VLDB 2026 Research / reviewers in the wild / expert
Jing Zhang 0024
dblp:05/3499-24
· DBLP profile ↗
49ranked-venue papers
14as first author
41since 2021 · last 2026
0000-0001-7417-9689ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 20 · 4 first-author · 17 since 2021Security and privacy · 13 · 6 first-author · 12 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 3 first-author · 7 since 2021Systems, architecture and hardware · 4 · 4 since 2021Databases, data management, data science and information retrieval · 4 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Privacy-Accountable Distributed Collaborative Authentication for Malicious Node Resistance in Vehicular Ad Hoc NetworksabstractIn vehicular ad hoc networks (VANETs), distributed identity authentication provides the foundation for securing sessions among entities over wireless channels while eliminating single points of failure. However, existing distributed authentica tion schemes for VANETs typically make unrealistic assumptions about node reliability and trustworthiness, failing to account for scenarios where authentication nodes may be compromised or collude with vehicles. Moreover, these schemes expose the com munication process to linkability attacks while allowing vehicles to self-register their public keys. To address these limitations, we propose a privacy-preserving and accountable distributed collab orative authentication scheme for VANETs that is resilient to ma licious nodes. Using threshold signature techniques, distributed authentication nodes collaboratively perform decentralized ve hicle identity authentication using a predefined threshold. Zero knowledge proof protects the privacy of the signing process while maintaining accountability and effectively preventing malicious behavior by nodes under external or internal adversarial attacks. Furthermore, vehicles self-register their public keys via smart contracts and blockchain technology, ensuring anonymity and unlinkability during registration while enabling the traceability of malicious vehicles. Security and performance analyses show that the proposed scheme enhances the security and robustness of distributed collaborative authentication in VANETs, achieving a better balance between computational and communication costs than existing schemes Ru Li 0005, Jie Cui 0004, Lu Wei 0003, Irina Pavlovna Bolodurina, Jing Zhang 0024, Hong Zhong 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Blockchain-Assisted Secure Announcement Sharing Scheme With Controllable Verifiable Distributed Security for VANETsabstractIn recent years, vehicle announcement sharing has become increasingly important in intelligent transportation networks. However, the demand for secure communication and real-time responses necessitates the development of an efficient and confidential announcement sharing scheme. Existing solutions are constrained by inadequate privacy in inter-group sharing and lack of storage security consideration. To address these issues, we propose a blockchain-assisted secure announcement sharing scheme with controllable verifiable distributed security. This scheme constructs a re-encrypted group signature framework to achieve controlled confidentiality of announcements while ensuring efficient and secure sharing. Additionally, by designing a lightweight verification algorithm powered by the Inter Planetary File System (IPFS) and blockchain, the scheme ensures rapid verifiable secure both the initial and long-term storage of announcements. Security proof and analysis show that the proposed scheme offers enhanced security and robust privacy protection. Performance analysis demonstrates that, while providing better computational efficiency than other schemes, the proposed scheme maintains low communication overhead and smaller storage verification costs, outperforming existing announcement sharing schemes. Jie Cui 0004, Jing Zhang 0024, Ru Li 0005, Yimin Wang 0004, Irina Pavlovna Bolodurina, Hong Zhong 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2026 | Blockchain-Assisted Message Reporting Scheme With Weighted Threshold Signature for Vehicular Ad-Hoc NetworksabstractIn vehicular ad-hoc networks (VANETs), message reporting is an effective method for improving traffic safety and efficiency. Most existing VANET message reporting schemes rely on the trust value of a single vehicle to determine message authenticity, which leads to unreliable message sources. Even multi vehicle-assisted reporting schemes are limited by the assumption that all vehicles have the same credibility, which does not reflect the actual dynamic VANET environment in which vehicles have different credibilities. To address this issue, we propose a blockchain-assisted VANET message reporting scheme with weighted threshold signatures. Through the design of weights, the credibility of different vehicles is quantified, and the impact of vehicles on the signing process is differentiated. Threshold signature generation relies on the weight sum of all signatories reaching a predetermined threshold, to enable flexible and reliable message reporting. Security analysis shows that our proposed scheme combined with blockchain can satisfy the security and privacy requirements of VANET message reporting. Performance analysis indicates that our proposed scheme outperforms the most advanced VANET message reporting schemes in terms of transmission and computation performance. Ru Li 0005, Jie Cui 0004, Jing Zhang 0024, Lu Wei 0003, Hong Zhong 0001, Debiao He |
IEEE Trans. Mob. Comput. | 3 |
| 2026 | Toward Stable and Low-Latency Task Offloading: A Multi-Agent Framework for Vehicular Edge Computing
Lu Wei 0003, Jie Cui 0004, Xianfeng Xie, Jing Zhang 0024, Irina Pavlovna Bolodurina, Hong Zhong 0001 |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2025 | CAUA: A Realistic and Effective Attack on Machine Unlearning Under Limited InformationabstractMachine unlearning aims to remove specific data from models to meet privacy regulations. While prior work has explored potential vulnerabilities in unlearning mechanisms, most assume adversaries with privileged access—an unrealistic premise in real-world Machine Learning-as-a-Service (MLaaS) settings. This raises a fundamental question: Can unlearning be exploited under restricted access constraints? We answer this affirmatively by proposing Class-Aligned Unlearning Attack (CAUA), a novel attack framework tailored to realistic deployment settings. CAUA uses target-class examples and public out-of-distribution data to generate semantically aligned inputs that integrate seamlessly into training. These inputs maintain model performance during training but, when unlearned, induce localized representation collapse and significant shifts in decision boundaries. We comprehensively evaluate CAUA across multiple datasets and unlearning paradigms. Notably, unlearning just 0.2% of training data causes up to a 73.4% drop in target-class F1 and a 60.4% drop in overall accuracy, revealing a previously overlooked vulnerability. Our work sheds new light on the risks of machine unlearning and lays a foundation for building more robust defenses. Jing Zhang 0024, Jie Cui 0004, Xianfeng Xie, Chunyang Fan |
ACSAC | 1 |
| 2025 | Edge Computing-Based Anonymous Cross-Domain Authentication Scheme for VANETsabstractIn the vehicular ad-hoc networks (VANETs), crossdomain communication among vehicles significantly improves traffic efficiency and road safety. However, due to the vulnerabilities of vehicle communication, it faces numerous security challenges when performing cross-domain communication. Existing schemes rely on trusted third parties for cross-domain authentication, resulting in issues such as low computational efficiency and weak privacy protection for vehicles, which cannot meet the demands of large-scale vehicle cross-domain communication. To address these problems, we propose an efficient and anonymous cross-domain authentication scheme based on edge computing. By using edge gateways to manage vehicle groups and handle cross-domain event requests, we solve the performance bottleneck issues caused by centralized authentication. Additionally, the use of a batch authentication mechanism further improves computational efficiency during large-scale authentications and reduces authentication latency. Security and performance analyses show that the proposed scheme can meet the security and performance requirements for cross-domain vehicle communication. Hong Zhong 0001, Chengdong Gu, Jing Zhang 0024, Qingyang Zhang 0001, Jiaxin Li 0001, Jie Cui 0004 |
