number of blocks, size, index) of the file remains unchanged, making it impossible for ordinary users or administrators to detect data replacement through conventional means; the auditing mechanism fails due to tag forgery, unable to identify the deletion behavior.</p>
</sec>
</sec>
<sec id="s6">
<label>6</label>
<title>Design of the Improved Scheme</title>
<p>In 2024, Miao et al. proposed a blockchain-based transparent certificateless cloud storage data integrity auditing scheme. In the original tag generation algorithm, the tag calculation for each data block is as shown in <xref ref-type="disp-formula" rid="eqn-1">Eq. (1)</xref>: where <inline-formula id="ieqn-236"><mml:math id="mml-ieqn-236"><mml:mi>T</mml:mi><mml:mo>=</mml:mo><mml:mi>r</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> (<inline-formula id="ieqn-237"><mml:math id="mml-ieqn-237"><mml:mi>r</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, <inline-formula id="ieqn-238"><mml:math id="mml-ieqn-238"><mml:mi>P</mml:mi></mml:math></inline-formula> is the generator of the cyclic group <inline-formula id="ieqn-239"><mml:math id="mml-ieqn-239"><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula>) is a random parameter introduced to enhance tag randomness. The key issue lies in the hash function <inline-formula id="ieqn-240"><mml:math id="mml-ieqn-240"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula>: its input only includes static or semi-static attributes (filename <inline-formula id="ieqn-241"><mml:math id="mml-ieqn-241"><mml:mtext>fname</mml:mtext></mml:math></inline-formula>, data block identifier <inline-formula id="ieqn-242"><mml:math id="mml-ieqn-242"><mml:msub><mml:mtext>id</mml:mtext><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, and user partial public key <inline-formula id="ieqn-243"><mml:math id="mml-ieqn-243"><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>), while omitting the random parameter <inline-formula id="ieqn-244"><mml:math id="mml-ieqn-244"><mml:mi>T</mml:mi></mml:math></inline-formula>. This problem allows adversaries to precompute <inline-formula id="ieqn-245"><mml:math id="mml-ieqn-245"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mtext>fname</mml:mtext><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mtext>id</mml:mtext><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> (due to the fixed nature of its input) and use this static hash value to forge valid tags, for example, by manipulating the random factor <inline-formula id="ieqn-246"><mml:math id="mml-ieqn-246"><mml:mi>r</mml:mi></mml:math></inline-formula> or colluding with malicious cloud servers to tamper with data while generating seemingly valid integrity proofs.</p>
<p>To make up for this security flaw, this paper proposes a lightweight and effective enhanced tag generation mechanism: incorporating the random parameter <inline-formula id="ieqn-247"><mml:math id="mml-ieqn-247"><mml:mi>T</mml:mi></mml:math></inline-formula> into the input of <inline-formula id="ieqn-248"><mml:math id="mml-ieqn-248"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula>, so the modified hash input becomes <inline-formula id="ieqn-249"><mml:math id="mml-ieqn-249"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mtext>fname</mml:mtext><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mtext>id</mml:mtext><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. The improved scheme only modifies the tag generation phase (TagGen) of the original framework, while keeping other algorithms (Setup, PartialKeyGen, KeyGen, Challenge, ProofGen, ProofVerify) unchanged. This minimal modification ensures backward compatibility, retains the efficiency of the original scheme, and eliminates the risk of tag forgery. The key enhancement is integrating the random parameter <inline-formula id="ieqn-250"><mml:math id="mml-ieqn-250"><mml:mi>T</mml:mi></mml:math></inline-formula> into the input of <inline-formula id="ieqn-251"><mml:math id="mml-ieqn-251"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula>, ensuring that both <inline-formula id="ieqn-252"><mml:math id="mml-ieqn-252"><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-253"><mml:math id="mml-ieqn-253"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula> depend on the same dynamic factor <inline-formula id="ieqn-254"><mml:math id="mml-ieqn-254"><mml:mi>T</mml:mi></mml:math></inline-formula>. The modified tag generation formula is:<disp-formula id="eqn-8"><label>(8)</label><mml:math id="mml-eqn-8" display="block"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>pk</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>r</mml:mi><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>fname</mml:mtext></mml:mrow><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-255"><mml:math id="mml-ieqn-255"><mml:mi>T</mml:mi><mml:mo>=</mml:mo><mml:mi>r</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> is a random element in <inline-formula id="ieqn-256"><mml:math id="mml-ieqn-256"><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula> generated by the DO for each tag set. By including <inline-formula id="ieqn-257"><mml:math id="mml-ieqn-257"><mml:mi>T</mml:mi></mml:math></inline-formula> in the input of <inline-formula id="ieqn-258"><mml:math id="mml-ieqn-258"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula>, the hash value <inline-formula id="ieqn-259"><mml:math id="mml-ieqn-259"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mtext>fname</mml:mtext><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mtext>id</mml:mtext><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> becomes dynamic, and each new tag set (with a different <inline-formula id="ieqn-260"><mml:math id="mml-ieqn-260"><mml:mi>r</mml:mi></mml:math></inline-formula>) generates a unique <inline-formula id="ieqn-261"><mml:math id="mml-ieqn-261"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula> value, preventing precomputation and forgery. Existing randomization technologies applied in cloud storage data integrity auditing schemes mostly focus on the signature/encryption layer of the protocol: random parameters are only introduced in the process of generating private key signatures, data encryption or audit proof blinding, and are not deeply integrated into the core cryptographic component of tag generation&#x2014;the hash function input layer. This separation makes the randomization of the scheme lack end-to-end consistency, and the static hash input still leaves the tag generation phase vulnerable to precomputation and forgery attacks. In addition, the random parameters of traditional methods are independently generated and managed by a single entity (such as the data owner), and there is no effective binding with the decentralized challenge generation mechanism of the blockchain, leading to the disconnection between the randomness of tag generation and the randomness of audit challenge, which cannot form a joint security defense against collusion attacks.</p>
<p>Different from the above methods, the randomization enhancement mechanism proposed in this paper realizes two core innovations of random parameter application: first, the dynamic random parameter <inline-formula id="ieqn-262"><mml:math id="mml-ieqn-262"><mml:mi>T</mml:mi></mml:math></inline-formula> is deeply fused into the input layer of the hash function <inline-formula id="ieqn-263"><mml:math id="mml-ieqn-263"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula> in the tag generation phase, rather than only being applied to the upper signature/encryption layer, making the hash value of the core tag component change with the dynamic random parameter <inline-formula id="ieqn-264"><mml:math id="mml-ieqn-264"><mml:mi>T</mml:mi></mml:math></inline-formula>, fundamentally eliminating the possibility of precomputing the hash value for tag forgery; second, the random parameter <inline-formula id="ieqn-265"><mml:math id="mml-ieqn-265"><mml:mi>T</mml:mi></mml:math></inline-formula> is strongly bound with the challenge generation mechanism of the blockchain smart contract&#x2014;the <inline-formula id="ieqn-266"><mml:math id="mml-ieqn-266"><mml:mi>T</mml:mi></mml:math></inline-formula> generated by the data owner for tag generation is uploaded to the cloud server and recorded in the audit proof, and the smart contract takes <inline-formula id="ieqn-267"><mml:math id="mml-ieqn-267"><mml:mi>T</mml:mi></mml:math></inline-formula> as an important verification parameter in the challenge and proof verification phase, realizing the randomization consistency of the whole process of &#x201C;tag generation&#x2013;challenge verification&#x2013;on-chain recording&#x201D;. This end-to-end randomization design makes the security of each link of the auditing protocol dependent on the same dynamic random factor, and forms a closed loop of randomization security, which effectively resists the combined attacks of tag forgery and proof forgery in the decentralized blockchain environment.</p>
<sec id="s6_1">
<label>6.1</label>
<title>System Initialization (Setup)</title>
<p>Executed by the Key Generation Center (KGC) to generate system public parameters and the master key:<list list-type="order">
<list-item>
<p>Select two cyclic groups <inline-formula id="ieqn-268"><mml:math id="mml-ieqn-268"><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula> (additive group) and <inline-formula id="ieqn-269"><mml:math id="mml-ieqn-269"><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mi>T</mml:mi></mml:msub></mml:math></inline-formula> (multiplicative group) of prime order <inline-formula id="ieqn-270"><mml:math id="mml-ieqn-270"><mml:mi>q</mml:mi></mml:math></inline-formula>, and a bilinear pairing <inline-formula id="ieqn-271"><mml:math id="mml-ieqn-271"><mml:mi>e</mml:mi><mml:mo>:</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mo>&#x00D7;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mi>T</mml:mi></mml:msub></mml:math></inline-formula>.</p></list-item>
<list-item>
<p>Choose a generator <inline-formula id="ieqn-272"><mml:math id="mml-ieqn-272"><mml:mi>P</mml:mi></mml:math></inline-formula> of <inline-formula id="ieqn-273"><mml:math id="mml-ieqn-273"><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula>.</p></list-item>
<list-item>
<p>Define the following hash functions:
<disp-formula id="ueqn-19"><mml:math id="mml-ueqn-19" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:mi>h</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>:</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:msup><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>,</mml:mo><mml:mspace width="1em" /><mml:msub><mml:mi>H</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo>:</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:msup><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2217;</mml:mo></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mn>1</mml:mn></mml:msub><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p></list-item>
<list-item>
<p>Select a pseudorandom permutation <inline-formula id="ieqn-274"><mml:math id="mml-ieqn-274"><mml:msub><mml:mi>&#x03C0;</mml:mi><mml:mrow><mml:mtext>key</mml:mtext></mml:mrow></mml:msub><mml:mo>:</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>&#x00D7;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:msup><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mi>n</mml:mi></mml:msup></mml:math></inline-formula> (for challenge block selection) and a pseudorandom function <inline-formula id="ieqn-275"><mml:math id="mml-ieqn-275"><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mtext>key</mml:mtext></mml:mrow></mml:msub><mml:mo>:</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>&#x00D7;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> (for challenge weight calculation).</p></list-item>
<list-item>
<p>Randomly select a master key <inline-formula id="ieqn-276"><mml:math id="mml-ieqn-276"><mml:mi>z</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> and compute the system public key <inline-formula id="ieqn-277"><mml:math id="mml-ieqn-277"><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>z</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula>. Here, <inline-formula id="ieqn-278"><mml:math id="mml-ieqn-278"><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula> is the public counterpart of the KGC&#x2019;s master secret key <inline-formula id="ieqn-279"><mml:math id="mml-ieqn-279"><mml:mi>z</mml:mi></mml:math></inline-formula> and will be used in the verification equation to bind the partial private key <inline-formula id="ieqn-280"><mml:math id="mml-ieqn-280"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>z</mml:mi><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> to the public system parameters.</p></list-item>
<list-item>
<p>Publish the system public parameters: <inline-formula id="ieqn-281"><mml:math id="mml-ieqn-281"><mml:mtext>pp</mml:mtext><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>q</mml:mi><mml:mo>,</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mi>T</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>e</mml:mi><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>h</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mtext>key</mml:mtext></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03C0;</mml:mi><mml:mrow><mml:mtext>key</mml:mtext></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> and secretly store the master key <inline-formula id="ieqn-282"><mml:math id="mml-ieqn-282"><mml:mi>z</mml:mi></mml:math></inline-formula>.</p></list-item>
</list></p>
</sec>
<sec id="s6_2">
<label>6.2</label>
<title>Partial Key Generation (PartialKeyGen)</title>
<p>Executed by the KGC to generate a partial private key for the Data Owner (DO):<list list-type="order">
<list-item>
<p>Input the DO&#x2019;s identity identifier <inline-formula id="ieqn-283"><mml:math id="mml-ieqn-283"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>.</p></list-item>
<list-item>
<p>Compute the partial public key <inline-formula id="ieqn-284"><mml:math id="mml-ieqn-284"><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> (binding the DO&#x2019;s identity with system parameters).</p></list-item>
<list-item>
<p>Compute the partial private key <inline-formula id="ieqn-285"><mml:math id="mml-ieqn-285"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>z</mml:mi><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> (generated using the master key <inline-formula id="ieqn-286"><mml:math id="mml-ieqn-286"><mml:mi>z</mml:mi></mml:math></inline-formula> and the partial public key <inline-formula id="ieqn-287"><mml:math id="mml-ieqn-287"><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>).</p></list-item>
<list-item>
<p>Transmit <inline-formula id="ieqn-288"><mml:math id="mml-ieqn-288"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> to the DO through a secure channel.</p></list-item>
</list></p>
</sec>
<sec id="s6_3">
<label>6.3</label>
<title>Key Generation (KeyGen)</title>
<p>Executed by the DO to generate a complete public-private key pair:<list list-type="order">
<list-item>
<p>The DO randomly selects a local key <inline-formula id="ieqn-289"><mml:math id="mml-ieqn-289"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>.</p></list-item>
<list-item>
<p>Compute the local public key <inline-formula id="ieqn-290"><mml:math id="mml-ieqn-290"><mml:msub><mml:mtext>pk</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mi>P</mml:mi></mml:math></inline-formula>.</p></list-item>
<list-item>
<p>The DO&#x2019;s public key is <inline-formula id="ieqn-291"><mml:math id="mml-ieqn-291"><mml:msub><mml:mtext>pk</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mi>P</mml:mi></mml:math></inline-formula>.</p></list-item>
<list-item>
<p>The DO&#x2019;s complete private key is <inline-formula id="ieqn-292"><mml:math id="mml-ieqn-292"><mml:msub><mml:mtext>Sk</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>.</p></list-item>
</list></p>
<p>Where <inline-formula id="ieqn-293"><mml:math id="mml-ieqn-293"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> is the local key and <inline-formula id="ieqn-294"><mml:math id="mml-ieqn-294"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> is the partial private key generated by the KGC.</p>
</sec>
<sec id="s6_4">
<label>6.4</label>
<title>Enhanced Tag Generation (TagGen)</title>
<p>Executed by the DO to generate enhanced unforgeable tags for each data block:<list list-type="order">
<list-item>
