VLDB 2026 Research / reviewers in the wild / expert
Ching-Fang Hsu 0001
dblp:06/478-1 · also Chingfang Hsu 0001
· DBLP profile ↗
40ranked-venue papers
10as first author
24since 2021 · last 2026
0000-0003-3847-7659ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 11 · 4 first-author · 6 since 2021Security and privacy · 11 · 1 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 2 first-author · 6 since 2021Databases, data management, data science and information retrieval · 6 · 2 first-author · 2 since 2021Systems, architecture and hardware · 4 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A practical blockchain-based vaccine supply management framework with verifiability and traceabilityabstractAbstract With increasing global demand for vaccines and the changing level of biotechnology, vaccines become an important force to promote the development of the global pharmaceutical market. Vaccine forms an important basis for human self-protection. At present, existing vaccine supply management is mostly established in a centralized manner with a central authority (CA) for assuring trust. This approach requires that a trusted CA be set up, and it incurs overhead costs in communications and storage in networks. At the same time, issues such as the authenticity, integrity, and privacy are still widespread in vaccine supply management. Therefore, it is crucial to study a vaccine supply management traceability scheme that can be supervised in a decentralized manner and whose data cannot be tampered with or forged. In view of the security and efficiency problems in the existing vaccine supply management traceability scheme, a practical blockchain-based vaccine supply management framework with verifiability and traceability is proposed in this paper. This architecture can solve the lack of centralization in the existing vaccine supply management and the problems of data falsification, tampering, and low work efficiency in the current vaccine supply supervision process. At the same time, aiming at the lack of efficiency and security of the existing signature schemes suitable for consortium chains, an improved SM2 digital signature algorithm based on key distribution authentication and modulo-free inverse operation is designed, which improves the signature efficiency and reliability in the signature verification process. Then, we design a new way to store vaccine production records, which can avoid the forgery and modification of production records by treating the production record of each production step as a separate piece of data. Based on the decentralized and traceable feature of the framework, it can well resolve the trust issue between consumers and the vaccine regulators. Consumers can be allowed to verify the authenticity of vaccine supply management process. In addition, the security analysis shows that the proposed framework meets all desired security requirements. Compared with similar solutions, the proposed scheme takes less computation and communication costs. Hence, our construction is more appropriate for practical vaccine supply management. Lulu Ke, Ching-Fang Hsu 0001, Man Ho Au, Zhe Xia |
Comput. J. | 2 |
| 2025 | A new robust PKC encryption method based on invertible matrix multiplication for HIE in medical IoT systemsabstractAbstract Electronic health information exchange (HIE) allows doctors, nurses, pharmacists, other health care providers and patients to appropriately access and securely share a patient’s vital medical information electronically—improving the speed, quality, safety and cost of patient care. At present, public key cryptography (PKC) is the most secure and practical cryptographic techniques to achieve this function in healthcare information exchange for medical IoT systems. ElGamal cryptosystem is one of the most well-known public key cryptosystems (they are also called asymmetric key cryptosystems), which is based on the discrete logarithm problem. At present, with the development of quantum computer technology, the ElGamal cryptosystem may be attacked by quantum algorithms. At the same time, since ElGamal requires several secure random integers to resist cryptographic analysis and ensure communication security and securing data sharing. Especially, when the encrypted information is large, multiple random numbers need to be used for grouping encryption, which makes the efficiency of ElGamal need to be improved. It is necessary to construct an alternative cryptographic algorithm that is more secure and efficient than ElGamal. In this paper, we construct a new public key cryptosystem (PKC) based on the discrete logarithm problem in $$GL\left(n,p\right)$$ G L n , p , which is constructed by the invertible matrix