Jing Qin 0002

dblp:00/1015-2 · DBLP profile ↗
← Back
49ranked-venue papers
2as first author
30since 2021 · last 2026
0000-0003-2380-0396ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 16 · 1 first-author · 7 since 2021Systems, architecture and hardware · 11 · 6 since 2021Computer networks · 7 · 1 first-author · 5 since 2021Databases, data management, data science and information retrieval · 7 · 6 since 2021Software engineering, systems software and programming languages · 4 · 3 since 2021Artificial intelligence and machine learning · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021
YearPublicationVenuePosition
2026 Multi-User Boolean Keyword Searchable Encryption With Fine-Grained Access Control for Cloud Storage
abstract
ABSTRACT Searchable Encryption (SE) enables users to perform searches on encrypted data while preserving data privacy. Since cloud servers are platforms that provide services for a large number of users, and data owners require access control over their data, SE schemes that support multi‐user settings and access control are therefore more suitable for cloud storage. However, in existing SE schemes that support multi‐user settings and access control, most only support single‐keyword or conjunctive keyword searches, and the search time grows linearly with the total amount of data. These limitations negatively impact both the accuracy and efficiency of search operations. This work proposes an SE scheme specifically designed for multi‐user settings. Data owners can enforce fine‐grained access control policies, while a specialized retrieval structure allows the cloud to assist users in performing Boolean keyword searches with improved efficiency. The search complexity of the proposed scheme is , where denotes the number of files relevant to the queried keyword. We demonstrate the scheme's effectiveness and practicality through performance analysis.
Xinyi Hou, Ye Su 0001, Jing Qin 0002, Jixin Ma 0001
Concurr. Comput. Pract. Exp.3
2026 Long-Term Key-Exposure-Resilient Deduplication and Integrity Auditing for IoT Without Third Parties
abstract
Integrity auditing with deduplication enables integrity verification of cloud-stored IoT data while alleviating storage overhead caused by data redundancy. In most existing deduplication auditing schemes, authenticators are generated using the initial client’s key. However, clients are often vulnerable to key exposure. Compromise of the private key undermines the auditing security of all identical files. Although client-key-based schemes provide stronger security, they still suffer from the risk of gradual key-exposure in long-term deployments. Therefore, achieving integrity auditing, data deduplication, and resistance to long-term key-exposure simultaneously remains a challenging problem. While some existing schemes achieve these objectives, they rely on a third-party auditor. Compromise of the auditor would endanger all clients, and its continuous involvement could incur additional communication overhead. To address these limitations in cloud-based IoT data storage, this work presents an integrity auditing scheme that simultaneously supports deduplication and long-term key-exposure resilience without requiring a third party for key updates. By aggregating authenticators and public keys of clients, authenticator storage, proof generation and proof verification costs remain independent of the number of participating clients. Additionally, the integrity of previously uploaded data remains protected even when all clients’ secret keys at the current time are compromised. Our scheme is provably secure in the random oracle model under the ℓ-wBDHI∗3assumption. Performance evaluations further demonstrate that the authenticator size and auditing cost are unaffected by the number of identical files, making the scheme practical for cloud-based IoT systems.
Xueqi Peng, Haining Yang, Jing Qin 0002, Pingyuan Zhang
IEEE Internet Things J.4
2026 Compact-key boolean searchable encryption for multi-category cloud data sharing
Jinlu Liu, Haining Yang, Jing Qin 0002, Zhiquan Liu 0001
Inf. Sci.4
2026 BPFLH: Byzantine-Robust Privacy-Preserving Federated Learning for Heterogeneous Data
abstract
Byzantine-robust federated learning (FL) aims to obtain an accurate global model even with potentially Byzantine users. However, most existing schemes rely on measuring the overall differences between the entire gradient vectors of different users, which fail to effectively distinguish malicious gradients from benign ones caused by data heterogeneity under non-IID settings, thereby compromising model performance. To tackle this challenge, we propose BPFLH, a novel Byzantine-robust privacy preserving FL framework for heterogeneous data. BPFLH is the first to introduce Bray–Curtis dissimilarity into FL, capturing the element-wise differences among gradients from different users. This method reduces the risk of misclassifying benign gradi ents as malicious and enhance the model's robustness against Byzantine attacks in non-IID data environments. Furthermore, BPFLH leverages CKKS homomorphic encryption to protect local gradients, enabling secure aggregation and Byzantine user detection without compromising privacy. Extensive experiments on real-world datasets under various attack scenarios and data distributions demonstrate that BPFLH exhibits strong robustness against Byzantine attacks while preserving privacy and maintaining superior accuracy compared to existing Byzantine-robust FL methods, particularly in non-IID environments.
Guofu Zhu, Wenting Shen, Zhiquan Liu 0001, Jing Qin 0002, Jixin Ma 0001
IEEE Trans. Dependable Secur. Comput.4
2026 Efficient Privacy-Preserving User Tracking From Threshold Multi-Party Private Set Intersection
abstract
The ubiquitous sensing capabilities of the Internet of Things (IoT) enable large-scale user tracking by identifying users who appear in at least t distributed location datasets. However, the distribution of these datasets across multiple tracking entities significantly increases the risk of sensitive data exposure. To address this problem, threshold multi-party private set intersection (T-MPSI) provides a promising privacy-preserving solution. Although the known works about T-MPSI have made valuable contributions, especially in terms of security, the efficiency deficiency in current T-MPSI protocols becomes apparent in large-scale deployment for user tracking. The core challenge is to develop an efficient T-MPSI protocol under the relaxed security constraint that is acceptable for user tracking. We first design a lightweight batch replicated secret sharing private membership test protocol with high performance. Moreover, we develop a one-round secure aggregation algorithm that bridges the gap between the secure query and the secure comparison built upon replicated secret sharing. Building on these techniques, we present an efficient T-MPSI protocol tailored to the designated k-collusion model. Our protocol significantly enhances secure query efficiency and ensures that the communication complexity of secure comparison remains independent of the number of parties. We formally prove its security, and extensive experiments in a LAN setting demonstrate at least a 6× speedup for secure query and a 3× speedup for secure comparison over the state-of-the-art protocol. These results confirm the practicality and efficiency of the proposed protocol for privacy-preserving user tracking.