<p>Split the data file <inline-formula id="ieqn-295"><mml:math id="mml-ieqn-295"><mml:mi>M</mml:mi></mml:math></inline-formula> into <inline-formula id="ieqn-296"><mml:math id="mml-ieqn-296"><mml:mi>n</mml:mi></mml:math></inline-formula> equal-length blocks <inline-formula id="ieqn-297"><mml:math id="mml-ieqn-297"><mml:msub><mml:mi>m</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mi>n</mml:mi></mml:msub></mml:math></inline-formula>, and assign a unique file identifier <inline-formula id="ieqn-298"><mml:math id="mml-ieqn-298"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>M</mml:mi></mml:msub></mml:math></inline-formula> and block identifiers <inline-formula id="ieqn-299"><mml:math id="mml-ieqn-299"><mml:msub><mml:mtext>id</mml:mtext><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mtext>id</mml:mtext><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mtext>id</mml:mtext><mml:mi>n</mml:mi></mml:msub></mml:math></inline-formula>.</p></list-item>
<list-item>
<p>Randomly select <inline-formula id="ieqn-300"><mml:math id="mml-ieqn-300"><mml:mi>r</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> and compute the random parameter <inline-formula id="ieqn-301"><mml:math id="mml-ieqn-301"><mml:mi>T</mml:mi><mml:mo>=</mml:mo><mml:mi>r</mml:mi><mml:mi>P</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula>.</p></list-item>
<list-item>
<p>For each data block <inline-formula id="ieqn-302"><mml:math id="mml-ieqn-302"><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> (<inline-formula id="ieqn-303"><mml:math id="mml-ieqn-303"><mml:mn>1</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mi>n</mml:mi></mml:math></inline-formula>), compute the enhanced tag <inline-formula id="ieqn-304"><mml:math id="mml-ieqn-304"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> according to <xref ref-type="disp-formula" rid="eqn-4">Eq. (4)</xref>.</p></list-item>
<list-item>
<p>Construct the tag set <inline-formula id="ieqn-305"><mml:math id="mml-ieqn-305"><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:msubsup><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:msubsup></mml:math></inline-formula> (each tag is associated with the shared random parameter <inline-formula id="ieqn-306"><mml:math id="mml-ieqn-306"><mml:mi>T</mml:mi></mml:math></inline-formula>), and compute the file-level tag <inline-formula id="ieqn-307"><mml:math id="mml-ieqn-307"><mml:msub><mml:mtext>Tag</mml:mtext><mml:mi>M</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:mi>H</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>M</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> (for additional file integrity verification).</p></list-item>
<list-item>
<p>Upload the data, tags, and metadata <inline-formula id="ieqn-308"><mml:math id="mml-ieqn-308"><mml:mo stretchy="false">(</mml:mo><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mtext>Tag</mml:mtext><mml:mi>M</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>M</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> to the Cloud Server (CS), and then delete the local copy of <inline-formula id="ieqn-309"><mml:math id="mml-ieqn-309"><mml:mi>M</mml:mi></mml:math></inline-formula>.</p></list-item>
<list-item>
<p>Send the delegation information <inline-formula id="ieqn-310"><mml:math id="mml-ieqn-310"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mtext>ID</mml:mtext><mml:mrow><mml:mtext>CS</mml:mtext></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mtext>Tag</mml:mtext><mml:mi>M</mml:mi></mml:msub></mml:math></inline-formula> to the TPA, authorizing it to perform integrity auditing.</p></list-item>
</list></p>
</sec>
<sec id="s6_5">
<label>6.5</label>
<title>Challenge Generation (Challenge)</title>
<p>Executed by smart contracts deployed on the blockchain to generate decentralized and tamper-proof challenge information. The process is divided into three phases:<list list-type="order">
<list-item>
<p><bold>Commit Phase:</bold> The DO selects a secret value <inline-formula id="ieqn-311"><mml:math id="mml-ieqn-311"><mml:mtext>sv</mml:mtext><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, computes its hash <inline-formula id="ieqn-312"><mml:math id="mml-ieqn-312"><mml:mi>h</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mtext>sv</mml:mtext><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, and submits an audit task to the smart contract. The task includes metadata (such as <inline-formula id="ieqn-313"><mml:math id="mml-ieqn-313"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mtext>fname</mml:mtext><mml:mo>,</mml:mo><mml:msub><mml:mtext>PK</mml:mtext><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>) and <inline-formula id="ieqn-314"><mml:math id="mml-ieqn-314"><mml:mi>h</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mtext>sv</mml:mtext><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> (ensuring <inline-formula id="ieqn-315"><mml:math id="mml-ieqn-315"><mml:mtext>sv</mml:mtext></mml:math></inline-formula> cannot be tampered with later).</p></list-item>
<list-item>
<p><bold>Reveal Phase:</bold> The DO deposits a security deposit (such as cryptocurrency) into the smart contract as honest collateral, and then reveals the secret value <inline-formula id="ieqn-316"><mml:math id="mml-ieqn-316"><mml:msup><mml:mtext>sv</mml:mtext><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>. The contract verifies whether <inline-formula id="ieqn-317"><mml:math id="mml-ieqn-317"><mml:mi>h</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mtext>sv</mml:mtext><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is equal to <inline-formula id="ieqn-318"><mml:math id="mml-ieqn-318"><mml:mi>h</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mtext>sv</mml:mtext><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>: if yes, proceed; otherwise, confiscate the security deposit.</p></list-item>
<list-item>
<p><bold>GetRandom Phase:</bold> The smart contract generates two challenge seeds using the revealed <inline-formula id="ieqn-319"><mml:math id="mml-ieqn-319"><mml:mtext>sv</mml:mtext></mml:math></inline-formula> and task metadata:
<disp-formula id="ueqn-20"><mml:math id="mml-ueqn-20" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>h</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>sv</mml:mtext></mml:mrow><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mi>t</mml:mi><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mrow><mml:mtext>fname</mml:mtext></mml:mrow><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>pk</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>
<disp-formula id="ueqn-21"><mml:math id="mml-ueqn-21" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>h</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>sv</mml:mtext></mml:mrow><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mi>t</mml:mi><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mrow><mml:mtext>fname</mml:mtext></mml:mrow><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>pk</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>where <inline-formula id="ieqn-320"><mml:math id="mml-ieqn-320"><mml:mi>t</mml:mi></mml:math></inline-formula> is a timestamp used to prevent replay attacks. Seeds <inline-formula id="ieqn-321"><mml:math id="mml-ieqn-321"><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-322"><mml:math id="mml-ieqn-322"><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> are used to select challenge blocks and compute challenge weights, respectively.</p></list-item>
</list></p>
</sec>
<sec id="s6_6">
<label>6.6</label>
<title>Proof Generation (ProofGen)</title>
<p>Executed by the CS to respond to the TPA&#x2019;s challenge and generate an integrity proof:<list list-type="order">
<list-item>
<p>Using the challenge seeds <inline-formula id="ieqn-323"><mml:math id="mml-ieqn-323"><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-324"><mml:math id="mml-ieqn-324"><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, the CS selects <inline-formula id="ieqn-325"><mml:math id="mml-ieqn-325"><mml:mi>c</mml:mi></mml:math></inline-formula> challenge blocks and their weights: for <inline-formula id="ieqn-326"><mml:math id="mml-ieqn-326"><mml:mi>&#x03BE;</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>c</mml:mi></mml:math></inline-formula>,
<disp-formula id="ueqn-22"><mml:math id="mml-ueqn-22" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:msub><mml:mi>i</mml:mi><mml:mi>&#x03BE;</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>&#x03C0;</mml:mi><mml:mrow><mml:mrow><mml:mtext>key</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>&#x03BE;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mspace width="1em" /><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>i</mml:mi><mml:mi>&#x03BE;</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mrow><mml:mtext>key</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>&#x03BE;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p></list-item>
<list-item>
<p>Randomly select <inline-formula id="ieqn-327"><mml:math id="mml-ieqn-327"><mml:mi>w</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> and compute the blinding factor <inline-formula id="ieqn-328"><mml:math id="mml-ieqn-328"><mml:mover><mml:mi>W</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>=</mml:mo><mml:mi>w</mml:mi><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula> (used to protect data privacy).</p></list-item>
<list-item>
<p>Compute the aggregate proof:
<disp-formula id="ueqn-23"><mml:math id="mml-ueqn-23" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:mi>&#x03B4;</mml:mi><mml:mo>=</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>&#x03BE;</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>c</mml:mi></mml:munderover><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>i</mml:mi><mml:mi>&#x03BE;</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:msub><mml:mi>i</mml:mi><mml:mi>&#x03BE;</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mspace width="1em" /><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>Aggregate Tag</mml:mtext></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>
<disp-formula id="ueqn-24"><mml:math id="mml-ueqn-24" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:mi>&#x03BC;</mml:mi><mml:mo>=</mml:mo><mml:mi>&#x03C9;</mml:mi><mml:mo>+</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>&#x03BE;</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>c</mml:mi></mml:munderover><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>i</mml:mi><mml:mi>&#x03BE;</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:msub><mml:mi>i</mml:mi><mml:mi>&#x03BE;</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mspace width="1em" /><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>Aggregate Data</mml:mtext></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula></p></list-item>
<list-item>
<p>Construct the proof <inline-formula id="ieqn-329"><mml:math id="mml-ieqn-329"><mml:mtext>proof</mml:mtext><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B4;</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:mo>,</mml:mo><mml:mover><mml:mi>W</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and send it to the smart contract, where <inline-formula id="ieqn-330"><mml:math id="mml-ieqn-330"><mml:mi>T</mml:mi></mml:math></inline-formula> is the random parameter in the DO&#x2019;s tag set.</p></list-item>
</list></p>
</sec>
<sec id="s6_7">
<label>6.7</label>
<title>Proof Verification (ProofVerify)</title>
<p>Executed by the TPA to verify the proof submitted by the CS and confirm data integrity:<list list-type="order">
<list-item>
<p>Obtain the proof <inline-formula id="ieqn-331"><mml:math id="mml-ieqn-331"><mml:mtext>proof</mml:mtext><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B4;</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:mo>,</mml:mo><mml:mover><mml:mi>W</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and challenge seeds <inline-formula id="ieqn-332"><mml:math id="mml-ieqn-332"><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> from the blockchain.</p></list-item>
<list-item>
<p>Recompute the challenge block indices <inline-formula id="ieqn-333"><mml:math id="mml-ieqn-333"><mml:msub><mml:mi>i</mml:mi><mml:mi>&#x03BE;</mml:mi></mml:msub></mml:math></inline-formula> and weights <inline-formula id="ieqn-334"><mml:math id="mml-ieqn-334"><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:msub><mml:mi>i</mml:mi><mml:mi>&#x03BE;</mml:mi></mml:msub></mml:mrow></mml:msub></mml:math></inline-formula> using <inline-formula id="ieqn-335"><mml:math id="mml-ieqn-335"><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-336"><mml:math id="mml-ieqn-336"><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>.</p></list-item>
<list-item>
<p>Verify whether the following equation holds:
<disp-formula id="eqn-9"><label>(9)</label><mml:math id="mml-eqn-9" display="block"><mml:mstyle displaystyle="false" scriptlevel="0"><mml:mrow><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B4;</mml:mi><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mover><mml:mi>W</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>,</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>I</mml:mi></mml:mrow></mml:munder><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mtext>ID</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>pk</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>pk</mml:mtext></mml:mrow><mml:mi>u</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>I</mml:mi></mml:mrow></mml:munder><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>fname</mml:mtext></mml:mrow><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mrow><mml:mtext>id</mml:mtext></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:mstyle></mml:mrow></mml:mstyle></mml:math></disp-formula>where <inline-formula id="ieqn-337"><mml:math id="mml-ieqn-337"><mml:mi>I</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>i</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>i</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>i</mml:mi><mml:mi>c</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> is the set of challenge block indices.</p></list-item>
<list-item>
<p>If <xref ref-type="disp-formula" rid="eqn-5">Eq. (5)</xref> holds, determine that the data is intact; otherwise, determine that the data has been tampered with. The TPA records the audit result (true for intact, false for tampered) and related metadata (such as block height, transaction ID) on the blockchain.</p></list-item>
</list></p>
</sec>
</sec>
<sec id="s7">
<label>7</label>
<title>Security Analysis</title>
<sec id="s7_1">
<label>7.1</label>
<title>Tag Unforgeability against Type I Attackers</title>
<p><bold>Theorem 1:</bold> <italic>If there exists a PPT Type I attacker</italic> <inline-formula id="ieqn-338"><mml:math id="mml-ieqn-338"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mi>I</mml:mi></mml:msub></mml:math></inline-formula> <italic>who cannot access the master key of the Key Generation Center (KGC) but can replace the Data Owner&#x2019;s (DO&#x2019;s) public key, and can forge a valid tag with non-negligible advantage</italic> <inline-formula id="ieqn-339"><mml:math id="mml-ieqn-339"><mml:mi>&#x03B5;</mml:mi></mml:math></inline-formula>, <italic>then a simulator</italic> <inline-formula id="ieqn-340"><mml:math id="mml-ieqn-340"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> <italic>can be constructed to solve the Computational Diffie-Hellman (CDH) problem with non-negligible advantage</italic> <inline-formula id="ieqn-341"><mml:math id="mml-ieqn-341"><mml:msup><mml:mi>&#x03B5;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2265;</mml:mo><mml:mi>&#x03B5;</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>q</mml:mi><mml:mi>T</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mn>2</mml:mn><mml:mi>e</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <italic>where</italic> <inline-formula id="ieqn-342"><mml:math id="mml-ieqn-342"><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> <italic>and</italic> <inline-formula id="ieqn-343"><mml:math id="mml-ieqn-343"><mml:msub><mml:mi>q</mml:mi><mml:mi>T</mml:mi></mml:msub></mml:math></inline-formula> <italic>are the number of partial key queries and tag queries, respectively</italic>.</p>

<p><bold>Proof:</bold>
<list list-type="order">
<list-item>
