VLDB 2026 Research / reviewers in the wild / expert
Huihui Zhu 0001
dblp:150/3149-1
· DBLP profile ↗
8ranked-venue papers
2as first author
8since 2021 · last 2026
0009-0006-5701-1837ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 3 · 3 since 2021Computer networks · 2 · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SecOutPIR: privacy preservation for data owner and access control for data user in outsourced private information retrievalabstractAbstract Private Information Retrieval (PIR) is a cryptographic technique that allows Data User (DU) to retrieve data from a SERVER without revealing which specific data item is being accessed. Traditional PIR protocols typically assume that the data is locally stored and directly controlled by Data Owner (DO), but in real-world scenarios, data is often hosted on untrusted third-party SERVERs, making it difficult for DO to effectively restrict the SERVER’s access to their data or control which DU is authorized to retrieve the data. Consequently, malicious SERVERs or unauthorized DU may infringe upon the privacy rights of DO. This paper presents SecOutPIR, a novel outsourced PIR system that addresses two key challenges: privacy preservation for DO and access control for DU. SecOutPIR integrates attribute-based encryption for fine-grained retrieval access control to ensure that only DU with valid retrieval can access the data, while also utilizing a decentralized identity management system based on decentralized identifiers and verifiable credentials to authenticate DU requests. The proposed system ensures that the DO’s data privacy is protected during data storage and retrieval, while also ensuring that only DU with authorized retrieval can make retrieval requests, thus preventing unauthorized access. We provide a detailed description of the system model, security requirements, and an in-depth security analysis. Furthermore, experimental results demonstrate that SecOutPIR significantly enhances the practicality and efficiency of PIR in outsourced settings by enabling fine-grained retrieval access control without degrading query performance. Our implementation demonstrates that the SERVER reply time increases with the dataset size, from 82.5 ms (1000 entries) to 113.8 ms (2000 entries) and 199.6 ms (5000 entries), while the query generation time remains approximately constant at around 2.0 ms. Fei Tang 0001, Ruixue Li, Huihui Zhu 0001, Mingjie Han |
Cybersecur. | 3 |
| 2026 | Efficient Multiuser Searchable and Revocable Data Sharing Scheme for IoVabstractThe Internet of Vehicles (IoV), as a critical component of future intelligent transportation systems, enables vehicles to generate and exchange massive volumes of sensing data in real time. To facilitate efficient data sharing and alleviate the burden of local storage, vehicle data is typically encrypted and outsourced to the cloud, with data availability ensured through searchable encryption. However, existing IoV data sharing frameworks offer limited support for secure multi-keyword search and dynamic user revocation. Moreover, most current solutions rely on public-key searchable encryption, which compromises the efficiency required for data processing in IoV environments. To address these challenges, we propose an efficient multi-user searchable and revocable data sharing scheme (EMUSR-SSE) tailored for IoV. EMUSR-SSE extends symmetric searchable encryption to support efficient multi-user access control and trustworthy multi-keyword search by designing a proxy matrix transformation mechanism integrated with Intel SGX. To enable flexible and scalable user revocation, EMUSR-SSE introduces a revocable dynamic sparse Merkle tree structure to manage multi-user permissions effectively. Furthermore, by leveraging the trusted execution environment within SGX and encrypting each data item individually, EMUSR-SSE significantly mitigates the risk of key leakage. Security analysis and experimental evaluations demonstrate that EMUSR-SSE achieves high efficiency and strong practical performance in dynamic IoV environments. Ping Wang 0086, Fei Tang 0001, Haining Luo, Fengjie Peng, Huihui Zhu 0001, Ankui Jing, Yawen Huang |
IEEE Internet Things J. | 5 |
| 2026 | ISSCC: Integrated Service for Full-Process Delivery in Secure Cloud ComputingabstractSecure cloud computing offers a range of services including storage, search, and computation, all of which have experienced ongoing performance advancements. However, seamlessly integrating these services into a unified “storage–search–computation” workflow remains challenging due to heterogeneous security mechanisms. For instance, searchable encryption, while effective for secure search, does not natively support computation over ciphertext. To address this gap, we propose ISSCC, an integrated service framework that seamlessly bridges storage, search, and computation in secure cloud environments. ISSCC employs searchable encryption to ensure secure data storage and search. To support post-search computation on retrieved results, ISSCC utilizes trusted execution environments instead of purely cryptographic approaches. We implement ISSCC on a real TEE-enabled cloud platform and conduct a comprehensive performance evaluation and security analysis. Experimental results demonstrate that ISSCC is both feasible and practical, delivering effective end-to-end services across the full “storage–search–computation” pipeline in secure cloud computing. Ping Wang 0086, Fei Tang 0001, Huihui Zhu 0001, Shiyue Kang |
IEEE Trans. Cloud Comput. | 4 |
| 2026 | DMS-P$^{2}$2CQ: Privacy-Preserving Collaborative Query Protocol for Distributed Multi-Server SystemsabstractA privacy-preserving collaborative query protocol for distributed multi-server systems (DMS-P$^{2}$CQ) enables a querying party to interact with multiple independent servers using an identifier$x_{u}$and receive a categorical decision (e.g.,Good/Moderate/Poor) determined by the total number of servers whose datasets contain$x_{u}$. This setting is motivated by financial applications such as credit assessment, where the querying party must not reveal$x_{u}$to data-owning institutions, and each institution must protect its proprietary user list. To meet both the functionality and privacy requirements of the querying party and the servers, we present two protocols that represent a privacy-efficiency trade-off. DMS-P$^{2}$CQ$_{1}$is a lightweight protocol inspired by OPRF-based PSI. It achieves identifier privacy and hides the identifier-to-server membership relation from the querying party via a two-stage OPRF with an aggregation/re-randomization server. However, it reveals the aggregate count to a randomly selected leader server and relies on a non-collusion assumption between two special servers. DMS-P$^{2}$CQ$_{2}$strengthens privacy by secret-sharing the count so that no single party learns the true aggregate count and removes the need for a trusted re-randomization server. We prove the security of two protocols under the semi-honest model. Experimental results on our local testbed show that with 20 servers and a dataset size of$2^{20}$, the runtimes for DMS-P$^{2}$CQ$_{1}$and DMS-P$^{2}$CQ$_{2}$are approximately 8.034s and 16.697s, respectively. Huihui Zhu 0001, Fei Tang 0001, Jinyong Shan, Ping Wang 0086, Yulun Song, Yunlong Xie |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Improved dynamic Byzantine Fault Tolerant consensus mechanism
Fei Tang 0001, Jinlan Peng, Ping Wang 0086, Huihui Zhu 0001, Tingxian Xu |
Comput. Commun. | 4 |
| 2024 | Efficient and secure heterogeneous online/offline signcryption for wireless body area network
Huihui Zhu 0001, Yongliang Xu, Guanhua Chen 0007, Liqing Chen |
Pervasive Mob. Comput. | 1 |
| 2022 | Heterogeneous online/offline signcryption for secure communication in Internet of Things
Huihui Zhu 0001, Wenyu Qin, Jinsong Shan |
J. Syst. Archit. | 2 |
| 2021 | An identity-based proxy re-encryption for data deduplication in cloud
Ge Kan, Huihui Zhu 0001, Yongliang Xu |
J. Syst. Archit. | 3 |