Bo Zhao 0027, Haining Yang, Jing Qin 0002, Jianting Ning, Jixin Ma 0001
IEEE Trans. Inf. Forensics Secur.3
2026 PUDSQ: Privacy-Preserving User-Defined Skyline Query Processing With Function Secret Sharing
abstract
Skyline query is a fundamental technique in multi-criteria decision-making, aiming to extract “optimal” results that are not dominated by any other data points across all attributes. It has significant value in applications that require trade-offs among multiple criteria. However, existing skyline query methods face two critical limitations: (i) conventional approaches adopt fixed dominance relationships, making it difficult to capture personalized user preferences; and (ii) cloud-based deployment models risk exposing sensitive data and query logic, making it difficult to ensure data privacy and protect query patterns while maintaining efficiency. To address these issues, we propose Privacy-Preserving User-Defined Skyline Query (PUDSQ), a novel privacy-preserving user-defined skyline query framework, which integrates efficient cryptographic techniques–secret sharing (SS) and function secret sharing (FSS)–with a secure database shuffling mechanism to achieve efficient query processing while ensuring robust privacy guarantees. PUDSQ introduces three main innovations: (i) a privacy-preserving filtering framework based on FSS provides dual protection for both data content and user preferences, effectively concealing database content and query logic; (ii) an FSS-based secure protocol suite supporting user-defined attribute retrieval, constrained-region retrieval, and secure skyline filtering; and (iii) a high-dimensional data processing strategy that integrates dimensionality reduction with an Sort-Filter-Skyline (SFS)-based presorting approach to address the high-dimensional data processing challenge and significantly improve efficiency. Experimental results demonstrate that, under equivalent security guarantees, PUDSQ reduces query latency by 8%-90% compared with state-of-the-art solution, with particularly notable advantages in high-dimensional scenarios, achieving an effective efficiency-privacy trade-off.
Zeqian Wang, Hao Wang 0007, Ye Su 0001, Ziyu Niu, Zhi Li 0056, Jing Qin 0002, Chunpeng Ge 0001
IEEE Trans. Serv. Comput.6
2025 Machine Learning Meets Encrypted Search: The Impact and Efficiency of OMKSA in Data Security
abstract
The convergence of machine learning and searchable encryption enhances the ability to protect the privacy and security of data and enhances the processing power of confidential data. To enable users to efficiently perform machine learning tasks on encrypted data domains, we delve into oblivious keyword search with authorization (OKSA). The OKSA scheme effectively maintains the privacy of the user’s query keywords and prevents the cloud server from inferring ciphertext information through the searching process. However, limitations arise because the traditional OKSA approach does not support multi‐keyword searches. If a data file is associated with multiple keywords, each keyword and corresponding data must be encrypted one by one, resulting in inefficiency. We introduce an innovative approach aimed at enhancing the efficiency of search processes while addressing the limitation of current encryption and search systems that handle only a single keyword. This method, known as the oblivious multiple keyword search with authorization (OMKSA), is designed for more effective keyword retrieval. One of our important innovations is that it uses the arithmetic techniques of bilinear pairs to generate new tokens and new search methods to optimize communication efficiency. Moreover, we present a detailed and rigorous demonstration of the security for our proposed protocol, aligned with the predefined security model. We conducted a comparative experiment to determine which of the two schemes, OKSA and OMKSA, is more efficient when querying multiple keywords. Based on our experimental results, our OMKSA is very efficient for data searchers. As the number of query keywords increases, the computational overhead of connected keyword searches remains stable. Finally, as we move into the 5G era, the potential applications of OMKSA are huge, with clear implications for areas such as machine learning and artificial intelligence. Our findings pave the way for further exploration and deployment of these frontier areas.
Zhongkai Wei, Ye Su 0001, Xi Zhang 0005, Haining Yang, Jing Qin 0002, Jixin Ma 0001
Int. J. Intell. Syst.5
2025 Oblivious Keyword Search With Authorization and Verification for IoT Devices in Untrusted Cloud Environments
abstract
With the rapid advancement of Internet of Things (IoT) technology, large volumes of data are exchanged among users via cloud servers. However, in an untrusted cloud server environment, the risk of data tampering is significant. For instance, a cloud server may fail to update its records promptly after receiving updated data from a data sender. Consequently, when the data receiver retrieves the relevant information, the cloud server may return outdated data, leading to security issues in data utilization. To address this problem, we propose a scheme that facilitates efficient verification in untrustworthy cloud environments. Our research approach is to utilize cryptographic accumulators within the oblivious searchable encryption model to achieve efficient verification. The data sender first uses a cryptographic accumulator to calculate the cumulative value of all messages to be uploaded, which are publicly accessible. In addition, the accumulator generates witness values for messages authorized to the data recipient. Before retrieving data, the data receiver can leverage the cryptographic accumulator to verify the timeliness of incoming messages, ensuring that the data is current and free from tampering. Furthermore, the data sender retains the flexibility to dynamically update the data stored in the cloud and efficiently refresh both the encrypted accumulator and its corresponding witness value. This article presents a rigorous security proof and a comparative experiment was carried out, supported by both analytical evaluations and experimental results, which collectively confirm the practical applicability of the proposed scheme in the context of the IoT.
Zhongkai Wei, Bo Zhao 0027, Haining Yang, Jing Qin 0002, Jixin Ma 0001
IEEE Internet Things J.4
2025 Low-Storage Verifiable Data Streaming With Efficient Revocation Approach
abstract
Verifiable data streaming (VDS) is proposed to authenticate a sequence of ordered data, such that the misbehavior on the data returned by cloud server can be effectively detected. VDS also allows to efficiently replace the outsourced data by another value. However, the old authentication information can make the expired data pass the verification. To prevent this attack, VDS schemes must provide a revocation approach to revoke the old authentication information. The current approach employs the tree-like authentication structure or cryptographic accumulator, which will influence the efficiency of the VDS scheme. In this work, we find an approach to construct the low-storage VDS scheme supporting efficient revocation. Towards this end, we fully exploit the property of chameleon hash function with ephemeral trapdoor to propose a signature, which is the crucial step to construct the VDS scheme. In our VDS scheme, the size of the authentication information can be reduced to be less than the scale of the data streaming (i.e., low storage). Furthermore, the client is able to revoke the old authentication information in an efficient manner, where she only needs to release a message (i.e., efficient revocation). The performance evaluation shows that the proposed VDS scheme is efficient and practical.
