VLDB 2026 Research / reviewers in the wild / expert
Lu Wei 0003
dblp:12/2554-3
· DBLP profile ↗
31ranked-venue papers
10as first author
29since 2021 · last 2026
0000-0003-3386-609XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 13 · 5 first-author · 12 since 2021Security and privacy · 9 · 4 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 1 first-author · 7 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | BliChain: A Blockchain-Assisted and Lightweight Cross-Domain Authentication Scheme for 6G-Enabled VANETabstractIn the evolution of 6G-based Vehicular Ad-hoc Networks (VANETs) from closed single-domain environments to open cross-domain environments, several security challenges arise, including heterogeneous domain trust barriers, vehicle identity privacy leakage, and high authentication overhead in dynamic scenarios. Existing schemes based on centralized public key infrastructure (PKI) suffer from single point failure risks and have difficulty balancing low latency with conditional privacy preservation. Meanwhile, blockchain-assisted solutions are often constrained by on-chain storage expansion and high computational overhead. To address these issues, this paper proposes a blockchain-assisted anonymous authentication scheme for 6G-VANETs. The proposed scheme uses blockchain to construct distributed trust anchors and enable secure sharing of public parameters across domains. By generating lightweight authentication parameters based on Lagrange interpolation polynomials, the scheme supports direct mutual authentication and session key agreement between vehicles without requiring massive certificate-related on-chain transactions. In addition, a pseudo-identity mechanism is introduced to achieve conditional privacy preservation, thereby balancing vehicle identity privacy and traceability. Security analysis demonstrates that the proposed scheme satisfies the required security properties under the random oracle model. Performance evaluation shows that compared with existing solutions, the proposed scheme significantly reduces computational overhead by 22.31%, 11.02%, and 29.19%, respectively, and communication overhead by 51.2%, 20.08%, and 24.61%, respectively. Jiaxin Li 0001, Hong Zhong 0001, Lu Wei 0003, Irina Pavlovna Bolodurina, Jie Cui 0004 |
IEEE Internet Things J. | 4 |
| 2026 | Privacy-Accountable Distributed Collaborative Authentication for Malicious Node Resistance in Vehicular Ad Hoc NetworksabstractIn vehicular ad hoc networks (VANETs), distributed identity authentication provides the foundation for securing sessions among entities over wireless channels while eliminating single points of failure. However, existing distributed authentica tion schemes for VANETs typically make unrealistic assumptions about node reliability and trustworthiness, failing to account for scenarios where authentication nodes may be compromised or collude with vehicles. Moreover, these schemes expose the com munication process to linkability attacks while allowing vehicles to self-register their public keys. To address these limitations, we propose a privacy-preserving and accountable distributed collab orative authentication scheme for VANETs that is resilient to ma licious nodes. Using threshold signature techniques, distributed authentication nodes collaboratively perform decentralized ve hicle identity authentication using a predefined threshold. Zero knowledge proof protects the privacy of the signing process while maintaining accountability and effectively preventing malicious behavior by nodes under external or internal adversarial attacks. Furthermore, vehicles self-register their public keys via smart contracts and blockchain technology, ensuring anonymity and unlinkability during registration while enabling the traceability of malicious vehicles. Security and performance analyses show that the proposed scheme enhances the security and robustness of distributed collaborative authentication in VANETs, achieving a better balance between computational and communication costs than existing schemes Ru Li 0005, Jie Cui 0004, Lu Wei 0003, Irina Pavlovna Bolodurina, Jing Zhang 0024, Hong Zhong 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Blockchain-Based Asynchronous Authentication and Key Agreement Scheme for Securing VANETsabstractIn vehicular ad hoc networks (VANETs), authentication and key agreement (AKA) protocols are crucial for establishing secure authentication and session keys for network communications, ensuring security for short-term vehicle interactions. However, traditional VANETs AKA schemes heavily rely on centralized trust architectures. This dependence raises significant concerns about overall system security and resilience, especially when these schemes operate over insecure wireless channels. Although recent studies have introduced decentralized architectures to mitigate this issue, a key limitation remains. These approaches typically assume synchronous network environments, which in practice limits their true decentralization capabilities in dynamic VANETs. To address these challenges, we propose a decentralized and asynchronous AKA scheme based on a consortium blockchain that enables the execution of the key agreement process in asynchronous VANETs environments. Furthermore, we employ lightweight cryptographic techniques combined with a Cuckoo filter to optimize computational efficiency, reduce communication overhead, and minimize on-chain storage costs. Security analyses and simulation experiments demonstrate that the proposed scheme delivers robust security and high performance under realistic network conditions. Lu Wei 0003, Yujia Zhong, Jie Cui 0004, Irina Pavlovna Bolodurina, Jiaxin Li 0001, Hong Zhong 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Post-Quantum Secure Authenticated Key Agreement Scheme for Vehicular Digital Twin
