VLDB 2026 Research / reviewers in the wild / expert
Yingjiu Li
dblp:15/2506
· DBLP profile ↗
172ranked-venue papers
18as first author
50since 2021 · last 2026
0000-0001-8256-6988ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 130 · 13 first-author · 37 since 2021Databases, data management, data science and information retrieval · 13 · 3 first-authorApplied, interdisciplinary, general and emerging computing · 12 · 8 since 2021Artificial intelligence and machine learning · 5 · 3 first-authorSystems, architecture and hardware · 5 · 3 since 2021Computer networks · 5 · 1 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 1 since 2021Theory of computation · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PriSrv+: Privacy and Usability-Enhanced Wireless Service Discovery with Fast and Expressive Matchmaking Encryption
Yang Yang 0026, Guomin Yang, Yingjiu Li, Pengfei Wu 0003, Minming Huang, Jian Weng 0001, HweeHwa Pang, Robert H. Deng |
NDSS | 3 |
| 2026 | AGChain: A Blockchain-based Gateway for Trustworthy App Delegation from Mobile App MarketsabstractThe popularity of smartphones has led to the growth of mobile app markets, creating a need for enhanced transparency, global access, and secure downloading. This article introduces AGChain, a blockchain-based gateway that enables trustworthy app delegation within existing markets. AGChain ensures that markets can continue providing services while users benefit from permanent, distributed, and secure app delegation. During its development, we address two key challenges: significantly reducing smart contract gas costs and enabling fully distributed IPFS-based file storage. Additionally, we tackle three system issues related to security and sustainability. We have implemented a prototype of AGChain on Ethereum and Polygon blockchains, achieving effective security and decentralization with a minimal gas cost of around 0.0028 USD per app upload (no cost for app download). AGChain also exhibits reasonable performance with an average overhead of 12%. Mengjie Chen, Xiao Yi, Daoyuan Wu, Jianliang Xu, Yingjiu Li, Debin Gao |
Distributed Ledger Technol. Res. Pract. | 5 |
| 2026 | FedWM: Data-Free Watermarking for Model Ownership Protection in Federated LearningabstractThe widespread adoption of federated learning has been driven by growing demands for privacy protection in model training. Federated learning enables multiple clients to collaboratively train a global model coordinated by a central server without sharing their raw data. However, when distributing the global model to clients, the central server faces significant security risks from malicious clients who may steal and misuse the model, thereby compromising its ownership. While existing watermarking techniques typically rely on main task data for ownership protection, their application in federated learning is limited since the server lacks access to this data, which remains with the clients. To address this challenge, we propose a novel data-free watermarking method. We utilize substitute data unrelated to the main task and improve efficiency by filtering out redundant samples. To optimize the watermarking process, we introduce a logits alignment-based optimization strategy that uses the substitute dataset with watermark triggers for effective embedding. Additionally, we propose a dynamic optimization algorithm to balance the trade-off between watermark embedding and main task. We comprehensively evaluate our approach across four datasets, four model architectures, and three mainstream deep learning tasks. Our experimental results demonstrate nearly perfect watermark performance while maintaining minimal impact on the main task. Notably, our watermarking method proves resistant to existing backdoor detection techniques, establishing its effectiveness, robustness and stealthiness. Congyi Li, Peizhuo Lv, Xuejing Yuan, Shengzhi Zhang, Kai Chen 0012, Yingjiu Li |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2026 | Hecate: Threshold Anonymous Credentials With Private Verifiers and Issuer-Hiding
Huamin Feng, Yang Yang 0026, Yingjiu Li, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | ERASE: Bypassing Collaborative Detection of AI Counterfeit via Comprehensive Artifacts EliminationabstractThe rapid advancement of AI-Generated Images (AIGI) has amplified concerns about increasingly undetectable deepfakes. Recent adversarial techniques further worsen this problem by enhancing the imperceptibility of synthetic forgeries to both human viewers and automated detection systems. To simulate realistic adversaries and expose detection vulnerabilities, AI-Generated Image Stealth (AIGI-S) methods specifically aim to make synthetic images harder to detect. However, existing AIGI-S approaches often lack universality and transferability across diverse detection models—especially in collaborative detection settings—and tend to prioritize machine deception over human perceptual fidelity, resulting in visible artifacts. Inspired by real-world antique painting forgery, we propose ERASE (comprehensivE counteRfeit ArtifactS Elimination), a stealth-oriented optimization framework designed for multi-detector environments. ERASE comprehensively suppresses generative artifacts and incorporates a perceptual optimization objective to improve deception against both detection algorithms and human examiners. Extensive evaluations across eight distinct generative subsets from the GenImage benchmark and fifteen detection models demonstrate that ERASE delivers substantially improved attack performance—improving single-detector evasion by +10.5% and collaborative detection evasion by +17.9%—while preserving high image quality. Qianyun Yang, Peizhuo Lv, Yingjiu Li, Shengzhi Zhang, Zhiwei Chen 0003, Zixu Li 0001, Yupeng Hu 0003 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | FlyCred: Contractual Anonymous Credentials Based on Oracles and EventsabstractIn a scenario where an issuer wishes to issue an attribute-based anonymous credential to a user, this issuance is conditional on a number of real-world outcomes. These outcomes involve multiple entrusted oracles confirming the occurrence of several events, after which the issuance can proceed successfully. Such contractual credentials can serve as an important building block for blockchain-based Web 3.0 systems and can be used in real-world applications that require privacy-preserving, prescheduled authorization. However, there is currently no work that enables the pre-issuance of credentials based on oracles and events. In this work, we propose contractual anonymous credentials, called FlyCred, to fill this gap. With FlyCred, the issuer can issue an encrypted credential to a user, controlled by a dual-layer authorization policy consisting of oracle-based and event-based expressive policies. As core building blocks, we introduce two novel cryptographic primitives: the Adaptor Anonymous Credential and ABE-based Signature Witness Encryption with Tags, which can serve as independent interests. We provide efficient instantiations of these primitives and evaluate their performance under different security levels and system parameters on a laptop, showing that the computation and communication overhead of the credential pre-issuance is less than 85.8 seconds and 8.7 MB, respectively. Yang Yang 0026, Huamin Feng, Yingjiu Li, Chunjie Cao, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2026 | Guest Editorial Introduction to the Special Issue on Federated Learning and Digital Twins for Intelligent Transportation System
Kuo-Hui Yeh, Yong Xiang 0001, Yingjiu Li, Chien-Ming Chen 0001 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2025 | IvyAPC: Auditable Generalized Payment Channels
Ming Li 0049, Jian Weng 0001, Yingjiu Li, Jia-Si Weng 0001, Junzuo Lai, Robert H. Deng |
FC | 4 |
| 2025 | Leakage-Resilient Easily Deployable and Efficiently Searchable Encryption (EDESE)abstractEasily Deployable and Efficiently Searchable Encryption (EDESE) is a cryptographic primitive designed for practical searchable applications, offering efficient search and easy deployment. However, it remains vulnerable to Leakage-Abuse attacks, allowing adversaries to exploit keyword-matching processes to extract sensitive information. To address these vulnerabilities, we introduce Leakage-Resilient EDESE (LR-EDESE) with k-indistinguishability and controlled leakage functions. We then propose Volume Leakage-Resilient EDESE (VLR-EDESE), a new scheme to protect against both query and document volume leakage. Our experimental results demonstrate that at k = 5000 (maximum security setting), VLR-EDESE incurs an overhead of 63× compared to the baseline EDESE without leakage protection, outperforming state-of-the-art methods with 320× and 97× overhead, respectively. For smaller k values (10, 20, 50, 100), storage and communication overhead remain within 2× and 2.5× of the baseline EDESE, highlighting VLR-EDESE's flexibility. Finally, we present CloudSec, an implementation of VLR-EDESE that seamlessly integrates with cloud storage platforms, using OneDrive as an example. Jiaming Yuan, Yingjiu Li, Jun Li 0001, Daoyuan Wu, Jianting Ning, Yangguang Tian, Robert H. Deng |
SACMAT | 2 |
| 2025 | AKMA+: Security and Privacy-Enhanced and Standard-Compatible AKMA for 5G Communication
Yang Yang 0026, Guomin Yang, Yingjiu Li, Minming Huang, Zilin Shen, Imtiaz Karim, Ralf Sasse, David A. Basin, Elisa Bertino, Jian Weng 0001, HweeHwa Pang, Robert H. Deng |
USENIX Security Symposium | 3 |
| 2025 | SelfDefend: LLMs Can Defend Themselves against Jailbreaking in a Practical Manner
Xunguang Wang, Daoyuan Wu, Zhenlan Ji, Zongjie Li, Pingchuan Ma 0004, Shuai Wang 0011, Yingjiu Li, Yang Liu 0003, Juergen Rahmel |
USENIX Security Symposium | 7 |
| 2025 | STPCH: strongly traceable policy-based chameleon hash for blockchain rewritingabstractAbstract Policy-based chameleon hash (PCH) is a useful primitive in blockchain rewriting. It allows a party to compute a chameleon hash based on an access policy, and another party who possesses sufficient privileges satisfying the access policy to rewrite the hashed object. However, PCH lacks strong traceability. The chameleon trapdoor holder may abuse their rewriting privilege and maliciously rewrite the hashed object without being identified. In this paper, we introduce a new primitive called strongly traceable policy-based chameleon hash (STPCH for short). We first present a generic framework of STPCH. Then, we present a practical instantiation, show its practicality through implementation and evaluation analysis. Nan Li 0007, Yingjiu Li, Yangguang Tian |
Comput. J. | 2 |
| 2025 | Message Control for Blockchain RewritingabstractBlockchain rewriting is necessary for modifying illegal or invalid messages included in blockchain transactions, while maintaining the consistency of subsequent blocks in the blockchain. However, arbitrary blockchain rewriting is not desirable as it defeats the purpose of blockchain rewriting. In this work, we propose a new security primitive named message-controlled chameleon hash (MCH) and apply it for message control in blockchain rewriting to ensure that no unspecified messages are generated from blockchain rewriting. The proposed MCH enables permitted parties to select candidate messages from designated message sets for blockchain rewriting at the message level. Our evaluation shows that the performance of MCH is comparable to the classic CH [26] and the state-of-the-art CH [16]. We also show that the proposed MCH can be easily integrated into both permissioned and permissionless blockchains. Yingjiu Li, Binanda Sengupta, Yangguang Tian, Jiaming Yuan, Tsz Hon Yuen |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | AccCred: Improved Accountable Anonymous Credentials With Dynamic Triple-Hiding CommitteesabstractAccountable anonymous credentials protect user privacy while holding the accountability of ill-intentioned individuals, which is a critical feature for applications such as online payments and other financial services. Existing accountable anonymous credentials rely on a public committee of trustworthy members who are assumed not to collude and are well protected to perform privacy revocation. However, this assumption is unsound in blockchain-based cryptocurrency systems because the selected committees may involve nodes with significant stakes, and public nodes serving as committee members are vulnerable against targeted attacks from high-computing power adversaries. In this paper, we propose an improved accountable anonymous credential called AccCred, allowing users and issuers to randomly select a hidden committee within a set of authenticated candidates for privacy revocation. No one except the members with corresponding private keys knows their identity, preventing proactive attacks. As a core component, we introduce the primitive of dynamic triple-hiding committees (DTHC), which achieves authentication, dynamic join/delete, random selection, and strong anonymity of committee members. As a building block of DTHC, we design a shuffle protocol to provide efficient shuffle proof of randomized public keys. We formally prove our scheme and compare its performance with previous work for demonstration of practicality. Sijiang Xie, Yang Yang 0026, Huiqin Xie, Yingjiu Li, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | AuditPCH: Auditable Payment Channel Hub With Privacy ProtectionabstractAnonymous Payment Channel Hub (PCH), one of the most promising layer-two solutions, settles the scalability issue in blockchain while guaranteeing the unlinkability of transacting parties. However, such developments bring conflicting requirements, i.e., hiding the sender-to-receiver relationships from any third party but opening the relationship to the auditor. Existing works do not support these requirements simultaneously since off-chain transactions are not recorded in the blockchain. Further, the privacy protection strategies hinder auditors from capturing the payment relationships. Thus, it is still a challenge to audit the finance activities of PCH transacting parties. This paper proposes a novel anonymous PCH solution called AuditPCH to achieve privacy and auditability. Concretely, we design a Linkable Randomizable Puzzle scheme for constructing conditional transactions, allowing a sender to pay for a receiver via the hub. As such, AuditPCH, with the new LRP scheme, ensures that 1) payment relationships can be protected from the hub and 2) an auditor with necessary trapdoors can associate the sender and receiver of a payment. We prove the security of AuditPCH under the Global Universal Composability framework. The extensive experimental evaluations on AuditPCH are established to demonstrate its functionality and flexibility. Jian Weng 0001, Junzuo Lai, Yingjiu Li, Jiahe Wu, Ming Li 0049, Jianfei Sun, Pengfei Wu 0003, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | DkvSSO: Delegatable Keyed-Verification Credentials for Efficient Anonymous Single Sign-OnabstractAnonymous single sign-on (ASSO) is an anonymous multi-service authentication method for end users. However, existing ASSO schemes suffer from heavy ticket requesting and verifying overheads, limiting their applications in large-scale settings. To address this problem, we propose a novel concept called keyed-verification anonymous credentials with disposable delegation (KVAC-DD) in the multi-verifier setting. Next, we extend KVAC-DD to build an efficient ASSO system, dubbed DkvSSO. The construction of DkvSSO can be instantiated in efficient prime-order groups, avoiding costly operations required in previous ASSO systems. We formally prove the security of our proposed constructions. Extensive experiments show that DkvSSO is significantly more efficient than existing ASSO schemes, making it suitable to be deployed in large-scale settings. Wenyi Xue, Yang Yang 0026, Minming Huang, Yingjiu Li, HweeHwa Pang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | SecPLF: Secure Protocols for Loanable Funds against Oracle Manipulation AttacksabstractThe evolving landscape of Decentralized Finance (DeFi) has raised critical security concerns, especially pertaining to Protocols for Loanable Funds (PLFs) and their dependency on price oracles, which are susceptible to manipulation. The emergence of flash loans has further amplified these risks, enabling increasingly complex oracle manipulation attacks that can lead to significant financial losses. Responding to this threat, we first dissect the attack mechanism by formalizing the standard operational and adversary models for PLFs. Based on our analysis, we propose SecPLF, a robust and practical solution designed to counteract oracle manipulation attacks efficiently. SecPLF operates by tracking a price state for each cryptoasset, including the recent price and the timestamp of its last update. By imposing price constraints on the price oracle usage, SecPLF ensures a PLF only engages a price oracle if the last recorded price falls within a defined threshold, thereby negating the profitability of potential attacks. Our evaluation based on historical market data confirms SecPLF's efficacy in providing high-confidence prevention against arbitrage attacks that arise due to minor price differences. SecPLF delivers proactive protection against oracle manipulation attacks, offering ease of implementation, oracle-agnostic property, and resource and cost efficiency. Sanidhay Arora, Yingjiu Li, Yebo Feng, Jiahua Xu 0002 |
AsiaCCS | 2 |
| 2024 | PriSrv: Privacy-Enhanced and Highly Usable Service Discovery in Wireless Communications
Yang Yang 0026, Robert H. Deng, Guomin Yang, Yingjiu Li, HweeHwa Pang, Minming Huang, Jian Weng 0001 |
NDSS | 4 |
| 2024 | Practical and secure policy-based chameleon hash for redactable blockchainsabstractAbstract Policy-based chameleon hash functions have been widely proposed for its use in blockchain rewriting systems. They allow anyone to create a mutable transaction associated with an access policy, while an authorized user who possesses sufficient rewriting privileges from a trusted authority satisfying the access policy can rewrite the mutable transaction. However, existing chameleon hash functions lack certain fundamental security guarantees, including forward security and backward security. In this paper, we introduce a new primitive called forward/backward-secure policy-based chameleon hash (FB-PCH for short). We present a practical instantiation. We prove that the proposed scheme achieves forward/backward-secure collision-resistance, and show its practicality through implementation and evaluation analysis. Nan Li 0007, Yingjiu Li, Mark Manulis, Yangguang Tian, Guomin Yang |
Comput. J. | 2 |
| 2024 | Policy-Based Remote User Authentication From Multi-BiometricsabstractAbstract In this paper, we introduce the first generic framework of policy-based remote user authentication from multiple biometrics. The proposed framework allows an authorized user to remotely authenticate herself to an authentication server using her multiple biometrics, which enhances both the security and usability of user authentications. The authentication server approves a user’s authentication request if and only if the user’s multiple biometrics satisfies an authentication policy. In particular, the authentication policy can be dynamically updated to satisfy different security and usability requirements in practice. We implement an instantiation of the proposed framework and report its performance under various authentication policies. Yangguang Tian, Yingjiu Li, Robert H. Deng, Guomin Yang, Nan Li 0007 |