<p><bold>Parameter Initialization:</bold> The simulator <inline-formula id="ieqn-344"><mml:math id="mml-ieqn-344"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> uses the CDH instance <inline-formula id="ieqn-345"><mml:math id="mml-ieqn-345"><mml:mo stretchy="false">(</mml:mo><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>a</mml:mi><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>b</mml:mi><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> with the goal of computing <inline-formula id="ieqn-346"><mml:math id="mml-ieqn-346"><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula>. <inline-formula id="ieqn-347"><mml:math id="mml-ieqn-347"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> constructs system public parameters, sets <inline-formula id="ieqn-348"><mml:math id="mml-ieqn-348"><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>a</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula>, randomly selects a target identity <inline-formula id="ieqn-349"><mml:math id="mml-ieqn-349"><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> and assigns a mark <inline-formula id="ieqn-350"><mml:math id="mml-ieqn-350"><mml:mi>&#x03C4;</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>. Select an additive cyclic group <inline-formula id="ieqn-351"><mml:math id="mml-ieqn-351"><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula> and a multiplicative cyclic group <inline-formula id="ieqn-352"><mml:math id="mml-ieqn-352"><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mi>T</mml:mi></mml:msub></mml:math></inline-formula> of prime order <inline-formula id="ieqn-353"><mml:math id="mml-ieqn-353"><mml:mi>q</mml:mi></mml:math></inline-formula>, a bilinear pairing <inline-formula id="ieqn-354"><mml:math id="mml-ieqn-354"><mml:mi>e</mml:mi><mml:mo>:</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mo>&#x00D7;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mi>T</mml:mi></mml:msub></mml:math></inline-formula>, define hash functions and pseudorandom functions/permutations that meet the requirements, set the system public key <inline-formula id="ieqn-355"><mml:math id="mml-ieqn-355"><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>a</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> (the master key <inline-formula id="ieqn-356"><mml:math id="mml-ieqn-356"><mml:mi>z</mml:mi><mml:mo>=</mml:mo><mml:mi>a</mml:mi></mml:math></inline-formula> is unknown), and disclose all parameters. Meanwhile, <inline-formula id="ieqn-357"><mml:math id="mml-ieqn-357"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> randomly selects a target identity <inline-formula id="ieqn-358"><mml:math id="mml-ieqn-358"><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, assigns a random mark <inline-formula id="ieqn-359"><mml:math id="mml-ieqn-359"><mml:mi>&#x03C4;</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> to all identities, where the mark of <inline-formula id="ieqn-360"><mml:math id="mml-ieqn-360"><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> is <inline-formula id="ieqn-361"><mml:math id="mml-ieqn-361"><mml:msup><mml:mi>&#x03C4;</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msup><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, and the marks of other identities are <inline-formula id="ieqn-362"><mml:math id="mml-ieqn-362"><mml:mi>&#x03C4;</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>.</p></list-item>
<list-item>
<p><bold>Query Responses:</bold>
<list list-type="simple">
<list-item><label>&#x25CF;</label>
<p><italic>Partial Key Query</italic>: When <inline-formula id="ieqn-363"><mml:math id="mml-ieqn-363"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mi>I</mml:mi></mml:msub></mml:math></inline-formula> queries the partial key of identity <inline-formula id="ieqn-364"><mml:math id="mml-ieqn-364"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>, if <inline-formula id="ieqn-365"><mml:math id="mml-ieqn-365"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2260;</mml:mo><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> (<inline-formula id="ieqn-366"><mml:math id="mml-ieqn-366"><mml:mi>&#x03C4;</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>), <inline-formula id="ieqn-367"><mml:math id="mml-ieqn-367"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> randomly selects <inline-formula id="ieqn-368"><mml:math id="mml-ieqn-368"><mml:msub><mml:mi>d</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, computes <inline-formula id="ieqn-369"><mml:math id="mml-ieqn-369"><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, and returns <inline-formula id="ieqn-370"><mml:math id="mml-ieqn-370"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>; if <inline-formula id="ieqn-371"><mml:math id="mml-ieqn-371"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2260;</mml:mo><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> (<inline-formula id="ieqn-372"><mml:math id="mml-ieqn-372"><mml:mi>&#x03C4;</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>), <inline-formula id="ieqn-373"><mml:math id="mml-ieqn-373"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> rejects the query to avoid leakage of the partial private key of the target identity.</p></list-item>
<list-item><label>&#x25CF;</label>
<p><italic>Public Key Replacement</italic>: When <inline-formula id="ieqn-374"><mml:math id="mml-ieqn-374"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mi>I</mml:mi></mml:msub></mml:math></inline-formula> replaces the public key of any identity, <inline-formula id="ieqn-375"><mml:math id="mml-ieqn-375"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> records the replacement relationship, and subsequent computations use the replaced public key synchronously.</p></list-item>
<list-item><label>&#x25CF;</label>
<p><italic>Tag Query</italic>: When <inline-formula id="ieqn-376"><mml:math id="mml-ieqn-376"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mi>I</mml:mi></mml:msub></mml:math></inline-formula> queries a tag, if <inline-formula id="ieqn-377"><mml:math id="mml-ieqn-377"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2260;</mml:mo><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, <inline-formula id="ieqn-378"><mml:math id="mml-ieqn-378"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> generates the tag according to the improved tag formula <inline-formula id="ieqn-379"><mml:math id="mml-ieqn-379"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mtext>id</mml:mtext><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mtext>pk</mml:mtext><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>r</mml:mi><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mtext>fname</mml:mtext><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mtext>id</mml:mtext><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> (<inline-formula id="ieqn-380"><mml:math id="mml-ieqn-380"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> is a random local key, <inline-formula id="ieqn-381"><mml:math id="mml-ieqn-381"><mml:mi>r</mml:mi></mml:math></inline-formula> is a random parameter, <inline-formula id="ieqn-382"><mml:math id="mml-ieqn-382"><mml:mi>T</mml:mi><mml:mo>=</mml:mo><mml:mi>r</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula>); if <inline-formula id="ieqn-383"><mml:math id="mml-ieqn-383"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, <inline-formula id="ieqn-384"><mml:math id="mml-ieqn-384"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> randomly selects <inline-formula id="ieqn-385"><mml:math id="mml-ieqn-385"><mml:mi>r</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, computes <inline-formula id="ieqn-386"><mml:math id="mml-ieqn-386"><mml:mi>T</mml:mi><mml:mo>=</mml:mo><mml:mi>r</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-387"><mml:math id="mml-ieqn-387"><mml:msubsup><mml:mi>Q</mml:mi><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>,</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, embeds <inline-formula id="ieqn-388"><mml:math id="mml-ieqn-388"><mml:mi>b</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> to construct the tag <inline-formula id="ieqn-389"><mml:math id="mml-ieqn-389"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:mi>b</mml:mi><mml:msubsup><mml:mi>Q</mml:mi><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>+</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>r</mml:mi><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, and returns <inline-formula id="ieqn-390"><mml:math id="mml-ieqn-390"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>.</p></list-item>
</list></p></list-item>
<list-item>
<p><bold>Forgery and Reduction:</bold> After making polynomial-time queries, <inline-formula id="ieqn-391"><mml:math id="mml-ieqn-391"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mi>I</mml:mi></mml:msub></mml:math></inline-formula> outputs a forged tag <inline-formula id="ieqn-392"><mml:math id="mml-ieqn-392"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> for a certain identity <inline-formula id="ieqn-393"><mml:math id="mml-ieqn-393"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>. If <inline-formula id="ieqn-394"><mml:math id="mml-ieqn-394"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> and its partial key has not been queried, <inline-formula id="ieqn-395"><mml:math id="mml-ieqn-395"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> substitutes the forged tag into the verification equation. Using the bilinearity of the bilinear pairing <inline-formula id="ieqn-396"><mml:math id="mml-ieqn-396"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>a</mml:mi><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>b</mml:mi><mml:mi>Q</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>Q</mml:mi><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>, combined with the collision resistance of the hash function and the non-degeneracy of the bilinear pairing, <inline-formula id="ieqn-397"><mml:math id="mml-ieqn-397"><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> is extracted from the forged tag, completing the solution to the CDH problem.</p></list-item>
<list-item>
<p><bold>Probability Analysis:</bold> The probability that <inline-formula id="ieqn-398"><mml:math id="mml-ieqn-398"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mi>I</mml:mi></mml:msub></mml:math></inline-formula> selects the target identity <inline-formula id="ieqn-399"><mml:math id="mml-ieqn-399"><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> for forgery and does not query its partial key is <inline-formula id="ieqn-400"><mml:math id="mml-ieqn-400"><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>q</mml:mi><mml:mi>T</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, and the probability of indistinguishability between the simulation and the real scheme is <inline-formula id="ieqn-401"><mml:math id="mml-ieqn-401"><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>q</mml:mi><mml:mi>T</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Therefore, the advantage of <inline-formula id="ieqn-402"><mml:math id="mml-ieqn-402"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> is <inline-formula id="ieqn-403"><mml:math id="mml-ieqn-403"><mml:msup><mml:mi>&#x03B5;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2265;</mml:mo><mml:mi>&#x03B5;</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>q</mml:mi><mml:mi>T</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mn>2</mml:mn><mml:mi>e</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, which contradicts the CDH hardness assumption. Thus, <inline-formula id="ieqn-404"><mml:math id="mml-ieqn-404"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mi>I</mml:mi></mml:msub></mml:math></inline-formula> cannot forge a valid tag.</p></list-item>
</list></p>
<p>&#x25A1;</p>
</sec>
<sec id="s7_2">
<label>7.2</label>
<title>Tag Unforgeability against Type II Attackers</title>

<p><bold>Theorem 2:</bold> <italic>If there exists a PPT Type II attacker</italic> <inline-formula id="ieqn-405"><mml:math id="mml-ieqn-405"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mrow><mml:mi>I</mml:mi><mml:mi>I</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> <italic>who can access the KGC&#x2019;s master key but cannot modify the DO&#x2019;s public key, and can forge a tag with non-negligible advantage</italic> <inline-formula id="ieqn-406"><mml:math id="mml-ieqn-406"><mml:mi>&#x03B5;</mml:mi></mml:math></inline-formula>, <italic>then there exists a simulator</italic> <inline-formula id="ieqn-407"><mml:math id="mml-ieqn-407"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> <italic>that can solve the CDH problem with advantage</italic> <inline-formula id="ieqn-408"><mml:math id="mml-ieqn-408"><mml:msup><mml:mi>&#x03B5;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2265;</mml:mo><mml:mi>&#x03B5;</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>q</mml:mi><mml:mi>T</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mn>2</mml:mn><mml:mi>e</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <italic>where</italic> <inline-formula id="ieqn-409"><mml:math id="mml-ieqn-409"><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> <italic>is the number of secret key queries</italic>.</p>

<p><bold>Proof:</bold>
<list list-type="order">
<list-item>
<p><bold>Parameter Initialization:</bold> <inline-formula id="ieqn-410"><mml:math id="mml-ieqn-410"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> receives the CDH instance <inline-formula id="ieqn-411"><mml:math id="mml-ieqn-411"><mml:mo stretchy="false">(</mml:mo><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>a</mml:mi><mml:mi>P</mml:mi><mml:mo>,</mml:mo><mml:mi>b</mml:mi><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, constructs system public parameters, sets the master key <inline-formula id="ieqn-412"><mml:math id="mml-ieqn-412"><mml:mi>z</mml:mi><mml:mo>=</mml:mo><mml:mi>a</mml:mi></mml:math></inline-formula> and the system public key <inline-formula id="ieqn-413"><mml:math id="mml-ieqn-413"><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>a</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula>, randomly selects a target identity <inline-formula id="ieqn-414"><mml:math id="mml-ieqn-414"><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> and assigns a mark <inline-formula id="ieqn-415"><mml:math id="mml-ieqn-415"><mml:msup><mml:mi>&#x03C4;</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msup><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, and the marks of other identities are <inline-formula id="ieqn-416"><mml:math id="mml-ieqn-416"><mml:mi>&#x03C4;</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>. <inline-formula id="ieqn-417"><mml:math id="mml-ieqn-417"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mrow><mml:mi>I</mml:mi><mml:mi>I</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> knows the master key and can obtain the partial private key of any identity.</p></list-item>
<list-item>
<p><bold>Query Responses:</bold>
<list list-type="simple">
<list-item><label>&#x25CF;</label>
<p><italic>Partial Key Query</italic>: For any identity <inline-formula id="ieqn-418"><mml:math id="mml-ieqn-418"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-419"><mml:math id="mml-ieqn-419"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> computes <inline-formula id="ieqn-420"><mml:math id="mml-ieqn-420"><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and the partial private key <inline-formula id="ieqn-421"><mml:math id="mml-ieqn-421"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>z</mml:mi><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>a</mml:mi><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>, and returns <inline-formula id="ieqn-422"><mml:math id="mml-ieqn-422"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> to <inline-formula id="ieqn-423"><mml:math id="mml-ieqn-423"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mrow><mml:mi>I</mml:mi><mml:mi>I</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>.</p></list-item>
<list-item><label>&#x25CF;</label>
<p><italic>Secret Key Query</italic>: When <inline-formula id="ieqn-424"><mml:math id="mml-ieqn-424"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mrow><mml:mi>I</mml:mi><mml:mi>I</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> queries the secret key of identity <inline-formula id="ieqn-425"><mml:math id="mml-ieqn-425"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>, if <inline-formula id="ieqn-426"><mml:math id="mml-ieqn-426"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2260;</mml:mo><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> (<inline-formula id="ieqn-427"><mml:math id="mml-ieqn-427"><mml:mi>&#x03C4;</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>), <inline-formula id="ieqn-428"><mml:math id="mml-ieqn-428"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> randomly selects <inline-formula id="ieqn-429"><mml:math id="mml-ieqn-429"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, and returns <inline-formula id="ieqn-430"><mml:math id="mml-ieqn-430"><mml:msub><mml:mtext>Sk</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>; if <inline-formula id="ieqn-431"><mml:math id="mml-ieqn-431"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula> (<inline-formula id="ieqn-432"><mml:math id="mml-ieqn-432"><mml:mi>&#x03C4;</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>), <inline-formula id="ieqn-433"><mml:math id="mml-ieqn-433"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> rejects the query.</p></list-item>