Jie Cui 0004, Jiyu Liu, Lu Wei 0003, Irina Pavlovna Bolodurina, Jiaxin Li 0001, Hong Zhong 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2026 | Blockchain-Assisted Message Reporting Scheme With Weighted Threshold Signature for Vehicular Ad-Hoc NetworksabstractIn vehicular ad-hoc networks (VANETs), message reporting is an effective method for improving traffic safety and efficiency. Most existing VANET message reporting schemes rely on the trust value of a single vehicle to determine message authenticity, which leads to unreliable message sources. Even multi vehicle-assisted reporting schemes are limited by the assumption that all vehicles have the same credibility, which does not reflect the actual dynamic VANET environment in which vehicles have different credibilities. To address this issue, we propose a blockchain-assisted VANET message reporting scheme with weighted threshold signatures. Through the design of weights, the credibility of different vehicles is quantified, and the impact of vehicles on the signing process is differentiated. Threshold signature generation relies on the weight sum of all signatories reaching a predetermined threshold, to enable flexible and reliable message reporting. Security analysis shows that our proposed scheme combined with blockchain can satisfy the security and privacy requirements of VANET message reporting. Performance analysis indicates that our proposed scheme outperforms the most advanced VANET message reporting schemes in terms of transmission and computation performance. Ru Li 0005, Jie Cui 0004, Jing Zhang 0024, Lu Wei 0003, Hong Zhong 0001, Debiao He |
IEEE Trans. Mob. Comput. | 4 |
| 2026 | Game Theory and Trust Management Driven Dynamic Proof-of-Work Blockchain Consensus Algorithm for Securing Internet of Vehicles
Lu Wei 0003, Yuanzhi Cao, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Mob. Comput. | 1 |
| 2026 | Toward Stable and Low-Latency Task Offloading: A Multi-Agent Framework for Vehicular Edge Computing
Lu Wei 0003, Jie Cui 0004, Xianfeng Xie, Jing Zhang 0024, Irina Pavlovna Bolodurina, Hong Zhong 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2025 | Blockchain-Assisted Revocable Cross-Domain Authentication for Vehicular Ad-Hoc NetworksabstractWith the rapid development of vehicular ad-hoc networks (VANETs) and the increasing diversification of user demands, interactions between different management domains have become more frequent. Identity authentication is an effective way to establish cross-domain trust and secure communication. However, the existing cross-domain authentication schemes of VANETs are limited to the same management or authentication technology for each domain and rely on centralized cross-domain identity management. Even distributed management solutions encounter latency sensitivity, security and privacy challenges. To address these challenges, we propose a blockchain-assisted revocable cross-domain authentication scheme for VANETs. The proposed scheme can establish trust between domain entities by deploying different authentication methods and using distributed management to avoid single-point failures. In addition, the scheme can revoke the identity of malicious vehicles by updating the group public key, thereby ensuring the security and privacy of cross-domain Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I) communication. This design avoids the additional impacts of blockchain technology constraints on the high mobility and real-time requirements of VANETs. Security analysis and performance evaluation show that our scheme can resist more attacks and has better security than other related schemes while also achieving a better balance between communication and computational cost. Ru Li 0005, Jie Cui 0004, Jing Zhang 0024, Lu Wei 0003, Hong Zhong 0001, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | DBCSec: DBC File-Guided Secure Communication Mechanism for CAN-FD BusabstractThe network architecture of modern vehicles is composed of multiple communication protocols and electronic control units (ECU). Compared to the widely used protocol of Controller Area Network (CAN), CAN with Flexible Data-Rate (CAN-FD) protocol is suitable for applications requiring higher data throughput. However, the CAN-FD bus is vulnerable to intrusion by external attackers. Nowadays, several secure mechanisms have been proposed to protect the security of in-vehicle data. However, there are still two issues: 1) Most schemes use a centralized controller for key distribution, which can easily lead to a single point of failure; 2) The existing key management modes are not suitable for real-world CAN-FD networks in vehicle manufacturing. To address these issues, we propose a lightweight semi-decentralized scheme based on Database CAN (DBC) files to secure in-vehicle communication. ECUs are grouped on the send-receive relationships set in the DBC file, considering both the communication mode and sending efficiency. Furthermore, the proposed scheme overcomes reliance on long-term keys. Moreover, the security is analyzed by the random oracle model. The performance analysis is evaluated on microcontroller units (MCU) STM32H743IIT and Raspberry Pi 3B. The proposed scheme optimizes the computational costs of authentication, key agreement, and secure communication stages by up to 97.89%, 99.95%, and 82.35%, and optimizes the communication costs by up to 75.52%, 98.42%, and 29.41% compared to existing methods. Simulation experiments demonstrate that the bus load of the scheme increases by up to 9.84% compared to the baseline network. Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Qingyang Zhang 0001, Lu Wei 0003, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | BAST: Blockchain-Assisted Secure and Traceable Data Sharing Scheme for Vehicular NetworksabstractIn vehicular networks, caching service content on edge servers (ESs) is a widely accepted strategy for promptly responding to vehicle requests, reducing communication overhead, and improving service experience. However, implementing such an architecture requires addressing the challenges associated with ES response data reliability and communication security. In this study, to tackle the ES response data reliability issue, a blockchain-assisted threshold signature scheme for cache-based vehicular networks is proposed. The scheme utilizes a threshold mechanism to sign the data broadcast by the ES, incorporates blockchain to trace malicious signers, and avoids the shortcomings and limitations associated with idealized assumptions for the ES in existing data-sharing schemes. Moreover, considering the communication security and high-speed mobility of vehicles, using the non-interactive signatures of knowledge based on the Σ-protocol, a secure and efficient message authentication scheme for vehicles and ESs is provided. Through rigorous security proofs and comprehensive analyses, our scheme satisfies the communication security requirements of vehicular networks. By leveraging the JPBC library for performance analysis, the proposed scheme demonstrates advantages as concerns both computation and communication overheads compared to related schemes. Moreover, we implemented the proposed scheme on an Ethereum test network (i.e., Goerli) to validate its feasibility. Xinzhong Liu 0002, Jie Cui 0004, Jing Zhang 0024, Rongwang Yin, Hong Zhong 0001, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | A Blockchain-Driven Hierarchical Authentication and Key Agreement Scheme for VANETs With Cloud-Edge CollaborationabstractVehicular ad-hoc networks (VANETs) are the cornerstone of intelligent transportation systems, designed to enhance road safety and traffic efficiency. However, their dynamic and distributed nature poses significant challenges for secure communication and key management. Traditional authentication and key agreement (AKA) schemes for VANETs often rely on centralized trust architectures, resulting in system security and reliability issues. Despite the introduction of distributed trust architecture schemes that have appeared recently, they fail to solve one issue, i.e., how the key agreement requests can be authenticated in the distributed communication scenario where the authentication authorities are all non-full-credible and have differentiated credibility. To solve this issue, we propose a hierarchical AKA scheme for VANETs with cloud-edge collaboration powered by consortium blockchain. Specifically, we first proposed a vehicle reputation evaluation algorithm for evaluating the trustworthiness of the vehicle, so that the AKA requests sent by vehicles with low reputation will be rejected. On the basis of the reputation evaluation algorithm, we proposed a hierarchical threshold-based AKA scheme for VANETs where cloud servers (CSs) and edge servers (ESs) can collaboratively authenticate the AKA requests, so that the authentication service can be trusted upon getting authenticated by a series of valid combinations of CSs and ESs. Both formal and informal security proofs validate the security of our proposed scheme, and simulation experiments demonstrate its efficiency. Lu Wei 0003, Yongjuan Zhang, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | False Message Detection System for VANETs: A Reputation Evaluation Method Based on Voting MechanismabstractVehicular ad hoc networks (VANETs) enable vehicles to engage in vehicle-to-vehicle and vehicle-to-infrastructure communications to enhance driving safety. However, the open nature of the network and the uncertainty of information sources make VANETs vulnerable to false message attacks, potentially causing severe traffic accidents. Existing false-message detection systems suffer from high false alarm rates and high resource consumption. To address these challenges, we propose a false message attack detection system based on a software-defined network architecture that can efficiently and accurately detect false message attacks with minimal consumption of system resources. The system aims to detect emergency and normal beacon messages broadcast by vehicles, construct an automotive reputation evaluation system using the voting mechanism of the Byzantine consensus, and introduce an XGBoost-based traffic event classifier to improve classification accuracy. Experimental results show that the system can reliably assess vehicle reputation levels, effectively defend against conspiracy attacks, and perform well in intrusion detection. Jie Cui 0004, Danting Yu, Jing Zhang 0024, Lu Wei 0003, Xianfeng Xie, Irina Pavlovna Bolodurina, Hong Zhong 0001 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2025 | Sustainable Learning-Based Intrusion Detection System for VANETsabstractVehicular intrusion detection systems (VIDSs) play a crucial role in protecting the security of vehicular ad hoc networks (VANETs). Recently, numerous researchers have proposed effective vehicular intrusion detection systems to protect the security of VANETs. However, some existing vehicle intrusion systems are susceptible to catastrophic forgetfulness in the process of implementing incremental updates to target novel attacks. Other solutions lack consideration for the continuous