VLDB 2026 Research / reviewers in the wild / expert
Hua Guo 0001
dblp:12/5941-1
· DBLP profile ↗
35ranked-venue papers
11as first author
15since 2021 · last 2026
0000-0002-6719-8846ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 4 first-author · 8 since 2021Computer networks · 7 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-authorSystems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-authorTheory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Secure and Efficient Handover Authentication and Key Agreement Protocol in Fog Computing
Yiran Han, Jianwei Liu 0001, Hua Guo 0001, Zongxiao Li, Shanyao Ren |
SACMAT | 3 |
| 2026 | Practical Multi-Party Private Set Intersection with Reducible Zero-Sharing
Yewei Guan, Hua Guo 0001, Man Ho Au, Jiarong Huo, Zhenyu Guan 0002 |
SP | 2 |
| 2026 | An ultra-lightweight PUF and ASCON-based authentication and key agreement protocol for UAV-ground station and UAV-UAV communicationabstractAbstract Unmanned aerial vehicles (UAVs) have been increasingly integrated into diverse domains such as environmental monitoring, intelligent transportation, border surveillance, and military reconnaissance, giving rise to the broader concept of the Internet of Drones (IoD). However, this rapid proliferation also underscores the urgent need for secure and efficient communication mechanisms, as UAVs typically operate over public channels that are highly vulnerable to various security and privacy threats. To address these issues, authentication and key agreement (AKA) protocols have been introduced to enhance secure communication. However, most of the existing AKA protocols either incur high computation cost due to complex cryptographic primitives, or fail to provide resilience against attacks such as replay, impersonation, and ephemeral secret leakage. In this paper, we propose an ultra-lightweight AKA protocol that integrates physical unclonable function (PUF) with the lightweight authenticated encryption with associated data (AEAD) primitive ASCON. The protocol supports UAV registration over open channels, achieves mutual authentication between UAV and ground station, and extends to secure UAV-UAV communication with the assistance of the ground station. A formal proof under the real-or-random (ROR) model demonstrates the semantic security of the proposed protocol, while informal analysis confirms robustness against diverse attacks. Comprehensive performance evaluation shows that the total computation cost of the proposed protocol is approximately 2.391 ms, which is the lowest among the compared schemes. Specifically, it reduces computation cost by up to 69.0% compared with representative IoD authentication protocols and remains approximately 10.9% lower than existing ultra-lightweight designs. These results demonstrate that the proposed protocol achieves a superior balance between security strength and resource efficiency, making it particularly suitable for resource-constrained IoD environments. Hua Guo 0001, Jianwei Liu 0001, Yiran Han, Hutao Song |
Cybersecur. | 2 |
| 2026 | A resource-efficient authentication and key agreement protocol for smart gridabstractAbstract Smart grid (SG) facilitates our lives by providing more reliable electricity and enabling better integration of renewable energy sources. Currently, numerous authentication and key agreement (AKA) protocols have been proposed to secure SG communication. However, these solutions often result in considerable cost, making them inappropriate for resource-constrained SG environment. In this paper, we propose a secure and resource-efficient AKA protocol by employing lightweight cryptography primitives including authenticated encryption with associated data (AEAD) primitive ASCON, hash function and XOR operation. The ASCON primitive simultaneously provides data confidentiality, integrity and authenticity with low computation cost, making it suitable for employing in resource-constrained SG environment. The secret intermediate values in the protocol are designed as hash values that incorporate both long-term and short-term secrets, thereby providing enhanced security while further reducing cost. Moreover, a dynamic indexing method is deployed in the protocol to resist de-synchronization attack. The designed protocol performs secure mutual authentication and session key establishment between entities without relying on a central trusted authority. The proposed protocol is proven secure through rigorous security proof under the real-or-random model and formally verified by AVISPA tool. Theoretical performance analysis and simulation results indicate that the proposed protocol outperforms other related protocols due to its lightweight nature and adherence to all fundamental security attributes, making it suitable for deployment in smart grid environment. Hua Guo 0001, Hutao Song, Yapeng Wu, Jianwei Liu 0001, Yiran Han |
