<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">IASC</journal-id>
<journal-id journal-id-type="nlm-ta">IASC</journal-id>
<journal-id journal-id-type="publisher-id">IASC</journal-id>
<journal-title-group>
<journal-title>Intelligent Automation &#x0026; Soft Computing</journal-title>
</journal-title-group>
<issn pub-type="epub">2326-005X</issn>
<issn pub-type="ppub">1079-8587</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">29657</article-id>
<article-id pub-id-type="doi">10.32604/iasc.2022.029657</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Consensus Mechanism of Blockchain Based on PoR with Data Deduplication</article-title><alt-title alt-title-type="left-running-head">Consensus Mechanism of Blockchain Based on PoR with Data Deduplication</alt-title><alt-title alt-title-type="right-running-head">Consensus Mechanism of Blockchain Based on PoR with Data Deduplication</alt-title>
</title-group>
<contrib-group content-type="authors">
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Zhou</surname><given-names>Wei</given-names></name>
<xref ref-type="aff" rid="aff-1">1</xref>
</contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Wang</surname><given-names>Hao</given-names></name>
<xref ref-type="aff" rid="aff-2">2</xref>
</contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Mohiuddin</surname><given-names>Ghulam</given-names></name>
<xref ref-type="aff" rid="aff-3">3</xref>
</contrib>
<contrib id="author-4" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Chen</surname><given-names>Dan</given-names></name>
<xref ref-type="aff" rid="aff-4">4</xref><email>chen8891dan@163.com</email>
</contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western"><surname>Ren</surname><given-names>Yongjun</given-names></name>
<xref ref-type="aff" rid="aff-1">1</xref>
</contrib>
<aff id="aff-1"><label>1</label><institution>Engineering Research Center of Digital Forensics of Ministry of Education, School of Computer Science, Nanjing University of Information Science &#x0026; Technology</institution>, <addr-line>Nanjing, 210044</addr-line>, <country>China</country></aff>
<aff id="aff-2"><label>2</label><institution>Shenzhen Research Institute, Nanjing University of Aeronautics and Astronautics</institution>, <addr-line>Shenzhen, 518000</addr-line>, <country>China</country></aff>
<aff id="aff-3"><label>3</label><institution>Department of Cyber Security at VaporVM</institution>, <addr-line>Abu Dhabi, 999041</addr-line>, <country>United Arab Emirates</country></aff>
<aff id="aff-4"><label>4</label><institution>School of Computer Engineering, Jiangsu University of Technology</institution>, <addr-line>Changzhou, 213001</addr-line>, <country>China</country></aff>
</contrib-group><author-notes><corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Dan Chen. Email: <email>chen8891dan@163.com</email></corresp></author-notes>
<pub-date pub-type="epub" date-type="pub" iso-8601-date="2022-05-23"><day>23</day>
<month>05</month>
<year>2022</year></pub-date>
<volume>34</volume>
<issue>3</issue>
<fpage>1473</fpage>
<lpage>1488</lpage>
<history>
<date date-type="received"><day>08</day><month>3</month><year>2022</year></date>
<date date-type="accepted"><day>14</day><month>4</month><year>2022</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2022 Zhou et al.</copyright-statement>
<copyright-year>2022</copyright-year>
<copyright-holder>Zhou et al.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_IASC_29657.pdf"></self-uri>
<abstract>
<p>As the basis of cloud computing, distributed storage technology mainly studies how data centers store, organize and manage data. Blockchain has become the most secure solution for cloud storage due to its decentralization and immutability. Consensus mechanism is one of the core technologies of blockchain, which affects the transaction processing capability, security and scalability of blockchain. The current mainstream consensus algorithms such as Proof of Work, Proof of Stake, and Delegated Proof of Stake all have the problem of wasting resources. And with the explosive growth of data, cloud storage nodes store a large amount of redundant data, which inevitably increases storage overhead and computing cost. To this end, we propose to use the Proof of Retrievability with deduplication algorithm as the consensus mechanism of the blockchain system and design a blockchain consensus protocol suitable for distributed storage. First, the data integrity verification protocol in the scheme guarantees that storage nodes correctly store the data they promise to store. Second, the deduplication algorithm in the protocol can optimize data auditing, greatly reduce the need for data storage space, and improve the scalability of data transmission. In addition, the scheme uses ring signatures in the audit process to ensure user anonymity and data unlinkability, while providing highly reliable data storage, and ensuring data storage security through blockchain. Finally, we demonstrate the security of the proposed scheme and evaluate its performance. The evaluation results show that our scheme is efficient and scalable.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Integrity verification</kwd>
<kwd>consensus</kwd>
<kwd>blockchain</kwd>
<kwd>deduplication</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>With the emergence and gradual maturity of technologies such as 5G, cloud computing, and artificial intelligence, the future will be an era of data explosion. With the emergence of massive data, how to store this data and how to use it rationally has become a problem that most companies and even experts think about. Compared with traditional storage networks, distributed storage has more advantages. The distributed system structure combines a large number of ordinary servers into a whole and uses server positioning to store information [<xref ref-type="bibr" rid="ref-1">1</xref>]. It has the advantages of high reliability, data consistency, and high performance. However, in the face of the explosive growth of massive data, it is necessary to solve the problems of data evolution from single internal small data to multiple dynamic big data, real-time data collection, and excessive data redundancy. Distributed storage will face many challenges in the future.</p>
<p>Peer-to-peer (P2P) architecture embodies a key concept of Internet technology, and one of its important goals is to allow all nodes on the network to provide resources, including bandwidth, storage space, and computing power [<xref ref-type="bibr" rid="ref-2">2</xref>]. This technology has been extensively researched, and users can use resources more efficiently and access data more quickly. The distributed nature of P2P network also increases failure-proof robustness by replicating data across multiple nodes. And in a general P2P network, nodes do not need to rely on a central index server to discover data, so the system will not have a single point of collapse. In fact, hundreds of well-known projects with huge user bases have already formed considerable momentum, such as Ethereum, filecoin, Fabric, etc.</p>
<p>Research on consensus algorithms in P2P network has started a long time ago. Bitcoin&#x2019;s Proof of Work (POW) is an innovation of great significance. It cleverly integrates the functions of Bitcoin&#x2019;s issuance, transaction payment and data verification through computing power competition, crossing the gap of byzantine fault tolerance in distributed systems. However, it cannot meet the needs of high throughput and timely processing of general applications. PeerCoin (PPC) first uses Proof of Stake (POS) to replace the proof of work based on hashing power in PoW, and the node with the highest stake in the system rather than the highest computing power obtains the block accounting right [<xref ref-type="bibr" rid="ref-3">3</xref>]. However, since the maximum rights and interests of nodes cannot be legally guaranteed, the PoS consensus mechanism still has the possibility of centralization. Delegated Proof of Stake (DPOS) is a democratic version of the POS consensus algorithm, and token holders can participate in voting [<xref ref-type="bibr" rid="ref-4">4</xref>]. Because they do not require high computing power, they are more scalable. However, the DPoS mechanism still needs to determine the accounting rights through voting and other processes, which will have a certain impact on the throughput. How to choose or design a suitable consensus algorithm for a specific business scenario is a major problem in the implementation of blockchain applications at this stage [<xref ref-type="bibr" rid="ref-5">5</xref>].</p>
<p>The current distributed storage solution cannot meet the persistent storage market demand [<xref ref-type="bibr" rid="ref-6">6</xref>]. First of all, if no other node pulls data, only the local machine has an orphaned copy of the data. Once the local machine fail, the data will be lost, and there is no data integrity monitoring and automatic data reconstruction. Second, the existing solution lacks a strong economic model, so it cannot use a large-capacity database as its service model [<xref ref-type="bibr" rid="ref-7">7</xref>]. A reliable economic model requires that at least a majority of nodes provide value to other nodes and volunteer to support the system. Therefore, an incentive mechanism is needed for participants to voluntarily provide and use resources.</p>
<p>Our design combines data integrity verification with the blockchain technology. Facing the persistent storage market demand, it provides a powerful economic model. As an incentive layer in distributed storage, it can better realize data storage and transactions. The main contributions are as follows:<list list-type="simple"><list-item><label>1)</label>
<p>We use Proof of Retrievability (POR) with the deduplication algorithm as a new consensus mechanism and design a safe and efficient distributed storage system based on blockchain. The nodes on the blockchain form a collaborative network, and the nodes can jointly maintain data verification records.</p></list-item><list-item><label>2)</label>
<p>We use ring signature technology in the consensus protocol to achieve data owner anonymity and file unlinkability by introducing more users in the file signature process and protect user outsourced data from privacy leaks and brute force attacks.</p></list-item><list-item><label>3)</label>
<p>We add adeduplication algorithm in the verification process to optimize the data audit and storage space of storage nodes, save network bandwidth for data transmission, and improve the scalability of the solution.</p></list-item></list></p>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Work</title>
<p>There has been a lot of research on data integrity verification and blockchain-based consensus mechanisms.</p>
<sec id="s2_1">
<label>2.1</label>
<title>Integrity Verification</title>
<p>In 2007, Ateniese et al. [<xref ref-type="bibr" rid="ref-8">8</xref>] first proposed a Provable Data Possession (PDP) protocol that can verify the integrity of cloud data. This scheme uses a probabilistic strategy to complete integrity verification, while using RSA Homomorphically Verifiable Tags (HVTs) to aggregate evidence into a small value. This not only reduces the computing overhead of cloud storage, but also greatly reduces the communication overhead of the protocol due to the characteristics of signature aggregation. In 2007, Juels et al. [<xref ref-type="bibr" rid="ref-9">9</xref>] proposed another classic verification scheme, POR scheme. The scheme effectively identifies the damage of the outsourcing documents by implanting some &#x201C;sentinel&#x201D; checking data blocks in the outsourcing documents and uses the Reed-Solomon error correction code to perform fault-tolerant preprocessing on the outsourced files, so as to restore the damaged data files. However, in this scheme, the data owner needs to consume huge computational cost for erroneous data recovery and original data encryption. In 2013, Yang et al. [<xref ref-type="bibr" rid="ref-10">10</xref>] proposed a cloud data privacy protection protocol, which can better solve the security risk of data confidentiality in the public audit process in Compact Proofs of Retrievability (CPOR). The protocol improves the overall performance of the scheme by reducing the number of data tags by using data fragmentation technology and HVT. In 2017, Hiremath et al. [<xref ref-type="bibr" rid="ref-11">11</xref>] introduced an efficient data auditing method that uses the AES encryption algorithm and SHA-2 (Secure Hash Algorithm), utilizing a third-party auditor to perform integrity checks. In this method, the user encrypts the data using the AES algorithm and obtains a message digest of the encrypted data using SHA-2. Encrypted data is sent to the cloud server, and message digests are sent to a third-party auditor (TPA) that performs data integrity checks. In 2018, Han et al. [<xref ref-type="bibr" rid="ref-12">12</xref>] proposed a pairless integrity verification scheme based on Schnorr signatures. However, this scheme suffers from computational errors in the domain and requires a third party. In 2019, Zhang et al. [<xref ref-type="bibr" rid="ref-13">13</xref>] proposed a general construction method for PoR based on Linear Homomorphic Structure Preserving Signatures (LHSPS). The unforgeability of LHSPS ensures the authenticity and tractability of the PoR scheme. In 2020, Yu et al. [<xref ref-type="bibr" rid="ref-14">14</xref>] designed a more efficient pairing-free scheme based on blockchain. However, this scheme can only be applied to private audits.</p>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>Consensus Mechanism</title>