Haining Yang, Dengguo Feng, Jing Qin 0002
IEEE Trans. Computers3
2025 Toward Efficient Verifiable Data Streaming Without Cryptographic Accumulator
abstract
Verifiable data streaming (VDS) enables the client to incrementally store a sequence of ordered data on an untrusted cloud server, and verify the validity of the retrieved data. Moreover, the client can replace a data with another value. The common security problem caused by updating operation is the cloud server may use old authentication information to make expired data pass the verification. To solve this problem, the known approaches use the cryptographic accumulator that actually influences the performance of VDS scheme. The main concerns can be generalized as how to design a VDS scheme without cryptographic accumulator, in such a way that further optimizes the performance of VDS scheme. We put forward the idea to convert the standard digital signature relevant to the updated data into chameleon digital signature whose non-transferability is the key to solve the problem. This is the first attempt to securely authenticate the dynamic data without cryptographic accumulator. In the proposed VDS scheme, the client's local storage overhead, computation overheads of the cloud server in responding to a query and updating the data are constant. As the experimental results shown, the proposed VDS scheme outperforms the scheme in terms of the efficiency.
Haining Yang, Jinlu Liu, Pingyuan Zhang, Jing Qin 0002, Huaxiong Wang
IEEE Trans. Mob. Comput.4
2025 Towards Efficient Verifiable Cloud Storage and Distribution for Large-Scale Data Streaming
abstract
Data streaming is an ordered sequence of data continuously generated over time, whose dynamic scale is hard to be predicated in advance. Since the traditional integrity verification primitives are not qualified to check the integrity of the retrieved data and the outsourced database in streaming setting, some specific schemes were proposed by adopting the tree- like authentication structure or the combination of signature and accumulator. However, these schemes are not optimal for the owner. The main concerns can be generalized as how to reduce the size of the authentication information to be less than the scale of the data streaming, and enable the resource-constrained owner to check the data integrity without using challenge. To address the problems, we intend to find a new approach to design the scheme by exploiting the novel technique called decentralized vector commitment (DVC). Towards this goal, we first propose a key exposure-freeness chameleon vector commitment scheme, and then present the efficient DVC technique based on our key exposure-freeness chameleon vector commitment scheme. The scheme is finally constructed by leveraging the efficient DVC technique. Besides the integrity verification, our scheme is also sufficient to efficiently distribute the data to a user who is protected from receiving the stale data. To optimize the performance in concurrently retrieving multiple data, we introduce the batch query that reduces large amounts of communication and computation overheads. The security analysis and performance evaluation show that our solutions are secure and efficient.
Haining Yang, Dengguo Feng, Jing Qin 0002
IEEE Trans. Parallel Distributed Syst.3
2024 SDTA: Secure Decentralized Trading Alliance for Electronic Medical Data
abstract
Abstract Massive medical data are indispensable for training diagnostic models to provide high-quality health monitoring services. The methods for sharing data in existing works involve securely and essentially copying data but often overlook the integration and efficiency of data storage, exchange and application. In this paper, we propose a Secure Decentralized Trading Alliance (SDTA) to encompass the entire process holistically. With monetary incentives, we formulate a chain-net structure for recording data digests and authentic transactions, thereby transforming data sharing into data trading without duplicating data storage. Data privacy is promised by encryption. To manage and employ encrypted medical data, users can update and search their encrypted data using an index and keywords, subsequently retrieving data within the SDTA framework. It is realized by a novel dynamic searchable symmetric encryption (SSE) with an $l$-level access strategy, which confines users to data pertinent solely to them, thus circumventing unnecessary data leakage. We scrutinize the storage efficiency and prove the fairness and security of SDTA. Finally, we generate datasets of varying sizes, where the time required to search for a single keyword is approximately 0.04 s with 1 000 000 (keyword, identifier) pairs, showing it quite acceptable.
Xi Zhang 0005, Ye Su 0001, Jing Qin 0002, Jiameng Sun
Comput. J.3
2024 Certificateless cloud storage auditing supporting data ownership transfer
Wenting Shen, Jing Qin 0002
Comput. Secur.3
2024 Efficient Key-Aggregate Cryptosystem With User Revocation for Selective Group Data Sharing in Cloud Storage
abstract
Cloud computing has become prevalent due to its extensive storage resources and robust computational capacities. To protect data security and privacy, data owners opt for uploading encrypted data to the cloud. Flexible sharing of these encrypted data in a group of users is a critical functionality in cloud storage. In addition, given that users may exit the group, revocation becomes a crucial requirement in group data-sharing systems. The Key-Aggregate Cryptosystem (KAC) has become a promising mechanism for group data sharing. The decryption rights for any set of ciphertexts can be efficiently delegated by distributing a constant-size aggregate key, while the confidentiality of other ciphertexts outside the set is maintained. However, in previous KAC schemes, revocation remains a challenging task regarding key update, ciphertext re-encryption, and collision resistance. In this paper, we propose a Key-Aggregate Cryptosystem with User Revocation (KAC-UR) scheme to overcome this challenge. The KAC-UR scheme not only achieves flexible data sharing, but also can perform secure and efficient user revocation with properties including collision resistance, revocation without data owner-user communication, and constant ciphertext size. The KAC-UR scheme also enables the cloud server to perform partial decryption, thereby significantly alleviating the computational burden for users. The KAC-UR scheme is chosen plaintext attack secure under the decisional Bilinear Diffie-Hellman Exponent assumption.
Jinlu Liu, Jing Qin 0002, Xi Zhang 0005, Huaxiong Wang
IEEE Trans. Knowl. Data Eng.2
2024 Secure, Dynamic, and Efficient Keyword Search With Flexible Merging for Cloud Storage
abstract
In this paper, we propose a Mergeable Searchable Symmetric Encryption (MSSE) scheme to enable secure keyword search and updates over encrypted cloud data. Particularly, MSSE allows flexible keyword merging, where users can remotely merge file identifiers associated with keywords to create new keyword-to-file identifier relationships. The function is designed for a user to manage their outsourced data conveniently. To this end, we first introduce a new encrypted index where each keyword's relevant file identifiers are grouped, encoded, and encrypted with super-increasing sequences and homomorphic encryption. With such an index, users leverage Distributed Multi-point Functions (DMPFs) to achieve secure keyword search and merge, maintaining efficiency while ensuring high privacy. To address the issue of maintaining “merging consistency” between pre-merged entries and newly updated entries, we employ the DMPF on clusters that incorporate the updated files. The approach significantly minimizes client-side computational overhead compared to re-executing the entire keyword merging process. We formally prove that MSSE can achieve parallel privacy. Extensive performance evaluation shows that MSSE is efficient in terms of computational and communication overheads.