Cybersecur. | 2 |
| 2026 | New permutation polynomials with coefficients 1 over finite fields and their compositional inverses
Hutao Song, Hua Guo 0001, Fengju Gao, Xiyong Zhang, Jianwei Liu 0001 |
Frontiers Comput. Sci. | 2 |
| 2026 | Some Flaws of Authentication and Key Agreement Protocols Against Ephemeral Secret Leakage Attack for Smart GridabstractThe increasing complexity of the smart grid raises significant concerns regarding the security of smart grid communication. As a countermeasure, authentication and key agreement (AKA) protocol ensures the secure transmission of sensitive information between legitimate entities by achieving mutual authentication and establishing session keys. One of the most urgent and critical security threats in AKA protocol concerns ephemeral secret leakage (ESL) attack, due to its threat to session key secrecy. However, there remains a lack of systematic understanding of how to resist ESL attacks in smart grid environment. Therefore, we categorize the ESL attack into three different types, then conduct an in-depth analysis of their root causes and propose corresponding recommendations to mitigate it. To further illustrate the effectiveness of the recommendations, we design a secure and efficient AKA protocol based on elliptic curve cryptography accordingly. The proposed protocol is proven secure through rigorous security proof under the random oracle model and formally verified by AVISPA tool. Performance comparisons indicate that the proposed protocol outperforms other related protocols due to its lightweight nature and adherence to all fundamental security attributes, making it well-suited for deployment in resource-constrained smart grid environment. Hua Guo 0001, Jianwei Liu 0001, Yiran Han, Hutao Song |
IEEE Internet Things J. | 2 |
| 2026 | Cryptanalysis of "Multi-Party Private Set Intersection With One-Round Online Interaction"abstractIn this letter, we identify critical vulnerabilities in both protocols proposed by Zhao et al. (published in IEEE TIFS, doi: 10.1109/TIFS.2025.3574993), showing that they are susceptible to collusion attacks. In the first protocol, the leaderP1can determine whether its items are held by any honest party by colluding with other participants. In the second protocol,P1can infer whether all honest parties hold a specific item without any collusion, violating the fundamental privacy guarantees of multi-party private set intersection. Yewei Guan, Hua Guo 0001, Jiarong Huo |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | An Efficient and Secure Authentication and Key Agreement Protocol for Multi-Device Scenarios in Fog ComputingabstractThe fog computing paradigm enables mobile users to seamlessly interact with crowds of nearby IoT devices for low-latency services. However, existing authentication and key agreement (AKA) protocols suffer from critical limitations in this mobile context. While existing AKA schemes are optimized for mobile edge environments, they incur substantial overhead in multi-device scenarios: they require repeated authentication for each device and generate distinct session keys per user-device pair, leading to high key management complexity at scale. Furthermore, traditional one-to-many protocols are unsuitable for distributed fog environments due to their reliance on trusted central nodes (e.g., gateways or servers) and incompatible communication models. To address these issues, this paper proposes an efficient and secure authentication protocol for fog computing that integrates elliptic curve cryptography with secret sharing. Our solution enables a user to authenticate an entire group of devices managed by a semi-trusted fog node (honest-but-curious) through a single protocol execution, effectively eliminating the authentication bottleneck caused by scaling devices. Formal security proof under the Real-Or-Random (ROR) model is provided, along with informal analysis, demonstrating the protocol ensures forward secrecy, user anonymity, and resistance to a comprehensive set of attacks, including ephemeral secret leakage, key compromise impersonation, and replay attacks. Performance analysis confirms the scheme maintains low communication and computational overhead while achieving comprehensive security. Yiran Han, Jianwei Liu 0001, Hua Guo 0001, Zongxiao Li, Shanyao Ren |
