VLDB 2026 Research / reviewers in the wild / expert
Tsz Hon Yuen
dblp:10/6625
· DBLP profile ↗
88ranked-venue papers
24as first author
39since 2021 · last 2026
0000-0002-0629-6792ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 73 · 20 first-author · 35 since 2021Systems, architecture and hardware · 5 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 1 since 2021Theory of computation · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 2 since 2021Artificial intelligence and machine learning · 1Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | OblivSage: Oblivious Graph Sampling for Privacy-Preserving GNN
Zhibo Xu, Shangqi Lai, Xiaoning Liu 0002, Alsharif Abuadbba, Tsz Hon Yuen, Joseph K. Liu, Xingliang Yuan |
ACISP (2) | 6 |
| 2026 | SoK: Stablecoins in Retail PaymentsabstractStablecoins have emerged as a rapidly growing digital payment instrument, raising the question of whether blockchain-based settlement can function as a substitute for incumbent card networks in retail payments. This Systematization of Knowledge (SoK) provides a systematic comparison between stablecoin payment arrangements and card networks by situating both within a unified analytical framework. We first map their respective payment infrastructures, participant roles, and transaction lifecycles, highlighting fundamental differences in how authorization, settlement, and recourse are organized. Building on this mapping, we introduce the CLEAR framework, which evaluates retail payment systems across five dimensions: cost, legality, experience, architecture, and reach. Our analysis shows that stablecoins deliver efficient, continuous, and programmable settlement, often compressing rail-level merchant fees and enabling 24/7 value transfer. However, these advantages are accompanied by an inversion of the traditional pricing and risk-allocation structure. Card networks internalize consumer-side frictions through subsidies, standardized liability rules, and post-transaction recourse, thereby supporting mass-market adoption. Stablecoin arrangements, by contrast, externalize transaction fees, error prevention, and dispute resolution to users, intermediaries, and courts, resulting in weaker consumer protection, higher cognitive burden at the point of interaction, and fragmented acceptance. Accordingly, stablecoins exhibit a conditional comparative advantage in closed-loop environments, cross-border corridors, and high-friction payment contexts, but remain structurally disadvantaged as open-loop retail payment instruments. Yuexin Xiang, Qin Wang 0008, Tsz Hon Yuen, Andreas Deppeler, Jiangshan Yu |
ICBC | 4 |
| 2026 | Measuring Memecoin FragilityabstractMemecoins, emerging from internet culture and community-driven narratives, have rapidly evolved into a unique class of crypto assets. Unlike technology-driven cryptocurrencies, their market dynamics are primarily shaped by viral social media diffusion, celebrity influence, and speculative capital inflows. To capture the distinctive vulnerabilities of these ecosystems, we present the first Memecoin Ecosystem Fragility Framework (ME2F). ME2F formalizes memecoin risks in three dimensions: i) Volatility Dynamics Score capturing persistent and extreme price swings together with spillover from base chains; ii) Whale Dominance Score quantifying ownership concentration among top holders; and iii) Sentiment Amplification Score measuring the impact of attention-driven shocks on market stability. We apply ME2F to representative tokens (over 65% market share) and show that fragility is not evenly distributed across the ecosystem. Politically themed tokens such as TRUMP, MELANIA, and LIBRA concentrate the highest risks, combining volatility, ownership concentration, and sensitivity to sentiment shocks. Established memecoins such as DOGE, SHIB, and PEPE fall into an intermediate range. Benchmark tokens ETH and SOL remain consistently resilient due to deeper liquidity and institutional participation. Our findings provide the first ecosystem-level evidence of memecoin fragility and highlight governance implications for enhancing market resilience in the Web3 era. Yuexin Xiang, Qishuang Fu, Qin Wang 0008, Tsz Hon Yuen, Jiangshan Yu |
ICBC | 5 |
| 2026 | GumSwap: Griefing-Free Universal Multi-Party Atomic Swaps
Dongkun Hou, Yuanzhe Zhang, Shujie Cui, Tsz Hon Yuen, Joseph K. Liu, Jiangshan Yu |
ICDCS | 4 |
| 2026 | Dualmatrix: conquering zkSNARK for large matrix multiplicationabstractAbstract We present , a zkSNARK solution for large-scale matrix multiplication. Classical zkSNARK protocols typically underperform in data analytic contexts, hampered by the large size of datasets and the superlinear nature of matrix multiplication. excels in its scalability. The prover time of scales linearly with respect to the number of non-zero elements in the input matrices. For $$n \times n$$ n × n matrix multiplication with N non-zero elements across three input matrices, employs a structured reference string (SRS) of size O ( n ), and achieves RAM usage of $$O(N+n)$$ O ( N + n ) , transcript size of $$O(\log n)$$ O ( log n ) , prover time of $$O(N+n)$$ O ( N + n ) , and verifier time of $$O(\log n)$$ O ( log n ) . The prover time, notably at $$O(N+n)$$ O ( N + n ) and surpassing all existing protocols, includes $$O(N+n)$$ O ( N + n ) field multiplications and O ( n ) exponentiations and pairings within bilinear groups. These efficiencies make effective for linear algebra on large matrices common in real-world applications. We evaluated with $$2^{15} \times 2^{15}$$ 2 15 × 2 15 input matrices each containing 1 G non-zero