HPCC | 4 |
| 2025 | TDID: A Three-Factor Decentralized Identity Authentication Scheme in MetaverseabstractThe Metaverse, an immersive parallel digital world, faces critical security challenges such as data leakage and impersonation attack. Existing authentication schemes often suffer from single-point failures due to centralization, incomplete decentralization, and low efficiency. To address these challenges, this paper proposes TDID, a three-factor decentralized identity authentication scheme. Our core contribution lies in the novel synergy of a confidential smart contract, executed within a Trusted Execution Environment (TEE), with the offline attackresistant OPAQUE password-authenticated key exchange protocol. The scheme achieves full decentralization by using the TEE-based contract as a decentralized root of trust. It allows users to establish a globally unique, collision-resistant identity, and ensures that a user's password and biometric key are never revealed to the server during authentication, thus providing robust resistance against offline dictionary attacks even from a compromised server. Rigorous security analysis, including formal verification using ProVerif and a provable security proof, along with performance evaluations, demonstrates that the proposed scheme significantly enhances security while maintaining efficient computational and communication performance. Jie Cui 0004, Mengfei Cheng, Jing Zhang 0024, Li Wang 0139, Irina Pavlovna Bolodurina, Hong Zhong 0001 |
ICPADS | 3 |
| 2025 | FEELPGen: Data-Free Knowledge Distillation for Personalized Federated Learning Across Heterogeneous Edge SilosabstractDeploying machine learning models on large-scale IoT devices in edge networks is challenging. Federated edge learning (FEEL) has emerged as a potential solution based on a hierarchical architecture. However, existing research relies primarily on an idealized cross-device assumption, overlooking more realistic cross-silo scenarios where devices typically belong to different organizational silos. To facilitate multi-group collaboration, we first propose a semi-decentralized FEEL structure called FEELPGen, in which different silos collaborate in training to maximize local model benefits without relying on trusted third-party coordination. Based on that, a two-layer aggregation algorithm is proposed to enhance the generalization ability under highly heterogeneous data distribution. For inner-silo learning, we devise a heterogeneity-aware, synchronous inner-silo aggregation algorithm utilizing data-free knowledge distillation based on generative learning (Gen). Feature vectors are generated to approximate silo knowledge. For inter-silo learning, a personalized (P), asynchronous inter-silo aggregation algorithm is proposed with adaptive selection and dynamic weight queues. To further improve efficiency, we introduce an optional optimized scheme, FEELPGen+, which integrates a privacy-preserving dimension-reduction algorithm. Finally, we provide a detailed analysis for convergence and complexity to verify the feasibility of FEELPGen. Extensive experiments demonstrate that FEELPGen achieves significant improvement in accuracy compared to the state-of-the-art schemes. Hong Zhong 0001, Jing Zhang 0024, Qingyang Zhang 0001, Jie Cui 0004 |
IEEE Internet Things J. | 4 |
| 2025 | Achieving Fair and Efficient Revocable Access Control for IIoT Data Sharing: A Blockchain-Enabled ApproachabstractWith the advancement of computing and communication technologies, Industrial Internet of Things (IIoT) has emerged accordingly. In IIoT environments, efficient data sharing is achieved through collaboration among end devices, edge servers, and cloud servers. However, ensuring the security, efficiency, and fairness of service data access for end devices remains a significant challenge. To address this, we propose a fair and efficient revocable access control scheme based on blockchain. The proposed scheme leverages smart contracts to establish a fair payment mechanism, ensuring fairness for IIoT data sharing. In addition, a proxy-assisted decryption approach is employed to minimize the decryption overhead on end devices. Moreover, the scheme supports efficient user revocation without requiring updates to the private keys of end users. This enhances the overall security and usability of the system. Finally, a thorough security and performance analysis indicate that the proposed scheme fits well within IIoT scenarios. Hong Zhong 0001, Jing Zhang 0024, Qingyang Zhang 0001, Jiaxin Li 0001, Jie Cui 0004 |
IEEE Internet Things J. | 3 |
| 2025 | CFTD: Core Fusion Time Series Dense Encoder for Intelligent Prediction With Edge AI in Social IoT SystemsabstractThe rapid development of the Internet-of-Things (IoT) has transformed human interaction with the world. The Social Internet-of-Things (SIoT) integrates social, emotional, and behavioral aspects into traditional IoT, creating an intelligent network that connects various smart devices. By combining Edge Computing with Artificial Intelligence (AI), data can be processed and analyzed directly on edge devices, improving processing efficiency. However, limited edge resources hinder local AI training, requiring cloud-based training of high-precision models, which are then deployed on edge devices for inference. In time series forecasting, Multilayer Perceptrons (MLPs) are widely used for their computational efficiency but often overlook correlations between time series. Some models adopt channel mixing mechanisms to improve modeling capability but increase computational complexity. To address this problem, we propose the Core Fusion Time Series Dense Encoder (CFTD) model, which incorporates a Core Extract-Distribute (COED) module for efficient channel fusion. Extensive experiments on real-world datasets demonstrate that this novel CFTD model achieves excellent predictive performance compared to the state-of-the-art models. Yao Lu 0021, Ziheng Suo, Jing Zhang 0024, Lu Liu 0001, Geyong Min |
IEEE Internet Things J. | 4 |
| 2025 | Blockchain-Assisted Revocable Cross-Domain Authentication for Vehicular Ad-Hoc NetworksabstractWith the rapid development of vehicular ad-hoc networks (VANETs) and the increasing diversification of user demands, interactions between different management domains have become more frequent. Identity authentication is an effective way to establish cross-domain trust and secure communication. However, the existing cross-domain authentication schemes of VANETs are limited to the same management or authentication technology for each domain and rely on centralized cross-domain identity management. Even distributed management solutions encounter latency sensitivity, security and privacy challenges. To address these challenges, we propose a blockchain-assisted revocable cross-domain authentication scheme for VANETs. The proposed scheme can establish trust between domain entities by deploying different authentication methods and using distributed management to avoid single-point failures. In addition, the scheme can revoke the identity of malicious vehicles by updating the group public key, thereby ensuring the security and privacy of cross-domain Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I) communication. This design avoids the additional impacts of blockchain technology constraints on the high mobility and real-time requirements of VANETs. Security analysis and performance evaluation show that our scheme can resist more attacks and has better security than other related schemes while also achieving a better balance between communication and computational cost. Ru Li 0005, Jie Cui 0004, Jing Zhang 0024, Lu Wei 0003, Hong Zhong 0001, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | DBCSec: DBC File-Guided Secure Communication Mechanism for CAN-FD BusabstractThe network architecture of modern vehicles is composed of multiple communication protocols and electronic control units (ECU). Compared to the widely used protocol of Controller Area Network (CAN), CAN with Flexible Data-Rate (CAN-FD) protocol is suitable for applications requiring higher data throughput. However, the CAN-FD bus is vulnerable to intrusion by external attackers. Nowadays, several secure mechanisms have been proposed to protect the security of in-vehicle data. However, there are still two issues: 1) Most schemes use a centralized controller for key distribution, which can easily lead to a single point of failure; 2) The existing key management modes are not suitable for real-world CAN-FD networks in vehicle manufacturing. To address these issues, we propose a lightweight semi-decentralized scheme based on Database CAN (DBC) files to secure in-vehicle communication. ECUs are grouped on the send-receive relationships set in the DBC file, considering both the communication mode and sending efficiency. Furthermore, the proposed scheme overcomes reliance on long-term keys. Moreover, the security is analyzed by the random oracle model. The performance analysis is evaluated on microcontroller units (MCU) STM32H743IIT and Raspberry Pi 3B. The proposed scheme optimizes the computational costs of authentication, key agreement, and secure communication stages by up to 97.89%, 99.95%, and 82.35%, and optimizes the communication costs by up to 75.52%, 98.42%, and 29.41% compared to existing methods. Simulation experiments demonstrate that the bus load of the scheme increases by up to 9.84% compared to the baseline network. Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Qingyang Zhang 0001, Lu Wei 0003, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | BAST: Blockchain-Assisted Secure and Traceable Data Sharing Scheme for Vehicular NetworksabstractIn vehicular networks, caching service content on edge servers (ESs) is a widely accepted strategy for promptly responding to vehicle requests, reducing communication overhead, and improving service experience. However, implementing such an architecture requires addressing the challenges associated with ES response data reliability and communication security. In this study, to tackle the ES response data reliability issue, a blockchain-assisted threshold signature scheme for cache-based vehicular networks is proposed. The scheme utilizes a threshold mechanism to sign the data broadcast by the ES, incorporates blockchain to trace malicious signers, and avoids the shortcomings and limitations associated with idealized assumptions for the ES in existing data-sharing schemes. Moreover, considering the communication security and high-speed mobility of vehicles, using the non-interactive signatures of knowledge based on the Σ-protocol, a secure and efficient message authentication scheme for vehicles and ESs is provided. Through rigorous security proofs and comprehensive analyses, our scheme satisfies the communication security requirements of vehicular networks. By leveraging the JPBC library for performance analysis, the proposed scheme demonstrates advantages as concerns both computation and communication overheads compared to related schemes. Moreover, we implemented the proposed scheme on an Ethereum test network (i.e., Goerli) to validate its feasibility. Xinzhong Liu 0002, Jie Cui 0004, Jing Zhang 0024, Rongwang Yin, Hong Zhong 0001, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | A Decentralized Threshold Credential Management With Fine-Grained Authentication for VANETsabstractIn Vehicular Ad-hoc Networks (VANETs), vehicles must authenticate their identities before accessing services. However, existing authentication schemes based on anonymous credentials still face single-point failure in multi-authority scenarios. In addition, in traditional anonymous credential schemes, the public key of credential authority is used directly to verify the credential, which may increase the risk of vehicle privacy being misused. To address these issues, we propose a decentralized threshold credential management system with fine-grained authentication for VANETs. The decentralized credential management architecture is proposed for VANETs with multiple credential authorities, each credential authority consists of multiple credential managers who issue credentials using the threshold mechanism, effectively solving the single-point failure. Based on this architecture, we design a fine-grained, privacy-preserving authentication scheme that allows vehicles to autonomously perform selective attribute disclosure, credential aggregation, and randomization before requesting verification from the Cloud Service Provider, thereby achieving a balance between privacy preservation and authentication efficiency. The security proofs and analysis show that our scheme satisfies the target security properties. Performance evaluations indicate that our scheme enables efficient, flexible credential management and authentication in VANETs while ensuring privacy preservation. Jing Zhang 0024, Xin Wang 0225, Jie Cui 0004, Ru Li 0005, Hong Zhong 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | False Message Detection System for VANETs: A Reputation Evaluation Method Based on Voting MechanismabstractVehicular ad hoc networks (VANETs) enable vehicles to engage in vehicle-to-vehicle and vehicle-to-infrastructure communications to enhance driving safety. However, the open nature of the network and the uncertainty of information sources make VANETs vulnerable to false message attacks, potentially causing severe traffic accidents. Existing false-message detection systems suffer from high false alarm rates and high resource consumption. To address these challenges, we propose a false message attack detection system based on a software-defined network architecture that can efficiently and accurately detect false message attacks with minimal consumption of system resources. The system aims to detect emergency and normal beacon messages broadcast by vehicles, construct an automotive reputation evaluation system using the voting mechanism of the Byzantine consensus, and introduce an XGBoost-based traffic event classifier to improve classification accuracy. Experimental results show that the system can reliably assess vehicle reputation levels, effectively defend against conspiracy attacks, and perform well in intrusion detection. Jie Cui 0004, Danting Yu, Jing Zhang 0024, Lu Wei 0003, Xianfeng Xie, Irina Pavlovna Bolodurina, Hong Zhong 0001 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2025 | Reputation System-Based Vehicle Violation Reporting Service With Invalid Signature Identification in VANETsabstractOwing to frequent traffic accidents, the violation reporting service is a promising method to enhance road safety in vehicular ad hoc networks (VANETs). However, to implement such a service, it is critical to ensure security, privacy, and efficiency when vehicles send messages to roadside units (RSU). In this study, to address these issues, a vehicle violation reporting service is proposed using reputation systems and a physically unclonable function. The proposed scheme ensures secure authentication between vehicles and RSUs, facilitates an efficient search for invalid signatures, and overcomes the limitations present in ID-based conditional privacy-preserving authentication schemes. Moreover, considering the dynamic VANET environment, the distribution of invalid signatures may vary across multiple scenarios. Therefore, a fault-tolerant mechanism is proposed to ensure the robustness of this approach. Security proof with the random oracle model and detailed security analysis proved that the scheme could satisfy the security requirements of VANETs. Our scheme outperforms related approaches in terms of authentication overhead and the identification of invalid signatures, achieving superior performance in both aspects. Jing Zhang 0024, Chengzhi Xia, Jie Cui 0004, Hong Zhong 0001, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2025 | Security-Enhanced Data Sharing via Efficient Sanitization for VANETsabstractWith the widespread deployment of vehicular ad-hoc networks (VANETs), data sharing has garnered considerable attention as a core feature of VANETs. Attribute-based proxy re-encryption (ABPRE) enables fine-grained access control and provides flexible ciphertext updates. The initially authorized vehicle generates the re-encryption key to enable ciphertext-to-ciphertext conversion in the cloud, allowing ciphertext to be shared with new recipients. However, initially authorized vehicles may not always be trustworthy and could share data with malicious receivers. In addition, the computation and communication overhead of ABPRE hinders its widespread application in VANETs. To address these issues, we propose a lightweight sanitizable scheme for edge-assisted VANETs based on ABPRE. In this scheme, the re-encryption key is verified by a sanitizer, to prevent the data from being shared with malicious data receivers. In addition, key-splitting techniques and edge computing are employed to reduce the communication and computation overhead of re-encryption. A comprehensive security analysis and performance evaluation demonstrate that the proposed scheme is efficient and practical. Hong Zhong 0001, Jie Cui 0004, Li Wang 0139, Jing Zhang 0024, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Mob. Comput. | 5 |
