Jianghong Wei

dblp:119/5639 · DBLP profile ↗
← Back
45ranked-venue papers
17as first author
34since 2021 · last 2026
0000-0002-0286-7973ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 25 · 9 first-author · 19 since 2021Artificial intelligence and machine learning · 6 · 1 first-author · 4 since 2021Systems, architecture and hardware · 6 · 2 first-author · 5 since 2021Computer networks · 5 · 2 first-author · 5 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author
YearPublicationVenuePosition
2026 Batch-Puncturing Circuit CP-ABE (and More) from Lattices
Yongkang Lang, Fangguo Zhang, Jianghong Wei, Xinyi Huang 0001, Xiaofeng Chen 0001
ACISP (2)3
2026 Forward-Secure Tag-Inverse Puncturable Identity-Based Encryption
Yang Ba, Xuexian Hu, Jianghong Wei
ACISP (2)4
2026 Verifiable and Controllable Data Sharing With Compliance Checking in Cloud Computing
abstract
Data capsule provides a feasible solution for controllable data sharing, where data owners outsource their data capsules containing encrypted data and compliance-checking policies to the cloud server, and only valid users can run a compliant analysis program to process the decrypted data capsules in the Trusted Execution Environment (TEE), without obtaining the raw data. However, existing schemes cannot achieve verifiable accesses and updates, which means that malicious servers may use corrupted/old data capsules to deceive users and TEE. In this paper, we introduce the concept of Verifiable Data Capsule (VDC) for secure and controllable data sharing. Specifically, we first design a lightweight authentication tag, dubbed Locally Verifiable Chameleon Tag (LVCT), which allows the data owner to bind all data capsules to a constant-size tag and enables users to recover the local tags for validating data capsules. On this basis, we present a concrete VDC scheme that utilizes a dual-level authentication structure to realize verifiable data updates, and verifiable state updates triggered by regular access without the aid of the data owner. Furthermore, we propose an efficient trust evaluation protocol to judge the credibility of cloud servers. Finally, both security analysis and performance evaluation demonstrate the practicability of the proposed scheme.
Guohua Tian, Meixia Miao, Jianghong Wei, Zheli Liu, Liang Guo 0013, Xiaofeng Chen 0001
IEEE Trans. Dependable Secur. Comput.3
2026 Verifiable Data Streaming Protocol Supporting Keyword Queries
abstract
The rapid deployment of emerging networks, such as the Internet of Things and cloud computing, has generated massive amounts of data. Data streaming is significant among these various data types due to its widespread use in many critical applications, such as gene sequencing, network intrusion detection, and stock trading. On the other hand, the continuously increased size of data streaming makes it impractical to store and manage the data locally, especially for those resource-constrained devices. Outsourcing the data streaming to cloud servers provides an ideal solution to the above storage issue. However, this raises the problem of how to guarantee the integrity of the outsourced data, as cloud servers may maliciously modify the data. To this end, the primitive of verifiable data streaming (VDS) was introduced to preserve the integrity of the outsourced data streaming, enabling data users to ensure that queried data items, including the contents and corresponding positions, are correct. Despite many proposed VDS protocols, most can only use the position index to query outsourced data streaming. Consequently, they fail to fulfill the requirements of those practical applications that need keyword queries. For example, in the setting of network intrusion detection, the data analyst would like to query all access records from the same IP address. In this paper, we extend the original VDS protocol to support keyword queries, i.e., allowing data users to retrieve outsourced data items with particular keywords. Specifically, we use a prefix tree to maintain keywords and another chameleon authentication tree to store data items. The two trees are bound together with cryptographic query proofs, ensuring the consistency between the position index and keyword queries. The proposed VDS protocol, which supports keyword queries, is proven secure in the standard model and outperforms previous VDS protocols in terms of functionality. The experimental results indicate that our proposal is also efficient and practical.
Meixia Miao, Peihong Qiang, Siqi Zhao, Jiawei Li 0011, Guohua Tian, Jianghong Wei
IEEE Trans. Netw. Serv. Manag.6
2025 An Enhanced Efficient Password-Authenticated Key Exchange Protocol for the Internet of Things
abstract
The symmetric Password-Authenticated Key Exchange (PAKE) protocol enables two parties sharing a low-entropy password to establish a high-entropy session key, offering advantages in simplicity and efficiency. This makes it particularly suitable for Internet of Things (IoT) devices with limited computational resources, positioning it as one of the most effective security methods for authentication and key exchange in IoT environments. In this paper, we analyze a recently proposed efficient symmetric PAKE protocol for IoT, identifying its vulnerability to offline dictionary attacks and its failure to meet the claimed security goals. Building upon the analysis of these design flaws, we present an enhanced protocol, demonstrating its security within the random oracle model. The enhanced protocol retains the protocol flow and computational operations of the original protocol to the greatest extent possible, maintains nearly the same computational efficiency, and simultaneously addresses the vulnerabilities that made the original protocol susceptible to offline dictionary attacks.