integers, which necessitate 32 T integer multiplications in naive matrix multiplication. recorded prover and verifier times of 150.84s and 0.56s, respectively. When applied to $$1M \times 1M$$ 1 M × 1 M sparse matrices each containing 1 G non-zero integers, it demonstrated prover and verifier times of 1, 384.45s and 0.67s. Our approach outperforms current zkSNARK solutions by successfully handling the large matrix multiplication task in experiment. We extend matrix operations from field matrices to group matrices, formalizing group matrix algebra. This mathematical advancement brings notable symmetries beneficial for high-dimensional elliptic curve cryptography. By leveraging the bilinear properties of our group matrix algebra in the context of the two-tier commitment scheme, achieves efficiency gains over previous matrix multiplication arguments. To accomplish this, we extend and enhance Bulletproofs to construct an inner product argument featuring a transparent setup and logarithmic verifier time. Mingshu Cong, Tsz Hon Yuen, Siu-Ming Yiu |
Cybersecur. | 2 |
| 2025 | SoK: A Deep Dive Into Anti-money Laundering Techniques for Blockchain Cryptocurrencies
Qishuang Fu, Joseph K. Liu, Shirui Pan, Tsz Hon Yuen |
ACISP (1) | 4 |
| 2025 | Efficient Private Set Intersection by Utilizing Oblivious Transfer ExtensionabstractThe private set intersection (PSI) allows two parties to know the intersection of their sets securely without revealing anything else. Many PSI protocols have been proposed, and many efficient schemes are based on oblivious pseudorandom functions (OPRF) built from oblivious transfer (OT). In this paper, we first propose a computationally friendly OPRF protocol by combining an OT extension (Crypto'03) with an oblivious key-value store (OKVS). By directly utilizing our OPRF protocol, we propose our PSI protocol. Compared with the most computationally friendly OT-based PSI protocol KKRT (CCS'16), our protocol can overcome the uncertainty issue of cuckoo hashing and runs faster 22.3% ∼ 41.2%. Compared with spot-low (Crypto'19) that has the lowest communication costs among the OT-based protocols, our protocol can run 69.5 × ∼1/4124.6 × faster than it with only 22% ∼ 23% more communication cost. CM (Crypto'20) aimed to balance computation and communication costs in their protocol such that it can run the fastest when the bandwidth is not high and not low. Our protocol outperforms CM in all settings with 5.8% ∼ 6.4% less communication costs. By utilizing our OPRF protocol, we also propose a more functional oblivious programmable pseudorandom function (OPPRF) protocol, allowing a party to securely obtain the payloads that correspond to common items. Our OPPRF protocol can be 1.7 × ∼1/42.4 × as fast as the state-of-the-art OPPRF protocol (Eurocrypt'21) in the LAN setting. Mingli Wu 0002, Tsz Hon Yuen, Siu-Ming Yiu |
AsiaCCS | 2 |
| 2025 | Scalable zkSNARKs for Matrix Computations - A Generic Framework for Verifiable Deep Learning
Mingshu Cong, Sherman S. M. Chow, Siu-Ming Yiu, Tsz Hon Yuen |
ASIACRYPT (5) | 4 |
| 2025 | Posterior Security: Anonymity and Message Hiding of Standard SignaturesabstractWe introduce posterior security of digital signatures, the additional security features after the original signature is generated. It is motivated by the scenario that some people store their secret keys in secure hardware and can only obtain a standard signature through a standardized interface. In this paper, we consider two different posterior security features: anonymity and message hiding. Tsz Hon Yuen, Ying-Teng Chen, Shimin Pan, Jiangshan Yu, Joseph K. Liu |
CCS | 1 |
| 2025 | More Practical Non-interactive Encrypted Conjunctive Search with Leakage and Storage Suppression
Huu Ngoc Duc Nguyen, Shujie Cui, Shangqi Lai, Tsz Hon Yuen, Joseph K. Liu |
ProvSec | 4 |
| 2025 | Plum: SNARK-Friendly Post-Quantum Signature Based on Power Residue PRFs
Xinyu Zhang 0017, Qishuang Fu, Ron Steinfeld, Joseph K. Liu, Tsz Hon Yuen, Man Ho Au |
ProvSec | 5 |
| 2025 | DIDO+: Data Provenance From Restricted TLS 1.3 Websites With Selective DisclosureabstractPublic data can be authenticated via TLS from trustworthy websites, while private data, such as user profiles, is generally restricted. Users cannot share their username and password to access private data (e.g., addresses) from restricted sites (e.g., utility companies). DECO (CCS 2020) presents a TLS 1.2-based solution that facilitates data liberation without imposing excessive trust assumptions or requiring server-side modifications. In our previous work, DIDO (ISPEC 2023), we proposed an optimized solution for TLS 1.3 websites. We addressed several open problems, including support for X25519 key exchange, the design of round-optimal three-party key exchange, the architecture of 2 PC for TLS 1.3 key scheduling, and circuit design optimized for 2 PC. Our implementation was tested on real-world websites. In this work, DIDO+, we provide a comparison with recent concurrent efforts and offer additional details about DIDO. We also present the NIZK proofs utilized in three-party key exchange under malicious settings. Finally, we introduce a new protocol called selective disclosure, which allows for the disclosure of specific portions of plaintext to the verifier, instead of the entirety. Kwan Yin Chan, Handong Cui, Tsz Hon Yuen, Siu-Ming Yiu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Message Control for Blockchain RewritingabstractBlockchain rewriting is necessary for modifying illegal or invalid messages included in blockchain transactions, while maintaining the consistency