updating capabilities of vehicle intrusion detection systems. It is worth mentioning that in the real world, the network attacks suffered by vehicles are not constant, and fixed intrusion detection systems may struggle to detect new network attacks effectively. To address these challenges, we propose an incremental learning-based vehicular intrusion detection scheme that supports continuous updating of the intrusion detection system. Specifically, we design a sample gradient optimization algorithm to enhance the data quality of training samples. Additionally, we utilize locally stored historical data to balance the number of old attack classes for model distillation, thus mitigating the problem of forgetting the old classes as the model learns new classes. The comprehensive experimental results on the CICIDS2017, TON_IOT, and Veremi datasets demonstrate that the proposed vehicular intrusion detection system maintains superior detection accuracy during continuous updating and surpasses the state-of-the-art solution. Lu Wei 0003, Hulin Jin, Jie Cui 0004, Jiaxin Li 0001, Debiao He |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2025 | Reputation System-Based Vehicle Violation Reporting Service With Invalid Signature Identification in VANETsabstractOwing to frequent traffic accidents, the violation reporting service is a promising method to enhance road safety in vehicular ad hoc networks (VANETs). However, to implement such a service, it is critical to ensure security, privacy, and efficiency when vehicles send messages to roadside units (RSU). In this study, to address these issues, a vehicle violation reporting service is proposed using reputation systems and a physically unclonable function. The proposed scheme ensures secure authentication between vehicles and RSUs, facilitates an efficient search for invalid signatures, and overcomes the limitations present in ID-based conditional privacy-preserving authentication schemes. Moreover, considering the dynamic VANET environment, the distribution of invalid signatures may vary across multiple scenarios. Therefore, a fault-tolerant mechanism is proposed to ensure the robustness of this approach. Security proof with the random oracle model and detailed security analysis proved that the scheme could satisfy the security requirements of VANETs. Our scheme outperforms related approaches in terms of authentication overhead and the identification of invalid signatures, achieving superior performance in both aspects. Jing Zhang 0024, Chengzhi Xia, Jie Cui 0004, Hong Zhong 0001, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2024 | Improved PBFT Consensus Based on Reputation System in Vehicle NetworkabstractBlockchain technology is a decentralized distributed database technology, which greatly improves the security and credibility of the data exchange process through decentralization. A great deal of research has already been conducted on combining blockchain and vehicular ad-hoc networks(VANETs) applications to solve the problems of opaque user transactions, data tampering, and insufficient motivation of participating parties. However, in the large-scale VANETs, the commonly used blockchain consensus mechanism PBFT suffers from poor scalability, high communication volume, and insufficient control of node behaviour. Therefore, in this paper, an improved consensus mechanism N-PBFT is designed for the field of VANETs based on the construction of vehicle trust management system. The improved consensus mechanism N-PBFT solves the problems of node identity peering, poor scalability, and high communication volume. After experimental testing, the proposed reputation system is able to effectively manage the information of the VANETs. And the improved PBFT consensus algorithm has a significant performance improvement over the traditional PBFT, SG-PBFT and RIPPB in terms of both throughput and latency. Jing Zhang 0024, Peiyv Yang, Jie Cui 0004, Lu Wei 0003, Hong Zhong 0001 |
BDCAT | 4 |
| 2024 | Multi-Authority Ciphertext-Policy Attribute-based Encryption with Hidden Policy for Securing Internet-of-VehiclesabstractWith the rapid development of the Internet-of-Vehicles (IoV) technologies, security and privacy issues associated with IoV data sharing have become increasingly prominent. Although attribute-based encryption (ABE) schemes offer effective solutions to these problems, the prevalent single-point failure vulnerabilities and risks of user privacy leakage in existing ABE schemes must be addressed. To this end, an original hidden policy scheme based on multi-authority ciphertext policy ABE is proposed. This scheme validates users by introducing multiple attribute authorities and generating intermediate attribute keys, effectively dispersing single-point performance pressure. Simultaneously, partial policy-hiding techniques are developed to ensure efficient system operation while protecting user privacy. Furthermore, this scheme introduces a central authority to track potentially malicious attribute authorities, preventing them from continuously generating incorrect attribute intermediate keys, thereby maintaining the overall security of the system. Additionally, by updating and revoking attribute versions, a flexible attribute revocation mechanism is achieved to further enhance system flexibility. Through in-depth security and performance analyses, the scheme is proven to be both secure and efficient for securing IoV. Jie Cui 0004, Jing Zhang 0024, Lu Wei 0003, Hong Zhong 0001, Geyong Min |
TrustCom | 3 |