Shouxin Shang, Xuexian Hu, Qihui Zhang, Jianghong Wei, Qinlong Fan
IEEE Internet Things J.4
2025 SECP-AKE: Secure and efficient certificateless-password-based authenticated key exchange protocol for smart healthcare systems
Xuexian Hu, Jianghong Wei, Yuanjun Xia, Yangfan Liang
J. Syst. Archit.4
2025 Deniable Identity-Based Matchmaking Encryption for Anonymous Messaging
abstract
Anonymous messaging system allows users to deliver messages without revealing the sending content and their identifiers, which has attracted ongoing concerns. However, to the best of our knowledge, all the existing solutions still fail to protect users’ privacy under coercion. That is, the user’s communication transcripts might be tracked and cached, and later coerced to reveal the underlying messages associated with the ciphertexts due to law enforcement reasons or for evil purposes. In addition, anonymity alone is not enough for some practical scenarios. For instance, a journalist just wants to communicate with those intended informants, and thereby gather information from anonymous but authenticated sources. In this paper, to address the above-mentioned issues, we introduce an authenticated and deniable anonymous messaging framework. Its core component is a new cryptographic primitive dubbed deniable identity-based matchmaking encryption (DIB-ME), which captures plausible deniability under coercion and mutual authentication without interactions simultaneously. We further present a concrete DIB-ME construction and prove its security in the random oracle model. The performance analysis indicates merits of the proposed DIB-ME scheme. We also implement the proposed DIB-ME construction and present extensive experiment results, as a proof of concept to demonstrate its soundness and practicability.
Yanmei Cao, Jianghong Wei, Xinyi Huang 0001, Xiaofeng Chen 0001, Yang Xiang 0001
IEEE Trans. Dependable Secur. Comput.2
2025 Function-Hiding Multi-Client Inner-Product Functional Encryption Without Pairings for Large Space
abstract
Multi-client functional encryption (MCFE) is an extension of functional encryption (FE) in the multi-user setting and serves as a generalization of multi-input functional encryption (MIFE). The necessity of hiding function when it contains sensitive information, coupled with the widespread application of inner product (IP) in the descriptive statistics, has led to extensive research on function-hiding MCFE for IP. However, these works all rely on pairings and impose serious restrictions on the size of supported messages, as they all use inefficient decryption involving the extraction of discrete logarithms. On the other hand, although Abdalla et al. (CRYPTO 2018) introduced the first inner-product MIFE scheme for large message space as a special case of MCFE, it is not function-hiding. Consequently, existing inner-product MCFE schemes either exclusively support large space or solely achieve function-hiding, with no solution simultaneously achieving both properties. This paper employs an incremental construction strategy to design the function-hiding inner-product MCFE scheme, which does not require pairings. This leads to two main advances. First, we achieve the function hiding for inner-product MIFE even for messages of super-polynomial size. Second, we obtain the first function-hiding inner-product MCFE for large space, where the length of the message is of super-polynomial size.
Jianghong Wei, Fuchun Guo, Yang Xiang 0001, Xiaofeng Chen 0001
IEEE Trans. Dependable Secur. Comput.2
2025 Lightweight 0-RTT Session Resumption Protocol for Constrained Devices
abstract
With the growing popularity of various Internet of Things (IoT) applications, securing data transmission over these networks become critical. The authenticated key exchange (AKE) protocol is a fundamental cryptographic primitive that achieves this goal by creating a shared session key. However, since IoT end devices are usually resource-constrained, devising secure and efficient AKE protocols for IoT applications remains challenging. In this paper, we investigate the design of zero round-trip time (0-RTT) session resumption protocols based on pre-shared keys, which enables an end device to send encrypted data to a server without prior key exchange. Specifically, we first propose a new construction of puncturable pseudo-random function (PRF), and prove its security under the RSA assumption. Then, based on the proposed puncturable PRF and authenticated encryption with associated data, we put forward a new construction of 0-RTT session resumption protocol that simultaneously provides forward security and resistance against replay attacks. We further demonstrate how to combine the proposed 0-RTT session resumption protocol with other symmetric AKE protocols for IoT applications. Both theoretical comparisons and experimental results indicate that our proposal has significant advantages in terms of computation and storage costs for practical parameter settings. Thus, it is especially desirable for constrained devices.
Jianghong Wei, Guohua Tian, Xiaofeng Chen 0001, Willy Susilo
IEEE Trans. Inf. Forensics Secur.1
2024 Pixel+ and Pixel++: Compact and Efficient Forward-Secure Multi-Signatures for PoS Blockchain Consensus
Jianghong Wei, Guohua Tian, Ding Wang 0002, Fuchun Guo, Willy Susilo, Xiaofeng Chen 0001
USENIX Security Symposium1
2024 Aggregatably Verifiable Data Streaming
abstract
In various real-time applications like intelligent transportation and stock trading systems, clients continuously generate the so-called data streaming that is sensitive to both the position and content. Due to the limitations of local storage resources, clients usually have to outsource the generated data to cloud servers that are not fully trusted. The primitive of verifiable data streaming (VDS) protocol was introduced to guarantee the integrity of the outsourced data streaming. Although many VDS protocols have been proposed to improve the efficiency and security of the original one, they mainly focus on how to verifiably retrieve specific data items, without considering the requirement of retrieving aggregated results. However, such a requirement is desirable in many practical applications that only need the aggregated results of the outsourced streaming data, such as satellite cloud atlas and real-time traffic data. In this paper, we introduce a new primitive named aggregatably verifiable data streaming (AVDS) that allows a data user to retrieve aggregated results of designated data items, while guaranteeing the validity of the aggregated results. Specifically, we introduce a new authenticated data structure named chameleon linear-map vector commitment (CLVC), and also provide a concrete construction. Furthermore, we propose a general framework of AVDS protocols from the building block of CLVC. The proposed AVDS protocol is proven to be secure in the standard model. Theoretical analysis and experimental results indicate that the proposed AVDS protocol extends previous VDS protocols in terms of functionality while having comparable computation and communication overhead.