<p>In 2008, Satoshi Nakamoto first introduced it into the blockchain in his paper [<xref ref-type="bibr" rid="ref-15">15</xref>], which is the underlying technology of Bitcoin. Traditional transactions require a centralized and trusted institution. The confirmation and recording of transactions are completely dependent on trusted institutions, which can lead to many issues such as transaction costs, efficiency and security. PoW is the consensus algorithm used in Bitcoin. Its core idea is to allocate accounting rights and rewards through the competition of computing power among nodes. Based on the information from the previous block, different nodes calculate a specific solution to a mathematical problem [<xref ref-type="bibr" rid="ref-16">16</xref>]. This math problem is difficult to solve. The first node to solve this math problem can create the next block and be rewarded with a certain number of bitcoins. The earliest application of PoS is PPCoin. In PoS, digital currency has the concept of coin age. The coin age of a coin is its value multiplied by the time period since it was created. The longer a node holds coins, the more power it has in the network. Coin holders will also receive certain rewards based on the coin age. In the design of PPCoin, mining is also required to obtain bookkeeping rights. The formula is proof hash&#x2009;&#x003C;&#x2009;coin age &#x002A; target. The proof hash is the combined hash of the weight factor, the unspent output value, and the fuzzy sum of the current time [<xref ref-type="bibr" rid="ref-17">17</xref>]. With the concept of coin age, blockchains no longer rely solely on POW. This effectively solves the resource waste problem in PoW. BitShares is an example of DPoS [<xref ref-type="bibr" rid="ref-18">18</xref>]. In a blockchain with DPoS, each node can choose witnesses based on their stake. In the entire network, the top N witnesses who participate in the election and get the most votes have the right to keep accounts. The number of witnesses, N, is defined as at least 50&#x0025; of voting stakeholders believe there is sufficient decentralization.</p>
</sec>
<sec id="s2_3">
<label>2.3</label>
<title>The Combination of Integrity Verification and Consensus Mechanism</title>
<p>In 2014, Miller et al. proposed a new scheme, Permacoin [<xref ref-type="bibr" rid="ref-19">19</xref>], which modified Bitcoin to produce highly decentralized file storage and reduce the overall waste of Bitcoin. Permacoin encourages participants to store locally, ensuring a high probability of complete data recovery, enabling robust file distribution. In 2018, Hao et al. [<xref ref-type="bibr" rid="ref-20">20</xref>] proposed a blockchain-based decentralized model called DCOM (Decentralized COllaborative verification Model). The model consists of a cooperative network of validating peers, each of which maintains a record of validation via a blockchain. Francati et al. [<xref ref-type="bibr" rid="ref-21">21</xref>] proposed a blockchain-based decentralized storage system&#x2014;Audita in 2019. It can be built on multiple blockchain systems and uses an enhanced network of participants including storage nodes and block creators.</p>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>Problem Statement</title>
<sec id="s3_1">
<label>3.1</label>
<title>System Model</title>
<p>Our goal is to provide a distributed storage system with proof of retrievability and deduplication algorithms as consensus mechanisms, incentivizing a majority of nodes to participate in storage services (see <xref ref-type="fig" rid="fig-1">Fig. 1</xref>). Because centralized storage cannot guarantee user privacy and user information is easily leaked, we use ring signatures and blockchain to achieve distributed storage. The system model consists of three entities: Data Owner (DO), Cloud Storage Provider (CSP), Third-Party Auditor (TPA).</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>System model</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="IASC_29657-fig-1.png"/>
</fig>
<p>Data owner (common node): The data owner is a node that owns a series of files that need to be stored on the cloud.</p>
<p>Cloud storage provider (storage node): The cloud storage provider is a node that provides cloud storage services to data owners.</p>
<p>Third-party auditor (retrieval node): The third-party auditor is a node that provides retrieval services for users.</p>
<p>The entire design includes the following functions: file storage, deduplication, privacy protection, and block election.</p>
<p><bold>File storage.</bold> To store files and ensure data integrity, the data owner uses proof of retrievability and encodes the files. Then the data owner sends a storage request, agrees on a price with the cloud storage provider, and signs a contract on the blockchain [<xref ref-type="bibr" rid="ref-22">22</xref>]. Cloud storage providers accept files and are checked by retrieval nodes for the duration of the contract. The retrieval proof will be issued as a transaction, including a reference to the storage contract in the blockchain and the storage integrity proof. The retrieval node and storage node will also receive a portion of the service incentive [<xref ref-type="bibr" rid="ref-23">23</xref>].</p>
<p><bold>Deduplication.</bold> In order to meet the optimization of storage capacity in cloud storage, a deduplication algorithm is added to the solution [<xref ref-type="bibr" rid="ref-24">24</xref>]. In terms of data integrity verification, duplicate identity authentication tags are not introduced, thereby ensuring that communication costs and computing costs remain unchanged. At the same time, a polynomial-time adversary without a complete data file cannot pass the verification process [<xref ref-type="bibr" rid="ref-25">25</xref>]. The algorithm greatly reduces the demand for physical storage space and brings many benefits to the entire system, such as saving the total storage cost and management cost; efficiently controlling the accelerated growth of data; increasing effective storage space and improving storage efficiency; saving network bandwidth for data transmission [<xref ref-type="bibr" rid="ref-26">26</xref>].</p>
<p><bold>Privacy protection.</bold> User privacy is one of the most important aspects of privacy protection. The system model needs to effectively manage and control personally identifiable information and enhance the confidentiality of documents. To do this, we use ring signatures to construct our scheme [<xref ref-type="bibr" rid="ref-27">27</xref>].</p>
<p>Multiple users participate in the file storage stage. During the signing process, the public key of everyone is used to sign the file, including the storage node, which makes the file signature untraceable. Unrelated nodes in the blockchain system cannot trace the sender of the file [<xref ref-type="bibr" rid="ref-28">28</xref>]. When other nodes verify the transaction, they can only determine that the file signature is one of many public keys, but cannot locate the specific sender of the file. At the same time, Sybil attacks and outsourcing attacks initiated by some malicious storage nodes are prevented.</p>
<p><bold>Election blocks.</bold> When data owners store data, they need to issue storage orders and a certain amount of blockchain tokens to reward storage nodes and retrieval nodes [<xref ref-type="bibr" rid="ref-29">29</xref>]. Storage nodes and retrieval nodes receive corresponding rewards after completing storage and retrieval services, and record transaction orders and storage proofs on the blockchain [<xref ref-type="bibr" rid="ref-30">30</xref>]. In our model, the blockchain will elect a leader based on the current storage node capacity to generate new blocks.</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Security Model</title>
<p>Inspired by the audit scheme [<xref ref-type="bibr" rid="ref-31">31</xref>], we briefly define the security model of the scheme.</p>
<p><bold><italic>Initialization</italic>:</bold> Challenger C first generates a random file and runs the algorithm to generate the file key pair (<italic>pk</italic>, <italic>sk</italic>) and the encoding block &#x007B;<italic>m</italic><sub><italic>i</italic></sub>&#x007D;. Then, C sends the public parameter para to the adversary A.</p>
<p><bold><italic>Query</italic>:</bold> The adversary randomly selects a block <italic>m</italic><sub><italic>j</italic></sub>&#x2009;&#x2208;&#x2009;&#x007B;<italic>m</italic><sub><italic>i</italic></sub>&#x007D; and queries the challenger C to obtain the corresponding hash value and signature until the query time reaches <italic>q</italic><sub><italic>s</italic></sub>.</p>
<p><bold><italic>Challenge</italic>:</bold> C randomly challenges A to some block <italic>Chal</italic><sub><italic>t</italic></sub> that has not yet been queried. According to <italic>Chal</italic><sub><italic>t</italic></sub>, generate aggregate signature <italic>&#x03C3;</italic><sub><italic>t</italic></sub> and proof <italic>Proof</italic><sub><italic>t</italic></sub>, and return them to C.</p>
<p><bold><italic>Verification</italic>:</bold> Check that <italic>&#x03C3;</italic><sub><italic>t</italic></sub> is consistent with <italic>Proof</italic>. If they agree, A wins, otherwise, A loses.</p>
<p>To enhance security and privacy protection, our proposed distributed storage scheme should satisfy validity, unforgeability and privacy protection. Defined as follows:<list list-type="simple"><list-item><label>1)</label>
<p>Effectiveness</p></list-item></list></p>
<p>Validity means that for any security parameter <italic>&#x03BB;</italic> and a negligible function <italic>negl</italic>(&#x2009;&#x22C5;&#x2009;), all proofs generated by honest nodes must pass verification, while proofs generated by malicious nodes cannot pass verification.<list list-type="simple"><list-item><label>2)</label>
<p>Unforgeability</p></list-item></list></p>
<p>Unforgeability means that no adversary to our verification scheme can make a verifier accept a proof of retrievability protocol instance with non-negligible probability unless it responds with a correctly computed value.<list list-type="simple"><list-item><label>3)</label>
<p>Privacy protection</p></list-item></list></p>
<p>Privacy protection means that the signer of the file identification in the scheme has unconditional anonymity, that is, for any algorithm A, any set of users <italic>R</italic>&#x2009;&#x003D;&#x2009;<italic>pk</italic><sub>1</sub>, <italic>pk</italic><sub>2</sub>, &#x2026;, <italic>pk</italic><sub><italic>n</italic></sub>, the probability <italic>P</italic>[<italic>pk</italic>&#x2009;&#x003D;&#x2009;<italic>pk</italic><sup>&#x2032;</sup>] is all 1/2, where <inline-formula id="ieqn-1">
<mml:math id="mml-ieqn-1"><mml:msub><mml:mi>T</mml:mi><mml:mi>&#x03C3;</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>I</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>c</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>c</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>d</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>d</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>d</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>d</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math>
</inline-formula> is the ring signature generated by <italic>pk</italic><sub><italic>s</italic></sub>.</p>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Construction of the Proposed Consensus Protocol</title>
<sec id="s4_1">
<label>4.1</label>
<title>Notation and Preliminaries</title>
<p>In the scheme we have used the following symbols (as shown in <xref ref-type="table" rid="table-1">Tab. 1</xref>).</p>
<table-wrap id="table-1"><label>Table 1</label>
<caption>
<title>The definition of symbols</title></caption>
<table><colgroup><col align="left"/><col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Symbol</th>
<th align="left">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left"><italic>&#x03BB;</italic></td>
<td align="left">Security parameters</td>
</tr>
<tr>
<td align="left"><italic>F</italic></td>
<td align="left">The encoded file</td>
</tr>
<tr>
<td align="left"><italic>H</italic>(&#x2009;&#x22C5;&#x2009;)</td>
<td align="left">One-way hash function</td>
</tr>
<tr>
<td align="left"><italic>G</italic></td>
<td align="left">Base point on elliptic curve</td>
</tr>
<tr>
<td align="left"><italic>a</italic>&#x2009;&#x2190;&#x2009;<italic>A</italic>(<italic>x</italic>)</td>
<td align="left">Algorithm <italic>A</italic> with input <italic>x</italic> and output <italic>a</italic></td>
</tr>
<tr>
<td align="left"><italic>e</italic></td>
<td align="left">Bilinear mapping</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>We use <italic>&#x03BB;</italic> to denote the security parameter. <italic>F</italic> represents the encoded file after user preprocessing, where <italic>F</italic>&#x2009;&#x003D;&#x2009;(<italic>m</italic><sub>1</sub>, <italic>m</italic><sub>2</sub>, &#x2026;, <italic>m</italic><sub><italic>n</italic></sub>). <italic>H</italic>(&#x2009;&#x22C5;&#x2009;) represents a one-way hash function. <italic>G</italic> is the base point on the elliptic curve. Let <italic>A</italic> denotes an algorithm, then, the notation <italic>a</italic>&#x2009;&#x2190;&#x2009;<italic>A</italic>(<italic>x</italic>) denotes an algorithm <italic>A</italic> that takes an input <italic>x</italic> and gets an output <italic>a</italic>. <italic>e</italic> is a bilinear map in the scheme.</p>
<sec id="s4_1_1">
<label>4.1.1</label>
<title>Bilinear Mapping</title>