<list-item><label>&#x25CF;</label>
<p><italic>Tag Query</italic>: If <inline-formula id="ieqn-434"><mml:math id="mml-ieqn-434"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2260;</mml:mo><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, <inline-formula id="ieqn-435"><mml:math id="mml-ieqn-435"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> generates a real tag according to the improved formula; if <inline-formula id="ieqn-436"><mml:math id="mml-ieqn-436"><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, <inline-formula id="ieqn-437"><mml:math id="mml-ieqn-437"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> randomly selects <inline-formula id="ieqn-438"><mml:math id="mml-ieqn-438"><mml:mi>r</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="double-struck">Z</mml:mi></mml:mrow><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, computes <inline-formula id="ieqn-439"><mml:math id="mml-ieqn-439"><mml:mi>T</mml:mi><mml:mo>=</mml:mo><mml:mi>r</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula>, sets <inline-formula id="ieqn-440"><mml:math id="mml-ieqn-440"><mml:msubsup><mml:mtext>pk</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>=</mml:mo><mml:mi>b</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> (embeds the CDH instance parameter <inline-formula id="ieqn-441"><mml:math id="mml-ieqn-441"><mml:mi>b</mml:mi></mml:math></inline-formula>), and generates a tag according to the formula <inline-formula id="ieqn-442"><mml:math id="mml-ieqn-442"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>D</mml:mi><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>+</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>r</mml:mi><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> (<inline-formula id="ieqn-443"><mml:math id="mml-ieqn-443"><mml:mi>&#x03B3;</mml:mi></mml:math></inline-formula> is a random value), and returns <inline-formula id="ieqn-444"><mml:math id="mml-ieqn-444"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>.</p></list-item>
</list></p></list-item>
<list-item>
<p><bold>Forgery and Reduction:</bold> After <inline-formula id="ieqn-445"><mml:math id="mml-ieqn-445"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mrow><mml:mi>I</mml:mi><mml:mi>I</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> outputs a forged tag <inline-formula id="ieqn-446"><mml:math id="mml-ieqn-446"><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> for <inline-formula id="ieqn-447"><mml:math id="mml-ieqn-447"><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math></inline-formula>, <inline-formula id="ieqn-448"><mml:math id="mml-ieqn-448"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> substitutes it into the verification equation. Since <inline-formula id="ieqn-449"><mml:math id="mml-ieqn-449"><mml:msubsup><mml:mtext>pk</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>=</mml:mo><mml:mi>b</mml:mi><mml:mi>P</mml:mi><mml:mo>=</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mi>P</mml:mi></mml:math></inline-formula> (implying <inline-formula id="ieqn-450"><mml:math id="mml-ieqn-450"><mml:msubsup><mml:mi>x</mml:mi><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>=</mml:mo><mml:mi>b</mml:mi></mml:math></inline-formula>), the forged tag must satisfy <inline-formula id="ieqn-451"><mml:math id="mml-ieqn-451"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mi>a</mml:mi><mml:msubsup><mml:mi>Q</mml:mi><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>+</mml:mo><mml:mi>b</mml:mi><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:msup><mml:mi>r</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Using the bilinearity of the bilinear pairing, <inline-formula id="ieqn-452"><mml:math id="mml-ieqn-452"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> extracts <inline-formula id="ieqn-453"><mml:math id="mml-ieqn-453"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>Q</mml:mi><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mi>b</mml:mi></mml:msup></mml:math></inline-formula>, and combines <inline-formula id="ieqn-454"><mml:math id="mml-ieqn-454"><mml:msubsup><mml:mi>Q</mml:mi><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>,</mml:mo><mml:mi>a</mml:mi><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> to derive <inline-formula id="ieqn-455"><mml:math id="mml-ieqn-455"><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> after eliminating irrelevant parameters, completing the solution to the CDH problem.</p></list-item>
<list-item>
<p><bold>Probability Analysis:</bold> The probability that the target identity is not queried for its secret key is <inline-formula id="ieqn-456"><mml:math id="mml-ieqn-456"><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>q</mml:mi><mml:mi>T</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, and the probability of simulation indistinguishability is <inline-formula id="ieqn-457"><mml:math id="mml-ieqn-457"><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mi>e</mml:mi></mml:math></inline-formula>. Thus, the advantage of <inline-formula id="ieqn-458"><mml:math id="mml-ieqn-458"><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow></mml:math></inline-formula> is <inline-formula id="ieqn-459"><mml:math id="mml-ieqn-459"><mml:msup><mml:mi>&#x03B5;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2265;</mml:mo><mml:mi>&#x03B5;</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>q</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>q</mml:mi><mml:mi>T</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mn>2</mml:mn><mml:mi>e</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, which contradicts the CDH hardness assumption. Therefore, <inline-formula id="ieqn-460"><mml:math id="mml-ieqn-460"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mrow><mml:mi>I</mml:mi><mml:mi>I</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> cannot forge a valid tag.</p></list-item>
</list></p>
<p>&#x25A1;</p>
</sec>
<sec id="s7_3">
<label>7.3</label>
<title>Proof Forgery Resistance against Type III Attackers</title>

<p><bold>Theorem 3:</bold> <italic>Under the Discrete Logarithm (DL) assumption, the probability that any PPT Type III attacker</italic> <inline-formula id="ieqn-461"><mml:math id="mml-ieqn-461"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mrow><mml:mi>I</mml:mi><mml:mi>I</mml:mi><mml:mi>I</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> <italic>forges a valid audit proof is negligible</italic>.</p>

<p><bold>Proof:</bold>
<list list-type="order">
<list-item>
<p><bold>Attack Goal and Constraints:</bold> After tampering with data, <inline-formula id="ieqn-462"><mml:math id="mml-ieqn-462"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mrow><mml:mi>I</mml:mi><mml:mi>I</mml:mi><mml:mi>I</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> attempts to generate a forged proof <inline-formula id="ieqn-463"><mml:math id="mml-ieqn-463"><mml:mtext>proof</mml:mtext><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msup><mml:mi>&#x03BC;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msup><mml:mi>W</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> such that the verification equation <inline-formula id="ieqn-464"><mml:math id="mml-ieqn-464"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mi>P</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03BC;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mi>W</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x2211;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mtext>pk</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x2211;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:msup><mml:mi>T</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> holds. In a real proof, <inline-formula id="ieqn-465"><mml:math id="mml-ieqn-465"><mml:mi>&#x03B4;</mml:mi><mml:mo>=</mml:mo><mml:mo>&#x2211;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-466"><mml:math id="mml-ieqn-466"><mml:mi>&#x03BC;</mml:mi><mml:mo>=</mml:mo><mml:mi>&#x03C9;</mml:mi><mml:mo>+</mml:mo><mml:mo>&#x2211;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, and the core constraint for the verification equation to hold is that <inline-formula id="ieqn-467"><mml:math id="mml-ieqn-467"><mml:mo>&#x2211;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> corresponds to real data and the blinding factor <inline-formula id="ieqn-468"><mml:math id="mml-ieqn-468"><mml:mi>&#x03C9;</mml:mi><mml:mo>=</mml:mo><mml:mi>w</mml:mi></mml:math></inline-formula>.</p></list-item>
<list-item>
<p><bold>Core Obstacle to Forgery:</bold> When <inline-formula id="ieqn-469"><mml:math id="mml-ieqn-469"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mrow><mml:mi>I</mml:mi><mml:mi>I</mml:mi><mml:mi>I</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> tampers with a data block to <inline-formula id="ieqn-470"><mml:math id="mml-ieqn-470"><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>, it needs to make <inline-formula id="ieqn-471"><mml:math id="mml-ieqn-471"><mml:msup><mml:mi>&#x03BC;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mi>W</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> match <inline-formula id="ieqn-472"><mml:math id="mml-ieqn-472"><mml:mo>&#x2211;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula>. Since <inline-formula id="ieqn-473"><mml:math id="mml-ieqn-473"><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>pub</mml:mtext></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mi>P</mml:mi></mml:math></inline-formula> (<inline-formula id="ieqn-474"><mml:math id="mml-ieqn-474"><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> is a hash value), if <inline-formula id="ieqn-475"><mml:math id="mml-ieqn-475"><mml:mo>&#x2211;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2260;</mml:mo><mml:mo>&#x2211;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, then <inline-formula id="ieqn-476"><mml:math id="mml-ieqn-476"><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x2211;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msubsup><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2211;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:msup><mml:mi>W</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2212;</mml:mo><mml:mi>&#x03C9;</mml:mi><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> must hold. The left-hand side of the equation is <inline-formula id="ieqn-477"><mml:math id="mml-ieqn-477"><mml:mo stretchy="false">(</mml:mo><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>m</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mi>P</mml:mi></mml:math></inline-formula> (<inline-formula id="ieqn-478"><mml:math id="mml-ieqn-478"><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>m</mml:mi></mml:math></inline-formula> is the weighted sum difference of the data), and the right-hand side is <inline-formula id="ieqn-479"><mml:math id="mml-ieqn-479"><mml:msup><mml:mi>W</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2212;</mml:mo><mml:mi>&#x03C9;</mml:mi><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mi>P</mml:mi></mml:math></inline-formula>. For the equation to hold, the discrete logarithm <inline-formula id="ieqn-480"><mml:math id="mml-ieqn-480"><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> of <inline-formula id="ieqn-481"><mml:math id="mml-ieqn-481"><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> needs to be solved, i.e., computing <inline-formula id="ieqn-482"><mml:math id="mml-ieqn-482"><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula> given <inline-formula id="ieqn-483"><mml:math id="mml-ieqn-483"><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-484"><mml:math id="mml-ieqn-484"><mml:mi>P</mml:mi></mml:math></inline-formula>.</p></list-item>
<list-item>
<p><bold>Intractability Under the DL Assumption:</bold> According to the DL assumption, a PPT attacker cannot efficiently compute the discrete logarithm <inline-formula id="ieqn-485"><mml:math id="mml-ieqn-485"><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula>. Even if <inline-formula id="ieqn-486"><mml:math id="mml-ieqn-486"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mrow><mml:mi>I</mml:mi><mml:mi>I</mml:mi><mml:mi>I</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> attempts to guess <inline-formula id="ieqn-487"><mml:math id="mml-ieqn-487"><mml:msub><mml:mi>h</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:math></inline-formula>, since <inline-formula id="ieqn-488"><mml:math id="mml-ieqn-488"><mml:mi>q</mml:mi></mml:math></inline-formula> is a sufficiently large prime number, the probability of successful guessing is <inline-formula id="ieqn-489"><mml:math id="mml-ieqn-489"><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>q</mml:mi></mml:math></inline-formula>, which is negligible. Meanwhile, the randomness of the blinding factor <inline-formula id="ieqn-490"><mml:math id="mml-ieqn-490"><mml:mi>&#x03C9;</mml:mi></mml:math></inline-formula> further increases the difficulty of forgery, and <inline-formula id="ieqn-491"><mml:math id="mml-ieqn-491"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mrow><mml:mi>I</mml:mi><mml:mi>I</mml:mi><mml:mi>I</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> cannot accurately construct <inline-formula id="ieqn-492"><mml:math id="mml-ieqn-492"><mml:msup><mml:mi>W</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> to satisfy the equation constraint. Therefore, the probability that <inline-formula id="ieqn-493"><mml:math id="mml-ieqn-493"><mml:msub><mml:mrow><mml:mi>&#x1D49C;</mml:mi></mml:mrow><mml:mrow><mml:mi>I</mml:mi><mml:mi>I</mml:mi><mml:mi>I</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> forges a valid audit proof is negligible.</p></list-item>
</list></p>
<p>&#x25A1;</p>
</sec>
<sec id="s7_4">
<label>7.4</label>
<title>Data Privacy Preservation</title>

<p><bold>Theorem 4:</bold> <italic>The scheme preserves the DO&#x2019;s data privacy during public auditing, and no external entity (including the Third-Party Auditor (TPA), CS, miners, etc.) can recover the original data from the audit records</italic>.</p>

<p><bold>Proof:</bold>
<list list-type="order">
<list-item>
<p><bold>Privacy Isolation of Audit Records:</bold> On-chain audit records include challenge seeds <inline-formula id="ieqn-494"><mml:math id="mml-ieqn-494"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, proof components <inline-formula id="ieqn-495"><mml:math id="mml-ieqn-495"><mml:mi>&#x03B4;</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:mo>,</mml:mo><mml:mi>W</mml:mi><mml:mo>,</mml:mo><mml:mi>T</mml:mi></mml:math></inline-formula>, and audit results. Each component achieves privacy preservation through cryptographic mechanisms and does not directly expose the original data <inline-formula id="ieqn-496"><mml:math id="mml-ieqn-496"><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>.</p></list-item>
<list-item>
<p><bold>Privacy Guarantee of Each Component:</bold>
<list list-type="simple">
<list-item><label>&#x25CF;</label>
<p><italic>Challenge Seeds</italic>: Generated by the DO&#x2019;s secret value <inline-formula id="ieqn-497"><mml:math id="mml-ieqn-497"><mml:mtext>sv</mml:mtext></mml:math></inline-formula>, timestamp <inline-formula id="ieqn-498"><mml:math id="mml-ieqn-498"><mml:mi>t</mml:mi></mml:math></inline-formula>, file name, user identity, and other parameters through hash functions, i.e., <inline-formula id="ieqn-499"><mml:math id="mml-ieqn-499"><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>h</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mtext>sv</mml:mtext><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mi>t</mml:mi><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mtext>fname</mml:mtext><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mtext>pk</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, <inline-formula id="ieqn-500"><mml:math id="mml-ieqn-500"><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>h</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mtext>sv</mml:mtext><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mi>t</mml:mi><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mtext>fname</mml:mtext><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mtext>pk</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. The one-wayness of hash functions ensures that external entities cannot reverse-engineer <inline-formula id="ieqn-501"><mml:math id="mml-ieqn-501"><mml:mtext>sv</mml:mtext></mml:math></inline-formula> or data-related information from the seeds, and the dynamic nature of the timestamp <inline-formula id="ieqn-502"><mml:math id="mml-ieqn-502"><mml:mi>t</mml:mi></mml:math></inline-formula> prevents attackers from predicting the distribution of challenge blocks.</p></list-item>