| 2025 | A Distributed Data-Driven and Machine Learning Method for High-Level Causal Analysis in Sustainable IoT SystemsabstractA causal relationship forms when one event triggers another's change or occurrence. Causality helps to understand connections among events, explain phenomena, and facilitate better decision-making. In IoT systems, massive consumption of energy may lead to specific types of air pollution. There are causal relationships among air pollutants. Analyzing their interactions allows for targeted adjustments in energy use, like shifting to cleaner energy and cutting high-emission sources. This reduces air pollution and boosts energy sustainability, aiding sustainable development. This paper introduces a distributed data-driven machine learning method for high-level causal analysis (DMHC), which extracts general and high-level Complex Event Processing (CEP) rules from unlabeled data. CEP rules can capture the interactions among events and represent the causal relationships among them. DMHC deploys a two-layer LSTM attention mechanism model and decision tree algorithm to filter and label data, extracting general CEP rules. Afterward, it proceeds to generate event logs based on general rules with heuristic mining (HM), extracting high-level CEP rules that pertain to causal relationships. These high-level rules complement the extracted general rules and reflect the causal relationships among the general rules. The proposed high-level methodology is validated using a real air quality dataset. Wangyang Yu 0001, Jing Zhang 0024, Lu Liu 0001, Xiaojun Zhai, Ruhul Kabir Howlader |
IEEE Trans. Sustain. Comput. | 2 |
| 2024 | Improved PBFT Consensus Based on Reputation System in Vehicle NetworkabstractBlockchain technology is a decentralized distributed database technology, which greatly improves the security and credibility of the data exchange process through decentralization. A great deal of research has already been conducted on combining blockchain and vehicular ad-hoc networks(VANETs) applications to solve the problems of opaque user transactions, data tampering, and insufficient motivation of participating parties. However, in the large-scale VANETs, the commonly used blockchain consensus mechanism PBFT suffers from poor scalability, high communication volume, and insufficient control of node behaviour. Therefore, in this paper, an improved consensus mechanism N-PBFT is designed for the field of VANETs based on the construction of vehicle trust management system. The improved consensus mechanism N-PBFT solves the problems of node identity peering, poor scalability, and high communication volume. After experimental testing, the proposed reputation system is able to effectively manage the information of the VANETs. And the improved PBFT consensus algorithm has a significant performance improvement over the traditional PBFT, SG-PBFT and RIPPB in terms of both throughput and latency. Jing Zhang 0024, Peiyv Yang, Jie Cui 0004, Lu Wei 0003, Hong Zhong 0001 |
BDCAT | 1 |
| 2024 | Multi-Authority Ciphertext-Policy Attribute-based Encryption with Hidden Policy for Securing Internet-of-VehiclesabstractWith the rapid development of the Internet-of-Vehicles (IoV) technologies, security and privacy issues associated with IoV data sharing have become increasingly prominent. Although attribute-based encryption (ABE) schemes offer effective solutions to these problems, the prevalent single-point failure vulnerabilities and risks of user privacy leakage in existing ABE schemes must be addressed. To this end, an original hidden policy scheme based on multi-authority ciphertext policy ABE is proposed. This scheme validates users by introducing multiple attribute authorities and generating intermediate attribute keys, effectively dispersing single-point performance pressure. Simultaneously, partial policy-hiding techniques are developed to ensure efficient system operation while protecting user privacy. Furthermore, this scheme introduces a central authority to track potentially malicious attribute authorities, preventing them from continuously generating incorrect attribute intermediate keys, thereby maintaining the overall security of the system. Additionally, by updating and revoking attribute versions, a flexible attribute revocation mechanism is achieved to further enhance system flexibility. Through in-depth security and performance analyses, the scheme is proven to be both secure and efficient for securing IoV. Jie Cui 0004, Jing Zhang 0024, Lu Wei 0003, Hong Zhong 0001, Geyong Min |
TrustCom | 2 |
| 2024 | Cross-Domain Authentication Scheme for Vehicles Based on Given Virtual IdentitiesabstractThe advancement of intelligent transportation systems has enhanced both vehicle ad hoc networks (VANETs) and road safety. However, traditional cross-domain scenarios in VANETs face challenges such as the computational burden of identity and message authentication, as well as privacy breaches. In this study, to mitigate the issues surrounding communication security and the significant computational overhead within traditional cross-domain scenarios in VANETs, we propose a certificate-based cross-domain authentication scheme specifically tailored for VANETs. Moreover, considering the inter-domain vehicle authentication challenges, the scheme introduces an efficient batch verification mechanism suitable for dynamic multi-vehicle cross-domain scenarios. To mitigate the potential single point of failure, a two-way synchronization database mechanism is presented, ensuring uninterrupted operations in case of primary database failure. Moreover, privacy protection for vehicles is enhanced through the use of virtual identities. Through rigorous security proofs and detailed security analyses, we demonstrate that the scheme meets the security requirements of vehicular networks and can resist more security attacks. Moreover, performance analysis highlights its superiority over related advanced schemes in cross-domain VANET scenarios. Through performance evaluation using the JPBC library and comparison with relevant schemes, the proposed solution demonstrated superior results in terms of communication and computational overhead. Jing Zhang 0024, Xiyang Wei, Yibo Wang 0017, Jie Cui 0004 |
IEEE Internet Things J. | 2 |
| 2024 | Secure and Efficient User-Centric V2C Communication for Intelligent Cyber-Physical Transportation SystemabstractRecently, the concept of intelligent cyber-physical transportation systems (ICTS) has entered the vehicle network, providing more efficient, safe, and sustainable services by applying intelligent technology to the transportation system. Because the communication channel between the vehicle and the cloud service provider (CSP) is open and insecure. Therefore, we must construct a secure Vehicle-to-CSP (V2C) communication scheme to ensure the security of vehicle privacy data. Current communication schemes mainly have two limitations. One is that the user’s role in communication is not considered, and the other is that the computational and communication overhead are not sufficiently low to satisfy the low latency requirements. To address the deficiencies, we propose a user-centric V2C communication scheme. The primary key in the signature is concealed, which ensures the confidentiality of the user’s legal real identity. Its main steps, based on the extended Chebyshev chaotic map and hash function, reduce the computational and communication overhead in the process. The security proof and analysis show that our proposed scheme satisfies the security and privacy requirements. The performance analysis shows that our proposed scheme outperforms other related schemes. Jing Zhang 0024, Ruonan Ying, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | A Multilevel Electronic Control Unit Re-Encryption Scheme for Autonomous VehiclesabstractElectronic control units (ECUs) connected by a controller area network (CAN) are used to perform various functions in modern vehicles. In the latest autonomous vehicles, redundant ECUs and a backup bus (different from CAN) are always equipped to prevent a single point of failure or network attack. However, due to the lack of protection measures of CAN bus, attackers can remotely intrude into the vehicle. Many schemes have proposed to use encryption to solve the security problem of CAN bus. Considering the current ECU storage space is limited, it is impossible to store all ECUs’ keys. When a single point of failure or network attack against an ECU occurs, it is necessary for the backup ECU to process the messages related to the failed ECU. How to ensure that the backup ECU can decrypt the encrypted messages and at the same time securely isolates the backbone network from the backup network is an urgent issue to be solved. In order to solve the problem of forwarding and processing such messages under encryption conditions, we propose an efficient re-encryption scheme based on proxy re-encryption. The scheme is also suitable for cross-bus communication without backup networks. Burrows-Abadi-Needham (BAN) logic, random oracle model and Automated Validation of Internet Security Protocols and Applications (AVISPA) tool are utilized to prove that the scheme is secure. The scheme is simulated based on the MIRACL cryptography library on the computer and Raspberry Pi. The simulation results demonstrate that the proposed scheme is secure compared with the existing scheme. Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Lu Liu 0001 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2024 | A Two-Layer Dynamic ECU Group Management Scheme for In-Vehicle CAN BusabstractTo enable the vehicle control system to provide better service, an increasing number of network nodes are being introduced into the vehicle; this also dramatically expands the attack surface of modern vehicles. In recent years, the security of vehicle communication buses and electronic control units (ECUs) has been extensively studied. However, in actual deployment, there is little concern for the fine management of secure communication schemes with respect to the security level of the ECU on the controller area network (CAN). On this basis, this paper proposes a two-layer ECU group dynamic management scheme based on the Chinese remainder theorem. Dynamic grouping management based on the credibility of ECUs while the vehicle is running can effectively balance efficiency and security. During communication, different groups use different modes to achieve higher efficiency. Security analysis shows that the proposed scheme can satisfy the requirements of security and privacy. Simulation results further demonstrate that the proposed scheme performs well in terms of computing and communication costs. Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2024 | CVAR: Distributed and Extensible Cross-Region Vehicle Authentication With Reputation for VANETsabstractThis study proposes a distributed and extensible cross-region vehicle authentication scheme with the reputation for improving the security and efficiency of cross-region vehicle authentication. The existing authentication schemes demonstrate the following drawbacks: 1) Each vehicle is preloaded with the same system private key, which may be leaked so that the entire system would be destroyed; 2) Other schemes rely on trusted authority to aid in selecting some cluster head nodes; 3) The existing cross-region authentication schemes are not flexible and scalable since they depend on the infrastructure fixed on the roadside. With the proposed scheme, each vehicle stores a long-term private key that is different from those of other vehicles, thereby avoiding a system crash when destroying a vehicle. When the cross-region vehicle enters a new region, it can verify the reputation value of the surrounding vehicles to select the edge computing vehicle. The formal security proof shows that the proposed scheme has adequate security under the real-or-random model. The performance evaluation of our scheme with several related schemes reveals that it generates relatively low computation and communication overhead, is more robust, and achieves minimum packet loss ratio and delay. Jing Zhang 0024, Hong Zhong 0001, Jie Cui 0004, Lu Wei 0003, Lu Liu 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2024 | LH-IDS: Lightweight Hybrid Intrusion Detection System Based on Differential Privacy in VANETsabstractVehicular Ad hoc Networks (VANETs) are vulnerable to various types of attacks. Intrusion Detection System (IDS) based on machine learning can effectively detect malicious network attacks in VANETs. However, machine learning training necessitates ample data which contain significant ample private information, increasing the risk of privacy disclosure. The privacy protection of training data for machine learning used in the IDS of VANETs is rarely investigated. Meanwhile, Differential Privacy (DP) is one of the most secure privacy protection methods based on perturbations. Therefore, we propose a lightweight hybrid IDS (LH-IDS) based on machine learning and DP. It uses algorithms based on unsupervised learning to detect anomalous network behaviour with high performance, especially unknown attacks in VANETs, while protecting data privacy. The DP is used to secure the privacy of the training data. Noise from different privacy budgets is added to datasets to obtain DP datasets. Subsequently, LH-IDS is used to verify the utility of the DP datasets. Extensive experiments confirm LH-IDS can not only detect anomalous and normal traffic with excellent performance but can also protect the private information of the training data. Additionally, the proposed model incurs only minimal CPU and memory overhead, making it a lightweight solution. Jie Cui 0004, Jietian Xiao, Hong Zhong 0001, Jing Zhang 0024, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | Privacy-Preserving and Secure Distributed Data Sharing Scheme for VANETsabstractData sharing is one of the essential services of vehicular ad hoc networks (VANETs), which primarily requires data security and access control, and ciphertext-policy attribute-based encryption (CP-ABE) is a promising tool. However, data sharing schemes of distributed CP-ABE have concerns about the single-point performance bottleneck and privacy leakage. The factor for the former is that the authority manages a disjoint attribute set. The latter is because the user's identity and attributes are required to submit to authorities, which targets to bind this information to decryption keys for collusion-resistant. We propose a privacy-preserving distributed data sharing scheme for VANETs. This scheme introduces asymmetric group key agreement to distributed CP-ABE, which realizes that multiple authorities manage an attribute, and the user can obtain the attribute key bound with his identity from any authority in the group. To match up to the requirement of privacy-preserving, a key extract protocol provided user anonymity is proposed, which implements that attribute keys can be obtained without revealing the user's identity and attributes. Moreover, partial policy hiding is satisfied. Finally, we analyze and evaluate the proposed scheme, and the results indicate that our scheme is secure and efficient. Li Wang 0139, Hong Zhong 0001, Jie Cui 0004, Jing Zhang 0024, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | DBCPA: Dual Blockchain-Assisted Conditional Privacy-Preserving Authentication Framework and Protocol for Vehicular Ad Hoc NetworksabstractVehicular ad hoc networks (VANETs) connect all vehicles through wireless channels. They provide extensive real-time traffic information services that improve driving safety and traffic management efficiency. However, VANETs are vulnerable to security attacks because of the open wireless nature of their communication channels. Most security mechanisms for traditional VANETs are centralized and have certain limitations in satisfying security requirements, such as anti-single-point failure, distributed security authentication of messages, and privacy preservation in VANETs. To address these issues, herein, we propose a dual blockchain-assisted conditional privacy-preserving authentication framework and protocol for VANETs. The identity authentication and privacy preservation of vehicles in VANETs can be realized without relying on a centralized trusted third party. The proposed scheme also allows for the conditional tracking of illegal vehicles. The decentralized dynamic revocation of illegal vehicles can be realized through smart contracts, rendering the scheme efficient and scalable. We implement this scheme in an Ethereum test network to demonstrate its feasibility and conduct an in-depth security analysis and comprehensive performance evaluation of the proposed scheme. The results demonstrate that the proposed scheme is an effective solution for the development of a decentralized authentication system