The unprecedented scale of large models,such as large language models(LLMs)and text-to-image diffusion models,has raised critical concerns about the unauthorized use of copyrighted data during model training.These con...The unprecedented scale of large models,such as large language models(LLMs)and text-to-image diffusion models,has raised critical concerns about the unauthorized use of copyrighted data during model training.These concerns have spurred a growing demand for dataset copyright auditing techniques,which aim to detect and verify potential infringements in the training data of commercial AI systems.This paper presents a survey of existing auditing solutions,categorizing them across key dimensions:data modality,model training stage,data overlap scenarios,and model access levels.We highlight major trends,including the prevalence of black-box auditing methods and the emphasis on fine-tuning rather than pre-training.Through an in-depth analysis of 12 representative works,we extract four key observations that reveal the limitations of current methods.Furthermore,we identify three open challenges and propose future directions for robust,multimodal,and scalable auditing solutions.Our findings underscore the urgent need to establish standardized benchmarks and develop auditing frameworks that are resilient to low watermark densities and applicable in diverse deployment settings.展开更多
Cloud storage,a core component of cloud computing,plays a vital role in the storage and management of data.Electronic Health Records(EHRs),which document users’health information,are typically stored on cloud servers...Cloud storage,a core component of cloud computing,plays a vital role in the storage and management of data.Electronic Health Records(EHRs),which document users’health information,are typically stored on cloud servers.However,users’sensitive data would then become unregulated.In the event of data loss,cloud storage providers might conceal the fact that data has been compromised to protect their reputation and mitigate losses.Ensuring the integrity of data stored in the cloud remains a pressing issue that urgently needs to be addressed.In this paper,we propose a data auditing scheme for cloud-based EHRs that incorporates recoverability and batch auditing,alongside a thorough security and performance evaluation.Our scheme builds upon the indistinguishability-based privacy-preserving auditing approach proposed by Zhou et al.We identify that this scheme is insecure and vulnerable to forgery attacks on data storage proofs.To address these vulnerabilities,we enhanced the auditing process using masking techniques and designed new algorithms to strengthen security.We also provide formal proof of the security of the signature algorithm and the auditing scheme.Furthermore,our results show that our scheme effectively protects user privacy and is resilient against malicious attacks.Experimental results indicate that our scheme is not only secure and efficient but also supports batch auditing of cloud data.Specifically,when auditing 10,000 users,batch auditing reduces computational overhead by 101 s compared to normal auditing.展开更多
Currently,there is a growing trend among users to store their data in the cloud.However,the cloud is vulnerable to persistent data corruption risks arising from equipment failures and hacker attacks.Additionally,when ...Currently,there is a growing trend among users to store their data in the cloud.However,the cloud is vulnerable to persistent data corruption risks arising from equipment failures and hacker attacks.Additionally,when users perform file operations,the semantic integrity of the data can be compromised.Ensuring both data integrity and semantic correctness has become a critical issue that requires attention.We introduce a pioneering solution called Sec-Auditor,the first of its kind with the ability to verify data integrity and semantic correctness simultaneously,while maintaining a constant communication cost independent of the audited data volume.Sec-Auditor also supports public auditing,enabling anyone with access to public information to conduct data audits.This feature makes Sec-Auditor highly adaptable to open data environments,such as the cloud.In Sec-Auditor,users are assigned specific rules that are utilized to verify the accuracy of data semantic.Furthermore,users are given the flexibility to update their own rules as needed.We conduct in-depth analyses of the correctness and security of Sec-Auditor.We also compare several important security attributes with existing schemes,demonstrating the superior properties of Sec-Auditor.Evaluation results demonstrate that even for time-consuming file upload operations,our solution is more efficient than the comparison one.展开更多
With the intelligentization of the Internet of Vehicles(lovs),Artificial Intelligence(Al)technology is becoming more and more essential,especially deep learning.Federated Deep Learning(FDL)is a novel distributed machi...With the intelligentization of the Internet of Vehicles(lovs),Artificial Intelligence(Al)technology is becoming more and more essential,especially deep learning.Federated Deep Learning(FDL)is a novel distributed machine learning technology and is able to address the challenges like data security,privacy risks,and huge communication overheads from big raw data sets.However,FDL can only guarantee data security and privacy among multiple clients during data training.If the data sets stored locally in clients are corrupted,including being tampered with and lost,the training results of the FDL in intelligent IoVs must be negatively affected.In this paper,we are the first to design a secure data auditing protocol to guarantee the integrity and availability of data sets in FDL-empowered IoVs.Specifically,the cuckoo filter and Reed-Solomon codes are utilized to guarantee error tolerance,including efficient corrupted data locating and recovery.In addition,a novel data structure,Skip Hash Table(SHT)is designed to optimize data dynamics.Finally,we illustrate the security of the scheme with the Computational Diffie-Hellman(CDH)assumption on bilinear groups.Sufficient theoretical analyses and performance evaluations demonstrate the security and efficiency of our scheme for data sets in FDL-empowered IoVs.展开更多