<p>Let <italic>G</italic><sub>1</sub>, <italic>G</italic><sub>2</sub> be additive group and multiplicative group of order <italic>g</italic>, respectively, and assume that <italic>g</italic><sub>1</sub> is the generator of <italic>G</italic><sub>1</sub>. Suppose that in the group <italic>G</italic><sub>1</sub>, <italic>G</italic><sub>2</sub>, the discrete logarithm problem is intractable. A bilinear mapping pair can be defined as <italic>e</italic>:<italic>G</italic><sub>1</sub>&#x2009;&#x00D7;&#x2009;<italic>G</italic><sub>1</sub>&#x2009;&#x2192;&#x2009;<italic>G</italic><sub>2</sub>, and satisfy the following properties:<list list-type="simple"><list-item><label>1)</label>
<p>Double mapping. <inline-formula id="ieqn-2">
<mml:math id="mml-ieqn-2"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>g</mml:mi><mml:mn>1</mml:mn><mml:mi>a</mml:mi></mml:msubsup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msubsup><mml:mi>g</mml:mi><mml:mn>2</mml:mn><mml:mi>b</mml:mi></mml:msubsup><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>g</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>g</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msup></mml:math>
</inline-formula>,&#x00A0;for all <italic>g</italic><sub>1</sub>, <italic>g</italic><sub>2</sub>&#x2009;&#x2208;&#x2009;<italic>G</italic><sub>1</sub> all <italic>a</italic>, <italic>b</italic> holds</p></list-item><list-item><label>2)</label>
<p>Non-degenerate. If <italic>e</italic>(<italic>g</italic><sub>1</sub>, <italic>g</italic><sub>2</sub>)&#x2009;&#x003D;&#x2009;1, there is <italic>g</italic><sub>2</sub>&#x2009;&#x2208;&#x2009;<italic>G</italic><sub>1</sub>, then there is <italic>g</italic><sub>1</sub>&#x2009;&#x003D;&#x2009;<italic>O</italic>.</p></list-item><list-item><label>3)</label>
<p>Computability. Efficient algorithms exist to compute <italic>e</italic>(<italic>g</italic><sub>1</sub>, <italic>g</italic><sub>2</sub>) for <italic>g</italic><sub>1</sub>, <italic>g</italic><sub>2</sub>&#x2009;&#x2208;&#x2009;<italic>G</italic><sub>1</sub>.</p></list-item></list></p>
</sec>
<sec id="s4_1_2">
<label>4.1.2</label>
<title>Proof of Storage</title>
<p>The POS scheme allows the scheme to allow user V to outsource the storage of data D to server P, and then repeatedly check whether P is still storing <italic>F</italic>. PDP and POR were introduced independently around the same time in 2007 [<xref ref-type="bibr" rid="ref-32">32</xref>]. Since then, the concept of POS has popularized PDP and PoR. The main difference between the POR model and the PDP model is that in the preprocessing stage, the use of error correction code or other codes to encode the file data can not only verify the integrity of the file, but also recover damaged data [<xref ref-type="bibr" rid="ref-33">33</xref>]. Adding the two algorithms of Encode () and Extract() to the PDP model can be extended to a POR model.</p>
</sec>
<sec id="s4_1_3">
<label>4.1.3</label>
<title>Blockchain</title>
<p>Blockchain refers to a new distributed infrastructure and computing paradigm that utilizes blockchain data structures to verify and store data, utilizes distributed node consensus algorithm to generate and update data, utilizes cryptography to ensure the security of data transmission and access, and utilizes smart contracts composed of automated script codes to program and manipulate data [<xref ref-type="bibr" rid="ref-34">34</xref>]. A blockchain is basically a series of linked blocks of data. Blocks are added to the blockchain through consensus of the majority of nodes in the system. Each block contains a block header and a sequence of transactions, each block header contains a link pointer to the block header of the previous block, the merkle root of the tree-like transaction information, and a timestamp [<xref ref-type="bibr" rid="ref-35">35</xref>]. In this way, the blocks are linked together in chronological order. Cryptographic hashing algorithms ensure that transaction data in each block is immutable and that linked blocks in the blockchain cannot be tampered with.</p>
</sec>
<sec id="s4_1_4">
<label>4.1.4</label>
<title>Ring Signature</title>
<p>In 2001, Rivest et al. [<xref ref-type="bibr" rid="ref-36">36</xref>] proposed a new type of signature technique called ring signatures in the context of how to leak secrets anonymously. Suppose there are <italic>n</italic> users, and each user <italic>u</italic><sub><italic>i</italic></sub> has a public key <italic>y</italic><sub><italic>i</italic></sub> and a corresponding private key <italic>x</italic><sub><italic>i</italic></sub>. Ring signature is a signature scheme that can realize the unconditional anonymity of the signer. It mainly consists of the following algorithms:</p>
<p><bold><italic>KeyGen</italic>.</bold> A probabilistic polynomial time (PPT) algorithm with the security parameter <italic>k</italic> as input and the public and private keys as output. Here it is assumed that <italic>KeyGen</italic> generates a public key <italic>y</italic><sub><italic>i</italic></sub> and a private key <italic>x</italic><sub><italic>i</italic></sub> for each user <italic>u</italic><sub><italic>i</italic></sub>.</p>
<p><bold><italic>Sign</italic>.</bold> A PPT algorithm, after inputting message <italic>m</italic> and the public key <italic>L</italic>&#x2009;&#x003D;&#x2009;&#x007B;<italic>y</italic><sub>1</sub>, <italic>y</italic><sub>2</sub>, &#x2026;, <italic>y</italic><sub><italic>n</italic></sub>&#x007D; of <italic>n</italic> ring members and the private key <italic>x</italic><sub><italic>s</italic></sub> of one of the members, generates a signature R for message <italic>m</italic>, in which a parameter in R is a ring according to certain rules.</p>
<p><bold><italic>Verify</italic>.</bold> A deterministic algorithm that, after inputting (<italic>m</italic>, <italic>R</italic>), if <italic>R</italic> is the ring signature of <italic>m</italic>, output &#x201C;True&#x201D;, otherwise output &#x201C;False&#x201D;.</p>
</sec>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Our Construction</title>
<p>In this section, we describe the construction of the proposed distributed storage consensus protocol.</p>
<p><bold><italic>KeyGen:</italic></bold></p>
<p>Given the security parameter <italic>&#x03BB;</italic>, the TA selects a random number <inline-formula id="ieqn-3">
<mml:math id="mml-ieqn-3"><mml:mi>&#x03B1;</mml:mi><mml:mrow><mml:mover><mml:mo stretchy="false">&#x27F5;</mml:mo><mml:mi>R</mml:mi></mml:mover></mml:mrow><mml:msubsup><mml:mi>Z</mml:mi><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math>
</inline-formula> to generate the public key <inline-formula id="ieqn-4">
<mml:math id="mml-ieqn-4"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msup><mml:mi>&#x03B1;</mml:mi><mml:mi>j</mml:mi></mml:msup></mml:mrow></mml:msup><mml:msubsup><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup></mml:math>
</inline-formula>, where <italic>&#x03B1;</italic> is the master key known only to the TA.</p>
<p>Data owner <italic>DO</italic><sub><italic>i</italic></sub> randomly selects <inline-formula id="ieqn-5">
<mml:math id="mml-ieqn-5"><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math>
</inline-formula>, calculates <italic>spk</italic><sub><italic>i</italic></sub>&#x2009;&#x2190;&#x2009;<italic>x</italic><sub><italic>i</italic></sub>&#x2009;&#x22C5;&#x2009;<italic>P</italic>, generates a signature key pair (<italic>spk</italic><sub><italic>i</italic></sub>, <italic>ssk</italic><sub><italic>i</italic></sub>), then selects a random number <inline-formula id="ieqn-6">
<mml:math id="mml-ieqn-6"><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math>
</inline-formula> and calculates &#x025B;&#x2009;&#x2190;&#x2009;<italic>g</italic><sup><italic>x</italic></sup>, <italic>v</italic>&#x2009;&#x2190;&#x2009;<italic>g</italic><sup><italic>&#x03B1;x</italic></sup>.</p>
<p>Among them, <inline-formula id="ieqn-7">
<mml:math id="mml-ieqn-7"><mml:mi>P</mml:mi><mml:mi>K</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>q</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>&#x03F5;</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>v</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:mi>k</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>u</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msup><mml:mi>&#x03B1;</mml:mi><mml:mi>j</mml:mi></mml:msup></mml:mrow></mml:msup><mml:msubsup><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math>
</inline-formula>, <italic>SK</italic>&#x2009;&#x003D;&#x2009;&#x007B;<italic>x</italic>, <italic>ssk</italic>&#x007D;, <italic>MK</italic>&#x2009;&#x003D;&#x2009;&#x007B;<italic>&#x03B1;</italic>&#x007D;.</p>
<p><bold><italic>Setup:</italic></bold></p>
<p>Data owner <italic>DO</italic><sub><italic>s</italic></sub> encodes the file <italic>F</italic>, <italic>F</italic><sup>&#x2032;</sup>&#x2009;&#x2190;&#x2009;<italic>F</italic>, <italic>F</italic><sup>&#x2032;</sup>&#x2009;&#x003D;&#x2009;&#x007B;<italic>m</italic><sub><italic>ij</italic></sub>&#x007D;, 1&#x2009;&#x2264;&#x2009;<italic>i</italic>&#x2009;&#x2264;&#x2009;<italic>n</italic>, 1&#x2009;&#x2264;&#x2009;<italic>j</italic>&#x2009;&#x2264;&#x2009;<italic>t</italic>&#x2009;&#x2212;&#x2009;1. Randomly chooses the filename <inline-formula id="ieqn-8">
<mml:math id="mml-ieqn-8"><mml:mi>n</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math>
</inline-formula>.</p>
<p>Selects a signature public key set <italic>R</italic>&#x2009;&#x003D;&#x2009;&#x007B;<italic>spk</italic><sub>1</sub>, <italic>spk</italic><sub>2</sub>, &#x2026;, <italic>spk</italic><sub><italic>n</italic></sub>&#x007D;, which contains the CSP&#x2019;s signature public key for verification, randomly selects <inline-formula id="ieqn-9">
<mml:math id="mml-ieqn-9"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math>
</inline-formula>, calculates <italic>L</italic><sub><italic>i</italic></sub> from <xref ref-type="disp-formula" rid="eqn-1">Eq. (1)</xref>, and calculates <italic>R</italic><sub><italic>i</italic></sub> from <xref ref-type="disp-formula" rid="eqn-2">Eq. (2)</xref>:</p>
<p><disp-formula id="eqn-1"><label>(1)</label>
<mml:math id="mml-eqn-1" display="block"><mml:msub><mml:mi>L</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd columnalign="left"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>G</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mi>s</mml:mi></mml:mtd></mml:mtr><mml:mtr><mml:mtd columnalign="left"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>G</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>+</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>s</mml:mi></mml:mtd></mml:mtr></mml:mtable><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo></mml:mrow></mml:math>
</disp-formula><disp-formula id="eqn-2"><label>(2)</label>
<mml:math id="mml-eqn-2" display="block"><mml:msub><mml:mi>R</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd columnalign="left"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mtext>&#xA0;</mml:mtext></mml:mrow><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mi>s</mml:mi></mml:mtd></mml:mtr><mml:mtr><mml:mtd columnalign="left"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>I</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>s</mml:mi></mml:mtd></mml:mtr></mml:mtable><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo></mml:mrow></mml:math>
</disp-formula></p>
<p>Among them, <inline-formula id="ieqn-10">
<mml:math id="mml-ieqn-10"><mml:msub><mml:mi>I</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math>
</inline-formula>. The purpose is to prevent double spend attacks. <italic>H</italic><sub>0</sub>(<italic>spk</italic><sub><italic>i</italic></sub>) maps <italic>spk</italic><sub><italic>i</italic></sub> to a point on the finite field elliptic curve.</p>
<p>Chooses <inline-formula id="ieqn-11">
<mml:math id="mml-ieqn-11"><mml:mi>r</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math>
</inline-formula> randomly and then calculates <italic>h</italic>, <italic>c</italic><sub><italic>i</italic></sub>, <italic>e</italic><sub><italic>i</italic></sub> from <xref ref-type="disp-formula" rid="eqn-3">Eqs. (3)</xref>&#x2013; <xref ref-type="disp-formula" rid="eqn-5">(5)</xref>.<disp-formula id="eqn-3"><label>(3)</label>
<mml:math id="mml-eqn-3" display="block"><mml:mi>h</mml:mi><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mi>r</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math>
</disp-formula><disp-formula id="eqn-4"><label>(4)</label>
<mml:math id="mml-eqn-4" display="block"><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd columnalign="left"><mml:msub><mml:mi>H</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>h</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>L</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>L</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>R</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>R</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:msubsup><mml:mrow><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mi>s</mml:mi></mml:mtd></mml:mtr><mml:mtr><mml:mtd columnalign="left"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>I</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="2em" /><mml:mspace width="2em" /><mml:mspace width="2em" /><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>s</mml:mi></mml:mtd></mml:mtr></mml:mtable><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo></mml:mrow></mml:math>
</disp-formula><disp-formula id="eqn-5"><label>(5)</label>
<mml:math id="mml-eqn-5" display="block"><mml:msub><mml:mi>e</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd columnalign="left"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mi>s</mml:mi></mml:mtd></mml:mtr><mml:mtr><mml:mtd columnalign="left"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mspace width="2em" /><mml:mspace width="2em" /><mml:mspace width="2em" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>s</mml:mi></mml:mtd></mml:mtr></mml:mtable><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo></mml:mrow></mml:math>