Xi Zhang 0005, Cheng Huang 0001, Ye Su 0001, Jing Qin 0002
IEEE Trans. Serv. Comput.4
2023 Multi-Keyword Ranked Searchable Encryption with the Wildcard Keyword for Data Sharing in Cloud Computing
abstract
Abstract Multi-keyword ranked searchable encryption (MRSE) supports multi-keyword contained in one query and returns the top-k search results related to the query keyword set. It realized effective search on encrypted data. Most previous works about MRSE can only make the complete keyword search and rank on the server-side. However, with more practice, users may not be able to express some keywords completely when searching. Server-side ranking increases the possibilities of the server inferring some keywords queried, leading to the leakage of the user’s sensitive information. In this paper, we propose a new MRSE system named ‘multi-keyword ranked searchable encryption with the wildcard keyword (MRSW)’. It allows the query keyword set to contain a wildcard keyword by using Bloom filter (BF). Using hierarchical clustering algorithm, a clustering Bloom filter tree (CBF-Tree) is constructed, which improves the efficiency of wildcard search. By constructing a modified inverted index (MII) table on the basis of the term frequency-inverse document frequency (TF-IDF) rule, the ranking function of MRSW is performed by the user. MRSW is proved secure under adaptive chosen-keyword attack (CKA2) model, and experiments on a real data set from the web of science indicate that MRSW is efficient and practical.
Jinlu Liu, Bo Zhao 0027, Jing Qin 0002, Xi Zhang 0005, Jixin Ma 0001
Comput. J.3
2023 A Verifiable Symmetric Searchable Encryption Scheme Based on the AVL Tree
abstract
Abstract Verifiable symmetric searchable encryption is a keyword search technology that supports verification of search results. Many schemes improve search performance by dividing each keyword label into segments and storing them in a Trie-tree at the expense of high storage. And the index will degenerate into a linear linked list when all keyword labels have the same prefix except for the last segment. But it will greatly affect the search efficiency. In this paper, we propose a verifiable symmetric searchable encryption scheme based on the AVL Tree (abbreviated as VSSE-AVL), which uses complete keyword labels to build the index. Compared with the Trie-tree index, VSSE-AVL not only balances storage and search performance, but also avoids degradation. To verify the correctness and completeness of empty search results, we store path information in each leaf node and node with only one child node. Considering the substitution attack, we bind the file identifier and the file so that the client will find out once the server returns inconsistent search results. Rigorous security analysis shows VSSE-AVL satisfies privacy and verifiability. Compared with the verifiable SSE-2 with the same security, the experimental evaluation shows that our proposed scheme performs better on storage, search and verification.
Xi Zhang 0005, Jing Qin 0002, Jixin Ma 0001
Comput. J.3
2023 Privacy-preserving healthcare monitoring for IoT devices under edge computing
Wenting Shen, Jing Qin 0002
Comput. Secur.4
2023 Privacy-preserving certificateless public auditing supporting different auditing frequencies
Wenting Shen, Jing Qin 0002, Huiying Hou
Comput. Secur.3
2023 Efficient and Flexible Multiauthority Attribute-Based Authentication for IoT Devices
abstract
The correctness and reliability of data sources are the keys to the practicality of data collected by Internet of Things (IoT) devices. Attribute-based signature (ABS) is a cryptographic primitive for users to sign with their own attributes, which can be applied to the authentication process in IoT scenarios. The attribute authority is responsible for issuing the attribute key to the user in ABS. Multiple authorities can complete attribute management tasks to avoid the threat of a single authority. However, attribute authorities need to execute multiple interactions to collaborate to generate attribute keys for users, which brings a large transmission burden. In addition, a lot of resource-constrained terminals in the IoT mostly play the role of signer or verifier in authentication protocols. The signature generation and verification algorithms often have heavy pairing and exponentiation operations. Currently, no ABS scheme takes into account the efficiency of all participating entities simultaneously. In this article, we present an aggregated anonymous key issue (AAKI) protocol to reduce the transmission burden between multiple authorities. Meanwhile, the noninteractive zero-knowledge proof aggregate exponentiation (NI-ZKPoKAE) protocol is designed to aggregate the transmitted secret values in AAKI. To reduce the computational burden of signers and verifiers, Blakley secret sharing, where the Hadamard matrix is used more efficiently to handle the$(n, n)$-threshold, is used to construct an efficient and fine-grained multiauthority ABS (EFMA-ABS) scheme. This brings high efficiency to all three types of parties involved in IoT authentication. Our above-mentioned protocols have been proven to be feasible and effective.
Ye Su 0001, Xi Zhang 0005, Jing Qin 0002, Jixin Ma 0001
IEEE Internet Things J.3
2023 Security-enhanced public-key authenticated searchable encryption
Leixiao Cheng, Jing Qin 0002, Fei Meng 0004
Inf. Sci.2
2023 Key-aggregate searchable encryption supporting conjunctive queries for flexible data sharing in the cloud
Jinlu Liu, Bo Zhao 0027, Jing Qin 0002, Xinyi Hou, Jixin Ma 0001
Inf. Sci.3
2023 Efficient Verifiable Unbounded-Size Database From Authenticated Matrix Commitment
abstract
Verifiable database with update (VDB) enables the client to store a large dataset in the outsourced database, and then efficiently query and update the data with a new value. It is attractive for the merits of checking the validity of the queried data and detecting the malicious actions of tampering with the outsourced database concurrently. However, the database in the context of VDB is merely suitable to store a fixed-size dataset. Hence, VDB is inapplicable to the unbounded-size database that provides the capability to store and manage the arbitrary-size datasets in the incremental manners. To circumvent the weaknesses, we research on the verifiable unbounded-size database with update (VUSDB). The VUSDB is sufficient for multiple clients to store their own arbitrary-size datasets in the database that has already contained some datasets. In order to design a VUSDB scheme, we first put forward a primitive called authenticated matrix commitment and give a scheme. This primitive is qualified to commit to a collection of ordered data represented in the form of matrix, and assure the ownership of the opened data. Then we utilize the authenticated matrix commitment scheme to construct a VUSDB scheme. The performance evaluation shows that the proposed schemes are efficient and practical.