of subsequent blocks in the blockchain. However, arbitrary blockchain rewriting is not desirable as it defeats the purpose of blockchain rewriting. In this work, we propose a new security primitive named message-controlled chameleon hash (MCH) and apply it for message control in blockchain rewriting to ensure that no unspecified messages are generated from blockchain rewriting. The proposed MCH enables permitted parties to select candidate messages from designated message sets for blockchain rewriting at the message level. Our evaluation shows that the performance of MCH is comparable to the classic CH [26] and the state-of-the-art CH [16]. We also show that the proposed MCH can be easily integrated into both permissioned and permissionless blockchains. Yingjiu Li, Binanda Sengupta, Yangguang Tian, Jiaming Yuan, Tsz Hon Yuen |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Reconstructing Chameleon Hash: Full Security and the Multi-Party SettingabstractChameleon hash (CH) function differs from a classical hash function in a way that a collision can be found with the knowledge of a trapdoor secret key. CH schemes have been used in various cryptographic applications such as sanitizable signatures and redactable blockchains. In this work, we reconstruct CH to ensure advanced security and usability. Our contributions are four-fold. First, we propose the first CH scheme, which supports full security, meaning the inclusion of both full indistinguishability and full collision-resistance. These two properties are required in the strongest CH security model in the literature. We achieve this by our innovative design of removing the CH public key during the computation of the hash value. Second, we investigate the security of CH in the multi-party setting and introduce the new properties of claimability and deniability under this setting. Third, we present and implement two instantiations of our CH scheme: an ECC-based one and a post-quantum lattice-based one. Our implementation demonstrates their practicality. Finally, we discuss the possible use cases in the blockchain. Kwan Yin Chan, Liqun Chen 0002, Yangguang Tian, Tsz Hon Yuen |
AsiaCCS | 4 |
| 2024 | zkMatrix: Batched Short Proof for Committed Matrix MultiplicationabstractMatrix multiplication is a common operation in applications like machine learning and data analytics. To demonstrate the correctness of such an operation in a privacy-preserving manner, we propose zkMatrix, a zero-knowledge proof for the multiplication of committed matrices. Among the succinct non-interactive zero-knowledge protocols that have an O(log n) transcript size and O(log n) verifier time, zkMatrix stands out as the first to achieve O(n2) prover time and O(n2) RAM usage for multiplying two n X n matrices. Significantly, zkMatrix distinguishes itself as the first zk-SNARK protocol specifically designed for matrix multiplication. By batching multiple proofs together, each additional matrix multiplication only necessitates O(n) group operations in prover time. Mingshu Cong, Tsz Hon Yuen, Siu-Ming Yiu |
AsiaCCS | 2 |
| 2024 | Threshold Ring Signatures: From DualRing to the t+1 Rings
Tsz Hon Yuen, Shimin Pan |
ProvSec (1) | 1 |
| 2024 | O-Ring and K-Star: Efficient Multi-party Private Set Intersection
Mingli Wu 0002, Tsz Hon Yuen, Kwan Yin Chan |
USENIX Security Symposium | 2 |
| 2024 | Bandwidth-Efficient Zero-Knowledge Proofs For Threshold ECDSAabstractAbstract In most threshold Elliptic Curve Digital Signature Algorithm (ECDSA) signatures using additively homomorphic encryption, the zero-knowledge (ZK) proofs related to the ciphertext or the message space are the bottleneck in terms of bandwidth as well as computation time. In this paper, we propose a compact ZK proof for relations related to the Castagnos–Laguillaumie (CL) encryption, which is 33% shorter and 29% faster than the existing work in PKC 2021. We also give new ZK proofs for relations related to homomorphic operations over the CL ciphertext. These new ZK proofs are useful to construct a bandwidth-efficient universal composable-secure threshold ECDSA without compromising the proactive security and the non-interactivity. In particular, we lowered the communication and computation cost of the key refresh algorithm in the Paillier-based counterpart from $O(n^3)$ to $O(n^2)$. Considering a 5-signer setting, the bandwidth is better than the Paillier-based counterpart for up to 99, 95 and 35% for key generation, key refreshment and pre-signing, respectively. Handong Cui, Kwan Yin Chan, Tsz Hon Yuen, Xin Kang 0001, Cheng-Kang Chu |
Comput. J. | 3 |
| 2023 | Practical Verifiable Random Function with RKA Security
Tsz Hon Yuen, Shimin Pan |
ACISP | 1 |
| 2023 | Scored Anonymous Credentials
Sherman S. M. Chow, Jack P. K. Ma, Tsz Hon Yuen |
ACNS | 3 |
| 2023 | A Practical Forward-Secure DualRing
Nan Li 0007, Yingjiu Li, Atsuko Miyaji, Yangguang Tian, Tsz Hon Yuen |
CANS | 5 |
| 2023 | Efficient Multiplicative-to-Additive Function from Joye-Libert Cryptosystem and Its Application to Threshold ECDSAabstractThreshold ECDSA receives interest lately due to its widespread adoption in blockchain applications. A common building block of all leading constructions involves a secure conversion of multiplicative shares into additive ones, which is called the multiplicative-to-additive (MtA) function. MtA dominates the overall complexity of all existing threshold ECDSA constructions. Specifically, O(n2) invocations of MtA are required in the case of n active signers. Hence, improvement of MtA leads directly to significant improvements for all state-of-the-art threshold ECDSA schemes. Haiyang Xue, Man Ho Au, Mengling Liu, Kwan Yin Chan, Handong Cui, Tsz Hon Yuen, Chengru Zhang |