</disp-formula>where name is the content of the signature here, and the ring signature of the file name name by the data owner <italic>DO</italic><sub><italic>s</italic></sub> is output as <inline-formula id="ieqn-12">
<mml:math id="mml-ieqn-12"><mml:msub><mml:mi>T</mml:mi><mml:mi>&#x03C3;</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>I</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>c</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>c</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>d</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>d</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>d</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>d</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math>
</inline-formula>. Finally, <italic>DO</italic><sub><italic>s</italic></sub> uses the signature private key <italic>ssk</italic><sub><italic>s</italic></sub> to generate the file identifier <inline-formula id="ieqn-13">
<mml:math id="mml-ieqn-13"><mml:mi>&#x03C4;</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mi>n</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mi>n</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:msub><mml:mi>T</mml:mi><mml:mi>&#x03C3;</mml:mi></mml:msub></mml:math>
</inline-formula>.</p>
<p>For each file block <italic>m</italic><sub><italic>i</italic></sub>, every file block generates an authentication tag <inline-formula id="ieqn-14">
<mml:math id="mml-ieqn-14"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:msup><mml:mi>u</mml:mi><mml:mrow><mml:mi>H</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>n</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mi>i</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mo movablelimits="false">&#x220F;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mrow><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:msup><mml:mi>&#x03B1;</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>+</mml:mo><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:msup></mml:mrow></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mi>x</mml:mi></mml:msup><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msup><mml:mi>u</mml:mi><mml:mrow><mml:mi>H</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>n</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mi>i</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mover><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2192;</mml:mo></mml:mover></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mi>x</mml:mi></mml:msup></mml:math>
</inline-formula>, where <inline-formula id="ieqn-15">
<mml:math id="mml-ieqn-15"><mml:mover><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mi>l</mml:mi></mml:msub><mml:mo>&#x2192;</mml:mo></mml:mover><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>s</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math>
</inline-formula>.</p>
<p>Data owner <italic>DO</italic><sub><italic>s</italic></sub> stores &#x007B;<italic>F</italic><sup>&#x2032;</sup>, <italic>&#x03C4;</italic>, <italic>&#x03C3;</italic><sub><italic>i</italic></sub>&#x007D; into CSP.</p>
<p><bold><italic>Challenge:</italic></bold></p>
<p>To verify data integrity, the third party first uses <italic>spk</italic><sub><italic>s</italic></sub> to verify <italic>&#x03C4;</italic> and the signature on <italic>&#x03C4;</italic>. Terminate if the signature is invalid. If the signature is valid, randomly selects the pair (<italic>k</italic><sub>1</sub>, <italic>k</italic><sub>2</sub>) where <inline-formula id="ieqn-16">
<mml:math id="mml-ieqn-16"><mml:msub><mml:mi>k</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>k</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math>
</inline-formula>, and sends the challenge value <italic>chal</italic>&#x2009;&#x003D;&#x2009;(<italic>c</italic>, <italic>k</italic><sub>1</sub>, <italic>k</italic><sub>2</sub>) to the CSP.</p>
<p><bold><italic>Prove:</italic></bold></p>
<p>CSP calculates <italic>a</italic><sub><italic>i</italic></sub>&#x2009;&#x003D;&#x2009;<italic>&#x03D5;</italic>(<italic>k</italic><sub>1</sub>, <italic>i</italic>), <italic>i</italic>&#x2009;&#x2208;&#x2009;<italic>c</italic> as the random index of the challenge block and <inline-formula id="ieqn-17">
<mml:math id="mml-ieqn-17"><mml:msub><mml:mi>b</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mi>k</mml:mi><mml:mn>2</mml:mn><mml:mrow><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mspace width="thickmathspace" /><mml:mi>q</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>c</mml:mi></mml:math>
</inline-formula> as the random parameter. Then generate <inline-formula id="ieqn-18">
<mml:math id="mml-ieqn-18"><mml:mi>y</mml:mi><mml:mo>=</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mover><mml:mi>A</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math>
</inline-formula>, <inline-formula id="ieqn-19">
<mml:math id="mml-ieqn-19"><mml:mi>A</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>c</mml:mi></mml:mrow></mml:munder><mml:mrow><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>c</mml:mi></mml:mrow></mml:munder><mml:mrow><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mi>s</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math>
</inline-formula>.</p>
<p>Then <inline-formula id="ieqn-20">
<mml:math id="mml-ieqn-20"><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mover><mml:mi>&#x03C9;</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>z</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2261;</mml:mo><mml:mrow><mml:mfrac><mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mover><mml:mi>A</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>z</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mover><mml:mi>A</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>z</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mrow></mml:mfrac></mml:mrow></mml:math>
</inline-formula>, <inline-formula id="ieqn-21">
<mml:math id="mml-ieqn-21"><mml:mover><mml:mi>&#x03C9;</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>&#x03C9;</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>&#x03C9;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>&#x03C9;</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math>
</inline-formula>. Next, generate <inline-formula id="ieqn-22">
<mml:math id="mml-ieqn-22"><mml:mi>&#x03BE;</mml:mi><mml:mo>=</mml:mo><mml:msubsup><mml:mo movablelimits="false">&#x220F;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>2</mml:mn></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msup><mml:mi>&#x03B1;</mml:mi><mml:mi>j</mml:mi></mml:msup></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mi>&#x03C9;</mml:mi><mml:mi>j</mml:mi></mml:msub></mml:mrow></mml:msup></mml:mrow></mml:math>
</inline-formula>.</p>
<p>The CSP finally computes <inline-formula id="ieqn-23">
<mml:math id="mml-ieqn-23"><mml:mi>&#x03C3;</mml:mi><mml:mo>=</mml:mo><mml:msub><mml:mo movablelimits="false">&#x220F;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:msubsup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow><mml:mrow><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub></mml:mrow></mml:msubsup></mml:mrow></mml:math>
</inline-formula> and sends <italic>Prf</italic>&#x2009;&#x003D;&#x2009;&#x007B;<italic>&#x03C3;</italic>, <italic>&#x03BE;</italic>, <italic>y</italic>&#x007D; to the third party.</p>
<p><bold><italic>Verify:</italic></bold></p>
<p>The third-party computes <inline-formula id="ieqn-24">
<mml:math id="mml-ieqn-24"><mml:mi>u</mml:mi><mml:mo>=</mml:mo><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>c</mml:mi></mml:mrow></mml:munder><mml:mrow><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mi>H</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:math>
</inline-formula> and <inline-formula id="ieqn-25">
<mml:math id="mml-ieqn-25"><mml:mi>&#x03B7;</mml:mi><mml:mo>=</mml:mo><mml:msup><mml:mi>u</mml:mi><mml:mi>&#x03BC;</mml:mi></mml:msup></mml:math>
</inline-formula> first. The user then verifies that <italic>e</italic>(<italic>&#x03B7;</italic>, &#x025B;)&#x2009;&#x22C5;&#x2009;<italic>e</italic>(<italic>&#x03BE;</italic>, <italic>v</italic>, <italic>&#x03BA;</italic><sup>&#x2212;<italic>r</italic></sup>)&#x2009;&#x003D;&#x2009;<italic>e</italic>(<italic>&#x03C3;</italic>, <italic>g</italic>)&#x2009;&#x22C5;&#x2009;<italic>e</italic>(&#x025B;<sup>&#x2212;<italic>y</italic></sup>, <italic>g</italic>) against <italic>Prf</italic>&#x2009;&#x003D;&#x2009;&#x007B;<italic>&#x03C3;</italic>, <italic>&#x03BE;</italic>, <italic>y</italic>&#x007D;.</p>
<p><bold><italic>Deduplication:</italic></bold></p>
<p>The CSP randomly selects <italic>k</italic><sub>3</sub>&#x2009;&#x2208;&#x2009;<italic>Z</italic><sub><italic>P</italic></sub>, computes <italic>d</italic><sub><italic>i</italic></sub>&#x2009;&#x003D;&#x2009;<italic>&#x03D5;</italic>(<italic>k</italic><sub>3</sub>, <italic>i</italic>) and sends it to a third party.</p>
<p>After receiving D, the third party responds to the corresponding data block <inline-formula id="ieqn-26">
<mml:math id="mml-ieqn-26"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math>
</inline-formula>, and the CSP calculates <inline-formula id="ieqn-27">
<mml:math id="mml-ieqn-27"><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>D</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub></mml:mrow></mml:math>
</inline-formula>, <inline-formula id="ieqn-28">
<mml:math id="mml-ieqn-28"><mml:msup><mml:mi>&#x03B7;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:msub><mml:mo movablelimits="false">&#x220F;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>D</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:msup><mml:mi>u</mml:mi><mml:mrow><mml:mi>H</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:math>
</inline-formula>, <inline-formula id="ieqn-29">
<mml:math id="mml-ieqn-29"><mml:msup><mml:mi>&#x03BE;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mo movablelimits="false">&#x220F;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>2</mml:mn></mml:mrow><mml:mrow><mml:mi>s</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msup><mml:mi>&#x03B1;</mml:mi><mml:mi>j</mml:mi></mml:msup></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mi>B</mml:mi><mml:mi>j</mml:mi></mml:msub></mml:mrow></mml:msup></mml:mrow><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>&#x03F5;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mover><mml:mi>B</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>&#x03F5;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math>
</inline-formula>, <inline-formula id="ieqn-30">
<mml:math id="mml-ieqn-30"><mml:mover><mml:mi>B</mml:mi><mml:mo>&#x2192;</mml:mo></mml:mover><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>D</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>D</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>s</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math>
</inline-formula>.</p>
<p>The CSP then verifies the integrity of the data block by <italic>e</italic>(<italic>&#x03B7;</italic><sup>&#x2032;</sup>, &#x025B;)&#x2009;&#x22C5;&#x2009;<italic>&#x03BE;</italic><sup>&#x2032;</sup>&#x2009;&#x003D;&#x2009;<italic>e</italic>(<italic>&#x03C3;</italic><sup>&#x2032;</sup>, <italic>g</italic>).</p>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Security Analysis</title>
<sec id="s5_1">
<label>5.1</label>
<title>Correctness</title>
<p><italic>Theorem</italic> 1: If the data owner and the storage node honestly follow the proposed storage protocol, any challenge-response verification can pass the verification of the retrieval node. The correctness of the equation is as follows.</p>
<p><italic>Proof</italic>: Based on <xref ref-type="disp-formula" rid="eqn-6">Eq. (6)</xref>, we obtain the correctness of Theorem 1.<disp-formula id="eqn-6"><label>(6)</label>
<mml:math id="mml-eqn-6" display="block"><mml:mtable columnalign="right left" rowspacing=".5em" columnspacing="thickmathspace" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B7;</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>&#x03F5;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BE;</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>v</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>&#x03F5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>r</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>u</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>g</mml:mi><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mi>x</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>C</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mi>H</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mrow><mml:mover><mml:mi>&#x03C9;</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:mi>&#x03F5;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>r</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>u</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>g</mml:mi><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mi>x</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>C</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mi>H</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>g</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mi>g</mml:mi><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mrow><mml:mfrac><mml:mrow><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mrow><mml:mover><mml:mi>A</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mrow><mml:mover><mml:mi>A</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>r</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>&#x03B1;</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>r</mml:mi></mml:mrow></mml:mfrac></mml:mrow><mml:mi>&#x03F5;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>r</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>u</mml:mi><mml:mrow><mml:mi>x</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>C</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mi>H</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:mi>x</mml:mi><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mrow><mml:mover><mml:mi>A</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03F5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>y</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03F5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>y</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math>