Comput. J. | 2 |
| 2024 | AnoPas: Practical anonymous transit pass from group signatures with time-bound keys
Yang Yang 0026, Yingjiu Li, Huamin Feng, HweeHwa Pang, Robert H. Deng |
J. Syst. Archit. | 3 |
| 2024 | Double Issuer-Hiding Attribute-Based Credentials From Tag-Based Aggregatable Mercurial SignaturesabstractAttribute-based anonymous credentials offer users fine-grained access control in a privacy-preserving manner. However, in such schemes obtaining a user's credentials requires knowledge of the issuer's public key, which obviously reveals the issuer's identity that must be hidden from users in certain scenarios. Moreover, verifying a user's credentials also requires the knowledge of issuer's public key, which may infer the user's private information from their choice of issuer. In this paper, we introduce the notion of double issuer-hiding attribute-based credentials (${\sf DIHAC}$) to tackle these two problems. In our model, a central authority can issue public-key credentials for a group of issuers, and users can obtain attribute-based credentials from one of the issuers without knowing which one it is. Then, a user can prove that their credential was issued by one of the authenticated issuers without revealing which one to a verifier. We provide a generic construction, as well as a concrete instantiation for${\sf DIHAC}$based on structure-preserving signatures on equivalence classes (JOC's 19) and a novel primitive which we calltag-based aggregatable mercurial signatures. Our construction is efficient without relying on zero-knowledge proofs. We provide rigorous evaluations on personal laptop and smartphone platforms, respectively, to demonstrate its practicability. Yang Yang 0026, Yingjiu Li, Huamin Feng, Guozhen Shi, HweeHwa Pang, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | AnoPay: Anonymous Payment for Vehicle Parking With Updatable CredentialabstractMany existing anonymous parking payment schemes lack high efficiency and flexibility. For instance, the calculation and communication costs involved in payment may linearly increase with the payment amount. In this paper, we propose an anonymous payment system (dubbed AnoPay) for vehicle parking, which leverages updatable attribute-based anonymous credentials and efficient zero-knowledge proof (ZKP) to achieve user anonymity and constant overhead for parking fee payment. To further improve the efficiency, we design a secure parking fee aggregation protocol based on linear homomorphic encryption to aggregate parking transactions, where the amount of each parking transaction is hidden and the privacy of the parking lot in terms of its revenue is guaranteed. AnoPay achieves both unlinkability and accountability, malicious payments can be efficiently traced when it is necessary. We provide a security model and rigorous proof for each security property of AnoPay. Extensive experiments and comparisons demonstrate the efficiency and practicality of the system. Yang Yang 0026, Wenyi Xue, Yonghua Zhan, Minming Huang, Yingjiu Li, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Accountable Fine-Grained Blockchain Rewriting in the Permissionless SettingabstractBlockchain rewriting with fine-grained access control allows a user to create a transaction associated with a set of attributes, while a modifier who possesses sufficient rewriting privileges from a trusted authority satisfying the attribute set can anonymously rewrite the transaction. However, it lacks accountability and is not designed for open blockchains that require no centralized trust authority. In this work, we introduce accountable fine-grained blockchain rewriting in a permissionless setting. The property of accountability allows the modifier’s identity and their rewriting privileges to be held accountable for the modified transactions in case of malicious rewriting. Our contributions are three-fold. First, we present a generic framework for secure blockchain rewriting in the permissionless setting. Second, we present an instantiation of our framework and show its practicality through evaluation analysis. Last, we demonstrate that our proof-of-concept implementation can be effectively integrated into open blockchains. Yangguang Tian, Bowen Liu 0005, Yingjiu Li, Pawel Szalachowski, Jianying Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | PkT-SIN: A Secure Communication Protocol for Space Information Networks With Periodic k-Time Anonymous AuthenticationabstractSpace Information Network (SIN) enables universal Internet connectivity for any object, even in remote and extreme environments where deploying a cellular network is difficult. Access authentication is crucial for ensuring user access control in SIN and preventing unauthorized entities from gaining access to network services. However, due to the complex communication environment in SIN, including exposed links and higher signal delay, designing a secure and efficient authentication scheme presents a significant challenge. In this paper, we propose a secure communication protocol for SIN with periodick-time anonymous authentication (named PkT-SIN) that allows satellite users to anonymously authenticate to ground stations at mostktimes in each single time period. An efficient handover mechanism is designed to ensure seamless communication for satellite users to communicate with different satellites and ground stations, taking into account the dynamic topology of SIN. As a core component of PkT-SIN, we propose a novel primitive, periodick-time keyed-verification anonymous credential (PkT-KVAC), that enables users to derivektokens from a credential for anonymous and unlinkable authentication. On the other hand, a verifier can always recognize a reused token from a dishonest user. PkT-KVAC is of independent contribution to anonymous authentication in pay-per-use business scenarios. Formal security proofs confirm that PkT-SIN and PkT-KVAC have desired security features. The supremacy of their computing features is demonstrated through comprehensive comparison and rigorous performance analysis. Yang Yang 0026, Wenyi Xue, Jianfei Sun, Guomin Yang, Yingjiu Li, HweeHwa Pang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | A Practical Forward-Secure DualRing
Nan Li 0007, Yingjiu Li, Atsuko Miyaji, Yangguang Tian, Tsz Hon Yuen |
CANS | 2 |
| 2023 | PRI: PCH-based privacy-preserving with reusability and interoperability for enhancing blockchain scalability
Jian Weng 0001, Wei Wu 0001, Ming Li 0049, Yingjiu Li, Haoxin Tu, Yongdong Wu, Robert H. Deng |
J. Parallel Distributed Comput. | 5 |
| 2023 | A Robustness-Assured White-Box Watermark in Neural NetworksabstractRecently, stealing highly-valuable and large-scale deep neural network (DNN) models becomes pervasive. The stolen models may be re-commercialized, e.g., deployed in embedded devices, released in model markets, utilized in competitions, etc, which infringes the Intellectual Property (IP) of the original owner. Detecting IP infringement of the stolen models is quite challenging, even with the white-box access to them in the above scenarios, since they may have experienced fine-tuning, pruning, functionality-equivalent adjustment to destruct any embedded watermark. Furthermore, the adversaries may also attempt to extract the embedded watermark or forge a similar watermark to falsely claim ownership. In this article, we propose a novel DNN watermarking solution, named$HufuNet$, to detect IP infringement of DNN models against the above mentioned attacks. Furthermore, HufuNet is the first one theoretically proved to guarantee robustness against fine-tuning attacks. We evaluate HufuNet rigorously on four benchmark datasets with five popular DNN models, including convolutional neural network (CNN) and recurrent neural network (RNN). The experiments and analysis demonstrate that HufuNet is highly robust against model fine-tuning/pruning, transfer learning, kernels cutoff/supplement, functionality-equivalent attacks and fraudulent ownership claims, thus highly promising to protect large-scale DNN models in the real world. Peizhuo Lv, Shengzhi Zhang, Kai Chen 0012, Ruigang Liang, Hualong Ma, Yue Zhao 0018, Yingjiu Li |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2023 | A Secure EMR Sharing System With Tamper Resistance and Expressive Access ControlabstractTo reduce the cost of human and material resources and improve the collaborations among medical systems, research laboratories and insurance companies for healthcare researches and commercial activities, electronic medical records (EMRs) have been proposed to shift from paperwork to friendly shareable electronic records. To take advantage of EMRs efficiently and reduce the cost of local storage, EMRs are usually outsourced to the remote cloud for sharing medical data with authorized users. However, cloud service providers are untrustworthy. In this paper, we propose an efficient, secure, and flexible EMR sharing system by introducing a novel cryptosystem called dual-policy revocable attribute-based encryption and tamper resistance blockchain technology. Our proposed system enables EMRs to be shared at a fine-grained level and allows data users to detect any unauthorized manipulation. Moreover, the key generation center can revoke malicious users without affecting the honest users. We provide the formal security model as well as the concrete scheme with security analysis. The experimental simulation and experimental analysis of our proposed scheme demonstrate that our proposed system has superior performances to the most relevant solutions. Shengmin Xu, Jianting Ning, Yingjiu Li, Yinghui Zhang 0002, Guowen Xu, Xinyi Huang 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | SparkAC: Fine-Grained Access Control in Spark for Secure Data Sharing and AnalyticsabstractWith the development of computing and communication technologies, an extremely large amount of data has been collected, stored, utilized, and shared, while new security and privacy challenges arise. Existing access control mechanisms provided by big data platforms have limitations in granularity and expressiveness. In this article, we present SparkAC, a novel access control mechanism for secure data sharing and analysis in Spark. In particular, we first propose apurpose-aware access control(PAAC) model, which introduces new concepts ofdata processing purposeanddata operation purposeand an automatic purpose analysis algorithm that identifies purposes from data analytics operations and queries. Moreover, we develop a unified access control mechanism that implements PAAC model in two modules. GuardSpark++ supports structured data access control in Spark Catalyst and GuardDAG supports unstructured data access control in Spark core. Finally, we evaluate GuardSpark++ and GuardDAG with multiple data sources, applications, and data analytics engines. Experimental results show that SparkAC provides effective access control functionalities with very small (GuardSpark++) or medium (GuardDAG) performance overhead. Tao Xue 0003, Yu Wen 0001, Bo Luo, Gang Li 0009, Yingjiu Li, Yanfei Hu, Dan Meng 0002 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | Accountable and Fine-Grained Controllable Rewriting in BlockchainsabstractMost blockchains are designed to be immutable such that an object, e.g., a block or a transaction, is persisted once it has been registered. However, blockchain immutability hinders blockchain development due to the increasing abuse of blockchain storage and legal obligations. To break immutability in a controlled way, Derler et al. (NDSS’19) proposed a redactable blockchain with fine-grained controllable rewriting by introducing the notion of policy-based chameleon hash (PCH). Given a PCH-based object associated with an access policy, a trapdoor holder whose rewriting privileges satisfy the access policy can alter the object. Although this work offers an elegant approach to blockchain rewriting, it lacks accountability. In practice, the trapdoor holders may abuse their rewriting privileges, and even use their chameleon trapdoor to build a device in a blackbox manner to gain illegal profits while avoiding being caught. In this paper, we introduce a new design of PCH with blackbox accountability (PCHA). Blackbox accountability offers not only linkability between any modified object and its modifier, but also traceability that enables a central authority to identify responsible trapdoor holders whose secret keys have contributed to the blackbox device. Besides modeling PCHAs, we present a generic construction of PCHAs with rigorous security proofs. We instantiate a concrete construction of PCHA by introducing a practical attribute-based traitor tracing (ABTT) with adaptive security on prime-order pairing groups. The experimental analysis demonstrates that our PCHA and ABTT schemes have modest overheads and superior functionality to the state-of-the-art solutions. In particular, the price of accountability in key generation, hash, and adaption is almost negligible compared to the state-of-the-art solution. Shengmin Xu, Xinyi Huang 0001, Jiaming Yuan, Yingjiu Li, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | ACB-Vote: Efficient, Flexible, and Privacy- Preserving Blockchain-Based Score Voting With Anonymously Convertible BallotsabstractBlockchain has emerged as a decentralized platform for e-voting. Among various blockchain-based voting systems, score voting provides flexible choices and better reflects public opinions. However, existing blockchain-based score voting systems suffer from heavy range proof overheads, and are much inefficient compared with other blockchain-based voting systems. Besides, voter anonymity in these systems is not rigorously addressed. In this paper, we propose an efficient, flexible and privacy-preserving score voting system, named ACB-Vote, from anonymously convertible ballots. ACB-Vote achieves voting anonymity with BBS+ signature and signature of knowledge. Driven by convertibly linkable signatures (CLS), ACB-Vote allows cast ballots to be converted, where the conversion mechanism prevents anonymous voters from multiple voting. Besides, the proposed system avoids heavy range proofs, enables batch ballot verification and facilitates flexible tallying methods. We formally define a security model for ACB-Vote and provide rigorous security proofs. Experiments show that the efficiency of ACB-Vote is competitive compared with the previous score voting systems and is affordable in blockchain environments. Wenyi Xue, Yang Yang 0026, Yingjiu Li, HweeHwa Pang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | CrowdFA: A Privacy-Preserving Mobile Crowdsensing Paradigm via Federated AnalyticsabstractMobile crowdsensing (MCS) systems typically struggle to address the challenge of data aggregation, incentive design, and privacy protection, simultaneously. However, existing solutions usually focus on one or, at most, two of these issues. To this end, this paper presents CROWDFA, a novel paradigm for privacy-preserving MCS through federated analytics (FA), which aims to achieve a well-rounded solution encompassing data aggregation, incentive design, and privacy protection. Specifically, inspired by FA, CRWODFA initiates an MCS computing paradigm that enables data aggregation and incentive design. Participants can perform aggregation operations on their local data, facilitated by CROWDFA, which supports various common data aggregation operations and bidding incentives. To address privacy concerns, CROWDFA relies solely on an efficient cryptographic primitive known as additive secret sharing to simultaneously achieve privacy-preserving data aggregation and privacy-preserving incentive. To instantiate CROWDFA, this paper presents a privacy-preserving data aggregation scheme (PRADA) based on CROWDFA, capable of supporting a range of data aggregation operations. Additionally, a CROWDFA-based privacy-preserving incentive mechanism (PRAED) is designed to ensure truthful and fair incentives for each participant, while maximizing their individual rewards. Theoretical analysis and experimental evaluations demonstrate that CROWDFA protects participants’ data and bid privacy while effectively aggregating sensing data. Notably, CROWDFA outperforms state-of-the-art approaches by achieving up to 22 times faster computation time. Bowen Zhao 0001, Xiaoguo Li, Ximeng Liu, Qingqi Pei, Yingjiu Li, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | Identifiable, But Not Visible: A Privacy-Preserving Person Reidentification SchemeabstractPerson re-identification (Person Re-ID) is widely regarded as a promising technique to identify a target person through surveillance cameras in the wild. Nevertheless, person Re-ID leads to severe personal image privacy concerns as personal images are stipulated by laws and guidelines as private data. To address these concerns, this article explores the first solution for building a privacy-preserving person Re-ID system. Specifically, this article formulizes privacy-preserving person Re-ID as similarity metrics of encrypted feature vectors because the underlying operation of person Re-ID is to compute the similarity of feature vectors that are extracted from person images by a machine learning model. However, feature vectors are generally denoted by floating-point numbers. To this end, this article exploits a series of new encoding mechanisms and secure batch computing protocols to encrypt floating-point feature vectors and achieve the underlying operation of person Re-ID. Rigorous theoretical analyses demonstrate that this work achieves person Re-ID without compromising any personal image privacy. Furthermore, the proposed secure batch protocols significantly enhance the performance of privacy-preserving person Re-ID while outputting the same precision as the previous method. Bowen Zhao 0001, Yingjiu Li, Ximeng Liu, Xiaoguo Li, HweeHwa Pang, Robert H. Deng |
IEEE Trans. Reliab. | 2 |
| 2023 | Threshold Attribute-Based Credentials With Redactable SignatureabstractThreshold attribute-based credentials are suitable for decentralized systems such as blockchains as such systems generally assume that authenticity, confidentiality, and availability can still be guaranteed in the presence of a threshold number of dishonest or faulty nodes. Coconut (NDSS’19) was the first selective disclosure attribute-based credentials scheme supporting threshold issuance. However, it does not support threshold tracing of user identities and threshold revocation of user credentials, which is desired for internal governance such as identity management, data auditing, and accountability. The communication and computation complexities of Coconut for verifying credentials are linear in the number of each user's attributes and thus costly. Addressing these issues, we propose a novel efficient threshold attribute-based anonymous credential scheme. While retaining all the features of Coconut, our scheme supports threshold tracing of user identities and threshold revocation of user credentials, and it significantly reduces the computational and communication complexities of credential verification. In addition, we prove that our scheme enjoys strong security features, including anonymity, blindness, traceability, and non-frameability. Huamin Feng, Yang Yang 0026, Yingjiu Li, HweeHwa Pang, Robert H. Deng |