CCS | 7 |
| 2023 | DIDO: Data Provenance from Restricted TLS 1.3 Websites
Kwan Yin Chan, Handong Cui, Tsz Hon Yuen |
ISPEC | 3 |
| 2023 | BlindHub: Bitcoin-Compatible Privacy-Preserving Payment Channel Hubs Supporting Variable AmountsabstractPayment Channel Hub (PCH) is a promising solution to the scalability issue of first-generation blockchains or cryptocurrencies such as Bitcoin. It supports off-chain payments between a sender and a receiver through an intermediary (called the tumbler). Relationship anonymity and value privacy are desirable features of privacy-preserving PCHs, which prevent the tumbler from identifying the sender and receiver pairs as well as the payment amounts. To our knowledge, all existing Bitcoin-compatible PCH constructions that guarantee relationship anonymity allow only a (predefined) fixed payment amount. Thus, to achieve payments with different amounts, they would require either multiple PCH systems or running one PCH system multiple times. Neither of these solutions would be deemed practical.In this paper, we propose the first Bitcoin-compatible PCH that achieves relationship anonymity and supports variable amounts for payment. To achieve this, we have several layers of technical constructions, each of which could be of independent interest to the community. First, we propose BlindChannel, a novel bi-directional payment channel protocol for privacy-preserving payments, where one of the channel parties is unable to see the channel balances. Then, we further propose BlindHub, a three-party (sender, tumbler, receiver) protocol for private conditional payments, where the tumbler pays to the receiver only if the sender pays to the tumbler. The appealing additional feature of BlindHub is that the tumbler cannot link the sender and the receiver while supporting a variable payment amount. To construct BlindHub, we also introduce two new cryptographic primitives as building blocks, namely Blind Adaptor Signature (BAS), and Flexible Blind Conditional Signature (FBCS). BAS is an adaptor signature protocol built on top of a blind signature scheme. FBCS is a new cryptographic notion enabling us to provide an atomic and privacy-preserving PCH. Lastly, we instantiate both BlindChannel and BlindHub protocols and present implementation results to show their practicality. Xianrui Qin, Shimin Pan, Arash Mirzaei, Zhimei Sui, Oguzhan Ersoy, Amin Sakzad, Muhammed F. Esgin, Joseph K. Liu, Jiangshan Yu, Tsz Hon Yuen |
SP | 10 |
| 2023 | Efficient Unbalanced Private Set Intersection Cardinality and User-friendly Privacy-preserving Contact Tracing
Mingli Wu 0002, Tsz Hon Yuen |
USENIX Security Symposium | 2 |
| 2023 | Practical fully leakage resilient signatures with auxiliary inputs
Cailing Cai, Shimin Pan, Tsz Hon Yuen, Siu-Ming Yiu |
Future Gener. Comput. Syst. | 3 |
| 2022 | Multi-signatures for ECDSA and Its Applications in Blockchain
Shimin Pan, Kwan Yin Chan, Handong Cui, Tsz Hon Yuen |
ACISP | 4 |
| 2022 | Don't Tamper with Dual System Encryption - Beyond Polynomial Related-Key Security of IBE
Tsz Hon Yuen, Cong Zhang 0001, Sherman S. M. Chow |
ACNS | 1 |
| 2022 | Tight Leakage-Resilient Identity-based Encryption under Multi-challenge SettingabstractIn this work, we present the first leakage-resilient identity-based encryption (LR-IBE) scheme that features (almost) tight security under the multi-challenge setting, in which the adversary could receive multiple challenging ciphertexts from multiple users. Meanwhile, our construction enjoys security against chosen-ciphertext attack (CCA) under the Matrix Decisional Diffie-Hellman (MDDH) assumption. Apart from admitting the continual leakage of secret key, we provide strong security via additionally allowing the continual leakage of the master secret key. Cailing Cai, Xianrui Qin, Tsz Hon Yuen, Siu-Ming Yiu |
AsiaCCS | 3 |
| 2022 | Attribute-Based Anonymous Credential: Optimization for Single-Use and Multi-Use
Kwan Yin Chan, Tsz Hon Yuen |
CANS | 2 |
| 2022 | Hash Proof System with Auxiliary Inputs and Its ApplicationabstractIn this work, we develop a hash proof system with auxiliary inputs (HPSAI), whose performance is as efficient as the underlying hash proof system (HPS). Moreover, we show that our HPSAI is a practical tool for the creation of leakage-resilient public key encryption (LR-PKE). In particular, we obtain a CCA-secure LR-PKE scheme that is able to leak most of the secret key information-theoretically with any hard-to-invert leakage function. Furthermore, our construction enjoys pairing-free and constant ciphertext size. Cailing Cai, Tsz Hon Yuen, Siu-Ming Yiu |
TrustCom | 2 |
| 2022 | GCD-Filter: Private Set Intersection Without Encryption
Mingli Wu 0002, Tsz Hon Yuen |
WASA (2) | 2 |