<list-item><label>&#x25CF;</label>
<p><italic>Proof Component <inline-formula id="ieqn-503"><mml:math id="mml-ieqn-503"><mml:mi>&#x03B4;</mml:mi></mml:math></inline-formula></italic>: <inline-formula id="ieqn-504"><mml:math id="mml-ieqn-504"><mml:mi>&#x03B4;</mml:mi><mml:mo>=</mml:mo><mml:mo>&#x2211;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo>&#x2211;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>r</mml:mi><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, which is an aggregate element in group <inline-formula id="ieqn-505"><mml:math id="mml-ieqn-505"><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula>. The <inline-formula id="ieqn-506"><mml:math id="mml-ieqn-506"><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> term is related to the original data but is masked by <inline-formula id="ieqn-507"><mml:math id="mml-ieqn-507"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and <inline-formula id="ieqn-508"><mml:math id="mml-ieqn-508"><mml:mi>r</mml:mi><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, and <inline-formula id="ieqn-509"><mml:math id="mml-ieqn-509"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> (secretly transmitted by the KGC), <inline-formula id="ieqn-510"><mml:math id="mml-ieqn-510"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> (locally stored by the DO), and <inline-formula id="ieqn-511"><mml:math id="mml-ieqn-511"><mml:mi>r</mml:mi></mml:math></inline-formula> (randomly generated) are all secret parameters, so external entities cannot separate and extract <inline-formula id="ieqn-512"><mml:math id="mml-ieqn-512"><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>.</p></list-item>
<list-item><label>&#x25CF;</label>
<p><italic>Proof Component <inline-formula id="ieqn-513"><mml:math id="mml-ieqn-513"><mml:mi>&#x03BC;</mml:mi></mml:math></inline-formula></italic>: <inline-formula id="ieqn-514"><mml:math id="mml-ieqn-514"><mml:mi>&#x03BC;</mml:mi><mml:mo>=</mml:mo><mml:mi>&#x03C9;</mml:mi><mml:mo>+</mml:mo><mml:mo>&#x2211;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, where <inline-formula id="ieqn-515"><mml:math id="mml-ieqn-515"><mml:mi>&#x03C9;</mml:mi></mml:math></inline-formula> is a random blinding factor. <inline-formula id="ieqn-516"><mml:math id="mml-ieqn-516"><mml:mo>&#x2211;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is a weighted sum of the data, which is completely masked by <inline-formula id="ieqn-517"><mml:math id="mml-ieqn-517"><mml:mi>&#x03C9;</mml:mi></mml:math></inline-formula>, and external entities cannot separate this weighted sum from <inline-formula id="ieqn-518"><mml:math id="mml-ieqn-518"><mml:mi>&#x03BC;</mml:mi></mml:math></inline-formula>; moreover, <inline-formula id="ieqn-519"><mml:math id="mml-ieqn-519"><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is generated by the challenge seeds (unpredictable), so even if multiple sets of <inline-formula id="ieqn-520"><mml:math id="mml-ieqn-520"><mml:mi>&#x03BC;</mml:mi></mml:math></inline-formula> values are obtained, individual <inline-formula id="ieqn-521"><mml:math id="mml-ieqn-521"><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> cannot be solved through linear equations.</p></list-item>
<list-item><label>&#x25CF;</label>
<p><italic>Proof Components <inline-formula id="ieqn-522"><mml:math id="mml-ieqn-522"><mml:mi>W</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-523"><mml:math id="mml-ieqn-523"><mml:mi>T</mml:mi></mml:math></inline-formula></italic>: <inline-formula id="ieqn-524"><mml:math id="mml-ieqn-524"><mml:mi>W</mml:mi><mml:mo>=</mml:mo><mml:mi>w</mml:mi><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> (<inline-formula id="ieqn-525"><mml:math id="mml-ieqn-525"><mml:mi>w</mml:mi></mml:math></inline-formula> is a random value), <inline-formula id="ieqn-526"><mml:math id="mml-ieqn-526"><mml:mi>T</mml:mi><mml:mo>=</mml:mo><mml:mi>r</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> (<inline-formula id="ieqn-527"><mml:math id="mml-ieqn-527"><mml:mi>r</mml:mi></mml:math></inline-formula> is a random value). Both are random elements in group <inline-formula id="ieqn-528"><mml:math id="mml-ieqn-528"><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow></mml:math></inline-formula>, have no direct association with the original data, and are only used to close the verification logic without leaking data information.</p></list-item>
<list-item><label>&#x25CF;</label>
<p><italic>Dynamic Hash Input</italic>: The input of <inline-formula id="ieqn-529"><mml:math id="mml-ieqn-529"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula> is <inline-formula id="ieqn-530"><mml:math id="mml-ieqn-530"><mml:mtext>fname</mml:mtext><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mtext>ID</mml:mtext><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:msub><mml:mi>Q</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mi>T</mml:mi></mml:math></inline-formula>, and the dynamic nature of <inline-formula id="ieqn-531"><mml:math id="mml-ieqn-531"><mml:mi>T</mml:mi></mml:math></inline-formula> makes the output of <inline-formula id="ieqn-532"><mml:math id="mml-ieqn-532"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula> always a random group element, preventing attackers from inferring file names and block ID patterns through static hash values and further guessing data content.</p></list-item>
</list></p></list-item>
</list></p>
<p>&#x25A1;</p>
</sec>
<sec id="s7_5">
<label>7.5</label>
<title>Collusion Resistance</title>

<p><bold>Theorem 5:</bold> <italic>The scheme can resist collusion attacks by any combination of entities (TPA and CS, CS and miners, KGC and CS, etc.), preventing data tampering or manipulation of audit results</italic>.</p>

<p><bold>Proof:</bold>
<list list-type="order">
<list-item>
<p><bold>Resistance against TPA-CS Collusion:</bold> Challenges are generated by blockchain smart contracts based on the DO&#x2019;s secret value <inline-formula id="ieqn-533"><mml:math id="mml-ieqn-533"><mml:mtext>sv</mml:mtext></mml:math></inline-formula>, timestamp <inline-formula id="ieqn-534"><mml:math id="mml-ieqn-534"><mml:mi>t</mml:mi></mml:math></inline-formula>, and metadata. The TPA is only responsible for performing verification and cannot manipulate the challenge seeds <inline-formula id="ieqn-535"><mml:math id="mml-ieqn-535"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, so it naturally cannot disclose future challenge block indices or weights to the CS. Meanwhile, tag generation in the improved scheme relies on the dynamic parameter <inline-formula id="ieqn-536"><mml:math id="mml-ieqn-536"><mml:mi>T</mml:mi></mml:math></inline-formula>, and the input of <inline-formula id="ieqn-537"><mml:math id="mml-ieqn-537"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula> includes <inline-formula id="ieqn-538"><mml:math id="mml-ieqn-538"><mml:mi>T</mml:mi></mml:math></inline-formula>, making the hash value impossible to precompute. Even if the CS colludes with the TPA, it cannot forge a tag that can pass verification, and the collusion attack fails.</p></list-item>
<list-item>
<p><bold>Resistance against CS-Minor Collusion:</bold> Challenge seeds are derived from the DO&#x2019;s private parameter <inline-formula id="ieqn-539"><mml:math id="mml-ieqn-539"><mml:mtext>sv</mml:mtext></mml:math></inline-formula> and the unpredictable timestamp <inline-formula id="ieqn-540"><mml:math id="mml-ieqn-540"><mml:mi>t</mml:mi></mml:math></inline-formula>. Miners are only responsible for maintaining the blockchain ledger and cannot interfere with the seed generation process, nor can they generate biased challenge blocks for the CS (such as avoiding tampered data blocks). In addition, all auditing processes and results are recorded on the blockchain, and the blockchain&#x2019;s consensus mechanism ensures the immutability of the ledger. Collusion between miners and the CS cannot modify the on-chain audit logs or evade audit responsibilities.</p></list-item>
<list-item>
<p><bold>Resistance against KGC-CS Collusion:</bold> The DO&#x2019;s complete private key is <inline-formula id="ieqn-541"><mml:math id="mml-ieqn-541"><mml:msub><mml:mtext>Sk</mml:mtext><mml:mi>u</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-542"><mml:math id="mml-ieqn-542"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> is a secret key generated locally by the DO (unknown to the KGC) and <inline-formula id="ieqn-543"><mml:math id="mml-ieqn-543"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> is a partial private key generated by the KGC. Even if the KGC leaks <inline-formula id="ieqn-544"><mml:math id="mml-ieqn-544"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> to the CS, the CS still lacks <inline-formula id="ieqn-545"><mml:math id="mml-ieqn-545"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> and cannot generate a valid tag according to the tag formula <inline-formula id="ieqn-546"><mml:math id="mml-ieqn-546"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>r</mml:mi><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Meanwhile, <inline-formula id="ieqn-547"><mml:math id="mml-ieqn-547"><mml:mi>T</mml:mi></mml:math></inline-formula> is randomly generated by the DO and incorporated into the input of <inline-formula id="ieqn-548"><mml:math id="mml-ieqn-548"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula>, so the KGC and CS cannot precompute the <inline-formula id="ieqn-549"><mml:math id="mml-ieqn-549"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula> value. Even if <inline-formula id="ieqn-550"><mml:math id="mml-ieqn-550"><mml:msub><mml:mi>D</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> is obtained, a tag matching <inline-formula id="ieqn-551"><mml:math id="mml-ieqn-551"><mml:mi>T</mml:mi></mml:math></inline-formula> cannot be forged, and the binding of <inline-formula id="ieqn-552"><mml:math id="mml-ieqn-552"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> and the <inline-formula id="ieqn-553"><mml:math id="mml-ieqn-553"><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula> term in the verification process further blocks the forgery path.</p></list-item>
<list-item>
<p><bold>Defense against Other Collusion Scenarios:</bold> For more complex scenarios such as collusion among the KGC, TPA, and CS, since the DO&#x2019;s local key <inline-formula id="ieqn-554"><mml:math id="mml-ieqn-554"><mml:msub><mml:mi>x</mml:mi><mml:mi>u</mml:mi></mml:msub></mml:math></inline-formula> and secret value <inline-formula id="ieqn-555"><mml:math id="mml-ieqn-555"><mml:mtext>sv</mml:mtext></mml:math></inline-formula> are always independently controlled by the DO and not leaked to any external entities, the colluders cannot obtain complete secret information, nor can they break through the tag unforgeability and the decentralized mechanism of challenge generation, making it impossible to achieve the attack goal.</p></list-item>
</list></p>
<p>&#x25A1;</p>
<p>A comparison of the original scheme and the improved scheme in four aspects is provided, and the security attribute analysis is shown in <xref ref-type="table" rid="table-1">Table 1</xref>:</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Comparison of security attributes.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>Security Attribute</th>
<th>Original Scheme</th>
<th>Improved Scheme</th>
</tr>
</thead>
<tbody>
<tr>
<td>Tag Unforgeability</td>
<td><inline-formula id="ieqn-556"><mml:math id="mml-ieqn-556"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-557"><mml:math id="mml-ieqn-557"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td>Collusion Resistance</td>
<td>Partial</td>
<td><inline-formula id="ieqn-558"><mml:math id="mml-ieqn-558"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
<tr>
<td>TPA Dependence</td>
<td><inline-formula id="ieqn-559"><mml:math id="mml-ieqn-559"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-560"><mml:math id="mml-ieqn-560"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>Dynamic Update Support</td>
<td><inline-formula id="ieqn-561"><mml:math id="mml-ieqn-561"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-562"><mml:math id="mml-ieqn-562"><mml:mi>&#x2713;</mml:mi></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec id="s8">
<label>8</label>
<title>Experimental Evaluation</title>
<p>To comprehensively verify the feasibility, efficiency, and security of the proposed blockchain-based certificateless cloud data integrity auditing scheme with enhanced tags in actual deployment, we fully implemented the seven core phases of the protocol on a standard experimental platform and measured the computational overhead of each phase.</p>
<sec id="s8_1">
<label>8.1</label>
<title>Experimental Environment Setup</title>
<sec id="s8_1_1">
<label>8.1.1</label>
<title>Hardware and Software Configuration</title>
<p>All experiments were performed on the same workstation to eliminate the impact of hardware differences on performance evaluation. The specific hardware and software configurations are as follows:<list list-type="bullet">
<list-item>
<p>Operating System: Windows 11 Professional (64-bit)</p></list-item>
<list-item>
<p>Central Processing Unit: Intel Core i7-12700H @ 2.30 GHz (14 cores/20 threads)</p></list-item>
<list-item>
<p>Memory Capacity: 32 GB DDR5 RAM</p></list-item>
<list-item>
<p>Storage Device: 1 TB NVMe PCIe 4.0 SSD</p></list-item>
<list-item>
<p>Java Runtime: OpenJDK 17.0.8 (LTS version)</p></list-item>
<list-item>
<p>Cryptographic Library: JPBC (Java Pairing-Based Cryptography Library) v2.0.0</p></list-item>
<list-item>
<p>Development and Debugging Environment: IntelliJ IDEA 2023.2 Community Edition</p></list-item>
<list-item>
<p>Bilinear Pairing Type: Type A symmetric bilinear pairing (defined by the <monospace>a. properties</monospace> configuration file, whose elliptic curve parameters correspond to approximately 1024-bit RSA security strength)</p></list-item>
</list></p>
</sec>
<sec id="s8_1_2">
<label>8.1.2</label>
<title>Parameter Settings</title>
<p>The parameter settings for the experiments are configured to simulate real-world multi-cloud storage auditing scenarios: the target file is named <monospace>exp_data_1GB.txt</monospace> (with a total simulated data volume of approximately 100 KB, split into 100 data blocks each of 1024 bytes for tag management), 10 blocks are randomly selected by the TPA for challenge during auditing, and the unique user identifier is set as <monospace>user_001</monospace>.</p>
<p>The bilinear pairing adopts a 160-bit prime order consistent with Type A curve specifications (meeting basic security requirements), and the hash functions used are deterministic group element-mapping implementations provided by the JPBC Library. These parameters ensure the validity and relevance of the experimental results while balancing security and computational feasibility.</p>
</sec>
</sec>
<sec id="s8_2">
<label>8.2</label>
<title>Computational Overhead Analysis</title>
<sec id="s8_2_1">
<label>8.2.1</label>
<title>Tag Generation Overhead (TagGen)</title>
<p>Tag generation is the main computational task on the DO side. We measured the time overhead of generating a single tag and batch-generating tags. Due to the addition of parameter <inline-formula id="ieqn-563"><mml:math id="mml-ieqn-563"><mml:mi>T</mml:mi></mml:math></inline-formula> to the input of <inline-formula id="ieqn-564"><mml:math id="mml-ieqn-564"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula>, the improved scheme has a slight increase in the time for a single hash computation, but the overall overhead increment is negligible in practical applications. The comparison of tag generation time is shown in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>:</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Tag generation time comparison.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_81399-fig-2.tif"/>
</fig>
</sec>
<sec id="s8_2_2">
<label>8.2.2</label>
<title>Proof Generation Overhead (ProofGen)</title>