</disp-formula></p>
<p><italic>Theorem</italic> 2: If the data owner follows the data deduplication protocol, any challenge-response verification can pass the verification of the storage node. The correctness of the equation is as follows.</p>
<p><italic>Proof</italic>: Based on <xref ref-type="disp-formula" rid="eqn-7">Eq. (7)</xref>, we obtain the correctness of Theorem 2.<disp-formula id="eqn-7"><label>(7)</label>
<mml:math id="mml-eqn-7" display="block"><mml:mtable columnalign="right left" rowspacing=".5em" columnspacing="thickmathspace" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>g</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:msup><mml:mi>u</mml:mi><mml:mrow><mml:mi>x</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>D</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:msub><mml:mi>p</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mi>H</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:mi>&#x03F5;</mml:mi><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mrow><mml:mover><mml:mi>B</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>g</mml:mi></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>u</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>g</mml:mi><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mi>&#x03B5;</mml:mi><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>D</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:msub><mml:mi>p</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mi>H</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>g</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>g</mml:mi><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mi>&#x03F5;</mml:mi><mml:msub><mml:mi>f</mml:mi><mml:mrow><mml:mrow><mml:mover><mml:mi>B</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo></mml:mover></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03B7;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>&#x03F5;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>&#x03BE;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:mtd></mml:mtr></mml:mtable></mml:math>
</disp-formula></p>
<p><italic>Theorem</italic> 3: The verifier verifies the document identity T according to the formula, and if T is correct, the verification is passed.</p>
<p><italic>Proof</italic>: Based on <xref ref-type="disp-formula" rid="eqn-8">Eqs. (8)</xref>&#x2013;<xref ref-type="disp-formula" rid="eqn-12">(12)</xref> and <xref ref-type="disp-formula" rid="eqn-13">(13)</xref>, we obtain the correctness of Theorem 3.<disp-formula id="eqn-8"><label>(8)</label>
<mml:math id="mml-eqn-8" display="block"><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:msubsup><mml:mrow><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>h</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math>
</disp-formula></p>
<p>When <italic>i</italic>&#x2009;&#x2260;&#x2009;<italic>s</italic>, <italic>&#x03B3;</italic><sub><italic>i</italic></sub>, <italic>&#x03B4;</italic><sub><italic>i</italic></sub> can be expressed as <xref ref-type="disp-formula" rid="eqn-9">Eqs. (9)</xref> and <xref ref-type="disp-formula" rid="eqn-10">(10)</xref>.</p>
<p><disp-formula id="eqn-9"><label>(9)</label>
<mml:math id="mml-eqn-9" display="block"><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>e</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mi>G</mml:mi><mml:mo>+</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mi>G</mml:mi><mml:mo>+</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>L</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math>
</disp-formula></p>
<p><disp-formula id="eqn-10"><label>(10)</label>
<mml:math id="mml-eqn-10" display="block"><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>e</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>I</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>I</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math>
</disp-formula></p>
<p>when <italic>i</italic>&#x2009;&#x003D;&#x2009;<italic>s</italic>, <italic>&#x03B3;</italic><sub><italic>i</italic></sub>, <italic>&#x03B4;</italic><sub><italic>i</italic></sub> is represented as follows:</p>
<p><disp-formula id="eqn-11"><label>(11)</label>
<mml:math id="mml-eqn-11" display="block"><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>e</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mi>G</mml:mi><mml:mo>+</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mi>G</mml:mi><mml:mo>+</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>L</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math>
</disp-formula></p>
<p><disp-formula id="eqn-12"><label>(12)</label>
<mml:math id="mml-eqn-12" display="block"><mml:mtable columnalign="right left" rowspacing=".5em" columnspacing="thickmathspace" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>e</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>I</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mo>=</mml:mo><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2217;</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>s</mml:mi><mml:mi>p</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mtd></mml:mtr></mml:mtable></mml:math>
</disp-formula></p>
<p>Therefore, according to the above equation, the correctness of the file identification can be verified by the <xref ref-type="disp-formula" rid="eqn-13">Eq. (13)</xref>.<disp-formula id="eqn-13"><label>(13)</label>
<mml:math id="mml-eqn-13" display="block"><mml:mtable columnalign="right left" rowspacing=".5em" columnspacing="thickmathspace" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:msub><mml:mi>H</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>h</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mo>=</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>h</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>L</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>L</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>L</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>L</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>R</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>R</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>R</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>R</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mo>=</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mi>i</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>s</mml:mi></mml:mrow><mml:mi>n</mml:mi></mml:msubsup><mml:mrow><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>n</mml:mi></mml:msubsup><mml:mrow><mml:msub><mml:mi>c</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:mtd></mml:mtr></mml:mtable></mml:math>
</disp-formula></p>
</sec>
<sec id="s5_2">
<label>5.2</label>
<title>Unforgeability</title>
<p><italic>Theorem</italic> 4: If the signature scheme is unforgeable and the computational Diffie-Hellman problem on bilinear groups is difficult, then any adversary to our public verification scheme for correctness cannot make the verifier accept the proof of retrievability protocol instance with non-negligible probability unless it responds with a correctly computed value.</p>
<p>We prove this theorem with a series of games defined in [<xref ref-type="bibr" rid="ref-37">37</xref>].</p>
<p>Game 0: The first game, Game 0, is simply a challenge game, similar to [<xref ref-type="bibr" rid="ref-37">37</xref>].</p>
<p>Game 1: Game 1 is the same as Game 0, with one difference. The challenger maintains a list of all signature tags issued as part of the storage protocol query. If an adversary submits a tag when initiating the proof of retrievability protocol or as a challenge tag, the challenger will abort if this is a valid tag that the challenger has never signed.</p>
<p>From the definition of games 0 and 1, it is obvious that if the opponents of games 0 and 1 have different success probabilities, we can use the opponent to construct a counterfeiter for the signature scheme.</p>
<p>Game 2: Game 2 is the same as Game 1, except that in Game 2, the challenger keeps a list of its responses to the opponent&#x2019;s query. The challenger now observes each instance of the adversary&#x2019;s proof of retrievability protocol. Suppose <italic>prf</italic>&#x2009;&#x003D;&#x2009;&#x007B;<italic>&#x03C3;</italic>, <italic>&#x03BE;</italic>, <italic>y</italic>&#x007D; is the expected response from an honest prover and <italic>Prf</italic><sup>&#x2032;</sup>&#x2009;&#x003D;&#x2009;&#x007B;<italic>&#x03C3;</italic><sup>&#x2032;</sup>, <italic>&#x03BE;</italic><sup>&#x2032;</sup>, <italic>y</italic><sup>&#x2032;</sup>&#x007D; is the adversary&#x2019;s response. The verification of <italic>prf</italic> &#x003D; &#x007B;<italic>&#x03C3;</italic>, <italic>&#x03BE;</italic>, <italic>y</italic>&#x007D; is <italic>e</italic>(<italic>&#x03B7;</italic>, &#x025B;)&#x2009;&#x22C5;&#x2009;<italic>e</italic>(<italic>&#x03BE;</italic>, <italic>v</italic>&#x2009;&#x22C5;&#x2009;&#x025B;<sup>&#x2212;<italic>r</italic></sup>)&#x2009;&#x003D;&#x2009;<italic>e</italic>(<italic>&#x03C3;</italic>, <italic>g</italic>)&#x2009;&#x22C5;&#x2009;<italic>e</italic>(&#x025B;<sup>&#x2212;<italic>y</italic></sup>, <italic>g</italic>), and the verification of <italic>prf</italic><sup>&#x2032;</sup>&#x2009;&#x003D;&#x2009;&#x007B;<italic>&#x03C3;</italic><sup>&#x2032;</sup>, <italic>&#x03BE;</italic><sup>&#x2032;</sup>, <italic>y</italic><sup>&#x2032;</sup>&#x007D; is <inline-formula id="ieqn-31">
<mml:math id="mml-ieqn-31"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B7;</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>&#x03F5;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mspace width="thinmathspace" /><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03BE;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>v</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>&#x03F5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>r</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03F5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mi>y</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math>
</inline-formula>. Then we can know that <inline-formula id="ieqn-32">
<mml:math id="mml-ieqn-32"><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mrow><mml:mfrac><mml:mrow><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03BE;</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>v</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>&#x03F5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>r</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03BE;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>v</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>&#x03F5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>r</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mfrac><mml:mrow><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac></mml:mrow><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>&#x03F5;</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>y</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2212;</mml:mo><mml:mi>y</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>g</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mstyle></mml:math>
</inline-formula>. At this point the opponent knows that <inline-formula id="ieqn-33">
<mml:math id="mml-ieqn-33"><mml:mi>&#x03B7;</mml:mi><mml:mo>=</mml:mo><mml:msup><mml:mi>u</mml:mi><mml:mrow><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>K</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mi>H</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mrow></mml:msup></mml:math>
</inline-formula>. We denote <italic>&#x03BE;</italic><sup>&#x2032;</sup> as <inline-formula id="ieqn-34">
<mml:math id="mml-ieqn-34"><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msup><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:msup></mml:math>
</inline-formula>, <italic>&#x03B7;</italic><sup>&#x2032;</sup> as <inline-formula id="ieqn-35">
<mml:math id="mml-ieqn-35"><mml:msup><mml:mi>g</mml:mi><mml:mi>&#x03C1;</mml:mi></mml:msup></mml:math>
</inline-formula>, <inline-formula id="ieqn-36">
<mml:math id="mml-ieqn-36"><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msup><mml:mi>&#x03C0;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:msup></mml:math>
</inline-formula>, according to the equation drawn above, we have <inline-formula id="ieqn-37">
<mml:math id="mml-ieqn-37"><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mi>&#x03C1;</mml:mi></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>&#x03F5;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mrow><mml:mfrac><mml:mrow><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mi>y</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>&#x03F5;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:mrow><mml:mfrac><mml:mrow><mml:msup><mml:mi>&#x03C0;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mi>x</mml:mi></mml:mfrac></mml:mrow></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>&#x03F5;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:msup><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mi>&#x03F5;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac></mml:mrow></mml:mstyle></mml:math>