multiplication and can become an alternative version of the ElGamal public key cryptosystem. We call it Matrix ElGamal cryptosystem (M-EPKC). It is proved that the proposed PKC is computationally secure, which can provide the same security as the ElGamal cryptosystem in a much smaller finite field and use fewer random integers when encrypting large amounts of messages. For matrices of size $$n$$ n , ElGamal PKC requires $$n$$ n times more random numbers to encrypt plaintext with the same amount of data. The proposed M-EPKC is not only proved to be resistant to Shor’s algorithm attack (Shor in SIAM Rev 41: 303–332, 1999) on the integer field, but it can also improve its own computational efficiency by accelerating the decryption algorithm. Therefore, compare with the ElGamal cryptosystem, our proposed M-EPKC can provide a more secure and efficient method in healthcare information exchange for medical IoT systems. Ching-Fang Hsu 0001, Lein Harn, Zhuo Zhao |
Cybersecur. | 2 |
| 2025 | Provably Secure and Efficient One-to-Many Authentication and Key Agreement Protocol for Resource-Asymmetric Smart EnvironmentsabstractThe smart environment is a crucial application of the Internet of Things(IoT). Due to its growing security and efficiency needs, recent years have seen the proposal of numerous authentication and key agreement (AKA) protocols. Unfortunately, most of existing AKA protocols only support one-to-one AKA and rely on the elliptic curve cryptosystem, resulting in huge overhead. In addition, these protocols fail to consider the resource-asymmetric characteristics of this scenario. That is, the resources on the gateway side are abundant, while the resources on user sides and device sides are limited. In order to achieve efficient and secure one-to-many AKA establishment in this scenario, where one-to-many means that users can realize key agreements with multiple smart devices at the same time. For the first time, this paper uses the one-to-many computing structure of the Chinese Remainder Theorem (CRT) to design an efficient one-to-many AKA establishment, which is perfectly adapted to resource-asymmetric allocation in smart environments. Compared with existing solutions, this solution has the following advantages. Firstly, our protocol is suitable for resource-asymmetric environments, where the gateway acts as an intermediate node and uses rich resources to integrate multiple AKA requests. Secondly, the solution supports users to negotiate session keys with multiple smart devices at the same time. Thirdly, we prove the protocol’s security under the Real-or-Random (ROR) model. In addition, we perform formal security verification of the protocol using the Automated Validation of Internet Security Protocols and Applications(AVISPA) tool. Finally, the security and efficiency of this solution are superior to similar solutions. Specifically, our solution can meet 18 security and functionality requirements. Compared with the latest similar scheme, assuming that the number of smart devices is 10, our scheme reduces the computational cost by 75.75%. At the same time, in terms of communication cost, our protocol reduces it by 37.78%. Ching-Fang Hsu 0001, Jianqun Cui, Man Ho Au, Lein Harn, Quanrun Li |
IEEE Internet Things J. | 2 |
| 2025 | Efficient and provably secure privacy-preserving two-factor authentication and key-agreement using blockchain and TEE for IoV environments
Qihang Hou, Ching-Fang Hsu 0001, Man Ho Au, Honglang Hu, Zhuo Zhao |
J. Syst. Archit. | 2 |
| 2025 | Lightweight and Provably Secure Privacy-Preserving Implicit Authentication Protocol Using Weighted-MinHash for IoV Environment
Honglang Hu, Ching-Fang Hsu 0001, Man Ho Au, Jianqun Cui, Lein Harn, Zhuo Zhao |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2025 | Provably secure and lightweight authentication protocol using PUF and blockchain for smart grids
Honglang Hu, Ching-Fang Hsu 0001, Jianqun Cui, Lein Harn, Qihang Hou |
J. Supercomput. | 2 |
| 2024 | Extremely Lightweight Constant-Round Membership-Authenticated Group Key Establishment for Resource-Constrained Smart Environments toward 5GabstractAbstract With rapid development of next-generation mobile networks and communications (5G networks), group-oriented applications in resource-constrained smart environments (RSEs), such as smart homes and smart classrooms, have attracted great attentions. Due to the insecure communications between resource-constrained devices, secure group communications in RSE toward 5G face many challenges. In RSE toward 5G, lightweight communications and low computational overheads are crucial. Besides, the private tokens used to generate the group key are expected to be reused multiple