| 2024 | CVAR: Distributed and Extensible Cross-Region Vehicle Authentication With Reputation for VANETsabstractThis study proposes a distributed and extensible cross-region vehicle authentication scheme with the reputation for improving the security and efficiency of cross-region vehicle authentication. The existing authentication schemes demonstrate the following drawbacks: 1) Each vehicle is preloaded with the same system private key, which may be leaked so that the entire system would be destroyed; 2) Other schemes rely on trusted authority to aid in selecting some cluster head nodes; 3) The existing cross-region authentication schemes are not flexible and scalable since they depend on the infrastructure fixed on the roadside. With the proposed scheme, each vehicle stores a long-term private key that is different from those of other vehicles, thereby avoiding a system crash when destroying a vehicle. When the cross-region vehicle enters a new region, it can verify the reputation value of the surrounding vehicles to select the edge computing vehicle. The formal security proof shows that the proposed scheme has adequate security under the real-or-random model. The performance evaluation of our scheme with several related schemes reveals that it generates relatively low computation and communication overhead, is more robust, and achieves minimum packet loss ratio and delay. Jing Zhang 0024, Hong Zhong 0001, Jie Cui 0004, Lu Wei 0003, Lu Liu 0001 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2024 | LH-IDS: Lightweight Hybrid Intrusion Detection System Based on Differential Privacy in VANETsabstractVehicular Ad hoc Networks (VANETs) are vulnerable to various types of attacks. Intrusion Detection System (IDS) based on machine learning can effectively detect malicious network attacks in VANETs. However, machine learning training necessitates ample data which contain significant ample private information, increasing the risk of privacy disclosure. The privacy protection of training data for machine learning used in the IDS of VANETs is rarely investigated. Meanwhile, Differential Privacy (DP) is one of the most secure privacy protection methods based on perturbations. Therefore, we propose a lightweight hybrid IDS (LH-IDS) based on machine learning and DP. It uses algorithms based on unsupervised learning to detect anomalous network behaviour with high performance, especially unknown attacks in VANETs, while protecting data privacy. The DP is used to secure the privacy of the training data. Noise from different privacy budgets is added to datasets to obtain DP datasets. Subsequently, LH-IDS is used to verify the utility of the DP datasets. Extensive experiments confirm LH-IDS can not only detect anomalous and normal traffic with excellent performance but can also protect the private information of the training data. Additionally, the proposed model incurs only minimal CPU and memory overhead, making it a lightweight solution. Jie Cui 0004, Jietian Xiao, Hong Zhong 0001, Jing Zhang 0024, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Mob. Comput. | 5 |
| 2024 | Privacy-Preserving and Secure Distributed Data Sharing Scheme for VANETsabstractData sharing is one of the essential services of vehicular ad hoc networks (VANETs), which primarily requires data security and access control, and ciphertext-policy attribute-based encryption (CP-ABE) is a promising tool. However, data sharing schemes of distributed CP-ABE have concerns about the single-point performance bottleneck and privacy leakage. The factor for the former is that the authority manages a disjoint attribute set. The latter is because the user's identity and attributes are required to submit to authorities, which targets to bind this information to decryption keys for collusion-resistant. We propose a privacy-preserving distributed data sharing scheme for VANETs. This scheme introduces asymmetric group key agreement to distributed CP-ABE, which realizes that multiple authorities manage an attribute, and the user can obtain the attribute key bound with his identity from any authority in the group. To match up to the requirement of privacy-preserving, a key extract protocol provided user anonymity is proposed, which implements that attribute keys can be obtained without revealing the user's identity and attributes. Moreover, partial policy hiding is satisfied. Finally, we analyze and evaluate the proposed scheme, and the results indicate that our scheme is secure and efficient. Li Wang 0139, Hong Zhong 0001, Jie Cui 0004, Jing Zhang 0024, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Mob. Comput. | 5 |
| 2024 | A Decentralized Authenticated Key Agreement Scheme Based on Smart Contract for Securing Vehicular Ad-Hoc NetworksabstractSince the communication channels in vehicular ad-hoc networks (VANETs) are wireless and open, malicious adversaries can monitor or fabricate messages transmitted across them. To secure vehicular communications, an authenticated key agreement (AKA) scheme needs to be designed for VNAETs. Traditional VANETs AKA schemes require the trusted authority (TA) to authenticate the legality of message and corresponding sender. However, the TA in these schemes is vulnerable to suffer from single-point-of-failure issues. Some blockchain-based VANETs AKA schemes have been proposed recently to address the deficiency. However, these schemes rely on the consortium or private blockchain in which TAs are still required for key generation, resulting that the practicality is limited. To solve the issue, we design a smart contract-based VANETs AKA scheme, where the AKA algorithm of our proposed scheme is implemented on smart contract deployed on a public blockchain system and the TA that is responsible for key generation will not be required. The security proof and analysis