VLDB 2026 Research / reviewers in the wild / expert
Fuchun Guo
dblp:13/93
· DBLP profile ↗
131ranked-venue papers
21as first author
56since 2021 · last 2026
0000-0001-6939-7710ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 86 · 18 first-author · 37 since 2021Applied, interdisciplinary, general and emerging computing · 11 · 2 first-author · 1 since 2021Systems, architecture and hardware · 9 · 6 since 2021Software engineering, systems software and programming languages · 8 · 1 first-author · 7 since 2021Databases, data management, data science and information retrieval · 8 · 2 since 2021Theory of computation · 6 · 2 since 2021Computer networks · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LRC-DPoR: Efficient Data Integrity Auditing with Local Repair and Dynamic Updates
Yumei Li 0003, Willy Susilo, Fuchun Guo, Yudi Zhang 0001, Mingwu Zhang |
ACISP (3) | 3 |
| 2026 | Improved Tightly Secure (ID-Based) Signatures in the AGM
Yanzibo Zhou, Fuchun Guo, Willy Susilo, Nan Li 0007 |
ACISP (1) | 2 |
| 2026 | Dynamic Puncturable Encryption
Priyanka Dutta 0001, Willy Susilo, Fuchun Guo, Dung Hoang Duong |
ACNS (1) | 3 |
| 2026 | KeyChaser: Unveiling API Keys in Browser Extensions
Shijin Chen, Willy Susilo, Yudi Zhang 0001, Fuchun Guo |
SP | 4 |
| 2026 | PAORE: public-key authenticated order-revealing encryption
Priyanka Dutta 0001, Willy Susilo, Fuchun Guo, Dung Hoang Duong |
Des. Codes Cryptogr. | 3 |
| 2026 | Tagged-FHE: strong syntax, stronger security, and standard model
Mengdi Ouyang, Zhaosen Shi, Xinyan Wu, Fuchun Guo, Fagen Li |
Des. Codes Cryptogr. | 5 |
| 2026 | Lattice-based logarithmic-size forward-secure ring signatures in QROM
Priyanka Dutta 0001, Willy Susilo, Fuchun Guo, Dung Hoang Duong |
Theor. Comput. Sci. | 3 |
| 2026 | SP2Join: Secure and Practical Multi-Table Pairwise Equi-Join Queries Over Encrypted DatabasesabstractPractical equi-join queries over encrypted databases aim to provide clients with flexible query capabilities while safeguarding data confidentiality. So far, the most promising and practical solution is CHT, which is based on Trusted Execution Environments (TEEs). However, such schemes can only support two-table equi-join queries, which are rather limited compared to Multi-Table Pairwise Equi-Join (MTPEJ). Furthermore, in terms of efficiency, throughput, and access pattern, the join implemented in TEEs is still problematic compared to a practical and secure scheme. In this work, we focus on this important type of equi-join, which facilitates join across any two tables among multiple tables. Specifically, we propose SP$^{2}$Join in this paper, the first MTPEJ framework that supports secure pairwise equi-join among multi-table by leveraging a novel oblivious pipeline join algorithm in TEEs. To validate our approach, we evaluate SP$^{2}$Join in MySQL using the benchmarks and real datasets, and the results demonstrate that SP$^{2}$Join is superior to the state-of-the-art in terms of secure equi-join. Particularly, our pipeline join query time is only 2.68% of CHT, yet throughput can reach up to 16.56 × of CHT. Even for MTPEJ, it is still 14.95% of CHT when implementing pairwise equi-join among 10 tables, with a time cost of approximately 140.30 ms. Siyi Lv, Zheli Liu, Fuchun Guo, Xiaofeng Chen 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Outsourced Cloud Storage and Dynamic Sharing: Efficient Time-Bound Access ControlabstractCloud storage has become the most attractive way to achieve data sharing by setting flexible access policies. Cryptographic tools are considered the most popular approach to protecting the privacy of data stored on the cloud. Dividing data into different classes plays a significant role in cloud storage, making data organization more methodical and data sharing more expressive and efficient. Unfortunately, current data sharing solutions either neglect data classification or suffer from data leakage. Specifically, shared keys can decrypt newly added encrypted data within the same class, and have key abuse issues where shared keys are untraceable once sold. In this work, we propose a time-bound data sharing system that addresses all these issues simultaneously. In our scheme, data is divided into different classes and encrypted according to its class and associated time period. Decryption keys for a set of chosen data classes can be aggregated into a single key, allowing users to decrypt multiple ciphertexts whose classes are within the set. While other encrypted data with classes outside the set remain confidential. Moreover, the aggregate key is time-bound which can only decrypt the ciphertexts generated before the embedded time period, ensuring it cannot access newly added encrypted data. The key size is independent of the chosen class set size and is only logarithmic in the bit length of the time period used. For each sharing, the shared aggregate key is different. In the event of data leakage or key selling, the data provider can identify the responsible users. We provide formal security analysis of our system and evaluate its performance through experiments. The results demonstrate that our system is highly efficient in terms of shared keys. It provides a practical solution for achieving efficient and dynamic data sharing in cloud storage. Willy Susilo, Jianchang Lai, Fuchun Guo, Yudi Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | IoT-Cloud Data Sharing and Access Control System With Efficient Policy UpdatingabstractThe integration of the Internet of Things (IoT) with cloud computing has expanded the scope of IoT applications but also introduced challenges in dynamic data management. Attribute-Based Encryption (ABE) serves as a crucial technology for constructing access control systems in data sharing environ ments. ABE schemes with policy updating capabilities allow data owners to dynamically and frequently modify access policies. Existing ABE schemes typically outsource the task of policy updating to a cloud server; however, the size of the update keys remains linear with the number of updated attributes and depends on the types of updated gates. The resulting updating costs are not less than generating a new ciphertext for data owners, especially when updating multiple attributes and threshold gates. Therefore, in this paper, we propose a novel ABE scheme, termed Policy Updatable Ciphertext-Policy ABE (PU CP-ABE), which enables efficient and flexible policy updating. Our construction ensures that the size of update keys depends only on the number of updating gates, independent of both the number of attributes and the gate types. Furthermore, PU-CP ABE provides a unified update mechanism that supports AND, OR, and threshold gates without requiring distinct update keys for different gate types. Luqi Huang, Fuchun Guo, Willy Susilo, Li Wang 0139 |
IEEE Trans. Serv. Comput. | 2 |
| 2025 | Onion Encryption Revisited: Relations Among Security Notions
Daichong Chao, Liehuang Zhu, Tong Wu 0011, Chuan Zhang 0003, Fuchun Guo |
Inscrypt (1) | 6 |
| 2025 | Public Verifiable Server-Aided Revocable Attribute-Based Encryption
Luqi Huang, Fuchun Guo, Willy Susilo, Yumei Li 0003 |
ICICS (1) | 2 |
| 2025 | Fast post-quantum private set intersection from oblivious pseudorandom function for mobile social networks
Zhuang Shan, Leyou Zhang, Qing Wu 0005, Qiqi Lai, Fuchun Guo |
J. Syst. Archit. | 5 |
| 2025 | Function-Hiding Multi-Client Inner-Product Functional Encryption Without Pairings for Large SpaceabstractMulti-client functional encryption (MCFE) is an extension of functional encryption (FE) in the multi-user setting and serves as a generalization of multi-input functional encryption (MIFE). The necessity of hiding function when it contains sensitive information, coupled with the widespread application of inner product (IP) in the descriptive statistics, has led to extensive research on function-hiding MCFE for IP. However, these works all rely on pairings and impose serious restrictions on the size of supported messages, as they all use inefficient decryption involving the extraction of discrete logarithms. On the other hand, although Abdalla et al. (CRYPTO 2018) introduced the first inner-product MIFE scheme for large message space as a special case of MCFE, it is not function-hiding. Consequently, existing inner-product MCFE schemes either exclusively support large space or solely achieve function-hiding, with no solution simultaneously achieving both properties. This paper employs an incremental construction strategy to design the function-hiding inner-product MCFE scheme, which does not require pairings. This leads to two main advances. First, we achieve the function hiding for inner-product MIFE even for messages of super-polynomial size. Second, we obtain the first function-hiding inner-product MCFE for large space, where the length of the message is of super-polynomial size. Jianghong Wei, Fuchun Guo, Yang Xiang 0001, Xiaofeng Chen 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | SVOC: Secure Aggregatable and Extractable System for Outsourced Cloud ComputationabstractWith the rapid advancement of technology, cloud computing has emerged as the most popular and promising service platform. A cloud user can delegate heavy computation tasks to cloud servers. To ensure the correctness of outsourced processing (e.g., machine learning and data mining), the cloud server must prove that the processing has been executed properly. However, even without malicious intent, it is possible for a cloud server to produce incorrect results. Consequently, clients may outsource the same task to multiple cloud servers and receive various results, aiding them in selecting the best outcome. To protect data privacy, the cloud server must encrypt the results before sending them back to the user. Yet, processing and verifying encrypted results remain significant challenges. To avoid the expensive computational overhead of decrypting ciphertexts from cloud servers one by one, clients prefer to use homomorphic encryption (HE) to obtain the combined output from a single server. However, existing schemes fall short of efficiently verifying the correctness of computations over encrypted data processed by multiple cloud servers, especially in extracting the results computed by each server. In this paper, we introduce a new framework for verifiable outsourced computing systems. In this system, each cloud server's computation result is protected by Paillier encryption, and the edge server can verify these results using zero-knowledge proofs and aggregate the verified ciphertexts. The client can extract the combined plaintext through the Base-3 conversion algorithm to identify each cloud server's results and any non-participating servers. We also prove the security of our scheme and analyze its performance from both theoretical and experimental aspects. Performance analysis shows that our system significantly reduces the client's workload and is userfriendly Willy Susilo, Yumei Li 0003, Fuchun Guo, Zhen Zhao 0005, Yannan Li 0001, Chunpeng Ge 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Key Cooperative Attribute-Based Encryption
Luqi Huang, Willy Susilo, Guomin Yang, Fuchun Guo |
ACISP (1) | 4 |
| 2024 | Threshold Ring Signatures with Accountability
Thanh Xuan Khuc, Willy Susilo, Dung Hoang Duong, Fuchun Guo, Kazuhide Fukushima, Shinsaku Kiyomoto |
ACISP (1) | 4 |
| 2024 | CrossAAD: Cross-Chain Abnormal Account Detection
Peng Jiang 0007, Fuchun Guo, Liehuang Zhu |
ACISP (3) | 3 |
| 2024 | Pairing-Free ID-Based Signatures as Secure as Discrete Logarithm in AGM
Jia-Ch'ng Loh, Fuchun Guo, Willy Susilo |
ACISP (1) | 2 |
| 2024 | A Fault-Tolerant Content Moderation Mechanism for Secure Messaging Systems
Tuong Ngoc Nguyen, Willy Susilo, Dung Hoang Duong, Fuchun Guo, Kazuhide Fukushima, Shinsaku Kiyomoto |
ACISP (2) | 4 |
| 2024 | Shrinkable Ring Signatures: It Wasn't Them!