IEEE Trans. Serv. Comput. | 5 |
| 2022 | M-EDESE: Multi-Domain, Easily Deployable, and Efficiently Searchable Encryption
Jiaming Yuan, Yingjiu Li, Jianting Ning, Robert H. Deng |
ISPEC | 2 |
| 2022 | Approach then connect: A Physical Location-based Wi-Fi Password Dynamic Update SchemeabstractLarge-scale organizations usually deploy Wi-Fi to offer wireless network services for the target users, and password-based authentication is the most commonly adopted to identify Wi-Fi network users. However, multiple security issues occur in the password-based authentication schemes, such as using static passwords, unauthorized user access, and etc. To solve these problems, we propose a dynamic Wi-Fi password scheme updating passwords according to the location-based physical access controls, which is compatible with IEEE 802.11i protocols without introducing extra equipment or user efforts. We reuse the available location based resources in IEEE 802.11 to broadcast dynamic salt values for password updating and implement a prototype system. The experimental results illustrate that the introduced overhead is acceptable (i.e., the disconnection due to password update lasts less than 320ms). Qiongxiao Wang, Jingqiang Lin 0001, Shijie Jia 0001, Yingjiu Li, Yikai Chen |
WCNC | 5 |
| 2022 | Policy-Based Editing-Enabled Signatures: Authenticating Fine-Grained and Restricted Data ModificationabstractAbstract Data owners often encrypt their bulk data and upload it to cloud in order to save storage while protecting privacy of their data at the same time. A data owner can allow a third-party entity to decrypt and access her data. However, if that entity wants to modify the data and publish the same in an authenticated way, she has to ask the owner for a signature on the modified data. This incurs substantial communication overhead if the data is modified often. In this work, we introduce the notion of policy-based editing-enabled signatures, where the data owner specifies a policy for her data such that only an entity satisfying this policy can decrypt the data. Moreover, the entity is permitted to produce a valid signature for the modified data (on behalf of the owner) without interacting with the owner every time the data is modified. On the other hand, a policy-based editing-enabled signature (PB-EES) scheme allows the data owner to choose any set of modification operations applicable to her data and still restricts a (possibly untrusted) entity to authenticate the data modified using operations from that set only. We provide two PB-EES constructions, a generic construction and a concrete instantiation. We formalize the security model for PB-EESs and analyze the security of our constructions. Finally, we evaluate the performance of the concrete PB-EES instantiation. Binanda Sengupta, Yingjiu Li, Yangguang Tian, Robert H. Deng, Zheng Yang 0001 |
Comput. J. | 2 |
| 2022 | Lightweight and Expressive Fine-Grained Access Control for Healthcare Internet-of-ThingsabstractHealthcare Internet-of-Things (IoT) is an emerging paradigm that enables embedded devices to monitor patients vital signals and allows these data to be aggregated and outsourced to the cloud. The cloud enables authorized users to store and share data to enjoy on-demand services. Nevertheless, it also causes many security concerns because of the untrusted network environment, dishonest cloud service providers and resource-limited devices. To preserve patients’ privacy, existing solutions usually apply cryptographic tools to offer access controls. However, fine-grained access control among authorized users is still a challenge, especially for lightweight and resource-limited end-devices. In this paper, we propose a novel healthcare IoT system fusing advantages of attribute-based encryption, cloud and edge computing, which provides an efficient, flexible, secure fine-grained access control mechanism with data verification in healthcare IoT network without any secure channel and enables data users to enjoy the lightweight decryption. We also define the formal security models and present security proofs for our proposed scheme. The extensive comparison and experimental simulation demonstrate that our scheme has better performance than existing solutions. Shengmin Xu, Yingjiu Li, Robert H. Deng, Yinghui Zhang 0002, Xiangyang Luo 0001, Ximeng Liu |
IEEE Trans. Cloud Comput. | 2 |
| 2022 | DeepMnemonic: Password Mnemonic Generation via Deep Attentive Encoder-Decoder ModelabstractStrong passwords are fundamental to the security of password-based user authentication systems. In the recent years, much effort has been made to evaluate the password strength or to generate strong passwords. Unfortunately, the usability or memorability of the strong passwords has been largely neglected. In this article, we aim to bridge the gap between strong password generation and the usability of strong passwords. We propose to automatically generate textual password mnemonics, i.e., natural language sentences, which are intended to help users better memorize passwords. We introduceDeepMnemonic, a deep attentive encoder-decoder framework which takes a password as input and then automatically generates a mnemonic sentence for the password. We conduct extensive experiments to evaluate DeepMnemonic on the real-world data sets. The experimental results demonstrate that DeepMnemonic outperforms a well-known baseline for generating semantically meaningful mnemonic sentences. Moreover, the user study further validates that the generated mnemonic sentences by DeepMnemonic are useful in helping users memorize strong passwords. Yao Cheng 0002, Chang Xu 0019, Zhen Hai, Yingjiu Li |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | SDAC: A Slow-Aging Solution for Android Malware Detection Using Semantic Distance Based API ClusteringabstractA novel slow-aging solution named SDAC is proposed to address the model aging problem in Android malware detection, which is due to the lack of adapting to the changes in Android specifications during malware detection. Different from periodic retraining of detection models in existing solutions, SDAC evolves effectively by evaluating new APIs’ contributions to malware detection according to existing API’s contributions. In SDAC, the contributions of APIs are evaluated by their contexts in the API call sequences extracted from Android apps. A neural network is applied on the sequences to assign APIs to vectors, among which the differences of API vectors are regarded as the semantic distances. SDAC then clusters all APIs based on their semantic distances to create a feature set in the training phase, and extends the feature set to include all new APIs in the detecting phase. Without being trained by any new set of real-labelled apps, SDAC can adapt to the changes in Android specifications by simply identifying new APIs appearing in the detection phase. In extensive experiments with datasets dated from 2011 to 2016, SDAC achieves a significantly higher accuracy and a significantly slower aging speed compared with MaMaDroid, a state-of-the-art Android malware detection solution which maintains resilience to API changes. Jiayun Xu, Yingjiu Li, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Untouchable Once Revoking: A Practical and Secure Dynamic EHR Sharing System via CloudabstractHealthcare Internet-of-Things (IoT) enables lightweight devices to observe patients’ vital signals and outsource them to a remote cloud to enjoy flexible data sharing. However, it faces many security threats as the outsourced data is no longer physically controlled by data owners, and the cloud that hosts the outsourced data is not fully trusted. Many privacy protection technologies have been adopted to solve this problem, among which cryptographic mechanisms have become one of the most promising tools. Unfortunately, current cryptographic mechanisms in healthcare IoT mainly suffer from the following challenges: 1) dynamic user groups for managing users’ accessibility; 2) efficient revocation mechanism to mitigate the burden during user revocation; 3) forward and backward secrecy to ensure session independence in the presence of session key leakage; 4) revocable storage to prevent data users from learning any unauthorized data even the data is authorized before; and 5) information manipulation during data transmission. In this article, we introduce a practical and secure system to address the above problems. Our system provides fine-grained access control with dynamic user groups for optimizing scalability and functionality. We prove that our system is secure against numerous real-world threats. Extensive comparison and experimental analysis demonstrate that our system enjoys superior performance than the state-of-the-art solutions. Shengmin Xu, Jianting Ning, Xinyi Huang 0001, Yingjiu Li, Guowen Xu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Match in My Way: Fine-Grained Bilateral Access Control for Secure Cloud-Fog ComputingabstractCloud-fog computing is a novel paradigm to extend the functionality of cloud computing to provide a variety of on-demand data services via the edge network. Many cryptographic tools have been introduced to preserve data confidentiality against the untrustworthy network and cloud servers. However, how to efficiently identify and retrieve useful data from a large number of ciphertexts without a costly decryption mechanism remains a challenging problem. In this article, we introduce a cloud-fog-device data sharing system (CFDS) with data confidentiality and data source identification simultaneously based on a new cryptographic primitive named matchmaking attribute-based encryption (MABE) by extending matchmaking encryption in CRYPTO’19. Our solution offers a secure fine-grained bilateral access control that includes (1) fine-grained sender access control, (2) fine-grained receiver access control, (3) sender privacy, and (4) performance optimization via outsourcing data source identification to fog nodes. We give the formal definition and security models of MABE, and present a concrete construction with formal security proofs. We also offer a detailed security analysis of our proposed CFDS against real-world security threats. The extensive comparison and experimental simulation demonstrate that, by immigrating heavy workload to fog nodes, our scheme has better functionalities and performances than the most related solutions. Shengmin Xu, Jianting Ning, Yingjiu Li, Yinghui Zhang 0002, Guowen Xu, Xinyi Huang 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | ShieldFL: Mitigating Model Poisoning Attacks in Privacy-Preserving Federated LearningabstractPrivacy-Preserving Federated Learning (PPFL) is an emerging secure distributed learning paradigm that aggregates user-trained local gradients into a federated model through a cryptographic protocol. Unfortunately, PPFL is vulnerable to model poisoning attacks launched by a Byzantine adversary, who crafts malicious local gradients to harm the accuracy of the federated model. To resist model poisoning attacks, existing defense strategies focus on identifying suspicious local gradients over plaintexts. However, the Byzantine adversary submits encrypted poisonous gradients to circumvent existing defense strategies in PPFL, resulting in encrypted model poisoning. To address the issue, in this paper we design a privacy-preserving defense strategy using two-trapdoor homomorphic encryption (referred to as ShieldFL), which can resist encrypted model poisoning without compromising privacy in PPFL. Specially, we first present the secure cosine similarity method aiming to measure the distance between two encrypted gradients. Then, we propose the Byzantine-tolerance aggregation using cosine similarity, which can achieve robustness for both Independently Identically Distribution (IID) and non-IID data. Extensive evaluations on three benchmark datasets (i.e.,MNIST, KDDCup99, and Amazon) show that ShieldFL outperforms existing defense strategies. Especially, ShieldFL can achieve 30%-80% accuracy improvement to defend two state-of-the-art model poisoning attacks in both non-IID and IID settings. Zhuoran Ma 0002, Jianfeng Ma 0001, Yinbin Miao, Yingjiu Li, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | UltraPIN: Inferring PIN Entries via UltrasoundabstractWhile PIN-based user authentication systems such as ATM have long been considered to be secure enough, they are facing new attacks, named UltraPIN, which can be launched from commodity smartphones. As a target user enters a PIN on a PIN-based user authentication system, an attacker may use UltraPIN to infer the PIN from a short distance (50 cm to 100 cm). In this process, UltraPIN leverages smartphone speakers to issue human-inaudible ultrasound signals and uses smartphone microphones to keep recording acoustic signals. It applies a series of signal processing techniques to extract high-quality feature vectors from low-energy and high-noise signals and then applies a combination of machine learning models to classify finger movement patterns during PIN entry and generate a ranked list of highly possible PINs as result. Rigorous experiments show that UltraPIN is highly effective and robust in PIN inference. Yingjiu Li, Robert H. Deng |
AsiaCCS | 2 |
| 2021 | LEAP: Leakage-Abuse Attack on Efficiently Deployable, Efficiently Searchable Encryption with Partially Known DatasetabstractSearchable Encryption (SE) enables private queries on encrypted documents. Most existing SE schemes focus on constructing industrial-ready, practical solutions at the expense of information leakages that are considered acceptable. In particular, ShadowCrypt utilizes a cryptographic approach named ''efficiently deployable, efficiently searchable encryption'' (EDESE) that reveals the encrypted dataset and the query tokens among other information. However, recent attacks showed that such leakages can be exploited to (partially) recover the underlying keywords of query tokens under certain assumptions on the attacker's background knowledge. Jianting Ning, Xinyi Huang 0001, Geong Sen Poh, Jiaming Yuan, Yingjiu Li, Jian Weng 0001, Robert H. Deng |
CCS | 5 |
| 2021 | Differential Training: A Generic Framework to Reduce Label Noises for Android Malware Detection
Jiayun Xu, Yingjiu Li, Robert H. Deng |
NDSS | 2 |
| 2021 | Unlinkable and Revocable Secret HandshakeabstractAbstract In this paper, we introduce a new construction for unlinkable secret handshake that allows a group of users to perform handshakes anonymously. We define formal security models for the proposed construction and prove that it can achieve session key security, anonymity and affiliation hiding. In particular, the proposed construction ensures that (i) anonymity against protocol participants (including group authority) is achieved since a hierarchical identity-based signature is used in generating group user’s pseudonym-credential pairs and (ii) revocation is achieved using a secret sharing-based revocation mechanism. Yangguang Tian, Yingjiu Li, Yi Mu 0001, Guomin Yang |
Comput. J. | 2 |
| 2021 | Lattice-based remote user authentication from reusable fuzzy signatureabstractIn this paper, we introduce a new construction of reusable fuzzy signature based remote user authentication that is secure against quantum computers. We investigate the reusability of fuzzy signature, and we prove that the fuzzy signature schemes provide biometrics reusability (aka. reusable fuzzy signature). We define formal security models for the proposed construction, and we prove that it achieves user authenticity and user privacy. The proposed construction ensures: 1) a user’s biometrics can be securely reused in remote user authentication; 2) a third party having access to the communication channel between a user and the authentication server cannot identify the user. Yangguang Tian, Yingjiu Li, Robert H. Deng, Binanda Sengupta, Guomin Yang |
J. Comput. Secur. | 2 |
| 2021 | Designing Leakage-Resilient Password Entry on Head-Mounted Smart Wearable Glass DevicesabstractWith the boom of Augmented Reality (AR) and Virtual Reality (VR) applications, head-mounted smart wearable glass devices are becoming popular to help users access various services like E-mail freely. However, most existing password entry schemes on smart glasses rely on additional computers or mobile devices connected to smart glasses, which require users to switch between different systems and devices. This may greatly lower the practicability and usability of smart glasses. In this paper, we focus on this challenge and design three practical anti-eavesdropping password entry schemes on stand-alone smart glasses, named gTapper, gRotator and gTalker. The main idea is to break the correlation between the underlying password and the interaction observable to adversaries. In our IRB-approved user study, these schemes are found to be easy-to-use without additional hardware under various test conditions, where the participants can enter their passwords within moderate time, at high accuracy, and in various situations. Yan Li 0075, Weizhi Meng 0001, Yingjiu Li, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2020 | Policy-based Chameleon Hash for Blockchain Rewriting with Black-box AccountabilityabstractPolicy-based chameleon hash is a useful primitive for blockchain rewriting. It allows a party to create a transaction associated with an access policy, while another party who possesses enough rewriting privileges satisfying the access policy can rewrite the transaction. However, it lacks accountability. The chameleon trapdoor holder may abuse his/her rewriting privilege and maliciously rewrite the hashed object in the transaction without being identified. In this paper, we introduce policy-based chameleon hash with black-box accountability (PCHBA). Black-box accountability allows an attribute authority to link modified transactions to responsible transaction modifiers in case of dispute, in which any public user identifies those transaction modifiers from interacting with an access device/blackbox. We first present a generic framework of PCHBA. Then, we present a practical instantiation, showing its practicality through implementation and evaluation analysis. Yangguang Tian, Nan Li 0007, Yingjiu Li, Pawel Szalachowski, Jianying Zhou 0001 |
ACSAC | 3 |