Meixia Miao, Siqi Zhao, Jiawei Li 0011, Jianghong Wei
IEEE Internet Things J.4
2024 Enhancing Generalization in Few-Shot Learning for Detecting Unknown Adversarial Examples
abstract
Abstract Deep neural networks, particularly convolutional neural networks, are vulnerable to adversarial examples, undermining their reliability in visual recognition tasks. Adversarial example detection is a crucial defense mechanism against such attacks but often relies on empirical observations and specialized metrics, posing challenges in terms of data efficiency, generalization to unknown attacks, and scalability to high-resolution datasets like ImageNet. To address these issues, we propose a prototypical network-based method using a deep residual network as the backbone architecture. This approach is capable of extracting discriminative features of adversarial and normal examples from various known adversarial examples by constructing few-shot adversarial detection tasks. Then the optimal mapping matrix is computed using the Sinkhorn algorithm from optimal transport theory, and the class centers are iteratively updated, enabling the detection of unknown adversarial examples across scenarios. Experimental results show that the proposed approach outperforms existing methods in the cross-adversary benchmark and achieves enhanced generalization on a subset of ImageNet in detecting both new adversarial attacks and adaptive white-box attacks. The proposed approach offers a promising solution for improving the safety of deep neural networks in practical applications.
Wenzhao Liu, Kuiwu Yang, Kaiwei Guo, Jianghong Wei
Neural Process. Lett.6
2024 SDIM: A Subtly Designed Invertible Matrix for Enhanced Privacy-Preserving Outsourcing Matrix Multiplication and Related Tasks
abstract
Matrix multiplication computation (MMC) is one of the most important basic operations with a variety of applications in the scientific and engineering community, including linear regression, k-nearest neighbor classification and biometric identification. However, performing these tasks with large-scale datasets can result in significant computation beyond the capabilities of resource-constrained clients. As outsourcing intensive tasks to cloud server has become a promising method, many matrix-transformation-based privacy-protected schemes have been presented for certain outsourcing tasks, such as Lei et al's scheme for the outsourcing MMC task and Zhao et al's scheme for matrix determinant computation. Nevertheless, Lei et al's scheme suffers from inherent security flaws that reveal the statistical information of zero elements in the original data. Additionally, Zhao et al's scheme can only be applied to specific outsourced tasks and is not suitable for more universal situations, such as MMC, where the client needs to compute the inverse matrix of the secret key. Therefore, designing an invertible matrix is a difficult task that affects privacy security, efficiency, and universality of the matrix-transformation-based privacy-protected outsourcing computing scheme. To address this challenge, we propose a subtly designed invertible matrix (SDIM) and a privacy-protected outsourcing MMC scheme based on the SDIM to remedy the inherent security flaws of Lei et al's scheme. We also propose an optimized matrix-chain multiplication method to maintain high efficiency of the SDIM-based privacy-protected scheme. This optimization also allows the SDIM to be universally applied not only to MMC tasks but also to other related outsourced tasks such as linear regression. Theoretical analyses and experiments show that our methods are more secure in terms of data privacy, with comparable efficiency to the state-of-the-art scheme based on matrix transformation. This SDIM-based scheme has achieved a well-balanced trade-off between security, efficiency and universality.
Xuexian Hu, Xiaofeng Chen 0001, Jianghong Wei, Wenfen Liu
IEEE Trans. Dependable Secur. Comput.4
2024 Blockchain-Based Compact Verifiable Data Streaming With Self-Auditing
abstract
The primitive of verifiable data streaming (VDS) provides a secure data outsourcing solution for resource-constrained users, that is, they can stream their continuously-generated data items to untrusted servers while enabling publicly verifiable query and update. However, existing VDS schemes either require the server to store the authentication tags of all data items to support data query and auditing, or bind all data items into a constant-size tag to achieve optimal storage on the server side, but cannot achieve public auditing. To close this gap, in this paper, we first design a novel authentication data structure, dubbed retrievable homomorphic verifiable tags (RHVTs), which allows users to aggregate the authentication tags of all data items into a constant-size tag, and enables them to retrieve the original tags from the aggregated tag when necessary. Based on this, we propose a compact verifiable and auditable data streaming (CVADS) scheme, which adopts a single-level authentication mechanism to achieve more efficient data append and update, as well as optimal storage and public auditing. For better robustness and performance, we introduce a nested dual-level authentication mechanism and propose a blockchain-based CVADS (BCVADS) scheme to achieve a distributed CVADS with self-auditing. Finally, we prove the security of our schemes in the random oracle model and demonstrate their practicality through a visual performance evaluation.