Tuong Ngoc Nguyen, Willy Susilo, Dung Hoang Duong, Fuchun Guo, Kazuhide Fukushima, Shinsaku Kiyomoto |
ISPEC | 4 |
| 2024 | Lattice-Based Universal Designated Multi-verifiers Signature Scheme
Yanhua Zhang, Willy Susilo, Fuchun Guo, Jiaming Wen 0001 |
ISPEC | 4 |
| 2024 | Traceable Ring Signatures: Logarithmic-Size, Without Any Setup, from Standard Assumptions
Thanh Xuan Khuc, Willy Susilo, Dung Hoang Duong, Fuchun Guo, Kazuhide Fukushima, Shinsaku Kiyomoto |
ProvSec (1) | 4 |
| 2024 | Tightly Secure Identity-Based Signature from Cryptographic Group Actions
Thanh Xuan Khuc, Willy Susilo, Dung Hoang Duong, Fuchun Guo, Hyungrok Jo, Tsuyoshi Takagi |
ProvSec (1) | 4 |
| 2024 | Pixel+ and Pixel++: Compact and Efficient Forward-Secure Multi-Signatures for PoS Blockchain Consensus
Jianghong Wei, Guohua Tian, Ding Wang 0002, Fuchun Guo, Willy Susilo, Xiaofeng Chen 0001 |
USENIX Security Symposium | 4 |
| 2024 | Secure Data Integrity Check Based on Verified Public Key Encryption With Equality Test for Multi-Cloud StorageabstractCloud computing eliminates the need for local hardware, addressing the challenge of high computing expenses. However, entrusting data to the cloud may pose the risk of unintentional data loss. Using multiple copies and multi-cloud servers is promising because even if the data on one cloud storage server is compromised, the data proprietor can retrieve the information from alternate cloud storage servers. To protect data security, data needs to be encrypted before uploading to the cloud. However, users cannot directly confirm whether their encrypted documents and copies are stored securely and with integrity on cloud servers. To verify data copies on remote servers without downloading and decrypting, we propose Public Verification Public Key Encryption with Equality Test (PVPKEET). Under PVPKEET, users upload encrypted data to cloud servers, and then the test result and proof will be provided by the cloud server without decryption. The publicly verified proof can be examined by all users, allowing everyone to witness the copies stored correctly. Our approach is resistant to chosen-plaintext attacks and is verifiable. A comparison with prior research demonstrates the efficiency and feasibility of our design. Willy Susilo, Chunhe Xia, Luqi Huang, Fuchun Guo, Tianbo Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Blockchain-Based Compact Verifiable Data Streaming With Self-AuditingabstractThe primitive of verifiable data streaming (VDS) provides a secure data outsourcing solution for resource-constrained users, that is, they can stream their continuously-generated data items to untrusted servers while enabling publicly verifiable query and update. However, existing VDS schemes either require the server to store the authentication tags of all data items to support data query and auditing, or bind all data items into a constant-size tag to achieve optimal storage on the server side, but cannot achieve public auditing. To close this gap, in this paper, we first design a novel authentication data structure, dubbed retrievable homomorphic verifiable tags (RHVTs), which allows users to aggregate the authentication tags of all data items into a constant-size tag, and enables them to retrieve the original tags from the aggregated tag when necessary. Based on this, we propose a compact verifiable and auditable data streaming (CVADS) scheme, which adopts a single-level authentication mechanism to achieve more efficient data append and update, as well as optimal storage and public auditing. For better robustness and performance, we introduce a nested dual-level authentication mechanism and propose a blockchain-based CVADS (BCVADS) scheme to achieve a distributed CVADS with self-auditing. Finally, we prove the security of our schemes in the random oracle model and demonstrate their practicality through a visual performance evaluation. Guohua Tian, Jianghong Wei, Meixia Miao, Fuchun Guo, Willy Susilo, Xiaofeng Chen 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Exploring Unobservable Blockchain-Based Covert Channel for Censorship-Resistant SystemsabstractBlockchain-based censorship-resistant systems enable the user to access the blocked content through a covert channel while avoiding a suspicious network connection between the user and the proxy. However, state-of-the-art blockchain-based censorship-resistant schemes cannot satisfy both low communication fees and unobservability, and their method of identifying transactions with covert data may inadvertently expose the covert channel. In this paper, we present Hades, a blockchain-based covert channel framework that aims to circumvent censorship. Hades allows users to encode covert data as a transaction field, and identify transactions with covert data by using another transaction field as a label. We also present the security model for Hades, which defines the unobservability of Hades as the indistinguishability of transactions with covert data from normal transactions. We further propose two cost-friendly and unobservable instantiations of Hades: the basic RDSAC and the improved DDSAC. RDSAC uses private keys to encode covert data and utilizes random factors in the signing process as labels, while incurring a communication delay. DDSAC avoids the delay by encoding covert data into random factors and sampling a transaction amount from normal transactions as the label. We implement a prototype system of Hades and evaluate its performance. Experiment results show that our Hades prototype is unobservable, robust, and efficient. RDSAC and DDSAC can identify 1,654 transactions in 6.054 seconds and 0.071 seconds, respectively. Hades supports 1KB data transfer at $0.44 on the Bitcoin mainnet and cost-free data transfer on the Bitcoin testnet. Zhuo Chen 0001, Liehuang Zhu, Peng Jiang 0007, Can Zhang 0002, Feng Gao 0019, Fuchun Guo |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | SDSS: Sequential Data Sharing System in IoTabstractE-healthcare as a significant facet of the Internet of Things (IoT) relies on wearable devices to continuously monitor users’ vital signals for health-related purposes. The sensitive and vast nature of the collected data necessitate secure encryption and storage on the cloud. Simultaneously, there is a need to share these data for healthcare purposes. How to balance the privacy and usability of these data is a challenging problem in the e-healthcare applications. A central problem arose from the continuous data collection is how to effectively share the data collected in one specific time period when users are unwell. We formalize it as the sequential data sharing problem. This problem appears in various IoT applications apart from e-healthcare, such as video surveillance. In this paper, we explain why all existing solutions cannot address the above problem. Then, we propose a novel sequential data sharing system (SDSS), where the data encrypted at any specific time period can be efficiently shared. We first present a practical construction of SDSS that supports securely sharing data within one specific time period in a symmetric manner. The decryption key are retrieved sequentially by utilizing the shared key and hash function. All involved calculations in the system are lightweight. Data pertaining to other non-selected time periods remain unknown. We then extend the SDSS to a multiple-range version, enabling simultaneous sharing data for multiple specific time periods, and show an example. We formalize the definition of security models and analyze the security of our systems. Finally, we evaluate the performance of our systems using SHA-256 and AES-256. Experimental results demonstrate that our systems are highly efficient. It takes less than 1 millisecond to encrypt 100KB data and less than 0.4 milliseconds to decrypt the corresponding cipher data. Our proposed systems provide a solution to balance the privacy and usability in the context of sequentially collected data. We believe that this work will enhance the adoption and practicality of IoT applications. Jianchang Lai, Willy Susilo, Robert H. Deng, Fuchun Guo |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | A Tightly Secure ID-Based Signature Scheme Under DL Assumption in AGM
Jia-Ch'ng Loh, Fuchun Guo, Willy Susilo, Guomin Yang |
ACISP | 2 |
| 2023 | Robust Decentralized Multi-client Functional Encryption: Motivation, Definition, and Inner-Product Constructions
Jianghong Wei, Fuchun Guo, Willy Susilo, Xiaofeng Chen 0001 |
ASIACRYPT (5) | 3 |
| 2023 | Compact Accountable Ring Signatures in the Plain Model
Thanh Xuan Khuc, Willy Susilo, Dung Hoang Duong, Fuchun Guo, Kazuhide Fukushima, Shinsaku Kiyomoto |
Inscrypt (1) | 4 |
| 2023 | Compact Ring Signatures with Post-Quantum Security in Standard Model
Tuong Ngoc Nguyen, Willy Susilo, Dung Hoang Duong, Fuchun Guo, Kazuhide Fukushima, Shinsaku Kiyomoto |
Inscrypt (1) | 4 |
| 2023 | Guest editorial: Special issue on frontiers in cyber security
Fagen Li, Emmanuel Ahene, Mingwu Zhang, Fuchun Guo |
J. Syst. Archit. | 4 |
| 2023 | C-Wall: Conflict-Resistance in Privacy-Preserving Cloud StorageabstractFollowing the success of cloud computing, it has been shown its importance to realize various access control models in the cloud storage setting. Chinese Wall is a traditional access control model in business for solving the conflict of interest (CoI) problem, and it would be very interesting to achieve conflict-resistant in cloud storage system. However, the access control model does not ensure the privacy of users, and it may reveal the user's interest, investment tendency, etc. Therefore, it raises a big challenge to implement the Chinese Wall without compromising the user's privacy. In this paper, we focus on the Chinese Wall model and apply it to the cloud storage while protecting the access patterns of users. Specifically, we first formulate the tree-based Chinese Wall access control and then propose the Chinese Wall Protocol (called C-Wall). We prove that our C-Wall not only realizes the conflict-resistant but also protects the user's privacy with universally composable security. Besides, we also apply C-Wall to privacy-preserving cloud storage and propose the C2-Wall, which not only maintains C-Wall's features, but also ensures the sensitive files from being touched by "honest-but-curious" cloud servers. Furthermore, we evaluate our C2-Wall by theoretical analysis and experimental validation. Experimental results show its effectiveness and efficiency for practical deployment. Xiaoguo Li, Tao Xiang 0001, Yi Mu 0001, Fuchun Guo, Zhongyuan Yao |
IEEE Trans. Cloud Comput. | 4 |
| 2023 | Blockchain-Based Accountable Auditing With Multi-Ownership TransferabstractCloud auditing enables the integrity verification of cloud data without the necessity of data retrieval, which significantly promotes the storage service of cloud computing. Auditing with ownership transfer is a variation where both cloud data and the tags for integrity verification can be transferred. In some scenarios, like joint-stock enterprise acquisition and electronic medical records migration, we argue that auditing and transferring data belonging to multiple owners are significantly important. However, to the best of our knowledge, there exists no such protocol in multi-ownership scenarios in the literature. In this paper, we propose a blockchain-based accountable auditing protocol with multi-ownership transfer for the first time. One distinguishable property is the simultaneous achievement of verifiability, accountability and multi-ownership transferability, merely with very little extra cost. Specifically, we construct a novel tag structure based on homomorphic authenticators and compact multi-signatures, enabling integrity verification and multi-ownership transfer. Subsequently, we record the information concerning data generation and ownership transfer on immutable blockchains to make these procedures accountable. Furthermore, we present a comprehensive analysis and extensive experiments to demonstrate the security and efficiency of the proposed protocol. Jun Shen 0006, Xiaofeng Chen 0001, Jianghong Wei, Fuchun Guo, Willy Susilo |