This paper attempts to explore interdisciplinary integration from four aspects:the necessity of interdisciplinary integration between legal studies and auditing,the difficulties and challenges encountered in this inte...This paper attempts to explore interdisciplinary integration from four aspects:the necessity of interdisciplinary integration between legal studies and auditing,the difficulties and challenges encountered in this integration,the ideas for teaching reform in the context of interdisciplinary integration,and the expected outcomes.The aim is to achieve an organic integration of legal studies and auditing through systematic teaching reforms,thereby providing students with comprehensive and integrated knowledge and skills training,ensuring the quality of talent cultivation,and adapting to the needs of social development.展开更多
Public institutions are charged with the responsibility of providing essential services for the welfare of the citizens by manipulating the economy's financial flow through public expenditure, taxation, and so on. Th...Public institutions are charged with the responsibility of providing essential services for the welfare of the citizens by manipulating the economy's financial flow through public expenditure, taxation, and so on. The reliance on public institutions to provide public services in Nigeria has resulted in disappointing results, because chief executives of the institutions take less interest in the degree of its success, and this accounts for the high level of fraudulent practices in such institutions. This study, therefore, examined the relationship between forensic auditing and fraudulent practices in Nigerian public institutions. To achieve this purpose, some hypothetical statements were made and a review of relevant literature was explored. The population of the study consisted of the general managers and accountants of 12 public institutions in Nigeria. The data generated were statistically tested with the Pearson Product-Moment Correlation Coefficient. The findings suggest that both the proactive and reactive forensic auditing techniques have a negative significant relationship with fraudulent practices in Nigerian public institutions. Based on the above, it was recommended that: (1) The Economic and Financial Crime Commission (EFCC), the Independent Corrupt Practices Commission (ICPC), and other anti-corruption bodies in Nigeria should have, in their payroll, internal forensic auditors to supplement the duties of the internal auditors; (2) Forensic auditors should regularly undergo training and development programs to acquaint them with relevant knowledge and skills for effective forensic auditing; and (3) Forensic auditing should be made mandatory for public institutions by regulatory authorities rather than being voluntary.展开更多
In China, an emerging economy, where investor protection is relatively weak, it is worthwhile and interesting to investigate whether independent external auditing, a sort of external corporate governance mechanism, ex...In China, an emerging economy, where investor protection is relatively weak, it is worthwhile and interesting to investigate whether independent external auditing, a sort of external corporate governance mechanism, exerts its influence. Using a sample of all A-share listed firms in 2005, this paper investigates the effects of independent external auditing on corporate governance via three aspects: (1) choice of auditing institution; (2) auditing fee; and (3) auditing opinion for annual reports. Empirical results show that, with worse agency problems in firms, the possibility of employing the “Big 41” to audit its annual reports is bigger. When determining auditing fees, auditing institutions take both firms' agency problems and the firm size into account. When issuing qualified opinions for poor-performing firms, auditors do not consider agency problems embedded in concentrated ownership. Overall, external independent auditing plays a limited role in corporate governance.展开更多
This paper is based on the samples of listed manufacturing companies of China, taking the financial performance as criterion, and then does research on the firm performance with different internal auditing modes, usin...This paper is based on the samples of listed manufacturing companies of China, taking the financial performance as criterion, and then does research on the firm performance with different internal auditing modes, using Cross-sectional data to analyze the distribution of internal auditing modes and the characteristics of the firm performance. The conclusion is that setting up internal auditing is good for the development of companies, but the function of internal auditing has not been widelv fulfilled.展开更多
The setting-up of the Malaysian Audit Oversight Board (AOB) in 2010 under the Securities Commission Amendment Act 2010 has extended the role of regulators into the statutory audit domain for public listed companies....The setting-up of the Malaysian Audit Oversight Board (AOB) in 2010 under the Securities Commission Amendment Act 2010 has extended the role of regulators into the statutory audit domain for public listed companies. Although the auditing profession in Malaysia has International Auditing Standards as prescribed minimum level of quality in the delivery of audit assurance services, self-regulation by the profession alone appears inadequate to ensure the delivery of quality audit services. With co-regulation, auditors now are monitored not just by the profession but also by a new statutory body with considerable regulatory powers to sanction auditors where quality of the audit process has been found wanting. This study solicits the opinions of auditors on their expectations of what the new regulator can achieve. Based on interviews with a sample of 30 auditors, the study finds that the majority believe that audit quality will be taken to a new level following AOB's remit of registration of auditors, compliance inspection with International Standard on Quality Control (ISQC), monitoring of financial statement quality, and its power of sanctions. A review of AOB's early years' inspection confirms these expectations.展开更多