| 2020 | GuardSpark++: Fine-Grained Purpose-Aware Access Control for Secure Data Sharing and Analysis in SparkabstractWith the development of computing and communication technologies, extremely large amount of data has been collected, stored, utilized, and shared, while new security and privacy challenges arise. Existing platforms do not provide flexible and practical access control mechanisms for big data analytics applications. In this paper, we present GuardSpark++, a fine-grained access control mechanism for secure data sharing and analysis in Spark. In particular, we first propose a purpose-aware access control (PAAC) model, which introduces new concepts of data processing/operation purposes to conventional purpose-based access control. An automatic purpose analysis algorithm is developed to identify purposes from data analytics operations and queries, so that access control could be enforced accordingly. Moreover, we develop an access control mechanism in Spark Catalyst, which provides unified PAAC enforcement for heterogeneous data sources and upper-layer applications. We evaluate GuardSpark++ with five data sources and four structured data analytics engines in Spark. The experimental results show that GuardSpark++ provides effective access control functionalities with a very small performance overhead (average 3.97%). Tao Xue 0003, Yu Wen 0001, Bo Luo, Yanfei Hu, Yingjiu Li, Gang Li 0009, Dan Meng 0002 |
ACSAC | 7 |
| 2020 | A New Construction for Linkable Secret HandshakeabstractAbstract In this paper, we introduce a new construction for linkable secret handshake that allows authenticated users to perform handshake anonymously within allowable times. We define formal security models for the new construction, and prove that it can achieve session key security, anonymity, untraceability and linkable affiliation-hiding. In particular, the proposed construction ensures that (i) anyone can trace the real identities of dishonest users who perform handshakes for more than k times; and (ii) an optimal communication cost between authorized users is achieved by exploiting the proof of knowledges. Yangguang Tian, Yingjiu Li, Robert H. Deng, Nan Li 0007, Guomin Yang, Zheng Yang 0001 |
Comput. J. | 2 |
| 2020 | Editing-Enabled Signatures: A New Tool for Editing Authenticated DataabstractData authentication primarily serves as a tool to achieve data integrity and source authentication. However, traditional data authentication does not fit well where an intermediate entity (editor) is required to modify the authenticated data provided by the source/data owner before sending the data to other recipients. To ask the data owner for authenticating each modified data can lead to higher communication overhead. In this article, we introduce the notion of editing-enabled signatures where the data owner can choose any set of modification operations applicable on the data and still can restrict any possibly untrusted editor to authenticate the data modified using an operation from this set only. Moreover, the editor does not need to interact with the data owner in order to authenticate the data every time it is modified. We construct an editing-enabled signature (EES) scheme that derives its efficiency from mostly lightweight cryptographic primitives. We formalize the security model for editing-enabled signatures and analyze the security of our EES scheme. Editing-enabled signatures can find numerous applications that involve generic editing tasks and privacy-preserving operations. We demonstrate how our EES scheme can be applied in two privacy-preserving applications. Binanda Sengupta, Yingjiu Li, Yangguang Tian, Robert H. Deng |
IEEE Internet Things J. | 2 |
| 2020 | Efficient ciphertext-policy attribute-based encryption with blackbox traceability
Shengmin Xu, Jiaming Yuan, Guowen Xu, Yingjiu Li, Ximeng Liu, Yinghui Zhang 0002, Zuobin Ying |
Inf. Sci. | 4 |
| 2020 | A new framework for privacy-preserving biometric-based remote user authenticationabstractIn this paper, we introduce the first general framework for strong privacy-preserving biometric-based remote user authentication based on oblivious RAM (ORAM) protocol and computational fuzzy extractors. We define formal security models for the general framework, and we prove that it can achieve user authenticity and strong privacy. In particular, the general framework ensures that: (1) a strong privacy and a log-linear time-complexity are achieved by using a new tree-based ORAM protocol; (2) a constant bandwidth cost is achieved by exploiting computational fuzzy extractors in the challenge-response phase of remote user authentications. Yangguang Tian, Yingjiu Li, Robert H. Deng, Nan Li 0007, Pengfei Wu 0003, Anyi Liu |
J. Comput. Secur. | 2 |
| 2020 | Leakage-resilient biometric-based remote user authentication with fuzzy extractors
Yangguang Tian, Yingjiu Li, Binanda Sengupta, Nan Li 0007, Chunhua Su |
Theor. Comput. Sci. | 2 |
| 2020 | Lightweight Sharable and Traceable Secure Mobile Health SystemabstractMobile health (mHealth) has emerged as a new patient centric model which allows real-time collection of patient data via wearable sensors, aggregation and encryption of these data at mobile devices, and then uploading the encrypted data to the cloud for storage and access by healthcare staff and researchers. However, efficient and scalable sharing of encrypted data has been a very challenging problem. In this paper, we propose a Lightweight Sharable and Traceable (LiST) secure mobile health system in which patient data are encrypted end-to-end from a patient's mobile device to data users. LiST enables efficient keyword search and fine-grained access control of encrypted data, supports tracing of traitors who sell their search and access privileges for monetary gain, and allows on-demand user revocation. LiST is lightweight in the sense that it offloads most of the heavy cryptographic computations to the cloud while only lightweight operations are performed at the end user devices. We formally define the security of LiST and prove that it is secure without random oracle. We also conduct extensive experiments to access the system's performance. Yang Yang 0026, Ximeng Liu, Robert H. Deng, Yingjiu Li |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2020 | Privacy-preserving Network Path ValidationabstractThe end-users communicating over a network path currently have no control over the path. For a better quality of service, the source node often opts for a superior (or premium) network path to send packets to the destination node. However, the current Internet architecture provides no assurance that the packets indeed follow the designated path. Network path validation schemes address this issue and enable each node present on a network path to validate whether each packet has followed the specific path so far. In this work, we introduce two notions of privacy— path privacy and index privacy —in the context of network path validation. We show that, in case a network path validation scheme does not satisfy these two properties, the scheme is vulnerable to certain practical attacks (that affect the privacy, reliability, neutrality and quality of service offered by the underlying network). To the best of our knowledge, ours is the first work that addresses privacy issues related to network path validation. We design PrivNPV, a privacy-preserving network path validation protocol, that satisfies both path privacy and index privacy. We discuss several attacks related to network path validation and how PrivNPV defends against these attacks. Finally, we discuss the practicality of PrivNPV based on relevant parameters. Binanda Sengupta, Yingjiu Li, Kai Bu, Robert H. Deng |
ACM Trans. Internet Techn. | 2 |
| 2019 | Anonymous Asynchronous Payment Channel from k-Time Accountable Assertion
Yangguang Tian, Yingjiu Li, Binanda Sengupta, Nan Li 0007, Yong Yu 0002 |
CANS | 2 |
| 2019 | A Closer Look Tells More: A Facial Distortion Based Liveness Detection for Face AuthenticationabstractFace authentication is vulnerable to media-based virtual face forgery (MVFF) where adversaries display photos/videos or 3D virtual face models of victims to spoof face authentication systems. In this paper, we propose a liveness detection mechanism, called FaceCloseup, to protect the face authentication on mobile devices. FaceCloseup detects MVFF-based attacks by analyzing the distortion of face regions in a user's closeup facial videos captured by built-in camera on mobile device. It can detect MVFF-based attacks with an accuracy of 99.48%. Yan Li 0075, Zilong Wang 0001, Yingjiu Li, Robert H. Deng, Binbin Chen 0001, Weizhi Meng 0001, Hui Li 0006 |
AsiaCCS | 3 |
| 2019 | DroidEvolver: Self-Evolving Android Malware Detection SystemabstractGiven the frequent changes in the Android framework and the continuous evolution of Android malware, it is challenging to detect malware over time in an effective and scalable manner. To address this challenge, we propose DroidEvolver, an Android malware detection system that can automatically and continually update itself during malware detection without any human involvement. While most existing malware detection systems can be updated by retraining on new applications with true labels, DroidEvolver requires neither retraining nor true labels to update itself, mainly due to the insight that DroidEvolver makes necessary and lightweight update using online learning techniques with evolving feature set and pseudo labels. The detection performance of DroidEvolver is evaluated on a dataset of 33,294 benign applications and 34,722 malicious applications developed over a period of six years. Using 6,286 applications dated in 2011 as the initial training set, DroidEvolver achieves high detection F-measure (95.27%), which only declines by 1.06% on average per year over the next five years for classifying 57,539 newly appeared applications. Note that such new applications could use new techniques and new APIs, which are not known to DroidEvolver when initialized with 2011 applications. Compared with the state-of-the-art overtime malware detection system MAMADROID, the F-measure of DroidEvolver is 2.19 times higher on average (10.21 times higher for the fifth year), and the efficiency of DroidEvolver is 28.58 times higher than MAMADROID during malware detection. DroidEvolver is also shown robust against typical code obfuscation techniques. Yingjiu Li, Robert H. Deng, Jiayun Xu |
EuroS&P | 2 |
| 2019 | Generic Construction of ElGamal-Type Attribute-Based Encryption Schemes with Revocability and Dual-Policy
Shengmin Xu, Yinghui Zhang 0002, Yingjiu Li, Ximeng Liu, Guomin Yang |
SecureComm (2) | 3 |
| 2019 | When Human cognitive modeling meets PINs: User-independent inter-keystroke timing attacks
Yingjiu Li, Robert H. Deng, Bing Chang, Shujun Li 0001 |
Comput. Secur. | 2 |
| 2019 | DABKE: Secure deniable attribute-based key exchange frameworkabstractWe introduce the first deniable attribute-based key exchange (DABKE) framework that is resilient to impersonation attacks. We define the formal security models for DABKE framework, and propose a generic compiler that converts any attribute-based key exchanges into deniable ones. We prove that it can achieve session key security and user privacy in the standard model, and strong deniability in the simulation-based paradigm. In particular, the proposed generic compiler ensures: 1) a dishonest user cannot impersonate other user’s session participation in conversations since implicit authentication is used among authorized users; 2) an authorized user can plausibly deny his/her participation after secure conversations with others; 3) the strongest form of deniability is achieved using one-round communication between two authorized users. Yangguang Tian, Yingjiu Li, Guomin Yang, Willy Susilo, Yi Mu 0001, Hui Cui 0001, Yinghui Zhang 0002 |
J. Comput. Secur. | 2 |
| 2019 | Collusion attacks and fair time-locked deposits for fast-payment transactions in BitcoinabstractIn Bitcoin network, the distributed storage of multiple copies of the block chain opens up possibilities for double-spending, i.e., a payer issues two separate transactions to two different payees transferring the same coins. While Bitcoin has inherent security mechanism to prevent double-spending attacks, it requires a certain amount of time to detect the double-spending attacks after the transaction has been initiated. Therefore, it is impractical to protect the payees from suffering in double-spending attacks in fast payment scenarios where the time between the exchange of currency and goods or services is shorten to few seconds. Although we cannot prevent double-spending attacks immediately for fast payments, decentralized non-equivocation contracts have been proposed to penalize the malicious payer after the attacks have been detected. The basic idea of these contracts is that the payer locks some coins in a deposit when he initiates a transaction with the payee. If the payer double-spends, a cryptographic primitive called accountable assertions can be used to reveal his Bitcoin credentials for the deposit. Thus, the malicious payer could be penalized by the loss of deposit coins. However, such decentralized non-equivocation contracts are subjected to collusion attacks where the payer colludes with the beneficiary of the depoist and transfers the Bitcoin deposit back to himself when he double-spends, resulting in no penalties. On the other hand, even if the beneficiary behaves honestly, the victim payee cannot get any compensation directly from the deposit in the original design. To prevent such collusion attacks, we design fair time-locked deposits for Bitcoin transactions to defend against double-spending. The fair deposits ensure that the payer will be penalized by the loss of his deposit coins if he double-spends and the victim payee’s loss will be compensated within a locked time period. We start with the protocols of making a deposit for one transaction. In particular, for the transaction with single input and output and the transaction with multiple inputs and outputs, we provide different designs of the deposits. We analyze the performance of deposits made for one transaction and show how the fair deposits work efficiently in Bitcoin. We also provide protocols of making a deposit for multiple transactions, which can reduce the burdens of a honest payer. In the end, we extend the fair deposits to non-equivocation contracts for other distributed systems. Xingjie Yu, Michael Thang Shiwen, Yingjiu Li, Robert H. Deng |
J. Comput. Secur. | 3 |
| 2019 | Attribute-Based Storage Supporting Secure Deduplication of Encrypted Data in CloudabstractAttribute-based encryption (ABE) has been widely used in cloud computing where a data provider outsources his/her encrypted data to a cloud service provider, and can share the data with users possessing specific credentials (or attributes). However, the standard ABE system does not support secure deduplication, which is crucial for eliminating duplicate copies of identical data in order to save storage space and network bandwidth. In this paper, we present an attribute-based storage system with secure deduplication in a hybrid cloud setting, where a private cloud is responsible for duplicate detection and a public cloud manages the storage. Compared with the prior data deduplication systems, our system has two advantages. First, it can be used to confidentially share data with users by specifying access policies rather than sharing decryption keys. Second, it achieves the standard notion of semantic security for data confidentiality while existing systems only achieve it by defining a weaker security notion. In addition, we put forth a methodology to modify a ciphertext over one access policy into ciphertexts of the same plaintext but under other access policies without revealing the underlying plaintext. Hui Cui 0001, Robert H. Deng, Yingjiu Li |
IEEE Trans. Big Data | 3 |
| 2019 | LiveForen: Ensuring Live Forensic Integrity in the CloudabstractTo expedite the forensic investigation process in the cloud, excessive and yet volatile data need to be acquired, transmitted, and analyzed in a timely manner. A common assumption for most existing forensic systems is that credible data can always be collected from a cloud infrastructure, which might be susceptible to various exploits. In this paper, we present the design, implementation, and evaluation of LiveForen, a system that enforces a trustworthy forensic data acquisition and transmission process in the cloud, whose computer platforms' integrity has been verified. To fulfill this objective, we propose two secure protocols that verify the fingerprints of the computer platforms, as well as the attributes of the human agents, by taking advantage of the trusted platform module and the attribute-based encryption. To transmit forensic data as a data stream and verify its integrity at the same time, a unique fragile watermark is embedded into the data stream without altering the data itself. The watermark allows not only the data integrity to be verified but also any malicious data manipulation to be localized, with minimum communication overhead. The experimental results demonstrate that LiveForen achieves good scalability and limited performance overhead for authentication, data transmission, and integrity verification in an Infrastructure-as-a-Service cloud environment. Anyi Liu, Huirong Fu, Yuan Hong 0001, Jigang Liu, Yingjiu Li |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2018 | Typing-Proof: Usable, Secure and Low-Cost Two-Factor Authentication Based on Keystroke TimingsabstractTwo-factor authentication (2FA) systems provide another layer of protection to users' accounts beyond password. Traditional hardware token based 2FA and software token based 2FA are not burdenless to users since they require users to read, remember, and type a onetime code in the process, and incur high costs in deployments or operations. Recent 2FA mechanisms such as Sound-Proof, reduce or eliminate users' interactions for the proof of the second factor; however, they are not designed to be used in certain settings (e.g., quiet environments or PCs without built-in microphones), and they are not secure in the presence of certain attacks (e.g., sound-danger attack and co-located attack). Yingjiu Li, Robert H. Deng |
ACSAC | 2 |
| 2018 | Privacy-Preserving Remote User Authentication with k-Times Untraceability
Yangguang Tian, Yingjiu Li, Binanda Sengupta, Robert H. Deng, Albert Ching, Weiwei Liu 0005 |
Inscrypt | 2 |
| 2018 | SCLib: A Practical and Lightweight Defense against Component Hijacking in Android ApplicationsabstractCross-app collaboration via inter-component communication is a fundamental mechanism on Android. Although it brings the benefits such as functionality reuse and data sharing, a threat called component hijacking is also introduced. By hijacking a vulnerable component in victim apps, an attack app can escalate its privilege for operations originally prohibited. Many prior studies have been performed to understand and mitigate this issue, but no defense is being deployed in the wild, largely due to the deployment difficulties and performance concerns. In this paper we present SCLib, a secure component library that performs in-app mandatory access control on behalf of app components. It does not require firmware modification or app repackaging as in previous works. The library-based nature also makes SCLib more accessible to app developers, and enables them produce secure components in the first place over fragmented Android devices. As a proof of concept, we design six mandatory policies and overcome unique implementation challenges to mitigate attacks originated from both system weaknesses and common developer mistakes. Our evaluation using ten high-profile open source apps shows that SCLib can protect their 35 risky components with negligible code footprint (less than 0.3% stub code) and nearly no slowdown to normal intra-app communication. The worst-case performance overhead is only about 5%. Daoyuan Wu, Debin Gao, Yingjiu Li, Robert H. Deng |