for VANETs. Jing Zhang 0024, Jie Cui 0004, Debiao He, Irina Pavlovna Bolodurina, Hong Zhong 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | CBDDS: Secure and Revocable Cache-Based Distributed Data Sharing for Vehicular NetworksabstractIn vehicular networks, caching content on an edge server (ES) is a popular method for quickly responding to massive vehicle service requests, reducing communication delays, and enhancing driver and passenger service experiences. However, after integrating ESs with vehicular networks to provide vehicles access to the cached content in these ESs, significant challenges regarding protecting the privacy of vehicle data and communication security arise. In this study, to address security and privacy-preserving issues, we propose a secure and revocable cache-based distributed data sharing scheme for vehicular networks wherein a token authentication mechanism and multi-authority ciphertext-policy attribute-based encryption are integrated. In this scheme, both authentication and authorization capabilities are delegated to an ES while restricting access to service content to only legal vehicles, achieving proper access control between vehicles and ESs, and effectively preserving the privacy of vehicle data. Moreover, we attributed the revocations of ESs to the associated attribute authorities, eliminating the need for a system-wide update of keying materials. Through rigorous security proofs and detailed security analyses, we demonstrate that the scheme meets the security requirements of vehicular networks and can resist more security attacks. The proposed scheme achieves better balance between computational and communication costs than related schemes. Jing Zhang 0024, Xinzhong Liu 0002, Jie Cui 0004, Hong Zhong 0001, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Mob. Comput. | 1 |
| 2023 | Identity-Based Broadcast Proxy Re-Encryption for Flexible Data Sharing in VANETsabstractData sharing is an integral part of vehicular ad hoc networks (VANETs), which provide drivers with safe and comfortable driving environments. However, when data are shared among multiple vehicles, they must be encrypted multiple times. Some solutions have used identity-based broadcast encryption to solve this problem. However, these schemes have two major limitations. First, the decryption cost is linearly related to the number of data receivers, where the identity of other receivers must be known. Second, only the data sender can forward the data. To address these important deficiencies, we propose an identity-based broadcast proxy re-encryption scheme to realize flexible and efficient data-sharing in VANETs. The data sender generates a fixed ciphertext that can be obtained by newly added vehicles through authorized vehicles. Data receivers can decrypt ciphertext directly without knowing the identities of other receivers, where the decryption overhead is constant. In addition, our scheme can achieve complete anonymous data sharing to protect vehicle privacy. A security proof shows that our scheme has sufficient security, and a performance analysis shows that our scheme performs well. Our proposed scheme is thus suitable for securing VANETs. Jing Zhang 0024, Shuangshuang Su, Hong Zhong 0001, Jie Cui 0004, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Secure Edge Computing-Assisted Video Reporting Service in 5G-Enabled Vehicular NetworksabstractSince traffic accidents occur frequently, a real-time video traffic reporting service is necessary in vehicular networks for a prompt response to accidents. Although the fifth-generation (5G) network provides a solution for real-time services in vehicular networks, the security and privacy of the services needs to be addressed first. The existing secure video reporting service schemes in 5G-enabled vehicular networks have significant computing, communication, and storage overheads, because of public key certificates, expensive bilinear pairing operations, and repeated video reporting to the cloud. To address these issues, we propose a secure edge computing-assisted video reporting service in 5G-enabled vehicular networks. In the proposed method, edge nodes complete the message verification and classification. Moreover, these nodes send the first received report message of the same accident to the designated official vehicles to realizes a local upload and download of video reports and to minimize the storage of repeated accident reports in the cloud. Security analysis indicates the proposed scheme is secure under the random oracle model and meets a series of vehicular networks requirements. In addition, performance evaluations show that the scheme achieves lower authentication overhead than existing signature schemes, and has lower total delay than other relevant video reporting service schemes. Hong Zhong 0001, Li Wang 0139, Jie Cui 0004, Jing Zhang 0024, Irina Pavlovna Bolodurina |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Blockchain-Assisted Privacy-Preserving Traffic Route Management Scheme for Fog-Based Vehicular Ad-Hoc NetworksabstractTraffic route management is essential for reducing traffic jams and enhancing driving safety because of the growing number of vehicles and frequent occurrence of traffic accidents. However, in vehicular ad-hoc networks (VANETs), real-time messages are transmitted via wireless channels, which can result in security and privacy concerns. Existing proposals for traffic route management exist security vulnerabilities, as well as high calculation and communication costs. Encouraged by this fact, we design a lightweight traffic route management scheme for fog-based VANETs. In this scheme, vehicles utilize homomorphic encryption to encrypt their driving routes and then send the encrypted information to a fog node. The traffic management center (TMC) decrypts the received ciphertexts that are aggregated by the fog node and performs traffic management according to the decrypted data, without knowing individual route of each vehicle. Furthermore, blockchain is used in the scheme to conduct public keys management of vehicles. Our detailed security proof and analysis indicate that our proposal can meet the security objectives of VANETs. Further, to demonstrate the feasibility of the scheme, we also implement it in the Ethereum test network (i.e., Rinkeby). Significantly, the performance analysis demonstrates that our proposal achieves a better performance than other relevant representative schemes. Jing Zhang 0024, Huixia Fang, Hong Zhong 0001, Jie Cui 0004, Debiao He |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | Collaborative Intrusion Detection System for SDVN: A Fairness Federated Deep Learning ApproachabstractWith the continuous innovations and development in communication technology and intelligent transportation systems, a new generation of vehicular ad hoc networks (VANETs) has become increasingly popular, making VANET communication security increasingly important. An intrusion detection system (IDS) is an important tool for detecting network attacks and is an effective means of improving network security. However, existing IDSs encounter several problems involving inaccurate detections, low detection efficiencies, and incomplete detections owing to extensive changes in vehicle locations in VANETs. This study explores federated learning in software-defined VANETs and designs an efficient and accurate collaborative intrusion detection system (CIDS) model. The model utilizes the collaboration among local software-defined networks (SDNs) to jointly train the CIDS model without directly exchanging local network data flows to improve the expansibility and globality of IDSs. To reduce the model difference between different SDN clients and improve the detection accuracy, this study regards the prediction loss for each SDN client as an objective from the perspective of constrained multi-objective optimization. By optimizing a surrogate maximum function containing all the objectives, the method adopts two-stage gradient optimization to achieve Pareto optimality for SDN clients with the worst fairness constraint maximization performance. In addition, this study evaluates the training model using two open-source datasets and compares it with the latest methods. Experimental results reveal that the proposed model ensures local data privacy and demonstrates high accuracy and efficiency in detecting attacks and is thus superior to the current schemes. Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2022 | Dataset for Evaluation of DDoS Attacks Detection in Vehicular Ad-Hoc Networks
