VLDB 2026 Research / reviewers in the wild / expert
Anjia Yang
dblp:119/6400
· DBLP profile ↗
73ranked-venue papers
9as first author
54since 2021 · last 2026
0000-0002-7958-6571ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 31 · 3 first-author · 22 since 2021Computer networks · 21 · 2 first-author · 19 since 2021Systems, architecture and hardware · 6 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Forward-Secure Identity-Based Signcryption With Equality Test for Social Recommendation on Smart IoT DevicesabstractWith the deep integration of smart IoT devices with social networks, platforms use user-interest similarity for social recommendations to connect like-minded people. Identity-based encryption with equality test (IBEET) enables equivalence testing of interest ciphertexts encrypted under different public keys and avoids costly certificate management. It is beneficial for privacy-preserving social recommendations on smart IoT devices. Nevertheless, existing IBEET schemes suffer from two critical flaws: the lack of forward security allows historical trapdoor holders to test newly generated ciphertexts, and the absence of ciphertext origin authentication impedes the legality verification of the ciphertext source. In this paper, taking into account IoT-device features like limited resources, we introduce a forward secure identity-based signcryption scheme with equality test enabling public verification (FS-IBSCET-PV) for social recommendation. It enables the platforms to leverage users’ trapdoors to perform equality tests on interest ciphertexts, accurately matching users who share common interests. Meanwhile, users can submit time-limited authorized trapdoors when needing recommendation services, thus effectively reducing the risk of trapdoor misuse. Furthermore, upon receiving recommendation results, users can publicly verify their origin without extra decryption to ensure the authenticity of the recommendations, consequently mitigating the hardware overhead. Security analysis and simulation experiments show that FS-IBSCET-PV has enhanced functionality and better testing efficiency than related schemes. It provides a secure and practical solution for privacy-preserving social recommendations on resource-limited smart IoT devices. Wenjie Yang 0001, Qunhao Ou, Futai Zhang, Anjia Yang |
IEEE Internet Things J. | 5 |
| 2026 | A practical and privacy-preserving framework for real-world large language model services
Xueping Liao, Wei Liu 0240, Anjia Yang |
Knowl. Based Syst. | 4 |
| 2026 | Two-Server Offline/Online Private Information Retrieval With Small Client StorageabstractIn this paper, we propose PIRS, a two-server offline/online private information retrieval scheme with small client storage. In PIRS, a client first engages in an offline phase to preprocess a database replicated on two servers to generate query-independent hints. Utilizing the pre-computed hints, the client then securely retrieves any record from the database without exposing its index during an online phase, with the server-side computational complexity being sublinear for high efficiency. Compared to state-of-the-art schemes, PIRS distinguishes itself by enabling the client to outsource the hints to the servers instead of storing them, dramatically reducing the local storage requirement from GB/MB to MB/KB, given that the size of the hints is directly proportional to the database volume. Specifically, the client employs secret sharing to achieve secure hint outsourcing and only fetches the relevant hint for each online PIR query. In such an outsourcing environment, we introduce a new technique named oblivious switching to obfuscate repeated hint/record accesses, and carefully tailor online PIR queries to guarantee sublinear computational complexity. Furthermore, we propose a secure and efficient method that delegates the task of locating appropriate hints for particular PIR queries to the servers, thus avoiding costly computations or extra data storage on the client side. Finally, we conduct a comprehensive security analysis to demonstrate PIRS's security, and develop a proof-of-concept prototype to show the practicality of PIRS in terms of computational, communication, and storage overheads. Cheng Huang 0001, Anjia Yang, Rongxing Lu, Xuemin Shen |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | Publicly Auditable Federated Learning With Privacy and Byzantine Robustness
Huang Zeng, Anjia Yang, Jian Weng 0001, Min-Rong Chen, Fengjun Xiao, Zilin Liu, Yi Liu 0053 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | Dual-Server Public-Key Authenticated Searchable Encryption With Constant Trapdoor Against Inside Keyword Guessing AttacksabstractPublic key authenticated encryption with keyword search (PAEKS) is an advanced asymmetric searchable encryption technique that provides strong resistance against inside keyword guessing attacks (KGAs). However, most PAEKS schemes are limited to one-to-one search, resulting in a linear increase in the number of trapdoors as the number of senders grows. Some solutions have been introduced, but they are still deficient in security or privacy. In this paper, we propose a novel dual-server public key authenticated searchable encryption scheme with constant trapdoor. The proposed scheme achieves robust security against inside KGAs even if a malicious server is allowed to collude with certain data senders. Meanwhile, in contrast to existing schemes, it prevents the leakage of keyword equivalence among unretrieved ciphertexts. Moreover, the data receiver in our system only needs to create one trapdoor per keyword to search for their ciphertexts produced by different data senders, which is not achievable in most prior works. The experimental results demonstrate that our proposed construction maintains comparable performance to existing solutions, especially in multi-sender scenarios. Wenjie Yang 0001, Shujie Lin, Futai Zhang, Anjia Yang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2026 | Forward Secure Identity-Based Encryption With Equality Test for Privacy-Preserving Friendship Recommendation on Social PlatformsabstractOn social platforms, the friendship recommendation models deployed suggest potential friends based on the similarities among users. As privacy concerns rise, more users choose to encrypt their attributes before requesting recommendation services. Identity-based encryption with equality test (IBEET) supports encrypted data comparison under different users' identities (public keys) and avoids the need for costly certificate management. This makes it highly suitable for implementing privacy-preserving friendship recommendation on social platforms. Nevertheless, most existing IBEET schemes lack the ability to control the validity period of trapdoors used for testing. Historical trapdoors may be maliciously utilized to test encrypted data generated in the future. To address this issue, we propose a forward secure identity-based encryption with equality test for friendship recommendation. Our construction enables an authorized tester to provide privacy-preserving recommendations based on encrypted data among different users. Furthermore, to control the tester's testing capability, time slots are encoded by the 0/1-encoding mechanism and embedded into both ciphertexts and trapdoors. This ensures that only the authorized tester possessing valid trapdoors can perform tests on specific ciphertexts. Under the bilinear Diffie-Hellman assumption in the random oracle model, we prove that the proposed IBEET achieves OW-ID-CCA security when the attacker has access to the trapdoor and IND-ID-CCA security when the attacker does not. Experiment simulation demonstrates that our construction outperforms existing ones in overall performance, particularly in testing that requires frequent execution for recommendation. Wenjie Yang 0001, Futai Zhang, Anjia Yang |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | PP-MTAD: Privacy-Preserving and Efficient Multivariate Time Series Anomaly Detection
Minhua Su, Jia-Nan Liu, Jia-Si Weng 0001, Anjia Yang, Xueqiao Liu, Jian Weng 0001 |
Inscrypt (2) | 5 |
| 2025 | Efficient Privacy-Preserving Outsourced K-Means Clustering via Secure Two-Party ComputationabstractK-means clustering is a foundational data analysis technique widely employed in many critical domains. However, the integration of data from different databases introduces privacy leakage risks during the clustering process. Moreover, computational and communication efficiency remain critical challenges in privacy-preserving implementations of clustering algorithms. To address these issues, this paper proposes a novel outsourced privacy-preserving k-means clustering framework based on secure two-party computation (2PC) protocols. The system consists of multiple users and two outsourced servers. Each user securely outsources their data to the servers, and the servers perform k-means clustering without leaking data privacy. The framework includes specialized sub-protocols for secure minimum value retrieval and secure division, effectively balancing privacy protection with computational efficiency. Comprehensive comparative experiments demonstrate communication overhead and computational overhead of the proposed scheme are reduced by at least 56% and 16% compared to state-of-the-art 2PC-based privacy-preserving clustering schemes while maintaining equivalent security level and high clustering accuracy. Zuxiang Mo, Anjia Yang |
GLOBECOM | 4 |
| 2025 | Zero-Knowledge Protocols with PVC Security: Striking the Balance Between Security and Efficiency
Yi Liu 0053, Yipeng Song, Anjia Yang, Junzuo Lai |
ICICS (1) | 3 |
| 2025 | Highly Efficient Actively Secure Two-Party Computation with One-Bit Advantage BoundabstractSecure two-party computation (2PC) enables two parties to jointly evaluate a function while maintaining input privacy. Despite recent significant progress, a notable efficiency gap remains between actively secure and passively secure protocols. In S&P'12, Huang, Katz, and Evans formalized the notion of active security with one-bit leakage, providing a promising approach to bridging this gap. Protocols derived from this notion have become foundational in designing highly efficient actively secure 2PC protocols. However, a critical challenge identified by Huang, Katz, and Evans remains unexplored: these protocols face significant weaknesses in ensuring fairness for honest parties when employed in standalone settings rather than as components within larger protocols. While the authors proposed two potential solutions to mitigate this issue, both approaches are prohibitively expensive and lack formalization of security guarantees. In this paper, we first formally define an enhanced notion called active security with one-bit-advantage bound, in which the adversaries' advantages are strictly bounded to at most one bit beyond what honest parties obtain. This bound is enforced through a progressive revelation mechanism, where the evaluation result is disclosed incrementally bit by bit. In addition, we propose a novel approach leveraging label structures within garbled circuits to design a highly efficient constant-round 2PC protocol that achieves active security with one-bit advantage bound. Our protocol demonstrates runtime performance nearly identical to that of passively secure garbled-circuit counterparts in duplex networks (e.g., 1.033 × for the SHA256 circuit in LAN), with low overhead for output progressive revelation (only 80 communicated bytes per bit release). With its strengthened security guarantees and minimal overhead, our protocol is highly suitable for practical 2PC applications. Yi Liu 0053, Junzuo Lai, Peng Yang 0016, Qi Wang 0012, Anjia Yang, Siu-Ming Yiu, Jian Weng 0001 |