show that our proposed scheme satisfies the session-key semantic security and essential security and privacy requirements, respectively. The performance analysis demonstrates that our proposed scheme outperforms existing blockchain-based VANETs AKA schemes. Lu Wei 0003, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Chengjie Gu, Debiao He |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | A Threshold-Based Full-Decentralized Authentication and Key Agreement Scheme for VANETs Powered by Consortium BlockchainabstractThe authentication and key agreement (AKA) scheme for VANETs can produce a series of short-term session keys, which can be used to secure the vehicular communications across open and insecure wireless channels. Traditional VANETs AKA schemes tend to employ the centralized trust architecture as the core authentication backend, which raises concerns about system security and reliability. Recently, several VANETs AKA schemes that are constructed on decentralized trust architecture have been proposed. However, these schemes do not achieve full decentralization and tend to suffer from key exposure issues, insufficient performance, and lack of optimization for on-chain storage costs. To address these shortcomings, we propose a threshold-based full-decentralized VANETs AKA scheme that is powered by consortium blockchain. In our proposed scheme, the threshold-based voting concept is employed to mitigate the key exposure issue inherent to the network infrastructure. Furthermore, we leverage lightweight cryptography in conjunction with the Cuckoo filter to reduce computational, communication, and on-chain operation costs brought by cryptographic operations and smart contracts. The security proof together with the cryptographic protocol validation tool prove the security of our proposed scheme, whereas the simulation experiment demonstrates the efficiency of our proposed scheme. Lu Wei 0003, Yongjuan Zhang, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | CBDDS: Secure and Revocable Cache-Based Distributed Data Sharing for Vehicular NetworksabstractIn vehicular networks, caching content on an edge server (ES) is a popular method for quickly responding to massive vehicle service requests, reducing communication delays, and enhancing driver and passenger service experiences. However, after integrating ESs with vehicular networks to provide vehicles access to the cached content in these ESs, significant challenges regarding protecting the privacy of vehicle data and communication security arise. In this study, to address security and privacy-preserving issues, we propose a secure and revocable cache-based distributed data sharing scheme for vehicular networks wherein a token authentication mechanism and multi-authority ciphertext-policy attribute-based encryption are integrated. In this scheme, both authentication and authorization capabilities are delegated to an ES while restricting access to service content to only legal vehicles, achieving proper access control between vehicles and ESs, and effectively preserving the privacy of vehicle data. Moreover, we attributed the revocations of ESs to the associated attribute authorities, eliminating the need for a system-wide update of keying materials. Through rigorous security proofs and detailed security analyses, we demonstrate that the scheme meets the security requirements of vehicular networks and can resist more security attacks. The proposed scheme achieves better balance between computational and communication costs than related schemes. Jing Zhang 0024, Xinzhong Liu 0002, Jie Cui 0004, Hong Zhong 0001, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Mob. Comput. | 5 |
| 2023 | A Lightweight and Conditional Privacy-Preserving Authenticated Key Agreement Scheme With Multi-TA Model for Fog-Based VANETsabstractRecently, the fog computing concept has been introduced into vehicular ad-hoc networks (VANETs) to formulate fog-based VANETs. Since the communication channels between vehicles and fog nodes are open and insecure, it is necessary to construct an authenticated key agreement (AKA) scheme for securing the channels. The existing AKA schemes have two main deficiencies. One is that the computational and communication overhead are not low enough to satisfy the requirements of delay-sensitive applications. The other is that the multi-trusted-authority (multi-TA) model has not been considered. To solve the deficiencies, we propose a lightweight and conditional privacy-preserving AKA scheme, where the main steps are designed with symmetric cryptography methods. The design can reduce the computational and communication overhead of the AKA process. Additionally, we consider the multi-TA model in the AKA process to solve the single-point-of-failure issue. By integrating Cuckoo filter into the multi-TA model, the secrecy of real identities of legal vehicles is guaranteed and the identity revocation function for illegal vehicles is supported in the AKA process. The security proof and analysis show that our proposed scheme satisfies the essential security and privacy requirements of VANETs. The performance analysis shows that our proposed scheme outperforms other related and represented schemes. Lu Wei 0003, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Lu Liu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Chaotic Map-Based Authentication Scheme Using Physical Unclonable Function for Internet of Autonomous VehicleabstractAutonomous Vehicles (AVs) are a highly discussed topic owing to their great performance and convenience. However, some requirements limit their wider deployment. Specifically, AV should be controlled by remote users