Haining Yang, Dengguo Feng, Jing Qin 0002
IEEE Trans. Dependable Secur. Comput.3
2023 Verifiable Key-Aggregate Searchable Encryption With a Designated Server in Multi-Owner Setting
abstract
Key-aggregate searchable encryption (KASE) schemes support selective data sharing and keyword-based ciphertext searching by using the constant-size shared key and trapdoor, making these schemes attractive for resource-constrained users to store, share, and search encrypted data in public clouds. However, most previously proposed KASE schemes suffer from our proposed “off-line keyword guessing attack (KGA)” and some other weaknesses. Consequently, they fail to gain the keyword ciphertext indistinguishability and trapdoor indistinguishability, which are vital security goals of searchable encryption. Inspired by the relationship of public key encryption with keyword search (PEKS) and KASE, we design a new KASE scheme called key-aggregate searchable encryption with a designated server (dKASE). The dKASE scheme achieves our proposed keyword ciphertext indistinguishability against chosen keyword attack (KC-IND-CKA) and keyword trapdoor indistinguishability against keyword guessing attack (KT-IND-KGA) security models, where the latter model captures off-line KGA. Then, we extend the dKASE scheme to verifiable dKASE in multi-owner setting (dVKASEM) scheme. With dVKASEM, when multiple data owners authorize a user to access data, the user merely needs to store his single key and generate a single trapdoor to query these owners’ data. Besides, the adoption of the aggregate signature significantly reduces the overhead of verifying whether data has been tampered with. Performance analysis illustrates that our schemes are efficient.
Jinlu Liu, Zhongkai Wei, Jing Qin 0002, Bo Zhao 0027, Jixin Ma 0001
IEEE Trans. Serv. Comput.3
2022 Divertible Searchable Symmetric Encryption for Secure Cloud Storage
abstract
Searchable Symmetric Encryption (SSE) is a promising method for users to store data in remote clouds securely and search them using keywords over an encrypted index. In this paper, we explore a new function named “keyword diverting” and propose a variant of SSE named Divertible Searchable Symmetric Encryption (DivSSE). Specifically, the index in DivSSE is encoded into an inverted, compressed, and encrypted format, by using the super-increasing sequence, symmetric homomorphic encryption (SHE), and a secure hash function. According to the homomorphic properties of SHE, users can construct a unique keyword diverting token, which can be utilized to update the encrypted index by obliviously merging data identifiers corresponding to different keywords without searching in advance and thus achieve keyword diverting. Moreover, based on function secret sharing, DivSSE can protect users' search patterns and reduce communication costs with the assistance of two independent clouds. Detailed security proof demonstrates that DivSSE can achieve parallel privacy, forward privacy, and backward privacy. Extensive performance evaluation also shows that DivSSE is efficient in terms of computational and communication overheads.
Xi Zhang 0005, Cheng Huang 0001, Ye Su 0001, Jing Qin 0002, Xuemin Shen
GLOBECOM4
2022 Publicly Verifiable Shared Dynamic Electronic Health Record Databases With Functional Commitment Supporting Privacy-Preserving Integrity Auditing
abstract
Electronic health record (EHR) is a system that collects patients' digital health information and shares it with other healthcare providers in the cloud. Since EHR contains a large amount of significant and sensitive information about patients, it is required that the system ensures response correctness and storage integrity. Meanwhile, with the rise of IoT, more low-performance terminals are deployed for receiving and uploading patient data to the server, which increases the computational and communication burden of the EHR systems. The verifiable database (VDB), where a user outsources his large database to a cloud server and makes queries once he needs certain data, is proposed as an efficient updatable cloud storage model for resource-constrained users. To improve efficiency, most existing VDB schemes utilize proof reuse and proof updating technique to prove correctness of the query results. However, it ignores the “real-time” of proof generation, which results in an overhead that the user has to perform extra process (e.g., auditing schemes) to check storage integrity. In this article, we propose a publicly verifiable shared updatable EHR database scheme that supports privacy-preserving and batch integrity checking with minimum user communication cost. We modify the existing functional commitment (FC) scheme for the VDB design and construct a concrete FC under the computationall-BDHE assumption. In addition, the use of an efficient verifier-local revocation group signature scheme makes our scheme support dynamic group member operations, and gives nice features, such as traceability and non-frameability.
Ye Su 0001, Jiameng Sun, Jing Qin 0002, Jiankun Hu
IEEE Trans. Cloud Comput.3
2022 Privacy-Preserving Outsourced Inner Product Computation on Encrypted Database
abstract
We consider an outsourced computation model in the selective data sharing setting. Specifically, one of the data owners outsources the encrypted data to an untrusted cloud server, and wants to share the specific function of these data with a group of data users. A data user can perform the specific computation on the data that it is authorized to access. We propose a construction under this model for the inner product computation by using the Inner Product Functional Encryption (IPFE) as a building block. A standard IPFE used on this model has two privacy weaknesses regarding the master secret key and the encrypted vector. We propose a strengthened IPFE that revises these weaknesses. We construct a new IPFE scheme and use it to construct an efficient outsourced inner product computation scheme. In our outsourced computation scheme, the storage overhead and the computation cost for a data user are independent of the vector size. The result privacy and the outsourced data privacy are well preserved against the untrusted cloud server. The experimental results show that our schemes are efficient and practical.
Haining Yang, Ye Su 0001, Jing Qin 0002, Huaxiong Wang
IEEE Trans. Dependable Secur. Comput.3
2021 Practical wildcard searchable encryption with tree-based index
abstract
Wildcard searchable encryption is an advanced variant of searchable encryption that can simultaneously maintain the searchability and confidentiality of the encrypted data. The wildcard searchable encryption outperforms the standard one for the fact that the users can use it to search the desired data even with the inexact keywords. Considering the millisecond level response time in the era of 5G, there are higher demands on the efficiency and accuracy that may be a pair of contradictions in wildcard searchable encryption. To improve the efficiency without sacrificing the accuracy, we put forward a novel scheme, tree-based index scheme (TBIS), through filtering the search results step by step instead of enumeration in the prior works and in the instantiation of TBIS, the search time drops sharply to the millisecond level. By using more kinds of characters, the accuracy of search result is improved visibly. TBIS achieves nonadaptive security that is indistinguishable against chosen character set attacks proposed in this paper. The security criteria can capture the relationship among characters, keywords and documents. At last, we put forward a frame structure in machine learning as an application of the proposed scheme.