IEEE Trans. Mob. Comput. | 3 |
| 2025 | Unbalanced Private Computation on Set Intersection with Reduced Computation and Communication
Zelin Tang, Hua Guo 0001, Yewei Guan, Kaijie Yang |
ICICS (1) | 2 |
| 2025 | East: Efficient and Accurate Secure Inference Framework for TransformerabstractTransformer has been successfully used in practical applications due to its powerful advantages. However, users' input is leaked to the model provider during the service. With people's attention to privacy, privacy-preserving Transformer inference is on the demand of such services. Secure protocols for non-linear functions are crucial in privacy-preserving Transformer inference, which are not well studied. Thus, designing practical secure protocols for non-linear functions is hard but significant to model performance. In this work, we propose a frameworkEastto enable efficient and accurate secure Transformer inference. Firstly, we propose a new oblivious piecewise polynomial evaluation algorithm and apply it to the activation functions, which reduces the runtime and communication of GELU by over 1.5× and 2.5×, compared to prior arts. Secondly, the secure protocols for softmax and layer normalization are carefully designed to faithfully maintain the desired functionality. Thirdly, several optimizations are conducted in detail to enhance the overall efficiency. We appliedEastto BERT and the results show that the inference accuracy remains consistent with the plaintext inference without fine-tuning. Compared to Iron, we achieve about 1.8× lower communication within 1.2× lower runtime. Yuanchao Ding, Hua Guo 0001, Yewei Guan, Weixin Liu 0003, Jiarong Huo, Zhenyu Guan 0002, Xiyong Zhang |
IEEE Trans. Serv. Comput. | 2 |
| 2024 | An Enhanced Multifactor Authentication and Key Agreement Protocol in Industrial Internet of ThingsabstractThe Industrial Internet of Things (IIoT) is the application of the Internet of Things (IoT) in the industrial field. IIoT allows users to remotely access industrial equipment and the data in it, which also brings certain challenges to the security of industrial data. Authentication and key agreement protocols are very effective security technologies in the matter of protecting industrial data. There is a large amount of research work on authentication protocols in IIoT, but most of the protocols have security weaknesses. Recently, Rafique et al. proposed a multi-factor protocol in IIoT that can accomplish authentication and session key establishment through a gateway. Rafique et al. claimed that their protocol is secure, unfortunately, we carefully analyze the protocol of Rafique et al. and find some security flaws, i.e., it is vulnerable to insider attack and known session-specific temporary information (KSSTI) attack, and unable to provide forward security. We explore the factors of insecurity and propose an enhanced multi-factor secure authentication and key agreement protocol in IIoT. The new protocol improves the security of the protocol while using only symmetric cryptography, hash function, and XOR operation. Formal security analysis and informal security discussions demonstrate that the new protocol is resistant to a variety of known attacks. After performance analysis, our protocol has lower computational cost, and increases no significant communication cost, while providing more secure and robust properties. Yiran Han, Hua Guo 0001, Jianwei Liu 0001, Brou Bernard Ehui, Yapeng Wu |
IEEE Internet Things J. | 2 |