IEEE Trans. Cloud Comput. | 4 |
| 2023 | Balancing Privacy and Flexibility of Cloud-Based Personal Health Records Sharing SystemabstractThe Internet of Things and cloud services have been widely adopted in many applications, and personal health records (PHR) can provide tailored medical care. The PHR data is usually stored on cloud servers for sharing. Weighted ABE is a practical and flexible technique to protect PHR data. Under a weighted ABE policy, the data user's attributes will be “scored”, if and only if the score reaches the threshold value, they can access the data. However, while this approach offers a flexible access policy, the data owners have difficulty controlling their privacy, especially sharing PHR data in collaborative e-health systems. This paper aims to find a balance between privacy and flexibility and proposes an AND-weighted ABE scheme in cloud-based personal health records sharing systems. The proposed scheme can meet both privacy and flexibility. Only when the data user satisfies the scored-based policy and is in the specified organization(s), can the data user access the PHR data. Besides, we give the security proof and the performance evaluation of the proposed scheme. The security proof and performance analysis show that the proposed scheme can efficiently and securely share PHR data in cloud service. Yudi Zhang 0001, Fuchun Guo, Willy Susilo, Guomin Yang |
IEEE Trans. Cloud Comput. | 2 |
| 2023 | EthereumX: Improving Signature Security With Randomness Preprocessing ModuleabstractEthereum leverages ECDSA as the digital signature scheme to validate transactions. From the provable security standpoint, ECDSA built on an 80-bit security Elliptic Curve group can achieve at most 50-bit concrete security, rather than 80-bit security, due to its reduction loss for$2^{30}$signature queries in security analysis. The state-of-the-art ECDSA scheme comes with no de facto formal security guarantee. Although there have been many signatures with higher concrete security, their structures are quite different from ECDSA and a total replacement of the signature field in Ethereum will incur high deployment cost. In this work, we present EthereumX without compromising the signature structure in Ethereum while achieves better security. The security gain is built on top of a new technique named randomness preprocessing module (RPM), which can securely pre-generate and verify randomness with the help of Ethereum. Calling RPM allows to pre-select randomness, which will be used for the subsequent signature, and to verify the randomness, assuring that it is previously generated. We give an instantiation with formal security guarantee and prove that it can be improved to 80-bit concrete security under the same discrete logarithm assumption as ECDSA. From this instantiated scheme, we implement EthereumX via a deployment into a locally simulated network. Experiment results show that EthereumX costs 5 seconds for a block generation which is equal to Ethereum, and generates/verifies at least$17017/10623$transactions per second that is practical enough in application, even if they are slightly slower than Ethereum which generates/verifies at least$17908/11257$transactions per second. We also mention that RMP can be applied to other DL-based signatures for the security improvement. Peng Jiang 0007, Fuchun Guo, Willy Susilo, Chao Lin 0003, Jiaxi Hu, Zhen Zhao 0005, Liehuang Zhu, Debiao He |
IEEE Trans. Serv. Comput. | 2 |
| 2023 | Secure Replication-Based Outsourced Computation Using Smart ContractsabstractThe replication-Based Outsourced Computation (RBOC) mechanism allows a client to outsource the same computing job to multiple contractors and the honest contractors will get paid in the incentivized system based on the fact that a majority of contractors will honestly perform the computation. As self-executing contracts, smart contracts are utilized in the decentralized blockchain networks to execute coded programs automatically transparently, and publicly. It is natural to apply smart contracts to RBOC to improve performance by setting smart contracts as the converter between the client and contractors to reduce the load on the client. However, it is infeasible to directly combine these two blocks together because the data including returned computing results from contractors in the decentralized blockchain are in the form of plaintexts such that some lazy contractors could copy others’ results as their own and still get paid, which will compromise the security of RBOC. The existing public-key encryption with equality test (PKEET) is a promising candidate solution to stop the above lazy contractors, where the results are encrypted by PKEET and then transferred without hindering smart contracts to compare the equality of underlying results. Unfortunately, we found that the advanced lazy contractors can still compromise security by forging ciphertexts to pass the equality test only with the encrypted results of other contractors. In this paper, to achieve security against lazy contractors, we introduce the notion of PKEET against lazy encryptors (PKEET-LE). Besides the fundamental property of PKEET that performs equality test on ciphertexts without decryption, PKEET-LE additionally realizes the security against the lazy encryptors who aim to forge a ciphertext for a given one to pass the equality test between them without the knowledge of the underlying plaintext. We further propose a concrete and practical PKEET-LE construction along with formal security proof. Finally, we conduct a performance evaluation to demonstrate that our PKEET-LE scheme is efficient and practical in the RBOC system using smart contracts. Willy Susilo, Fuchun Guo, Zhen Zhao 0005, Yinhao Jiang, Chunpeng Ge 0001 |
IEEE Trans. Serv. Comput. | 2 |
| 2023 | PPDF: A Privacy-Preserving Cloud-Based Data Distribution System With FilteringabstractCloud computing has emerged as a popular choice for distributing data among both individuals and companies. Ciphertext-policy attribute-based encryption (CP-ABE) has been extensively used to provide data security and enable fine-grained access control. With this encryption technique, only users whose attributes satisfy the access policy can access the plaintext. In order to mitigate the computational overhead on users, particularly on lightweight devices, partial decryption has been introduced, where the cloud assists in performing the decryption computations without revealing sensitive information. However, in this process, the cloud obtains the user's attributes, thus infringing on the user's privacy. To address this issue, this article proposes a privacy-preserving cloud-based data distribution system with filtering (PPDF) to enable partial decryption without revealing the user's attributes. The proposed system also employs an edge server to assist the user in filtering out invalid ciphertexts, i.e., ciphertexts where the user's attributes do not satisfy the access policy, and transmit only the valid partially decrypted ciphertexts to the data receiver. Consequently, the proposed PPDF scheme achieves constant decryption cost for the data receiver. We provide a security proof and a performance evaluation of the proposed scheme, which confirms its effectiveness and practicality in various real-world applications. Yudi Zhang 0001, Willy Susilo, Fuchun Guo, Guomin Yang |
IEEE Trans. Serv. Comput. | 3 |
| 2022 | Multimodal Private Signatures
Khoa Nguyen 0002, Fuchun Guo, Willy Susilo, Guomin Yang |
CRYPTO (2) | 2 |
| 2022 | Efficient Unique Ring Signatures from Lattices
Tuong Ngoc Nguyen, The-Anh Ta, Huy Quoc Le, Dung Hoang Duong, Willy Susilo, Fuchun Guo, Kazuhide Fukushima, Shinsaku Kiyomoto |
ESORICS (2) | 6 |
| 2022 | Public Cloud Data Auditing Revisited: Removing the Tradeoff Between Proof Size and Storage Cost
Willy Susilo, Yannan Li 0001, Fuchun Guo, Jianchang Lai, Ge Wu 0001 |
ESORICS (2) | 3 |
| 2022 | Optimal Tightness for Chain-Based Unique Signatures
Fuchun Guo, Willy Susilo |
EUROCRYPT (2) | 1 |
| 2022 | Secure Infectious Diseases Detection System With IoT-Based e-Health PlatformsabstractIn a traditional health system, it merely depends on doctors’ initiative reports to discover infectious diseases, which causes late responses from the Center for Disease Control (CDC) and therefore may result in snowballed loss of lives and economy. Sometimes, the disease has spread when doctors realize it is infectious, and the CDC has to invest more human and material resources to control it. In this article, we propose a new secure infectious diseases detection system with the help of the IoT-based e-health platform. In our system model, the hospitals collect patients’ electronic health records (EHRs) and outsource the encrypted EHRs to the contracted cloud. The CDC can regularly send a test query to the cloud server to check whether there are patients who have similar symptoms or some increasing signs, which are regarded as signs of infectious diseases. With this system, the CDC can find the small signs of infectious diseases so that it can make appropriate and timely measures to save more lives. To enable the cloud server to perform the required test, we propose a new cryptographic notion, called public-key encryption with DFET (PKE-DFET), with which we can check whether the underlying messages of two ciphertexts are equal or not after ignoring the bits on designated positions without decryption. The cloud server can utilize the PKE-DFET to flexibly count the number of patients with similar symptoms following the CDC’s instructions. We first instantiate the PKE-DFET into a concrete construction, where anyone can be a tester to perform the DFET on ciphertexts. Finally, we extend our PKE-DFET construction to enable it to be flexible in different actual application scenarios. Zhen Zhao 0005, Fuchun Guo, Ge Wu 0001, Willy Susilo, Baocang Wang |
IEEE Internet Things J. | 2 |
| 2022 | Generic conversions from CPA to CCA without ciphertext expansion for threshold ABE with constant-size ciphertexts
Jianchang Lai, Fuchun Guo, Willy Susilo, Peng Jiang 0007, Guomin Yang, Xinyi Huang 0001 |
Inf. Sci. | 2 |
| 2022 | PKE-MET: Public-Key Encryption With Multi-Ciphertext Equality Test in Cloud ComputingabstractCloud computing enables users to remove the necessity of the need of local hardware architecture, which removes the burden of the users from high computation costs. Therefore, it has attracted much attention and research has been conducted heavily on it. To protect users’ privacy, data is usually encrypted prior to being sent to the cloud server. As the resulting system is unusable, since the cloud can no longer search throughout the data, new cryptographic primitive such as public-key encryption with equality test (PKEET) has been introduced. In PKEET, users can test whether the underlying messages of two ciphertexts encrypted under different public keys are equal or not without the need to decrypt those ciphertexts. This is a very useful tool, especially for the cloud database, since PKEET mainly focuses on the equality test between two ciphertexts. However, in practice, the cloud server may need to verify the equivalence among more than two ciphertexts. This leads to disclosing unnecessary information of users and redundant computation cost will also occur when using traditional PKEET schemes. How to make this more efficient and practical remains an interesting research problem. In this article, to solve the aforementioned problems by providing a novel concept of public-key encryption with multi-ciphertext equality test (PKE-MET). In PKE-MET, each ciphertext can designate a number$s$such that the cloud server can only perform equality test on this ciphertext with other$s-1$ciphertexts, where all their designated numbers are$s$. For PKE-MET, besides traditional OW-CPA and IND-CPA security, we specially define Number security. We instantiate PKE-MET to a concrete scheme and give its security proof. Furthermore, to enable the primitive to be more practical in applications, we extend it to the concept of PKE with flexible MET (PKE-FMET). In PKE-FMET, the cloud server can perform equality test on any number of ciphertexts as long as the maximum number of their designated numbers is less than or equal to the number of ciphertexts. We construct a PKE-FMET scheme based on our PKE-MET construction and prove its security under the defined security models. Besides, the performance analysis mainly of efficiency and security between our constructions and existing equality test schemes in cloud computing show that our proposed schemes are more efficient and secure in the multi-ciphertext scenario. Willy Susilo, Fuchun Guo, Zhen Zhao 0005, Ge Wu 0001 |