<p>Proof generation is executed by the Cloud Server (CS), involving tag aggregation and data blinding operations. The improved scheme reduces the overhead in the proof generation phase because <inline-formula id="ieqn-565"><mml:math id="mml-ieqn-565"><mml:mi>T</mml:mi></mml:math></inline-formula> has been precomputed and stored in the CS, and only one dynamic hash needs to be called during the aggregation process. The comparison of proof generation time is shown in <xref ref-type="fig" rid="fig-3">Fig. 3</xref>:</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Proof generation time comparison.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_81399-fig-3.tif"/>
</fig>
</sec>
<sec id="s8_2_3">
<label>8.2.3</label>
<title>Proof Verification Overhead (ProofVerify)</title>
<p>The verification phase is executed by the TPA or smart contract, including bilinear pairing computation and hash verification. The main overhead of the verification phase comes from bilinear pairing operations. The overall verification time of the improved scheme is reduced, and the efficiency is improved. The comparison of proof verification time is shown in <xref ref-type="fig" rid="fig-4">Fig. 4</xref>:</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Proof verification time comparison.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_81399-fig-4.tif"/>
</fig>
</sec>
</sec>
<sec id="s8_3">
<label>8.3</label>
<title>Communication Overhead Analysis</title>
<p>Communication overhead is a key performance indicator in the practical deployment of cloud storage integrity auditing schemes, which mainly depends on the data volume and number of interactions transmitted between entities (Data Owner DO, Cloud Server CS, Third-Party Auditor TPA, blockchain nodes) during the auditing process.</p>
<sec id="s8_3_1">
<label>8.3.1</label>
<title>Communication Scenarios and Composition of Transmitted Data</title>
<p>The core communication scenarios during the auditing process include four types:
<list list-type="simple">
<list-item>
<label>DO &#x02192; CS</label> 
<p>Data Upload Phase: The DO transmits original data blocks, corresponding tag sets (<inline-formula id="ieqn-566"><mml:math id="mml-ieqn-566"><mml:mi mathvariant="normal">&#x03A6;</mml:mi></mml:math></inline-formula>), and file tags (<inline-formula id="ieqn-567"><mml:math id="mml-ieqn-567"><mml:msub><mml:mtext>Tag</mml:mtext><mml:mi>M</mml:mi></mml:msub></mml:math></inline-formula>) to the CS;</p></list-item>
<list-item>
<label>TPA &#x02192; CS</label>
<p>Challenge Phase: The TPA generates challenge information based on smart contracts and sends it to the CS. The challenge information includes challenge seeds <inline-formula id="ieqn-568"><mml:math id="mml-ieqn-568"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, challenge block index sets (<inline-formula id="ieqn-569"><mml:math id="mml-ieqn-569"><mml:mi>I</mml:mi></mml:math></inline-formula>), and verification parameters;</p></list-item>
<list-item>
<label>CS &#x02192; TPA</label>
<p>Proof Feedback Phase: The CS generates integrity proofs according to the challenge information and returns them to the TPA. The proof information includes aggregate tags (<inline-formula id="ieqn-570"><mml:math id="mml-ieqn-570"><mml:mi>&#x03B4;</mml:mi></mml:math></inline-formula>), blinding parameters (<inline-formula id="ieqn-571"><mml:math id="mml-ieqn-571"><mml:mi>&#x03BC;</mml:mi><mml:mo>,</mml:mo><mml:mover><mml:mi>W</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover></mml:math></inline-formula>), and precomputed parameters (<inline-formula id="ieqn-572"><mml:math id="mml-ieqn-572"><mml:mi>T</mml:mi></mml:math></inline-formula>);</p></list-item>
<list-item>
<label>TPA &#x02192; Blockchain</label>
<p>Result On-Chain Phase: The TPA packages the audit results, challenge information, and proof information into transactions and uploads them to the chain to ensure the traceability of the auditing process.</p></list-item>
</list></p>
<p>The composition of transmitted data in the two schemes follows the same protocol logic, but the improved scheme simplifies the dimensions of some transmission parameters by optimizing the tag structure and challenge generation mechanism. The specific differences are shown in <xref ref-type="table" rid="table-2">Table 2</xref>.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Comparison of transmitted data composition.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>Communication Scenario</th>
<th>Original Scheme</th>
<th>Improved Scheme</th>
</tr>
</thead>
<tbody>
<tr>
<td>DO<inline-formula id="ieqn-573"><mml:math id="mml-ieqn-573"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>CS</td>
<td><inline-formula id="ieqn-574"><mml:math id="mml-ieqn-574"><mml:mo stretchy="false">(</mml:mo><mml:mi>M</mml:mi><mml:mo>,</mml:mo><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mtext>Tag</mml:mtext><mml:mi>M</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-575"><mml:math id="mml-ieqn-575"><mml:mo stretchy="false">(</mml:mo><mml:mi>M</mml:mi><mml:mo>,</mml:mo><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mtext>Tag</mml:mtext><mml:mi>M</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>TPA<inline-formula id="ieqn-576"><mml:math id="mml-ieqn-576"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>CS</td>
<td><inline-formula id="ieqn-577"><mml:math id="mml-ieqn-577"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mtext>additional identity verification paramet</mml:mtext><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-578"><mml:math id="mml-ieqn-578"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mi>f</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>CS<inline-formula id="ieqn-579"><mml:math id="mml-ieqn-579"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>TPA</td>
<td><inline-formula id="ieqn-580"><mml:math id="mml-ieqn-580"><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B4;</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:mo>,</mml:mo><mml:mover><mml:mi>W</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mo>,</mml:mo><mml:mtext>auxiliary verification tags</mml:mtext><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-581"><mml:math id="mml-ieqn-581"><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B4;</mml:mi><mml:mo>,</mml:mo><mml:mi>&#x03BC;</mml:mi><mml:mo>,</mml:mo><mml:mover><mml:mi>W</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>,</mml:mo><mml:mi>T</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>TPA<inline-formula id="ieqn-582"><mml:math id="mml-ieqn-582"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>Blockchain</td>
<td><inline-formula id="ieqn-583"><mml:math id="mml-ieqn-583"><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B8;</mml:mi><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mtext>additional signature certificates</mml:mtext><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-584"><mml:math id="mml-ieqn-584"><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B8;</mml:mi><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s8_3_2">
<label>8.3.2</label>
<title>Quantitative Analysis of Communication Data Volume</title>
<p>Based on the experimental parameter settings (100 data blocks, 10 challenge blocks, 160-bit bilinear pairing group element length, 256-bit hash value length), the communication data volume of each scenario is quantitatively calculated. The results are shown in <xref ref-type="table" rid="table-3">Table 3</xref>. The data volume calculation rules are: group elements (<inline-formula id="ieqn-585"><mml:math id="mml-ieqn-585"><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">G</mml:mi></mml:mrow><mml:mi>T</mml:mi></mml:msub></mml:math></inline-formula>) are counted as 160 bits (20 bytes), hash values are counted as 256 bits (32 bytes), and integer parameters (<inline-formula id="ieqn-586"><mml:math id="mml-ieqn-586"><mml:mi>&#x03BC;</mml:mi></mml:math></inline-formula>, index <inline-formula id="ieqn-587"><mml:math id="mml-ieqn-587"><mml:mi>i</mml:mi></mml:math></inline-formula>) are counted as 64 bits (8 bytes).</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Quantitative comparison of communication data volume (unit: Bytes).</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>Communication Scenario</th>
<th>Original Scheme</th>
<th>Improved Scheme</th>
<th>Reduction Ratio</th>
</tr>
</thead>
<tbody>
<tr>
<td>DO<inline-formula id="ieqn-588"><mml:math id="mml-ieqn-588"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>CS</td>
<td>106,432</td>
<td>106,432</td>
<td>0%</td>
</tr>
<tr>
<td>TPA<inline-formula id="ieqn-589"><mml:math id="mml-ieqn-589"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>CS</td>
<td>176</td>
<td>144</td>
<td>18.18%</td>
</tr>
<tr>
<td>CS<inline-formula id="ieqn-590"><mml:math id="mml-ieqn-590"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>TPA</td>
<td>100</td>
<td>68</td>
<td>32.00%</td>
</tr>
<tr>
<td>TPA<inline-formula id="ieqn-591"><mml:math id="mml-ieqn-591"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>Blockchain</td>
<td>416</td>
<td>352</td>
<td>15.38%</td>
</tr>
<tr>
<td>Total Communication Volume</td>
<td>107,124</td>
<td>106,996</td>
<td>0.12%</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn id="table-3fn1" fn-type="other">
<p>Note: The DO<inline-formula id="ieqn-592"><mml:math id="mml-ieqn-592"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>CS phase accounts for more than 99% of the total communication volume. Therefore, although the reduction ratio of the total communication volume of the improved scheme is not significant, the overhead optimization effect in the core interaction phases (TPA<inline-formula id="ieqn-593"><mml:math id="mml-ieqn-593"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>CS, CS<inline-formula id="ieqn-594"><mml:math id="mml-ieqn-594"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>TPA) is obvious, which can significantly reduce network transmission pressure in high-frequency auditing scenarios.</p>
</fn>
</table-wrap-foot>
</table-wrap>
</sec>
</sec>
<sec id="s8_4">
<label>8.4</label>
<title>Comparative Analysis with State-of-the-Art Schemes</title>
<p>To further verify the superiority of the proposed enhanced scheme in terms of comprehensive performance and security, we select three representative blockchain-based data integrity auditing schemes in the current academic community for multi-dimensional comparison: Miao et al. (2024) (the original certificateless scheme optimized in this paper), Liu et al. (2025) (blockchain-based auditing scheme with enhanced tag mechanism based on bilinear pairing), and Wu et al. (2022) (lightweight on-chain-off-chain collaborative auditing protocol).</p>
<sec id="s8_4_1">
<label>8.4.1</label>
<title>Computational Overhead Comparison</title>
<p><xref ref-type="table" rid="table-4">Table 4</xref> presents the computational overhead comparison of each scheme under different data block scales when the number of challenge blocks is fixed at 25. This experiment focuses on the impact of data storage scale expansion on audit efficiency, which is consistent with the actual scenario of dynamic growth of data volume in multi-cloud storage environments.</p>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Computational overhead comparison under different data block scales.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>Scheme</th>
<th>100</th>
<th>200</th>
<th>250</th>
<th>500</th>
</tr>
</thead>
<tbody>
<tr>
<td>Wu et al. [<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
<td>31</td>
<td>42</td>
<td>54</td>
<td>114</td>
</tr>
<tr>
<td>Miao et al. [<xref ref-type="bibr" rid="ref-30">30</xref>]</td>
<td>20</td>
<td>22</td>
<td>26</td>
<td>27</td>
</tr>
<tr>
<td>Liu et al. [<xref ref-type="bibr" rid="ref-39">39</xref>]</td>
<td>26</td>
<td>42</td>
<td>58</td>
<td>100</td>
</tr>
<tr>
<td>Our Improved Scheme</td>
<td>25</td>
<td>117</td>
<td>102</td>
<td>118</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>For our improved scheme, when the number of data blocks is 100, the overhead is 25 ms, which is only 25% higher than that of the Miao et al. (2024) scheme, reflecting the controllable overhead growth brought by enhanced security (introducing the dynamic random parameter <inline-formula id="ieqn-595"><mml:math id="mml-ieqn-595"><mml:mi>T</mml:mi></mml:math></inline-formula>). When the number of data blocks increases to 200, the overhead increases to 117 ms in stages, then drops to 102 ms at 250 blocks, and stabilizes at 118 ms at 500 blocks, showing a &#x201C;first rise and then stabilize&#x201D; trend. This is because the scale effect of batch processing offsets part of the additional computational overhead, verifying the stability of the scheme in medium and large-scale data scenarios.</p>
<p><xref ref-type="table" rid="table-5">Table 5</xref> shows the computational overhead comparison of each scheme under different challenge block scales when the number of data blocks is fixed at 100. This experiment aims to simulate the scenario of dynamic adjustment of audit intensity and explore the efficiency performance of the scheme under low, medium, and high audit frequencies.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Computational overhead comparison under different challenge block scales.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>Scheme</th>
<th>10</th>
<th>25</th>
<th>50</th>
<th>100</th>
</tr>
</thead>
<tbody>
<tr>
<td>Wu et al. [<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
<td>26</td>
<td>31</td>
<td>20</td>
<td>21</td>
</tr>
<tr>
<td>Miao et al. [<xref ref-type="bibr" rid="ref-30">30</xref>]</td>
<td>19</td>
<td>20</td>
<td>26</td>
<td>30</td>
</tr>
<tr>
<td>Liu et al. [<xref ref-type="bibr" rid="ref-39">39</xref>]</td>
<td>21</td>
<td>26</td>
<td>25</td>
<td>19</td>
</tr>
<tr>
<td>Our Improved Scheme</td>
<td>19</td>
<td>25</td>
<td>19</td>
<td>53</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Our improved scheme shows a &#x201C;fluctuating balance&#x201D; characteristic: the overhead is 19 ms when there are 10 challenge blocks (the same as the Miao et al. (2024) scheme), increases to 25 ms when there are 25 blocks, drops to 19 ms when there are 50 blocks, and stabilizes at 53 ms when there are 100 blocks. Under the conventional audit intensity (25&#x2013;50 challenge blocks), the overhead of the improved scheme is in a reasonable range; under high audit intensity (100 blocks), although the overhead increases, it remains controllable, and is significantly better than the performance of the Liu et al. (2025) scheme with the same security intensity in large-scale data scenarios.</p>
</sec>
<sec id="s8_4_2">
<label>8.4.2</label>
<title>Communication Overhead Comparison</title>
<p>Communication overhead is quantified by the total data volume (Bytes) of the four core communication scenarios (DO<inline-formula id="ieqn-596"><mml:math id="mml-ieqn-596"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>CS, TPA<inline-formula id="ieqn-597"><mml:math id="mml-ieqn-597"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>CS, CS<inline-formula id="ieqn-598"><mml:math id="mml-ieqn-598"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>TPA, TPA<inline-formula id="ieqn-599"><mml:math id="mml-ieqn-599"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>Blockchain) in the auditing process, and the qualitative analysis focuses on the on-chain data volume (the key factor affecting blockchain transaction fees and latency). The comparison results are shown in <xref ref-type="table" rid="table-6">Table 6</xref>.</p>
<table-wrap id="table-6">
<label>Table 6</label>
<caption>
<title>Communication overhead comparison with state-of-the-art schemes (unit: Bytes).</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>Scheme</th>
<th>DO<inline-formula id="ieqn-600"><mml:math id="mml-ieqn-600"><mml:mo mathvariant="bold" stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>CS</th>
<th>TPA<inline-formula id="ieqn-601"><mml:math id="mml-ieqn-601"><mml:mo mathvariant="bold" stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>CS</th>
<th>CS<inline-formula id="ieqn-602"><mml:math id="mml-ieqn-602"><mml:mo mathvariant="bold" stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>TPA</th>
<th>TPA<inline-formula id="ieqn-603"><mml:math id="mml-ieqn-603"><mml:mo mathvariant="bold" stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>Blockchain</th>
</tr>
</thead>
<tbody>
<tr>
<td>Wu et al. [<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
<td>106,432</td>
<td>208</td>
<td>96</td>
<td>480</td>
</tr>
<tr>
<td>Miao et al. [<xref ref-type="bibr" rid="ref-30">30</xref>]</td>
<td>106,432</td>