times. However, the conventional frameworks for secure group communications cannot meet these requirements. A practical construction of extremely lightweight constant-round membership authenticated group key establishment framework is proposed in this paper for RSE toward 5G, which not only implements identity authentication among the members and group key establishment but also ensures extremely lightweight computation and communication costs by each group member. In our proposed scheme, the increase in the number of group members will not lead to a linear or logarithmic increase in the communication and calculation costs at the member side. Our framework also resists external and internal attacks and meets all the desirable security features. In this framework, the privacy of tokens can be well protected, so that they can be reused for multiple times. Therefore, our scheme significantly reduces the costs of communication and calculation, and it is more efficient compared with the related schemes in the literature. This proposal is fairly suitable for lightweight membership authentication and group key establishment in RSE toward 5G. Ching-Fang Hsu 0001, Zhe Xia, Tianshu Cheng, Lein Harn |
Comput. J. | 1 |
| 2024 | PRLAP-IoD: A PUF-based Robust and Lightweight Authentication Protocol for Internet of Drones
Ching-Fang Hsu 0001, Man Ho Au, Lein Harn, Jianqun Cui, Zhe Xia, Zhuo Zhao |
Comput. Networks | 2 |
| 2024 | Lightweight ring-neighbor-based user authentication and group-key agreement for internet of dronesabstractAbstract As mobile internet and Internet of Things technologies continue to advance, the application scenarios of peer-to-peer Internet of Drones (IoD) are becoming increasingly diverse. However, the development of IoD also faces significant challenges, such as security, privacy protection, and limited computing power, which require technological innovation to overcome. For group secure communication, it is necessary to provide two basic services, user authentication and group key agreement. Due to the limited storage of IoD devices, group key negotiation requires lightweight calculations, and conventional schemes cannot satisfy the requirements of group communication in the IoD. To this end, a new lightweight communication scheme based on ring neighbors is presented in this paper for IoD, which not only realizes the identity verification of user and group key negotiation, but also improves computational efficiency on each group member side. A detailed security analysis substantiates that the designed scheme is capable of withstanding attacks from both internal and external adversaries while satisfying all defined security requirements. More importantly, in our proposal, the computational cost on the user side remains unaffected by the variability of the number of members participating in group communication, as members communicate in a non-interactive manner through broadcasting. As a result, the protocol proposed in this article demonstrates lower computational and communication costs in comparison to other cryptographic schemes. Hence, this proposal presents a more appealing approach to lightweight group key agreement protocol with user authentication for application in the IoD. Zhuo Zhao, Ching-Fang Hsu 0001, Lein Harn, Zhe Xia |
Cybersecur. | 2 |
| 2024 | A revocable and comparable attribute-based signature scheme from lattices for IoMT
Ching-Fang Hsu 0001, Man Ho Au, Lein Harn, Jianqun Cui, Zhuo Zhao |
J. Syst. Archit. | 2 |
| 2024 | Efficient and Privacy-Preserving Skyline Queries Over Encrypted Data Under a Blockchain-Based Audit ArchitectureabstractSkyline queries is an advanced data mining algorithm suitable for multi-criteria decision-making scenarios (i.e., medical pre-diagnosis). Privacy-preserving skyline queries schemes are usually constructed by certain methods of cryptography such as additive homomorphic cryptosystem, secret sharing technology, etc. Interestingly, these secure skyline queries schemes require that skyline computations do not reveal any message details, including encrypted inter-tuple domination relations, among which privacy schemes based on homomorphic cryptosystems are the most popular due to their strong security. However, existing secure skyline queries schemes not only suffer from low computational efficiency, but also do not have sufficient security for privacy-key management in the system. To address the above issues, this paper designs an efficient and privacy-preserving skyline queries over encrypted data under a blockchain-based audit architecture. Firstly, we propose a blockchain-based audit architecture that not only provides error auditing functionality but also makes our scheme suitable for (distributed) multi-user scenarios while providing secure key management in the system. Secondly, we implement a series of secure sub-protocols using the CRT-Based Paillier encryption algorithm and construct a privacy sparse matrix elimination protocol to reduce the size of the dataset, leading to a significant reduction in computational cost without compromising privacy. Finally, we put forward our secure skyline queries protocol and prove its security. The performance evaluation shows that our proposed method our proposed method is significantly more efficient (at least 7.4 times faster) compared to current methods. Shuchang Zeng, Ching-Fang Hsu 0001, Lein Harn, Yi-Ning Liu 0002, Yang Liu 0368 |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2023 | Efficient and Secure Authentication Key Establishment Protocol Using Chaotic Map and PUF in Smart EnvironmentsabstractWith the rapid growth and popularization of the Internet of Things (IoT), it has been applied to numerous fields such as smart industry, smart agriculture and smart home. Designing practical and robust authentication key agreement (AKA) schemes for smart environments has become a pressing problem to be solved. Due to differences in security requirements and resource allocation in smart environments, which we call security-asymmetry and resource-asymmetry, it is necessary to design specific AKA schemes for this environment. Since the design of remote AKA protocols does not fully consider security-asymmetry and resource-asymmetry, many existing schemes are not practical in smart environments. With regard to security-asymmetry, compared with traditional public-key techniques applied in AKA schemes, chaotic map is more effective than modular exponentiation and scalar multiplication, and it supplies many feasible attributes such as unpredictability, unrepeatability, uncertainty, which can be used to achieve communication security between users and gateways, while security operations based on hash function are sufficient to secure communications between gateways and smart devices. In view of resource-asymmetry, the complex operations in the authentication process can be completed by the gateway, so as to make full use of the rich resources on gateway side and reduce the use of resources on user side and device side. Based on such considerations, an efficient and secure authentication key agreement scheme based on chaotic map and physical unclonable function (PUF) for smart environments is proposed. We present a rigorous informal analysis of the proposed scheme. Moreover, the formal security verification is accomplished using the Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. Finally, performance evaluations indicate the proposed protocol consumes less communication cost and computation cost while achieving more security functions compared to other four state-of-the-art related schemes. Fengling Pang, Ching-Fang Hsu 0001, Man Ho Au, Lein Harn, Li Long |
TrustCom | 2 |
| 2023 | Multiple Blind Signature for e-Voting and e-CashabstractAbstract In this paper, we propose a new cryptographic primitive, called multiple blind signature (MBS), which is designed based on the integration of both normal blind signature scheme and dual signature. The major difference between a normal blind signature and an MBS is that using a normal blind signature, only one message, $m$, can be verified, but using an MBS, any subset, ${M}^{\prime }$, of multiple messages in a set, $M$, where ${M}^{\prime}{\subseteq} M$, can be verified. With this additional property, we will show that MBS is especially suitable for e-voting and e-cash applications. In other words, we classify these processes in two applications into two phases, on-line and off-line phases. One unique property of this design is that most time-consuming computation and interaction can be performed in advance in off-line phase. There is no cost of computation and interaction in the online phase. Lein Harn, Ching-Fang Hsu 0001, Zhe Xia |
Comput. J. | 2 |