</inline-formula>, then <inline-formula id="ieqn-38">
<mml:math id="mml-ieqn-38"><mml:mi>&#x03C1;</mml:mi><mml:mo>=</mml:mo><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mi>y</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo>+</mml:mo><mml:mrow><mml:mfrac><mml:mrow><mml:msup><mml:mi>&#x03C0;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mi>x</mml:mi></mml:mfrac></mml:mrow><mml:mspace width="thinmathspace" /><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math>
</inline-formula>, that is, (<italic>&#x03C1;</italic>&#x2009;&#x002B;&#x2009;<italic>&#x03B8;</italic><sup>&#x2032;</sup>(<italic>&#x03B1;</italic>&#x2009;&#x2212;&#x2009;<italic>k</italic><sub>2</sub>))<italic>x</italic>&#x2009;&#x003D;&#x2009;&#x2212;<italic>xy</italic><sup>&#x2032;</sup>&#x2009;&#x002B;&#x2009;<italic>&#x03C0;</italic><sup>&#x2032;</sup>. In this case, the adversary can output <inline-formula id="ieqn-39">
<mml:math id="mml-ieqn-39"><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03C1;</mml:mi><mml:mo>+</mml:mo><mml:msup><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mi>x</mml:mi></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:msup><mml:mi>&#x03F5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mi>y</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math>
</inline-formula>. If the adversary knows the value of <italic>&#x03B8;</italic><sup>&#x2032;</sup>, he can get <inline-formula id="ieqn-40">
<mml:math id="mml-ieqn-40"><mml:mo stretchy="false">(</mml:mo><mml:mi>v</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>&#x03F5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>r</mml:mi></mml:mrow></mml:msup><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:msup><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>&#x03B7;</mml:mi><mml:mi>x</mml:mi></mml:msup><mml:mo>=</mml:mo><mml:msup><mml:mi>&#x03F5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mi>y</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math>
</inline-formula>. That is, given <italic>g</italic> and <italic>g</italic><sup><italic>x</italic></sup>, where <italic>x</italic> is unknown, the adversary can solve the Static Diffie-Hellman problem with instance <inline-formula id="ieqn-41">
<mml:math id="mml-ieqn-41"><mml:mstyle displaystyle="true" scriptlevel="0"><mml:msup><mml:mi>u</mml:mi><mml:mi>x</mml:mi></mml:msup><mml:mo>=</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mrow><mml:mfrac><mml:mrow><mml:msup><mml:mi>&#x03F5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mi>y</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>v</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>&#x03F5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>r</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:msup><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:msup></mml:mrow></mml:mfrac></mml:mrow></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:msup><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:msub><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>C</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mi>H</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo fence="false" stretchy="false">|</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:msup></mml:mstyle></mml:math>
</inline-formula>. If the adversary does not know the value of <italic>&#x03B8;</italic><sup>&#x2032;</sup>, TA gives the adversary <inline-formula id="ieqn-42">
<mml:math id="mml-ieqn-42"><mml:msup><mml:mi>&#x03BE;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:mi>&#x03B7;</mml:mi><mml:mo>=</mml:mo><mml:msup><mml:mi>g</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03C1;</mml:mi><mml:mo>+</mml:mo><mml:msup><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:math>
</inline-formula> and &#x025B;&#x2009;&#x003D;&#x2009;<italic>g</italic><sup><italic>x</italic></sup>, where the adversary does not know <italic>x</italic> and <italic>&#x03C1;</italic>&#x2009;&#x002B;&#x2009;<italic>&#x03B8;</italic><sup>&#x2032;</sup>(<italic>&#x03B1;</italic>&#x2009;&#x2212;&#x2009;<italic>k</italic><sub>2</sub>), and the adversary can solve the CDH problem with instance <inline-formula id="ieqn-43">
<mml:math id="mml-ieqn-43"><mml:msup><mml:mi>&#x03F5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mi>y</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:msup><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math>
</inline-formula>. Obviously, <italic>&#x03C3;</italic><sup>&#x2032;</sup>&#x2009;&#x003D;&#x2009;<italic>&#x03C3;</italic>.</p>
<p>Game 3: Game 3 is the same as Game 2, with the following differences: As before, the challenger observes the proof of retrievability protocol instance. Suppose the document that caused the abort was the signature &#x007B;<italic>&#x03C3;</italic><sub><italic>i</italic></sub>&#x007D;, and suppose <italic>Q</italic>&#x2009;&#x003D;&#x2009;(<italic>a</italic><sub><italic>i</italic></sub>, <italic>b</italic><sub><italic>i</italic></sub>) was the query that caused the challenger to abort, and the adversary&#x2019;s response to that query was <italic>P</italic><sup>&#x2032;</sup>&#x2009;&#x003D;&#x2009;(<italic>&#x03C3;</italic><sup>&#x2032;</sup>, <italic>&#x03BE;</italic><sup>&#x2032;</sup>, <italic>y</italic><sup>&#x2032;</sup>). Let <italic>P</italic>&#x2009;&#x003D;&#x2009;(<italic>&#x03C3;</italic>, <italic>&#x03BE;</italic>, <italic>y</italic>) be the expected response from an honest prover. We have already proved in game 2 that <italic>&#x03C3;</italic><sup>&#x2032;</sup>&#x2009;&#x003D;&#x2009;<italic>&#x03C3;</italic>, that is, only <inline-formula id="ieqn-44">
<mml:math id="mml-ieqn-44"><mml:msubsup><mml:mi>b</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math>
</inline-formula> and <italic>b</italic><sub><italic>i</italic></sub> can be different, i.e., (<italic>&#x03BE;</italic><sup>&#x2032;</sup>, <italic>y</italic><sup>&#x2032;</sup>) and (<italic>&#x03BE;</italic>, <italic>y</italic>) can be different. Defining &#x0394;<italic>&#x03BE;</italic>&#x2009;&#x003D;&#x2009;<italic>&#x03BE;</italic><sup>&#x2032;</sup>&#x2009;&#x2212;&#x2009;<italic>&#x03BE;</italic>, &#x0394;<italic>y</italic>&#x2009;&#x003D;&#x2009;<italic>y</italic><sup>&#x2032;</sup>&#x2009;&#x2212;&#x2009;<italic>y</italic>, the simulator answers the adversary&#x2019;s query. Finally, the adversary outputs a fake proof <italic>P</italic><sup>&#x2032;</sup>&#x2009;&#x003D;&#x2009;(<italic>&#x03C3;</italic><sup>&#x2032;</sup>, <italic>&#x03BE;</italic><sup>&#x2032;</sup>, <italic>y</italic><sup>&#x2032;</sup>).</p>
</sec>
<sec id="s5_3">
<label>5.3</label>
<title>Privacy Protection</title>
<p><italic>Theorem</italic> 5: The signer of the file identification in the scheme has unconditional anonymity, that is, for any algorithm <italic>A</italic>, any set of users <italic>R</italic>&#x2009;&#x003D;&#x2009;<italic>pk</italic><sub>1</sub>, <italic>pk</italic><sub>2</sub>, &#x2026;, <italic>pk</italic><sub><italic>n</italic></sub>, the probability <italic>P</italic>[<italic>pk</italic>&#x2009;&#x003D;&#x2009;<italic>pk</italic><sup>&#x2032;</sup>] is all 1/2, where <inline-formula id="ieqn-45">
<mml:math id="mml-ieqn-45"><mml:msub><mml:mi>T</mml:mi><mml:mi>&#x03C3;</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>I</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>c</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>c</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>c</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>c</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>d</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>d</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>d</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>d</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math>
</inline-formula> is the ring signature generated by <italic>pk</italic><sub><italic>s</italic></sub>.</p>
<p><italic>Proof</italic>:</p>
<p>The output signature is obscured to any third party until the signer actively discloses all information. In the ring signature generation algorithm <italic>Aring</italic>, the <italic>L</italic><sub><italic>i</italic></sub> and <italic>R</italic><sub><italic>i</italic></sub> values required to calculate <italic>c</italic><sub><italic>i</italic></sub> and <italic>e</italic><sub><italic>i</italic></sub> are calculated by the signer by randomly selecting the corresponding <inline-formula id="ieqn-46">
<mml:math id="mml-ieqn-46"><mml:msub><mml:mi>u</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>v</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="thickmathspace" /><mml:msub><mml:mi>w</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math>
</inline-formula>, and the signer&#x2019;s private key is also randomly selected to obtain <inline-formula id="ieqn-47">
<mml:math id="mml-ieqn-47"><mml:mi>s</mml:mi><mml:msub><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mi>Z</mml:mi><mml:mi>q</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup></mml:math>
</inline-formula>. So, the result of signature <inline-formula id="ieqn-48">
<mml:math id="mml-ieqn-48"><mml:msub><mml:mi>T</mml:mi><mml:mi>&#x03C3;</mml:mi></mml:msub></mml:math>
</inline-formula> is uniformly distributed in G. The probability of members outside the ring guessing the actual signer is not more than 1/(<italic>n</italic>&#x2009;&#x002B;&#x2009;1), and the probability of members in the ring guessing the actual signer is not more than 1/<italic>n</italic>, so this signature scheme complies with unconditional anonymity.</p>
</sec>
</sec>
<sec id="s6">
<label>6</label>
<title>Performance Analysis</title>
<p>In this section, we evaluate the experimental results in terms of storage overhead, computation overhead, and communication overhead to show the efficiency of our proposed consensus scheme. The simulated experiments were run on a laptop with Intel i7&#x2013;7500U CPU @ 2.70&#x2005;GHz. and 8 GB RAM. We simulated a prototype of the scheme in C language, based on the free Pairing-Based Cryptography (PBC) Library. Next, we compare the performance of the proposed scheme with Scheme [<xref ref-type="bibr" rid="ref-38">38</xref>] and Scheme [<xref ref-type="bibr" rid="ref-39">39</xref>] from the aspects of storage overhead, computational overhead, and communication overhead.</p>
<sec id="s6_1">
<label>6.1</label>
<title>Storage Overhead</title>
<p><xref ref-type="fig" rid="fig-2">Fig. 2</xref> shows the relationship between the number of data owners and the storage overhead between storage nodes. In our proposed consensus protocol, storage nodes keep only one file copy for duplicate data. That is, the storage node always maintains only one copy of the file, even if the number of data owners is increasing [<xref ref-type="bibr" rid="ref-40">40</xref>]. Compared with the SW scheme or other schemes, our consensus protocol has lower storage overhead.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>The relationship between the number of data owners and the storage cost</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="IASC_29657-fig-2.png"/>
</fig>
</sec>
<sec id="s6_2">
<label>6.2</label>
<title>Computational Overhead</title>
<p>The consensus protocol we propose has three algorithms in the audit phase: Challenge, Prove, and Verify. Concepts used in the scheme we give definitions in <xref ref-type="table" rid="table-2">Tab. 2</xref> and experimental results in <xref ref-type="fig" rid="fig-3">Fig. 3</xref> to visually describe the computational overhead of these three algorithms. During the integrity verification audit process, the third party runs the challenge algorithm and sends the challenge information to the CSP at a negligible cost. After receiving the challenge value, the CSP performs (<italic>k</italic>&#x2009;&#x002B;&#x2009;<italic>s</italic>&#x2009;&#x2212;&#x2009;1)<italic>MUL</italic> and (<italic>s</italic>&#x2009;&#x002B;&#x2009;<italic>k</italic>)<italic>EXP</italic> operations to generate the storage proof. After that, the computational complexity of the third-party audit proof is <italic>O</italic>(1)<italic>MUL</italic>&#x2009;&#x002B;&#x2009;<italic>O</italic>(1)<italic>EXP</italic>&#x2009;&#x002B;&#x2009;<italic>O</italic>(1)<italic>Pair</italic>. In addition, in the deduplication stage, the user does not need any computational overhead, and the computational complexity of the operation that the user needs to perform is <italic>O</italic>(<italic>s</italic>&#x2009;&#x002B;&#x2009;<italic>d</italic>)<italic>MUL</italic>&#x2009;&#x002B;&#x2009;<italic>O</italic>(<italic>s</italic>)<italic>EXP</italic>&#x2009;&#x002B;&#x2009;<italic>O</italic>(1)<italic>Pair</italic>. In the experiments, we choose to challenge the number of blocks from 1 to 1000. When the number of challenges is 1, the running time of the <italic>Challenge</italic> algorithm is the least, which is 0.016&#x2005;s, and it reaches 0.216&#x2005;s when the number of challenges grows to 1000. In the Prove algorithm, when the number of challenge blocks is increased from 200 to 1000, the running time increases from 0.346&#x2005;s to 3.879&#x2005;s. In the Verify algorithm, the running time required to challenge 1000 blocks is 10.347&#x2005;s, which takes the most time among these algorithms. It can be concluded that during the audit process, the computational cost is linearly related to the number of challenge blocks [<xref ref-type="bibr" rid="ref-41">41</xref>]. <xref ref-type="fig" rid="fig-3">Fig. 3</xref> shows that the computational cost of the three algorithms <italic>Challenge</italic>, <italic>Prove</italic>, and <italic>Verify</italic> varies with the number of challenge blocks.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>The relationship between computational overhead and number of challenge blocks</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="IASC_29657-fig-3.png"/>