Xi Zhang 0005, Bo Zhao 0027, Jing Qin 0002, Ye Su 0001, Haining Yang
Int. J. Intell. Syst.3
2021 Data Integrity Auditing without Private Key Storage for Secure Cloud Storage
abstract
Using cloud storage services, users can store their data in the cloud to avoid the expenditure of local data storage and maintenance. To ensure the integrity of the data stored in the cloud, many data integrity auditing schemes have been proposed. In most, if not all, of the existing schemes, a user needs to employ his private key to generate the data authenticators for realizing the data integrity auditing. Thus, the user has to possess a hardware token (e.g., USB token, smart card) to store his private key and memorize a password to activate this private key. If this hardware token is lost or this password is forgotten, most of the current data integrity auditing schemes would be unable to work. In order to overcome this problem, we propose a new paradigm called data integrity auditing without private key storage and design such a scheme. In this scheme, we use biometric data (e.g., iris scan, fingerprint) as the user’s fuzzy private key to avoid using the hardware token. Meanwhile, the scheme can still effectively complete the data integrity auditing. We utilize a linear sketch with coding and error correction processes to confirm the identity of the user. In addition, we design a new signature scheme which not only supports blockless verifiability, but also is compatible with the linear sketch. The security proof and the performance analysis show that our proposed scheme achieves desirable security and efficiency.
Wenting Shen, Jing Qin 0002, Jia Yu 0003, Rong Hao, Jiankun Hu, Jixin Ma 0001
IEEE Trans. Cloud Comput.2
2021 Outsourced Decentralized Multi-Authority Attribute Based Signature and Its Application in IoT
abstract
IoT (Internet of things) devices often collect data and store the data in the cloud for sharing and further processing; This collection, sharing, and processing will inevitably encounter secure access and authentication issues. Attribute based signature (ABS), which utilizes the signer’s attributes to generate private keys, plays a competent role in data authentication and identity privacy preservation. In ABS, there are multiple authorities that issue different private keys for signers based on their various attributes, and a central authority is usually established to manage all these attribute authorities. However, one security concern is that if the central authority is compromised, the whole system will be broken. In this paper, we present an outsourced decentralized multi-authority attribute based signature (ODMA-ABS) scheme. The proposed ODMA-ABS achieves attribute privacy and stronger authority-corruption resistance than existing multi-authority attribute based signature schemes can achieve. In addition, the overhead to generate a signature is further reduced by outsourcing expensive computation to a signing cloud server. We present extensive security analysis and experimental simulation of the proposed scheme. We also propose an access control scheme that is based on ODMA-ABS.
Jiameng Sun, Ye Su 0001, Jing Qin 0002, Jiankun Hu, Jixin Ma 0001
IEEE Trans. Cloud Comput.3
2020 EVA: Efficient Versatile Auditing Scheme for IoT-Based Datamarket in Jointcloud
abstract
Cloud storage offers convenient outsourcing services to users, and it serves as a basic platform to drive Internet-of-Things (IoT) where massive devices are connected to the cloud storage and interact with each other. However, cloud storage is more than a data warehouse. In the literature, data market was proposed as a novel model to empower IoT, where data are circulated as merchandise in the digital marketplace with financial activities. When storing IoT data in cloud storage, security and efficiency rules should be applied. Meanwhile, data dynamics is counted as a critical factor to the feasibility of datamarket as data are supposed to be manipulated through circulation and exploitation for IoT. Another issue is the single-point-of-failure (SPoF) of cloud server in which the initiative of jointcloud was suggested. Since providing data security, efficiency, and dynamics simultaneously is challenging, in this article, we propose a versatile auditing scheme (EVA) as a solution to problems. Our proposal ensures that data are securely, efficiently, and dynamically stored in the jointcloud meanwhile supported by data trades via blockchain. We give a comprehensive security analysis based on our security definitions and experiments to support our claims. The evidence has shown that our EVA is efficient for processing large files when proper parameters are chosen.
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Jingwei Li 0001, Qi Xia 0001, Jing Qin 0002
IEEE Internet Things J.8
2020 Verifiable inner product computation on outsourced database for authenticated multi-user data sharing
Haining Yang, Ye Su 0001, Jing Qin 0002, Huaxiong Wang, Yongcheng Song
Inf. Sci.3
2020 A Dynamic Searchable Symmetric Encryption Scheme for Multiuser with Forward and Backward Security
abstract
Dynamic Searchable Symmetric Encryption for Multiuser (M-DSSE) is an advanced form of symmetric encryption. It extends the traditional symmetric encryption to support the operations of adding and deleting the encrypted data and allow an authenticated group of data users to retrieve their respective desired encrypted data in the dynamic database. However, M-DSSE would suffer from the privacy concerns regarding forward and backward security. The former allows an attacker to identify the keywords contained in the added data by lunching file-injection attacks, while the latter allows to utilize the search results and the deleted data to learn the content. To our knowledge, these privacy concerns for M-DSSE have not been fully considered in the existing literatures. Taking account of this fact, we focus on the dynamic searchable symmetric encryption for multiuser meeting the needs of forward and backward security. In order to propose a concrete scheme, the primitives of Pseudorandom Functions (PRF) and the Homomorphic Message Authenticator (HMAC) are employed to construct the inverted index and update the search token. The proposed scheme is proven secure in the random model. And the performance analysis shows that the proposed scheme achieves the enhanced security guarantees at the reasonable price of efficiency.
Xi Zhang 0005, Ye Su 0001, Jing Qin 0002
Secur. Commun. Networks3
2019 An improved scheme for outsourced computation with attribute-based encryption
abstract
Summary With the wide deployment of cloud computing, outsourcing complicated computational tasks to cloud service providers has attracted much attention. An increasing number of clients with computationally constrained devices choose to outsource their heavy tasks to cloud servers to reduce the computational overhead in local. However, how to preserve the integrity of computational results becomes a challenge since commercial cloud servers are not trusted. Public verifiability is an effective mechanism to allow clients to verify the integrity of the results returned by the servers. Because the results are sensitive in many applications, it raises the problem of privacy leakage in the public verification process. In this paper, we propose an efficient verifiable computation scheme while keeping output privacy. The proposed scheme achieves blind verifiability such that the verifiers who have not the additional information (retrieve key) can verify the integrity of the result without learning the result. Furthermore, by combining with (k,n)‐threshold sharing, our scheme allows the clients jointly learn the results.