| 2024 | A Security-Enhanced Authentication and Key Agreement Protocol in Smart GridabstractWith the enablement of Internet of Things technology, the electrical grid is currently undergoing a drastic revolution, which is known as smart grid. Since massive sensitive data and control commands transmitted via public channels, the smart grid is challenged by various cyber threats. Authenticated key agreement protocols in smart grid effectively ensure the confidentiality and authentication of communication through mutual authentication and establishing session keys. In this article, we review the existing elliptic curve cryptography (ECC)-based authentication and key agreement protocols in smart gird and perform a security analysis of Hu et al.’s protocol. We exhibit that the protocol fails to resist key compromise impersonation (KCI) attack and cannot provide untraceability. Furthermore, we propose a security-enhanced authentication and key agreement protocol based on ECC, which performs registration, authentication, and key agreement phases over public channels to enable mutual authentication and to establish session keys. The protocol is also proved to be security-enhanced by formal proof and informal analysis. The performance analysis results demonstrate that the proposed protocol is comparable to other existing protocols while achieving enhanced security. Therefore, the protocol satisfies the deployment requirements for resource-constrained smart grid. Yapeng Wu, Hua Guo 0001, Yiran Han, Jianwei Liu 0001 |
IEEE Trans. Ind. Informatics | 2 |
| 2023 | A novel two-factor multi-gateway authentication protocol for WSNs
Chen Chen 0094, Hua Guo 0001, Yapeng Wu, Jianwei Liu 0001 |
Ad Hoc Networks | 2 |
| 2022 | Cryptanalysis of a white-box SM4 implementation based on collision attackabstractAbstract White‐box cryptography is to primarily protect the key of a cipher from being extracted in a white‐box scenario, where an adversary has full access to the execution environment of software implementation. Since the introduction of white‐box cryptography, a number of white‐box implementations of the Chinese SM4 block cipher standard have been proposed, and all of them have been attacked based on Billet et al.’s attack. In this study, we show that collision‐based attack can work more efficiently on Shi et al.’s white‐box SM4 implementation than the previously published attacks, by devising an attack with a time complexity of , significantly reducing the previously known time complexity of to a very practical level. Our attack can also be similarly applied to some other white‐box SM4 implementations. Rusi Wang, Hua Guo 0001, Jiqiang Lu, Jianwei Liu 0001 |
IET Inf. Secur. | 2 |
| 2021 | A Secure Distance-Bounding Protocol with Mutual AuthenticationabstractDistance-bounding protocol is a useful primitive in resisting distance-based attacks. Currently, most of the existing distance-bounding protocols usually do not take the reuse of nonces in designing the protocols into consideration. However, there have been some literature studies showing that nonce repetition may lead to the leakage of the shared key between protocol participants. Aikaterini et al. introduced a countermeasure that could serve as a supplementary in most distance-bounding systems allowing nonce repetition. However, their proposal only holds against passive attackers. In this paper, we introduce an active attack model and show that their countermeasure is insecure under the proposed active attack model. We also discover that all existing distance-bounding protocols with mutual authentication are vulnerable to distance-based attacks if a short nonce is applied under the proposed active model. To address this security concern, we propose a new distance-bounding protocol with mutual authentication to prevent distance-based attacks under the active adversary model. A detailed security analysis is presented for the proposed distance-bounding protocol with mutual authentication. Weiwei Liu 0005, Hua Guo 0001, Yangguang Tian |
Secur. Commun. Networks | 2 |
| 2020 | A unified framework of identity-based sequential aggregate signatures from 2-level HIBE schemes
Zhoujun Li 0001, Hua Guo 0001 |
Inf. Sci. | 3 |
| 2019 | A secure and efficient three-factor multi-gateway authentication protocol for wireless sensor networks
Hua Guo 0001, Tongge Xu, Xiyong Zhang, Jianfeng Ye |
Ad Hoc Networks | 1 |
| 2018 | Self-healing group key distribution protocol in wireless sensor networks for secure IoT communications
Hua Guo 0001, Yandong Zheng, Xiong Li 0002, Zhoujun Li 0001, Chunhe Xia |
Future Gener. Comput. Syst. | 1 |