Guohua Tian, Jianghong Wei, Meixia Miao, Fuchun Guo, Willy Susilo, Xiaofeng Chen 0001
IEEE Trans. Dependable Secur. Comput.2
2024 Optimal Verifiable Data Streaming Under Concurrent Queries
abstract
The rapid development of both hardware and software has promoted the popularization of various real-time applications like health monitoring and intrusion detection that are widely deployed in outsourcing scenarios, e.g., mobile edge computing and cloud computing. In these applications, end devices continuously generate unbounded sequences of data items at a fast rate, i.e., the so-called streaming data. Nevertheless, storing and processing massive amounts of streaming data poses a challenge for resources-restricted end devices. Although outsourcing data items to edge servers or cloud servers is an attractive solution to the above problem, it also brings a new challenge, i.e., how to guarantee the integrity of outsourced data, since streaming data applications are usually sensitive of both location and the corresponding context, and servers are not completely trusted. To this end, the primitive of verifiable data streaming (VDS) protocol was introduced to maintain outsourced streaming data, while preserving its integrity. However, existing VDS constructions mainly use the structure of Merkle hash tree, and inherently have logarithmic costs. Consequently, they are infeasible for real-time applications that are delay sensitive and generate unpredictable size of streaming data. In this paper, we optimize previous VDS protocols from the aspects of communication overhead and computation cost. Specifically, we adopt a technical route different from Merkle hash tree, i.e, combining the digital signature with the cryptographic accumulator. In our construction, we employ Boneh-Lynn-Shacham (BLS) signature to guarantee the integrity of the context and position of each outsourced data item, and adopt an RSA accumulator to invalidate the old signature after the corresponding data item was updated. This immediately yields an optimal VDS construction that has constant costs even under concurrent queries, which is more desirable for those resource-limited mobile devices. In addition, the aggregability of BLS signature makes our VDS construction capable of data auditing, which enables the user to remotely verify the integrity of outsourced streaming data. We provide a formal security proof of the proposed VDS construction under well-studied complexity assumptions in the random oracle model. As a proof-of-concept, we also implement our proposal, and conduct extensive experiments to demonstrate its practicability.
Jianghong Wei, Meixia Miao, Guohua Tian, Jun Shen 0006, Xiaofeng Chen 0001, Willy Susilo
IEEE Trans. Mob. Comput.1
2023 Robust Decentralized Multi-client Functional Encryption: Motivation, Definition, and Inner-Product Constructions
Jianghong Wei, Fuchun Guo, Willy Susilo, Xiaofeng Chen 0001
ASIACRYPT (5)2
2023 Improving temporal knowledge graph embedding using tensor factorization
Mengli Zhang, Jianghong Wei
Appl. Intell.4
2023 Towards secure asynchronous messaging with forward secrecy and mutual authentication
Jianghong Wei, Xiaofeng Chen 0001, Jianfeng Wang 0001, Willy Susilo, Ilsun You
Inf. Sci.1
2023 System-widely and fine-grained forward secure identity-based signature scheme
Jianghong Wei, Xuexian Hu, Kuiwu Yang
J. Inf. Secur. Appl.2
2023 VRBC: A Verifiable Redactable Blockchain With Efficient Query and Integrity Auditing
abstract
Driven by various legal obligations and service requirements, the redactable blockchain was introduced to balance the modifiability and immutability of blockchain technology. However, such a blockchain inevitably generates one or even more acceptable versions for the same block data, enabling malicious full nodes to deceive light/new nodes with old data, and even disrupt the consistency of the blockchain ledger. In this paper, we introduce the concept of verifiable redactable blockchain (VRBC) to provide efficient validity verification for on-chain data. To this end, we design a novel authentication data structure, called blockchain authentication tree (BAT), which employs a chameleon hash function and aggregatable vector commitment to bind continuously-appended blocks. Based on this, we propose an efficient VRBC scheme supporting integrity auditing, which not only allows the light nodes to query and validate on-chain data, but also enables new nodes to check the integrity of the blockchain ledger before synchronizing it, effectively avoiding resource waste and security risks caused by invalid queries and ledger synchronization. Furthermore, we introduce some optimized strategies to improve the performance of our scheme and extend it to transaction-level and permissionless VRBC. Finally, we demonstrate the practicability of our scheme through detailed security analysis and visual performance evaluation.
Guohua Tian, Jianghong Wei, Miroslaw Kutylowski, Willy Susilo, Xinyi Huang 0001, Xiaofeng Chen 0001
IEEE Trans. Computers2
2023 Communication-Efficient Verifiable Data Streaming Protocol in the Multi-User Setting
abstract
Verifiable data streaming (VDS) protocols enable end users with limited storage space to continuously stream data items to an untrusted cloud server, while preserving the capacity of verifying the integrity of those retrieved data items for downstream tasks. Although there has been plenty of research around the construction of VDS, we observe that they all focus on the scenario of single-user. When deploying these VDS protocols into more common applications that involve multiple users’ data (e.g., network data monitoring and stock trends analysis), the size of the proof used to prove the integrity of retrieved data items grows linearly with the number of involved users. This would bring tremendous communication overhead, especially for lightweight users. To this end, we initiate the study of VDS protocols that are suitable for multi-user (or cross-user) setting. Specifically, we first introduce a new primitive called aggregatable chameleon vector commitment (ACVC) that allows to aggregate multiple proofs from different commitments into a single proof. Then, based on ACVC, we present a communication-efficient VDS protocol for the multi-user setting. That is, when querying data items from multiple users, the size of corresponding proof is constant and independent of the number of involved users. Theoretical analysis indicates that the proposed VDS protocol outperforms previous VDS protocols in terms of communication overhead. We also implement the proposed ACVC, and conduct extensive experiments to demonstrate its practicability.