CODASPY | 4 |
| 2018 | MobiCeal: Towards Secure and Practical Plausibly Deniable Encryption on Mobile DevicesabstractWe introduce MobiCeal, the first practical Plausibly Deniable Encryption (PDE) system for mobile devices that can defend against strong coercive multi-snapshot adversaries, who may examine the storage medium of a user's mobile device at different points of time and force the user to decrypt data. MobiCeal relies on "dummy write" to obfuscate the differences between multiple snapshots of storage medium due to existence of hidden data. By incorporating PDE in block layer, MobiCeal supports a broad deployment of any block-based file systems on mobile devices. More importantly, MobiCeal is secure against side channel attacks which pose a serious threat to existing PDE schemes. A proof of concept implementation of MobiCeal is provided on an LG Nexus 4 Android phone using Android 4.2.2. It is shown that the performance of MobiCeal is significantly better than prior PDE systems against multi-snapshot adversaries. Bing Chang, Fengwei Zhang, Yingjiu Li, Wen Tao Zhu, Yangguang Tian, Albert Ching |
DSN | 4 |
| 2018 | DeepRefiner: Multi-layer Android Malware Detection System Applying Deep Neural NetworksabstractAs malicious behaviors vary significantly across mobile malware, it is challenging to detect malware both efficiently and effectively. Also due to the continuous evolution of malicious behaviors, it is difficult to extract features by laborious human feature engineering and keep up with the speed of malware evolution. To solve these challenges, we propose DeepRefiner to identify malware both efficiently and effectively. The novel technique enabling effectiveness is the semantic-based deep learning. We use Long Short Term Memory on the semantic structure of Android bytecode, avoiding missing the details of method-level bytecode semantics. To achieve efficiency, we apply Multilayer Perceptron on the xml files based on the finding that most malware can be efficiently identified using information only from xml files. We evaluate the detection performance of DeepRefiner with 62,915 malicious applications and 47,525 benign applications, showing that DeepRefiner effectively detects malware with an accuracy of 97.74% and a false positive rate of 2.54%. We compare DeepRefiner with a state-of-the-art single classifierbased detection system, StormDroid, and ten widely used signature-based anti-virus scanners. The experimental results show that DeepRefiner significantly outperforms StormDroid and anti-virus scanners. In addition, we evaluate the robustness of DeepRefiner against typical obfuscation techniques and adversarial samples. The experimental results demonstrate that DeepRefiner is robust in detecting obfuscated malicious applications. Yingjiu Li, Robert H. Deng |
EuroS&P | 2 |
| 2018 | DSH: Deniable Secret Handshake Framework
Yangguang Tian, Yingjiu Li, Yinghui Zhang 0002, Nan Li 0007, Guomin Yang, Yong Yu 0002 |
ISPEC | 2 |
| 2018 | Privacy-Preserving Biometric-Based Remote User Authentication with Leakage Resilience
Yangguang Tian, Yingjiu Li, Rongmao Chen, Nan Li 0007, Ximeng Liu, Bing Chang, Xingjie Yu |
SecureComm (1) | 2 |
| 2018 | User-friendly deniable storage for mobile devices
Bing Chang, Fengwei Zhang, Wen Tao Zhu, Yingjiu Li |
Comput. Secur. | 6 |
| 2018 | Making a good thing better: enhancing password/PIN-based user authentication with smartwatchabstractWearing smartwatches becomes increasingly popular in people’s lives. This paper shows that a smartwatch can help its bearer authenticate to a login system effectively and securely even if the bearer’s password has already been revealed. This idea is motivated by our observation that a sensor-rich smartwatch is capable of tracking the wrist motions of its bearer typing a password or PIN, which can be used as an authentication factor. The major challenge in this research is that a sophisticated attacker may imitate a user’s typing behavior as shown in previous research on keystroke dynamics based user authentication. We address this challenge by applying a set of machine learning and deep learning classifiers on the user’s wrist motion data that are collected from a smartwatch worn by the user when inputting his/her password or PIN. Our solution is user-friendly since it does not require users to perform any additional actions when typing passwords or PINs other than wearing smartwatches. We conduct a user study involving 51 participants so as to evaluate the feasibility and performance of our solution. User study results show that the best classifier is the Bagged Decision Trees, which yields 4.58% FRR and 0.12% FAR on a QWERTY keyboard, and 6.13% FRR and 0.16% FAR on a numeric keypad. Bing Chang, Yingjiu Li, Qiongxiao Wang, Wen Tao Zhu, Robert H. Deng |
Cybersecur. | 2 |
| 2018 | Attribute-based cloud storage with secure provenance over encrypted data
Hui Cui 0001, Robert H. Deng, Yingjiu Li |
Future Gener. Comput. Syst. | 3 |
| 2018 | Efficient and Expressive Keyword Search Over Encrypted Data in CloudabstractSearchable encryption allows a cloud server to conduct keyword search over encrypted data on behalf of the data users without learning the underlying plaintexts. However, most existing searchable encryption schemes only support single or conjunctive keyword search, while a few other schemes that are able to perform expressive keyword search are computationally inefficient since they are built from bilinear pairings over the composite-order groups. In this paper, we propose an expressive public-key searchable encryption scheme in the prime-order groups, which allows keyword search policies (i.e., predicates, access structures) to be expressed in conjunctive, disjunctive or any monotonic Boolean formulas and achieves significant performance improvement over existing schemes. We formally define its security, and prove that it is selectively secure in the standard model. Also, we implement the proposed scheme using a rapid prototyping tool called Charm [37], and conduct several experiments to evaluate it performance. The results demonstrate that our scheme is much more efficient than the ones built over the composite-order groups. Hui Cui 0001, Zhiguo Wan, Robert H. Deng, Guilin Wang, Yingjiu Li |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2018 | Empirical Study of Face Authentication Systems Under OSNFD AttacksabstractFace authentication has been widely available on smartphones, tablets, and laptops. As numerous personal images are published in online social networks (OSNs), OSN-based facial disclosure (OSNFD) creates significant threat against face authentication. We make the first attempt to quantitatively measure OSNFD threat to real-world face authentication systems on smartphones, tablets, and laptops. Our results show that the percentage of vulnerable users that are subject to spoofing attacks is high, which is about 64 percent for laptop users, and 93 percent smartphone/tablet users. We investigate liveness detection methods in the real-world face authentication systems against OSNFD threat. We discover that under protection of liveness detection, the percentage of vulnerable images is 18.8 percent, but the percentage of vulnerable users is as high as 73.3 percent. This evidence suggests that the current face authentication systems are not strong enough under OSNFD attacks. Finally, we develop a risk estimation tool based on logistic regression, and analyze the impacts of key attributes of facial images on the OSNFD risk. Our statistical analysis reveals that the most influential attributes of facial images are image resolution, facial makeup, occluded eyes, and illumination. This tool can be used to evaluate OSNFD risk for OSN images to increase users' awareness of OSNFD. Yan Li 0075, Yingjiu Li, Qiang Yan 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2018 | Every Step You Take, I'll Be Watching You: Practical StepAuth-Entication of RFID PathsabstractPath authentication thwarts counterfeits in RFID-based supply chains. Its motivation is that tagged products taking invalid paths are likely faked and injected by adversaries at certain supply chain partners/steps. Existing solutions are path-grained in that they simply regard a product as genuine if it takes any valid path. Furthermore, they enforce distributed authentication by offloading the sets of valid paths to some or all steps from a centralized issuer. This not only imposes network and storage overhead but also leaks transaction privacy. We present StepAuth, the first step-grained path authentication protocol that is practically efficient for authenticating products with strict path bindings. We encode a path into a secret with minimum path visibility disclosure between adjacent steps. Carrying the secret, a product has to go through steps in the exact order as in the designated path to pass authentication. StepAuth enforces no tag computation and enables each step to locally verify path secrets without pre-offloaded valid-path sets. Toward an even higher security guarantee, StepAuth can hinder an adversary capable of compromising all steps from forging valid secrets. We make StepAuth practically efficient by taking advantage of nested encryption and hybrid encryption. To achieve a 128-b security for a practically long path of 100 steps, StepAuth generates a secret around 10 KB, which can be well supported by high-memory EPC Gen2 tags. Such secrets take StepAuth less than 1 s to encode and around 10 ms to verify. Kai Bu, Yingjiu Li |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | Server-Aided Attribute-Based Signature With Revocation for Resource-Constrained Industrial-Internet-of-Things DevicesabstractThe industrial Internet-of-things (IIoT) can be seen as the usage of Internet-of-things technologies in industries, which provides a way to improve the operational efficiency. An attribute-based signature (ABS) has been a very useful technique for services requiring anonymous authentication in practice, where a signer can sign a message over a set of attributes without disclosing any information about his/her identity, and a signature only attests to the fact that it is created by a signer with several attributes satisfying some claim predicate. However, an ABS scheme requires exponentiation and/or pairing operations in the signature generation and verification algorithms, and hence, it is quite expensive for resource-constrained devices like a sensor in the IIoT network to run an ABS scheme. To reduce the computational overheads for both signers and verifiers, it has been suggested to introduce a server to help with signature generation and verification, but existing results on the ABS with “server-aided computation” either suffer from the security issues or are not sufficiently efficient. In this paper, we consider server-aided ABS one step further, and propose a notion called server-aided ABS with revocation (SA-ABSR), which not only securely mitigates the workloads of users in generating and verifying signatures, but also enables user revocation by having the server immediately stop signature generations for revoked signers. We formally define the security model for SA-ABSR, present a concrete construction of SA-ABSR based on a standard ABS scheme, and prove its security under the defined security model. Also, we implement the proposed SA-ABSR scheme and the underlying standard ABS scheme to evaluate the performance, from which it is easy to see that the proposed SA-ABSR scheme is more efficient than its underlying ABS scheme. Hui Cui 0001, Robert H. Deng, Joseph K. Liu, Xun Yi, Yingjiu Li |
IEEE Trans. Ind. Informatics | 5 |
| 2017 | Attribute-Based Encryption with Expressive and Authorized Keyword Search
Hui Cui 0001, Robert H. Deng, Joseph K. Liu, Yingjiu Li |
ACISP (1) | 4 |
| 2017 | What You See is Not What You Get: Leakage-Resilient Password Entry Schemes for Smart GlassesabstractSmart glasses are becoming popular for users to access various services such as email. To protect these services, password-based user authentication is widely used. Unfortunately, the password-based user authentication has inherent vulnerability against password leakage. Many efforts have been put on designing leakage-resilient password entry schemes on PCs and mobile phones with traditional input equipment including keyboards and touch screens. However, such traditional input equipment is not available on smart glasses. Existing password entry on smart glasses relies on additional PCs or mobile devices. Such solutions force users to switch between different systems, which causes interrupted experience and may lower the practicability and usability of smart glasses. In this paper, we propose a series of leakage-resilient password entry schemes on stand-alone smart glasses, which are gTapper, gRotator, and gTalker. These schemes ensure no leakage in password entry by breaking the correlation between the underlying password and the interaction observable to adversaries. They are practical in the sense that they only require a touch pad, a gyroscope, and a microphone which are commonly available on smart glasses. The usability of the proposed schemes is evaluated by user study under various test conditions which are common in users' daily usage. The results of our user study reveal that the proposed schemes are easy-to-use so that users enter their passwords within moderate time, at high accuracy, and in various situations. Yan Li 0075, Yingjiu Li, Robert H. Deng |
AsiaCCS | 3 |
| 2017 | Employing Smartwatch for Enhanced Password Authentication
Bing Chang, Yingjiu Li, Pingjian Wang, Wen Tao Zhu |
WASA | 3 |
| 2017 | EvoPass: Evolvable graphical password against shoulder-surfing attacks
Xingjie Yu, Yingjiu Li, Liang Li 0003, Wen Tao Zhu |
Comput. Secur. | 3 |
| 2017 | A study on a feasible no-root approach on AndroidabstractRoot is the administrative privilege on Android, which is however inaccessible on stock Android devices. Due to the desire for privileged functionalities and the reluctance of rooting their devices, Android users seek for no-root approaches, which provide users with part of root privileges without rooting their devices. Existing no-root approaches require users to launch a separate service via Android Debug Bridge (ADB) on an Android device, which would perform user-desired tasks. However, it is unusual for a third-party Android application to work with a separate native service via sockets, and it requires the application developers to have extra knowledge such as Linux programming in application development. In this paper, we propose a feasible no-root approach based on new functionalities added on Android, which creates no separate service but an ADB loopback. To ensure such no-root approach is not misused in a proactive instead of reactive manner, we examine its dark side. We find out that while this approach makes it easy for no-root applications to work, it may lead to a “ permission explosion,” which enables any third-party application to attain shell permissions beyond its granted permissions. The permission explosion can further lead to exploits including privacy leakage, account takeover, application UID abuse, and user input inference. A practical experiment is carried out to evaluate the situation in the real world, which shows that many real-world applications from Google Play and four third-party application markets are indeed vulnerable to these exploits. To mitigate the dark side of the new no-root approach and make it more suitable for users to adopt, we identify the causes of the exploits, and propose a permission-based solution. We also provide suggestions to application developers and application markets on how to prevent these exploits. Yingjiu Li, Robert H. Deng, Lingyun Ying |
J. Comput. Secur. | 2 |
| 2017 | Universally Composable RFID Mutual AuthenticationabstractUniversally Composable (UC) framework provides the strongest security notion for designing fully trusted cryptographic protocols, and it is very challenging on applying UC security in the design of RFID mutual authentication protocols. In this paper, we formulate the necessary conditions for achieving UC secure RFID mutual authentication protocols which can be fully trusted in arbitrary environment, and indicate the inadequacy of some existing schemes under the UC framework. We define the ideal functionality for RFID mutual authentication and propose the first UC secure RFID mutual authentication protocol based on public key encryption and certain trusted third parties which can be modeled as functionalities. We prove the security of our protocol under the strongest adversary model assuming both the tags' and readers' corruptions. We also present two (public) key update protocols for the cases of multiple readers: one uses Message Authentication Code (MAC) and the other uses trusted certificates in Public Key Infrastructure (PKI). Furthermore, we address the relations between our UC framework and the zero-knowledge privacy model proposed by Deng et al. [1]. Chunhua Su, Bagus Santoso, Yingjiu Li, Robert H. Deng, Xinyi Huang 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2017 | A Secure, Usable, and Transparent Middleware for Permission Managers on AndroidabstractAndroid's permission system offers an all-or-nothing choice when installing an app. To make it more flexible and fine-grained, users may choose a popular app tool, called permission manager, to selectively grant or revoke an app's permissions at runtime. A fundamental requirement for such permission manager is that the granted or revoked permissions should be enforced faithfully. However, we discover that none of existing permission managers meet this requirement due to permission leaks, in which an unprivileged app can exercise certain permissions which are revoked or not-granted through communicating with a privileged app.To address this problem, we propose a secure, usable, and transparent OS-level middleware for any permission manager to defend against the permission leaks. The middleware is provably secure in a sense that it can effectively block all possible permission leaks.The middleware is designed to have a minimal impact on the usability of running apps. In addition, the middleware is transparent to users and app developers and it requires minor modifications on permission managers and Android OS. Finally, our evaluation shows that the middleware incurs relatively low performance overhead and power consumption. Daibin Wang, Haixia Yao, Yingjiu Li, Hai Jin 0001, Deqing Zou, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2017 | An Efficient Privacy-Preserving Outsourced Computation over Public DataabstractIn this paper, we propose a new efficient privacy-preserving outsourced computation framework over public data, called EPOC. EPOC allows a user to outsource the computation of a function over multi-dimensional public data to the cloud while protecting the privacy of the function and its output. Specifically, we introduce three types of EPOC in order to tradeoff different levels of privacy protection and performance. We present a new cryptosystem called Switchable Homomorphic Encryption with Partially Decryption (SHED) as the core cryptographic primitive for EPOC. We introduce two coding techniques, called message pre-coding technique and message extending and coding technique respectively, for messages encrypted under a composite order group. Furthermore, we propose a Secure Exponent Calculation Protocol with Public Base (SEPB), which serves as the core sub-protocol in EPOC. Detailed security analysis shows that the proposed EPOC achieves the goal of outsourcing computation of a private function over public data without privacy leakage to unauthorized parties. In addition, performance evaluations via extensive simulations demonstrate that EPOC is efficient in both computation and communications. Ximeng Liu, Baodong Qin, Robert H. Deng, Yingjiu Li |