| 2023 | Construction of Lightweight Authenticated Joint Arithmetic Computation for 5G IoT NetworksabstractAbstract The next generation of Internet of Things (IoT) networks and mobile communications (5G IoT networks) has the particularity of being heterogeneous, therefore, it has very strong ability to compute, store, etc. Group-oriented applications demonstrate its potential ability in 5G IoT networks. One of the main challenges for secure group-oriented applications (SGA) in 5G IoT networks is how to secure communication and computation among these heterogeneous devices. Conventional protocols are not suitable for SGA in 5G IoT networks since multiparty joint computation in this environment requires lightweight communication and computation overhead. Furthermore, the primary task of SGA is to securely transmit various types of jointly computing data. Hence, membership authentication and secure multiparty joint arithmetic computation become two fundamental security services in SGA for 5G IoT networks. The membership authentication allows communication entities to authenticate their communication partners and the multiparty joint computations allow a secret output to be shared among all communication entities. The multiparty joint computation result can be used to protect exchange information in the communication or be used as a result that all users jointly compute by using their secret inputs. A novel construction of computation/communications-efficient membership authenticated joint arithmetic computation is proposed in this paper for 5G IoT networks, which not only integrates the function of membership authentication and joint arithmetic computation but also realizes both computation and communication efficiency on each group member side. Our protocol is secure against inside attackers and outside attackers, and also meets all the described security goals. Meanwhile, in this construction the privacy of tokens can be well protected so tokens can be reused multiple times. This proposal is noninteractive and can be easily extended to joint arithmetic computation with any number of inputs. Hence, our design has more attraction for lightweight membership authenticated joint arithmetic computation in 5G IoT networks. Ching-Fang Hsu 0001, Lein Harn, Zhe Xia, Jianqun Cui, Jingxue Chen |
Comput. J. | 1 |
| 2023 | Ideal dynamic threshold Multi-secret data sharing in smart environments for sustainable cities
Ching-Fang Hsu 0001, Zhe Xia, Lein Harn, Man Ho Au, Jianqun Cui, Zhuo Zhao |
Inf. Sci. | 1 |
| 2023 | Simple and efficient threshold changeable secret sharing
Lein Harn, Ching-Fang Hsu 0001, Zhe Xia, Shuchang Zeng, Fengling Pang |
J. Inf. Secur. Appl. | 2 |
| 2023 | A Practical Lightweight Anonymous Authentication and Key Establishment Scheme for Resource-Asymmetric Smart EnvironmentsabstractWith the rapid developments of Internet of Things (IoT) technologies, the security of sensitive data has attracted more and more attention for many resource-asymmetric smart environments, such as smart home, smart agriculture and so on. The resource-asymmetry environment refers to the uneven distribution of resources on different devices side, which is specifically manifested as gateway side is resource-rich, user side and device side are resource-restricted. Hence, a secure and practical authentication key establishment scheme for such smart environments is urgently needed. Recently many researchers have designed authentication and key establishment schemes for security purpose, however most of them cannot consider the excess of gateway resources and guarantee the anonymity of user, and further, they are not suitable for resource-asymmetric smart environments because they are not lightweight enough in user side and smart device side. Due to the fact that Rabin cryptosystem has the large difference in time-consuming between encryption and decryption, it is extremely suitable for constructing authentication and key establishment scheme for resource-asymmetric smart environments. So, a new practical authentication and key establishment scheme based on the Rabin cryptosystem for resource-asymmetric smart environments is proposed, which can make better use of the advantages of abundant gateway resources and realize the lightweight operations on device side and user side, and at the same time can provide user anonymity. With Proverif and BAN logic, we can prove that our solution not only provides anonymity, but also satisfies all defined security features. Simultaneously, compared with latest similar protocols in computation cost and communication overhead, the results show that our scheme is more effective. Hence, our design has more attraction for authentication and key establishment scheme in resource-asymmetric smart environments. Linyan Bai, Ching-Fang Hsu 0001, Lein Harn, Jianqun Cui, Zhuo Zhao |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Three-Factor Anonymous Authentication and Key Agreement Based on Fuzzy Biological Extraction for Industrial Internet of ThingsabstractWith the increasing popularity and wide application of the Internet, the users (such as managers and data consumers) in the Industrial Internet of Things (IIoT) can remotely analyze and control real-time data collected by various smart sensor devices. However, there are many security and privacy issues in the process of transmitting collected data through public channels