IEEE Trans. Cloud Comput. | 2 |
| 2022 | An Anonymous Authentication System for Pay-As-You-Go Cloud Computing$^*$*abstractCloud computing offers on-demand availability of computing resources over the Internet. To attract users, cloud providers offer their resources as services at reasonable prices and provide various price models to reflect higher level of quality of service (QoS), which are referred as pricing schemes.$k$-times anonymous authentication ($k$-TAA) is an attractive approach to construct pricing schemes, providing access controllability, user anonymity and public traceability. In$k$-TAA schemes, authenticated users are permitted to anonymously access services from a provider at most$k$times, while the ones whose the number of access times exceeds$k$can be publicly traced. That is,$k$-TAA schemes offer a prepaid plan that charges users based on the amount of access times. Alternatively, pay-as-you-go (PAYG) is a pricing strategy that allows users to be charged based on the amount of usage, reducing the costs on unnecessary resources. Adopting$k$-TAA schemes to PAYG model, the access bound$k$is decided by the prepayment amount and the service usage is tracked by the number of access times. However, this approach is impractical, since existing$k$-TAA schemes only allow an one-time access in an authentication. This article aims to bridge this gap in the literature by designing an efficient and secure authentication system for PAYG cloud computing, supporting flexible access controllability, user anonymity and public traceability. To achieve this, we propose a new$k$-TAA primitive, called$k$-times anonymous pay-as-you-go authentication ($k$-TAA-PAYG), that allows users to access services for multiple times in an authentication as long as the number of their access times does not exceed$k$. We first formalize the definition and security model for$k$-TAA-PAYG scheme. Subsequently, we present a concrete construction of$k$-TAA-PAYG scheme, with the computational complexity as$O(1)$and the constant communicational cost. Finally, comparing with the most efficient$k$-TAA scheme proposed by Emuraet al., the experimental results show that our$k$-TAA-PAYG scheme is 2.5 to 3 times faster and saves up to 66 percent storage in grant processes. The time cost of an authentication of our$k$-TAA-PAYG scheme is constant (1.4-2.4 ms), while Emuraet al.’s scheme needs more than one second when the number of access time is greater than 1, 000. Jianye Huang 0001, Willy Susilo, Fuchun Guo, Ge Wu 0001, Zhen Zhao 0005, Qiong Huang 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | Sanitizable Access Control System for Secure Cloud Storage Against Malicious Data PublishersabstractCloud computing is considered as one of the most prominent paradigms in the information technology industry, since it can significantly reduce the costs of hardware and software resources in computing infrastructure. This convenience has enabled corporations to efficiently use the cloud storage as a mechanism to share data among their employees. At the first sight, by merely storing the shared data as plaintext in the cloud storage and protect them using an appropriate access control would be a nice solution. This is assuming that the cloud is fully trusted for not leaking any information, which is impractical as the cloud is owned by a third party. Therefore, encryption is mandatory, and the shared data will need to be stored as a ciphertext using an appropriate access control. However, in practice, some of these employees may be malicious and may want to deviate from the required sharing policy. The existing protection in the literature has been explored to allow only legitimate recipients to decrypt the contents stored in the cloud storage, but unfortunately,no existing workdeals with issues raised due to the presence of malicious data publishers. Malicious data publishers construct data following the given policy, but the ciphertexts can actually be decrypted by unauthorized users without valid keys, or simply, anyone else who is unauthorized. The impact of the involvement of malicious data publishers is detrimental, as it may damage intellectual properties from the corporations. Therefore, it remains an elusive research problem on how to enable a sound approach to resolve the issue when malicious data publishers are involved in the system, which is a very practical question. In this work, we presenta new direction of researchthat can cope with the presence of malicious data publishers. We resolve the aforementioned problem by proposing the notion of Sanitizable Access Control System (SACS), which is designed for a secure cloud storage that can also resist against malicious data publishers. We define the threat model and its formal security model, as well as its design and scheme which is based on$q$q-Parallel Bilinear Diffie-Hellman Exponent Assumption. We provide the security proof of our construction as well as its performance analysis. We believe that this work has opened a new area of research which has never been explored before, even though it is very practical. Therefore, this work will enhance the adoption of secure cloud storage in practice. Willy Susilo, Peng Jiang 0007, Jianchang Lai, Fuchun Guo, Guomin Yang, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Data Access Control in Cloud Computing: Flexible and Receiver ExtendableabstractBroadcast encryption provides a promising technique of data access control for specified users in cloud computing. A data uploader can generate a ciphertext for a set of chosen users such that only the intended users are able to access the data. However, with the rapidly increasing of collaboration between users, it is desired to extend the receiver set to grant decryption right for more users. The existing broadcast encryption systems cannot support receiver extension. In this article, we for the first time take this problem into consideration and give a solution. We take the merits of identity-based cryptosystem and propose a notion of EIBBE: a flexible data access control with receiver extendable for cloud computing based on broadcast encryption. It allows the authorized user to extend the receiver set$S$stated in the IBBE ciphertext by adding a new receiver set$S^{\prime }$without re-encryption. Both the users in$S$and$S^{\prime }$can access the data successfully. Moreover, the data uploader determines the maximum number of extended receivers. We then give a concrete construction of EIBBE and provide a rigorous security analysis of our proposed scheme. Finally, we demonstrate the scheme's efficiency and feasibility. Jianchang Lai, Fuchun Guo, Willy Susilo, Xinyi Huang 0001, Peng Jiang 0007, Futai Zhang |
IEEE Trans. Serv. Comput. | 2 |
| 2021 | Lightweight Public Key Encryption With Equality Test Supporting Partial Authorization in Cloud StorageabstractAbstract Public key encryption with equality test (PKEET) can check whether two ciphertexts are encrypted from the same message or not without decryption. This attribute enables PKEET to be increasingly utilized in cloud storage, where users store their encrypted data on the cloud. In traditional PKEET, the tester is authorized by the data receiver to perform equality test on its ciphertexts. However, the tester can only test one ciphertext or all ciphertexts of one receiver with one authorization. It means that the receiver cannot adaptively authorize the test right of any number of ciphertexts to the tester. A trivial solution is authorizing one ciphertext each time and repeating multiple times. The corresponding size of trapdoor in this method is linear with the number of authorized ciphertexts. This will incur storage burden for the tester. To solve the aforementioned problem, we propose the concept of PKEET supporting partial authentication (PKEET-PA). We then instantiate the concept to a lightweight PKEET-PA, which achieves constant-size trapdoor. Besides, we prove the security of our PKEET-PA scheme against two types of adversaries. Compared with other PKEET schemes that can be used in trivial solution, our PKEET-PA is more efficient in receivers’ computation and has lower trapdoor size. Zhen Zhao 0005, Fei Gao 0001, Willy Susilo, Qiaoyan Wen, Fuchun Guo, Yijie Shi |
Comput. J. | 6 |
| 2021 | A cloud-aided privacy-preserving multi-dimensional data comparison protocol
Hua Shen 0002, Mingwu Zhang, Hao Wang 0007, Fuchun Guo, Willy Susilo |
Inf. Sci. | 4 |
| 2021 | Generic construction for tightly-secure signatures from discrete log
Jianchang Lai, Ge Wu 0001, Peng Jiang 0007, Zhen Zhao 0005, Willy Susilo, Fuchun Guo |
Theor. Comput. Sci. | 6 |
| 2021 | Privacy-Preserving Proof of Storage for the Pay-As-You-Go Business ModelabstractProof of Storage (PoS) enables a cloud storage provider to prove that a client's data is intact. However, existing PoS protocols are not designed for the pay-as-you-go business model in which payment is made based on both storage volume and duration. In this paper, we propose two PoS protocols suitable for the pay-as-you-go storage business model. The first is a time encapsulated Proof of Retrievability (PoR) protocol that ensures retrievability of the original file upon successful auditing by a client. Considering the large size of outsourced data, we then extend the protocol to a privacy-preserving public auditing protocol which allows a third party auditor to audit outsourced data on behalf of its clients without sacrificing the privacy of the data or the timestamp (i.e., time of storage). We formalize the definition, system model and security model of the proposed PoS system and prove the security of the proposed protocols by a sequence of games in the algebraic group model with a random oracle. We analyze the performance of the protocols both theoretically and experimentally and show that the protocols are practical. Tong Wu 0011, Guomin Yang, Yi Mu 0001, Fuchun Guo, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Efficient and Adaptive Procurement Protocol with Purchasing PrivacyabstractA procurement protocol is a protocol for a buyer to purchase digital goods at their prices from a vendor. A procurement protocol with privacy preservation can be achieved by priced oblivious transfer (POT). POT allows the buyer to obliviously procure items one by one. An adaptive POT protocol only consumes O(1) communication cost in each transaction, where all items are committed and encrypted before transactions. However, we found that the state-of-the-art adaptive POT protocol proposed by Rial et al. is less practical and does not meet real-world needs. It has to restrict to the one-buyer setting where all items are encrypted associated with one buyer's public key. For multiple buyers, the vendor must respectively encrypt all the same items for each buyer. Besides, it has to employ computationally expensive primitives such as zero-knowledge proof which imply inefficient computation operations. It is therefore unscalable and unsuitable in large-scale applications. In this paper, we propose an efficient adaptive priced oblivious transfer protocol to address the aforementioned problems. The proposed adaptive POT is built on top of a new cryptographic primitive, namely, adaptive set membership encryption (ASME). In our proposed protocol, all items are encrypted without the use of buyers' public keys and hence they can be used for universal buyers. Our protocol significantly reduces the transaction cost compared to existing schemes. For example, the communication in each transaction costs only 6 group elements compared to at least 141 group elements in Rial et al.'s protocol. The implementation shows that our protocol is efficient in terms of bandwidth and computational cost. Peng Jiang 0007, Fuchun Guo, Willy Susilo, Man Ho Au, Xinyi Huang 0001, Joseph K. Liu |