during emergencies. It may lead to AV’s system facing the risk of being intruded on by a malicious party, resulting in unreasonable decisions. We, therefore, design the Internet of autonomous vehicle (IoAV) model to mitigate the problems arising from these limitations. To promote a secure remote control of the AV, a reliable authentication scheme, which can be used in IoAV, must be performed. Our proposed chaotic map-based authenticated key agreement (CMAKA) method provides secure remote control features for AVs. In this method, users, data centers, and AV establish a secure communication channel through the negotiation of three independent session keys. Furthermore, a physical unclonable function (PUF) is employed to produce a trusted private key during the authentication. The security of our scheme is evaluated using game hopping through the widespread Real-or-Random (ROR) model. Compared with other existing three-factor authentication schemes, the performance of our protocol is higher in both security requirements and total cost. Jie Cui 0004, Hong Zhong 0001, Lu Wei 0003, Lu Liu 0001 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2023 | Collaborative Intrusion Detection System for SDVN: A Fairness Federated Deep Learning ApproachabstractWith the continuous innovations and development in communication technology and intelligent transportation systems, a new generation of vehicular ad hoc networks (VANETs) has become increasingly popular, making VANET communication security increasingly important. An intrusion detection system (IDS) is an important tool for detecting network attacks and is an effective means of improving network security. However, existing IDSs encounter several problems involving inaccurate detections, low detection efficiencies, and incomplete detections owing to extensive changes in vehicle locations in VANETs. This study explores federated learning in software-defined VANETs and designs an efficient and accurate collaborative intrusion detection system (CIDS) model. The model utilizes the collaboration among local software-defined networks (SDNs) to jointly train the CIDS model without directly exchanging local network data flows to improve the expansibility and globality of IDSs. To reduce the model difference between different SDN clients and improve the detection accuracy, this study regards the prediction loss for each SDN client as an objective from the perspective of constrained multi-objective optimization. By optimizing a surrogate maximum function containing all the objectives, the method adopts two-stage gradient optimization to achieve Pareto optimality for SDN clients with the worst fairness constraint maximization performance. In addition, this study evaluates the training model using two open-source datasets and compares it with the latest methods. Experimental results reveal that the proposed model ensures local data privacy and demonstrates high accuracy and efficiency in detecting attacks and is thus superior to the current schemes. Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2022 | Dataset for Evaluation of DDoS Attacks Detection in Vehicular Ad-Hoc Networks
Hong Zhong 0001, Lu Wei 0003, Jing Zhang 0024, Chengjie Gu, Jie Cui 0004 |
WASA (3) | 3 |
| 2022 | Secure and Efficient Data Sharing Among Vehicles Based on Consortium BlockchainabstractThe large amount of driving data can help intelligent vehicles make decisions to drive safely, improve vehicular services and enhance driving experience. In traditional vehicular networks, data sharing needs to be done with roadside units (RSUs). However, RSUs cannot be entirely trusted and the data stored in the RSUs may be tampered with. In addition, the deployment of RSUs along roads consumes a large amount of social resources. Further, data sharing between vehicles lacks a trusted environment, and vehicles may be unwilling to share data with others because of data security and privacy concerns. Moreover, in the event of unauthorized data sharing, the source of the leaked data is difficult to trace. In this study, we exploit consortium blockchain technology to achieve traceable and anonymous vehicle-to-vehicle (V2V) data sharing, effectively preventing second-hand sharing of data. The combination of 5G and blockchain makes it possible to share data without using RSUs. We design an enhanced delegated proof-of-stake consensus algorithm to make it more suitable for applications in the distributed Internet of Vehicles (IoV). A comprehensive analysis shows that the proposed scheme is secure and efficient. Jie Cui 0004, Fenqiang Ouyang, Zuobin Ying, Lu Wei 0003, Hong Zhong 0001 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2022 | Proven Secure Tree-Based Authenticated Key Agreement for Securing V2V and V2I Communications in VANETsabstractVehicular ad hoc networks (VANETs) are vulnerable to many kinds of security attacks, so it is necessary to design an authenticated key agreement (AKA) scheme for securing communication channels in VANETs. Existing AKA schemes in VANETs have not provided an efficient and secure method to secure V2V and V2I communications simultaneously while meeting the necessary security and privacy requirements. Further, few key updating mechanisms, which are secure, conditional privacy-preserving, practical, and lightweight, exist in current VANETs AKA schemes. In this paper, we propose a proven secure AKA scheme for securing V2V and V2I communications in VANETs, which can be divided into two parts. The first part is a three-party authentication process in which vehicles, road side unit (RSU), and trust authority (TA) authenticate each other. The second part is the key agreement