IEEE Trans. Serv. Comput. | 4 |
| 2016 | A Feasible No-Root Approach on Android
Yingjiu Li, Robert H. Deng |
ACISP (2) | 2 |
| 2016 | Server-Aided Revocable Attribute-Based Encryption
Hui Cui 0001, Robert H. Deng, Yingjiu Li, Baodong Qin |
ESORICS (2) | 3 |
| 2016 | Efficient Tag Path Authentication Protocol with Less Tag Memory
Yingjiu Li, Zongyang Zhang, Yunlei Zhao |
ISPEC | 2 |
| 2016 | Attacking Android smartphone systems without permissionsabstractAndroid requires third-party applications to request for permissions when they access critical mobile resources, such as users' personal information and system operations. In this paper, we present the attacks that can be launched without permissions. We first perform call graph analysis, component analysis and data-flow analysis on various parts of Android framework to retrieve unprotected APIs. Unprotected APIs provide a way of accessing resources without any permissions. We then exploit selected unprotected APIs and launch a number of attacks on Android phones. We discover that without requesting for any permissions, an attacker can access to device ID, phone service state, SIM card state, Wi-Fi and network information, as well as user setting information, such as airplane, location, NFC, USB and power modes of mobile devices. An attacker can also disturb Bluetooth discovery services, and block the incoming emails, calendar events, and Google documents. Moreover, an attacker can set volumes of devices and trigger alarm tones and ringtones that users personally set for their devices. An attacker can also launch camera, mail, music and phone applications even when the devices are locked. We compare our research on two Android versions, and discover that as platform providers incorporate more APIs, the number of unprotected APIs increases and new attacks become possible. We thus suggest platform providers to inspect Android frameworks systematically before releasing new versions. Su Mon Kywe, Yingjiu Li, Kunal Petal, Michael Grace |
PST | 2 |
| 2016 | Attribute-Based Encryption with Granular Revocation
Hui Cui 0001, Robert H. Deng, Xuhua Ding, Yingjiu Li |
SecureComm | 4 |
| 2016 | Ciphertext-policy attribute-based encryption with partially hidden access structure and its application to privacy-preserving electronic medical record system in cloud environmentabstractAbstract With the development of cloud computing, more and more sensitive data are uploaded to cloud by companies or individuals, which brings forth new challenges for outsourced data security and privacy. Ciphertext‐policy attribute‐based encryption (CP‐ABE) provides fine‐grained access control of encrypted data in the cloud; in a CP‐ABE scheme, an access structure, also referred to as ciphertext‐policy, is sent along with a ciphertext explicitly, and anyone who obtains a ciphertext can know the access structure associated with the ciphertext. In certain applications, access structures contain very sensitive information and must be protected from everyone except the users whose private key attributes satisfy the access structures. In this paper, we propose a new model for CP‐ABE with partially hidden access structure (See Figure 2). In our model, each attribute consists of two parts: an attribute name and its value; if the private key attributes of a user do not satisfy the access structure associated with a ciphertext, the specific attribute values of the access structure are hidden, while other information about the access structure is public. Based on the CP‐ABE scheme proposed by Lewko and Waters recently, we then present a concrete construction of CP‐ABE with partially hidden access structure and prove that it is fully secure in the standard model. In addition, we discuss how our new model can be employed to construct a privacy‐preserving electronic medical record system in the cloud environment. Copyright © 2016 John Wiley & Sons, Ltd. Lixian Liu, Junzuo Lai, Robert H. Deng, Yingjiu Li |
Secur. Commun. Networks | 4 |
| 2016 | ICCDetector: ICC-Based Malware Detection on AndroidabstractMost existing mobile malware detection methods (e.g., Kirin and DroidMat) are designed based on the resources required by malwares (e.g., permissions, application programming interface (API) calls, and system calls). These methods capture the interactions between mobile apps and Android system, but ignore the communications among components within or cross application boundaries. As a consequence, the majority of the existing methods are less effective in identifying many typical malwares, which require a few or no suspicious resources, but leverage on inter-component communication (ICC) mechanism when launching stealthy attacks. To address this challenge, we propose a new malware detection method, named ICCDetector. ICCDetector outputs a detection model after training with a set of benign apps and a set of malwares, and employs the trained model for malware detection. The performance of ICCDetector is evaluated with 5264 malwares, and 12026 benign apps. Compared with our benchmark, which is a permission-based method proposed by Peng et al. in 2012 with an accuracy up to 88.2%, ICCDetector achieves an accuracy of 97.4%, roughly 10% higher than the benchmark, with a lower false positive rate of 0.67%, which is only about a half of the benchmark. After manually analyzing false positives, we discover 43 new malwares from the benign data set, and reduce the number of false positives to seven. More importantly, ICCDetector discovers 1708 more advanced malwares than the benchmark, while it misses 220 obvious malwares, which can be easily detected by the benchmark. For the detected malwares, ICCDetector further classifies them into five newly defined malware categories, which help understand the relationship between malicious behaviors and ICC characteristics. We also provide a systemic analysis of ICC patterns of benign apps and malwares. Yingjiu Li, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | Seeing Your Face Is Not Enough: An Inertial Sensor-Based Liveness Detection for Face AuthenticationabstractLeveraging built-in cameras on smartphones and tablets, face authentication provides an attractive alternative of legacy passwords due to its memory-less authentication process. However, it has an intrinsic vulnerability against the media-based facial forgery (MFF) where adversaries use photos/videos containing victims' faces to circumvent face authentication systems. In this paper, we propose FaceLive, a practical and robust liveness detection mechanism to strengthen the face authentication on mobile devices in fighting the MFF-based attacks. FaceLive detects the MFF-based attacks by measuring the consistency between device movement data from the inertial sensors and the head pose changes from the facial video captured by built-in camera. FaceLive is practical in the sense that it does not require any additional hardware but a generic front-facing camera, an accelerometer, and a gyroscope, which are pervasively available on today's mobile devices. FaceLive is robust to complex lighting conditions, which may introduce illuminations and lead to low accuracy in detecting important facial landmarks; it is also robust to a range of cumulative errors in detecting head pose changes during face authentication. Yan Li 0075, Yingjiu Li, Qiang Yan 0001, Hancong Kong, Robert H. Deng |
CCS | 2 |
| 2015 | Server-Aided Revocable Identity-Based EncryptionabstractEfficient user revocation in Identity-Based Encryption (IBE) has been a challenging problem and has been the subject of several research efforts in the literature. Among them, the tree-based revocation approach, due to Boldyreva, Goyal and Kumar, is probably the most efficient one. In this approach, a trusted Key Generation Center (KGC) periodically broadcasts a set of key updates to all (non-revoked) users through public channels, where the size of key updates is only $$O(r\log \frac{N}{r})$$ , with N being the number of users and r the number of revoked users, respectively; however, every user needs to keep at least $$O(\log N)$$ long-term secret keys and all non-revoked users are required to communicate with the KGC regularly. These two drawbacks pose challenges to users who have limited resources to store their secret keys or cannot receive key updates in real-time. To alleviate the above problems, we propose a novel system model called server-aided revocable IBE. In our model, almost all of the workloads on users are delegated to an untrusted server which manages users’ public keys and key updates sent by a KGC periodically. The server is untrusted in the sense that it does not possess any secret information. Our system model requires each user to keep just one short secret key and does not require users to communicate with either the KGC or the server during key updating. In addition, the system supports delegation of users’ decryption keys, namely it is secure against decryption key exposure attacks. We present a concrete construction of the system that is provably secure against adaptive-ID chosen plaintext attacks under the DBDH assumption in the standard model. One application of our server-aided revocable IBE is encrypted email supporting lightweight devices (e.g., mobile phones) in which an email server plays the role of the untrusted server so that only non-revoked users can read their email messages. Baodong Qin, Robert H. Deng, Yingjiu Li, Shengli Liu 0001 |
ESORICS (1) | 3 |
| 2015 | CICC: a fine-grained, semantic-aware, and transparent approach to preventing permission leaks for Android permission managersabstractAndroid's permission system offers an all-or-nothing installation choice for users. To make it more flexible, users may choose a popular app tool, called permission manager, to selectively grant or revoke an app's permissions at runtime. A fundamental requirement for such permission manager is that the granted or revoked permissions should be enforced faithfully. However, we discover that none of existing permission managers meet this requirement due to permission leaks. To address this problem, we propose CICC, a fine-grained, semantic-aware, and transparent approach for any permission managers to defend against the permission leaks. Compared to existing solutions, CICC is fine-grained because it detects the permission leaks using call-chain information at the component instance level, instead of at the app level or component level. The fine-grained feature enables it to generate a minimal impact on the usability of running apps. CICC is semantic-aware in a sense that it manages call-chains in the whole lifecycle of each component instance. CICC is transparent to users and app developers, and it requires minor modification to permission managers. Our evaluation shows that CICC incurs relatively low performance overhead and power consumption. Daibin Wang, Haixia Yao, Yingjiu Li, Hai Jin 0001, Deqing Zou, Robert H. Deng |
WISEC | 3 |
| 2015 | Privacy leakage analysis in online social networks
Yan Li 0075, Yingjiu Li, Qiang Yan 0001, Robert H. Deng |
Comput. Secur. | 2 |
| 2015 | Leakage-resilient password entry: Challenges, design, and evaluation
Qiang Yan 0001, Jin Han 0002, Yingjiu Li, Jianying Zhou 0001, Robert H. Deng |
Comput. Secur. | 3 |
| 2015 | Statistical Database Auditing Without Query Denial ThreatabstractStatistical database auditing is the process of checking aggregate queries that are submitted in a continuous manner, to prevent inference disclosure. Compared to other data protection mechanisms, auditing has the features of flexibility and maximum information. Auditing is typically accomplished by examining responses to past queries to determine whether a new query can be answered. It has been recognized that query denials release information and can cause data disclosure. This paper proposes an auditing mechanism that is free of query denial threat and applicable to mixed types of aggregate queries, including sum, max, min, deviation, etc. The core ideas are (i) deriving the complete information leakage from each query denial and (ii) carrying the complete leaked information derived from past answered and denied queries to audit each new query. The information leakage deriving problem can be formulated as a set of parametric optimization programs, and the whole auditing process can be modeled as a series of convex optimization problems. Haibing Lu, Jaideep Vaidya, Vijayalakshmi Atluri, Yingjiu Li |
INFORMS J. Comput. | 4 |
| 2014 | Fully secure key-policy attribute-based encryption with constant-size ciphertexts and fast decryptionabstractAttribute-based encryption (ABE), introduced by Sahai and Waters, is a promising cryptographic primitive, which has been widely applied to implement fine-grained access control system for encrypted data. In its key-policy flavor, attribute sets are used to annotate ciphertexts and secret keys are associated with access structures that specify which ciphertexts a user is entitled to decrypt. In most existing key-policy attribute-based encryption (KP-ABE) constructions, the size of the ciphertext is proportional to the number of attributes associated with it and the decryption cost is proportional to the number of attributes used during decryption. In this paper, we present a new construction of KP-ABE. Our proposed construction is the first KP-ABE scheme, which has the following features simultaneously: expressive (i.e., supporting arbitrary monotonic access structures); fully secure in the standard model; constant-size ciphertexts and fast decryption. The downside of our construction is that secret keys have quadratic size in the number of attributes. Junzuo Lai, Robert H. Deng, Yingjiu Li, Jian Weng 0001 |
AsiaCCS | 3 |
| 2014 | Understanding OSN-based facial disclosure against face authentication systemsabstractFace authentication is one of promising biometrics-based user authentication mechanisms that have been widely available in this era of mobile computing. With built-in camera capability on smart phones, tablets, and laptops, face authentication provides an attractive alternative of legacy passwords for its memory-less authentication process. Although it has inherent vulnerability against spoofing attacks, it is generally considered sufficiently secure as an authentication factor for common access protection. However, this belief becomes questionable since image sharing has been popular in online social networks (OSNs). A huge number of personal images are shared every day and accessible to potential adversaries. This OSN-based facial disclosure (OSNFD) creates a significant threat against face authentication. In this paper, we make the first attempt to quantitatively measure the threat of OSNFD. We examine real-world face-authentication systems designed for both smartphones, tablets, and laptops. Interestingly, our results find that the percentage of vulnerable images that can used for spoofing attacks is moderate, but the percentage of vulnerable users that are subject to spoofing attacks is high. The difference between systems designed for smartphones/tablets and laptops is also significant. In our user study, the average percentage of vulnerable users is 64% for laptop-based systems, and 93% for smartphone/tablet-based systems. This evidence suggests that face authentication may not be suitable to use as an authentication factor, as its confidentiality has been significantly compromised due to OSNFD. In order to understand more detailed characteristics of OSNFD, we further develop a risk estimation tool based on logistic regression to extract key attributes affecting the success rate of spoofing attacks. The OSN users can use this tool to calculate risk scores for their shared images so as to increase their awareness of OSNFD. Yan Li 0075, Qiang Yan 0001, Yingjiu Li, Robert H. Deng |
AsiaCCS | 4 |
| 2014 | Authorized Keyword Search on Encrypted Data
Junzuo Lai, Yingjiu Li, Robert H. Deng, Jian Weng 0001 |
ESORICS (1) | 3 |
| 2014 | Permission based Android security: Issues and countermeasures
Zheran Fang, Weili Han, Yingjiu Li |
Comput. Secur. | 3 |
| 2014 | Towards semantically secure outsourcing of association rule mining on categorical data
Junzuo Lai, Yingjiu Li, Robert H. Deng, Jian Weng 0001, Chaowen Guan, Qiang Yan 0001 |
Inf. Sci. | 2 |
| 2013 | Launching Generic Attacks on iOS with Approved Third-Party Applications
Jin Han 0002, Su Mon Kywe, Qiang Yan 0001, Feng Bao 0001, Robert H. Deng, Debin Gao, Yingjiu Li, Jianying Zhou 0001 |
ACNS | 7 |
| 2013 | Expressive search on encrypted dataabstractDifferent from the traditional public key encryption, searchable public key encryption allows a data owner to encrypt his data under a user's public key in such a way that the user can generate search token keys using her secret key and then query an encryption storage server. On receiving such a search token key, the server filters all or related stored encryptions and returns matched ones as response. Junzuo Lai, Xuhua Zhou, Robert H. Deng, Yingjiu Li, Kefei Chen |
AsiaCCS | 4 |
| 2013 | Designing leakage-resilient password entry on touchscreen mobile devicesabstractTouchscreen mobile devices are becoming commodities as the wide adoption of pervasive computing. These devices allow users to access various services at anytime and anywhere. In order to prevent unauthorized access to these services, passwords have been pervasively used in user authentication. However, password-based authentication has intrinsic weakness in password leakage. This threat could be more serious on mobile devices, as mobile devices are widely used in public places. Qiang Yan 0001, Jin Han 0002, Yingjiu Li, Jianying Zhou 0001, Robert H. Deng |
AsiaCCS | 3 |
| 2013 | Anonymous Authentication of Visitors for Mobile Crowd Sensing at Amusement Parks
Divyan M. Konidala, Robert H. Deng, Yingjiu Li, Hoong Chuin Lau, Stephen E. Fienberg |