SP | 5 |
| 2025 | Privacy-preserving cross-domain point-of-interests recommendation based on friendship in LBSs
Lulu Han, Weiqi Luo 0002, Anjia Yang, Yudan Cheng, Junzuo Lai, Jiaquan Shen |
Comput. Networks | 3 |
| 2025 | An Efficient Revocable Identity-Based Aggregate Signature Scheme With Designated Verifiers in Healthcare Wireless Sensor NetworksabstractIn healthcare wireless sensor networks (HWSNs), a process of medical diagnosis heavily relies on the medical data collected by lightweight sensors, as any malicious modification may result in severe consequences. Furthermore, large-scale data transmission in HWSNs would impose significant communication overhead. Therefore, efficiently guaranteeing the availability of these data while reducing the communication cost is crucial in HWSNs. Aggregate signatures suit the resource-limited environments, but existing ones still face several challenges, including vulnerability to coalition attacks, privacy preservation, and revocation of misbehaving signers. In this paper, we propose an efficient revocable identity-based aggregate signature scheme with designated verifiers (R-IBAS-DV) for HWSNs. In our proposed scheme, numerous individual signatures on the collected medical data can be aggregated into a succinct aggregate signature and their validity is equivalent to that of the aggregate signature. The equivalence property of our proposed scheme is sound even under coalition attacks and exclusively verifiable by designated healthcare professionals. Meanwhile, our proposed scheme is rooted in Hess’s practical identity-based signature, thereby circumventing costly certificate management. Additionally, it incorporates RSA accumulators to facilitate the efficient revocation of malicious signers. Security analysis and performance comparisons demonstrate that our R-IBAS-DV scheme offers enhanced security and lower computation overhead, making it particularly suitable for resource-constrained HWSNs. Wenjie Yang 0001, Junzhe Fan, Futai Zhang, Anjia Yang, Zhiquan Liu 0001 |
IEEE Internet Things J. | 4 |
| 2025 | LieCConv: An Image Classification Algorithm Based on Lie Group Convolutional Neural NetworkabstractIn Lie group convolutional neural networks (LG-CNNs), the calculation and storage of Lie group distances have quadratic space complexity. In order to improve the memory utilization efficiency of LG-CNNs, a novel Lie group convolutional neural network called LieCConv is proposed. LieCConv utilizes an innovative sampling algorithm and a linear space complexity calculation and storage approach for Lie group distances, substantially enhancing network memory efficiency. Firstly, LieCConv employs a novel sampling algorithm called array-neighborhood sampling (ANS) in the downsampling stage. ANS only requires neighborhood information to obtain an excellent sample set with a low threshold of use. The sample set generated by ANS reflects the distribution of the original set. Then, LieCConv adopts a batch calculation and storage scheme for Lie group distances, which effectively declines the space complexity of calculating and storing Lie group distances from quadratic complexity to linear complexity, reducing the memory consumption during training. Finally, the contrast between ANS and farthest point sampling was presented, demonstrating that ANS better captures the distribution characteristics of the original dataset. The memory usage of LieCConv and LieConv was compared, revealing that LieCConv reduces the memory usage for calculating and storing Lie group distances to less than 500 MB. And the performance of LieCConv was evaluated on RotMNIST, RotFashionMNIST and TT100K, validating that LieCConv is universal and effective. Xizhao Luo, Chongben Tao, Anjia Yang |
Neural Process. Lett. | 5 |
| 2025 | The Lives of Others: Snooping on Smartphone Usage Behaviors via Attention-Enabled Multi-Channel Spatiotemporal Information FusionabstractUsing side-effect sensing information to monitor the behavior of smartphone usage raises privacy leakage concerns. However, existing research typically utilizes only a single sensing channel or performs a simple aggregation of multi-channel data to infer user behavior, without sufficiently leveraging rich spatiotemporal information embedded in the diverse sensing channels. Such a narrow focus of existing works fails to exhibit the real risk of user privacy leakage. To bridge this research gap, we propose HiddenSpy, a comprehensive study assessing the smartphone usage snooping associated with multiple sensing channels, such as accelerometers and magnetometers. We start by examining the relationship between the data gathered from each channel and daily usage behaviors, highlighting information volume differences across channels. Building on this analysis, we propose a multi-layer attention mechanism that dynamically adjusts the importance of spatiotemporal information from different channels and time frames, facilitating the efficient use of multi-channel data for behavior inference. Importantly, our work marks a pivotal shift from addressing information leakage in single channels to managing information exposure throughout the smartphone sensing system, laying the foundation for more comprehensive protective measures. To validate our approach, we collect data from forty widely-used applications and evaluate the corresponding usage behavior snooping performance. The results show that HiddenSpy improves accuracy in three common snooping tasks, while its defense mechanism reduces accuracy to a low level, effectively preventing information leakage. Hangcheng Cao, Guowen Xu, Shengmin Xu, Xinyuan Qian 0002, Anjia Yang, Jianting Ning |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | Efficient and Privacy-Preserving Ride Matching Over Road Networks Against Malicious ORH ServerabstractOnline ride-hailing (ORH) services have become indispensable for our travel needs, offering the convenience of easily locating the nearest driver for riders through ride matching algorithms. However, existing ORH systems, such as Lyft and Didi, require users (both riders and drivers) to disclose their real-time location information during the matching process, thus giving rise to serious privacy concerns. Despite the proposal of various privacy-preserving ride-matching schemes, they remain insufficient in addressing potential malicious behaviors from the ORH server, such as colluding with designated drivers and deviation from computation protocols to interfere with the matching process. These behaviors lead to non-optimal matching results for riders. To address these issues, we present EMPRide, an efficient and privacy-preserving ride-matching scheme resistant to malicious ORH server. In EMPRide, we design an efficient and accurate computation of distances between users protocol, which integrates road network embedding and secure two-party computation. Additionally, we design a verification protocol that allows riders to verify the correctness of computed distances and matching results. Crucially, the communication overhead for riders in EMPRide remains constant, irrelevant to the number of available drivers. Our evaluation using real-world datasets demonstrates that EMPRide significantly outperforms existing solutions. Specifically, under identical conditions, in EMPRide, the computation speed on the ORH server is$19.22\times $faster and the communication cost is$8.08\times $less than state-of-the-art approaches. Moreover, riders experience a speed improvement of 4.84 orders of magnitude with$1.30\times $less communication, while drivers benefit from a 4.79 orders of magnitude speed increase with$1.45\times $less communication. Mingtian Zhang, Anjia Yang, Jian Weng 0001, Min-Rong Chen, Huang Zeng, Yi Liu 0053, Zhihua Xia |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Enabling Privacy-Preserving and Publicly Auditable Federated LearningabstractFederated learning (FL) has attracted widespread attention because it supports the joint training of models by multiple participants without moving private dataset. However, there are still many security issues in FL that deserve discussion. In this paper, we consider three major issues: 1) how to ensure that the training process can be publicly audited by any third party; 2) how to avoid the influence of malicious participants on training; 3) how to ensure that private gradients and models are not leaked to third parties. Many solutions have been proposed to address these issues, while solving the above three problems simultaneously is seldom considered. In this paper, we propose a publicly auditable and privacy-preserving federated learning scheme that is resistant to malicious participants uploading gradients with wrong directions and enables anyone to audit and verify the correctness of the training process. In particular, we design a robust aggregation algorithm capable of detecting gradients with wrong directions from malicious participants. Then, we design a random vector generation algorithm and combine it with zero sharing and blockchain technologies to make the joint training process publicly auditable, meaning anyone can verify the correctness of the training. Finally, we conduct a series of experiments, and the experimental results show that the model generated by the protocol is comparable in accuracy to the original FL approach while keeping security advantages. Huang Zeng, Anjia Yang, Jian Weng 0001, Min-Rong Chen, Fengjun Xiao, Yi Liu 0053, Ye Yao 0003 |
ICC | 2 |
| 2024 | A Logarithmic-Size Certificateless Traceable Ring Signature Based on SM2-DualRing and its Application in Data SharingabstractAs a special ring signature, a traceable ring signature (TRS) provides limited anonymity and traceability, and has been shown useful in many practical applications such as anonymous voting. On the other hand, DualRing, a novel generic construction of ring signature introduced in CRYPTO 2021, can reduce computation and communication costs. Recently, building upon DualRing, Ye et al. proposed a lattice-based TRS that introduced TripleRing construction to ensure traceability. However, the proposed TRS encounters issues with certificate management and linear signature size. To address these concerns, we introduce a certificateless TRS with logarithmic size based on SM2-DualRing (SDR-CTRS) in the discrete logarithm setting. The SDR-CTRS leverages the TripleRing construction and non-interactive sum argument. Security analysis indicates that our SDR-CTRS satisfies tag-linkability, anonymity, and exculpability under the discrete logarithm hypothesis. Theoretical analysis shows that the SDR-CTRS features logarithmic communication cost and acceptable computation cost. Additionally, the SDR-CTRS does not require a fully trusted party during the tracking phase. Finally, to illustrate the practicality of the ring signature, we present a blockchain-based data sharing system with conditional privacy protection based on it. Shumei Liu, Anjia Yang, Junhua Zheng |