IEEE Trans. Serv. Comput. | 2 |
| 2021 | PPFilter: Provider Privacy-Aware Encrypted Filtering SystemabstractFiltering refers to an operation to determine whether the concerned data should be accepted and transferred, or be blocked and marked as a malicious traffic flow. It mitigates the inter-domain bandwidth overhead, local computational cost and storage cost for data identification. In many sensitive applications, the identity of the data provider needs to be hidden. This creates challenges how to filter the transmitted data packet with an encrypted form. It is non-trivial to hide this data provider's identity while enabling filtering, as the policy used as a matching criteria will need to determine whether the data needs to be transferred or not without knowing the origin of that data. In this work, we designPPFilter, a privacy-aware encrypted filtering mechanism which allows the filtering to be conducted without the need to know the identity of the data provider. PPFilter achieves the integrity protection of the data packets and the provider privacy Level 3. PPFilter is built on top of a novel notion calledidentity-based encryption with sender search (IESS), which supports anonymous sender identity in an encrypted searching. We present a provably secure IESS instantiation, and apply it to achieve a PPFilter protocol. PPFilter allows the data provider's identity to be hidden from both the transferred data and policy while enabling the filtering capability, which solves the aforementioned problem. The analysis and evaluation show that PPFilter maintains cost-reasonable filtering while preserving provider privacy, and hence it guarantees its practicality. Peng Jiang 0007, Fuchun Guo, Willy Susilo, Man Ho Au, Jianchang Lai, Wenmin Li 0001 |
IEEE Trans. Serv. Comput. | 2 |
| 2020 | Secure Cloud Auditing with Efficient Ownership Transfer
Jun Shen 0006, Fuchun Guo, Xiaofeng Chen 0001, Willy Susilo |
ESORICS (1) | 2 |
| 2020 | On the General Construction of Tightly Secure Identity-Based Signature SchemesabstractAbstract A tightly secure scheme has a reduction, where the reduction loss is a small constant. Identity-based signature (IBS) is an important cryptographic primitive, and tightly secure IBS schemes enjoy the advantage that the security parameter can be optimal to achieve a certain security level. General constructions of IBS schemes (Bellare, M., Namprempre, C., and Neven, G. (2004) Security Proofs for Identity-Based Identification and Signature Schemes. In Proc. EUROCRYPT 2004, May 2–6, pp. 268–286. Springer, Berlin, Interlaken, Switzerland; Galindo, D., Herranz, J., and Kiltz, E. (2006) On the Generic Construction of Identity-Based Signatures With Additional Properties. In Proceedings of ASIACRYPT 2006, December 3–7, pp. 178–193. Springer, Berlin, Shanghai, China) and their security have been extensively studied. However, the security is not tight and how to generally construct a tightly secure IBS scheme remains unknown. In this paper, we concentrate on the general constructions of IBS schemes. We first take an insight into previous constructions and analyze the reason why it cannot achieve tight security. To further study possible tightly secure constructions, we propose another general construction, which could be seen as a different framework of IBS schemes. Our construction requires two traditional signature schemes, whereas the construction by Bellare et al. uses one scheme in a two-round iteration. There are no additional operations in our general construction. Its main advantage is providing the possibility of achieving tight security for IBS schemes in the random oracle model. Combining two known signature schemes, we present an efficient IBS scheme with tight security as an example. Ge Wu 0001, Zhen Zhao 0005, Fuchun Guo, Willy Susilo, Futai Zhang |
Comput. J. | 3 |
| 2020 | Black-Box Accountable Authority Identity-Based Revocation SystemabstractAbstract Identity-based revocation system (IBRS) generates the ciphertext with a revoked identity list such that only the non-revoked identities can use their private keys to decrypt this ciphertext. IBRS can be efficiently applied in some practical applications, such as the pay-TV systems when the number of revoked identities are much less than the non-revoked ones. However, since IBRS is based on identity-based cryptography, it also suffers from the inherent key escrow problem where the private key generator (PKG) has full control of each user’s private key. As a consequence, it is hard to judge whether a pirated private key is generated by the PKG or the suspected user. There is no study on IBRS fulfilling accountability in literature to date. In this paper, we introduce the notion of accountable authority IBRS (A-IBRS), which provides accountability in IBRS schemes. In an A-IBRS, the aforementioned problem can be alleviated and resolved. Furthermore, a full black-box A-IBRS can distinguish the creator of a black box between the PKG and the associated user and the dishonest PKG is allowed to access the decryption results of the user private key. We formalize the definition and security models of the full black-box A-IBRS schemes. Then, we present a concrete full black-box A-IBRS scheme with constant-size master public key and private key. Finally, we prove the security of our scheme under the defined security models without random oracle. Zhen Zhao 0005, Ge Wu 0001, Fuchun Guo, Willy Susilo, Yi Mu 0001, Baocang Wang, Yupu Hu |
Comput. J. | 3 |
| 2020 | Searchain: Blockchain-based private keyword search in decentralized storage
Peng Jiang 0007, Fuchun Guo, Kaitai Liang, Jianchang Lai, Qiaoyan Wen |
Future Gener. Comput. Syst. | 2 |
| 2020 | A Lightweight Privacy-Preserving Fair Meeting Location Determination SchemeabstractEquipped with mobile devices, people relied on location-based services (LBSs) can expediently and reasonably organize their activities. But location information may disclose people's sensitive information, such as interests and health status. Besides, the limited resources of mobile devices restrict the further development of LBSs. In this article, aiming at the fair meeting position determination service, we design a lightweight privacy-preserving solution. In our scheme, mobile users only need to submit service requests. A cloud server and a location services provider are responsible for service response, where the cloud server achieves most of the calculation, and the location services provider determines the fair meeting location based on the computational results of the cloud server and broadcasts it to mobile users. The proposed scheme adopts homomorphic encryptions and random permutation methods to preserve the location privacy of mobile users. The security analyses show that the proposed scheme is privacy preserving under our defined threat models. Besides, the presented solution only needs to calculate $n$ Euclidean distances, and hence, our scheme has linear computation and communication complexity. Hua Shen 0002, Mingwu Zhang, Hao Wang 0007, Fuchun Guo, Willy Susilo |
IEEE Internet Things J. | 4 |
| 2020 | Certificateless aggregate signature scheme secure against fully chosen-key attacks
Ge Wu 0001, Futai Zhang, Fuchun Guo, Willy Susilo |
Inf. Sci. | 4 |
| 2020 | Accountable authority identity-based broadcast encryption with constant-size private keys and ciphertexts
Zhen Zhao 0005, Fuchun Guo, Jianchang Lai, Willy Susilo, Baocang Wang, Yupu Hu |
Theor. Comput. Sci. | 2 |
| 2019 | A New Encoding Framework for Predicate Encryption with Non-linear Structures in Prime Order Groups
Jongkil Kim, Willy Susilo, Fuchun Guo, Joonsang Baek, Nan Li 0007 |
ACNS | 3 |
| 2019 | Attribute-Based Information Flow ControlabstractAbstract Information flow control (IFC) regulates where information is permitted to travel within information systems. To enforce IFC, access control encryption (ACE) was proposed to support both the no read-up rule and the no write-down rule. There are some problems in existing schemes. First, the communication cost is linear with the number of receivers. Second, senders are not authenticated, namely an unauthorized sender can send a message to a receiver. To reduce communication cost and implement sender authentication, we propose an attribute-based IFC (ABIFC) scheme by introducing attribute-based systems into IFC. Our ABIFC scheme captures the following features: (i) flexible IFC policies are defined over a universal set of descriptive attributes; (ii) both the no read-up rule and the no write-down rule are supported; (iii) the communication cost is linear with the number of required attributes, instead of receivers; (iv) receivers can outsource heavy computation to a server without compromising data confidentiality; (v) authorized senders can control release their attributes when sending messages to receivers. To the best of our knowledge, it is the first IFC scheme where flexible policies are defined over descriptive attributes and outsourced computation is supported. Jinguang Han, Maoxuan Bei, Liqun Chen 0002, Yang Xiang 0001, Jie Cao 0001, Fuchun Guo, Weizhi Meng 0001 |
Comput. J. | 6 |
| 2019 | Strongly leakage resilient authenticated key exchange, revisited
Guomin Yang, Rongmao Chen, Yi Mu 0001, Willy Susilo, Fuchun Guo, Jie Li 0041 |
Des. Codes Cryptogr. | 5 |
| 2019 | Identity-based revocation system: Enhanced security model and scalable bounded IBRS construction with short parameters
Peng Jiang 0007, Jianchang Lai, Fuchun Guo, Willy Susilo, Man Ho Au, Guomin Yang, Yi Mu 0001, Rongmao Chen |
Inf. Sci. | 3 |
| 2019 | Generalized public-key cryptography with tight security
Ge Wu 0001, Fuchun Guo, Willy Susilo |
Inf. Sci. | 2 |
| 2019 | Accountable identity-based encryption with distributed private key generators
Zhen Zhao 0005, Ge Wu 0001, Willy Susilo, Fuchun Guo, Baocang Wang, Yupu Hu |
Inf. Sci. | 4 |
| 2019 | Tightly Secure Public-Key Cryptographic Schemes from One-More Assumptions
Ge Wu 0001, Jianchang Lai, Fuchun Guo, Willy Susilo, Futai Zhang |
J. Comput. Sci. Technol. | 3 |
| 2019 | Efficient identity-based broadcast encryption with keyword search against insider attacks for database systems
Peng Jiang 0007, Fuchun Guo, Yi Mu 0001 |
Theor. Comput. Sci. | 2 |
| 2018 | Identity-Based Broadcast Encryption for Inner ProductsabstractIn the identity-based broadcast encryption (IBBE), only these users whose identities are chosen in the ciphertext computing can decrypt the encrypted message. In this paper, we introduce an extension of IBBE, namely Identity-Based Broadcast Encryption for Inner Product (IBBE-IP), where message encryption is replaced by inner product encryption (IPE) introduced by Abdalla et al. (PKC 2015). Precisely, in the IBBE-IP, the private key is associated with a pair of an identity and a vector (ID,y→). The user with private key of (ID,y→) can decrypt the encrypted vector x→ for an identity set S selected by the encryptor and learn the inner product 〈x→,y→〉 if and only if ID∈S. Differing from the IBBE, the decryption in the IBBE-IP yields the inner product associated with the encrypted vector without leaking any information of the vector. The encrypted vector is protected as long as the number of selected identities is less than their length. We present a construction of IBBE-IP with constant-size private keys and it supports unbounded private key queries, which was unachieved in the previous works of IPE in the public-key setting. The security of our proposed scheme is proved in the random oracle model. Jianchang Lai, Yi Mu 0001, Fuchun Guo, Peng Jiang 0007, Sha Ma |