Hong Zhong 0001, Lu Wei 0003, Jing Zhang 0024, Chengjie Gu, Jie Cui 0004 |
WASA (3) | 4 |
| 2022 | Secure and Lightweight Conditional Privacy-Preserving Authentication for Fog-Based Vehicular Ad Hoc NetworksabstractVehicular ad hoc networks (VANETs) play an ever-increasing important role in improving traffic management and enhancing driving safety. However, vehicular communication using a wireless channel faces security and privacy challenges. The conditional privacy-preserving authentication (CPPA) scheme is suitable for solving the above challenges, but the existing identity-based CPPA schemes suffer from inborn key escrow issues. Motivated by this, we propose a lightweight CPPA scheme based on elliptic curve cryptography to solve the above issues, in which the pseudonym and public/private key pair of the vehicle is generated by itself, so that the proposed scheme avoids the key escrow issue. Furthermore, to achieve efficient vehicular communication, a CPPA scheme is proposed using a fog computing model that supports mobility, low latency, and location awareness. The pseudonym of the vehicle is generated by two hash chains in the proposed scheme, so that the storage overhead can be reduced efficiently under the condition that backward security is guaranteed. Security analysis shows that the scheme is secure under the random oracle and satisfies the security requirements of VANETs. Performance evaluation demonstrates that the proposed scheme outperforms related schemes in terms of computational and communication overhead. Hong Zhong 0001, Jie Cui 0004, Jing Zhang 0024, Irina Pavlovna Bolodurina, Lu Liu 0001 |
IEEE Internet Things J. | 4 |
| 2022 | Reliable and Efficient Content Sharing for 5G-Enabled Vehicular NetworksabstractConditional privacy preservation and message authentication serve as the primary research issues in terms of security in vehicular networks. With the arrival of 5G era, the downloading speed of network services and the message transmission speed have significantly improved. Consequently, the content exchanged by users in vehicular networks is not limited to traffic information, and vehicles moving at high speeds can share a wide variety of contents. However, sharing content reliably and efficiently remains challenging owing to the fast-moving character of vehicles. To solve this problem, we propose a reliable and efficient content sharing scheme in 5G-enabled vehicular networks. The vehicles with content downloading requests quickly filter the adjacent vehicles to choose capable and suitable proxy vehicles and request them for content services. Thus, the purpose of obtaining a good hit ratio, saving network traffic, reducing time delay, and easing congestion during peak hours can be achieved. The security analysis indicates that the proposed scheme meets the security requirements of vehicular networks. Our cryptographic operations are based on the elliptic curve, and finally, the proposed scheme also displays favorable performance compared to other related schemes. Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Lu Liu 0001 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2021 | Secure and Efficient Certificateless Provable Data Possession for Cloud-Based Data Management Systems
Jing Zhang 0024, Jie Cui 0004, Hong Zhong 0001, Chengjie Gu, Lu Liu 0001 |
DASFAA (1) | 1 |
| 2021 | Toward Achieving Fine-Grained Access Control of Data in Connected and Autonomous VehiclesabstractA connected and autonomous vehicle (CAV) is often fitted with a large number of onboard sensors and applications to support autonomous driving functions. Based on the current research, little work on applications' access to in-vehicle data has been done. Furthermore, most existing autonomous driving operating systems lack authentication and encryption units. As such, applications can excessively obtain confidential information, such as vehicle location and owner preferences and even upload it to the cloud, threatening the security of the vehicle and the privacy of the owner. In this study, we propose a fine-grained access control scheme to restrict applications' access to data in CAVs (FGAC-inCAVs). First, we present a system model composed of the following elements: a trusted third party (TTP), which is a fully trusted authority; perception components like sensors, which can capture the road information (pictures, videos, etc.); and multiple applications. Then, a fast attribute-based encryption (ABE) is presented, and security analysis also shows it is secure against selective and chosen-plaintext attacks. Furthermore, we propose a key update scheme based on the Chinese remainder theorem (CRT). Finally, the theoretical analysis and simulation experiments demonstrate its feasibility and efficiency. Jie Cui 0004, Xuelian Chen, Jing Zhang 0024, Qingyang Zhang 0001, Hong Zhong 0001 |
IEEE Internet Things J. | 3 |
| 2021 | Toward Trusted and Secure Communication Among Multiple Internal Modules in CAVabstractBy equipping various sensors and analyzing sensed data, vehicles can perform automatic driving; these vehicles are known as connected and autonomous vehicles (CAVs). In CAVs, tampered data will result in incorrect driving decisions. Hence, secure data transmission should be ensured to enable correct life-critical decisions. Untrusted resource-constrained modules allow attackers to obtain private data from CAVs, such as the key. Benefitting from trusted computing, the proposed scheme can verify the trusted status of internal modules and achieve secure data transmission by adopting the remote attestation and hash message authentication code. The scheme is proven to be secure in the random oracle model under the computational Diffie–Hellman problem. Furthermore, we perform experiments and evaluate the performance using Intel Software Guard eXtensions, which provide part of the trusted computing function. The experimental results show that the scheme could be efficient and suitable for CAVs. Hong Zhong 0001, Wenwen Cao, Qingyang Zhang 0001, Jing Zhang 0024, Jie Cui 0004 |
IEEE Internet Things J. | 4 |
| 2021 | PA-CRT: Chinese Remainder Theorem Based Conditional Privacy-Preserving Authentication Scheme in Vehicular Ad-Hoc NetworksabstractExisting security and identity-based vehicular communication protocols used in Vehicular Ad-hoc Networks (VANETs) to achieve conditional privacy-preserving mostly rely on an ideal hardware device called tamper-proof device (TPD) equipped in vehicles. Achieving fast authentication during the message verification process is usually challenging in such strategies and further they suffer performance constraints from resulting overheads. To address such challenges, this paper proposes a novel Chinese remainder theorem (CRT)-based conditional privacy-preserving authentication scheme for securing vehicular authentication. The proposed protocol only requires realistic TPDs, and eliminates the need for pre-loading the master key onto the vehicle's TPDs. Chinese remainder theorem can dynamically assist the trusted authorities (TAs) whilst generating and broadcasting new group keys to the vehicles in the network. The proposed scheme solves the leakage problem during side channel attacks, and ensures higher level of security for the entire system. In addition, the proposed scheme avoids using the bilinear pairing operation and map-to-point hash operation during the authentication process, which helps achieving faster verification even under increasing number of signature. Moreover, the security analysis shows that our proposed scheme is secure under the random oracle model and the performance analysis shows that our proposed scheme is efficient in reducing computation and communication overheads. Jing Zhang 0024, Jie Cui 0004, Hong Zhong 0001, Lu Liu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | SMAKA: Secure Many-to-Many Authentication and Key Agreement Scheme for Vehicular NetworksabstractWith the rising popularity of the Internet and communication technology, vehicles can analyze and judge the real-time data collected by various cloud service providers (CSPs) in a vehicular network. However, in a vehicular network environment, real-time data are transmitted via wireless channels, which can lead to security and privacy issues. To avoid illegal access by adversaries, vehicle authentication and key agreement mechanism has been considered as one of the promising security measures in vehicular network environments. Besides, most of the solutions focus on authentication between