MSN | 2 |
| 2024 | PACDAM: Privacy-Preserving and Adaptive Cross-Chain Digital Asset MarketplaceabstractAs the deployment of blockchains expands across various industries, the demand for exchanging digital assets among blockchain users has risen. Most of existing solutions either solely support asset exchanges among users on the same blockchain, or have limitations by only enabling cross-chain asset exchanges among a few specific blockchains or requiring an intermediary to involve in the cross-chain transaction. To address this problem, in this paper, we propose the concept of cross-chain digital asset marketplace which enables users across different blockchains to exchange their assets securely and efficiently. We then propose a privacy-preserving and adaptive cross-chain digital asset marketplace scheme, denoted as PACDAM. It adaptively matches purchasers’ requests and ensures atomic and privacy-preserving cross-chain transactions. Built on adaptor signatures and randomizable time-lock puzzles, the cross-chain transaction procedure only relies on the underlying blockchain for signature verification, making PACDAM compatible with various blockchains. Furthermore, this protocol eliminates the necessity for third-party involvement (e.g., brokers) in cross-chain transactions, leading to a substantial enhancement in system efficiency and scalability. We also give a comprehensive security analysis of PACDAM, demonstrating its robustness against common attacks and preserving the privacy of transaction participants. Finally, we conduct a series of experiments, and the results validate the effectiveness of our proposed scheme. Jia-Nan Liu, Anjia Yang, Jian Weng 0001, Min-Rong Chen, Zilin Liu, Ming Li 0049 |
IEEE Internet Things J. | 3 |
| 2024 | Byzantine-Robust and Privacy-Preserving Federated Learning With Irregular ParticipantsabstractFederated learning, as a form of distributed learning, aims to protect the local data while utilizing distributed data to train a global model. However, federated learning still faces challenges related to privacy leakage in Internet of Things (IoT). Researches indicate that the server can infer private information from the local gradients. Additionally, malicious participants may upload poisoning local models, which contaminate the global model and cause a decline in accuracy. Furthermore, irregular participants with low-quality data in the real world can also impact the performance of the global model. Simultaneously addressing these three issues poses a significant challenge. This is because privacy protection strategies in FL are designed to prevent access to the local gradients to avoid information leakage. However, strategies with Byzantine robustness and defense against irregular participants typically require access to the local gradients to calculate the reliability of each participant. Therefore, we use secret sharing as the underlying technology to propose a 3PC privacy-preserving federated learning framework BPFL that can resist Byzantine attacks and irregular participants. Compared with the previous schemes, our scheme can not only protect data privacy but also minimize the negative impact of malicious or irregular participants on the global model. We implemented BPFL and compared it with Mkrum and PPFL. Experimental results indicate that our approach maintains high performance when facing malicious attackers and irregular participants. Wuzheng Tan, Yijian Zhong, Yulin Kang, Anjia Yang, Jian Weng 0001 |
IEEE Internet Things J. | 5 |
| 2024 | An Identity-Based Strong Designated Verifier Dual-Signature Scheme With Constrained DelegatabilityabstractVerifying the correctness of outsourcing computation is both cumbersome and expensive, and it also requires third-party verification if auditing or arbitrating is involved. Due to its complexities, users are likely to re-outsource the verification workload to trusted third-party vendors. Multiple outsourcing tasks increase the expense of communications and expose more vulnerabilities. To address this problem, we propose an identity-based strong designated verifier dual signature scheme with constrained-delegatability. The particular innovation lies in two aspects. Firstly, in cases where there are multiple parties involved, users can autonomously designate verifiers. Second, we first present the concept of constrained-delegatability, where a signature cannot be delegated to any other than the cloud service provider. In this scheme, a user can specify a trusted verifier for the dual signature co-signed by both him and the service provider on the outsourcing result. The provider cannot designate anyone else to check the signature. The proposed scheme is provably secure based on elliptic curve bilinear pairing and the hardness assumption of computational diffie-hellman and bilinear diffie-hellman problems. Moreover, our scheme simplifies the outsourcing process and reduces the total computational costs and communication time compared to previously reported ones. Zhengyan Ding, Xizhao Luo, Anjia Yang |
IEEE Internet Things J. | 6 |
| 2024 | Enabling Secure and Flexible Streaming Media With Blockchain IncentiveabstractAs a typical application of mobile crowdsourcing, streaming media has been attracting increasing attention since recent years. However, traditional streaming media platforms, such as Netflix, Disney+, and Hulu, may suffer some problems like inflexible billing modes, lacking sustainability in the incentive mechanisms, and management censorship. These problems may lead to a decrease in user participation rate, which will directly affect the interests of streaming media platforms. To address these issues, we propose a secure, efficient and flexible streaming media platform framework based on blockchain and well-designed smart contracts. In particular, we design a new billing model based on pay-as-you-go strategy and a new incentive mechanism with probabilistic payment technique. To improve the fairness of our incentive model, we introduce a secondary fee refund protocol where a user’s second consecutive payment could be refunded, which in turn can attract more users to participate in the platform. Since blockchain has the natural properties of decentralization and transparency, the proposed framework is resistant to censorship and enables the transactions to be publicly auditable. Based on the proposed framework, we have implemented two streaming media platform schemes. Scheme I relies primarily on smart contracts to implement the framework’s functionality, while Scheme II moves the main flow of framework to off-chain channels. As the execution of smart contracts requires transaction fees, Scheme I is more expensive but can provide much more security and accountability as well. Scheme II can execute the transaction process much faster and with only a small transaction fee. Finally, we deployed these two schemes on Ropsten and conduct a series of experiments. The results show the effectiveness and efficiency of the proposed schemes. Tao Li 0067, Anjia Yang, Jian Weng 0001, Min-Rong Chen, Xizhao Luo, Changkun Jiang |
IEEE Internet Things J. | 2 |
| 2024 | Multi-Motion Segmentation via Co-Attention-Induced Heterogeneous Model FittingabstractMotion segmentation is an essential task in artificial intelligence and computer vision. However, scene motion in real-world intelligent systems usually integrates multiple types of models, so specifying only one type of basic model may lead to the failure of scene-motion segmentation tasks. In this paper, we propose a novel and efficient heterogeneous model-fitting-based motion segmentation method (HMFMS) to accurately segment moving objects. HMFMS includes a new co-attention-induced heterogeneous model construction algorithm (HMC), an adaptive heterogeneous model refinement algorithm (HMR), and a heterogeneous model segmentation algorithm (HMS). First, we propose HMC to generate high-quality accumulated correlation matrices, by evaluating the quality of heterogeneous model hypotheses, based on the density estimation technique. Next, we propose HMR to construct sparse affinity matrices from the accumulated correlation matrices by applying information theory, effectively suppressing the values of correlations between different objects. Finally, we fuse the sparse affinity matrices and perform motion segmentation by using HMS, to obtain more accurate segmentation results. Experimental results show that HMFMS obtains superior performance on four challenging datasets (i.e., Hopkins155, Hopkins12, MTPV62 and KT3DMoSeg), compared with several subspace-based and model-fitting-based motion segmentation methods. More remarkably, HMFMS outperforms the state-of-the-art MCMS method by 57.1% and 1.8 times in terms of accuracy and computational efficiency on the representative KT3DMoSeg, respectively. Shuyuan Lin, Anjia Yang, Taotao Lai, Jian Weng 0001, Hanzi Wang |
IEEE Trans. Circuits Syst. Video Technol. | 2 |