Comput. J. | 3 |
| 2018 | Functional encryption for computational hiding in prime order groups via pair encodings
Jongkil Kim, Willy Susilo, Fuchun Guo, Man Ho Au |
Des. Codes Cryptogr. | 3 |
| 2018 | Ciphertext-policy attribute-based encryption against key-delegation abuse in fog computing
Yinhao Jiang, Willy Susilo, Yi Mu 0001, Fuchun Guo |
Future Gener. Comput. Syst. | 4 |
| 2018 | Privacy-enhanced attribute-based private information retrieval
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Peng Jiang 0007, Willy Susilo |
Inf. Sci. | 3 |
| 2018 | Constant-size ciphertexts in threshold attribute-based encryption without dummy attributes
Willy Susilo, Guomin Yang, Fuchun Guo, Qiong Huang 0001 |
Inf. Sci. | 3 |
| 2018 | Efficient k-out-of-n oblivious transfer scheme with the ideal communication cost
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Rongmao Chen, Sha Ma |
Theor. Comput. Sci. | 3 |
| 2017 | An Efficient KP-ABE with Short Ciphertexts in Prime OrderGroups under Standard AssumptionabstractWe introduce an efficient Key-Policy Attribute-Based Encryption (KP-ABE) scheme in prime order groups. Our scheme is semi-adaptively secure under the decisional linear assumption and supports a large universe of attributes and multi-use of attributes. Those properties are critical for real applications of KP-ABE schemes since they enable an efficient and flexible access control. Prior to our work, existing KP-ABE schemes with short ciphertexts were in composite order groups or utilized either Dual Pairing Vector Spaces (DPVS) or Dual System Groups (DSG) in prime order groups. However, those techniques brought an efficiency loss. In this work, we utilize a nested dual system encryption which is a variant of Waters' dual system encryption (Crypto' 09) to achieve semi-adaptively secure KP-ABE. As a result, we obtain a new scheme having better efficiency compared to existing schemes while it keeps a semi-adaptive security under the standard assumption. We implement our scheme and compare its efficiency with the previous best work. Jongkil Kim, Willy Susilo, Fuchun Guo, Man Ho Au, Surya Nepal |
AsiaCCS | 3 |
| 2017 | Optimal Security Reductions for Unique Signatures: Bypassing Impossibilities with a Counterexample
Fuchun Guo, Rongmao Chen, Willy Susilo, Jianchang Lai, Guomin Yang, Yi Mu 0001 |
CRYPTO (2) | 1 |
| 2017 | Fuzzy Extractors for Biometric IdentificationabstractFuzzy extractor provides key generation from biometrics and other noisy data. The generated key is seamlessly usable for any cryptographic applications because its information entropy is sufficient for security. Biometric authentication offers natural and passwordless user authentication in various systems where fuzzy extractors can be used for biometric information security. Typically, a biometric system operates in two modes: verification and identification. However, existing fuzzy extractors does not support efficient user identification. In this paper, we propose a succinct fuzzy extractor scheme which enables efficient biometric identification as well as verification that it satisfies the security requirements. We show that the proposed scheme can be easily used in both verification and identification modes. To the best of our knowledge, we propose the first fuzzy extractor based biometric identification protocol. The proposed protocol is able to identify a user with constant computational cost rather than linear-time computation required by other fuzzy extractor schemes. We also provide security analysis of proposed schemes to show their security levels. The implementation shows that the performance of proposed identification protocol is constant and it is close to that of verification protocols. Nan Li 0007, Fuchun Guo, Yi Mu 0001, Willy Susilo, Surya Nepal |
ICDCS | 2 |
| 2017 | Fully Privacy-Preserving ID-Based Broadcast Encryption with AuthorizationabstractA revocable ID-based broadcast encryption scheme allows an authorized third party to revoke any receiver (decryptor) from the initial receiver set S of the original broadcast ciphertext without the need of decryption. However, the existing revocable ID-based broadcast encryption schemes in the literature cannot fully preserve the receiver privacy and have a large size of ciphertext when the revoked user sets are large. To solve these problems, in this paper, we propose a novel scheme: fully privacy-preserving ID-based broadcast encryption with authorization. Our scheme allows an authorized party to dynamically handle the decryption rights of receivers via an authorized user set L without knowing the message and the identities of the initial receivers. Only those users who are both in S and L can decrypt the ciphertext successfully. The final ciphertext reveals nothing about the identity information of receivers and the authorized users. Our scheme achieves full collusion resistance and is applicable to anonymous data sharing where the receivers are decided by the authorized third party (or multiple authorized third parties) excluding the data owner. We show that our proposed scheme is provably secure under the defined security models in the random oracle model. Jianchang Lai, Yi Mu 0001, Fuchun Guo, Rongmao Chen |
Comput. J. | 3 |
| 2017 | Secure-channel free keyword search with authorization in manager-centric databases
Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Qiaoyan Wen |
Comput. Secur. | 3 |
| 2017 | Strong authenticated key exchange with auxiliary inputs
Rongmao Chen, Yi Mu 0001, Guomin Yang, Willy Susilo, Fuchun Guo |
Des. Codes Cryptogr. | 5 |
| 2017 | A note on the strong authenticated key exchange with auxiliary inputs
Rongmao Chen, Yi Mu 0001, Guomin Yang, Willy Susilo, Fuchun Guo, Zheng Yang 0001 |
Des. Codes Cryptogr. | 5 |
| 2017 | Sequence aware functional encryption and its application in searchable encryption
Tran Viet Xuan Phuong, Guomin Yang, Willy Susilo, Fuchun Guo, Qiong Huang 0001 |
J. Inf. Secur. Appl. | 4 |
| 2017 | Private Keyword-Search for Database Systems Against Insider Attacks
Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Qiaoyan Wen |
J. Comput. Sci. Technol. | 3 |
| 2017 | Fully privacy-preserving and revocable ID-based broadcast encryption for data access control in smart city
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Willy Susilo, Rongmao Chen |
Pers. Ubiquitous Comput. | 3 |
| 2017 | Optimized Identity-Based Encryption from Bilinear Pairing for Lightweight DevicesabstractLightweight devices such as smart cards and RFID tags have a very limited hardware resource, which could be too weak to cope with asymmetric-key cryptography. It would be desirable if the cryptographic algorithm could be optimized in order to better use hardware resources. In this paper, we demonstrate how identity-based encryption algorithms from bilinear pairing can be optimized so that hardware resources can be saved. We notice that the identity-based encryption algorithms from bilinear pairing in the literature must perform both elliptic curve group operations and multiplicative group operations, which consume a lot of hardware resources. We manage to eliminate the need of multiplicative group operations for encryption. This is a significant discovery since the hardware structure can be simplified for implementing pairing-based cryptography. Our experimental results show that our encryption algorithm saves up to 47 percent memory (27,239 RAM bits) in FPGA implementation. Fuchun Guo, Yi Mu 0001, Willy Susilo, Homer Hsing, Duncan S. Wong, Vijay Varadharajan |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2017 | EACSIP: Extendable Access Control System With Integrity Protection for Enhancing Collaboration in the CloudabstractIt is widely acknowledged that the collaborations with more users increase productivity. Secure cloud storage is a promising tool to enhance such a collaboration. Access control system can be enabled with attribute-based encryption. In this system, a user encrypts and uploads his/her data to the cloud with an access policy, such that only people who satisfy that access policy can decrypt the data. When a recipient would like to enable another person who is originally unauthorized by the original access policy, this recipient will need to extend the access policy by adding a new policy that includes the new person hence, the notion of extendable access control system. Admitting new users to access the uploaded data is an important requirement in enhancing collaborations. The main issue is with regards to the integrity protection during the process of extending the access policy. When a new access policy is added, the cloud has to be sure that the extended access policy remains guarding the same encrypted data as the original access policy, even though the cloud cannot decrypt this ciphertext, which is a challenging problem to solve. In this paper, we answer the above problem affirmatively by introducing an extendable access control system with Integrity Protection (EACSIP), which is suitable to enhance collaboration in the cloud. The construction of EACSIP is built on top of a novel cryptographic primitive, namely functional key encapsulation with equality testing. The security proof and the performance evaluation of EACSIP are provided in this paper. Willy Susilo, Peng Jiang 0007, Fuchun Guo, Guomin Yang, Yong Yu 0002, Yi Mu 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2016 | One-Round Strong Oblivious Signature-Based Envelope
Rongmao Chen, Yi Mu 0001, Willy Susilo, Guomin Yang, Fuchun Guo, Mingwu Zhang |
ACISP (2) | 5 |
| 2016 | Public Key Encryption with Authorized Keyword Search
Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Qiaoyan Wen |
ACISP (2) | 3 |
| 2016 | Ciphertext-Policy Attribute-Based Encryption with Key-Delegation Abuse Resistance
Yinhao Jiang, Willy Susilo, Yi Mu 0001, Fuchun Guo |
ACISP (1) | 4 |
| 2016 | Anonymous Identity-Based Broadcast Encryption with Revocation for File Sharing
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Willy Susilo, Rongmao Chen |
ACISP (2) | 3 |
| 2016 | Cryptographic Reverse Firewall via Malleable Smooth Projective Hash Functions
Rongmao Chen, Yi Mu 0001, Guomin Yang, Willy Susilo, Fuchun Guo, Mingwu Zhang |
ASIACRYPT (1) | 5 |
| 2016 | Iterated Random Oracle: A Universal Approach for Finding Loss in Security Reduction
Fuchun Guo, Willy Susilo, Yi Mu 0001, Rongmao Chen, Jianchang Lai, Guomin Yang |
ASIACRYPT (2) | 1 |
| 2016 | Recipient Revocable Identity-Based Broadcast Encryption: How to Revoke Some Recipients in IBBE without Knowledge of the PlaintextabstractIn this paper, we present the notion of recipient-revocable identity-based broadcast encryption scheme. In this notion, a content provider will produce encrypted content and send them to a third party (which is a broadcaster). This third party will be able to revoke some identities from the ciphertext. We present a security model to capture these requirements, as well as a concrete construction. The ciphertext consists of k+3 group elements, assuming that the maximum number of revocation identities is k. That is, the ciphertext size is linear in the maximal size of R, where R is the revocation identity set. However, we say that the additional elements compared to that from an IBBE scheme are only for the revocation but not for decryption. Therefore, the ciphertext sent to the users for decryption will be of constant size (i.e.,3 group elements). Finally, we present the proof of security of our construction. Willy Susilo, Rongmao Chen, Fuchun Guo, Guomin Yang, Yi Mu 0001, Yang-Wai Chow |
AsiaCCS | 3 |
| 2016 | Strongly Leakage-Resilient Authenticated Key Exchange
Rongmao Chen, Yi Mu 0001, Guomin Yang, Willy Susilo, Fuchun Guo |
CT-RSA | 5 |