| 2018 | A Secure Three-Factor Multiserver Authentication Protocol against the Honest-But-Curious ServersabstractThree‐factor multiserver authentication protocols become a prevalence in recent years. Among these protocols, almost all of them do not involve the registration center into the authentication process. To improve the protocol’s efficiency, a common secret key is shared among all severs, which leads to a serious weakness; i.e., we find that these protocols cannot resist the passive attack from the honest‐but‐curious servers. This paper takes Wang et al.’s protocol as an example, to exhibit how an honest‐but‐curious server attacks their protocol. To remedy this weakness, a novel three‐factor multiserver authentication protocol is presented. By introducing the registration center into the authentication process, the new protocol can resist the passive attack from the honest‐but‐curious servers. Security analyses including formal and informal analyses are given, demonstrating the correctness and validity of the new protocol. Compared with related protocols, the new protocol possesses more secure properties and more practical functionalities than others at a relatively low computation cost and communication cost. Hua Guo 0001, Chen Chen 0094, Xiong Li 0002, Jiongchao Jin |
Wirel. Commun. Mob. Comput. | 1 |
| 2015 | Transferable conditional e-cash with optimal anonymity in the standard modelabstractTransferable conditional electronic‐cash (e‐cash) allows the recipient of a coin in a transaction to transfer it in a later payment transaction to the third person based on the outcome not known in advance. Anonymity is a very important property for a transferable conditional e‐cash. However, none of the existed transferable conditional e‐cash achieve the optimal anonymity because of its special structure, that is, introducing transferability in the conditional e‐cash. In this study, they novelly present a transferable conditional e‐cash scheme using a totally different structure, that is, adding condition into the transferable e‐cash. Thanks to employing Groth–Sahai proofs systems and commuting signatures, the new transferable conditional e‐cash satisfies optimal anonymity. Accordingly, they present an extended security model by introducing a publisher who is responsible for publishing two outcomes of a condition. Then, they prove the new scheme's security in the standard model. Compared with the existing transferable conditional e‐cash, the efficiency of the new scheme is also improved since the size of the computation and communication is constant. Jiangxiao Zhang, Hua Guo 0001, Zhoujun Li 0001, Chang Xu 0004 |
IET Inf. Secur. | 2 |
| 2014 | Affiliation-Hiding Authenticated Asymmetric Group Key Agreement Based on Short SignatureabstractThe notion of Affiliation-Hiding Authenticated Group Key Agreement (AH-AGKA) protocols was first introduced by Jarecki et al. in CT-RSA 2007, where they presented two concrete AH-AGKA protocols. In this paper, we show that Jarecki et al.'s second protocol has some drawbacks. We propose a new affiliation-hiding protocol. Differing from Jarecki et al.'s protocol, our protocol is asymmetric. Compared with existing AH-AGKA protocols, our scheme not only exhibits the affiliation-hiding property, but also holds the properties of detectability and perfect forward secrecy. Chang Xu 0004, Hua Guo 0001, Zhoujun Li 0001, Yi Mu 0001 |
Comput. J. | 2 |
| 2013 | Ancestor Excludable Hierarchical ID-Based Encryption Revisited
Hua Guo 0001, Zhoujun Li 0001 |
NSS | 2 |
| 2013 | Efficient and dynamic key management for multiple identities in identity-based systems
Hua Guo 0001, Chang Xu 0004, Zhoujun Li 0001, Yi Mu 0001 |
Inf. Sci. | 1 |
| 2013 | New construction of affiliation-hiding authenticated group key agreementabstractABSTRACT In CT‐RSA 2007, Jarecki, Kim, and Tsudik introduced the notion of affiliation‐hiding authenticated group key agreement (AH‐AGKA) protocols and presented two concrete AH‐AGKA protocols. In this paper, we will show that these protocols have some drawbacks. We will also introduce the notion of affiliation‐hiding authenticated asymmetric group key agreement (AH‐AAGKA) and present an AH‐AAGKA protocol. AH‐AAGKA protocols allow the participants of a group to establish a common encryption key associated with several decryption keys; each of which can only be computed by the corresponding legitimate participant. Meanwhile, any party is assured that its affiliation is revealed to the participants that belong to the same group only. Compared with previous AH‐AGKA protocols, if invalid players participate in our protocol, legitimate participants can identify these invalid players. In contrast to existing AH‐AGKA protocols, our protocol holds perfect forward secrecy, which is proven in a novel security model we proposed. Additionally, we present a new privacy model to prove that our protocol achieves linkable affiliation‐hiding property. Copyright © 2012 John Wiley & Sons, Ltd. Chang Xu 0004, Hua Guo 0001, Zhoujun Li 0001, Yi Mu 0001 |