in IIoT environment. In order to against the illegal access by opponents, a novel anonymous user authentication and key agreement scheme based on hash and elliptic curve encryption is proposed in this article, which not only uses a pseudonym tuple database in control nodes to realize the functions of user dynamic joining and anonymity protection, but also resists key loss and device capture attacks through fuzzy biometric extraction technology. In addition, the formal secure analysis of the proposed scheme is carried out using the BAN logic model and ROR model, which proves the security of the proposed scheme. Meanwhile, we also prove the scheme can against the described existing attacks and meet the design goals by a detailed informal security discussion. Compared with the latest similar IIoT authentication proposals, our solution has a very obvious advantage in communication efficiency and realizes more functions. Hence, our scheme is more suitable for the IIoT environment, and can also generate greater benefits. Ching-Fang Hsu 0001, Lein Harn, Jianqun Cui, Zhuo Zhao |
IEEE Trans. Serv. Comput. | 2 |
| 2022 | A novel threshold changeable secret sharing scheme
Lein Harn, Ching-Fang Hsu 0001, Zhe Xia |
Frontiers Comput. Sci. | 2 |
| 2021 | Non-interactive integrated membership authentication and group arithmetic computation output for 5G sensor networksabstractAbstract Group‐oriented applications show its potential ability in the next generation of wireless sensor networks (5G WSNs), which have the particularity of being heterogeneous and so have different capabilities in terms of storage, computing, communicating and energy. One of the main challenges for secure group‐oriented applications (SGA) in 5G WSNs is how to secure communication between these heterogeneous devices. Conventional protocols are not suitable for SGA in 5G sensor networks since multiparty output establishment in this environment requires lightweight communication and computation overhead, further the primary task of SGA in 5G WSNs is to securely transmit various types of jointly computing data. Hence, membership authentication and multiparty output for arithmetic computations become two fundamental and necessary security services in SGA for 5G WSNs. In this paper we propose a novel design of non‐interactive integrated membership authenticated multiparty output for arithmetic computations in 5G sensor networks, which embeds the function of membership authentication and multiparty output for arithmetic computations. Since any arithmetic computation function is composed of multiple additions and multiplications, our result serves as a general method for multiparty computation output in SGA. This design is more suitable for lightweight membership authenticated multiparty arithmetic computations output in 5G sensor networks. Ching-Fang Hsu 0001, Lein Harn, Zhe Xia, Maoyuan Zhang, Zhuo Zhao |
IET Commun. | 1 |
| 2021 | Design of ideal secret sharing based on new results on representable quadripartite matroids
Ching-Fang Hsu 0001, Lein Harn, Zhe Xia, Maoyuan Zhang, Quanrun Li |
J. Inf. Secur. Appl. | 1 |
| 2021 | Non-interactive secure multi-party arithmetic computations with confidentiality for P2P networks
Lein Harn, Zhe Xia, Ching-Fang Hsu 0001 |
Peer-to-Peer Netw. Appl. | 3 |
| 2021 | Lightweight Privacy-Preserving Data Sharing Scheme for Internet of Medical ThingsabstractInternet of Medical Things (IoMT) is a kind of Internet of Things (IoT) that includes patients and medical sensors. Patients can share real‐time medical data collected in IoMT with medical professionals. This enables medical professionals to provide patients with efficient medical services. Due to the high efficiency of cloud computing, patients prefer to share gathering medical information using cloud servers. However, sharing medical data on the cloud server will cause security issues, because these data involve the privacy of patients. Although recently many researchers have designed data sharing schemes in medical domain for security purpose, most of them cannot guarantee the anonymity of patients and provide access control for shared health data, and further, they are not lightweight enough for IoMT. Due to these security and efficiency issues, a novel lightweight privacy‐preserving data sharing scheme is constructed in this paper for IoMT. This scheme can achieve the anonymity of patients and access control of shared medical data. At the same time, it satisfies all described security features. In addition, this scheme can achieve lightweight computations by using elliptic curve cryptography (ECC), XOR operations, and hash function. Furthermore, performance evaluation demonstrates that the proposed scheme takes less computation cost through comparison with similar solutions. Therefore, it is fairly an attractive solution for efficient and secure data sharing in IoMT. Zhuo Zhao, Ching-Fang Hsu 0001, Lein Harn, Lulu Ke |