| 2024 | Multi-Client Secure and Efficient DPF-Based Keyword Search for Cloud StorageabstractIn this paper, we propose a multi-client secure and efficient keyword search scheme for cloud storage, which is built upon distributed point function (DPF). Specifically, outsourced keyword indexes are encoded by using garbled bloom filter and cuckoo filter, instead of bloom filter adopted by most of the state-of-the-art DPF-based schemes. In this way, clients can apply cuckoo hashing into DPF and utilize a segmentation method to interact with cloud servers for keyword search, and servers can obliviously aggregate DPF evaluation results to perform the search. Accordingly, the computational complexity at server side can be significantly reduced. Furthermore, the proposed scheme preserves constant downlink overheads, which is more communication-efficient for multi-keyword conjunctive search. To achieve privacy preservation and access control for multiple clients, we propose a double encryption method to encrypt outsourced indexes and correspondingly put forward an authorization algorithm from set-constrained pseudorandom functions by which fine-grained search-authorized keys can be generated, and collusion attacks among clients are addressed by integrating Wegman-Carter message authentication codes and cover-free systems. Since our scheme is designed under both semi-honest and malicious models (i.e., malicious servers may return incorrect query results), we use a simulation-based proof to formally demonstrate its security properties. Finally, we develop a proof-of-concept prototype and perform extensive experiments to show our scheme's practicality and efficiency in terms of computation, communication, and storage overheads. Cheng Huang 0001, Anjia Yang, Rongxing Lu, Xuemin Shen |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | VerifyML: Obliviously Checking Model Fairness Resilient to Malicious Model HolderabstractIn this paper, we presentVerifyML, the first secure inference framework to check the fairness degree of a given Machine learning (ML) model.VerifyMLis generic and is immune to any obstruction by the malicious model holder during the verification process. We rely on secure two-party computation (2 PC) technology to implementVerifyML, and carefully customize a series of optimization methods to boost its performance for both linear and nonlinear layer execution. Specifically, (1)VerifyMLallows the vast majority of overhead to be performed offline, thus meeting the low latency requirements for online inference. (2) To speed up offline preparation, we first design novel homomorphic parallel computing techniques to accelerate the authenticated Beaver's triple (including matrix- vector and convolution triples) generation procedure. It achieves up to$1.7\times$computation speedup and gains at least$10.7\times$less communication overhead compared to state-of-the-art work. (3) We also present a new cryptographic protocol to evaluate the activation functions of non-linear layers, which is$4\times$–$42\times$faster and has$\gt 48\times$less communication than the existing 2 PC protocol against malicious parties. In fact,VerifyMLeven beats the state-of-the-art semi-honest ML secure inference system! We provide a formal theoretical analysis forVerifyMLsecurity and demonstrate its performance superiority on mainstream ML models including ResNet-18 and LeNet. Guowen Xu, Xingshuo Han, Gelei Deng, Tianwei Zhang 0004, Shengmin Xu, Jianting Ning, Anjia Yang, Hongwei Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2024 | PriGenX: Privacy-Preserving Query With Anonymous Access Control for Genomic DataabstractPresently, similar sequence search is a fundamental technique in genomic data research. Patients or researchers, who want to check whether they or their research objects have genetic diseases or potential illnesses, need to query similar sequences with their genes in certain genomic databases. As a consequence, this may raise privacy issues since the genomic data are regarded as an identifier of each individual and contain lots of sensitive information. Up to date, some solutions have been brought up for achieving secure similarity search over genomic data, but they are still defective in searching exact similar sequences, supporting fine-grained access control, preventing side information leakage, and being built on strong security models at the same time. In this paper, aiming at the above challenge, we propose a maliciously secure similar sequence search scheme with fine-grained access control over genomic data, named PriGenX. Based on oblivious transfer and authenticated garbling techniques, our scheme also supports secure access control with anonymity for protecting the identity of each party preventing side information leakage, and implementing a flexible over-threshold similarity search. Experimental results and security analysis indicate that our scheme is scalable and maliciously secure. Yaxi Yang, Jian Weng 0001, Jia-Nan Liu, Leo Yu Zhang, Anjia Yang |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2024 | Privacy-Preserving Travel Recommendation Based on Stay Points Over Outsourced Spatio-Temporal DataabstractWith the pervasiveness of GPS-enabled devices, mobile users can directly visit the best travel routes matching their interests and obtain a better user experience via location-based travel recommendation services. As the number of queries grows, the travel agency for location-based travel recommendations tends to outsource its recommendation services to the cloud server. Since the travel agency’s popular travel routes and raw trajectory data from mobile users contain sensitive information, privacy protection should be guaranteed. Although some schemes have been proposed to solve the privacy problems, no previous works related to the location-based recommendation are proposed over mobile users’ raw trajectories. To solve this problem, we propose a privacy-preserving travel recommendation scheme based on stay points over the raw encrypted trajectory data. Specifically, we first propose an adapted longest common subsequence computation algorithm to measure the similarity of two trajectories. Second, to support some computations under ciphertext, we design several secure two-party computation (S2PC) primitives (e.g., secure division, secure mean coordinate, and secure comparison) based on the Paillier cryptosystem. Third, we implement secure stay points extraction and adapted longest common subsequence computation protocols via these secure computation primitives. Finally, we analyze the security of our proposed scheme in the semi-honest model and show that the privacy of mobile users’ trajectories, query results, and the travel agency’s popular travel routes are well protected. Meanwhile, we evaluate the performance of each secure computation primitive and conduct extensive experiments on synthetic datasets, and the experimental results show that our scheme is practical in the real applications. Lulu Han, Weiqi Luo 0002, Rongxing Lu, Yandong Zheng, Anjia Yang, Junzuo Lai, Yudan Cheng |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2024 | PPRP: Preserving Location Privacy for Range-Based Positioning in Mobile NetworksabstractIn this paper, we propose a privacy-preserving range-based positioning scheme, named PPRP, which can preserve the location privacy of both user equipment (UE) and anchors (ACs) in mobile networks. Specifically, PPRP is established on a decentralized trust-based framework that divides trust between two location management function (LMF) servers. With such a framework, UE and ACs are allowed to securely upload their range/range-difference measurement data to LMF servers using lightweight additive secret sharing techniques (ASS) instead of cumbersome cryptographic operations. Then, PPRP takes secret-shared measurement data as inputs and decomposes UE's location estimation procedures into secure two-party matrix computation sub-protocols, which are elaborately crafted using somewhat homomorphic encryption and randomization techniques to ensure both efficiency and privacy preservation in positioning. Furthermore, to mitigate the negative effects arising from non-line-of-sight (NLoS) ACs, PPRP achieves privacy-preserving residual-based NLoS analysis. To this end, we additionally propose a series of secure two-party sub-protocols to support various non-linear functions, including comparison, division, square root computation, oblivious shuffle and sorting. These sub-protocols serve as fundamental modules that can be effectively combined to perform sophisticated operations of NLoS analysis in a privacy-preserving manner. A comprehensive simulation-based security analysis demonstrates that PPRP can achieve location privacy preservation. Finally, we develop a proof-of-concept prototype and conduct extensive experiments to show PPRP's high performance in terms of positioning accuracy, computational efficiency, and communication complexity. Cheng Huang 0001, Anjia Yang, Rongxing Lu, Xuemin Shen |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Privacy-Preserving Bilateral Multi-Receiver Matching With Revocability for Mobile Social NetworksabstractMobile social networks (MSNs) offer convenient and ubiquitous services to expand social circles, share information, etc. These services require strict security measures to prevent the spread of deceptive content, misleading information, and malicious behavior. Achieving bilateral access control, message confidentiality and authenticity, and identity privacy can establish a positive network environment. Identity-based matchmaking encryption (IB-ME) with all the above features is a promising cryptographic primitive for MSNs. However, IB-ME can only specify one receiver. To share data with multiple users, the sender needs to encrypt the same message many times, resulting in higher frequencies of communication. Moreover, in multi-receiver scenarios, revocation of decryption permission may be necessary due to the possibility of malicious behavior, organization changes, or discontinuing subscription services. To our knowledge, no cryptographic primitives have been developed that satisfy these requirements. To address these challenges, we introduce the concept of revocable multi-receiver IB-ME and formalize its syntax and security definitions. We propose a revocable multi-receiver IB-ME scheme that provides privacy and authenticity in the random oracle model. Our evaluation demonstrates that it is efficient, and the sizes of system parameters and secret keys are independent of the number of receivers and revoked receivers. Axin Wu, Dengguo Feng, Min Zhang 0043, Anjia Yang, Jialin Chi |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | Efficient Bilateral Privacy-Preserving Data Collection for Mobile CrowdsensingabstractMobile crowdsensing (MCS) utilizes ubiquitous mobile devices to collect massive amounts of data and offer various high-quality services. During the data collection and upload process, bilateral access control is implemented to recruit qualified data providers and prevent unauthorized access to collected data. However, the efficiency of existing bilateral access control schemes applicable in the data collection phase is dissatisfactory, as their ciphertext sizes are linear with the number of attributes. Additionally, data confidentiality and authenticity, as well as lightweight encryption and decryption processes, are crucial for the deployment of MCS since the former eliminate the risks of data abuse and false data injection, and the latter are typically limited in their computation and communication resources. To reduce the resource consumption of these devices, we present EBAC-CC, an efficient bilateral access control with constant-size ciphertexts that ensures data confidentiality and authenticity and allows for flexible threshold bilateral access control. Besides, offline/online techniques and outsourced decryption are employed to quickly generate ciphertexts and recover perceptual data, which also alleviates their computation burdens. We also prove its privacy and authenticity in the standard model and evaluate its efficacy theoretically and experimentally, demonstrating its superiority over other bilateral access control schemes. Axin Wu, Weiqi Luo 0002, Anjia Yang, Yinghui Zhang 0002, Jianhao Zhu |
IEEE Trans. Serv. Comput. | 3 |
| 2023 | Robust Publicly Verifiable Covert Security: Limited Information Leakage and Guaranteed Correctness with Low Overhead
Yi Liu 0053, Junzuo Lai, Qi Wang 0012, Xianrui Qin, Anjia Yang, Jian Weng 0001 |
ASIACRYPT (1) | 5 |
| 2023 | Fusion: Efficient and Secure Inference Resilient to Malicious Servers