one vehicle and one CSP. In such strategies, the implementation of efficient authentication for multiple vehicles and CSPs simultaneously is usually challenging. Further, they are also subjected to performance limitations due to the overhead incurred. To solve these issues, we propose a many-to-many authentication and key agreement scheme for secure authentication between multiple vehicles and CSPs. The proposed scheme can prevent unauthorized access and provide SK-security even if temporary information is leaked. To improve the service, the CSP only needs to broadcast an anonymous message periodically instead of having to generate a unique anonymous message for each of vehicles. Similarly, when a vehicle wants to request the services of m CSPs, it only needs to send one request message instead of m. Therefore, the proposed scheme not only implements many-to-many communication but also significantly reduces the computation and communication overhead. Moreover, a thorough security analysis shows that the proposed scheme provides better security compared to other related schemes. Jing Zhang 0024, Hong Zhong 0001, Jie Cui 0004, Yan Xu 0007, Lu Liu 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | LPE-RCM: Lightweight Privacy-Preserving Edge-Based Road Condition Monitoring for VANETs
Yan Xu 0007, Jie Cui 0004, Jing Zhang 0024, Hong Zhong 0001 |
WASA (2) | 4 |
| 2020 | An Extensible and Effective Anonymous Batch Authentication Scheme for Smart Vehicular NetworksabstractIn recent years, research on the security of Industry 4.0 and the Internet of Things (IoT) has attracted a close attention from industry, government, and the scientific community. Smart vehicular networks, as a type of industrial IoT, inevitably exchange large amounts of security and privacy-sensitive data, which make them attractive targets for attackers. For protecting network security and privacy, we have proposed an extensible and effective anonymous batch authentication scheme. In contrast to traditional pseudonym authentication schemes, the same system private key need not to be preloaded in our scheme, effectively avoiding a system failure when destroying a vehicle. Besides, the certificate revocation list (CRL) size is merely related to the number of vehicles that have been revoked, regardless of the number of pseudonym certificates for revoked vehicles. Moreover, this scheme maintains the effectiveness of the traditional scheme, effectively reduces the scale of the CRL, and employs an identity revocation scheme that supports rapid distribution. The scheme supports conditional privacy protection, namely, only the trusted authority (TA) can uniquely trace and revoke vehicles. For illegal vehicles, the TA releases the two hashed seeds to facilitate traceability by all entities in its domain. Furthermore, security analysis indicates that our solution is secure under the random oracle model and fulfills a series of security requirements of vehicular networks. Compared to existing authentication schemes, performance evaluations show that the scheme offers relatively good performance in terms of time consumption. Jing Zhang 0024, Hong Zhong 0001, Jie Cui 0004, Yan Xu 0007, Lu Liu 0001 |
IEEE Internet Things J. | 1 |
| 2020 | Edge Computing in VANETs-An Efficient and Privacy-Preserving Cooperative Downloading SchemeabstractWith the advancements in social media and rising demand for real traffic information, the data shared in vehicular ad hoc networks (VANETs) indicate that the size and amount of requested data will continue increasing. Vehicles in the same area often have similar data downloading requests. If we ignore the common requests, the resource allocation efficiency of the VANET system will be quite low. Motivated by this fact, we propose an efficient and privacy-preserving data downloading scheme for VANETs, based on the edge computing concept. In the proposed scheme, a roadside unit (RSU) can find the popular data by analyzing the encrypted requests sent from nearby vehicles without having to sacrifice the privacy of their download requests. Further, the RSU caches the popular data in nearby qualified vehicles called edge computing vehicles (ECVs). If a vehicle wishes to download the popular data, it can download it directly from the nearby ECVs. This method increases the downloading efficiency of the system. The security analysis results show that the proposed scheme can resist multiple security attacks. The performance analysis results demonstrate that our scheme has reasonable computation and communication overhead. Finally, the OMNeT++ simulation results indicate that our scheme has good network performance. Jie Cui 0004, Lu Wei 0003, Hong Zhong 0001, Jing Zhang 0024, Yan Xu 0007, Lu Liu 0001 |
IEEE J. Sel. Areas Commun. | 4 |
| 2020 | Extensible Conditional Privacy Protection Authentication Scheme for Secure Vehicular Networks in a Multi-Cloud EnvironmentabstractWith an increasing number of cloud service providers (CSPs), research works on multi-cloud environments to provide solutions to avoid vendor lock-in and deal with the single-point failure problem have expanded considerably. However, a few schemes focus on the conditional privacy protection authentication of vehicular networks under a multi-cloud environment. In this regard, we propose a robust and extensible authentication scheme for vehicular networks to fulfil the ever-growing diversified service demands from users. According to our solution, the vehicles need to register with the trusted authority (TA) only once to achieve a fast and efficient authentication with CSPs. Additionally, as long as the new CSP is successfully registered in TA, it can participate in vehicular service. A cloud broker, which is managed by the TA, is responsible for connecting all the cloud services; consequently, the complexity involved in the selection of CSPs is hidden from the users' view. A detailed security analysis establishes that our scheme can fulfil conditional privacy protection and achieve the security objectives of vehicular networks. Our scheme is based on elliptic curve cryptography and does not employ the complex bilinear pairing operation. An evaluation of performance of the proposed scheme indicates that it is suitable for applications involving vehicular networks. Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Lu Liu 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2019 | Privacy-preserving authentication scheme with full aggregation in VANET
Hong Zhong 0001, Shunshun Han, Jie Cui 0004, Jing Zhang 0024, Yan Xu 0007 |
Inf. Sci. | 4 |
| 2019 | An Efficient Message-Authentication Scheme Based on Edge Computing for Vehicular Ad Hoc NetworksabstractWith the progress in wireless communication technology and the increasing number of vehicles, vehicular ad hoc networks (VANETs) have become essential for improving road conditions and enhancing driving experience. The core of the VANETs is the communication between different vehicles, and the security of the communication is based on message authentication. Several schemes have been designed to enhance the efficiency of message authentication. However, these schemes have the disadvantage of redundant authentication, i.e., repeated authentication of the same message, and fail to seek invalid messages from the batch of messages. To solve these problems, this paper introduces a novel edge-computing concept into the message-authentication process of VANETs. In our scheme, the roadside unit can efficiently authenticate messages from nearby vehicles and broadcast the authentication results to the vehicles within its communication range, thereby reducing redundant authentication and enhancing the efficiency of the entire system. The security analysis results show that the proposed scheme satisfies the security requirements of the VANETs. The performance analysis results show that the proposed scheme can not only work well in an ideal environment where the attacker is absent but also capable of quickly identifying valid and invalid messages even if the VANET is attacked. Jie Cui 0004, Lu Wei 0003, Jing Zhang 0024, Yan Xu 0007, Hong Zhong 0001 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2018 | An efficient certificateless aggregate signature without pairings for vehicular ad hoc networks
Jie Cui 0004, Jing Zhang 0024, Hong Zhong 0001, Yan Xu 0007 |
Inf. Sci. | 2 |
| 2017 | Area-based mobile multicast group key management scheme for secure mobile cooperative sensing
Jie Cui 0004, Hong Zhong 0001, Weiya Luo, Jing Zhang 0024 |
Sci. China Inf. Sci. | 4 |