| 2022 | Non-Interactive Multi-Client Searchable Encryption: Realization and ImplementationabstractIn this article, we introduce a new mechanism for constructing multi-client searchable encryption (SE). By tactfully leveraging the RSA-function, we propose the first multi-client SE protocol that successfully avoids per-query interaction between data owner and client. Therefore, our approach significantly reduces the communication cost by eliminating the need for data owner to authorize client queries at all times. To be compatible with the RSA-based approach, we also present a deterministic and memory-efficient ‘keyword to prime’ hash function, which may be of independent interest. Further, to improve efficiency, we put forward a more generic construction from set-constrained PRFs. The construction not only inherits the merits of our first protocol, but also achieves an enhanced security (against untrusted clients), where colluding attack among clients is also taken into account. Both protocols are instantiated via the recent representative SE protocol by Cashet al.with the support of boolean queries. At last, we implement our proposed protocols and comprehensively evaluate their performance to demonstrate their practicability and scalability. Shifeng Sun 0001, Cong Zuo 0001, Joseph K. Liu, Amin Sakzad, Ron Steinfeld, Tsz Hon Yuen, Xingliang Yuan, Dawu Gu |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2021 | A Trustless GQ Multi-signature Scheme with Identifiable Abort
Handong Cui, Tsz Hon Yuen |
ACISP | 2 |
| 2021 | Efficient Online-friendly Two-Party ECDSA SignatureabstractTwo-party ECDSA signatures have received much attention due to their widespread deployment in cryptocurrencies. Depending on whether or not the message is required, we could divide two-party signing into two different phases, namely, offline and online. Ideally, the online phase should be made as lightweight as possible. At the same time, the cost of the offline phase should remain similar to that of a normal signature generation. However, the existing two-party protocols of ECDSA are not optimal: either their online phase requires decryption of a ciphertext, or their offline phase needs at least two executions of multiplicative-to-additive conversion which dominates the overall complexity. This paper proposes an online-friendly two-party ECDSA with a lightweight online phase and a single multiplicative-to-additive function in the offline phase. It is constructed by a novel design of a re-sharing of the secret key and a linear sharing of the nonce. Our scheme significantly improves previous protocols based on either oblivious transfer or homomorphic encryption. We implement our scheme and show that it outperforms prior online-friendly schemes (i.e., those have lightweight online cost) by a factor of roughly 2 to 9 in both communication and computation. Furthermore, our two-party scheme could be easily extended to the 2-out-of-n threshold ECDSA. Haiyang Xue, Man Ho Au, Tsz Hon Yuen, Handong Cui |
CCS | 4 |
| 2021 | DualRing: Generic Construction of Ring Signatures with Efficient Instantiations
Tsz Hon Yuen, Muhammed F. Esgin, Joseph K. Liu, Man Ho Au, Zhimin Ding |
CRYPTO (1) | 1 |
| 2021 | One-More Unforgeability of Blind ECDSA
Xianrui Qin, Cailing Cai, Tsz Hon Yuen |
ESORICS (2) | 3 |
| 2021 | Privacy-Preserving Contact Tracing Protocol for Mobile Devices: A Zero-Knowledge Proof Approach
Joseph K. Liu, Man Ho Au, Tsz Hon Yuen, Cong Zuo 0001, Jiawei Wang 0003, Amin Sakzad, Xiapu Luo, Li Li 0029, Kim-Kwang Raymond Choo |
ISPEC | 3 |
| 2021 | Security on SM2 and GOST Signatures against Related Key AttacksabstractThe US Standard (EC)DSA is currently almost the most popular digital signature scheme. Chinese and Russian governments also proposed their counterparts: SM2 and GOST R 34.10 (GOST). Nowadays, there are already many industrial applications supporting SM2 and GOST digital signatures. Unfortunately, the existing analyses for SM2 and GOST are rather limited when compared to ECDSA. This paper focuses on the security of SM2 and GOST from the viewpoints of RKA security (related-key attack) and sKRKA security (strong known related key attack). RKA captures the real attacks of tampering and fault injection in hardware-stored secret keys. sKRKA, a recently proposed security model modified from RKA, captures the real attacks in the BIP-32 HD wallet and the stealth address used in Monero. It was proved that ECDSA is insecure in the RKA model (ICISC 2015) and but secure in the sKRKA model (NSS 2019). In this work, we proved that GOST is insecure in both RKA and skRKA models, but SM2 is secure in both RKA and sKRKA models. This result well differentiates the security of ECDSA, SM2 and GOST, and demonstrates that Chinese SM2 is capable to construct secure cryptocurrency systems using BIP-32 HD wallet or stealth address, as secure as ECDSA, but outperforms ECDSA in resisting tampering or fault injection attacks. Handong Cui, Xianrui Qin, Cailing Cai, Tsz Hon Yuen |
TrustCom | 4 |
| 2020 | LPPRS: New Location Privacy Preserving Schemes Based on Ring Signature over Mobile Social Networks
Cailing Cai, Tsz Hon Yuen, Handong Cui, Mingli Wu 0002, Siu-Ming Yiu |
Inscrypt | 2 |
| 2020 | Compatible Certificateless and Identity-Based Cryptosystems for Heterogeneous IoT
Rouzbeh Behnia, Attila A. Yavuz, Muslum Ozgur Ozmen, Tsz Hon Yuen |
ISC | 4 |
| 2020 | Address-based Signature
Handong Cui, Tsz Hon Yuen |
TrustCom | 2 |
| 2020 | Server-aided revocable attribute-based encryption for cloud computing servicesabstractSummary Attribute‐based encryption (ABE) has been regarded as a promising solution in cloud computing services to enable scalable access control without compromising the security. Despite of the advantages, efficient user revocation has been a challenge in ABE. One suggestion for user revocation is using the binary tree in the key generation phase of an ABE scheme, which enables a trusted key generation center to periodically distribute the key update information to all nonrevoked users over a public channel. This revocation approach reduces the size of key updates from linear to logarithmic in the number of users. But it requires each user to keep a private key of the logarithmic size, and asks each nonrevoked user to periodically update his/her decryption key