We create the first compact and provably secure proof of retrievability systems. Our solutions allow for compact proofs with just one authenticator value -- in practice this can lead to proofs with as little as 40 bytes of communication. We present two solutions with similar structure. The first one is privately verifiable and builds elegantly on pseudorandom functions (PRFs); the second allows for publicly verifiable proofs and is built from the signature scheme of Boneh, Lynn, and Shacham in bilinear groups. Both solutions rely on homomorphic properties to aggregate a proof into one small authenticator value.
Category / Keywords: cryptographic protocols / storage, retrievability, homomorphic authenticators Publication Info: Extended abstract to appear in Proc. Asiacrypt 2008. Date: received 17 Feb 2008, last revised 11 Jan 2011 Contact author: hovav at cs ucsd edu Available formats: PDF | BibTeX Citation Version: 20110112:015736 (All versions of this report) Discussion forum: Show discussion | Start new discussion