| 2016 | Privacy-Preserving Cloud Auditing with Multiple Uploaders
Ge Wu 0001, Yi Mu 0001, Willy Susilo, Fuchun Guo |
ISPEC | 4 |
| 2016 | Ciphertext-Policy Attribute Based Encryption Supporting Access Policy Update
Yinhao Jiang, Willy Susilo, Yi Mu 0001, Fuchun Guo |
ProvSec | 4 |
| 2016 | Oblivious Keyword Search with Authorization
Peng Jiang 0007, Jianchang Lai, Fuchun Guo, Rongmao Chen |
ProvSec | 4 |
| 2016 | Online/Offline Ciphertext Retrieval on Resource Constrained DevicesabstractThe ciphertext retrieval is of paramount importance for data confidentiality and utilization in mobile cloud environment. The receiver, usually equipped with resource constrained devices, retrieves data stored in the cloud server by submitting a confidential request (or trapdoor) to the cloud. Previous schemes need at least one exponentiation operation in group |$\mathbb {G}$| for each keyword to generate the trapdoor, which is quite burdensome for mobile devices to support such computational cost. The computational cost of trapdoor generation limits the application of ciphertext retrieval, especially in a wireless environment. In this paper, we propose the first online/offline ciphertext retrieval (OOCR) scheme, where the trapdoor generation is split into two phases: offline phase and online phase . Most of the computation of the trapdoor could be performed in the offline phase prior to knowing the keyword. The generation of the real trapdoor with keyword can be done efficiently in the online phase. The most challenging task is to resist the so-called insider attacks, which is about keyword guessing attacks from the untrusted cloud server. We also build a novel framework to resist insider attacks and propose an OOCR scheme against insider attacks. Our semantic security proof and performance analysis demonstrate that the proposal is practical for mobile cloud applications. Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Qiaoyan Wen |
Comput. J. | 3 |
| 2016 | Generalized closest substring encryption
Fuchun Guo, Willy Susilo, Yi Mu 0001 |
Des. Codes Cryptogr. | 1 |
| 2016 | Centralized keyword search on encrypted data for cloud applicationsabstractAbstract Centralized approaches are widely adopted to improve the qualities of outsourced services owing to its feature of efficient system management. Because the cloud is untrusted, data are usually encrypted before outsourcing. One of the interesting applications is searchable encrypted keywords, a well‐known cryptographic primitive that allows encryption while enabling search for keywords. However, achieving data retrieval without revealing privacy in a cloud‐based centralized system is still a challenging problem. In this paper, we introduce centralized approaches to searchable encryption and present a novel centralized system for retrieval services. In our system, the centralized manager can search and access all the encrypted data from authorized users, while each user can only search and access his or her own data. The system builds on a new cryptographic notion calledcentralized keyword search on encrypted data. We formalize its security model and propose a centralized keyword search on encrypted data construction that is featured by short ciphertext and search result verification. We further extend the construction for removing secure channel and enabling batch authentication on data legalities. The experiment demonstrates the performance of our proposals. Copyright © 2016 John Wiley & Sons, Ltd. Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Jianchang Lai |
Secur. Commun. Networks | 3 |
| 2016 | Efficient extensible conditional privacy-preserving authentication scheme supporting batch verification for VANETsabstractAbstract By using pseudo‐identity‐based signature, a conditional privacy‐preserving authentication scheme was proposed in this paper, called EECB, to solve the anonymous authentication issue in vehicular ad hoc networks. In this scheme, pseudo‐identities and the corresponding private keys are generated by the private key generator alone, which is credible and independent. So only Adding private key generators can satisfy the increasing pseudo‐identities demand. In other words, it has achieved the extensible of the scheme. However, the malicious vehicle can only be traced by trust authority. Furthermore, the protocol supports batch verification and the operation of a signature verification only needs two bilinear pairings and some point multiplication. The security of the signature scheme in EECB can be proved to be equivalent to the standard computational Diffie–Hellman problem in the random oracle. The experiment and the analysis indicated that, compared with the existing well‐known schemes, EECB has higher authentication efficiency and less communication cost. Copyright © 2017 John Wiley & Sons, Ltd. Yimin Wang 0004, Hong Zhong 0001, Yan Xu 0007, Jie Cui 0004, Fuchun Guo |
Secur. Commun. Networks | 5 |
| 2016 | Efficient dynamic threshold identity-based encryption with constant-size ciphertext
Willy Susilo, Fuchun Guo, Yi Mu 0001 |
Theor. Comput. Sci. | 2 |
| 2016 | Server-Aided Public Key Encryption With Keyword SearchabstractPublic key encryption with keyword search (PEKS) is a well-known cryptographic primitive for secure searchable data encryption in cloud storage. Unfortunately, it is inherently subject to the (inside) offline keyword guessing attack (KGA), which is against the data privacy of users. Existing countermeasures for dealing with this security issue mainly suffer from low efficiency and are impractical for real applications. In this paper, we provide a practical and applicable treatment on this security vulnerability by formalizing a new PEKS system named server-aided public key encryption with keyword search (SA-PEKS). In SA-PEKS, to generate the keyword ciphertext/trapdoor, the user needs to query a semitrusted third-party called keyword server (KS) by running an authentication protocol, and hence, security against the offline KGA can be obtained. We then introduce a universal transformation from any PEKS scheme to a secure SA-PEKS scheme using the deterministic blind signature. To illustrate its feasibility, we present the first instantiation of SA-PEKS scheme by utilizing the Full Domain Hash RSA signature and the PEKS scheme proposed by Boneh et al. in Eurocrypt 2004. Finally, we describe how to securely implement the client-KS protocol with a rate-limiting mechanism against online KGA and evaluate the performance of our solutions in experiments. Rongmao Chen, Yi Mu 0001, Guomin Yang, Fuchun Guo, Xinyi Huang 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2016 | Dual-Server Public-Key Encryption With Keyword Search for Secure Cloud StorageabstractSearchable encryption is of increasing interest for protecting the data privacy in secure searchable cloud storage. In this paper, we investigate the security of a well-known cryptographic primitive, namely, public key encryption with keyword search (PEKS) which is very useful in many applications of cloud storage. Unfortunately, it has been shown that the traditional PEKS framework suffers from an inherent insecurity called inside keyword guessing attack (KGA) launched by the malicious server. To address this security vulnerability, we propose a new PEKS framework named dual-server PEKS (DS-PEKS). As another main contribution, we define a new variant of the smooth projective hash functions (SPHFs) referred to as linear and homomorphic SPHF (LH-SPHF). We then show a generic construction of secure DS-PEKS from LH-SPHF. To illustrate the feasibility of our new framework, we provide an efficient instantiation of the general framework from a Decision Diffie-Hellman-based LH-SPHF and show that it can achieve the strong security against inside the KGA. Rongmao Chen, Yi Mu 0001, Guomin Yang, Fuchun Guo |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2016 | Distance-Based Encryption: How to Embed Fuzziness in Biometric-Based EncryptionabstractWe introduce a new encryption notion called distance-based encryption (DBE) to apply biometrics in identity-based encryption. In this notion, a ciphertext encrypted with a vector and a threshold value can be decrypted with a private key of another vector, if and only if the distance between these two vectors is less than or equal to the threshold value. The adopted distance measurement is called Mahalanobis distance, which is a generalization of Euclidean distance. This novel distance is a useful recognition approach in the pattern recognition and image processing community. The primary application of this new encryption notion is to incorporate biometric identities, such as face, as the public identity in an identity-based encryption. In such an application, usually the input biometric identity associated with a private key will not be exactly the same as the input biometric identity in the encryption phase, even though they are from the same user. The introduced DBE addresses this problem well as the decryption condition does not require identities to be identical but having small distance. The closest encryption notion to DBE is the fuzzy identity-based encryption, but it measures biometric identities using a different distance called an overlap distance (a variant of Hamming distance) that is not widely accepted by the pattern recognition community, due to its long binary representations. In this paper, we study this new encryption notion and its constructions. We show how to generically and efficiently construct such a DBE from an inner product encryption (IPE) with reasonable size of private keys and ciphertexts. We also propose a new IPE scheme with the shortest private key to build DBE, namely, the need for a short private key. Finally, we study the encryption efficiency of DBE by splitting our IPE encryption algorithm into offline and online algorithms. Fuchun Guo, Willy Susilo, Yi Mu 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | Privacy-Preserving and Regular Language Search Over Encrypted Cloud DataabstractUsing cloud-based storage service, users can remotely store their data to clouds but also enjoy the high quality data retrieval services, without the tedious and cumbersome local data storage and maintenance. However, the sole storage service cannot satisfy all desirable requirements of users. Over the last decade, privacy-preserving search over encrypted cloud data has been a meaningful and practical research topic for outsourced data security. The fact of remote cloud storage service that users cannot have full physical possession of their data makes the privacy data search a formidable mission. A naive solution is to delegate a trusted party to access the stored data and fulfill a search task. This, nevertheless, does not scale well in practice as the fully data access may easily yield harm for user privacy. To securely introduce an effective solution, we should guarantee the privacy of search contents, i.e., what a user wants to search, and return results, i.e., what a server returns to the user. Furthermore, we also need to guarantee privacy for the outsourced data, and bring no additional local search burden to user. In this paper, we design a novel privacy-preserving functional encryption-based search mechanism over encrypted cloud data. A major advantage of our new primitive compared with the existing public key based search systems is that it supports an extreme expressive search mode, regular language search. Our security and performance analysis show that the proposed system is provably secure and more efficient than some searchable systems with high expressiveness. Kaitai Liang, Xinyi Huang 0001, Fuchun Guo, Joseph K. Liu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2015 | A New General Framework for Secure Public Key Encryption with Keyword Search
Rongmao Chen, Yi Mu 0001, Guomin Yang, Fuchun Guo |
ACISP | 4 |
| 2015 | Improved Identity-Based Online/Offline Encryption
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Willy Susilo |