for each new time period. To further optimize user revocation in ABE, a server‐aided revocable ABE (SR‐ABE) scheme has been proposed, in which almost all workloads of users incurred by the user revocation are outsourced to an untrusted server, and each user only needs to store a private key of the constant size. In addition, SR‐ABE does not require any secure channel for the key transmission, and a user only needs to perform a small amount of calculations to decrypt a ciphertext. In this paper, we revisit the notion of SR‐ABE, and present a generic construction of SR‐ABE, which can transform a revocable ABE (RABE) scheme to an SR‐ABE scheme. In addition, we give an instantiation of SR‐ABE by applying the generic construction on a concrete RABE scheme, and implement an instantiation of SR‐ABE and an RABE scheme to evaluate the performance of SR‐ABE. Hui Cui 0001, Tsz Hon Yuen, Robert H. Deng, Guilin Wang |
Concurr. Comput. Pract. Exp. | 2 |
| 2020 | PAChain: Private, authenticated & auditable consortium blockchain and its implementation
Tsz Hon Yuen |
Future Gener. Comput. Syst. | 1 |
| 2019 | PAChain: Private, Authenticated and Auditable Consortium Blockchain
Tsz Hon Yuen |
CANS | 1 |
| 2019 | Strong Known Related-Key Attacks and the Security of ECDSA
Tsz Hon Yuen, Siu-Ming Yiu |
NSS | 1 |
| 2018 | Time-Based Direct Revocable Ciphertext-Policy Attribute-Based Encryption with Short Revocation List
Joseph K. Liu, Tsz Hon Yuen, Peng Zhang 0029, Kaitai Liang |
ACNS | 2 |
| 2018 | Anonymity Reduction Attacks to Monero
Dimaz Ankaa Wijaya, Joseph K. Liu, Ron Steinfeld, Dongxi Liu, Tsz Hon Yuen |
Inscrypt | 5 |
| 2018 | Compact Ring Signature in the Standard Model for Blockchain
Peng Zhang 0029, Qingchun Shentu, Joseph K. Liu, Tsz Hon Yuen |
ISPEC | 5 |
| 2017 | RingCT 2.0: A Compact Accumulator-Based (Linkable Ring Signature) Protocol for Blockchain Cryptocurrency Monero
Shifeng Sun 0001, Man Ho Au, Joseph K. Liu, Tsz Hon Yuen |
ESORICS (2) | 4 |
| 2017 | A general framework for secure sharing of personal health records in cloud system
Man Ho Au, Tsz Hon Yuen, Joseph K. Liu, Willy Susilo, Xinyi Huang 0001, Yang Xiang 0001, Zoe Lin Jiang |
J. Comput. Syst. Sci. | 2 |
| 2016 | Efficient Completely Non-Malleable and RKA Secure Public Key Encryptions
Shifeng Sun 0001, Parampalli Udaya, Tsz Hon Yuen, Yu Yu 0001, Dawu Gu |
ACISP (2) | 3 |
| 2016 | Efficient Construction of Completely Non-Malleable CCA Secure Public Key EncryptionabstractNon-malleability is an important and intensively studied security notion for many cryptographic primitives. In the context of public key encryption, this notion means it is infeasible for an adversary to transform an encryption of some message m into one of a related message m' under the given public key. Although it has provided a strong security property for many applications, it still does not suffice for some scenarios like the system where the users could issue keys on-the-fly. In such settings, the adversary may have the power to transform the given public key and the ciphertext. To withstand such attacks, Fischlin introduced a stronger notion, known as complete non-malleability, which requires that the non-malleability property be preserved even for the adversaries attempting to produce a ciphertext of some related message under the transformed public key. To date, many schemes satisfying this stronger security have been proposed, but they are either inefficient or proved secure in the random oracle model. In this work, we put forward a new encryption scheme in the common reference string model. Based on the standard DBDH assumption, the proposed scheme is proved completely non-malleable secure against adaptive chosen ciphertext attacks in the standard model. In our scheme, the well-formed public keys and ciphertexts could be publicly recognized without drawing support from unwieldy techniques like non-interactive zero knowledge proofs or one-time signatures, thus achieving a better performance. Shifeng Sun 0001, Dawu Gu, Joseph K. Liu, Parampalli Udaya, Tsz Hon Yuen |
AsiaCCS | 5 |
| 2016 | An Efficient Non-interactive Multi-client Searchable Encryption with Support for Boolean Queries
Shifeng Sun 0001, Joseph K. Liu, Amin Sakzad, Ron Steinfeld, Tsz Hon Yuen |
ESORICS (1) | 5 |
| 2016 | Efficient Privacy-Preserving Charging Station Reservation System for Electric VehiclesabstractIn this paper, we propose a privacy-preserving reservation system for electric vehicles (EV) charging stations. Due to the short driving range of EV, frequent charging is necessary. A mechanism for charging station reservation for EV owners is desirable. Our proposed system allows the vehicle owner to reserve a number of charging stations along the intended route at different time-slots. Yet it is secure against misuse such that a user can only hold a limited number of reservations simultaneously. More importantly, our system can provide privacy for users. The charging station does not know the identity of the user who has reserved it. Thus location privacy can be protected. We demonstrate the practicality of our system with a prototype implementation on a smart phone. Finally, we also provide a security proof to show that our system is secure under well-known computational assumptions. Joseph K. Liu, Willy Susilo, Tsz Hon Yuen, Man Ho Au, Zoe Lin Jiang, Jianying Zhou 0001 |
Comput. J. | 3 |
| 2016 | Accountable mobile E-commerce scheme via identity-based plaintext-checkable encryption
Jinguang Han, Xinyi Huang 0001, Tsz Hon Yuen, Jiguo Li 0001, Jie Cao 0001 |
Inf. Sci. | 4 |