Caiqin Dong, Jian Weng 0001, Jia-Nan Liu, Yue Zhang 0025, Anjia Yang, Yudan Cheng, Shun Hu |
NDSS | 6 |
| 2023 | Fully privacy-preserving location recommendation in outsourced environments
Lulu Han, Weiqi Luo 0002, Anjia Yang, Yandong Zheng, Rongxing Lu, Junzuo Lai, Yudan Cheng |
Ad Hoc Networks | 3 |
| 2023 | Backdoor-Resistant Public Data Integrity Verification Scheme Based on Smart ContractsabstractThis article analyzes existing smart contract-based public data integrity verification schemes and identifies certain weaknesses. First, the fair arbitration mechanism deployed in these schemes fails to meet the users’ requirements as it may not promptly notify users of data corruption or loss. Second, to ensure outsourced data confidentiality, existing data integrity schemes use a conventional encrypted method, where each user randomly selects a key to encrypt the outsourced data. Such a method results in varying ciphertexts for the same data by different users, leading to additional storage costs for the cloud server. Third, users’ devices, if poorly designed or even intentionally backdoored, can potentially exfiltrate secrets and compromise the security of schemes. To address these issues, we propose the first backdoor-resistant public data integrity verification scheme based on smart contracts (ASSIST). The key idea is to introduce a new entity (a whistleblower) to periodically monitor the state of verification results recorded in the blockchain. This allows for timely notification of data corruption to users. ASSIST requires users to encrypt their data with a cryptographic primitive called message-locked encryption (MLE), which motivates different users to produce the same ciphertext for the same data and reduces storage costs for cloud servers. We also deploy a cryptographic reverse firewall between users’ devices and the external to rerandomize interactive messages, making the exfiltration impossible. We provide rigorous security proofs to demonstrate the security of ASSIST. The performance evaluation shows that ASSIST is efficient regarding computation and communication costs. Shanshan Li 0004, Chunxiang Xu, Yuan Zhang 0006, Yicong Du, Anjia Yang, Xinsheng Wen, Kefei Chen |
IEEE Internet Things J. | 5 |
| 2023 | Edge-Cloud-Assisted Certificate Revocation Checking: An Efficient Solution Against Irresponsible Service ProvidersabstractCertificate revocation checking (CRC) is a fundamental requirement in certificate-based public-key cryptographic systems. Most existing CRC schemes are not tailored for edge-cloud computing systems, and directly applying these schemes would cause security and efficiency problems. In this article, we first propose a two-layer edge-cloud-assisted CRC framework, dubbed ECA-CRC, where edge nodes utilizing a probabilistic checking algorithm serve as a first layer, and the cloud server utilizing a deterministic checking algorithm serves as a second layer. Both the edge nodes and the cloud server collaboratively provide verifiable CRC services for devices. The most prominent manifestations of ECA-CRC are that: 1) most CRC requests can be processed with the probabilistic checking layer, which reduces the checking delay significantly while providing an accurate CRC service and 2) devices can detect the irresponsible behavior of the service provider, including using an incorrect revoked certificate set (RCS) to compute checking results or procrastinating on updating the RCS, as soon as possible. We then propose an efficient instantiation of ECA-CRC, dubbed eECA-CRC, by utilizing a Merkle hash tree (MHT)-based homomorphic signature, Cuckoo filter, and Othello. We formally prove the security of eECA-CRC against the irresponsible service provider under the random oracle model. We implement an eECA-CRC prototype and conduct a comprehensive performance evaluation based on a public certificate database. Our results show that 95% of CRC requests are completed on the edge nodes, and only 5% of CRC requests need to be handled by the cloud server. Yaqing Song, Yuan Zhang 0006, Chunxiang Xu, Shiyu Li 0002, Anjia Yang, Nan Cheng 0001 |
IEEE Internet Things J. | 5 |
| 2023 | Scalable CCA-secure public-key authenticated encryption with keyword search from ideal lattices in cloud computing
Jian Weng 0001, Anjia Yang, Xiaojian Liang, Zike Jiang, Lin Hou 0002 |
Inf. Sci. | 3 |
| 2023 | Enabling Traceable and Verifiable Multi-User Forward Secure Searchable Encryption in Hybrid CloudabstractForward secure searchable encryption (FSSE) scheme allows one data user to search on encrypted databases while resisting the file injection attack. The data utilization can be further improved by extending the single-user scenario to the multi-user scenario. However, there are some issues needed to be considered when a data owner shares data with multiple data users. First, the public cloud server can not be completely trusted as it may be dishonest returning incorrect or incomplete results. Second, authorized users may trade their private keys for financial benefit. To our knowledge, state-of-the-art searchable encryption schemes only consider part of the following desirable features: the verifiability of results, the resistance to file injection attacks, the traceability and revocation of malicious users who abuse their private keys in the multi-user setting. Based on these motivations, we first propose enabling traceable and verifiable multi-user FSSE, which achieves the above functionalities. Besides, we carry out the security proof which demonstrates that our scheme can meet the requirements of security. We also assess the performance from theoretical analysis and experimental analysis, which shows that compared with other similar schemes, our scheme has richer functionalities with comparable efficiency. Axin Wu, Anjia Yang, Weiqi Luo 0002, Jinghang Wen |
IEEE Trans. Cloud Comput. | 2 |
| 2023 | Maliciously Secure and Efficient Large-Scale Genome-Wide Association Study With Multi-Party ComputationabstractGenome-Wide Association Study (GWAS) aims at detecting the association between diseases and Single-Nucleotide Polymorphisms (SNPs) with statistical techniques and has great potential for disease diagnosis. To obtain high-quality results, GWAS requires large-scale genomic data containing individuals’ privacy information. Thus, how to improve the efficiency of GWAS while protecting the privacy of genomic data becomes a critical challenge. In this paper, we propose a secure and efficient GWAS scheme. By using secure three-party computation, we present a series of protocols, i.e., Secure Quality Control, Secure Principle Component Analysis, Secure Cochran-Armitage trend test, and Secure Logistic Regression, to cover the most significant procedures of secure GWAS. In these protocols, a new comparison protocol is designed to reduce communication and improve efficiency. Furthermore, by extending the above comparison protocol to be maliciously secure and utilizing other technologies, e.g., consistency check, we extend the whole GWAS scheme to malicious security with rationally additional overhead. Experimental results demonstrate that our protocols achieve about 33% performance improvement than the state-of-art secure GWAS scheme using two-party computation in terms of runtime and communication in the semi-honest setting. The cost of our scheme in the malicious setting is around 1.5X than that in the semi-honest setting. Caiqin Dong, Jian Weng 0001, Jia-Nan Liu, Anjia Yang, Zhiquan Liu 0001, Yaxi Yang, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | pvCNN: Privacy-Preserving and Verifiable Convolutional Neural Network TestingabstractWe propose a new approach for privacy-preserving and verifiable convolutional neural network (CNN) testing in a distrustful multi-stakeholder environment. The approach is aimed to enable that a CNN modeldeveloperconvinces auserof the truthful CNN performance over non-public data frommultiple testers, while respecting model and data privacy. To balance the security and efficiency issues, we appropriately integrate three tools with the CNN testing, including collaborative inference, homomorphic encryption (HE) and zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK). We start with strategically partitioning a CNN model into a private part kept locally by the model developer, and a public part outsourced to an outside server. Then, the private part runs over the HE-protected test data sent by a tester, and transmits its outputs to the public part for accomplishing subsequent computations of the CNN testing. Second, the correctness of the above CNN testing is enforced by generating zk-SNARK based proofs, with an emphasis on optimizing proving overhead for two-dimensional (2-D) convolution operations, since the operations dominate the performance bottleneck during generating proofs. We specifically present a new quadratic matrix program (QMP)-based arithmetic circuit witha single multiplication gatefor expressing 2-D convolution operations between multiple filters and inputs in a batch manner. Third, we aggregate multiple proofs with respect to a same CNN model but different testers’ test data (i.e., different statements) into one proof, and ensure that the validity of the aggregated proof implies the validity of the original multiple proofs. Lastly, our experimental results demonstrate that our QMP-based zk-SNARK performs nearly 13.9× faster than the existing quadratic arithmetic program (QAP)-based zk-SNARK in proving time, and 17.6× faster in Setup time, for high-dimension matrix multiplication. Besides, the limitation on handling a bounded number of multiplications of QAP-based zk-SNARK is relieved. Jia-Si Weng 0001, Jian Weng 0001, Gui Tang, Anjia Yang, Ming Li 0049, Jia-Nan Liu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Fuzzy Identity-Based Matchmaking Encryption and Its ApplicationabstractAteniese et al. introduced the primitive of matchmaking encryption (ME) at CRYPTO 2019 and left open several important questions, which include extending ME to fuzzy cases or giving an efficient ME in the identity-based setting without relying on random oracles. The main challenge is to achieve fuzzy bilateral access control while providing identity privacy of the sender and receiver, message confidentiality and authenticity without random oracles. In this work, we resolve the question by formalizing the first fuzzy identity-based ME (IB-ME) and presenting a concrete construction. Specifically, we propose the formal syntax definition of fuzzy IB-ME. In fuzzy IB-ME, the identities of senders and receivers are characterized by attribute sets. A ciphertext can be correctly decrypted if the overlaps between the attribute set of the sender or receiver and the attribute set specified by the other party are simultaneously greater than a threshold, which can be applied to many attractive applications such as fuzzy bilateral access control in online social dating. Then, we present concrete details of fuzzy IB-ME based on fuzzy identity-based encryption, which does not rely on other cryptographic tools such as two-input functional encryption and