The user control over the life cycle of data is of an extreme importance in clouds in order to determine whether the service provider adheres to the client’s pre-specified needs in the contract between them or n...The user control over the life cycle of data is of an extreme importance in clouds in order to determine whether the service provider adheres to the client’s pre-specified needs in the contract between them or not, significant clients concerns raise on some aspects like social, location and the laws to which the data are subject to. The problem is even magnified more with the lack of transparency by Cloud Service Providers (CSPs). Auditing and compliance enforcement introduce different set of challenges in cloud computing that are not yet resolved. In this paper, a conducted questionnaire showed that the data owners have real concerns about not just the secrecy and integrity of their data in cloud environment, but also for spatial, temporal, and legal issues related to their data especially for sensitive or personal data. The questionnaire results show the importance for the data owners to address mainly three major issues: Their ability to continue the work, the secrecy and integrity of their data, and the spatial, legal, temporal constraints related to their data. Although a good volume of work was dedicated for auditing in the literature, only little work was dedicated to the fulfillment of the contractual obligations of the CSPs. The paper contributes to knowledge by proposing an extension to the auditing models to include the fulfillment of contractual obligations aspects beside the important aspects of secrecy and integrity of client’s data.展开更多
With the rapid development of economy, auditing professional judgment is becoming more and more important in auditing practice.This paper analyzes the importance of audit professional judgment, the cause and the appli...With the rapid development of economy, auditing professional judgment is becoming more and more important in auditing practice.This paper analyzes the importance of audit professional judgment, the cause and the application of audit professional judgment in auditing practice.展开更多
This study focused on a multi-indicator assessment methodology for governmental environmental auditing of water protection programs. The environmental status of Wuli Lake in China was assessed using the global indicat...This study focused on a multi-indicator assessment methodology for governmental environmental auditing of water protection programs. The environmental status of Wuli Lake in China was assessed using the global indicators (driver-status-response) developed by the Commission on Sustainable Development, and four additional indicators proposed by the author: water quality, pollution load, aquatic ecosystem status, and lake sediment deposition. Various hydrological, chemical, biological and environmental parameters were used to estimate the values of the indicators for assessment of environmental status of the lake based on time series data sets for twenty years. The indicators proposed can be customized to meeting the needs for particular assessment of water protection programs. This method can be used to evaluate the performance of national environmental protection programs and provide technical support for environmental auditors.展开更多
Perfecting the natural resource system and auditing natural resource assets are requirements in protecting natural resources and developing an ecological civilization in practice.While the natural resource asset audit...Perfecting the natural resource system and auditing natural resource assets are requirements in protecting natural resources and developing an ecological civilization in practice.While the natural resource asset audit both confirms and quantifies natural resources,the nature of such resources makes it difficult to identify their ownership.Further,these resources'diversity creates complex measurement standards and activities,all of which require relevant institutional guarantees.However,the existing audit system for natural resource assets includes insufficient stock,incremental difficulties,and poor guidance,which cannot meet the requirements for environmental governance and an ecological civilization.Thus,it is necessary to define natural resource assets’rights and measurement systems and responsibility regulations,among others;construct an auditing participation system,technical regulations,and evaluation criterion for natural resource assets;amend the Audit Law in a timely manner;and enact natural resource asset legislation.Ultimately,such efforts would eliminate the bottleneck in the natural resource asset auditing system and facilitate the construction of a resource-saving,environmentally friendly society.展开更多
