Yan Zhang 0097

dblp:04/3348-97 · DBLP profile ↗
← Back
8ranked-venue papers
5as first author
8since 2021 · last 2026
0000-0003-2092-2195ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 3 first-author · 5 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2026 An Efficiency-Improved and Conditional Privacy-Preserving Authentication Scheme Based on Merkle Hash Tree in MEC
abstract
Authentication is an important security issue for multi-access edge computing (MEC). However, the existing authentication schemes have not achieved a good balance between privacy preserving, efficiency, and low computation overhead on the device side. To address this issue, we propose an efficiency-improved and conditional privacy-preserving authentication scheme suitable for resource-constrained MEC devices. Our core idea is integrating the merkle hash tree (MHT) into the anonymous authentication scheme constructed by the blockchain and key derivation function (KDF) to improve efficiency. The MHT not only reduces the on-chain storage overhead brought by the increasing pseudo-public keys of KDF, but also utilizes few hash functions to achieve lightweight${\bm {k}}$-times authentications with the same edge server. Despite these advantages, managing pseudo-key pairs in the form of MHT leafs still brings efficiency and unlinkability problems. We construct the partially shuffled merkle hash tree to only shuffle leafs within the device group, and combine with the KDF to update MHTs in a public manner by synchronizing pseudo-key pairs. Consequently, the efficiency of key update can be ensured. Moreover, a time-bound key derivation function based on physically unclonable function and BIP-32 is developed to provide immediate and permanent device revocation. Only the remaining valid pseudo-public keys of the revoked device will be recorded on the blockchain, which reveals no linkable information and avoids frequently reconstructing all the MHTs. We prove the authentication security and discuss other security features. A proof-of-concept prototype was implemented to conduct experiments and comparative analysis for performance evaluation.
Yan Zhang 0097, Chunsheng Gu, Peizhong Shi, Zhengjun Jing, Weizhi Meng 0001
IEEE Trans. Dependable Secur. Comput.1
2025 Repeated Game-Based Long-Term Incentive Mechanism for Blockchain-Enabled Reliable Federated Learning in IIoT
abstract
Federated Learning (FL) has emerged as a promising paradigm for privacy-preserving collaborative model training in the Industrial Internet of Things (IIoT). By leveraging the decentralization, immutability, and transparency of blockchain technology, Blockchain-enabled FL (BFL) has gained significant attention for enhancing FL’s security and reliability. However, BFL still faces challenges in motivating client participation. While several incentive mechanisms have been proposed, most primarily focus on short-term rewards and overlook the long-term influence of individual contributions on global model performance. To address these challenges, we propose a novel BFL framework that integrates model training with blockchain mining on the client side. Specifically, we design a long-term incentive mechanism based on repeated game theory, where the interactions between participants and the task publisher (TP) are modeled as an infinitely repeated game. We formally prove the existence of a Subgame Perfect Nash Equilibrium, providing theoretical guarantees for stable long-term cooperation. Furthermore, we introduce a hybrid reward scheme that jointly considers contributions to both training and mining tasks, encouraging sustained engagement and attracting new participants. Extensive experiments on MNIST and CIFAR-10 validate that the proposed mechanism enhances the robustness of FL and effectively promotes long-term client participation.
