Cloud computing has become the default medium for storing and sharing large, AI-relevant datasets among organisations, employees, and third-party data consumers. As data ownership increasingly moves between multiple stakeholders rather than a single custodian, existing cloud auditing techniques—largely built around Provable Data Possession (PDP) and Proof of Retrievability (POR)—struggle to provide secure, efficient, and scalable ownership management for group-based data transactions.
This paper surveys recent literature (2020-2025) on cloud data auditing, public and privacy-preserving auditing, dynamic data auditing, blockchain-assisted auditing, and ownership transfer mechanisms, with particular emphasis on the recently published scalable cloud auditing protocol with efficient ownership transfer for group transactions. Sixteen representative works are reviewed and compared across technique, advantages, and limitations, revealing recurring weaknesses: quadratic computational overhead when handling dynamic group membership, secret-key exposure during ownership transfer that enables collusion attacks, dependence on fully trusted third parties, and poor support for partial ownership transfer within a shared group. Building on these findings, this paper outlines a research direction for a Cloud-Based Auditing System with Efficient Ownership Management that employs BLS aggregate signatures with hash-bound key pairs, random-mask-protected index keys, and a Third-Party Auditor (TPA) model involving a Sale Group (SG) and a Buy Group (BG) to achieve linear-time ownership modification, resistance to rogue-key and collusion attacks, and low-cost partial or full ownership transfer, without full reliance on a trusted authority.
Introduction
The text presents a literature survey on secure cloud data auditing, multi-owner data management, and ownership transfer, particularly for large AI datasets stored in cloud platforms. As datasets are increasingly shared between employees, research groups, and organizations, verifying data integrity without downloading the entire dataset has become important. Provable Data Possession (PDP) and Proof of Retrievability (POR) enable cloud users to verify data integrity remotely with lower bandwidth and computation requirements.
However, traditional PDP/POR schemes were mainly designed for single data owners. They face difficulties when data ownership is shared among groups or when members are added, revoked, or transferred to another group. Some existing approaches also expose secret information during ownership transfer, creating risks of collusion attacks between dishonest users and cloud service providers.
The survey reviews 16 research works published mainly between 2020 and 2025. These studies cover several areas:
PDP and POR: Provide remote data-integrity verification without downloading complete datasets.
Dynamic and privacy-preserving auditing: Support data updates while protecting data contents and user identities.
Data Transferable PDP (DT-PDP): Enables ownership transfer using cryptographic tokens and signatures.
Blockchain-based auditing: Provides transparent and immutable records of ownership and user revocation.
Identity-based and certificateless cryptography: Reduces certificate-management requirements.
Deduplication and keyword-based auditing: Improve storage efficiency and allow selective data verification.
Privacy-preserving and batch auditing: Enable multiple owners or datasets to be audited efficiently.
The reviewed studies demonstrate significant improvements in privacy, scalability, revocation, dynamic data management, and ownership transfer, but they also have important limitations. These include high computational costs, pairing operations, blockchain latency, complex indexing, dependence on trusted Third-Party Auditors (TPAs) or Private Key Generators, and limited support for complete group-to-group ownership transfer.
The comparative analysis identifies two major research gaps. First, schemes that provide greater security and functionality generally introduce higher computational, communication, or storage overhead. Second, many systems still depend on trusted third parties, which conflicts with the goal of secure auditing in semi-trusted or untrusted cloud environments.
Proposed Research Direction
To address these limitations, the paper proposes a scalable and collusion-resistant group-oriented cloud auditing and ownership-management system based on:
BLS aggregate signatures for efficient verification of multiple owners.
Hash-bound public keys to protect against rogue-key attacks.
Random index masking to improve privacy and prevent information leakage.
Group-based ownership management to support partial ownership transfer without unnecessarily affecting other group members.
Conclusion
This survey reviewed sixteen representative works spanning classical PDP/POR auditing, dynamic and privacy-preserving auditing, identity-based and certificateless schemes, deduplication-aware auditing, blockchain-assisted ownership management, and the recent scalable BLS-based ownership-transfer protocol for group transactions. The comparative analysis shows that, despite substantial progress in data-integrity verification, existing systems continue to struggle with three intertwined problems: scalable multi-owner key management, secure ownership transfer without key leakage, and reduced dependence on fully trusted parties. The proposed direction—built around hash-bound BLS aggregate signatures, random index masking, and an SG/BG/CSP/TPA system model—offers a concrete path toward a cloud auditing system that supports dynamic, group-oriented data ownership with linear scalability and resistance to collusion and rogue-key attacks. Future work will focus on implementing and experimentally validating this design against the computational and communication benchmarks established in the surveyed literature.