Identity-based public cloud storage auditing schemes can check the integrity of cloud data, and reduce the complicated certificate management. In such a scheme, one Private Key Generator(PKG) is employed to authentica...Identity-based public cloud storage auditing schemes can check the integrity of cloud data, and reduce the complicated certificate management. In such a scheme, one Private Key Generator(PKG) is employed to authenticate the identity and generate private keys for all users, and one Third Party Auditor(TPA) is employed to by users to check the integrity of cloud data. This approach is undesirable for large-scale users since the PKG and the TPA might not be able to afford the heavy workload. To solve the problem, we give a hierarchical Private Key Generator structure for large-scale user groups, in which a root PKG delegates lower-level PKGs to generate private keys and authenticate identities. Based on the proposed structure, we propose an authorized identity-based public cloud storage auditing scheme, in which the lowest-level PKGs play the role of TPA, and only the authorized lowest-level PKGs can represent users in their domains to check cloud data's integrity. Furthermore, we give the formal security analysis and experimental results, which show that our proposed scheme is secure and efficient.展开更多
With the rapid advancement of cloud computing,cloud storage services have developed rapidly.One issue that has attracted particular attention in such remote storage services is that cloud storage servers are not enoug...With the rapid advancement of cloud computing,cloud storage services have developed rapidly.One issue that has attracted particular attention in such remote storage services is that cloud storage servers are not enough to reliably save and maintain data,which greatly affects users’confidence in purchasing and consuming cloud storage services.Traditional data integrity auditing techniques for cloud data storage are centralized,which faces huge security risks due to single-point-of-failure and vulnerabilities of central auditing servers.Blockchain technology offers a new approach to this problem.Many researchers have endeavored to employ the blockchain for data integrity auditing.Based on the search of relevant papers,we found that existing literature lacks a thorough survey of blockchain-based integrity auditing for cloud data.In this paper,we make an in-depth survey on cloud data integrity auditing based on blockchain.Firstly,we cover essential basic knowledge of integrity auditing for cloud data and blockchain techniques.Then,we propose a series of requirements for evaluating existing Blockchain-based Data Integrity Auditing(BDIA)schemes.Furthermore,we provide a comprehensive review of existing BDIA schemes and evaluate them based on our proposed criteria.Finally,according to our completed review and analysis,we explore some open issues and suggest research directions worthy of further efforts in the future.展开更多
The security of cloud data has always been a concern.Cloud server provider may maliciously tamper or delete user’s data for their own benefit,so data integrity audit is of great significance to verify whether data is...The security of cloud data has always been a concern.Cloud server provider may maliciously tamper or delete user’s data for their own benefit,so data integrity audit is of great significance to verify whether data is modified or not.Based on the general three-party audit architecture,a dynamic auditing scheme without bilinear pairings is proposed in this paper.It utilizes exponential operation instead of bilinear mapping to verify the validity of evidence.By establishing the mapping relation between logic index and tag index of data block with index transformation table,our scheme can easily support dynamic data operation.By hiding random numbers in the integrity evidence,our scheme can protect users’privacy information.Detailed security analysis shows that our scheme is secure against attacks such as forgery,replaying and substitution.Further experiments demonstrate that our scheme has lower computational overhead.展开更多
Cloud storage service reduces the burden of data users by storing users' data files in the cloud. But, the files might be modified in the cloud. So, data users hope to check data files integrity periodically. In a pu...Cloud storage service reduces the burden of data users by storing users' data files in the cloud. But, the files might be modified in the cloud. So, data users hope to check data files integrity periodically. In a public auditing protocol, there is a trusted auditor who has certain ability to help users to check the integrity of data files. With the advantages of no public key management and verification, researchers focus on public auditing protocol in ID-based cryptography recently. However, some existing protocols are vulnerable to forgery attack. In this paper, based on ID-based signature technology, by strengthening information authentication and the computing power of the auditor, we propose an ID-based public auditing protocol for cloud data integrity checking. We also prove that the proposed protocol is secure in the random oracle model under the assumption that the Diffie-Hellman problem is hard. Furthermore, we compare the proposed protocol with other two ID-based auditing protocols in security features, communication efficiency and computation cost. The comparisons show that the proposed protocol satisfies more security features with lower computation cost.展开更多
Remote data auditing becomes critical to ensure the storage reliability in distributed cloud storage.Recently,Le et al proposed an efficient private data auditing scheme NC-Audit designed for regenerating codes,which ...Remote data auditing becomes critical to ensure the storage reliability in distributed cloud storage.Recently,Le et al proposed an efficient private data auditing scheme NC-Audit designed for regenerating codes,which claimed that NC-Audit can effectively realize privacy-preserving data auditing for distributed storage systems.However,our analysis shows that NC-Audit is not secure for that the adversarial cloud can forge some illegal blocks to cheat the auditor successfully with a high probability even without storing the user’s whole data,when the coding field is large enough.展开更多
基金supported in part by NSFC under Grant Nos.62402379,U22A2029 and U24A20237.