ISPEC | 3 |
| 2013 | Think Twice before You Share: Analyzing Privacy Leakage under Privacy Control in Online Social Networks
Yan Li 0075, Yingjiu Li, Qiang Yan 0001, Robert H. Deng |
NSS | 2 |
| 2012 | A New Framework for Privacy of RFID Path Authentication
Shaoying Cai, Robert H. Deng, Yingjiu Li, Yunlei Zhao |
ACNS | 3 |
| 2012 | Expressive CP-ABE with partially hidden access structuresabstractAt Eurocrypt 2005, Sahai and Waters [7] introduced the concept of attribute-based encryption (ABE). ABE enables public key based one-to-many encryption and is envisioned as a promising cryptographic primitive for realizing scalable and fine-grained access control systems. There are two kinds of ABE schemes [1], key-policy ABE (KP-ABE) and ciphertext-policy ABE (CP-ABE) schemes. This paper, our concern is on the latter. Junzuo Lai, Robert H. Deng, Yingjiu Li |
AsiaCCS | 3 |
| 2012 | SecDS: a secure EPC discovery service system in EPCglobal networkabstractIn recent years, the Internet of Things (IOT) has drawn considerable attention from the industrial and research communities. Due to the vast amount of data generated through IOT devices and users, there is an urgent need for an effective search engine to help us make sense of this massive amount of data. With this motivation, we begin our initial works on developing a secure and efficient search engine (SecDS) based on EPC Discovery Services (EPCDS) for EPCglobal network, an integral part of IOT. SecDS is designed to provide a bridge between different partners of supply chains to share information while enabling them to find who is in possession of an item. The most important property of SecDS is: while efficiently processing user's search, it is also secure. In order to prevent unauthorized access to SecDS, an extended attribute-based access control model is proposed and implemented such that information belonging to different companies can be protected using different policies. Darren Sim, Yingjiu Li, Robert H. Deng |
CODASPY | 3 |
| 2012 | On Limitations of Designing Leakage-Resilient Password Systems: Attacks, Principals and Usability
Qiang Yan 0001, Jin Han 0002, Yingjiu Li, Robert H. Deng |
NDSS | 3 |
| 2012 | Distributed Path Authentication for Dynamic RFID-Enabled Supply Chains
Shaoying Cai, Yingjiu Li, Yunlei Zhao |
SEC | 2 |
| 2012 | A secure and efficient discovery service system in EPCglobal network
Yingjiu Li, Robert H. Deng |
Comput. Secur. | 2 |
| 2012 | Guest Editor's Prefaceabstractthe 25th Annual WG 11.3 Conference on Data and Applications Security and Privacy (DBSec 2011) was held in Richmond, VA, USA, in which I served as program chair.Celebrating on its 25th anniversary, DBSec provided a forum for presenting original unpublished research results, practical experiences and innovative ideas in data and applications security and privacy.The conference was an overwhelming success, with four invited talks, fourteen regular papers and nine short papers being included in the conference program.After the conference, four high-quality papers were selected from the conference program and included in this Special Issue in Journal of Computer Security after significant extensions and rigorous reviews.These four papers reflect different aspects of data and applications security and privacy, ranging from algorithms of enforcing confidentiality and visibility constraints in data publishing, protocol of adapting confidentiality policy for inference control of queries to a propositional information system, architectures for processing multilevel secure continuous queries in data stream management systems, and protocols of solving distributed linear programming problems in a secure and efficient manner.In private data publication, certain data fragments must be protected to meet confidentiality constraints, while other fragments can be released due to visibility requirements.The paper "An OBDD approach to enforce confidentiality and visibility constraints in data publishing", by Valentina Ciriani, Sabrina De Capitani di Vimercati, Sara Foresti, Giovanni Livraga and Pierangela Samarati, addresses a challenging problem of computing a fragmentation composed of the minimum number fragments in private data publication.The key idea in their work is to translate the problem into the problem of computing a maximum weighted clique over a fragmentation graph, which can be computed using ordered binary decision diagrams (OBDDs) that satisfy all the confidentiality constraints and a subset of the visibility constraints defined in the system.An efficient heuristic algorithm is proposed to solve this translated problem."Dynamic policy adaptation for inference control of queries to a propositional information system", by Joachim Biskup, provides an alternative option to represent the history of queries in policy-based inference control by suitably adapting inference control policy after returning an answer to a query.A comprehensive protocol is proposed for policy adaptation.A formal proof is provided to show that the policy adaption approach is equivalent to traditional inference control approaches.The efficiency of the proposed approach is discussed in special cases under dedicated data structures. Yingjiu Li |
J. Comput. Secur. | 1 |
| 2011 | A software-based root-of-trust primitive on multicore platformsabstractSoftware-based root-of-trust has been proposed to overcome the disadvantage of hardware-based root-of-trust, which is the high cost in deployment and upgrade (when vulnerabilities are discovered). However, prior research on software-based root-of-trust only focuses on uniprocessor platforms. The essential security properties of such software-based root-of-trust, as analyzed and demonstrated in our paper, can be violated on multicore platforms. Since multicore processors are becoming increasingly popular, it is imperative to explore the feasibility of software-based root-of-trust on them. Qiang Yan 0001, Jin Han 0002, Yingjiu Li, Robert H. Deng, Tieyan Li |
AsiaCCS | 3 |
| 2011 | Fully Secure Cipertext-Policy Hiding CP-ABE
Junzuo Lai, Robert H. Deng, Yingjiu Li |
ISPEC | 3 |
| 2011 | Secure and Practical Key Distribution for RFID-Enabled Supply Chains
Tieyan Li, Yingjiu Li, Guilin Wang |
SecureComm | 2 |
| 2011 | Privacy Risk Assessment with Bounds Deduced from BoundsabstractAs more and more organizations collect, store, and release large amounts of personal information, it is increasingly important for the organizations to conduct privacy risk assessment so as to comply with various emerging privacy laws and meet information providers' demands. Existing statistical database security and inference control solutions may not be appropriate for protecting privacy in many new uses of data as these methods tend to be either less or over-restrictive in disclosure limitation or are prohibitively complex in practice. We address a fundamental question in privacy risk assessment which asks: how to accurately derive bounds for protected information from inaccurate released information or, more particularly, from bounds of released information. We give an explicit formula for calculating such bounds from bounds, which we call square bounds or S-bounds. Classic F-bounds in statistics become a special case of S-bounds when all released bounds retrograde to exact values. We propose a recursive algorithm to extend our S-bounds results from two dimensions to high dimensions. To assess privacy risk for a protected database of personal information given some bounds of released information, we define typical privacy disclosure measures. For each type of disclosure, we investigate the distribution patterns of privacy breaches as well as effective and efficient controls that can be used to eliminate privacy risk, both based on our S-bounds results. Yingjiu Li, Haibing Lu |
Int. J. Uncertain. Fuzziness Knowl. Based Syst. | 1 |
| 2011 | A zero-knowledge based framework for RFID privacyabstractFormal RFID security and privacy frameworks are fundamental to the design and analysis of robust RFID systems. In this paper, we develop a new definitional framework for RFID privacy in a rigorous and precise manner. Our framework is based on a zero-knowledge (ZK) formulation [The Foundations of Cr yptography, Cambridge Univ. Press, Cambridge, 2001; ACM Symposium on Theory of Computing, 1985, pp. 291–304] and incorporates the notions of adaptive completeness and mutual authentication. We provide meticulous justification of the new framework and contrast it with existing ones in the literature. In particular, we prove that our framework is strictly stronger than the ind-privacy model in International Conference on Pervasive Computing and Communications, 2007, which answers an open question posed in International Conference on Pervasive Computing and Communications, 2007, for developing stronger RFID privacy models. We also clarify certain confusions and rectify several defects in the existing frameworks. Finally, based on the protocol in Conference on Computer and Communications Security, 2009, we propose an efficient RFID mutual authentication protocol and analyze its security and privacy. The methodology used in our analysis can also be applied to analyze other RFID protocols within the new framework. Robert H. Deng, Yingjiu Li, Moti Yung, Yunlei Zhao |
J. Comput. Secur. | 2 |
| 2011 | Guest editors' prefaceabstractIn March 2010, the 2010 Workshop on RFID Security (RFIDSec'10 Asia) was held in Singapore, in which we served as program co-chairs.Aligned with the earliest RFID security workshop (RFIDsec) starting in 2005, this workshop provided an international forum for sharing original research results and application experiences among researchers in the field of RFID system security.The workshop was an overwhelming success, with twelve high-quality papers being included in the workshop program.To further promote the fast-evolving research on RFID system security, we solicited original research papers in the theory and practice concerning RFID system security for a special issue in Journal of Computer Security.After rigorous review, this special issue selected two papers (after significant extensions) out of the twelve papers appeared in RFIDsec'10 Asia workshop and three papers out of fourteen new submissions after the workshop.These five papers reflect different aspects of RFID system security, ranging from theoretical study on unconditionally secure approach for low-cost RFID systems to experimental research on practical eavesdropping and skimming attacks, from RFID distance-bounding protocols, secure ownership transfer of RFID tags to efficient construction of HB family protocols.A brief description of the subject matter is provided below.While computationally secure protocols have been extensively studied in RFID system security research, the topic of unconditionally secure approach has been relatively neglected mainly for practical reasons: such approach would be less efficient and more costly.The paper "Securing low-cost RFID systems: An unconditionally secure approach", by Basel Alomair, Loukas Lazos and Radha Poovendran, seeks to bring more research to the design of unconditionally secure protocols that are suitable for low-cost RFID tags with stringent computational capabilities.The key idea in their work is to let RFID readers, which are computationally powerful, generate random numbers and deliver them to RFID tags in an unconditionally secure manner, after which an unconditionally secure message authentication code can be computed with a single multiplication operation on the tag side so as to solve the identity authentication problem in RFID systems."Practical eavesdropping and skimming attacks on high-frequency RFID tokens", by Gerhard P. Hancke, adds to our understanding of the feasibility of practical attacks against standard high-frequency RFID tokens.The major contribution of this paper is to provide enough details about experimental setup and results for eavesdropping and skimming attacks to high-frequency RFID tokens, confirming that near-field RFID devices are vulnerable to practical attacks beyond the advertised operating range. Yingjiu Li, Jianying Zhou 0001 |
J. Comput. Secur. | 1 |
| 2011 | On two RFID privacy notions and their relationsabstractPrivacy of RFID systems is receiving increasing attention in the RFID community. Basically, there are two kinds of RFID privacy notions in the literature: one based on the indistinguishability of two tags, denoted as ind-privacy, and the other based on the unpredictability of the output of an RFID protocol, denoted as unp-privacy. In this article, we first revisit the existing unpredictability-based RFID privacy models and point out their limitations. We then propose a new RFID privacy model, denoted as unp * -privacy, based on the indistinguishability of a real tag and a virtual tag. We formally clarify its relationship with the ind-privacy model. It is proven that ind-privacy is weaker than unp * -privacy. Moreover, the minimal (necessary and sufficient) condition on RFID tags to achieve unp * -privacy is determined. It is shown that if an RFID system is unp * -private, then the computational power of an RFID tag can be used to construct a pseudorandom function family provided that the RFID system is complete and sound. On the other hand, if each tag is able to compute a pseudorandom function, then the tags can be used to construct an RFID system with unp * -privacy. In this sense, a pseudorandom function family is the minimal requirement on an RFID tag's computational power for enforcing RFID system privacy. Finally, a new RFID mutual authentication protocol is proposed to satisfy the minimal requirement. Yingjiu Li, Robert H. Deng, Junzuo Lai, Changshe Ma |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2010 | Revisiting Unpredictability-Based RFID Privacy Models
Junzuo Lai, Robert H. Deng, Yingjiu Li |
ACNS | 3 |
| 2010 | A New Framework for RFID Privacy
Robert H. Deng, Yingjiu Li, Moti Yung, Yunlei Zhao |
ESORICS | 2 |
| 2010 | Privacy Disclosure Analysis and Control for 2D Contingency Tables Containing Inaccurate Data
Kevin Chiew, Yingjiu Li, Yanjiang Yang |
Privacy in Statistical Databases | 3 |
| 2010 | Vulnerability analysis of RFID protocols for tag ownership transfer
Pedro Peris-Lopez, Julio César Hernández Castro, Juan Tapiador, Tieyan Li, Yingjiu Li |
Comput. Networks | 5 |
| 2010 | Efficient discrete logarithm based multi-signature scheme in the plain public key model
Changshe Ma, Jian Weng 0001, Yingjiu Li, Robert H. Deng |
Des. Codes Cryptogr. | 3 |
| 2010 | An intrusion response decision-making model based on hierarchical task network planning
Chengpo Mu, Yingjiu Li |
Expert Syst. Appl. | 2 |
| 2010 | Two robust remote user authentication protocols using smart cards
Kuo-Hui Yeh, Chunhua Su, Nai-Wei Lo, Yingjiu Li, Yi-Xiang Hung |
J. Syst. Softw. | 4 |
| 2010 | Shifting Inference Control to User Side: Architecture and ProtocolabstractInference has been a longstanding issue in database security, and inference control, aiming to curb inference, provides an extra line of defense to the confidentiality of databases by complementing access control. However, in traditional inference control architecture, database server is a crucial bottleneck, as it enforces highly computation-intensive auditing for all users who query the protected database. As a result, most auditing methods, though rigorously studied, are not practical for protecting large-scale real-world database systems. In this paper, we shift this paradigm by proposing a new inference control architecture, entrusting inference control to each user's platform that is equipped with trusted computing technology. The trusted computing technology is designed to attest the state of a user's platform to the database server, so as to assure the server that inference control could be enforced as prescribed. A generic protocol is proposed to formalize the interactions between the user's platform and database server. The authentication property of the protocol is formally proven. Since inference control is enforced in a distributed manner, our solution avoids the bottleneck in the traditional architecture, thus can potentially support a large number of users making queries. Yanjiang Yang, Yingjiu Li, Robert H. Deng, Feng Bao 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2009 | RFID privacy: relation between two notions, minimal condition, and efficient constructionabstractPrivacy of RFID systems is receiving increasing attention in the RFID community. Basically, there are two kinds of RFID privacy notions: one based on the indistinguishability of two tags, denoted as ind-privacy, and the other based on the unpredictability of the output of a protocol, denoted as unp-privacy. In this paper, the definition of unp-privacy is refined and the relation between the two notions is clarified: it is proven that ind-privacy is weaker than unp-privacy. Moreover, the minimal (necessary and sufficient)condition on RFID tags to achieve unp-privacy is determined. It is shown that if an RFID system has strong (or weak) unp-privacy then the computational power of an RFID tag can be used to construct a pseudorandom function family provided that the RFID system is complete and sound. On the other hand, if each tag is able to compute a pseudorandom function, then the tags can be used to construct an RFID system with strong (or weak) unp-privacy. In this sense, a pseudorandom function family is the minimal requirement on an RFID tag's computational power for enforcing strong RFID system privacy. Finally, a new RFID protocol is proposed to satisfy the minimal requirement, which also outperforms the state-of-the-art RFID protocols in terms of computational cost and communication overhead. Changshe Ma, Yingjiu Li, Robert H. Deng, Tieyan Li |
CCS | 2 |
| 2009 | An efficient online auditing approach to limit private data disclosureabstractIn a database system, disclosure of confidential private data may occur if users can put together the answers of past queries. Traditional access control mechanisms cannot guard against such breaches to private data. Online auditing techniques have been advanced to limit such disclosure of private data. Essentially, before answering any query, these techniques inspect the answers of the past queries to determine whether answering this query would compromise the stated data disclosure policies. While the primary requirement for online auditing is high efficiency, existing auditing approaches are expensive with respect to both computational time and space. Specifically, this cost is excessive in the general case of auditing arbitrary aggregate queries over real-valued confidential attributes with respect to interval-based privacy disclosure. Haibing Lu, Yingjiu Li, Vijayalakshmi Atluri, Jaideep Vaidya |
EDBT | 2 |
| 2009 | Enabling Secure Secret Updating for Unidirectional Key Distribution in RFID-Enabled Supply Chains
Shaoying Cai, Tieyan Li, Changshe Ma, Yingjiu Li, Robert H. Deng |
ICICS | 4 |
| 2009 | Ensuring Dual Security Modes in RFID-Enabled Supply Chain Systems
Shaoying Cai, Tieyan Li, Yingjiu Li, Robert H. Deng |
ISPEC | 3 |
| 2009 | Self-enforcing Private Inference Control