Baofu Han, Yan Zhang 0097, Pan Feng, Katinka Wolter, Hao Zhang 0056, Raja Jurdak, Chau Yuen
IEEE Internet Things J.3
2025 Bring Your Device Group (BYDG): Efficient and Privacy-Preserving User-Device Authentication Protocol in Multi-Access Edge Computing
abstract
Authentication is an important security issue for multi-access edge computing (MEC). To restrict user access from untrusted devices, Bring Your Own Device (BYOD) policy has been proposed to authenticate users and devices simultaneously. However, when integrating BYOD policy into MEC authentication to improve security, issues of efficient binding and user-device conditional anonymity have not been well supported. To address these issues, we propose Bring Your Device Group (BYDG) policy by constructing efficient and privacy-preserving user-device authentication. Our core idea is to use key sequences generated by PUFs-based key derivation functions (KDFs) to not only construct efficient binding relationships, but also achieve conditional anonymity for device groups. Specifically, a flexible and secure binding method is first developed by leveraging Chinese Remainder Theorem (CRT) to bind user with device groups. Each device’s CRT modulus is derived from the key sequence to construct many-to-many user-device binding relationships, which are managed in the form of on-chain Pedersen Commitment. Moreover, we design an identity anonymizing and tracing method for device groups. The key sequence is regarded as traceable device pseudo-identities, and then inserted into the cuckoo filter to reduce the on-chain storage overhead and mitigate malicious login attempts with low costs. Based on above two methods, the combination of Pedersen Commitment and Zero-Knowledge Proof of Knowledge is used to achieve user-device authentication with conditional anonymity. The security analysis was presented to demonstrate important security properties. A proof-of-concept prototype was implemented to conduct performance evaluation and comparative analysis.
Yan Zhang 0097, Chunsheng Gu, Peizhong Shi, Zhengjun Jing, Bo Liu 0001
IEEE Trans. Inf. Forensics Secur.1
2024 Building PUF as a Service: Distributed Authentication and Recoverable Data Sharing With Multidimensional CRPs Security Protection
abstract
Physically Unclonable Functions (PUFs) have emerged as hardware fingerprints for IoT devices in the form of challenge-response pairs (CRPs). This mapping behaviour is regarded as a physically secure primitive, activating mechanisms of authentication and data protection. However, multidimensional security threats to CRPs, including impersonation attacks, availability attacks, machine learning attacks, and single point failure, impede the applications of PUFs technology. To simultaneously solve these threats, this paper not only leverages Shamir secret sharing (SSS) to provide comprehensive CRPs protection, but also integrates blockchain to address trust issues of synchronization, supervision, and deployment brought by the SSS system. Specifically, we first propose a security-enhanced and reliable CRPs management method. This method leverages SSS and its homomorphic addition feature to protect CRPs storage, sharing, and backup processes. Meanwhile, blockchain is involved in the SSS system to synchronize CRPs and supervise sharing behaviours. Then, a PUF-as-a-service (PaaS) framework is constructed, which utilizes blockchain to trace the change of the SSS system and integrate different PUFs-based security mechanisms. Once deployed in PaaS, users can always utilize transactions to build secure on-chain channels with SSS system and employ the PUF service. Based on our CRPs management method and PaaS framework, we successfully constructed PUFs-based distributed authentication and recoverable data sharing with multidimensional CRPs protection. The security proof and discussions of our scheme are also provided. Moreover, a proof-of-concept prototype was implemented to conduct experimental evaluations and comparative analysis. The results and additional discussions demonstrate that our work is efficient, practical, and suitable for IoT deployment.
Yan Zhang 0097, Bo Liu 0001, Jinke Chang
IEEE Internet Things J.1
2023 A novel blockchain's private key generation mechanism based on facial biometrics and physical unclonable function
Yazhou Wang 0006, Yan Zhang 0097, Guozhu Liu, Zhen Mao
J. Inf. Secur. Appl.3
2022 Novel Strong-PUF-Based Authentication Protocols Leveraging Shamir's Secret Sharing
abstract
Physical unclonable function (PUF) has emerged as an attractive hardware primitive for lightweight authentication in the Internet of Things (IoT). However, strong-PUF-based authentication schemes are threatened by powerful machine learning attacks. Therefore, dedicated lightweight protocols are required to preserve the privacy of the embedded strong PUF. In this article, we show that the “availability” and “reliability” features of Shamir’s secret sharing (SSS) can be applied to address the security issue. In protocol A, the mappings between challenges and responses are randomly shuffled to resist the machine learning attacks. Leveraging the “availability” feature of SSS, the verification process is unaffected by the randomized challenge–response pairs (CRPs) at the server end. Moreover, the “reliability” feature of SSS provides the error-tolerant characteristic in our protocol, which is suitable for the noisy PUFs. Protocol A also presented a method to securely store the CRPs at the server side. The improved protocol A optimizes protocol A by eliminating the response storage and matching process at the server end. In protocol B, we present a mutual authentication protocol, where no response is exposed to the adversary. Protocol B can be classified as the lightweight protocol because it can avoid the use of cryptographic algorithms and error-correcting codes. We rigorously analyze and prove the security of our protocols with formal security proofs, informal security analysis, and several selected machine learning techniques, including logistic regression (LR), the deep neural network (DNN), approximate attack, AutoGluon-Tabular, and a new brute-force machine learning attack. Furthermore, we present an efficient implementation of our protocols on FPGA. The experimental results show the feasibility and practicability of our protocols under different parameters.