文摘The unprecedented scale of large models,such as large language models(LLMs)and text-to-image diffusion models,has raised critical concerns about the unauthorized use of copyrighted data during model training.These concerns have spurred a growing demand for dataset copyright auditing techniques,which aim to detect and verify potential infringements in the training data of commercial AI systems.This paper presents a survey of existing auditing solutions,categorizing them across key dimensions:data modality,model training stage,data overlap scenarios,and model access levels.We highlight major trends,including the prevalence of black-box auditing methods and the emphasis on fine-tuning rather than pre-training.Through an in-depth analysis of 12 representative works,we extract four key observations that reveal the limitations of current methods.Furthermore,we identify three open challenges and propose future directions for robust,multimodal,and scalable auditing solutions.Our findings underscore the urgent need to establish standardized benchmarks and develop auditing frameworks that are resilient to low watermark densities and applicable in diverse deployment settings.
基金supported by National Natural Science Foundation of China(No.62172436)Additionally,it is supported by Natural Science Foundation of Shaanxi Province(No.2023-JC-YB-584)Engineering University of PAP’s Funding for Scientific Research Innovation Team and Key Researcher(No.KYGG202011).
文摘Cloud storage,a core component of cloud computing,plays a vital role in the storage and management of data.Electronic Health Records(EHRs),which document users’health information,are typically stored on cloud servers.However,users’sensitive data would then become unregulated.In the event of data loss,cloud storage providers might conceal the fact that data has been compromised to protect their reputation and mitigate losses.Ensuring the integrity of data stored in the cloud remains a pressing issue that urgently needs to be addressed.In this paper,we propose a data auditing scheme for cloud-based EHRs that incorporates recoverability and batch auditing,alongside a thorough security and performance evaluation.Our scheme builds upon the indistinguishability-based privacy-preserving auditing approach proposed by Zhou et al.We identify that this scheme is insecure and vulnerable to forgery attacks on data storage proofs.To address these vulnerabilities,we enhanced the auditing process using masking techniques and designed new algorithms to strengthen security.We also provide formal proof of the security of the signature algorithm and the auditing scheme.Furthermore,our results show that our scheme effectively protects user privacy and is resilient against malicious attacks.Experimental results indicate that our scheme is not only secure and efficient but also supports batch auditing of cloud data.Specifically,when auditing 10,000 users,batch auditing reduces computational overhead by 101 s compared to normal auditing.
基金This research was supported by the Qinghai Provincial High-End Innovative and Entrepreneurial Talents Project.
文摘Currently,there is a growing trend among users to store their data in the cloud.However,the cloud is vulnerable to persistent data corruption risks arising from equipment failures and hacker attacks.Additionally,when users perform file operations,the semantic integrity of the data can be compromised.Ensuring both data integrity and semantic correctness has become a critical issue that requires attention.We introduce a pioneering solution called Sec-Auditor,the first of its kind with the ability to verify data integrity and semantic correctness simultaneously,while maintaining a constant communication cost independent of the audited data volume.Sec-Auditor also supports public auditing,enabling anyone with access to public information to conduct data audits.This feature makes Sec-Auditor highly adaptable to open data environments,such as the cloud.In Sec-Auditor,users are assigned specific rules that are utilized to verify the accuracy of data semantic.Furthermore,users are given the flexibility to update their own rules as needed.We conduct in-depth analyses of the correctness and security of Sec-Auditor.We also compare several important security attributes with existing schemes,demonstrating the superior properties of Sec-Auditor.Evaluation results demonstrate that even for time-consuming file upload operations,our solution is more efficient than the comparison one.
基金supported by the National Natural Science Foundation of China under Grants No.U1836115,No.61922045,No.61877034,No.61772280the Natural Science Foundation of Jiangsu Province under Grant No.BK20181408+2 种基金the Peng Cheng Laboratory Project of Guangdong Province PCL2018KP004the CICAEET fundthe PAPD fund.