Xuan Jing, Meixia Miao, Jianghong Wei, Jianfeng Wang 0001
IEEE Trans. Cloud Comput.3
2023 Blockchain-Based Accountable Auditing With Multi-Ownership Transfer
abstract
Cloud auditing enables the integrity verification of cloud data without the necessity of data retrieval, which significantly promotes the storage service of cloud computing. Auditing with ownership transfer is a variation where both cloud data and the tags for integrity verification can be transferred. In some scenarios, like joint-stock enterprise acquisition and electronic medical records migration, we argue that auditing and transferring data belonging to multiple owners are significantly important. However, to the best of our knowledge, there exists no such protocol in multi-ownership scenarios in the literature. In this paper, we propose a blockchain-based accountable auditing protocol with multi-ownership transfer for the first time. One distinguishable property is the simultaneous achievement of verifiability, accountability and multi-ownership transferability, merely with very little extra cost. Specifically, we construct a novel tag structure based on homomorphic authenticators and compact multi-signatures, enabling integrity verification and multi-ownership transfer. Subsequently, we record the information concerning data generation and ownership transfer on immutable blockchains to make these procedures accountable. Furthermore, we present a comprehensive analysis and extensive experiments to demonstrate the security and efficiency of the proposed protocol.
Jun Shen 0006, Xiaofeng Chen 0001, Jianghong Wei, Fuchun Guo, Willy Susilo
IEEE Trans. Cloud Comput.3
2023 Securing Fine-Grained Data Sharing and Erasure in Outsourced Storage Systems
abstract
The wide use of internet-connected services makes massive personal data collected by service providers without the need of our consent. Although the archived data may enable them to provide better service experiences for users, it also presents serious risks to individual privacy, especially when active or unexpected data breaches have become commonplace. To mitigate this issue, several acts and regulations (e.g., the European Union general data protection regulation) have been issued and specified a lot of security requirements for personal data management. Among these various requirements, we mainly focus on the requirement of giving back the access control of personal data to data owners themselves and the right to be forgotten for data erasure. In this article, we provide a cryptographic solution of achieving these two requirements in the setting of outsourced storage. Specifically, we introduce a personal data management framework built upon a novel cryptographic primitive dubbed as forward-secure attribute-based puncturable encryption (FS-DABPE). This primitive simultaneously features of system-wide forward secrecy and practical key management as well as fine-grained access control of the encrypted personal data. Consequently, by locally puncturing, updating and erasing system-wide secret keys, it securely realizes fine-grained personal data sharing and data erasure without interactions. Furthermore, to instantiate the proposed framework, we present a concrete FS-DABPE construction, and prove its security under a well-studied complexity assumption. In addition, we provide a prototype implementation of the concrete construction, and present extensive experimental results that illustrate its feasibility and practicability.
Jianghong Wei, Xiaofeng Chen 0001, Jianfeng Wang 0001, Xinyi Huang 0001, Willy Susilo
IEEE Trans. Parallel Distributed Syst.1
2022 Batched Fully Homomorphic Encryption from TFHE
Jianghong Wei
ISC2
2022 Batched Fully Dynamic Multi-key FHE from FHEW-Like Cryptosystems
Jianghong Wei
ProvSec2
2022 VAEPass: A lightweight passwords guessing model based on variational auto-encoder
Kunyu Yang, Xuexian Hu, Qihui Zhang, Jianghong Wei, Wenfen Liu
Comput. Secur.4
2022 Verifiable data streaming protocol supporting update history queries
abstract
With the widespread development of intelligent systems, a considerable number of mobile devices are connected together, and continuously generate huge amounts of data. Although cloud storage provides perfect solution for effectively storing these massive data, how to ensure the integrity of the outsourced data becomes challenging. For this reason, the primitive of verifiable data streaming (VDS) protocol was introduced, and enables a data owner to continuously outsource streaming data to an untrusted cloud server, while capturing the integrity of the outsourced data. That is, when a data user retrieves some data item via its index from the server, he/she can publicly verify its integrity with the proof generated and returned by the server. Supporting data update is one of the major features of VDS, and allows the data owner to replace an old data item with a new one. Although many VDS protocols have been proposed to enhance the functionality and efficiency of the original VDS protocol, they all ignore the issue of preserving those updated data items. In fact, in various application scenarios of VDS, preserving and storing previously updated data items is actually necessary. For example, in the setting of DNA sequencing, there might be multiple versions of DNA fragments at the same location due to the genetic mutation. Obviously, for more precise treatment, all these DNA fragments need to be preserved. To this end, in this paper, we propose a VDS protocol that features of enabling the query of the update history of each data item. Specifically, we first put forward a new chameleon authentication tree with update history (UCAT), which consists of two CATs (the basic tree and the update history tree). In more detail, the basic tree is used to store the data item appended to the corresponding location for the first time, and the update history tree is utilized to preserve each updated version of the corresponding data item. Furthermore, based on UCAT, we propose a VDS protocol supporting update history queries, which allows a data user to retrieve any version of the data item. The theoretical analysis and performance evaluation indicate that our protocol outperforms previous ones in the field of functionality, and its computation/communication costs are acceptable. We also prove its security in the standard model.