References
[1] C. Wu, W. You, and X. Huang, \"Scalable Cloud Auditing With Efficient Ownership Transfer for Group Transactions,\" IEEE Trans. Inf. Forensics Security, vol. 20, pp. 12665-12679, 2025, doi: 10.1109/TIFS.2025.3636056.
[2] Z. Xu, D. He, P. Vijayakumar, B. B. Gupta, and J. Shen, \"Certificateless public auditing scheme with data privacy and dynamics in group user model of cloud-assisted medical WSNs,\" IEEE J. Biomed. Health Informat., vol. 27, no. 5, pp. 2334-2344, May 2023.
[3] W. Shen, C. Gai, J. Yu, and Y. Su, \"Keyword-based remote data integrity auditing supporting full data dynamics,\" IEEE Trans. Services Comput., vol. 17, no. 5, pp. 2516-2529, Sep. 2024.
[4] J. Yu and W. Shen, \"Secure cloud storage auditing with deduplication and efficient data transfer,\" Cluster Comput., vol. 27, no. 2, pp. 2203-2215, Apr. 2024.
[5] X. Peng, W. Shen, Y. Yang, and X. Zhang, \"Secure deduplication and cloud storage auditing with efficient dynamic ownership management and data dynamics,\" IEEE Trans. Netw. Service Manage., vol. 22, no. 4, pp. 3463-3479, Aug. 2025.
[6] Y. Qi, Y. Luo, Y. Huang, and X. Li, \"Blockchain-based privacy-preserving group data auditing with secure user revocation,\" Comput. Syst. Sci. Eng., vol. 45, no. 1, pp. 183-199, 2023.
[7] R. Rabaninejad, M. A. Attari, M. R. Asaar, and M. R. Aref, \"A lightweight auditing service for shared data with secure user revocation in cloud storage,\" IEEE Trans. Services Comput., vol. 15, no. 1, pp. 1-15, Jan. 2022.
[8] X. Zhang, Q. Liu, B. Liu, Y. Zhang, and J. Xue, \"Dynamic certificateless outsourced data auditing mechanism supporting multi-ownership transfer via blockchain systems,\" IEEE Trans. Netw. Service Manage., vol. 22, no. 2, pp. 2017-2030, Apr. 2025.
[9] Y. Zhang, J. Yu, R. Hao, C. Wang, and K. Ren, \"Enabling efficient user revocation in identity-based cloud storage auditing for shared big data,\" IEEE Trans. Dependable Secure Comput., vol. 17, no. 3, pp. 608-619, May 2020.
[10] J. Li, H. Yan, and Y. Zhang, \"Efficient identity-based provable multi-copy data possession in multi-cloud storage,\" IEEE Trans. Cloud Comput., vol. 10, no. 1, pp. 356-365, Jan. 2022.
[11] J. Li, H. Yan, and Y. Zhang, \"Identity-based privacy preserving remote data integrity checking for cloud storage,\" IEEE Syst. J., vol. 15, no. 1, pp. 577-585, Mar. 2021.
[12] C. Gai, W. Shen, M. Yang, and J. Yu, \"PPADT: Privacy-preserving identity-based public auditing with efficient data transfer for cloud-based IoT data,\" IEEE Internet Things J., vol. 10, no. 22, pp. 20065-20079, Nov. 2023.
[13] T. Kavitha, Sk. H. Basha, K. W. Madonna, K. Sireesha, Tufail M. S., and M. Odeh, \"Experimental evaluation of secure and verifiable data control access over cloud storage environment using dynamic cryptographic strategy,\" in Proc. ICSES, 2024, doi: 10.1109/ICSES63760.2024.10910755.
[14] A. Joshi, A. Dumka, A. Raturi, D. P. Singh, and S. Kumar, \"Improved security and privacy in cloud data security and privacy: Measures and attacks,\" in Proc. ICFIRTP, 2022, doi: 10.1109/ICFIRTP56122.2022.10063186.
[15] C. Siva Kumar, P. Jagruthi, L. Vasantha, N. Pavithra, P. Siroshini, and T. Supriya, \"Secure and proficient provable data procurity with privacy protection in cloud storage,\" in Proc. ICCCI, 2023, doi: 10.1109/ICCCI56745.2023.10128477.
[16] G. Wu, L. Cao, H. Shen, L. Chen, X. Tan, and J. Han, \"Cloud auditing for outsourced storage service in healthcare systems with static data transfer,\" Electron. Res. Arch., vol. 33, no. 4, pp. 2577-2600, 2022