文摘With the intelligentization of the Internet of Vehicles(lovs),Artificial Intelligence(Al)technology is becoming more and more essential,especially deep learning.Federated Deep Learning(FDL)is a novel distributed machine learning technology and is able to address the challenges like data security,privacy risks,and huge communication overheads from big raw data sets.However,FDL can only guarantee data security and privacy among multiple clients during data training.If the data sets stored locally in clients are corrupted,including being tampered with and lost,the training results of the FDL in intelligent IoVs must be negatively affected.In this paper,we are the first to design a secure data auditing protocol to guarantee the integrity and availability of data sets in FDL-empowered IoVs.Specifically,the cuckoo filter and Reed-Solomon codes are utilized to guarantee error tolerance,including efficient corrupted data locating and recovery.In addition,a novel data structure,Skip Hash Table(SHT)is designed to optimize data dynamics.Finally,we illustrate the security of the scheme with the Computational Diffie-Hellman(CDH)assumption on bilinear groups.Sufficient theoretical analyses and performance evaluations demonstrate the security and efficiency of our scheme for data sets in FDL-empowered IoVs.
文摘This paper attempts to explore interdisciplinary integration from four aspects:the necessity of interdisciplinary integration between legal studies and auditing,the difficulties and challenges encountered in this integration,the ideas for teaching reform in the context of interdisciplinary integration,and the expected outcomes.The aim is to achieve an organic integration of legal studies and auditing through systematic teaching reforms,thereby providing students with comprehensive and integrated knowledge and skills training,ensuring the quality of talent cultivation,and adapting to the needs of social development.
文摘Public institutions are charged with the responsibility of providing essential services for the welfare of the citizens by manipulating the economy's financial flow through public expenditure, taxation, and so on. The reliance on public institutions to provide public services in Nigeria has resulted in disappointing results, because chief executives of the institutions take less interest in the degree of its success, and this accounts for the high level of fraudulent practices in such institutions. This study, therefore, examined the relationship between forensic auditing and fraudulent practices in Nigerian public institutions. To achieve this purpose, some hypothetical statements were made and a review of relevant literature was explored. The population of the study consisted of the general managers and accountants of 12 public institutions in Nigeria. The data generated were statistically tested with the Pearson Product-Moment Correlation Coefficient. The findings suggest that both the proactive and reactive forensic auditing techniques have a negative significant relationship with fraudulent practices in Nigerian public institutions. Based on the above, it was recommended that: (1) The Economic and Financial Crime Commission (EFCC), the Independent Corrupt Practices Commission (ICPC), and other anti-corruption bodies in Nigeria should have, in their payroll, internal forensic auditors to supplement the duties of the internal auditors; (2) Forensic auditors should regularly undergo training and development programs to acquaint them with relevant knowledge and skills for effective forensic auditing; and (3) Forensic auditing should be made mandatory for public institutions by regulatory authorities rather than being voluntary.
文摘In China, an emerging economy, where investor protection is relatively weak, it is worthwhile and interesting to investigate whether independent external auditing, a sort of external corporate governance mechanism, exerts its influence. Using a sample of all A-share listed firms in 2005, this paper investigates the effects of independent external auditing on corporate governance via three aspects: (1) choice of auditing institution; (2) auditing fee; and (3) auditing opinion for annual reports. Empirical results show that, with worse agency problems in firms, the possibility of employing the “Big 41” to audit its annual reports is bigger. When determining auditing fees, auditing institutions take both firms' agency problems and the firm size into account. When issuing qualified opinions for poor-performing firms, auditors do not consider agency problems embedded in concentrated ownership. Overall, external independent auditing plays a limited role in corporate governance.
基金This paper is supported by National Natural Science Foundation of China (NoL70372028), the "Projects 985" and "Projects 211" of Nankai University. It's the authors' responsibility to stand the errors in this paper..
文摘This paper is based on the samples of listed manufacturing companies of China, taking the financial performance as criterion, and then does research on the firm performance with different internal auditing modes, using Cross-sectional data to analyze the distribution of internal auditing modes and the characteristics of the firm performance. The conclusion is that setting up internal auditing is good for the development of companies, but the function of internal auditing has not been widelv fulfilled.
文摘The setting-up of the Malaysian Audit Oversight Board (AOB) in 2010 under the Securities Commission Amendment Act 2010 has extended the role of regulators into the statutory audit domain for public listed companies. Although the auditing profession in Malaysia has International Auditing Standards as prescribed minimum level of quality in the delivery of audit assurance services, self-regulation by the profession alone appears inadequate to ensure the delivery of quality audit services. With co-regulation, auditors now are monitored not just by the profession but also by a new statutory body with considerable regulatory powers to sanction auditors where quality of the audit process has been found wanting. This study solicits the opinions of auditors on their expectations of what the new regulator can achieve. Based on interviews with a sample of 30 auditors, the study finds that the majority believe that audit quality will be taken to a new level following AOB's remit of registration of auditors, compliance inspection with International Standard on Quality Control (ISQC), monitoring of financial statement quality, and its power of sanctions. A review of AOB's early years' inspection confirms these expectations.