Wirel. Commun. Mob. Comput. | 2 |
| 2021 | Lightweight and flexible key distribution schemes for secure group communications
Lein Harn, Ching-Fang Hsu 0001, Zhe Xia |
Wirel. Networks | 2 |
| 2020 | Lightweight group key distribution schemes based on pre-shared pairwise keysabstractIn a secure communication, a one‐time session key is needed to be shared among all participants. Most well‐known key distribution schemes, such as Diffie–Hellman public‐key key distribution scheme invented in 1976 and quantum key distribution scheme invented in 1984 (also called the BB84 scheme), can only allow two users to share a key in conventional one‐to‐one communications. There are many research papers in the literature to propose group key distribution schemes for multiple participants in modern group communications. In this study, the authors propose lightweight group key distributions using pre‐shared pairwise keys. The authors first propose a three‐party group key distribution scheme. They then extend the basic three‐party scheme to establish a group key for a large size of group communications. The proposed generalised schemes can be based to any type of pairwise key distribution schemes, e.g. either quantum or non‐quantum. Moreover, both generalised multi‐party group key distribution schemes are lightweight. The main operations in the proposed schemes are key comparison between two or more than two keys (i.e. logic XOR operation) and the computation of key derivation functions. Lein Harn, Ching-Fang Hsu 0001, Zhe Xia |
IET Commun. | 2 |
| 2020 | Secret sharing with secure secret reconstruction
Lein Harn, Zhe Xia, Ching-Fang Hsu 0001, Yi-Ning Liu 0002 |
Inf. Sci. | 3 |
| 2020 | Cryptanalysis and Improvement of a Group Authentication Scheme with Multiple Trials and Multiple AuthenticationsabstractAuthentication is one of the most fundamental services in cryptography and information security. Compared with the traditional authentication methods, group authentication allows a group of users to be authenticated at once rather than authenticating each of these users individually. Therefore, it is more desirable in the group oriented environment, such as multicast/conference communications. In this paper, we first demonstrate that a recent group authentication scheme by Chien (Security and Communication Networks, 2017) suffers some security flaws, i.e. an adversary in the asynchronous communication model can pretend to be a legitimate group member without being detected. We then use the Anonymous Veto Networks (AV-net) to patch Chien’s scheme, so that its security can be rigorously proved in a well-defined security model. Zhe Xia, Yining Liu 0001, Ching-Fang Hsu 0001, Chin-Chen Chang 0001 |
Secur. Commun. Networks | 3 |
| 2020 | UMKESS: user-oriented multi-group key establishments using secret sharing
Ching-Fang Hsu 0001, Lein Harn, Bing Zeng 0005 |
Wirel. Networks | 1 |
| 2019 | A Provably Secure and Lightweight Identity-Based Two-Party Authenticated Key Agreement Protocol for Vehicular Ad Hoc NetworksabstractAs an important part of smart cities, vehicle ad hoc networks (VANETs) have attracted much attention from both industry and academia. In a VANET, generating a secure session key to facilitate subsequent data-in-transit transfer between two or more vehicles is crucial, which can be achieved by using an authenticated key agreement protocol. However, most of the existing identity-based two-party authenticated key agreement protocols have significant computational requirements or are known to be insecure. Thus, in this paper, a secure and efficient identity-based two-party authenticated key agreement protocol is presented by us. This protocol does not involve complex bilinear pairing computations and can generate a valid session key in two rounds. The security of the proposed protocol is proved in the eCK model which has better capability to describe a protocol’s security than the famous CK model, and it has been widely used in the security proof of ID-based key agreement protocols currently. Additionally, we also evaluate its performance for potential utility in a VANET. Quanrun Li, Ching-Fang Hsu 0001, Kim-Kwang Raymond Choo, Debiao He |
Secur. Commun. Networks | 2 |
| 2018 | Centralized Group Key Establishment Protocol without a Mutually Trusted Third Party
Lein Harn, Ching-Fang Hsu 0001 |
Mob. Networks Appl. | 2 |