Meixia Miao, Jiawei Li 0011, Yunling Wang, Jianghong Wei, Xinghua Li 0001
Int. J. Intell. Syst.4
2022 Verifiable data streaming with efficient update for intelligent automation systems
abstract
The wide deployment of Internet of Things (IoT) devices enables the controller to continuously collect massive volume data in automation systems, and makes it possible to make intelligent decisions based on machine learning techniques. In fact, data-driven intelligent automation systems have been common in the industrial community. Nevertheless, how to effectively store the collected stream data and ensure their integrity is still challenging. To this end, the notion of verifiable data streaming (VDS) protocol, which enables a client to outsource the stream data to an untrusted server in a verifiable manner, was introduced. However, we argue that existing VDS protocols based on the chameleon authentication tree (CAT) are inefficient in the data update, since the whole CAT must be updated accordingly to avoid acute exposure of chameleon hashing. Thus, they are infeasible for intelligent automation systems that need to frequently update data. In this article, we first introduce a new primitive called double-trapdoor chameleon hash tree (DCHT) based on the double-trapdoor chameleon hash families, where each leaf of DCHT is calculated and fixed by using a double-trapdoor chameleon hash family, making the entire DCHT always unchanged. Furthermore, we propose a novel VDS protocol based on the DCHT. Due to the distinctive properties of the underlying DCHT, the proposed VDS protocol has a constant update cost and more efficient than previous VDS protocols based on CAT. Besides, we prove that the proposed VDS protocol is secure in the standard model.
Meixia Miao, Jianghong Wei, Kuanching Li, Willy Susilo
Int. J. Intell. Syst.2
2022 Blockchain-Based Secure Deduplication and Shared Auditing in Decentralized Storage
abstract
Data deduplication and public auditing are significant for providing secure and efficient network storage services. However, the existing data deduplication schemes supporting auditing not only cannot effectively alleviate the threats of the single point of failure and duplicate-faking attack, but also have to bear the massive waste of computation and storage resources caused by metadata redundancy and repetitive audit tasks. In this article, we propose a blockchain-based secure deduplication and shared auditing scheme in decentralized storage. Specifically, our scheme utilizes a novel deduplication protocol based on the double-server storage model to achieve efficient space-saving while protecting data users from losing data under a single point of failure and duplicate-faking attack. Besides, it sharply reduces the computation and storage costs of metadata by introducing a lightweight authenticator generation algorithm and update protocol. On this basis, our scheme further adopts a blockchain-based two-way shared auditing mechanism to achieve decentralized public auditing without the third-party auditor, in which the audit authenticators and results of outsourced data are shared among its users to avoid repetitive audit tasks. Security and performance analysis indicates the practicability of our scheme.
Guohua Tian, Yunhan Hu, Jianghong Wei, Zheli Liu, Xinyi Huang 0001, Xiaofeng Chen 0001, Willy Susilo
IEEE Trans. Dependable Secur. Comput.3
2022 Enabling (End-to-End) Encrypted Cloud Emails With Practical Forward Secrecy
abstract
With the widespread use of cloud emails and frequent reports on large-scale email leakage events, a security property so-called forward secrecy becomes desirable and indispensable for both individuals and cloud email service providers to strengthen the security of cloud email systems. Specifically, forward secrecy can guarantee the confidentiality of those previously encrypted emails even if the user’s secret key gets exposed. However, due to the failure to meet the security and practicality requirements of email systems simultaneously, typical methods of achieving forward secrecy, such as Diffie-Hellman key exchange and forward-secure public-key encryption, have not been widely approved and adopted. In this article, to capture forward secrecy of encrypted cloud email systems without sacrificing the practicability, we introduce a new cryptographic primitive named forward-secure puncturable identity-based encryption (fs-PIBE), which enables an email user to perform fine-grained revocation of decryption capacity. In more detail, the user is allowed to preserve the decryption capacity of unreceived encrypted emails, while abolishing that of those received ones. Thus, it provides more practical forward secrecy than typical manners, in which the decryption capacity of received and unreceived encrypted emails is revoked simultaneously. Based on such a primitive, we build a framework of encrypted cloud email systems, and instantiate it with a concrete fs-PIBE construction that has constant size of ciphertext and provable security in the standard model. Furthermore, to improve the security and efficiency of the presented framework, we extend the proposed fs-PIBE scheme to support end-to-end encryption and outsourced decryption, respectively. In addition, as a proof-of-concept of the proposed fs-PIBE scheme, we implement it and produce various experiments to demonstrate its practicability and correctness.