Secur. Commun. Networks | 2 |
| 2012 | Anonymous Transferable Conditional E-cash
Jiangxiao Zhang, Zhoujun Li 0001, Hua Guo 0001 |
SecureComm | 3 |
| 2012 | Affiliation-Hiding Authenticated Asymmetric Group Key AgreementabstractWe introduce the concept of Affiliation-Hiding Authenticated Asymmetric Group Key Agreement (AH-AAGKA) and construct a concrete one-round AH-AAGKA protocol. An AH-AAGKA protocol allows the participants of a group to establish a common encryption key associated with several decryption keys; each of which can only be computed by the corresponding legitimate group member. An AH-AAGKA protocol has the following privacy feature. For a member 𝒰i of a group G, if 𝒰i participates in an AH-AAGKA protocol, any protocol participant 𝒰j cannot learn whether 𝒰i is a member of G, unless 𝒰j himself is a member of group G. Our scheme demonstrates new features in comparison with other existing AH-AGKA protocols. If non-group members participate in our protocol, honest parties can identify these non-group members. Our scheme also captures Unlinkability and Perfect Forward Secrecy (PFS), which are missing in other existing schemes. We propose a novel security model to prove that our protocol holds PFS and present a new privacy model to prove that our scheme meets Affiliation-Hiding property. Chang Xu 0004, Zhoujun Li 0001, Yi Mu 0001, Hua Guo 0001 |
Comput. J. | 4 |
| 2011 | An efficient and non-interactive hierarchical key agreement protocol
Hua Guo 0001, Yi Mu 0001, Zhoujun Li 0001, Xiyong Zhang |
Comput. Secur. | 1 |
| 2011 | Provably secure identity-based authenticated key agreement protocols with malicious private key generators
Hua Guo 0001, Zhoujun Li 0001, Yi Mu 0001, Xiyong Zhang |
Inf. Sci. | 1 |
| 2011 | Authenticated key exchange protocol with selectable identitiesabstractAbstract In the traditional identity‐based cryptography, a user, who holds multiple identities, has to manage multiple private keys, where each private key is associated with an identity. In this paper, we present a key agreement protocol, which allows a single private key to map multiple public keys (identities) that are selectable by the user. That is, the established session key is associated with an arbitrary subset of identities held by the user, while the unselected identities remain secret to other participants. As a bonus, our scheme can be considered as a credential‐based key agreement, where the unique private key can be treated as a credential of the user and the user only proves that his credential is associated with some selected identities. We prove that our scheme is secure in the random oracle model. Copyright © 2010 John Wiley & Sons, Ltd. Hua Guo 0001, Yi Mu 0001, Xiyong Zhang, Zhoujun Li 0001 |
Wirel. Commun. Mob. Comput. | 1 |
| 2009 | An Efficient Certificateless Encryption Scheme in the Standard ModelabstractWe propose an efficient certificateless public key encryption (CL-PKE) scheme which is provably secure against chosen ciphertext attacks without random oracles. Our scheme is more computationally efficient than the existing schemes and provides the shortest public key length compared to other existing CL-PKEs with random oracles. We also propose a practical self-generated-certificate encryption (SGC-PKE) scheme based on our CL-PKE scheme. One of merits of such cryptographic systems is that it can be applied to countermeasure "Denial-of-Decryption (DoD) Attacks" that is inherent in CL-PKE. Hua Guo 0001, Xiyong Zhang, Yi Mu 0001, Zhoujun Li 0001 |
NSS | 1 |
| 2009 | Server-Controlled Identity-Based Authenticated Key Exchange
Hua Guo 0001, Yi Mu 0001, Xiyong Zhang, Zhoujun Li 0001 |
ProvSec | 1 |
| 2009 | Novel and Efficient Identity-Based Authenticated Key Agreement Protocols from Weil Pairings
Hua Guo 0001, Yi Mu 0001, Xiyong Zhang, Zhoujun Li 0001 |
UIC | 1 |
| 2008 | Cryptanalysis of simple three-party key exchange protocol
Hua Guo 0001, Zhoujun Li 0001, Yi Mu 0001, Xiyong Zhang |
Comput. Secur. | 1 |
| 2006 | A Note of Perfect Nonlinear Functions
Xiyong Zhang, Hua Guo 0001, Jinjiang Yuan |
CANS | 2 |
| 2006 | Nonexistence of a Kind of Generalized Perfect Binary Array
Xiyong Zhang, Hua Guo 0001, Wenbao Han |
SETA | 2 |