process, which is used in the key generation and updating processes. For this phase, we design a tree-based key agreement algorithm that considers two scenarios, i.e., the joining of an authenticated vehicle and the leaving of the vehicle. The formal security proof and the security analysis show that our proposed scheme satisfies session key security and the necessary security requirements in VANETs, respectively. The performance analysis demonstrates that our proposed scheme has an advantage over several representative AKA schemes in VANETs. Lu Wei 0003, Jie Cui 0004, Hong Zhong 0001, Yan Xu 0007, Lu Liu 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2021 | Secure and Lightweight Conditional Privacy-Preserving Authentication for Securing Traffic Emergency Messages in VANETsabstractOwing to the development of wireless communication technology and the increasing number of automobiles, vehicular ad hoc networks (VANETs) have become essential tools to secure traffic safety and enhance driving convenience. It is necessary to design a conditional privacy-preserving authentication (CPPA) scheme for VANETs because of their vulnerability and security requirements. Traditional CPPA schemes have two deficiencies. One is that the communication or storage overhead is not sufficiently low, but the traffic emergency message requires an ultra-low transmission delay. The other is that traditional CPPA schemes do not consider updating the system secret key (SSK), which is stored in an unhackable Tamper Proof Device (TPD), whereas side-channel attack methods and the wide usage of the SSK increase the probability of breaking the SSK. To solve the first issue, we propose a CPPA signature scheme based on elliptic curve cryptography, which can achieve message recovery and be reduced to elliptic curve discrete logarithm assumption, so that traffic emergency messages are secured with ultra-low communication overhead. To solve the second issue, we design an SSK updating algorithm, which is constructed on Shamir's secret sharing algorithm and secure pseudo random function, so that the TPDs of unrevoked vehicles can update SSK securely. Formal security proof and analysis show that our proposed scheme satisfies the security and privacy requirements of VANETs. Performance analysis demonstrates that our proposed scheme requires less storage size and has a lower transmission delay compared with related schemes. Lu Wei 0003, Jie Cui 0004, Yan Xu 0007, Jiujun Cheng, Hong Zhong 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Edge Computing in VANETs-An Efficient and Privacy-Preserving Cooperative Downloading SchemeabstractWith the advancements in social media and rising demand for real traffic information, the data shared in vehicular ad hoc networks (VANETs) indicate that the size and amount of requested data will continue increasing. Vehicles in the same area often have similar data downloading requests. If we ignore the common requests, the resource allocation efficiency of the VANET system will be quite low. Motivated by this fact, we propose an efficient and privacy-preserving data downloading scheme for VANETs, based on the edge computing concept. In the proposed scheme, a roadside unit (RSU) can find the popular data by analyzing the encrypted requests sent from nearby vehicles without having to sacrifice the privacy of their download requests. Further, the RSU caches the popular data in nearby qualified vehicles called edge computing vehicles (ECVs). If a vehicle wishes to download the popular data, it can download it directly from the nearby ECVs. This method increases the downloading efficiency of the system. The security analysis results show that the proposed scheme can resist multiple security attacks. The performance analysis results demonstrate that our scheme has reasonable computation and communication overhead. Finally, the OMNeT++ simulation results indicate that our scheme has good network performance. Jie Cui 0004, Lu Wei 0003, Hong Zhong 0001, Jing Zhang 0024, Yan Xu 0007, Lu Liu 0001 |
IEEE J. Sel. Areas Commun. | 2 |
| 2019 | An Efficient Message-Authentication Scheme Based on Edge Computing for Vehicular Ad Hoc NetworksabstractWith the progress in wireless communication technology and the increasing number of vehicles, vehicular ad hoc networks (VANETs) have become essential for improving road conditions and enhancing driving experience. The core of the VANETs is the communication between different vehicles, and the security of the communication is based on message authentication. Several schemes have been designed to enhance the efficiency of message authentication. However, these schemes have the disadvantage of redundant authentication, i.e., repeated authentication of the same message, and fail to seek invalid messages from the batch of messages. To solve these problems, this paper introduces a novel edge-computing concept into the message-authentication process of VANETs. In our scheme, the roadside unit can efficiently authenticate messages from nearby vehicles and broadcast the authentication results to the vehicles within its communication range, thereby reducing redundant authentication and enhancing the efficiency of the entire system. The security analysis results show that the proposed scheme satisfies the security requirements of the VANETs. The performance analysis results show that the proposed scheme can not only work well in an ideal environment where the attacker is absent but also capable of quickly identifying valid and invalid messages even if the VANET is attacked. Jie Cui 0004, Lu Wei 0003, Jing Zhang 0024, Yan Xu 0007, Hong Zhong 0001 |
IEEE Trans. Intell. Transp. Syst. | 2 |