</fig>
<table-wrap id="table-2"><label>Table 2</label>
<caption>
<title>The definition of symbols</title></caption>
<table><colgroup><col align="left"/><col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Symbol</th>
<th align="left">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left"><italic>n</italic></td>
<td align="left">The number of encoded file blocks</td>
</tr>
<tr>
<td align="left"><italic>k</italic></td>
<td align="left">The number of elements that each block contains</td>
</tr>
<tr>
<td align="left"><italic>s</italic></td>
<td align="left">The number of challenge blocks</td>
</tr>
<tr>
<td align="left"><italic>EXP</italic></td>
<td align="left">One multiplication operation</td>
</tr>
<tr>
<td align="left"><italic>MUL</italic></td>
<td align="left">One exponentiation operation</td>
</tr>
<tr>
<td align="left"><italic>Pair</italic></td>
<td align="left">One pairing operation</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s6_3">
<label>6.3</label>
<title>Communication Overhead</title>
<p>In our proposed consensus protocol, the algorithm in the audit phase does not bring communication overhead to users. At the same time, if the storage node has a copy of the storage file, the communication overhead with the data owner will be less than that without a copy of the storage file. <xref ref-type="fig" rid="fig-4">Fig. 4</xref> shows the change in communication time between the number of challenge blocks from 200 to 1000, as the number of challenge blocks increases during the audit process. Scheme [<xref ref-type="bibr" rid="ref-38">38</xref>], scheme [<xref ref-type="bibr" rid="ref-39">39</xref>] and our proposed scheme all have an upward trend in communication time, and our scheme has more advantages than them in communication time.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>The relationship between communication overhead and number of challenge blocks</title></caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="IASC_29657-fig-4.png"/>
</fig>
</sec>
</sec>
<sec id="s7">
<label>7</label>
<title>Conclusion</title>
<p>In this paper, we propose a blockchain consensus protocol suitable for distributed storage, which utilizes verifiable computation instead of a trust mechanism to solve the problems of existing distributed storage in blockchain platforms. In addition, the proof of retrievability with data deduplication technology can optimize data auditing and storage space while ensuring storage security, which greatly improves the efficiency and scalability of the scheme. Finally, the ring signature algorithm is used in the scheme to ensure user anonymity and file unlinkability, preventing privacy leakage and brute force attacks. In conclusion, this scheme is of great significance for improving the practicability of distributed storage services on the blockchain.</p>
</sec>
</body>
<back><fn-group>
<fn fn-type="other">
<p><bold>Funding Statement:</bold> This work was supported by the National Natural Science Foundation of China (No. 62072249, 62032025), Yongjun Ren received the grant and the URLs to sponsors&#x2019; websites is <uri xlink:href="https://www.nsfc.gov.cn/">https://www.nsfc.gov.cn/</uri>. This work was also supported by the Guangdong Basic and Applied Basic Research Foundation (No. 2021A1515012650). Hao Wang received the Grant and the URLs to sponsors&#x2019; websites is <uri xlink:href="http://gdstc.gd.gov.cn/">http://gdstc.gd.gov.cn/</uri>.</p>
</fn>
<fn fn-type="conflict">
<p><bold>Conflicts of Interest:</bold> The authors declare that they have no conflicts of interest to report regarding the present study.</p>
</fn>
</fn-group>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Leong</surname></string-name>, <string-name><given-names>A. G.</given-names> <surname>Dimakis</surname></string-name> and <string-name><given-names>T.</given-names> <surname>Ho</surname></string-name></person-group>, &#x201C;<article-title>Distributed storage allocations</article-title>,&#x201D; <source>IEEE Transactions on Information Theory</source>, vol. <volume>58</volume>, no. <issue>7</issue>, pp. <fpage>4733</fpage>&#x2013;<lpage>4752</lpage>, <year>2012</year>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Hei</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Liang</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Liang</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Liu</surname></string-name> and <string-name><given-names>K. W.</given-names> <surname>Ross</surname></string-name></person-group>, &#x201C;<article-title>A measurement study of a large-scale P2P IPTV system</article-title>,&#x201D; <source>IEEE Transactions on Multimedia</source>, vol. <volume>9</volume>, no. <issue>8</issue>, pp. <fpage>1672</fpage>&#x2013;<lpage>1687</lpage>, <year>2007</year>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Xue</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Yuan</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Ahmed</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Moniz</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Cao</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Proof of contribution: A modification of proof of work to increase mining efficiency</article-title>,&#x201D; in <conf-name>Proc. 2018 IEEE 42nd Annual Computer Software &#x0026; Applications Conf. (COMPSAC)</conf-name>, <conf-loc>Tokyo, Japan</conf-loc>, pp. <fpage>636</fpage>&#x2013;<lpage>644</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X. R.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Sun</surname></string-name>, <string-name><given-names>X. M.</given-names> <surname>Sun</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Sun</surname></string-name> and <string-name><given-names>S. K.</given-names> <surname>Jha</surname></string-name></person-group>, &#x201C;<article-title>Robust reversible audio watermarking scheme for telemedicine and privacy protection</article-title>,&#x201D; <source>Computers, Materials &#x0026; Continua</source>, vol. <volume>71</volume>, no. <issue>2</issue>, pp. <fpage>3035</fpage>&#x2013;<lpage>3050</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y. J.</given-names> <surname>Ren</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Leng</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Qi</surname></string-name>, <string-name><given-names>K. S.</given-names> <surname>Pradip</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Wang</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Multiple cloud storage mechanism based on blockchain in smart homes</article-title>,&#x201D; <source>Future Generation Computer Systems</source>, vol. <volume>115</volume>, pp. <fpage>304</fpage>&#x2013;<lpage>313</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C. P.</given-names> <surname>Ge</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>J. Y.</given-names> <surname>Xia</surname></string-name> and <string-name><given-names>L. M.</given-names> <surname>Fang</surname></string-name></person-group>, &#x201C;<article-title>Revocable identity-based broadcast proxy re-encryption for data sharing in clouds</article-title>,&#x201D; <source>IEEE Transactions on Dependable &#x0026; Secure Computing</source>, vol. <volume>18</volume>, no. <issue>3</issue>, pp. <fpage>1214</fpage>&#x2013;<lpage>1226</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L. M.</given-names> <surname>Fang</surname></string-name>, <string-name><given-names>M. H.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>C. T.</given-names> <surname>Lin</surname></string-name>, <string-name><given-names>S. L.</given-names> <surname>Ji</surname></string-name> <etal>et al.,</etal></person-group>&#x201C;<article-title>A secure and authenticated mobile payment protocol against off-site attack strategy</article-title>,&#x201D; <source>IEEE Transactions on Dependable &#x0026; Secure Computing</source>, vol. <volume>21</volume>, no. <issue>8</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>12</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>G.</given-names> <surname>Ateniese</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Burns</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Curtmola</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Herring</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Kissner</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Provable data possession at untrusted stores</article-title>,&#x201D; in <conf-name>Proc. of the 14th ACM Conf. on Computer &#x0026; Communications Security</conf-name>, <conf-loc>Alexandria Virginia, USA</conf-loc>, pp. <fpage>598</fpage>&#x2013;<lpage>609</lpage>, <year>2007</year>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Juels</surname></string-name> and <string-name><given-names>B. S.</given-names> <surname>Kaliski</surname> <suffix>Jr</suffix></string-name></person-group>, &#x201C;<article-title>PORs: Proofs of retrievability for large files</article-title>,&#x201D; in <conf-name>Proc. of the 14th ACM Conf. on Computer &#x0026; Communications Security</conf-name>, <conf-loc>Alexandria Virginia, USA</conf-loc>, pp. <fpage>584</fpage>&#x2013;<lpage>597</lpage>, <year>2007</year>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Yang</surname></string-name> and <string-name><given-names>X.</given-names> <surname>Jia</surname></string-name></person-group>, &#x201C;<article-title>An efficient and secure dynamic auditing protocol for data storage in cloud computing</article-title>,&#x201D; <source>IEEE Transactions on Parallel &#x0026; Distributed Systems</source>, vol. <volume>24</volume>, no. <issue>9</issue>, pp. <fpage>1717</fpage>&#x2013;<lpage>1726</lpage>, <year>2012</year>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Hiremath</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Kunte</surname></string-name></person-group>, &#x201C;<article-title>A novel data auditing approach to achieve data privacy and data integrity in cloud computing</article-title>,&#x201D; in <conf-name>Proc. 2017 Int. Conf. on Electrical, Electronics, Communication, Computer, and Optimization Techniques (ICEECCOT)</conf-name>, <conf-loc>Mysuru, India</conf-loc>, pp. <fpage>306</fpage>&#x2013;<lpage>310</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Han</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Li</surname></string-name> and <string-name><given-names>W.</given-names> <surname>Chen</surname></string-name></person-group>, &#x201C;<article-title>A lightweight and privacy-preserving public cloud auditing scheme without bilinear pairings in smart cities</article-title>,&#x201D; <source>Computer Standards &#x0026; Interfaces</source>, vol. <volume>62</volume>, pp. <fpage>84</fpage>&#x2013;<lpage>97</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Liu</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Han</surname></string-name></person-group>, &#x201C;<article-title>Proofs of retrievability from linearly homomorphic structure-preserving signatures</article-title>,&#x201D; <source>International Journal of Information &#x0026; Computer Security</source>, vol. <volume>11</volume>, no. <issue>2</issue>, pp. <fpage>178</fpage>&#x2013;<lpage>202</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Yu</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Du</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Guizani</surname></string-name></person-group>, &#x201C;<article-title>Integritychain: Provable data possession for decentralized storage</article-title>,&#x201D; <source>IEEE Journal on Selected Areas in Communications</source>, vol. <volume>38</volume>, no. <issue>6</issue>, pp. <fpage>1205</fpage>&#x2013;<lpage>1217</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Nakamoto</surname></string-name></person-group>, &#x201C;<article-title>Bitcoin: A peer-to-peer electronic cash system</article-title>,&#x201D; <source>Decentralized Business Review</source>, vol. 4, pp. <fpage>21260</fpage>, <year>2008</year>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Han</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>S. M.</given-names> <surname>He</surname></string-name>, <string-name><given-names>P. K.</given-names> <surname>Sharma</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Multiple strategies differential privacy on sparse tensor factorization for network traffic analysis in 5G</article-title>,&#x201D; <source>IEEE Transactions on Industrial Informatics</source>, vol. <volume>18</volume>, no. <issue>3</issue>, pp. <fpage>1939</fpage>&#x2013;<lpage>1948</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y. J.</given-names> <surname>Ren</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Leng</surname></string-name>, <string-name><given-names>Y. P.</given-names> <surname>Cheng</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Wang</surname></string-name></person-group>, &#x201C;<article-title>Secure data storage based on blockchain and coding in edge computing</article-title>,&#x201D; <source>Mathematical Biosciences &#x0026; Engineering</source>, vol. <volume>16</volume>, no. <issue>4</issue>, pp. <fpage>1874</fpage>&#x2013;<lpage>1892</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C. P.</given-names> <surname>Ge</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Susilo</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>J. Y.</given-names> <surname>Xia</surname></string-name>, <string-name><given-names>L. M.