<td>176</td>
<td>100</td>
<td>416</td>
</tr>
<tr>
<td>Liu et al. [<xref ref-type="bibr" rid="ref-39">39</xref>]</td>
<td>106,432</td>
<td>240</td>
<td>128</td>
<td>576</td>
</tr>
<tr>
<td>Our Improved Scheme</td>
<td>106,432</td>
<td>144</td>
<td>68</td>
<td>352</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>As shown in <xref ref-type="table" rid="table-6">Table 6</xref>, the communication overhead of the four schemes in the DO<inline-formula id="ieqn-604"><mml:math id="mml-ieqn-604"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>CS phase is consistent at 106432 Bytes, which is determined by the fixed process of data tag generation and upload and does not change with the optimization of the auditing mechanism. The improved scheme in this paper achieves the best performance in the TPA<inline-formula id="ieqn-605"><mml:math id="mml-ieqn-605"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>CS, CS<inline-formula id="ieqn-606"><mml:math id="mml-ieqn-606"><mml:mo stretchy="false">&#x2192;</mml:mo></mml:math></inline-formula>TPA, and on-chain interaction phases.</p>

</sec>
<sec id="s8_4_3">
<label>8.4.3</label>
<title>Challenge Phase Overhead Comparison</title>
<p><xref ref-type="table" rid="table-7">Table 7</xref> details the differences between the original scheme and the improved scheme in the challenge phase in terms of the number of computational operations and communication data volume.</p>
<table-wrap id="table-7">
<label>Table 7</label>
<caption>
<title>Challenge phase overhead comparison.</title>
</caption>
<table>
<colgroup>
<col align="center" width="45mm"/>
<col align="center" width="55mm"/>
<col align="center" width="55mm"/> </colgroup>
<thead>
<tr>
<th>Comparison</th>
<th>Original Scheme</th>
<th>Improved Scheme</th>
</tr>
</thead>
<tbody>
<tr>
<td>Computational Operations</td>
<td>Hash Operation: 6 times Pseudorandom Function Call: 3</td>
<td>Hash Operation: 4 times Pseudorandom Function Call: 2</td>
</tr>
<tr>
<td>Communication Data Volume</td>
<td>Total: 176 Bytes Effective Data Ratio: 81.82%</td>
<td>Total: 144 Bytes Effective Data Ratio: 100%</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
</sec>
<sec id="s9">
<label>9</label>
<title>Conclusion</title>
<p>This paper focuses on the core issue of insufficient tag security in cloud storage data integrity auditing. Targeting the tag forgery vulnerability caused by the lack of dynamic random parameters in the hash function input of the blockchain-based certificateless auditing scheme proposed by Miao et al., a systematic improvement study is conducted. Firstly, by in-depth analyzing the tag generation mechanism of the original scheme, multiple attack paths such as tag forgery, data tampering, illegal insertion, and deletion induced by static hash inputs are clarified. Secondly, a lightweight enhancement scheme is proposed, which incorporates the dynamic random parameter <inline-formula id="ieqn-607"><mml:math id="mml-ieqn-607"><mml:mi>T</mml:mi></mml:math></inline-formula> into the input of the hash function <inline-formula id="ieqn-608"><mml:math id="mml-ieqn-608"><mml:msub><mml:mi>H</mml:mi><mml:mn>3</mml:mn></mml:msub></mml:math></inline-formula>, making tag generation depend on both static attributes and dynamic factors, thereby fundamentally blocking the possibility of attackers precomputing and forging tags. Subsequently, under the Computational Diffie-Hellman (CDH) and Discrete Logarithm (DL) hardness assumptions, the scheme&#x2019;s resistance against Type I, Type II, and Type III adversaries is verified through formal proofs, ensuring core security properties such as tag unforgeability, collusion resistance, and data privacy protection. Finally, experimental performance analysis confirms that the improved scheme only introduces negligible computational overhead, and the efficiency of the proof generation and verification phases is improved compared with the original scheme, maintaining good practicality.</p>
<p>The core contribution of this paper lies in achieving a significant enhancement of security with minimal modifications. In the blockchain decentralized auditing scenario, the scheme achieves dynamic unforgeability of tags with minimal modifications (only one additional hash operation), while maintaining full compatibility with blockchain smart contracts. This avoids the sharp increase in on-chain computing overhead caused by substantial protocol modifications, and effectively solves the contradiction between &#x201C;security improvement and efficiency loss&#x201D; of existing randomization methods in blockchain scenarios. It not only retains the key management advantages of certificateless cryptography and the decentralized transparency characteristics of blockchain from the original scheme but also effectively compensates for the security flaws in the tag generation phase, providing a data integrity auditing solution that balances high security and practicality for multi-cloud storage environments.</p>
<p>Future research can be further expanded in three aspects: first, exploring the lightweight optimization of the scheme in resource-constrained scenarios such as edge computing and IoT terminals to further reduce the local computational overhead of tag generation; second, integrating zero-knowledge proof technology to enhance data privacy protection during the auditing process, achieving the dual goals of verifiable audit results and zero leakage of data content; third, expanding the cross-chain auditing capability of the scheme to adapt to the complex multi-cloud storage architecture with heterogeneous blockchains, and improving the compatibility and scalability of the scheme in large-scale distributed storage environments.</p>
</sec>
</body>
<back>
<ack>
<p>Not applicable.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>This research was funded by Engineering University of PAP&#x2019;s Funding for Education and Teaching Program Grant (No. Wjx2025069), Engineering University of PAP&#x2019;s Funding for Basic and Cutting-Edge Innovation Grant (No. Wjy202520) and Engineering University of PAP&#x2019;s The Second Batch of Scientific Research and Innovation Teams. This work is also supported by Stability Program of National Key Laboratory of Security Communication (WD202513).</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>Conceptualization: Chao Zhang and Xu An Wang; Methodology: Chao Zhang and Weiwei Jiang; Software: Weidong Zhong; Validation: Ziteng Wang and Miao Tian; Formal analysis: Jianhong Ling; Investigation: Chao Zhang; Resources: Hangjiang Du; Data curation: Chao Zhang; Writing&#x2014;original draft preparation: Chao Zhang; Writing&#x2014;review and editing: Chao Zhang; Visualization: Chao Zhang; Supervision: Yunhui Duan; Project administration: Chao Zhang; Funding acquisition: Weidong Zhong. All authors reviewed and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>Data supporting the findings of <xref ref-type="sec" rid="s8">Section 8</xref> are available from the corresponding author, Weiwei Jiang (Email: jww@bupt.edu.cn), upon reasonable request.</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>This study did not involve any human or animal subjects, and therefore, ethical approval was not required.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest: </title>
<p>The authors declare no conflicts of interest.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Mell</surname> <given-names>P</given-names></string-name>, <string-name><surname>Grance</surname> <given-names>T</given-names></string-name></person-group>. <article-title>The NIST definition of cloud computing</article-title>. <year>2011 [cited 2026 Jan 1]</year>. Available from: <ext-link ext-link-type="uri" xlink:href="https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=909616">https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id&#x003D;909616</ext-link>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Armbrust</surname> <given-names>M</given-names></string-name>, <string-name><surname>Fox</surname> <given-names>A</given-names></string-name>, <string-name><surname>Griffith</surname> <given-names>R</given-names></string-name>, <string-name><surname>Joseph</surname> <given-names>AD</given-names></string-name>, <string-name><surname>Katz</surname> <given-names>R</given-names></string-name>, <string-name><surname>Konwinski</surname> <given-names>A</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>A view of cloud computing</article-title>. <source>Commun ACM</source>. <year>2010</year>;<volume>53</volume>(<issue>4</issue>):<fpage>50</fpage>&#x2013;<lpage>8</lpage>. doi:<pub-id pub-id-type="doi">10.1145/1721654.1721672</pub-id>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hashizume</surname> <given-names>K</given-names></string-name>, <string-name><surname>Rosado</surname> <given-names>DG</given-names></string-name>, <string-name><surname>Fern&#x00E1;ndez-Medina</surname> <given-names>E</given-names></string-name>, <string-name><surname>Fernandez</surname> <given-names>EB</given-names></string-name></person-group>. <article-title>An analysis of security issues for cloud computing</article-title>. <source>J Internet Serv Appl</source>. <year>2013</year>;<volume>4</volume>(<issue>1</issue>):<fpage>5</fpage>. doi:<pub-id pub-id-type="doi">10.1186/1869-0238-4-5</pub-id>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Ateniese</surname> <given-names>G</given-names></string-name>, <string-name><surname>Burns</surname> <given-names>R</given-names></string-name>, <string-name><surname>Curtmola</surname> <given-names>R</given-names></string-name>, <string-name><surname>Herring</surname> <given-names>J</given-names></string-name>, <string-name><surname>Kissner</surname> <given-names>L</given-names></string-name>, <string-name><surname>Peterson</surname> <given-names>Z</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Provable data possession at untrusted stores</article-title>. In: <conf-name>Proceedings of the 14th ACM Conference on Computer and Communications Security; 2007 Oct 29&#x2013;Nov 2</conf-name>; <publisher-loc>Alexandria, VA, USA</publisher-loc>. p. <fpage>598</fpage>&#x2013;<lpage>609</lpage>. doi:<pub-id pub-id-type="doi">10.1145/1315245.1315318</pub-id>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Juels</surname> <given-names>A</given-names></string-name>, <string-name><surname>Kaliski</surname> <given-names>BS</given-names> <suffix>Jr</suffix></string-name></person-group>. <article-title>Pors: proofs of retrievability for large files</article-title>. In: <conf-name>Proceedings of the 14th ACM Conference on Computer and Communications Security; 2007 Oct 29&#x2013;Nov 2</conf-name>; <publisher-loc>Alexandria, VA, USA</publisher-loc>. p. <fpage>584</fpage>&#x2013;<lpage>97</lpage>. doi:<pub-id pub-id-type="doi">10.1145/1315245.1315317</pub-id>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shacham</surname> <given-names>H</given-names></string-name>, <string-name><surname>Waters</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Compact proofs of retrievability</article-title>. <source>J Cryptol</source>. <year>2013</year>;<volume>26</volume>(<issue>3</issue>):<fpage>442</fpage>&#x2013;<lpage>83</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s00145-012-9129-2</pub-id>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>C</given-names></string-name>, <string-name><surname>Ren</surname> <given-names>K</given-names></string-name>, <string-name><surname>Lou</surname> <given-names>W</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Enabling public auditability and data dynamics for storage security in cloud computing</article-title>. <source>IEEE Trans Parallel Distrib Syst</source>. <year>2011</year>;<volume>22</volume>(<issue>5</issue>):<fpage>847</fpage>&#x2013;<lpage>59</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tpds.2010.183</pub-id>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Yuan</surname> <given-names>J</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Efficient public integrity checking for cloud data sharing with multi-user modification</article-title>. In: <conf-name>Proceedings of the IEEE INFOCOM 2014&#x2014;IEEE Conference on Computer Communications; 2014 Apr 27&#x2013;May 2</conf-name>; <publisher-loc>Toronto, ON, Canada</publisher-loc>. p. <fpage>2121</fpage>&#x2013;<lpage>9</lpage>. doi:<pub-id pub-id-type="doi">10.1109/infocom.2014.6848154</pub-id>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>C</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Ren</surname> <given-names>K</given-names></string-name>, <string-name><surname>Cao</surname> <given-names>N</given-names></string-name>, <string-name><surname>Lou</surname> <given-names>W</given-names></string-name></person-group>. <article-title>Toward secure and dependable storage services in cloud computing</article-title>. <source>IEEE Trans Serv Comput</source>. <year>2012</year>;<volume>5</volume>(<issue>2</issue>):<fpage>220</fpage>&#x2013;<lpage>32</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tsc.2011.24</pub-id>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Ali</surname> <given-names>H</given-names></string-name>, <string-name><surname>Abidin</surname> <given-names>S</given-names></string-name>, <string-name><surname>Alam</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Auditing of outsourced data in cloud computing: an overview</article-title>. In: <conf-name>Proceedings of the 2024 11th International Conference on Computing for Sustainable Global Development (INDIACom); 2024 Feb 28&#x2013;Mar 1</conf-name>; <publisher-loc>New Delhi, India</publisher-loc>. p. <fpage>111</fpage>&#x2013;<lpage>7</lpage>. doi:<pub-id pub-id-type="doi">10.23919/indiacom61295.2024.10498177</pub-id>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>C</given-names></string-name>, <string-name><surname>Chow</surname> <given-names>SSM</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Ren</surname> <given-names>K</given-names></string-name>, <string-name><surname>Lou</surname> <given-names>W</given-names></string-name></person-group>. <article-title>Privacy-preserving public auditing for secure cloud storage</article-title>. <source>IEEE Trans Comput</source>. <year>2013</year>;<volume>62</volume>(<issue>2</issue>):<fpage>362</fpage>&#x2013;<lpage>75</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tc.2011.245</pub-id>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yoosuf</surname> <given-names>MS</given-names></string-name>, <string-name><surname>Anitha</surname> <given-names>R</given-names></string-name></person-group>. <article-title>LDuAP: lightweight dual auditing protocol to verify data integrity in cloud storage servers</article-title>. <source>J Ambient Intell Humaniz Comput</source>. <year>2022</year>;<volume>13</volume>(<issue>8</issue>):<fpage>3787</fpage>&#x2013;<lpage>805</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s12652-021-03321-7</pub-id>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zheng</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Xie</surname> <given-names>S</given-names></string-name>, <string-name><surname>Dai</surname> <given-names>HN</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>X</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Blockchain challenges and opportunities: a survey</article-title>. <source>Int J Web Grid Serv</source>. <year>2018</year>;<volume>14</volume>(<issue>4</issue>):<fpage>352</fpage>. doi:<pub-id pub-id-type="doi">10.1504/ijwgs.2018.095647</pub-id>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yue</surname> <given-names>D</given-names></string-name>, <string-name><surname>Li</surname> <given-names>R</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Tian</surname> <given-names>W</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Blockchain-based verification framework for data integrity in edge-cloud storage</article-title>. <source>J Parallel Distrib Comput</source>. <year>2020</year>;<volume>146</volume>(<issue>22</issue>):<fpage>1</fpage>&#x2013;<lpage>14</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jpdc.2020.06.007</pub-id>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Huang</surname> <given-names>P</given-names></string-name>, <string-name><surname>Fan</surname> <given-names>K</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>K</given-names></string-name>, <string-name><surname>Li</surname> <given-names>H</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>A collaborative auditing blockchain for trustworthy data integrity in cloud storage system</article-title>. <source>IEEE