| 2016 | ABKS-CSC: attribute-based keyword search with constant-size ciphertextsabstractAbstract Attribute‐based keyword search (ABKS) was proposed to enable a third party to search encrypted keywords without compromising the security of the original data. Because it can express flexible access policy, ABKS has attracted a lot of attention. Existing ABKS schemes mainly focused on the expression of access structures, while the computation cost and communication cost are linear with the number of required attributes. Therefore, existing ABKS schemes are unsuitable to the devices that have constrained space and computing power, such as smart phone and tablet. In this paper, an ABKS with constant‐size ciphertext scheme is proposed. The proposed scheme captures the following nice features: (1) The index encryption algorithm has constant computation cost; (2) the searchable ciphertexts are constant size; (3) the trapdoors for keywords are constant size; and (4) the test algorithm has constant computation cost. To the best of our knowledge, it is the first time that an ABKS with constant‐size ciphertext scheme is proposed. Copyright © 2016 John Wiley & Sons, Ltd. Jinguang Han, Willy Susilo, Tsz Hon Yuen, Jiguo Li 0001 |
Secur. Commun. Networks | 4 |
| 2015 | Related Randomness Attacks for Public Key CryptosystemsabstractWe initiate the study of related randomness attack in the face of a number of practical attacks in public key cryptography, ranges from active attacks like fault-injection, to passive attacks like software (mis)implementation on choosing random numbers. Our new definitions cover the well-known related-key attacks (RKA) where secret keys are related, and a number of new attacks, namely, related encryption randomness attacks, related signing randomness attacks, and related public key attacks. We provide generic constructions for security against these attacks, which are efficiently built upon normal encryption and signature schemes, leveraging RKA-secure pseudorandom function and generator. Tsz Hon Yuen, Cong Zhang 0001, Sherman S. M. Chow, Siu-Ming Yiu |
AsiaCCS | 1 |
| 2015 | k-Times Attribute-Based Anonymous Access Control for Cloud ComputingabstractIn this paper, we propose a new notion called$k$-times attribute-based anonymous access control, which is particularly designed for supporting cloud computing environment. In this new notion, a user can authenticate himself/herself to the cloud computing server anonymously. The server only knows the user acquires some required attributes, yet it does not know the identity of this user. In addition, we provide a$k$-times limit for anonymous access control. That is, the server may limit a particular set of users (i.e., those users with the same set of attribute) to access the system for a maximum$k$-times within a period or an event. Further additional access will be denied. We also prove the security of our instantiation. Our implementation result shows that our scheme is practical. Tsz Hon Yuen, Joseph K. Liu, Man Ho Au, Xinyi Huang 0001, Willy Susilo, Jianying Zhou 0001 |
IEEE Trans. Computers | 1 |
| 2014 | Identity-Based Encryption with Post-Challenge Auxiliary Inputs for Secure Cloud Applications and Sensor Networks
Tsz Hon Yuen, Ye Zhang 0001, Siu-Ming Yiu, Joseph K. Liu |
ESORICS (1) | 1 |
| 2014 | Improvements on an authentication scheme for vehicular sensor networks
Joseph K. Liu, Tsz Hon Yuen, Man Ho Au, Willy Susilo |
Expert Syst. Appl. | 2 |
| 2014 | Towards a cryptographic treatment of publish/subscribe systemsabstractPublish/subscribe mechanism is a typical many-to-many messaging paradigm when multiple applications want to receive the same message or when a group of applications would like to notify each other. Nonetheless, there exist only a few works that address the security issues for content-based publish/subscribe systems formally. Although the security requirements have been partially addressed by Wang et al., there is no formal definition for all of these security requirements in the literature. As a result, most of the existing schemes do not have any security proof and it is difficult to justify whether those schemes are really secure in practice. Furthermore, there is no comprehensive scheme that satisfies the most essential security requirements at the same time. In this paper, we introduce the first security model for important security requirements of content-based publish/subscribe systems. We also give a new security requirement for publisher authenticity, which means that the publisher is authenticated to publish certain types of notification only, and cannot publish other types of notification. We then exhibit a new scheme which fulfills most of the security requirements. Furthermore, we also provide a comprehensive proof for our concrete construction according to the new model. Tsz Hon Yuen, Willy Susilo, Yi Mu 0001 |
J. Comput. Secur. | 1 |
| 2013 | Multi-key leakage-resilient threshold cryptographyabstractWith the goal of ensuring availability of security services such as encryption and authentication, we initiate the study of leakage-resilient threshold cryptography, for achieving formal security guarantee under various key-exposure attacks. A distinctive property of threshold cryptosystems is that a threshold number of secret keys are used in the main cryptographic function such as decryption or signing. Even though some existing security models allow leakages of multiple keys of different users, these keys are not used simultaneously to decrypt a ciphertext or sign a message. Cong Zhang 0001, Tsz Hon Yuen, Hao Xiong 0002, Sherman S. M. Chow, Siu-Ming Yiu, Yi Jun He |