ACISP | 3 |
| 2015 | Vulnerabilities of an ECC-based RFID authentication schemeabstractRadio frequency identification (RFID) authentication is an indispensable part of RFID applications, which allows a reader to identify objects in an authenticated manner. Recently, Liao and Hsiao proposed a very interesting elliptic curve cryptography-based RFID authentication scheme with ID-verifier transfer protocol. They claimed that the proposed protocol is secure against many attacks and satisfies essential security requirements of RFID systems. However, in this paper, we demonstrate that the protocol suffers from several attacks, in contrast to their original claims in the paper. Furthermore, we also propose a repaired version of the authentication protocol against identified attacks, and we provide formal security proofs. Nan Li 0007, Yi Mu 0001, Willy Susilo, Fuchun Guo, Vijay Varadharajan |
Secur. Commun. Networks | 4 |
| 2015 | BL-MLE: Block-Level Message-Locked Encryption for Secure Large File DeduplicationabstractDeduplication is a popular technique widely used to save storage spaces in the cloud. To achieve secure deduplication of encrypted files, Bellare et al. formalized a new cryptographic primitive named message-locked encryption (MLE) in Eurocrypt 2013. Although an MLE scheme can be extended to obtain secure deduplication for large files, it requires a lot of metadata maintained by the end user and the cloud server. In this paper, we propose a new approach to achieve more efficient deduplication for (encrypted) large files. Our approach, named block-level message-locked encryption (BL-MLE), can achieve file-level and block-level deduplication, block key management, and proof of ownership simultaneously using a small set of metadata. We also show that our BL-MLE scheme can be easily extended to support proof of storage, which makes it multi-purpose for secure cloud storage. Rongmao Chen, Yi Mu 0001, Guomin Yang, Fuchun Guo |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2014 | POSTER: Euclidean Distance Based Encryption: How to Embed Fuzziness in Biometric Based EncryptionabstractWe introduce a new encryption notion called Euclidean Distance based Encryption (EDE). In this notion, a ciphertext encrypted with a vector and a threshold value can be decrypted with a private key of another vector, if and only if the Euclidean distance between these two vectors is less than or equal to the threshold value. Euclidean distance is the underlying technique in the pattern recognition and image processing community for image recognition. The primary application of this encryption notion is to enable an identity-based encryption that incorporates biometric identifiers, such as fingerprint, face, hand geometry, vein and iris. In that application, usually the input biometric will not be exactly the same during the enrollment and encryption phases. In this poster, we propose this new encryption notion and study its construction. We show how to generically and efficiently construct an EDE from an inner-product encryption (IPE) with reasonable size of private keys and ciphertexts. We also propose a new IPE scheme that is equipped with a specific characteristic to build EDE, namely the need for short private key. Our IPE scheme achieves the shortest private key compared to existing IPE schemes in the literature, where our private key is composed of two group elements only. Fuchun Guo, Willy Susilo, Yi Mu 0001 |
CCS | 1 |
| 2014 | Attribute-Based Signature with Message Recovery
Kefeng Wang, Yi Mu 0001, Willy Susilo, Fuchun Guo |
ISPEC | 4 |
| 2014 | Server-Aided Signature Verification for Lightweight DevicesabstractServer-aided verification (SAV) has potential applicability in lightweight devices for improving signature verification, where the verifier possesses a computationally weak hardware. We observe that lightweight devices run all algorithms through hardware implementation with logic circuits. Existing SAV protocols indeed improve computational efficiency for lightweight devices, however, few of them take the hardware cost into consideration. The hardware implementation of SAV protocols could be still costly and expensive for lightweight devices. Currently, the most secure SAV protocols in the literature for pairing-based (𝔾1 × 𝔾2 → 𝔾T) signatures can securely delegate pairing computations to the server; however, verifiers are still required to perform group operations over two completely different groups 𝔾1 and 𝔾T, which heavily contribute to the cost of hardware implementation. In this work, we propose several collusion-resistant SAV protocols for pairing-based signatures to improve their applicability for lightweight devices. In our SAV protocols, verifiers are only required to perform group operations in 𝔾1. In comparison with existing SAV protocols, our protocols save the unnecessary hardware cost for implementing group operations in 𝔾T and therefore are more applicable to lightweight applications. Fuchun Guo, Yi Mu 0001, Willy Susilo, Vijay Varadharajan |
Comput. J. | 1 |
| 2014 | Subset Membership Encryption and Its Applications to Oblivious TransferabstractIn this paper, we propose a novel cryptographic notion called subset membership encryption (SME), and provide a very efficient SME scheme. Given a system parameter generated by an encryptor (Alice), a decryptor (Bob) generates a randomized privacy-preserved attribute token P(G) from a set of attributes G. A message is encrypted using an attribute set A chosen by Alice and P(G) provided by Bob. It requires that A is a subset of G for Bob to decrypt the message. We propose a very efficient SME scheme, where both the size of P(G) and ciphertext are short and independent of G and A. In particular, it has three useful and practical applications to oblivious transfer as follows. 1) k-Out-of-n Oblivious Transfer (OT): SME can be naturally applied to a two-round OT, which features a great communication efficiency especially for the receiver, where the receiver only sends two group elements to the message sender. 2) Priced Oblivious Transfer (POT): Our POT protocol allows a buyer to purchase any number of items in each transaction and hide selected items, price and balance from the vendor. In comparison with previous POT protocols, our protocol is more flexible and eliminates the restriction that a buyer can only purchase one item in a transaction. Our POT scheme is very efficient since it does not require any zero-knowledge proof or homomorphic encryption. 3) Restricted Priced Oblivious Transfer (RPOT): We introduce a novel POT named RPOT where a vendor can set restrictions on items or prices in POT. For example, a seller could offer a discounted price to those buyers who have purchased some specific items previously from the same seller. Fuchun Guo, Yi Mu 0001, Willy Susilo |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2014 | CP-ABE With Constant-Size Keys for Lightweight DevicesabstractLightweight devices, such as radio frequency identification tags, have a limited storage capacity, which has become a bottleneck for many applications, especially for security applications. Ciphertext-policy attribute-based encryption (CP-ABE) is a promising cryptographic tool, where the encryptor can decide the access structure that will be used to protect the sensitive data. However, current CP-ABE schemes suffer from the issue of having long decryption keys, in which the size is linear to and dependent on the number of attributes. This drawback prevents the use of lightweight devices in practice as a storage of the decryption keys of the CP-ABE for users. In this paper, we provide an affirmative answer to the above long standing issue, which will make the CP-ABE very practical. We propose a novel CP-ABE scheme with constant-size decryption keys independent of the number of attributes. We found that the size can be as small as 672 bits. In comparison with other schemes in the literature, the proposed scheme is the only CP-ABE with expressive access structures, which is suitable for CP-ABE key storage in lightweight devices. Fuchun Guo, Yi Mu 0001, Willy Susilo, Duncan S. Wong, Vijay Varadharajan |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2013 | Membership Encryption and Its Applications
Fuchun Guo, Yi Mu 0001, Willy Susilo, Vijay Varadharajan |
ACISP | 1 |
| 2012 | Identity-Based Traitor Tracing with Short Private Key and Short Ciphertext
Fuchun Guo, Yi Mu 0001, Willy Susilo |
ESORICS | 1 |
| 2012 | A Pre-computable Signature Scheme with Efficient Verification for RFID
Fuchun Guo, Yi Mu 0001, Willy Susilo, Vijay Varadharajan |
ISPEC | 1 |
| 2011 | Self-certified ring signaturesabstractWe present a new notion, Self-certified Ring Signature (SCRS), to provide an alternative solution to the certificate management problem in ring signatures and eliminate private key escrow problem in identity based ring signatures. Our scheme captures all features of ring signatures and exhibits the advantages such as low storage, communication and computation cost. The main contribution of this paper is a precise definition of self-certified ring signatures along with a concrete construction. We also provide a security model of SCRS and a security proof of our scheme. Nan Li 0007, Yi Mu 0001, Willy Susilo, Fuchun Guo |
AsiaCCS | 4 |
| 2011 | Short Signatures with a Tighter Security Reduction Without Random OraclesabstractThe recent work by Hofheinz and Kiltz (Crypto 2008) has demonstrated that it is feasible to generate a short signature with <320 bits and 80-bit security without the need of random oracles. The authors also showed that the signature length can be reduced to 230 bits if no more than 230 signatures are generated. In this paper, we present three novel short signature schemes with a comparable signature length. Although our schemes can be considered as variants of Hofheinz and Kiltz's schemes, ours can be proved with a much tighter security reduction without random oracles. Our first scheme offers a 270-bit short signature length for 80-bit security without using random oracles and can be tightly reduced to the q-strong Diffie–Hellman problem. Using a stateful signing approach in our second scheme, we show how to further shorten the signature length to 191 bits. Our idea can also be applied to construct short RSA-based signatures with a tight security reduction to the strong RSA problem without random oracles. We note that the 80-bit security defined in all short signature schemes without random oracles is associated with loose reductions or strong assumptions. We compare our schemes with the Boneh–Boyen short signature scheme (Eurocrypt 2004) and the Hofheinz–Kiltz short signature scheme by taking security reductions into account. We show that with the same assumptions, our schemes offer the shortest signatures and achieve the same concrete security. Fuchun Guo, Yi Mu 0001, Willy Susilo |
Comput. J. | 1 |
| 2011 | Improving security of q-SDH based digital signatures
Fuchun Guo, Yi Mu 0001, Willy Susilo |
J. Syst. Softw. | 1 |
| 2010 | Efficient Online/Offline Signatures with Computational Leakage Resilience in Online Phase
Fuchun Guo, Yi Mu 0001, Willy Susilo |
Inscrypt | 1 |
| 2010 | Online/Offline Verification of Short Signatures
Yilian Zhang, Zhide Chen, Fuchun Guo |
Inscrypt | 3 |
| 2009 | How to Prove Security of a Signature with a Tighter Security Reduction
Fuchun Guo, Yi Mu 0001, Willy Susilo |
ProvSec | 1 |
| 2008 | Optimal Online/Offline Signature: How to Sign a Message without Online Computation
Fuchun Guo, Yi Mu 0001 |
ProvSec | 1 |
| 2007 | Mutative Identity-Based Signatures or Dynamic Credentials Without Random Oracles
Fuchun Guo, Yi Mu 0001, Zhide Chen |
CANS | 1 |
| 2007 | Multi-Identity Single-Key Decryption without Random Oracles
Fuchun Guo, Yi Mu 0001, Zhide Chen, Li Xu 0002 |
Inscrypt | 1 |
| 2007 | Identity-Based Encryption: How to Decrypt Multiple Ciphertexts Using a Single Decryption Key
Fuchun Guo, Yi Mu 0001, Zhide Chen |
Pairing | 1 |