文摘The user control over the life cycle of data is of an extreme importance in clouds in order to determine whether the service provider adheres to the client’s pre-specified needs in the contract between them or not, significant clients concerns raise on some aspects like social, location and the laws to which the data are subject to. The problem is even magnified more with the lack of transparency by Cloud Service Providers (CSPs). Auditing and compliance enforcement introduce different set of challenges in cloud computing that are not yet resolved. In this paper, a conducted questionnaire showed that the data owners have real concerns about not just the secrecy and integrity of their data in cloud environment, but also for spatial, temporal, and legal issues related to their data especially for sensitive or personal data. The questionnaire results show the importance for the data owners to address mainly three major issues: Their ability to continue the work, the secrecy and integrity of their data, and the spatial, legal, temporal constraints related to their data. Although a good volume of work was dedicated for auditing in the literature, only little work was dedicated to the fulfillment of the contractual obligations of the CSPs. The paper contributes to knowledge by proposing an extension to the auditing models to include the fulfillment of contractual obligations aspects beside the important aspects of secrecy and integrity of client’s data.
文摘With the rapid development of economy, auditing professional judgment is becoming more and more important in auditing practice.This paper analyzes the importance of audit professional judgment, the cause and the application of audit professional judgment in auditing practice.
基金Project supported by the International Project between The Netherlands Royal Academy of Arts and Sciences and Chinese Academy of Sciences (No. 04CDP014) the National Natural Science Foundation of China (No. 40471130)
文摘This study focused on a multi-indicator assessment methodology for governmental environmental auditing of water protection programs. The environmental status of Wuli Lake in China was assessed using the global indicators (driver-status-response) developed by the Commission on Sustainable Development, and four additional indicators proposed by the author: water quality, pollution load, aquatic ecosystem status, and lake sediment deposition. Various hydrological, chemical, biological and environmental parameters were used to estimate the values of the indicators for assessment of environmental status of the lake based on time series data sets for twenty years. The indicators proposed can be customized to meeting the needs for particular assessment of water protection programs. This method can be used to evaluate the performance of national environmental protection programs and provide technical support for environmental auditors.
基金supported by Chinese National Funding of Social Science[Grant number.18BJY024],Study on the Cooperative Supervision Mechanism of Budget Implementation Based on National Audit.
文摘Perfecting the natural resource system and auditing natural resource assets are requirements in protecting natural resources and developing an ecological civilization in practice.While the natural resource asset audit both confirms and quantifies natural resources,the nature of such resources makes it difficult to identify their ownership.Further,these resources'diversity creates complex measurement standards and activities,all of which require relevant institutional guarantees.However,the existing audit system for natural resource assets includes insufficient stock,incremental difficulties,and poor guidance,which cannot meet the requirements for environmental governance and an ecological civilization.Thus,it is necessary to define natural resource assets’rights and measurement systems and responsibility regulations,among others;construct an auditing participation system,technical regulations,and evaluation criterion for natural resource assets;amend the Audit Law in a timely manner;and enact natural resource asset legislation.Ultimately,such efforts would eliminate the bottleneck in the natural resource asset auditing system and facilitate the construction of a resource-saving,environmentally friendly society.
基金supported by National Natural Science Foundation of China (No. 61572267, No. 61272425, No. 61402245)the Open Project of Co-Innovation Center for Information Supply & Assurance Technology, Anhui University+1 种基金the Open Project of the State Key Laboratory of Information Security,Institute of Information Engineering,Chinese Academy of Sciences(No.2017-MS-21, No.2016-MS-23)National Cryptography Development Fund of China (MMJJ20170118)
文摘Identity-based public cloud storage auditing schemes can check the integrity of cloud data, and reduce the complicated certificate management. In such a scheme, one Private Key Generator(PKG) is employed to authenticate the identity and generate private keys for all users, and one Third Party Auditor(TPA) is employed to by users to check the integrity of cloud data. This approach is undesirable for large-scale users since the PKG and the TPA might not be able to afford the heavy workload. To solve the problem, we give a hierarchical Private Key Generator structure for large-scale user groups, in which a root PKG delegates lower-level PKGs to generate private keys and authenticate identities. Based on the proposed structure, we propose an authorized identity-based public cloud storage auditing scheme, in which the lowest-level PKGs play the role of TPA, and only the authorized lowest-level PKGs can represent users in their domains to check cloud data's integrity. Furthermore, we give the formal security analysis and experimental results, which show that our proposed scheme is secure and efficient.