non-interactive zero-knowledge proof systems. In this process, fuzzy bilateral access control and identity privacy are achieved through the formalism of arranged ME and the splitting technique while message authenticity is provided through the authentication and binding of the encryption key. The identity privacy of the sender and receiver, confidentiality, and authenticity of messages are reduced to the decisional bilinear Diffie-Hellman, decision linear, and computational bilinear Diffie-Hellman assumptions in the selective model without random oracles. Finally, we implement the scheme and evaluate its performance through theoretical analyses and experiments to demonstrate its efficiency. Axin Wu, Weiqi Luo 0002, Jian Weng 0001, Anjia Yang, Jinghang Wen |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | A Blockchain-Based Copyright Protection Scheme With Proactive DefenseabstractCopyright protection, including copyright registration, copyright transfer and infringement penalty, plays a critical role in preventing illegal usage of original works. The mainstream traditional copyright protection schemes need an authority online all the time to handle copyright issues and face some problems such as intricate copyright transfer, single point of failure and so on. To alleviate the burden of the authority, a few blockchain-based copyright protection schemes are proposed. However, most of them do not consider copyright transfer, and their infringement penalty may only happen after copyright owners discover the infringement behavior (i.e., “ex-post penalty”). In this article, we propose a new security strategy, called “Proactive Defense” in copyright protection which can prevent infringement before it occurs. With our proposed proactive defense strategy, we design a secure copyright protection scheme which provides advantages of compact copyright transfer and prior infringement penalty. More concrete, both copyright registration and transfer are regarded as transactions and recorded to the blockchain. Based on the double-authentication-prevention signature and non-interactive zero-knowledge proof techniques, illegal copyright transfer can be detected and the infringement penalty can be done automatically with a tailored smart contract before the completion of the transfer. Our security analysis shows that the proposed scheme can achieve all desirable security properties. Moreover, we implement our scheme in Java and evaluate the performance experimentally. Experimental results show that the proposed scheme has good security and efficiency, which can be applied for the copyright protection. Anjia Yang, Jian Weng 0001, Cheng Huang 0001, Tao Li 0067 |
IEEE Trans. Serv. Comput. | 2 |
| 2023 | PPOLQ: Privacy-Preserving Optimal Location Query With Multiple-Condition Filter in Outsourced EnvironmentsabstractThe optimal location selection is one type of the location-based services (LBS) that aims to find the best location for a new facility from some candidate facilities given a set of existing facilities and a set of customers. Due to reliable and flexible cloud services, outsourcing such heavy-computation tasks has been a popular trend. However, since the cloud is not fully trusted, and the location data contains the sensitive information, privacy protection becomes an essential requirement for these services. Although some related works have been proposed to provide privacy protection, the privacy of data and queries, accuracy of query results, and multiple features of location data are not considered by them simultaneously. In this paper, we propose a privacy-preserving optimal location query scheme PPOLQ that supports multiple-condition filter and queries over multiple data providers in outsourced environments. Specifically, we first design a secure division protocol and a secure inner product protocol based on the Paillier algorithm and the random masking technique, respectively. After that, based on the proposed algorithms, the additive homomorphic encryption, and the secure two-party computation techniques, we develop a privacy-preserving optimal location query scheme. Finally, we analyze the security of our proposed algorithms and scheme in the semi-honest model. Meanwhile, we implement all algorithms and the proposed scheme, and our implementation is open source at Gitee. We also evaluate their performances using synthetic datasets, and extensive experiments show that our scheme is practical for the real-world applications. Lulu Han, Weiqi Luo 0002, Yaxi Yang, Anjia Yang, Rongxing Lu, Junzuo Lai, Yandong Zheng |
IEEE Trans. Serv. Comput. | 4 |
| 2023 | Concurrent and efficient IoT data trading based on probabilistic micropayments
Tao Li 0067, Anjia Yang, Jian Weng 0001, Qingfu Pei |
Wirel. Networks | 2 |
| 2022 | A Multisignature-Based Secure and OBU-Friendly Emergency Reporting Scheme in VANETabstractActing as an important part of Internet of Things (IoTs), vehicular ad-hoc network (VANET) has attracted considerable attention in recent years, where the emergency reporting system is a significant branch and can improve road safety and optimize traffic management. In an emergency reporting system, the authenticity of the emergency messages needs to be ensured carefully since malicious entities may report fake emergency messages to seek personal profit. However, most existing emergency reporting schemes are not efficient enough for secure reporting, given the limited resources of onboard units (OBUs). In this work, we propose a new emergency reporting architecture based on multisignature, where the computation and communication overhead of road-side units (RSUs) is greatly reduced, as the signatures sent to the RSUs have been aggregated. Then, we transform a chameleon signature into a multisignature and propose a secure and OBU-friendly emergency reporting scheme (SOERS) under our architecture. The proposed scheme only requires one hash, two multiplication, and two addition operations to generate a signature for each OBU. Moreover, batch verification of multisignatures further improves the efficiency. Security analysis shows that our scheme is secure against the vehicles-collusion attack and the rogue-key attack, which is a severe issue in multisignature. Finally, performance evaluation shows that our scheme is an efficient solution for emergency reporting. Anjia Yang, Jian Weng 0001, Jia-Si Weng 0001, Tao Li 0067 |
IEEE Internet Things J. | 2 |
| 2022 | DAMIA: Leveraging Domain Adaptation as a Defense Against Membership Inference AttacksabstractDeep Learning (DL) techniques allow ones to train models from a dataset to solve tasks. DL has attracted much interest given its fancy performance and potential market value, while security issues are amongst the most colossal concerns. However, the DL models may be prone to the membership inference attack, where an attacker determines whether a given sample is from the training dataset. Efforts have been made to hinder the attack but unfortunately, they may lead to a major overhead or impaired usability. In this article, we propose and implement DAMIA, leveraging Domain Adaptation (DA) as a defense aginist membership inference attacks. Our observation is that during the training process, DA obfuscates the dataset to be protected using another relate and similar dataset, and derives a model that underlyingly extracts the features from both datasets. Seeing that the model is obfuscated, membership inference fails, while the extracted features provide supports for usability. Extensive experiments have been conducted to validates our intuition. The model trained by DAMIA has a negligible footprint to the usability and introduces slight overhead compared with other defenses. Our experiment also excludes factors that may hinder the performance of DAMIA, and comparisons with other defenses, providing a potential guideline to vendors and researchers to benefit from our solution in a timely manner. Weiqi Luo 0002, Jian Weng 0001, Yue Zhang 0025, Anjia Yang |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2022 | Enabling Efficient, Secure and Privacy-Preserving Mobile Cloud StorageabstractMobile cloud storage (MCS) provides clients with convenient cloud storage service. In this article, we propose an efficient, secure and privacy-preserving mobile cloud storage scheme, which protects the data confidentiality and privacy simultaneously, especially the access pattern. Specifically, we propose an oblivious selection and update (OSU) protocol as the underlying primitive of the proposed mobile cloud storage scheme. OSU is based on onion additively homomorphic encryption with constant encryption layers and enables the client to obliviously retrieve an encrypted data item from the cloud and update it with a fresh value by generating a small encrypted vector, which significantly reduces the client’s computation as well as the communication overheads. Compared with previous works, our presented work has valuable properties, such as fine-grained data structure (small item size), lightweight client-side computation (a few of additively homomorphic operations) and constant communication overhead, which make it more suitable for MCS scenario. Moreover, by employing the “verification chunks” method, our scheme can be verifiable to resist malicious cloud. The comparison and evaluation indicate that our scheme is more efficient than existing oblivious storage solutions with the aspects of client and cloud workloads, respectively. Jia-Nan Liu, Xizhao Luo, Jian Weng 0001, Anjia Yang, Xu An Wang 0014, Ming Li 0049, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Revisiting Error-Correction in Precommitment Distance-Bounding ProtocolsabstractDistance-bounding (DB) protocols are used to verify the physical proximity of two devices. DB can be used to establish trusted ad-hoc connections in the industrial Internet-of-Things, e.g., nodes can verify they are deployed in the same location and monitoring the same piece of equipment. Thresholds and error correction codes (ECCs) are two methods to provide error-resilience for DB protocols working in noisy environments. However, the threshold method adds overheads and the ECC method increases the adversary success probability, compared to threshold, when implemented in precommitment DB protocols. In this article, we investigate the ECC method and demonstrate that designers can mitigate increased adversary success probability by using nonsystematic codes. To demonstrate this idea, we compare a prominent precommitment protocol by Brands and Chaum (BC) integrated with different types of ECCs with two existing error-resilience methods, showing how nonsystematic codes provide improved protocol security. Moreover, We further evaluate the BC protocol with nonsystematic ECCs and discuss how to configure protocols to minimize the protocol failure rate, while maintaining adequate attack success probability. Jingyi Zhang 0006, Anjia Yang, Qiao Hu 0005, Gerhard P. Hancke 0002, Zhe Liu 0001 |
IEEE Trans. Ind. Informatics | 2 |