Jianghong Wei, Xiaofeng Chen 0001, Jianfeng Wang 0001, Xuexian Hu, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.1
2021 Optimal Verifiable Data Streaming Protocol with Data Auditing
Jianghong Wei, Guohua Tian, Jun Shen 0006, Xiaofeng Chen 0001, Willy Susilo
ESORICS (2)1
2021 Studies of Keyboard Patterns in Passwords: Recognition, Characteristics and Strength Evolution
Kunyu Yang, Xuexian Hu, Qihui Zhang, Jianghong Wei, Wenfen Liu
ICICS (1)4
2021 RS-HABE: Revocable-Storage and Hierarchical Attribute-Based Access Scheme for Secure Sharing of e-Health Records in Public Cloud
abstract
Personal e-health records (EHR) enable medical workers (e.g., doctors and nurses) to conveniently and quickly access each patient's medical history through the public cloud, which greatly facilitates patients' visits and makes telemedicine possible. Additionally, since EHR involve patients' personal privacy information, EHR holders would hesitate to directly outsource their data to cloud servers. A natural and favorite manner of conquering this issue is to encrypt these outsourced EHR such that only authorized medical workers can access them. Specifically, the ciphertext-policy attribute-based encryption (CP-ABE) supports fine-grained access over encrypted data and is considered to be a perfect solution of securely sharing EHR in the public cloud. In this paper, to strengthen the system security and meet the requirement of specific applications, we add functionalities of user revocation, secret key delegation and ciphertext update to the original ABE, and propose a revocable-storage hierarchical attribute-based encryption (RS-HABE) scheme, as the core building of establishing a framework for secure sharing of EHR in public cloud. The proposed RS-HABE scheme features of forward security (a revoked user can no longer access previously encrypted data) and backward security (a revoked user also cannot access subsequently encrypted data) simultaneously, and is proved to be selectively secure under a complexity assumption in bilinear groups, without random oracles. The theoretical analysis indicates that the proposed scheme surpasses existing similar works in terms of functionality and security, at the acceptable cost of computation overhead. Moreover, we implement the proposed scheme and present experiments to demonstrate its practicability.
Jianghong Wei, Xiaofeng Chen 0001, Xinyi Huang 0001, Xuexian Hu, Willy Susilo
IEEE Trans. Dependable Secur. Comput.1
2021 Communication-Efficient and Fine-Grained Forward-Secure Asynchronous Messaging
abstract
In recent years, motivated by the revelation of long-term and widespread surveillance of personal communications, extensive efforts have been putting intostore-and-forwardasynchronous messaging systems (e.g., email and SMS) for providing critical security guarantees. Of particular interest among them is forward security, which makes past messages remain secure in the event that the secret key gets exposed. Traditional forward-secure public key encryption can provide forward security for asynchronous scenarios, but it is not flexible enough for instant messaging systems. This is mainly because that, after updating his/her secret key, the user totally loses the decryption capacity of ciphertexts that have not been received. In this paper, to achieve practical forward-security of asynchronous messaging systems, we investigate the construction of a new primitive named forward-secure puncturable encryption (FSPE) that captures fine-grained forward security. Namely, the user can maintain the decryption capacity of those encrypted messages that have not been received yet. Meanwhile, even if the secret key is disclosed, those received messages can still remain secure. Specifically, we propose a communication-efficient FSPE scheme for achieving fine-grained forward-secure asynchronous messaging. Moreover, to improve the efficiency of asynchronous messaging built upon FSPE, we extend it to support outsourced decryption. We also implement the proposed scheme and evaluate a proof-of-concept of main algorithms, so as to increase confidence on its correctness and practicability.
Jianghong Wei, Xiaofeng Chen 0001, Jianfeng Ma 0001, Xuexian Hu, Kui Ren 0001
IEEE/ACM Trans. Netw.1
2020 Privacy-preserving constrained spectral clustering algorithm for large-scale data sets
abstract
With the increasing concern on the preservation of personal privacy, privacy‐preserving data mining has become a hot topic in recent years. Spectral clustering is one of the most widely used clustering algorithm for exploratory data analysis and usually has to deal with sensitive data sets. How to conduct privacy‐preserving spectral clustering is an urgent problem to be solved. In this study, the authors focus on introducing the notion of differential privacy, which is considered as the de facto standard of privacy‐preserving data analysis, into spectral clustering. Specifically, by combining the well‐studied constrained spectral clustering with the Wishart mechanism in a novel way, the authors propose a differentially private constrained spectral clustering (DP‐CSC) algorithm. The DP‐CSC algorithm is proved to capture asymptotic property and achieves ‐differential privacy. To illustrate the effectiveness and efficiency of DP‐CSC, the authors conduct experiments on five real‐word data sets. The results indicate that the DP‐CSC algorithm can provide acceptable clustering accuracy with short running time while preserving individual privacy.
Ji Li 0004, Jianghong Wei, Mao Ye 0004, Wenfen Liu, Xuexian Hu
IET Inf. Secur.2
2019 Forward-Secure Puncturable Identity-Based Encryption for Securing Cloud Emails
Jianghong Wei, Xiaofeng Chen 0001, Jianfeng Wang 0001, Xuexian Hu, Jianfeng Ma 0001
ESORICS (2)1
2019 Forward and backward secure fuzzy encryption for data sharing in cloud computing
Jianghong Wei, Xuexian Hu, Wenfen Liu, Qihui Zhang
Soft Comput.1
2018 Secure Data Sharing in Cloud Computing Using Revocable-Storage Identity-Based Encryption
abstract
Cloud computing provides a flexible and convenient way for data sharing, which brings various benefits for both the society and individuals. But there exists a natural resistance for users to directly outsource the shared data to the cloud server since the data often contain valuable information. Thus, it is necessary to place cryptographically enhanced access control on the shared data. Identity-based encryption is a promising cryptographical primitive to build a practical data sharing system. However, access control is not static. That is, when some user's authorization is expired, there should be a mechanism that can remove him/her from the system. Consequently, the revoked user cannot access both the previously and subsequently shared data. To this end, we propose a notion called revocable-storage identity-based encryption (RS-IBE), which can provide the forward/backward security of ciphertext by introducing the functionalities of user revocation and ciphertext update simultaneously. Furthermore, we present a concrete construction of RS-IBE, and prove its security in the defined security model. The performance comparisons indicate that the proposed RS-IBE scheme has advantages in terms of functionality and efficiency, and thus is feasible for a practical and cost-effective datasharing system. Finally, we provide implementation results of the proposed scheme to demonstrate its practicability.