基金This work was supported in part by the National Natural Science Foundation of China under Grant 62072351in part by the Academy of Finland under Grant 308087,Grant 335262,Grant 345072,and Grant 350464+1 种基金in part by the Open Project of Zhejiang Lab under Grant 2021PD0AB01and in part by the 111 Project under Grant B16037.
文摘With the rapid advancement of cloud computing,cloud storage services have developed rapidly.One issue that has attracted particular attention in such remote storage services is that cloud storage servers are not enough to reliably save and maintain data,which greatly affects users’confidence in purchasing and consuming cloud storage services.Traditional data integrity auditing techniques for cloud data storage are centralized,which faces huge security risks due to single-point-of-failure and vulnerabilities of central auditing servers.Blockchain technology offers a new approach to this problem.Many researchers have endeavored to employ the blockchain for data integrity auditing.Based on the search of relevant papers,we found that existing literature lacks a thorough survey of blockchain-based integrity auditing for cloud data.In this paper,we make an in-depth survey on cloud data integrity auditing based on blockchain.Firstly,we cover essential basic knowledge of integrity auditing for cloud data and blockchain techniques.Then,we propose a series of requirements for evaluating existing Blockchain-based Data Integrity Auditing(BDIA)schemes.Furthermore,we provide a comprehensive review of existing BDIA schemes and evaluate them based on our proposed criteria.Finally,according to our completed review and analysis,we explore some open issues and suggest research directions worthy of further efforts in the future.
基金This work is supported by the National Key R&D Program of China(2016YFB0800402)partially supported by the National Natural Science Foundation of China under Grant No.61232004and the Fundamental Research Funds for the Central Universities(2016YXMS020).
文摘The security of cloud data has always been a concern.Cloud server provider may maliciously tamper or delete user’s data for their own benefit,so data integrity audit is of great significance to verify whether data is modified or not.Based on the general three-party audit architecture,a dynamic auditing scheme without bilinear pairings is proposed in this paper.It utilizes exponential operation instead of bilinear mapping to verify the validity of evidence.By establishing the mapping relation between logic index and tag index of data block with index transformation table,our scheme can easily support dynamic data operation.By hiding random numbers in the integrity evidence,our scheme can protect users’privacy information.Detailed security analysis shows that our scheme is secure against attacks such as forgery,replaying and substitution.Further experiments demonstrate that our scheme has lower computational overhead.
基金Supported by the Applied Basic and Advanced Technology Research Programs of Tianjin(15JCYBJC15900)the National Natural Science Foundation of China(51378350)
文摘Cloud storage service reduces the burden of data users by storing users' data files in the cloud. But, the files might be modified in the cloud. So, data users hope to check data files integrity periodically. In a public auditing protocol, there is a trusted auditor who has certain ability to help users to check the integrity of data files. With the advantages of no public key management and verification, researchers focus on public auditing protocol in ID-based cryptography recently. However, some existing protocols are vulnerable to forgery attack. In this paper, based on ID-based signature technology, by strengthening information authentication and the computing power of the auditor, we propose an ID-based public auditing protocol for cloud data integrity checking. We also prove that the proposed protocol is secure in the random oracle model under the assumption that the Diffie-Hellman problem is hard. Furthermore, we compare the proposed protocol with other two ID-based auditing protocols in security features, communication efficiency and computation cost. The comparisons show that the proposed protocol satisfies more security features with lower computation cost.
基金Supported by the National Natural Science Foundation of China(61872088)the Science and Technology Plan Project of Xi’an(2020KJWL02,2017CGWL35)the China National Study Abroad Fund。
文摘Remote data auditing becomes critical to ensure the storage reliability in distributed cloud storage.Recently,Le et al proposed an efficient private data auditing scheme NC-Audit designed for regenerating codes,which claimed that NC-Audit can effectively realize privacy-preserving data auditing for distributed storage systems.However,our analysis shows that NC-Audit is not secure for that the adversarial cloud can forge some illegal blocks to cheat the auditor successfully with a high probability even without storing the user’s whole data,when the coding field is large enough.