| 2022 | Dynamic Multitarget Detection Algorithm of Voxel Point Cloud Fusion Based on PointRCNNabstractCurrent 3D target detection methods used in the field of autonomous driving generally have low real-time performance and insufficient target context feature to detect dynamic multi-target accurately. In order to solve these problems, a dynamic multi-target detection algorithm of voxel point cloud fusion based on PointRCNN is proposed, which adopts a two-stage detection structure. The first stage directly processes the point cloud to extract key point features and divides voxel space. A novel submanifold sparse convolution is used to extract voxel features. Then key point features and voxel features of the point cloud are merged to generate pre-selection boxes. In the second stage, reference points are set based on the voxel features. The features of key points around reference points are merged for the second time to achieve optimized detection boxes. Finally, for the problem of inconsistent confidence, a mandatory consistency loss function is proposed to improve the accuracy of the detection box. The proposed algorithm was compared with other algorithms in three different datasets, and further tested on a self-made dataset from an actual vehicle platform. Results showed that the proposed algorithm had higher accuracy, better robustness, stronger generalization ability for dynamic multi-target detection. Xizhao Luo, Feng Zhou 0013, Chongben Tao, Anjia Yang, Peiyun Zhang, Yonghua Chen |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2022 | Delegating Authentication to Edge: A Decentralized Authentication Architecture for Vehicular NetworksabstractSecure and efficient access authentication is one of the most important security requirements for vehicular networks, but it is difficult to fulfill due to potential security attacks and long authentication delay caused by high vehicle mobility, etc. Most of the existing authentication protocols, either do not consider attacks like single point of failure or do not focus on reducing authentication delay. To address these issues, we introduce an edge-assisted decentralized authentication (EADA) architecture, which provides secure and more communication-efficient authentication by enabling an authentication server to delegate its authentication capability to distributed edge nodes (ENs) such as roadside units (RSUs) and base stations (BSs). Under the architecture, we propose a threshold mutual authentication protocol that supports fast handover, which involves two scenarios, Auth-I and Auth-II. Auth-I only happens once when a vehicle tries to access the network for the first time, while Auth-II happens when a vehicle seamlessly roams between two ENs, i.e., handover. Specifically, for Auth-I, each vehicle can be cooperatively authenticated by$t$out of$n$ENs with identity-based signature techniques to obtain an authentication token and the involved ENs can be efficiently authenticated in a batch by the vehicle. For Auth-II, the vehicle can utilize the token as its private credential to achieve fast handover based on identity-based signature without interacting with multiple ENs, which further reduces the authentication delay significantly. In addition, we design a flexible method to support dynamic joining and leaving of ENs without the assistance of a trusted center. We demonstrate that the proposed protocol is secure and efficient through security analysis and performance evaluation. Anjia Yang, Jian Weng 0001, Kan Yang 0001, Cheng Huang 0001, Xuemin Shen |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2021 | Attribute-Based Conditional Proxy Re-encryption in the Standard Model Under LWE
Xiaojian Liang, Jian Weng 0001, Anjia Yang, Zike Jiang |
ESORICS (2) | 3 |
| 2021 | Efficient and Fully Secure Lattice-Based IBE with Equality Test
Jian Weng 0001, Anjia Yang, Xiaojian Liang, Zike Jiang, Jinghang Wen |
ICICS (2) | 3 |
| 2021 | Privacy-Preserving Group Authentication for RFID Tags Using Bit-Collision PatternsabstractWhen authenticating a group of radio-frequency identification tags, a common method is to authenticate each tag with some challenge-response exchanges. However, sequentially authenticating individual tags one by one might not be desirable, especially when considering that a reader often has to deal with multiple tags within a limited period, since it will incur long scanning time and heavy communication costs. To address these problems, we put forward a novel efficient group authentication protocol, where a group of tags can be authenticated simultaneously with only one challenge and one response. The protocol is built on a newly designed symmetric key-based algorithm and the bit-collision pattern technique, so that authentication responses transmitted by multiple tags in a group at the same time will result in a verifiable bit-collision pattern that represents the authentication response for the entire group. The proposed approach can significantly reduce the authentication time and communication cost in the sense that the verifier can authenticate the entire group within a period that is comparable to the time taken to perform a single-tag authentication and requires only one challenge. In addition, we extend our protocol to support the privacy-preserving property, which prevents the tagged items from being tracked by illegitimate parties. A thorough security analysis shows that the proposed protocol can resist common practical attacks and experimental results show that the protocol is very efficient in terms of time and communication costs. We also discuss important practical aspects that should be considered when implementing these protocols. Anjia Yang, Dutliff Boshoff, Qiao Hu 0005, Gerhard P. Hancke 0002, Xizhao Luo, Jian Weng 0001, Keith Mayes, Konstantinos Markantonakis |
IEEE Internet Things J. | 1 |
| 2021 | Lightweight and Privacy-Preserving Delegatable Proofs of Storage with Data Dynamics in Cloud StorageabstractCloud storage has been in widespread use nowadays, which alleviates users' burden of local data storage. Meanwhile, how to ensure the security and integrity of the outsourced data stored in a cloud storage server has also attracted enormous attention from researchers. Proofs of storage (POS) is the main technique introduced to address this problem. Publicly verifiable POS allowing a third party to verify the data integrity on behalf of the data owner significantly improves the scalability of cloud service. However, most of existing publicly verifiable POS schemes are extremely slow to compute authentication tags for all data blocks due to many expensive group exponentiation operations, even much slower than typical network uploading speed, and thus it becomes the bottleneck of the setup phase of the POS scheme. In this article, we propose a new variant formulation called “Delegatable Proofs of Storage (DPOS)”. Then, we construct a lightweight privacy-preserving DPOS scheme, which on one side is as efficient as private POS schemes, and on the other side can support third party auditor and can switch auditors at anytime, close to the functionalities of publicly verifiable POS schemes. Compared to traditional publicly verifiable POS schemes, we speed up the tag generation process by at least several hundred times, without sacrificing efficiency in any other aspect. In addition, we extend our scheme to support fully dynamic operations with high efficiency, reducing the computation of any data update to O(log n) and simultaneously only requiring constant communication costs. We prove that our scheme is sound and privacy preserving against auditor in the standard model. Experimental results verify the efficient performance of our scheme. Anjia Yang, Jia Xu 0006, Jian Weng 0001, Jianying Zhou 0001, Duncan S. Wong |
IEEE Trans. Cloud Comput. | 1 |
| 2021 | Looking Back! Using Early Versions of Android Apps as Attack VectorsabstractAndroid platform is gaining explosive popularity. This leads developers to invest resources to maintain the upward trajectory of the demand. Unfortunately, as the profit potential grows higher, the chances of these Apps getting attacked also get higher. Therefore, developers improved the security of their Apps, which limits attackers ability to compromise upgraded versions of the Apps. However, developers cannot enhance the security of earlier versions that have been released on the Play Store. The earlier versions of the App can be subject to reverse engineering and other attacks. In this paper, we find that attackers can use these earlier versions as attack vectors, which threatens well protected upgraded versions. We show how to attack the upgraded versions of some popular Apps, including Facebook, Sina Weibo and Qihoo360-Cloud-Driven by analyzing the vulnerabilities existing in their earlier versions. We design and implement a tool named DroidSkynet to analyze and find out vulnerable apps from the Play Store. Among 1,500 mainstream Apps collected from the real world, our DroidSkynet indicates the success rate of attacking an App using an earlier version is 34 percent. We also explore possible mitigation solutions to achieve a balance between utility and security of the App update process. Yue Zhang 0025, Jian Weng 0001, Jia-Si Weng 0001, Lin Hou 0002, Anjia Yang, Ming Li 0049, Yang Xiang 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Preventing Overshadowing Attacks in Self-Jamming Audio ChannelsabstractRecently there has been a growing interest in short-range communication using audio channels for device pairing and as a self-jamming communication medium. Given that such channels are audible to participants they are considered more resistant to active attacks, i.e., the attack signal would be heard by the participants. In this paper, we investigate the validity of this assumption using two prominent acoustic self-jamming systems implementations. We show that basic overshadowing attacks are possible in these systems and that these attacks cannot be effectively detected by the participants if the attacker is close to the receiving device. Finally, we propose a novel physical-layer solution for effectively detecting overshadowing attacks, which can improve state-of-the-art acoustic self-jamming systems by ensuring channel integrity while not requiring fundamental modifications to these schemes. Qiao Hu 0005, Yuanzhen Liu, Anjia Yang, Gerhard P. Hancke 0002 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | Blockchain-Based Efficient Public Integrity Auditing for Cloud Storage Against Malicious Auditors
Shanshan Li 0004, Chunxiang Xu, Yuan Zhang 0006, Anjia Yang, Xinsheng Wen, Kefei Chen |
Inscrypt | 4 |
| 2020 | A Provably Secure Certificateless Proxy Signature Scheme Against Malicious-But-Passive KGC AttacksabstractAbstract In certificateless proxy signature (CLPS), the key generation center is responsible for initializing the system parameters and can obtain the opportunity to adaptively set some trapdoors in them when wanting to launch some attacks. Until now, how to withstand the malicious-but-passive key generation center (MKGC) attacks in CLPS is still an interesting problem. In this paper, we focus on the challenging issue and introduce a CLPS scheme provably secure in the standard model. To the best of our knowledge, we are the first to demonstrate its security under MKGC attacks by adopting the technology of embedding the classic difficulty problems into the target entity public key rather than the system parameters during the security proof process. Wenjie Yang 0001, Jian Weng 0001, Xinyi Huang 0001, Anjia Yang |