Jianghong Wei, Wenfen Liu, Xuexian Hu
IEEE Trans. Cloud Comput.1
2017 Compressed constrained spectral clustering framework for large-scale data sets
Wenfen Liu, Mao Ye 0004, Jianghong Wei, Xuexian Hu
Knowl. Based Syst.3
2017 PMDP: A Framework for Preserving Multiparty Data Privacy in Cloud Computing
abstract
The amount of Internet data is significantly increasing due to the development of network technology, inducing the appearance of big data. Experiments have shown that deep mining and analysis on large datasets would introduce great benefits. Although cloud computing supports data analysis in an outsourced and cost-effective way, it brings serious privacy issues when sending the original data to cloud servers. Meanwhile, the returned analysis result suffers from malicious inference attacks and also discloses user privacy. In this paper, to conquer the above privacy issues, we propose a general framework for Preserving Multiparty Data Privacy (PMDP for short) in cloud computing. The PMDP framework can protect numeric data computing and publishing with the assistance of untrusted cloud servers and achieve delegation of storage simultaneously. Our framework is built upon several cryptography primitives (e.g., secure multiparty computation) and differential privacy mechanism, which guarantees its security against semihonest participants without collusion. We further instantiate PMDP with specific algorithms and demonstrate its security, efficiency, and advantages by presenting security analysis and performance discussion. Moreover, we propose a security enhanced framework sPMDP to resist malicious inside participants and outside adversaries. We illustrate that both PMDP and sPMDP are reliable and scale well and thus are desirable for practical applications.
Ji Li 0004, Jianghong Wei, Wenfen Liu, Xuexian Hu
Secur. Commun. Networks2
2016 Practical Attribute-based Signature: Traceability and Revocability
abstract
As a new variant of digital signature, attribute-based signature (ABS) is appealing for many scenarios, where both authentication and anonymity are desired. However, in such a paradigm, a user's secret key is not linkable to an authenticated identity, and the same set of attributes might be shared among multiple users. Consequently, a malicious user would leak his secret key for some purposes without the risk of being identified among these equal users. On the other hand, for a cryptosystem with a large number of users, there should be an efficient revocation mechanism to further inform that a user's credential is abolished. We note that none of the existing ABS schemes simultaneously supports traceability and revocability, which are crucial towards the practicability of ABS. In this work, we first give a formal security model for traceable and revocable ABS. Next, we provide a concrete construction that admits flexible threshold signing predicates. Finally, we prove the anonymity and traceability of the proposed scheme in the standard model. To the best of our knowledge, our construction is the first ABS scheme that enjoys the functionalities of traceability and revocability simultaneously, and thus is more feasible for practical applications.
Jianghong Wei, Xinyi Huang 0001, Wenfen Liu, Xuexian Hu
Comput. J.1
2016 Security pitfalls of "ePASS: An expressive attribute-based signature scheme"
Jianghong Wei, Wenfen Liu, Xuexian Hu
J. Inf. Secur. Appl.1
2015 Revocable Threshold Attribute-Based Signature against Signing Key Exposure
Jianghong Wei, Xinyi Huang 0001, Xuexian Hu, Wenfen Liu
ISPEC1
2015 Forward-Secure Threshold Attribute-Based Signature Scheme
abstract
In an attribute-based signature (ABS) scheme, each signer is issued a private key according to his/her attributes, and can sign a message with respect to some signing predicate satisfied by his/her attributes. A recipient of the signature can verify that the signature is indeed endorsed by someone that possesses some attributes satisfying the signing predicate, without learning any information about the attributes that are utilized to produce the signature. Since the introduction of ABS, it has been well investigated in recent years. However, there are few works proposed to solve the problem of key exposure in the setting of ABS. In fact, this problem becomes more acute with the increasing tendency that unprotected and mobile devices are more and more popular. To solve the above problem, this work proposes a forward-secure ABS scheme supporting threshold predicates. The proposed scheme is proved secure under the η-Diffie–Hellman Exponent assumption without random oracles, and is also efficient in terms of communication and computation. Furthermore, it is implemented to show its practical applicability.
Jianghong Wei, Wenfen Liu, Xuexian Hu
Comput. J.1
2014 Traceable attribute-based signcryption
abstract
ABSTRACT Signcryption can provide confidentiality and authenticity for many cryptographic applications. In this study, we propose a new efficient attribute‐based signcryption scheme. This scheme achieves confidentiality against chosen ciphertext attacks and unforgeability against chosen messages attacks in the selective attribute model. In addition, our scheme enjoys traceability by use of non‐interactive witness indistinguishable proofs; that is, the authority can break the anonymity of users when necessary. Compared with previous works, our scheme has advantages in terms of functionality and efficiency simultaneously. Copyright © 2013 John Wiley & Sons, Ltd.
Jianghong Wei, Xuexian Hu, Wenfen Liu
Secur. Commun. Networks1