Yan Zhang 0097, Caicai Wang, Cheng Tao 0006
IEEE Internet Things J.4
2022 Efficient and Privacy-Preserving Blockchain-Based Multifactor Device Authentication Protocol for Cross-Domain IIoT
abstract
Industrial Internet of Things (IIoT) has emerged as a prospective technology that improves the productivity and automation level for industrial applications. Devices from cooperative IIoT domains will communicate and collaborate on the increasingly complicated manufacturing tasks. To secure cross-domain device collaborations, we propose combining the blockchain with multifactor authentication. Because the multifactor authentication conforms to IIoT devices’ operation modes and brings higher security levels, and the blockchain technology contributes to building trust among different domains. However, this combined usage still has limitations in terms of the potential loss of factor attack, the storage overhead on the blockchain, and the contradiction between efficiency and privacy preservation. Motivated by these facts, in this article, we develop a privacy-preserving blockchain-based multifactor device authentication protocol for cross-domain IIoT. Specifically, multiple factors are additionally encoded by the hardware fingerprint into random numbers, before being transformed into key materials. The blockchain only stores each domain’s dynamic accumulator, which accumulates derived key materials for devices, thereby reducing the overhead. Moreover, the on-chain accumulator is leveraged to efficiently verify the unlinkable identities of cross-domain IIoT devices. The security of our protocol is formally proved, and the security features and functionalities are, respectively, discussed. A proof-of-concept prototype was implemented to prove the efficiency and reliability. The comparison results indicate that the on-chain storage is greatly reduced. Finally, the smart contract’s performance was evaluated to show scalability.
Yan Zhang 0097, Bo Liu 0001, Rui Chen 0014, Jinke Chang
IEEE Internet Things J.1
2021 A Privacy-Aware PUFs-Based Multiserver Authentication Protocol in Cloud-Edge IoT Systems Using Blockchain
abstract
The combination of the Internet of Things (IoT) and cloud-edge (CE) paradigm promises to be an efficient system to aggregate and further process huge volumes of data from IoT nodes. Physical unclonable functions (PUFs) emerge as a prospective primitive to provide IoT nodes with lightweight physical identities for authentication. However, when integrating PUFs into multiserver authentication protocols to improve security, the following problems occur: 1) the challenge–response pairs (CRPs) of PUFs generated by devices need to be explicitly stored by each edge server. This will cause the privacy leakage of CRPs; 2) the reliability is reduced resulting from the single point failure; and 3) existing PUFs-based authentication protocols would need to put great efforts into synchronizing CRPs, to ensure consistency in multiserver systems. To overcome these problems, in this article, we propose a privacy-aware authentication protocol for the multiserver CE-IoT systems by combining PUFs and the blockchain technique. The real correlations of CRPs are double encoded into mapping correlations (MCs) by a one-time physical identity and the keyed-hash function. The blockchain is leveraged to store MCs, synchronize them efficiently, and incorporate the multireceiver encryption to share the physical identity securely. The security of our protocol is formally proved by a random oracle model, and security features are discussed to show that our protocol resists various attacks. Moreover, a prototype was implemented to prove the efficiency of the protocol, and the comparison results present that our protocol accommodates CE-IoT systems. Finally, the simulation of the smart contract evaluates the scalability of our protocol.
Yan Zhang 0097, Bo Liu 0001, Haipeng Zheng
IEEE Internet Things J.1