Yanjiang Yang, Yingjiu Li, Jian Weng 0001, Jianying Zhou 0001, Feng Bao 0001 |
ProvSec | 2 |
| 2009 | Attacks and improvements to an RIFD mutual authentication protocol and its extensionsabstractIn WiSec'08, Song and Mitchell proposed an RFID mutual authentication protocol. Song also extended this protocol for RFID tag ownership transfer. These two protocols are designed to have the most security properties in the literature. We discover that, however, the mutual authentication protocol is vulnerable to both tag impersonation attack and reader impersonation attack, which enable an adversary to impersonate any legitimate reader or tag. We also discover that the ownership transfer protocol is vulnerable to a de-synchronization attack, which prevents a legitimate reader from authenticating a legitimate tag, and vice versa. We analyze the vulnerabilities of these protocols and propose our revisions to eliminate the vulnerabilities with comparable storage and computational requirements. Shaoying Cai, Yingjiu Li, Tieyan Li, Robert H. Deng |
WISEC | 2 |
| 2009 | Certificate revocation release policiesabstractPublic key infrastructure provides a promising foundation for verifying the authenticity of communicating parties and transferring trust over the Internet. The key issue in public key infrastructure is how to process certificate revocations. Previous research in this area has concentrated on the tradeoffs that can be made among different revocation options. No rigorous efforts have been made to understand the probability distribution of certificate revocation requests based on real empirical data. In this study, we first collect real data from VeriSign and suggest a functional form for the probability density function of certificate revocation requests. Exponential distribution function is chosen as it adequately approximates the real data. We then provide an economic model based on which a certificate authority can choose the optimal Certificate Revocation List (CRL) release interval considering the intrinsic properties among different types of certificate services. To conclude we draw some insights by comparing the performance of four different CRL strategies. Giri Kumar Tayi, Chengyu Ma, Yingjiu Li |
J. Comput. Secur. | 4 |
| 2009 | Multistage Off-Line Permutation Packet Routing on a Mesh: An Approach with Elementary Mathematics
Kevin Chiew, Yingjiu Li |
J. Comput. Sci. Technol. | 2 |
| 2008 | A Security and Performance Evaluation of Hash-Based RFID Protocols
Tong-Lee Lim, Tieyan Li, Yingjiu Li |
Inscrypt | 3 |
| 2008 | Empirical Analysis of Certificate Revocation Lists
Daryl Walleck, Yingjiu Li, Shouhuai Xu |
DBSec | 2 |
| 2008 | Disclosure Analysis and Control in Statistical Databases
Yingjiu Li, Haibing Lu |
ESORICS | 1 |
| 2008 | Determining error bounds for spectral filtering based reconstruction methods in privacy preserving data mining
Songtao Guo, Xintao Wu, Yingjiu Li |
Knowl. Inf. Syst. | 3 |
| 2008 | Protecting business intelligence and customer privacy while outsourcing data mining tasks
Yingjiu Li, Xintao Wu |
Knowl. Inf. Syst. | 2 |
| 2008 | Practical Inference Control for Data CubesabstractThe fundamental problem for inference control in data cubes is how to efficiently calculate the lower and upper bounds for each cell value given the aggregations of cell values over multiple dimensions. In this paper, we provide the first practical solution for estimating exact bounds in two-dimensional irregular data cubes (that is, data cubes in which certain cell values are known to a snooper). Our results imply that the exact bounds cannot be obtained by a direct application of the Frechet bounds in some cases. We then propose a new approach to improve the classic Frechet bounds for any high-dimensional data cube in the most general case. The proposed approach improves upon the Frechet bounds in the sense that it gives bounds that are at least as tight as those computed by Frechet yet is simpler in terms of time complexity. Based on our solutions to the fundamental problem, we discuss various security applications such as privacy protection of released data, fine-grained access control, and auditing, and identify some future research directions. Haibing Lu, Yingjiu Li |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2007 | Protecting RFID communications in supply chainsabstractRecent years have seen much growing attention on RFID security. However, little work has been performed to address the security issues in the context of supply chain management, which is exactly the major field for RFID applications. Existing RFID solutions cannot be applied directly in this field because of a set of special RFID security requirements to be addressed for supply chain management. The major contribution of this paper is to identify the unique set of security requirements in supply chains and to propose a practical design of RFID communication protocols that satisfy the security requirements. Yingjiu Li, Xuhua Ding |
AsiaCCS | 1 |
| 2007 | New Paradigm of Inference Control with Trusted Computing
Yanjiang Yang, Yingjiu Li, Robert H. Deng |
DBSec | 2 |
| 2007 | Chaining watermarks for detecting malicious modifications to streaming data
Huiping Guo, Yingjiu Li, Sushil Jajodia |
Inf. Sci. | 2 |
| 2007 | Parity-based inference control for multi-dimensional range sum queriesabstractThis paper studies the inference control of multi-dimensional range (MDR) sum queries. We show that existing inference control methods are usually inefficient for MDR queries. We then consider parity-based inference control that restricts users to queries involving an even number of sensitive values. Such a restriction renders inferences significantly more difficult, because an even number is closed under addition and subtraction, whereas inferences target at one value. However, more sophisticated inferences are still possible with only even MDR queries. We show that the collection of all even MDR queries causes inferences if and only if a special collection of sum-two queries (that is, the summation of exactly two values) does so. The result leads to an inference control method with an improved computational complexity [Formula: see text] (over the previous result of [Formula: see text]) for m MDR queries over n values. We show that no odd MDR queries can be answered without causing inferences. We show how to check non-MDR queries for inferences in linear time. We also show how to find large inference-free subsets of even MDR queries when they do cause inferences. Lingyu Wang 0001, Yingjiu Li, Sushil Jajodia, Duminda Wijesekera |
J. Comput. Secur. | 2 |
| 2007 | Preserving privacy in association rule mining with bloom filters
Yingjiu Li, Xintao Wu |
J. Intell. Inf. Syst. | 2 |
| 2006 | Publicly verifiable ownership protection for relational databasesabstractToday, watermarking techniques have been extended from the multimedia context to relational databases so as to protect the ownership of data even after the data are published or distributed. However, all existing watermarking schemes for relational databases are secret key based, thus require a secret key to be presented in proof of ownership. This means that the ownership can only be proven once to the public (e.g., to the court). After that, the secret key is known to the public and the embedded watermark can be easily destroyed by malicious users. Moreover, most of the existing techniques introduce distortions to the underlying data in the watermarking process, either by modifying least significant bits or exchanging categorical values. The distortions inevitably reduce the value of the data. In this paper, we propose a watermarking scheme by which the ownership of data can be publicly proven by anyone, as many times as necessary. The proposed scheme is distortion-free, thus suitable for watermarking any type of data without fear of error constraints. The proposed scheme is robust against typical database attacks including tuple/attribute insertion/deletion, random/selective value modification, data frame-up, and additive attacks. Yingjiu Li, Robert H. Deng |
AsiaCCS | 1 |
| 2006 | Rights Protection for Data Cubes
Yingjiu Li, Robert H. Deng, Kefei Chen |
ISC | 2 |
| 2006 | On the Lower Bound of Reconstruction Error for Spectral Filtering Based Privacy Preserving Data Mining
Songtao Guo, Xintao Wu, Yingjiu Li |
PKDD | 3 |
| 2006 | Disclosure Analysis for Two-Way Contingency Tables
Haibing Lu, Yingjiu Li, Xintao Wu |
Privacy in Statistical Databases | 2 |
| 2006 | Practical Inference Control for Data Cubes (Extended Abstract)abstractThe fundamental problem for inference control in data cubes is how to efficiently calculate the lower and upper bounds for each cell value given the aggregations of cell values over multiple dimensions. In this paper, we provide the first practical solution for estimating exact bounds in two-dimensional irregular data cubes (i.e., data cubes in which certain cell values are known to a snooper). Our results imply that the exact bounds cannot be obtained by a direct application of the Frechet bounds in some cases. We then propose a new approach to improve the classic Frechet bounds for any high-dimensional data cube in the most general case. The proposed approach improves upon the Frechet bounds in the sense that it gives bounds that are at least as tight as those computed by Frechet, yet is simpler in terms of time complexity. Based on our solutions to the fundamental problem, we discuss two security applications, privacy protection of released data and fine-grained access control and auditing. Yingjiu Li, Haibing Lu, Robert H. Deng |
S&P | 1 |
| 2006 | On the Release of CRLs in Public Key Infrastructure
Chengyu Ma, Yingjiu Li |
USENIX Security Symposium | 3 |
| 2006 | A fragile watermarking scheme for detecting malicious modifications of database relations
Huiping Guo, Yingjiu Li, Anyi Liu, Sushil Jajodia |
Inf. Sci. | 2 |
| 2006 | Looking into the seeds of time: Discovering temporal patterns in large transaction sets
Yingjiu Li, Sencun Zhu, Xiaoyang Sean Wang, Sushil Jajodia |
Inf. Sci. | 1 |
| 2005 | Privacy Aware Market Basket Data Set Generation: A Feasible Approach for Inverse Frequent Set MiningabstractAssociation rule mining has received a lot of attention in the data mining community and several algorithms were proposed to improve the performance of association rule or frequent itemset mining. The IBM Almaden synthetic data generator has been commonly used for performance evaluation. One recent work shows that the data generated is not good enough for benchmarking as it has very different characteristics from real-world data sets. Hence there is a great need to use real-world data sets as benchmarks. However, organizations hesitate to provide their data due to privacy concerns. Recent work on privacy preserving association rule mining addresses this issue by modifying real data sets to hide sensitive or private rules. However, modifying individual values in real data may impact on other, non-sensitive rules. In this paper, we propose a feasible solution to the NP-complete problem of inverse frequent set mining. Since solving this problem by linear programming techniques is very computationally prohibitive, we apply graph-theoretical results to divide the original itemsets into components that preserve maximum likelihood estimation. We then use iterative proportional fitting method to each component. The technique is experimentally evaluated with two real data sets and one synthetic data set. The results show that our approach is effective and efficient for reconstructing market basket data set from a given set of frequent itemsets while preserving sensitive information. Xintao Wu, Yongge Wang 0001, Yingjiu Li |
SDM | 4 |
| 2005 | Fingerprinting Relational Databases: Schemes and SpecialtiesabstractIn this paper, we present a technique for fingerprinting relational data by extending Agrawal et al.'s watermarking scheme. The primary new capability provided by our scheme is that, under reasonable assumptions, it can embed and detect arbitrary bit-string marks in relations. This capability, which is not provided by prior techniques, permits our scheme to be used as a fingerprinting scheme. We then present quantitative models of the robustness properties of our scheme. These models demonstrate that fingerprints embedded by our scheme are detectable and robust against a wide variety of attacks including collusion attacks. Yingjiu Li, Vipin Swarup, Sushil Jajodia |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2004 | Defending Against Additive Attacks with Maximal Errors in Watermarking Relational DatabasesabstractRecently, several database watermarking techniques have been developed to fight against database piracy. In watermarking, a database owner’s identification information is embedded into a database such that proof of ownership can be established by detecting the information in pirated data. However, most watermarking systems are vulnerable to the severe threat of additive attacks and this threat has not been studied formally. In an additive attack, a pirate inserts an additional watermark such that the proof of ownership becomes ambiguous. In this paper, we present an effective approach to defending against additive attacks. Our strategy is to raise the errors introduced during watermark insertion to a predetermined threshold such that any additive attack would introduce more errors than the threshold. Exceeding the error threshold means that the pirated data is less useful or less competitive; thus, the owner does not need to claim ownership for such pirated data. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Yingjiu Li, Vipin Swarup, Sushil Jajodia |
DBSec | 1 |
| 2004 | Tamper detection and localization for categorical data using fragile watermarksabstractToday, database relations are widely used and distributed over the Internet. Since these data can be easily tampered with, it is critical to ensure the integrity of these data. In this paper, we propose to make use of fragile watermarks to detect and localize malicious alterations made to a database relation with categorical attributes. Unlike other watermarking schemes which inevitably introduce distortions to the cover data, the proposed scheme is distortion free. In our algorithm, all tuples in a database relation are first securely divided into groups according to some secure parameters. Watermarks are embedded and verified in each group independently. Thus, any modifications can be localized to some specific groups. Theoretical analysis shows that the probability of missing detection is very low. Yingjiu Li, Huiping Guo, Sushil Jajodia |
Digital Rights Management Workshop | 1 |
| 2003 | Constructing a virtual primary key for fingerprinting relational dataabstractAgrawal and Kiernan's watermarking technique for database relations [1] and Li et al's fingerprinting extension [6] both depend critically on primary key attributes. Hence, those techniques cannot embed marks in database relations without primary key attributes. Further, the techniques are vulnerable to simple attacks that alter or delete the primary key attribute.This paper proposes a new fingerprinting scheme that does not depend on a primary key attribute. The scheme constructs virtual primary keys from the most significant bits of some of each tuple's attributes. The actual attributes that are used to construct then virtual primary key differ from tuple to tuple. Attribute selection is based on a secret key that is known to the merchant only. Further, the selection does not depend on an apriori ordering over the attributes, or on knowledge of the original relation or fingerprint codeword.The virtual primary keys are then used in fingerprinting as in previous work [6]. Rigorous analysis shows that, with high probability, only embedded fingerprints can be detected and embedded fingerprints cannot be modified or erased by a variety of attacks. Attacks include adding, deleting, shuffling, or modifying tuples or attributes (including a primary key attribute if one exists), guessing secret keys, and colluding with other recipients of a relation. Yingjiu Li, Vipin Swarup, Sushil Jajodia |
Digital Rights Management Workshop | 1 |
| 2003 | Precisely Answering Multi-dimensional Range Queries without Privacy Breaches
Lingyu Wang 0001, Yingjiu Li, Duminda Wijesekera, Sushil Jajodia |
ESORICS | 2 |
| 2003 | Discovering calendar-based temporal association rules
Yingjiu Li, Peng Ning, Xiaoyang Sean Wang, Sushil Jajodia |
Data Knowl. Eng. | 1 |
| 2002 | Auditing Interval-Based Inference
Yingjiu Li, Lingyu Wang 0001, Xiaoyang Sean Wang, Sushil Jajodia |
CAiSE | 1 |
| 2002 | Enhancing Profiles for Anomaly Detection Using Time GranularitiesabstractRecently, association rules have been used to generate profiles of “normal” behavior for anomaly detection. However, the time factor (especially in terms of multiple time granularities) has not been utilized extensively in generation of these profiles. In reality, user behavior during different tim e intervals may be very different. For example, the “normal” number and duration of FTP connections may vary from working hours to midnight, from business day to weekend or holiday. Furthermore, these variations may depend on the day of the month or the week. This paper proposes to build profiles using temporal association rules in terms of multiple time granularities, and describes algorithms to discover these profiles. Because multiple time granularities are used for the profile generation, the proposed method is more flexible and precise than previous methods that use fixed partition of time intervals. Finally, the paper describes an experiment and its preliminary result on TCP-dump data. Yingjiu Li, Ningning Wu, Xiaoyang Sean Wang, Sushil Jajodia |
J. Comput. Secur. | 1 |
| 2001 | Discovering Calendar-based Temporal Association RulesabstractA temporal association rule is an association rule that holds during specific time intervals. An example is that eggs and coffee are frequently sold together in morning hours. The paper studies temporal association rules during the time intervals specified by user-given calendar schemas. Generally, the use of calendar schemas makes the discovered temporal association rules easier to understand. An example of calendar schema is (year, month, day), which yields a set of calendar-based patterns of the form (d/sub 3/, d/sub 2/, d/sub 1/), where each d/sub i/ is either an integer or the symbol *. For example, (2000, *, 16) is such a pattern, which corresponds to the time intervals, each consisting of the 16th day of a month in year 2000. This paper defines two types of temporal association rules: precise-match association rules require that the association rule holds during every interval, and fuzzy-match ones require that the association rule holds during most of these intervals. The paper extends the well-known a priori algorithm, and also develops two optimization techniques to take advantage of the special properties of the calendar-based patterns. The experiments show that the algorithms and optimization techniques are effective. Yingjiu Li, Peng Ning, Xiaoyang Sean Wang, Sushil Jajodia |
TIME | 1 |