Haining Yang, Jiameng Sun, Jing Qin 0002, Jixin Ma 0001
Concurr. Comput. Pract. Exp.3
2019 A Lightweight Identity-Based Cloud Storage Auditing Supporting Proxy Update and Workload-Based Payment
abstract
Cloud storage auditing allows the users to store their data to the cloud with a guarantee that the data integrity can be efficiently checked. In order to release the user from the burden of generating data signatures, the proxy with a valid warrant is introduced to help the user process data in lightweight cloud storage auditing schemes. However, the proxy might be revoked or the proxy’s warrant might expire. These problems are common and essential in real-world applications, but they are not considered and solved in existing lightweight cloud storage auditing schemes. In this paper, we propose a lightweight identity-based cloud storage auditing scheme supporting proxy update, which not only reduces the user’s computation overhead but also makes the revoked proxy or the expired proxy unable to process data on behalf of the user any more. The signatures generated by the revoked proxy or the expired proxy can still be used to verify data integrity. Furthermore, our scheme also supports workload-based payment for the proxy. The security proof and the performance analysis indicate that our scheme is secure and efficient.
Wenting Shen, Jing Qin 0002, Jixin Ma 0001
Secur. Commun. Networks2
2019 A Secure Data Sharing Scheme with Designated Server
abstract
The cloud-assisted Internet of Things (CIoT) is booming, which utilizes powerful data processing capabilities of the cloud platform to solve massive Internet of Things (IoT) data. However, the CIoT faces new security challenges, such as the confidentiality of the outsourced data. Data encryption is a fundamental technique that can guarantee the confidentiality of outsourced data, but it limits target encrypted data retrieval from cloud platform. Public key encryption with keyword search (PEKS) provides a promising solution to address this problem. In PEKS, a cloud server can be authorized to search the keyword in encrypted documents and retrieve associated encrypted documents for the receiver. However, most existing PEKS schemes merely focus on keyword search function while ignoring the associated documents encryption/decryption function. Thus, in practice, a PEKS scheme must cooperate with another separated public key encryption (PKE) scheme to fulfill a completely secure data sharing scheme. To address this problem, in this paper, we propose a secure data sharing scheme with designated server that combines PKE scheme with PEKS scheme, which provides both keyword search and documents encryption/decryption functions. Furthermore, only the designated server can search the keyword via encrypted documents for enhanced security in our work. Moreover, our scheme also satisfies the public verifiability of search results, which includes both keywords and documents ciphertexts’ correctness and integrity. As to the security, our scheme provides stronger indistinguishability security of document and keyword in the proposed security model.
Binrui Zhu, Jiameng Sun, Jing Qin 0002, Jixin Ma 0001
Secur. Commun. Networks3
2019 Fuzzy matching: multi-authority attribute searchable encryption without central authority
Binrui Zhu, Jiameng Sun, Jing Qin 0002, Jixin Ma 0001
Soft Comput.3
2019 Enabling Identity-Based Integrity Auditing and Data Sharing With Sensitive Information Hiding for Secure Cloud Storage
abstract
With cloud storage services, users can remotely store their data to the cloud and realize the data sharing with others. Remote data integrity auditing is proposed to guarantee the integrity of the data stored in the cloud. In some common cloud storage systems such as the electronic health records system, the cloud file might contain some sensitive information. The sensitive information should not be exposed to others when the cloud file is shared. Encrypting the whole shared file can realize the sensitive information hiding, but will make this shared file unable to be used by others. How to realize data sharing with sensitive information hiding in remote data integrity auditing still has not been explored up to now. In order to address this problem, we propose a remote data integrity auditing scheme that realizes data sharing with sensitive information hiding in this paper. In this scheme, a sanitizer is used to sanitize the data blocks corresponding to the sensitive information of the file and transforms these data blocks' signatures into valid ones for the sanitized file. These signatures are used to verify the integrity of the sanitized file in the phase of integrity auditing. As a result, our scheme makes the file stored in the cloud able to be shared and used by others on the condition that the sensitive information is hidden, while the remote data integrity auditing is still able to be efficiently executed. Meanwhile, the proposed scheme is based on identity-based cryptography, which simplifies the complicated certificate management. The security analysis and the performance evaluation show that the proposed scheme is secure and efficient.
Wenting Shen, Jing Qin 0002, Jia Yu 0003, Rong Hao, Jiankun Hu
IEEE Trans. Inf. Forensics Secur.2
2018 Confidentiality-Preserving Publicly Verifiable Computation Schemes for Polynomial Evaluation and Matrix-Vector Multiplication
abstract
With the development of cloud services, outsourcing computation tasks to a commercial cloud server has drawn attention of various communities, especially in the Big Data era. Public verifiability offers a flexible functionality in real circumstance where the cloud service provider (CSP) may be untrusted or some malicious users may slander the CSP on purpose. However, sometimes the computational result is sensitive and is supposed to remain undisclosed in the public verification phase, while existing works on publicly verifiable computation (PVC) fail to achieve this requirement. In this paper, we highlight the property of result confidentiality in publicly verifiable computation and present confidentiality-preserving public verifiable computation (CP-PVC) schemes for multivariate polynomial evaluation and matrix-vector multiplication, respectively. The proposed schemes work efficiently under the amortized model and, compared with previous PVC schemes for these computations, achieve confidentiality of computational results, while maintaining the property of public verifiability. The proposed schemes proved to be secure, efficient, and result-confidential. In addition, we provide the algorithms and experimental simulation to show the performance of the proposed schemes, which indicates that our proposal is also acceptable in practice.
Jiameng Sun, Binrui Zhu, Jing Qin 0002, Jiankun Hu, Jixin Ma 0001
Secur. Commun. Networks3
2017 A confidentiality preserving publicly verifiable computation for multivariate polynomials
abstract
With the development of cloud services, outsourcing computation tasks to a commercial cloud server has drawn attentions by various communities, especially in the Big Data age. Public verifiability offers a flexible functionality in real circumstance where the cloud service provider (CSP) may be untrusted or some malicious users may slander the CSP on purpose. However, sometimes the computational result is sensitive and is not willing to be exposed in the public verification phase. In this paper, we present a confidential-preserving public verifiable computation (CP-PVC) scheme for Evaluation of High Degree Polynomials. Compared with previous proposals, our scheme achieves confidentiality of computational result, while not sacrificing the property of public verifiability. We also provide the algorithm and experimental evaluation to show the efficiency of our scheme.