Access</source>. <year>2020</year>;<volume>8</volume>:<fpage>94780</fpage>&#x2013;<lpage>94</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2020.2993606</pub-id>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Miao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>YingMiao</surname> <given-names>QH</given-names></string-name>, <string-name><surname>Qiong Huang</surname> <given-names>MX</given-names></string-name>, <string-name><surname>Meiyan Xiao</surname> <given-names>WS</given-names></string-name></person-group>. <article-title>IPAPA: incentive public auditing scheme against procrastinating auditor</article-title>. <source>J Internet Technol</source>. <year>2022</year>;<volume>23</volume>(<issue>7</issue>):<fpage>1505</fpage>&#x2013;<lpage>17</lpage>. doi:<pub-id pub-id-type="doi">10.53106/160792642022122307006</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Feng</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Ren</surname> <given-names>L</given-names></string-name>, <string-name><surname>Zheng</surname> <given-names>W</given-names></string-name></person-group>. <article-title>Data integrity audit scheme based on blockchain expansion technology</article-title>. <source>IEEE Access</source>. <year>2022</year>;<volume>10</volume>:<fpage>55900</fpage>&#x2013;<lpage>7</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2022.3176754</pub-id>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Cui</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zhong</surname> <given-names>H</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Gu</surname> <given-names>C</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Efficient blockchain-based data integrity auditing for multi-copy in decentralized storage</article-title>. <source>IEEE Trans Parallel Distrib Syst</source>. <year>2023</year>;<volume>34</volume>(<issue>12</issue>):<fpage>3162</fpage>&#x2013;<lpage>73</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tpds.2023.3323155</pub-id>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Zhu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Ahn</surname> <given-names>GJ</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>H</given-names></string-name>, <string-name><surname>Yau</surname> <given-names>SS</given-names></string-name></person-group>. <article-title>Dynamic audit services for integrity verification of outsourced storages in clouds</article-title>. In: <conf-name>Proceedings of the 2011 ACM Symposium on Applied Computing; 2011 Mar 21&#x2013;24</conf-name>; <publisher-loc>TaiChung, Taiwan</publisher-loc>. p. <fpage>1550</fpage>&#x2013;<lpage>7</lpage>. doi:<pub-id pub-id-type="doi">10.1145/1982185.1982514</pub-id>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yang</surname> <given-names>K</given-names></string-name>, <string-name><surname>Jia</surname> <given-names>X</given-names></string-name></person-group>. <article-title>An efficient and secure dynamic auditing protocol for data storage in cloud computing</article-title>. <source>IEEE Trans Parallel Distrib Syst</source>. <year>2013</year>;<volume>24</volume>(<issue>9</issue>):<fpage>1717</fpage>&#x2013;<lpage>26</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tpds.2012.278</pub-id>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhou</surname> <given-names>C</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>L</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Lattice-based provable data possession in the standard model for cloud-based smart grid data management systems</article-title>. <source>Int J Distrib Sens Netw</source>. <year>2022</year>;<volume>18</volume>(<issue>4</issue>):<fpage>155013292210929</fpage>. doi:<pub-id pub-id-type="doi">10.1177/15501329221092940</pub-id>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Tan</surname> <given-names>C</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Provable data possession of resource-constrained mobile devices in cloud computing</article-title>. <source>J Netw</source>. <year>2011</year>;<volume>6</volume>(<issue>7</issue>):<fpage>1033</fpage>&#x2013;<lpage>40</lpage>. doi:<pub-id pub-id-type="doi">10.4304/jnw.6.7.1033-1040</pub-id>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Yan</surname> <given-names>H</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Identity-based privacy preserving remote data integrity checking for cloud storage</article-title>. <source>IEEE Syst J</source>. <year>2021</year>;<volume>15</volume>(<issue>1</issue>):<fpage>577</fpage>&#x2013;<lpage>85</lpage>. doi:<pub-id pub-id-type="doi">10.1109/jsyst.2020.2978146</pub-id>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yuan</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>W</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Z</given-names></string-name></person-group>. <article-title>Identity-based public data integrity verification scheme in cloud storage system via blockchain</article-title>. <source>J Supercomput</source>. <year>2022</year>;<volume>78</volume>(<issue>6</issue>):<fpage>8509</fpage>&#x2013;<lpage>30</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s11227-021-04193-6</pub-id>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Jiang</surname> <given-names>G</given-names></string-name>, <string-name><surname>Srikanthan</surname> <given-names>T</given-names></string-name></person-group>. <article-title>Blockchain-based public auditing for big data in cloud storage</article-title>. <source>Inf Process Manag</source>. <year>2020</year>;<volume>57</volume>(<issue>6</issue>):<fpage>102382</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.ipm.2020.102382</pub-id>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Xu</surname> <given-names>S</given-names></string-name>, <string-name><surname>Cai</surname> <given-names>X</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Ren</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>L</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>H</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>zkrpChain: privacy-preserving data auditing for consortium blockchains based on zero-knowledge range proofs</article-title>. In: <conf-name>Proceedings of the 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom; 2020 Dec 29&#x2013;2021 Jan 1)</conf-name>; <publisher-loc>Guangzhou, China</publisher-loc>. p. <fpage>656</fpage>&#x2013;<lpage>63</lpage>. doi:<pub-id pub-id-type="doi">10.1109/trustcom50675.2020.00092</pub-id>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Shao</surname> <given-names>B</given-names></string-name>, <string-name><surname>Ji</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Bian</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Efficient identity-based provable multi-copy data possession in multi-cloud storage, revisited</article-title>. <source>IEEE Commun Lett</source>. <year>2020</year>;<volume>24</volume>(<issue>12</issue>):<fpage>2723</fpage>&#x2013;<lpage>7</lpage>. doi:<pub-id pub-id-type="doi">10.1109/lcomm.2020.3013280</pub-id>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>T</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Audit as you go: a smart contract-based outsourced data integrity auditing scheme for multiauditor scenarios with one person, one vote</article-title>. <source>Secur Commun Netw</source>. <year>2022</year>;<volume>2022</volume>(<issue>3</issue>):<fpage>8783952</fpage>&#x2013;<lpage>13</lpage>. doi:<pub-id pub-id-type="doi">10.1155/2022/8783952</pub-id>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tahir</surname> <given-names>M</given-names></string-name>, <string-name><surname>Sardaraz</surname> <given-names>M</given-names></string-name>, <string-name><surname>Muhammad</surname> <given-names>S</given-names></string-name>, <string-name><surname>Saud Khan</surname> <given-names>M</given-names></string-name></person-group>. <article-title>A lightweight authentication and authorization framework for blockchain-enabled IoT network in health-informatics</article-title>. <source>Sustainability</source>. <year>2020</year>;<volume>12</volume>(<issue>17</issue>):<fpage>6960</fpage>. doi:<pub-id pub-id-type="doi">10.3390/su12176960</pub-id>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Miao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Miao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Miao</surname> <given-names>X</given-names></string-name></person-group>. <article-title>Blockchain-based transparent and certificateless data integrity auditing for cloud storage</article-title>. <source>Concurr Comput</source>. <year>2024</year>;<volume>36</volume>(<issue>27</issue>):<fpage>e8285</fpage>. doi:<pub-id pub-id-type="doi">10.1002/cpe.8285</pub-id>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Nweje</surname> <given-names>U</given-names></string-name></person-group>. <article-title>Blockchain technology for secure data integrity and transparent audit trails in cybersecurity</article-title>. <source>Int J Res Publ Rev</source>. <year>2024</year>;<volume>5</volume>(<issue>12</issue>):<fpage>4902</fpage>&#x2013;<lpage>16</lpage>. doi:<pub-id pub-id-type="doi">10.55248/gengpi.5.1224.0211</pub-id>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>S</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>C</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Du</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Blockchain-based transparent integrity auditing and encrypted deduplication for cloud storage</article-title>. <source>IEEE Trans Serv Comput</source>. <year>2022</year>;<volume>16</volume>(<issue>1</issue>):<fpage>134</fpage>&#x2013;<lpage>46</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tsc.2022.3144430</pub-id>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhu</surname> <given-names>C</given-names></string-name>, <string-name><surname>Lu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Xia</surname> <given-names>N</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Sun</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>A lightweight blockchain-assisted certificateless cloud data integrity auditing scheme without third-party auditor</article-title>. <source>IEEE Trans Inform Forensic Secur</source>. <year>2026</year>;<volume>21</volume>:<fpage>976</fpage>&#x2013;<lpage>91</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tifs.2026.3652010</pub-id>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>L</given-names></string-name>, <string-name><surname>Guan</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Enabling integrity and compliance auditing in blockchain-based GDPR-compliant data management</article-title>. <source>IEEE Internet Things J</source>. <year>2023</year>;<volume>10</volume>(<issue>23</issue>):<fpage>20955</fpage>&#x2013;<lpage>68</lpage>. doi:<pub-id pub-id-type="doi">10.1109/jiot.2023.3285211</pub-id>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shen</surname> <given-names>W</given-names></string-name>, <string-name><surname>Gai</surname> <given-names>C</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Su</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Keyword-based remote data integrity auditing supporting full data dynamics</article-title>. <source>IEEE Trans Serv Comput</source>. <year>2024</year>;<volume>17</volume>(<issue>5</issue>):<fpage>2516</fpage>&#x2013;<lpage>29</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tsc.2023.3339521</pub-id>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tu</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Du</surname> <given-names>W</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Lv</surname> <given-names>M</given-names></string-name></person-group>. <article-title>An improved multi-copy cloud data auditing scheme and its application</article-title>. <source>J King Saud Univ Comput Inf Sci</source>. <year>2023</year>;<volume>35</volume>(<issue>3</issue>):<fpage>120</fpage>&#x2013;<lpage>30</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jksuci.2023.01.021</pub-id>.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kumar</surname> <given-names>RP</given-names></string-name>, <string-name><surname>Bandanadam</surname> <given-names>SR</given-names></string-name></person-group>. <article-title>Block chain-based decentralized public auditing for cloud storage with improved EIGAMAL encryption model</article-title>. <source>Int J Inf Technol</source>. <year>2024</year>;<volume>16</volume>(<issue>2</issue>):<fpage>697</fpage>&#x2013;<lpage>711</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s41870-023-01599-8</pub-id>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>L</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>M</given-names></string-name>, <string-name><surname>Jia</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Guan</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>Z</given-names></string-name></person-group>. <article-title>SStore: an efficient and secure provable data auditing platform for cloud</article-title>. <source>IEEE Trans Inform Forensic Secur</source>. <year>2024</year>;<volume>19</volume>:<fpage>4572</fpage>&#x2013;<lpage>84</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tifs.2024.3383772</pub-id>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Blockchain-based integrity auditing for shared data in cloud storage with file prediction</article-title>. <source>Comput Netw</source>. <year>2023</year>;<volume>236</volume>:<fpage>110040</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.comnet.2023.110040</pub-id>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Qian</surname> <given-names>S</given-names></string-name>, <string-name><surname>Cui</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zhong</surname> <given-names>H</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>F</given-names></string-name>, <string-name><surname>He</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Blockchain-based privacy-preserving deduplication and integrity auditing in cloud storage</article-title>. <source>IEEE Trans Comput</source>. <year>2025</year>;<volume>74</volume>(<issue>5</issue>):<fpage>1717</fpage>&#x2013;<lpage>29</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tc.2025.3540670</pub-id>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhou</surname> <given-names>H</given-names></string-name>, <string-name><surname>Shen</surname> <given-names>W</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Certificate-based multi-copy cloud storage auditing supporting data dynamics</article-title>. <source>Comput Secur</source>. <year>2025</year>;<volume>148</volume>(<issue>3</issue>):<fpage>104096</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2024.104096</pub-id>.</mixed-citation></ref>
<ref id="ref-42"><label>[42]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Miao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Gai</surname> <given-names>K</given-names></string-name>, <string-name><surname>Zhu</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Blockchain-assisted multi-keyword searchable provable data possession for cloud storage</article-title>. <source>Sci China Inf Sci</source>. <year>2026</year>;<volume>69</volume>(<issue>3</issue>):<fpage>132101</fpage>. doi:<pub-id pub-id-type="doi">10.1007/s11432-024-4409-6</pub-id>.</mixed-citation></ref>
<ref id="ref-43"><label>[43]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Vijayakumar</surname> <given-names>D</given-names></string-name>, <string-name><surname>Srinivasagan</surname> <given-names>KG</given-names></string-name>, <string-name><surname>Vivekrabinson</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Enhancing cloud storage security through blockchain-enabled data deduplication and auditing with a fair payment</article-title>. <source>Peer Peer Netw Appl</source>. <year>2025</year>;<volume>18</volume>(<issue>3</issue>):<fpage>147</fpage>. doi:<pub-id pub-id-type="doi">10.1007/s12083-025-01970-5</pub-id>.</mixed-citation></ref>
<ref id="ref-44"><label>[44]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xu</surname> <given-names>C</given-names></string-name>, <string-name><surname>Feng</surname> <given-names>L</given-names></string-name>, <string-name><surname>Jing</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>F</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>PATD: privacy-preserving auditing and transparent deduplication in UAV cloud storage</article-title>. <source>Comput Secur</source>. <year>2026</year>;<volume>166</volume>(<issue>3</issue>):<fpage>104905</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2026.104905</pub-id>.</mixed-citation></ref>
</ref-list>
</back></article>