</given-names> <surname>Fang</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Secure keyword search and data sharing mechanism for cloud computing</article-title>,&#x201D; <source>IEEE Transactions on Dependable &#x0026; Secure Computing</source>, vol. <volume>18</volume>, no. <issue>6</issue>, pp. <fpage>2787</fpage>&#x2013;<lpage>2800</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Miller</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Juels</surname></string-name>, <string-name><given-names>E.</given-names> <surname>Shi</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Parno</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Katz</surname></string-name></person-group>, &#x201C;<article-title>Permacoin: Repurposing bitcoin work for data preservation</article-title>,&#x201D; in <conf-name>Proc. 2014 IEEE Symp. on Security &#x0026; Privacy</conf-name>, <conf-loc>Berkeley, CA, USA</conf-loc>, pp. <fpage>475</fpage>&#x2013;<lpage>490</lpage>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Hao</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Xin</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Jiang</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Wang</surname></string-name></person-group>, &#x201C;<article-title>Decentralized data integrity verification model in untrusted environment</article-title>,&#x201D; in <conf-name>Proc. Asia-Pacific Web (APWeb) and Web-age Information Management (WAIM) Joint Int. Conf. on Web &#x0026; Big Data</conf-name>, <conf-loc>Macau, China</conf-loc>, pp. <fpage>410</fpage>&#x2013;<lpage>424</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Francati</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Ateniese</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Faye</surname></string-name>, <string-name><given-names>A. M.</given-names> <surname>Milazzo</surname></string-name>, <string-name><given-names>A. M.</given-names> <surname>Perillo</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Audita: A blockchain-based auditing framework for off-chain storage</article-title>,&#x201D; in <conf-name>Proc. of the 9th Int. Workshop on Security in Blockchain &#x0026; Cloud Computing</conf-name>, <conf-loc>Virtual Event Hong Kong</conf-loc>, pp. <fpage>5</fpage>&#x2013;<lpage>10</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C. P.</given-names> <surname>Ge</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Susilo</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Baek</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>J. Y.</given-names> <surname>Xia</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Revocable attribute-based encryption with data integrity in clouds</article-title>,&#x201D; <source>IEEE Transactions on Dependable &#x0026; Secure Computing</source>, vol. <volume>99</volume>, pp. <fpage>1</fpage>&#x2013;<lpage>1</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>C. Y.</given-names> <surname>Jin</surname></string-name>, <string-name><given-names>Q.</given-names> <surname>Tang</surname></string-name>, <string-name><given-names>N. X.</given-names> <surname>Xiong</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Srivastava</surname></string-name></person-group>, &#x201C;<article-title>Intelligent ubiquitous network accessibility for wireless-powered MEC in UAV-assisted B5G</article-title>,&#x201D; <source>IEEE Transactions on Network Science &#x0026; Engineering</source>, vol. <volume>8</volume>, no. <issue>4</issue>, pp. <fpage>2801</fpage>&#x2013;<lpage>2813</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y. J.</given-names> <surname>Ren</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Zhu</surname></string-name>, <string-name><given-names>Y. Q.</given-names> <surname>Gao</surname></string-name>, <string-name><given-names>J. Y.</given-names> <surname>Xia</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Zhou</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Long-term preservation of electronic record based on digital continuity in smart cities</article-title>,&#x201D; <source>Computers, Materials &#x0026; Continua</source>, vol. <volume>66</volume>, no. <issue>3</issue>, pp. <fpage>3271</fpage>&#x2013;<lpage>3287</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G.</given-names> <surname>Xiao</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>W.</given-names> <surname>He</surname></string-name>, <string-name><given-names>A. Y.</given-names> <surname>Zomaya</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Caspmv: A customized and accelerative spmv framework for the sunway taihulight</article-title>,&#x201D; <source>IEEE Transactions on Parallel &#x0026; Distributed Systems</source>, vol. <volume>32</volume>, no. <issue>1</issue>, pp. <fpage>131</fpage>&#x2013;<lpage>146</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Xiaoyong</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Zeng</surname></string-name> and <string-name><given-names>B.</given-names> <surname>Veeravalli</surname></string-name></person-group>, &#x201C;<article-title>A novel security-driven scheduling algorithm for precedence constrained tasks in heterogeneous distributed systems</article-title>,&#x201D; <source>IEEE Transactions on Computers</source>, vol. <volume>60</volume>, no. <issue>7</issue>, pp. <fpage>1017</fpage>&#x2013;<lpage>1029</lpage>, <year>2010</year>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Xu</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Feng</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Ren</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Front-end control mechanism of electronic records</article-title>,&#x201D; <source>Computer Systems Science &#x0026; Engineering</source>, vol. <volume>39</volume>, no. <issue>3</issue>, pp. <fpage>337</fpage>&#x2013;<lpage>349</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y. J.</given-names> <surname>Ren</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Qi</surname></string-name>, <string-name><given-names>Y. P.</given-names> <surname>Cheng</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Wang</surname></string-name> and <string-name><given-names>O.</given-names> <surname>Alfarraj</surname></string-name></person-group>, &#x201C;<article-title>Digital continuity guarantee approach of electronic record based on data quality theory</article-title>,&#x201D; <source>Computers, Materials &#x0026; Continua</source>, vol. <volume>63</volume>, no. <issue>3</issue>, pp. <fpage>1471</fpage>&#x2013;<lpage>1483</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C. P.</given-names> <surname>Ge</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Susilo</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Baek</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>J. Y.</given-names> <surname>Xia</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>A verifiable and fair attribute-based proxy re-encryption scheme for data sharing in clouds</article-title>,&#x201D; <source>IEEE Transactions on Dependable &#x0026; Secure Computing</source>, vol. <volume>21</volume>, no. <issue>7</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>12</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y. J.</given-names> <surname>Ren</surname></string-name>, <string-name><given-names>F. J.</given-names> <surname>Zhu</surname></string-name>, <string-name><given-names>S. P.</given-names> <surname>Kumar</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Wang</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Data query mechanism based on hash computing power of blockchain in internet of things</article-title>,&#x201D; <source>Sensors</source>, vol. <volume>20</volume>, no. <issue>1</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>22</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Q.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Ren</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Lou</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>Enabling public auditability and data dynamics for storage security in cloud computing</article-title>,&#x201D; <source>IEEE Transactions on Parallel &#x0026; Distributed Systems</source>, vol. <volume>22</volume>, no. <issue>5</issue>, pp. <fpage>847</fpage>&#x2013;<lpage>859</lpage>, <year>2010</year>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y. J.</given-names> <surname>Ren</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Zhu</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Sharma</surname></string-name> and <string-name><given-names>U.</given-names> <surname>Ghosh</surname></string-name></person-group>, &#x201C;<article-title>Novel vote scheme for decision-making feedback based on blockchain in internet of vehicles</article-title>,&#x201D; <source>IEEE Transactions on Intelligent Transportation Systems</source>, vol. <volume>23</volume>, no. <issue>2</issue>, pp. <fpage>1639</fpage>&#x2013;<lpage>1648</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Tang</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Bilal</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Yu</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>A parallel random forest algorithm for big data in a spark cloud computing environment</article-title>,&#x201D; <source>IEEE Transactions on Parallel &#x0026; Distributed Systems</source>, vol. <volume>28</volume>, no. <issue>4</issue>, pp. <fpage>919</fpage>&#x2013;<lpage>933</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Zhou</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Zhou</surname></string-name> and <string-name><given-names>K.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>Adaptive processing for distributed skyline queries over uncertain data</article-title>,&#x201D; <source>IEEE Transactions on Knowledge &#x0026; Data Engineering</source>, vol. <volume>28</volume>, no. <issue>2</issue>, pp. <fpage>371</fpage>&#x2013;<lpage>384</lpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X. R.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>W. F.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Sun</surname></string-name>, <string-name><given-names>X. M.</given-names> <surname>Sun</surname></string-name> and <string-name><given-names>S. K.</given-names> <surname>Jha</surname></string-name></person-group>, &#x201C;<article-title>A robust 3-D medical watermarking based on wavelet transform for data protection</article-title>,&#x201D; <source>Computer Systems Science &#x0026; Engineering</source>, vol. <volume>41</volume>, no. <issue>3</issue>, pp. <fpage>1043</fpage>&#x2013;<lpage>1056</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="journal">R. L. Rivest, A. Shamir, and Y. Tauman, &#x201C;How toleak a secret,&#x201D; in <italic>Proc. Int. Conf. on the Theory &#x0026; Application of Cryptology &#x0026; Information Security</italic>, Melbourne, Australia, pp. 552&#x2013;565, 2001.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Li</surname></string-name> and <string-name><given-names>K.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>A game approach to multi-servers load balancing with load-dependent server availability consideration</article-title>,&#x201D; <source>IEEE Transactions on Cloud Computing</source>, vol. <volume>9</volume>, no. <issue>1</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>13</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Shacham</surname></string-name> and <string-name><given-names>B.</given-names> <surname>Waters</surname></string-name></person-group>, &#x201C;<article-title>Compact proofs of retrievability</article-title>,&#x201D; in <conf-name>Proc. Int. Conf. on the Theory &#x0026; Application of Cryptology &#x0026; Information Security</conf-name>, <conf-loc>Melbourne, Australia</conf-loc>, pp. <fpage>90</fpage>&#x2013;<lpage>107</lpage>, <year>2008</year>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Yu</surname></string-name>, <string-name><given-names>M. H.</given-names> <surname>Au</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Ateniese</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Huang</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Susilo</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Identity-based remote data integrity checking with perfect data privacy preserving for cloud storage</article-title>,&#x201D; <source>IEEE Transactions on Information Forensics &#x0026; Security</source>, vol. <volume>12</volume>, no. <issue>4</issue>, pp. <fpage>767</fpage>&#x2013;<lpage>778</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y. J.</given-names> <surname>Ren</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Qi</surname></string-name>, <string-name><given-names>Y. P.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Wang</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Kim</surname></string-name></person-group>, &#x201C;<article-title>Integrity verification mechanism of sensor data based on bilinear map accumulator</article-title>,&#x201D; <source>ACM Transactions on Internet Technology</source>, vol. <volume>21</volume>, no. <issue>1</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>20</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>N. P.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>Q.</given-names> <surname>Qian</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Xu</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Ren</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Inversion of temperature and humidity profile of microwave radiometer based on bp network</article-title>,&#x201D; <source>Intelligent Automation &#x0026; Soft Computing</source>, vol. <volume>29</volume>, no. <issue>3</issue>, pp. <fpage>741</fpage>&#x2013;<lpage>755</lpage>, <year>2021</year>.</mixed-citation></ref>
</ref-list>
</back>
</article>