Jiameng Sun, Binrui Zhu, Jing Qin 0002, Jixin Ma 0001
SERA3
2016 A secure biometric authentication based on PEKS
abstract
Summary Biometrics refers to metrics related to human characteristics and traits such as finger prints. How to use biometric to replace an encryption key or an identity certificate efficiently and securely is a hot topic in this big data era. In this field, secure biometric authentication is an important application, which refers to automated authentication based on their encrypted biological and behavioral traits. Searchable encryption is a powerful technology supporting retrieval for encrypted data with specific encrypted keyword index. It also has a profound meaning in the big data field. In this paper, we propose a generic transformation from searchable encryption to secure biometric authentication and construct a specific secure biometric authentication scheme based on public key encryption with keyword search (PEKS). The security of this authentication relies on the distinguishability of trapdoors and indexes in PEKS. In our scheme, the user does not need to claim the target user to authenticate in authentication message, and we change the pattern of authenticating by one bit. Compared with some existing authentication scheme, the proposed scheme is more efficient in the practical application. Furthermore, searchable encryption is an earlier cryptographic system that has relatively mature methods. Our transformation from searchable encryption to secure biometric authentication presents a new direction of constructing authentication scheme. Copyright © 2015 John Wiley & Sons, Ltd.
Jing Qin 0002, Lihua Du
Concurr. Comput. Pract. Exp.2
2016 Secure searches in the cloud: A survey
Jing Qin 0002, Jiankun Hu
Future Gener. Comput. Syst.2
2016 Threshold attribute-based signcryption and its application to authenticated key agreement
abstract
Abstract Signcryption is a public key cryptosystem that achieves the functions of digital signature and public key encryption simultaneously. It significantly reduces the cost of traditional signature‐then‐encryption approach. Although a large body of signcryption schemes have been proposed, few works have been done on attribute‐based signcryption (ABSC), which simultaneously achieves the functionalities of attribute‐based encryption and attribute‐based signature, two important cryptographic primitives proposed to enforce fine‐grained access control and user authentication in cloud computing applications. In this paper, we present a threshold ABSC scheme. The scheme is proven secure under the well‐established Decisional Bilinear Diffie–Hellman and the standard Computational Diffie–Hellman assumptions in the standard model. Compared with the state of the ABSC art, our scheme has comparable efficiency without relying on any random oracle. Furthermore, we construct an authenticated key agreement protocol based on this threshold attribute‐based signcryption from the point of improving the security of cloud computing. Copyright © 2016 John Wiley & Sons, Ltd.
Haibin Zheng, Jing Qin 0002, Jiankun Hu, Qianhong Wu
Secur. Commun. Networks2
2015 Threshold Attribute-Based Signcryption in Standard Model
abstract
Signcryption is a public key cryptosystem that achieves the functions of digital signature and public key encryption simultaneously. It significantly reduces the cost of traditional signature-then-encryption approach. Although a large body of signcryption schemes have been proposed, few works have been done on attribute-based signcrytion (ABSC) which simultaneously achieves the functionalities of attribute-based encryption (ABE) and attribute-based signature (ABS), two important cryptographic primitives proposed to enforce fine-grained access control and user authentication in cloud computing applications. In this paper, we present a threshold attribute-based signcryption (TABSC) scheme. The scheme is proven secure under the well-established Decisional Bilinear Diffie-Hellman (DBDH) and the standard Computational Diffie-Hellman (CDH) assumptions in the standard model. Compared with the state of the ABSC art, our scheme has comparable efficiency without relying on any random oracle.
Haibin Zheng, Jing Qin 0002, Jiankun Hu, Qianhong Wu
CSCloud2
2014 A general transformation from KP-ABE to searchable encryption
Jing Qin 0002, Huawei Zhao, Jiankun Hu
Future Gener. Comput. Syst.2
2014 A new Lagrange solution to the privacy-preserving general geometric intersection problem
Jing Qin 0002, Hongwei Duan, Huawei Zhao, Jiankun Hu
J. Netw. Comput. Appl.1
2013 An Energy Efficient Key Management Scheme for Body Sensor Networks
abstract
Body sensor networks (BSNs) are distributed systems where biosensor nodes are distributed in different positions to collect health data from the human body and deliver the information to a remote medical center. Due to medical data regulations, security of BSNs is very important. However, the operational resources of biosensor nodes in BSNs are very restricted, and traditional security technologies are not directly applicable to BSNs. Due to characteristics of biosensors, time synchronization and low-energy communication are two challenging problems for BSNs. In this paper, a fuzzy commitment technology with weak time synchronization mechanism for keys negotiation is developed, with a multihop route key management scheme proposed for efficient energy consumption management, including an energy-based multihop-route-choice method. Security analyses and performance evaluation have been provided to validate the proposed scheme.
Huawei Zhao, Jing Qin 0002, Jiankun Hu
IEEE Trans. Parallel Distributed Syst.2
2012 Simulatable Oblivious Transfer Protocols Based on Blind Signature
abstract
Oblivious Transfer protocol (OTP) is a paramount important primitive tool in modern cryptography. Essentially, OTP can be used to construct a secure multi-party computation protocol and distributed oblivious transfer protocol (DOTP). DOTP is the general OTP in the distributed setting. Private information retrieval (PIR) and symmetric private information retrieval (SPIR) problems are also analogous to those of the OTP. Due to its importance, the task of constructing efficient and secure OTP has attracted a lot interests. In this paper, a paradigm of OPT protocol and a practical fully-simulatable OTP protocol based on blind GDH (Gap Diffie-Hellman) signature are presented. The proposed schemes can achieve higher efficiency and better security than the popular Malkhi & Sella scheme. The salient property of short signature length of GDH signature scheme enables our proposals applicable to low-bandwidth communication environments.
Jing Qin 0002, Jiankun Hu, Huawei Zhao
TrustCom1
2012 Hashed Random Key Pre-distribution Scheme for Large Heterogeneous Sensor Networks
abstract
Many wireless sensor networks (WSNs) consist of a large number of distributed sensor nodes that are batteries powered, vulnerable to tampering, and equipped with limited computational capabilities and memory. These characteristics render WSNs facing many security threats, which require cryptographic security mechanisms for secure communication, key revocation and management of security issues arising from the addition of new nodes. In this paper, we propose a key management scheme to meet the security requirements of wireless sensor networks. The scheme relies on the theory of random graph to build a fully secure connectivity for distributed sensor nodes. It uses heterogeneous structure to limit ranges of attacks, and utilizes hash chains to realize authentication of pool keys and broadcast messages of auxiliary nodes. The security and network connectivity characteristics supported by the key management scheme are discussed and simulation experiments are presented.
Huawei Zhao, Jiankun Hu, Jing Qin 0002, Vijay Varadharajan, Haishan Wan
TrustCom3