Comput. J. | 4 |
| 2019 | CrowdBC: A Blockchain-Based Decentralized Framework for CrowdsourcingabstractCrowdsourcing systems which utilize the human intelligence to solve complex tasks have gained considerable interest and adoption in recent years. However, the majority of existing crowdsourcing systems rely on central servers, which are subject to the weaknesses of traditional trust-based model, such as single point of failure. They are also vulnerable to distributed denial of service (DDoS) and Sybil attacks due to malicious users involvement. In addition, high service fees from the crowdsourcing platform may hinder the development of crowdsourcing. How to address these potential issues has both research and substantial value. In this paper, we conceptualize a blockchain-based decentralized framework for crowdsourcing named CrowdBC, in which a requester's task can be solved by a crowd of workers without relying on any third trusted institution, users' privacy can be guaranteed and only low transaction fees are required. In particular, we introduce the architecture of our proposed framework, based on which we give a concrete scheme. We further implement a software prototype on Ethereum public test network with real-world dataset. Experiment results show the feasibility, usability, and scalability of our proposed crowdsourcing system. Ming Li 0049, Jian Weng 0001, Anjia Yang, Wei Lu 0001, Yue Zhang 0025, Lin Hou 0002, Jia-Nan Liu, Yang Xiang 0001, Robert H. Deng |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2018 | Fully distributed certificateless threshold signature without random oracles
Wenjie Yang 0001, Weiqi Luo 0002, Xizhao Luo, Jian Weng 0001, Anjia Yang |
Sci. China Inf. Sci. | 5 |
| 2018 | HB+DB: Distance bounding meets human based authentication
Elena Pagnin, Anjia Yang, Qiao Hu 0005, Gerhard P. Hancke 0002, Aikaterini Mitrokotsa |
Future Gener. Comput. Syst. | 2 |
| 2018 | Exploring relationship between indistinguishability-based and unpredictability-based RFID privacy models
Anjia Yang, Yunhui Zhuang, Jian Weng 0001, Gerhard P. Hancke 0002, Duncan S. Wong, Guomin Yang |
Future Gener. Comput. Syst. | 1 |
| 2018 | Notes on a provably-secure certificate-based encryption against malicious CA attacks
Wenjie Yang 0001, Jian Weng 0001, Anjia Yang, Congge Xie, Yaxi Yang |
Inf. Sci. | 3 |
| 2018 | OTP-IoT: An ownership transfer protocol for the Internet of Things
Mohammad Saiful Islam Mamun, Chunhua Su, Anjia Yang, Atsuko Miyaji, Ali A. Ghorbani 0001 |
J. Inf. Secur. Appl. | 3 |
| 2018 | Two-Hop Distance-Bounding Protocols: Keep Your Friends CloseabstractAuthentication in wireless communications often depends on the physical proximity to a location. Distance-bounding (DB) protocols are cross-layer authentication protocols that are based on the round-trip-time of challenge-response exchanges and can be employed to guarantee physical proximity and combat relay attacks. However, traditional DB protocols rely on the assumption that the prover (e.g., user) is in the communication range of the verifier (e.g., access point); something that might not be the case in multiple access control scenarios in ubiquitous computing environments as well as when we need to verify the proximity of our two-hop neighbour in an ad-hoc network. In this paper, we extend traditional DB protocols to a two-hop setting, i.e., when the prover is out of the communication range of the verifier and thus, they both need to rely on an untrusted in-between entity in order to verify proximity. We present a formal framework that captures the most representative classes of existing DB protocols and provide a general method to extend traditional DB protocols to the two-hop case (three participants). We analyze the security of two-hop DB protocols and identify connections with the security issues of the corresponding one-hop case. Finally, we demonstrate the correctness of our security analysis and the efficiency of our model by transforming five existing DB protocols to the two-hop setting and we evaluate their performance with simulated experiments. Anjia Yang, Elena Pagnin, Aikaterini Mitrokotsa, Gerhard P. Hancke 0002, Duncan S. Wong |
IEEE Trans. Mob. Comput. | 1 |
| 2017 | Strongly Unforgeable Certificateless Signature Resisting Attacks from Malicious-But-Passive KGCabstractIn digital signature, strong unforgeability requires that an attacker cannot forge a new signature on any previously signed/new messages, which is attractive in both theory and practice. Recently, a strongly unforgeable certificateless signature (CLS) scheme without random oracles was presented. In this paper, we firstly show that the scheme fails to achieve strong unforgeability by forging a new signature on a previously signed message under its adversarial model. Then, we point out that the scheme is also vulnerable to the malicious-but-passive key generation center (MKGC) attacks. Finally, we propose an improved strongly unforgeable CLS scheme in the standard model. The improved scheme not only meets the requirement of strong unforgeability but also withstands the MKGC attacks. To the best of our knowledge, we are the first to prove a CLS scheme to be strongly unforgeable against the MKGC attacks without using random oracles. Wenjie Yang 0001, Jian Weng 0001, Weiqi Luo 0002, Anjia Yang |
Secur. Commun. Networks | 4 |
| 2017 | A New ADS-B Authentication Framework Based on Efficient Hierarchical Identity-Based Signature with Batch VerificationabstractAutomatic dependent surveillance-broadcast (ADS-B) has become a crucial part of next generation air traffic surveillance technology and will be mandatorily deployed for most of the airspaces worldwide by 2020. Each aircraft equipped with an ADS-B device keeps broadcasting plaintext messages to other aircraft and the ground station controllers once or twice per second. The lack of security measures in ADS-B systems makes it susceptible to different attacks. Among the various security issues, we investigate the integrity and authenticity of ADS-B messages. We propose a new framework for providing ADS-B with authentication based on three-level hierarchical identity-based signature (HIBS) with batch verification. Previous signature-based ADS-B authentication protocols focused on how to generate signatures efficiently, while our schemes can also significantly reduce the verification cost, which is critical to ADS-B systems, since at any time an ADS-B receiver may receive lots of signatures. We design two concrete schemes. The basic scheme supports partial batch verification and the extended scheme provides full batch verification. We give a formal security proof for the extended scheme. Experiment results show that our schemes with batch verification are tremendously more efficient in batch verifying n signatures than verifying n signatures independently. For example, the running time of verifying 100 signatures is 502 and 484 ms for the basic scheme and the extended scheme respectively, while the time is 2500 ms if verifying the signatures independently. Anjia Yang, Xiao Tan 0003, Joonsang Baek, Duncan S. Wong |
IEEE Trans. Serv. Comput. | 1 |
| 2016 | Lightweight Delegatable Proofs of Storage
Jia Xu 0006, Anjia Yang, Jianying Zhou 0001, Duncan S. Wong |
ESORICS (1) | 2 |
| 2016 | Practical limitation of co-operative RFID jamming methods in environments without accurate signal synchronization
Qiao Hu 0005, Lavinia Mihaela Dinca, Anjia Yang, Gerhard P. Hancke 0002 |
Comput. Networks | 3 |
| 2015 | HB+DB, mitigating man-in-the-middle attacks against HB+ with distance boundingabstractAuthentication for resource-constrained devices is seen as one of the major challenges in current wireless communication networks. The HB+ protocol performs device authentication based on the learning parity with noise (LPN) problem and simple computational steps, that renders it suitable for resource-constrained devices such as radio frequency identification (RFID) tags. However, it has been shown that the HB+ protocol as well as many of its variants are vulnerable to a simple man-in-the-middle attack. We demonstrate that this attack could be mitigated using physical layer measures from distance-bounding and simple modifications to devices' radio receivers. Our hybrid solution (HB+DB) is shown to provide both effective distance-bounding using a lightweight HB+-based response function, and resistance against the man-in-the-middle attack to HB+. We provide experimental evaluation of our results as well as a brief discussion on practical requirements for secure implementation. Elena Pagnin, Anjia Yang, Gerhard P. Hancke 0002, Aikaterini Mitrokotsa |
WISEC | 2 |
| 2015 | A secure and efficient Ciphertext-Policy Attribute-Based Proxy Re-Encryption for cloud data sharing
Kaitai Liang, Man Ho Au, Joseph K. Liu, Willy Susilo, Duncan S. Wong, Guomin Yang, Yong Yu 0002, Anjia Yang |
Future Gener. Comput. Syst. | 8 |
| 2015 | A new unpredictability-based radio frequency identification forward privacy model and a provably secure constructionabstractAbstract The privacy model of radio frequency identification (RFID) systems is for formalizing the adversarial capabilities and the security requirements of RFID anonymity and untraceability. Existing unpredictability‐based privacy models such as unp‐privacy, eunp‐privacy, unp*‐privacy, and unpτ‐privacy have captured different kinds of practical attacks, and some of them also have mutual authentication included. However, forward privacy, which allows a tag to remain untraceable even after its corruption, is yet to be well captured in any unpredictability‐based privacy models. In this paper, we describe some forward privacy‐related attacks that can be launched against RFID tags in practice. We then propose a new unpredictability‐based forward privacy model called unpfτ‐privacy. It extends an existing one called unpτ‐privacy, which has been shown to be stronger than ind‐privacy, unp‐privacy, and unp*‐privacy. We also propose an RFID protocol that supports forward privacy and mutual authentication. We show that it can be proven secure in the unpfτ‐privacy model. Copyright © 2015 John Wiley & Sons, Ltd. Anjia Yang, Kaitai Liang, Yunhui Zhuang, Duncan S. Wong, Xiaohua Jia |
Secur. Commun. Networks | 1 |
| 2013 | A New Unpredictability-Based RFID Privacy Model
Anjia Yang, Yunhui Zhuang, Duncan S. Wong, Guomin Yang |
NSS | 1 |
| 2013 | A Highly Efficient RFID Distance Bounding Protocol without Real-Time PRF Evaluation
Yunhui Zhuang, Anjia Yang, Duncan S. Wong, Guomin Yang |
NSS | 2 |
| 2012 | An Efficient Single-Slow-Phase Mutually Authenticated RFID Distance Bounding Protocol with Tag Privacy
Anjia Yang, Yunhui Zhuang, Duncan S. Wong |
ICICS | 1 |