AsiaCCS | 2 |
| 2013 | Attribute Specified Identity-Based Encryption
Hao Xiong 0002, Tsz Hon Yuen, Cong Zhang 0001, Yi Jun He, Siu-Ming Yiu |
ISPEC | 2 |
| 2013 | Threshold-Oriented Optimistic Fair Exchange
Yang Wang 0074, Man Ho Au, Joseph K. Liu, Tsz Hon Yuen, Willy Susilo |
NSS | 4 |
| 2013 | Towards Anonymous Ciphertext Indistinguishability with Identity Leakage
Tsz Hon Yuen, Cong Zhang 0001, Sherman S. M. Chow, Joseph K. Liu |
ProvSec | 1 |
| 2013 | Efficient Linkable and/or Threshold Ring Signature Without Random OraclesabstractLinkable ring signatures have found many attractive applications. One of the recent important extensions is a linkable threshold ring signature (LTRS) scheme. Unfortunately, the existing LTRS schemes are only secure in the random oracle model (ROM). In this paper, we make the following contributions. First, we construct the first LTRS scheme that is secure without requiring the ROM. Further, we enhance the security of a threshold ring signature (for both linkable or non-linkable) by providing a stronger definition of anonymity. This strengthened notion makes threshold ring signature schemes more suitable in real life. Finally, we provide efficient schemes that outperform the existing schemes in the literature. Our scheme is particularly suitable for electronic commerce or electronic government where anonymity and accountability are the most concerned factors. Tsz Hon Yuen, Joseph K. Liu, Man Ho Au, Willy Susilo, Jianying Zhou 0001 |
Comput. J. | 1 |
| 2013 | Secure ID-based linkable and revocable-iff-linked ring signature with constant-size construction
Man Ho Au, Joseph K. Liu, Willy Susilo, Tsz Hon Yuen |
Theor. Comput. Sci. | 4 |
| 2012 | Fully Leakage-Resilient Signatures with Auxiliary Inputs
Tsz Hon Yuen, Siu-Ming Yiu, Lucas C. K. Hui |
ACISP | 1 |
| 2012 | PE(AR)2: Privacy-Enhanced Anonymous Authentication with Reputation and Revocation
Kin Ying Yu, Tsz Hon Yuen, Sherman S. M. Chow, Siu-Ming Yiu, Lucas C. K. Hui |
ESORICS | 2 |
| 2012 | Identity-Based Encryption Resilient to Continual Auxiliary Leakage
Tsz Hon Yuen, Sherman S. M. Chow, Ye Zhang 0001, Siu-Ming Yiu |
EUROCRYPT | 1 |
| 2012 | Continual Leakage-Resilient Dynamic Secret Sharing in the Split-State Model
Hao Xiong 0002, Cong Zhang 0001, Tsz Hon Yuen, Echo P. Zhang, Siu-Ming Yiu, Sihan Qing |
ICICS | 3 |
| 2012 | Forward Secure Attribute-Based Signatures
Tsz Hon Yuen, Joseph K. Liu, Xinyi Huang 0001, Man Ho Au, Willy Susilo, Jianying Zhou 0001 |
ICICS | 1 |
| 2011 | Threshold ring signature without random oraclesabstractIn this paper, we present the notion and construction of threshold ring signature without random oracles. This is the first scheme in the literature that is proven secure in the standard model. Our scheme extends the Shacham-Waters signature from PKC 2007 in a non-trivial way. We note that our technique is specifically designed to achieve a threshold ring signature in the standard model. Interestingly, we can still maintain the signature size to be the same as the Shacham-Waters signature, while only a tiny computation cost is added. Tsz Hon Yuen, Joseph K. Liu, Man Ho Au, Willy Susilo, Jianying Zhou 0001 |
AsiaCCS | 1 |
| 2011 | Fully Secure Multi-authority Ciphertext-Policy Attribute-Based Encryption without Random Oracles
Zhen Liu 0008, Zhenfu Cao, Qiong Huang 0001, Duncan S. Wong, Tsz Hon Yuen |
ESORICS | 5 |
| 2011 | Forward Secure Ring Signature without Random Oracles
Joseph K. Liu, Tsz Hon Yuen, Jianying Zhou 0001 |
ICICS | 2 |
| 2011 | Concurrent Signatures with Fully Negotiable Binding Control
Tsz Hon Yuen, Duncan S. Wong, Willy Susilo, Qiong Huang 0001 |
ProvSec | 1 |
| 2010 | Towards a Cryptographic Treatment of Publish/Subscribe Systems
Tsz Hon Yuen, Willy Susilo, Yi Mu 0001 |
CANS | 1 |
| 2009 | Efficient Non-interactive Range Proof
Tsz Hon Yuen, Qiong Huang 0001, Yi Mu 0001, Willy Susilo, Duncan S. Wong, Guomin Yang |
COCOON | 1 |
| 2008 | Sanitizable Signatures Revisited
Tsz Hon Yuen, Willy Susilo, Joseph K. Liu, Yi Mu 0001 |
CANS | 1 |
| 2007 | (Convertible) Undeniable Signatures Without Random Oracles
Tsz Hon Yuen, Man Ho Au, Joseph K. Liu, Willy Susilo |
ICICS | 1 |
| 2007 | Certificate Based (Linkable) Ring Signature
Man Ho Au, Joseph K. Liu, Willy Susilo, Tsz Hon Yuen |
ISPEC | 4 |
| 2007 | Practical Threshold Signatures Without Random Oracles
Jin Li 0002, Tsz Hon Yuen, Kwangjo Kim |
ProvSec | 2 |
| 2006 | Ring signatures without random oraclesabstractSince the formalization of ring signature by Rivest, Shamir and Tauman in 2001, there are lots of variations appeared in the literature. Almost all of the variations rely on the random oracle model for security proof. In this paper, we propose a ring signature scheme based on bilinear pairings, which is proven to be secure against adaptive chosen message attack without using the random oracle model. It is one of the first in the literature to achieve this security level. Sherman S. M. Chow, Victor K.-W. Wei, Joseph K. Liu, Tsz Hon Yuen |
AsiaCCS | 4 |
| 2006 | WebQuest Markup Language (WQML) for Sharable Inquiry-Based Learning
Sebastian Fleissner, Yuen-Yan Chan, Tsz Hon Yuen, Victor Ng |
ICCSA (1) | 3 |
| 2005 | Group Signature Where Group Manager, Members and Open Authority Are Identity-Based
Victor K.-W. Wei, Tsz Hon Yuen, Fangguo Zhang |
ACISP | 2 |
| 2005 | Fast and Proven Secure Blind Identity-Based Signcryption from Pairings
Tsz Hon Yuen, Victor K.-W. Wei |
CT-RSA | 1 |
| 2005 | Signcryption in Hierarchical Identity Based Cryptosystem
Sherman S. M. Chow, Tsz Hon Yuen, Lucas C. K. Hui, Siu-Ming Yiu |
SEC | 2 |