| 2017 | A Practical Hybrid Group Key Establishment for Secure Group CommunicationsabstractA group key establishment enables a group key shared among all group members. In this paper, we proposed a novel group key establishment, which is a hybrid of the Diffie–Hellman (DH) public-key scheme and the secret sharing scheme. Our protocol takes the advantages of the DH scheme, which does not need a mutually trusted key generation center (KGC) and the secret sharing scheme, which reduces the computational time. Employing the DH scheme allows any group member to act as a KGC to distribute a secret key to all group members. The secret sharing scheme is used as the encryption tool to transfer a group key to group members. Since public-key encryption involves modular exponentiations using a larger modulus (say at least 1024 bits) as compared with the secret sharing encryption involves polynomial operations using a smaller modulus (say only 160 bits), our proposed approach is faster than the broadcast encryption in public-key setting. We show that our protocol can provide key secrecy, key authentication and key independence. Lein Harn, Ching-Fang Hsu 0001 |
Comput. J. | 2 |
| 2017 | A Novel Design of Membership Authentication and Group Key Establishment ProtocolabstractA new type of authentication, called group authentication, has been proposed recently which can authenticate all users belonging to the same group at once in a group communication. However, the group authentication can only detect the existence of nonmembers but cannot identify who are the nonmembers. Furthermore, in a group communication, it needs not only to authenticate memberships but also to establish a group key among all members. In this paper, we propose a novel design to provide both membership authentication and group key establishment. Our proposed membership authentication can not only detect nonmembers but also identify who are the nonmembers. We first propose a basic membership authentication and key establishment protocol which can only support one-time group communication. Then, we extend the basic protocol to support multiple group communications. Our design is unique since tokens of users issued by a group manager (GM) during registration are used for both membership authentication and group key establishment. Lein Harn, Ching-Fang Hsu 0001 |
Secur. Commun. Networks | 2 |
| 2017 | How to Share Secret Efficiently over NetworksabstractIn a secret-sharing scheme, the secret is shared among a set of shareholders, and it can be reconstructed if a quorum of these shareholders work together by releasing their secret shares. However, in many applications, it is undesirable for nonshareholders to learn the secret. In these cases, pairwise secure channels are needed among shareholders to exchange the shares. In other words, a shared key needs to be established between every pair of shareholders. But employing an additional key establishment protocol may make the secret-sharing schemes significantly more complicated. To solve this problem, we introduce a new type of secret-sharing, calledprotected secret-sharing(PSS), in which the shares possessed by shareholders not only can be used to reconstruct the original secret but also can be used to establish the shared keys between every pair of shareholders. Therefore, in the secret reconstruction phase, the recovered secret is only available to shareholders but not to nonshareholders. In this paper, an information theoretically secure PSS scheme is proposed, its security properties are analyzed, and its computational complexity is evaluated. Moreover, our proposed PSS scheme also can be applied to threshold cryptosystems to prevent nonshareholders from learning the output of the protocols. Lein Harn, Ching-Fang Hsu 0001, Zhe Xia, Junwei Zhou 0002 |
Secur. Commun. Networks | 2 |
| 2017 | Computation-efficient key establishment in wireless group communications
Ching-Fang Hsu 0001, Lein Harn, Yi Mu 0001, Maoyuan Zhang |
Wirel. Networks | 1 |
| 2016 | Realizing secret sharing with general access structure
Lein Harn, Ching-Fang Hsu 0001, Mingwu Zhang, Tingting He 0003, Maoyuan Zhang |
Inf. Sci. | 2 |
| 2015 | Dynamic threshold secret reconstruction and its application to the threshold cryptography
Lein Harn, Ching-Fang Hsu 0001 |
Inf. Process. Lett. | 2 |
| 2014 | Analysis of VMSS Schemes for Group Key Transfer Protocol
Ching-Fang Hsu 0001 |
NPC | 1 |
| 2011 | An ideal multi-secret sharing scheme based on MSP
Ching-Fang Hsu 0001, Qi Cheng 0008, Xueming Tang, Bing Zeng 0005 |
Inf. Sci. | 1 |
| 2011 | A novel linear multi-secret sharing scheme for group communication in wireless mesh networks
Ching-Fang Hsu 0001, Guohua Cui, Qi Cheng 0008 |
J. Netw. Comput. Appl. | 1 |
| 2009 | On Non-representable Secret Sharing Matroids
Qi Cheng 0008, Ching-Fang Hsu 0001 |
ISPEC | 4 |