VLDB 2026 Research / reviewers in the wild / expert
Cheng-Kang Chu
dblp:16/4408
· DBLP profile ↗
24ranked-venue papers
10as first author
5since 2021 · last 2025
0000-0002-1429-7955ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 8 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorTheory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Delegatable Multi-Authority Attribute-Based Anonymous CredentialsabstractIn cloud computing, users need to authenticate to access various resources. Attribute-based anonymous credentials (ABCs) provide a tool for privacy-preserving authentication, allowing users to prove possession of a set of attributes to cloud service providers anonymously. Most existing works on ABC deal with credentials on attributes issued by a single authority (issuer). In reality, it is more practical for users to obtain credentials on attributes from multiple authorities. There are a few works on multi-authority ABC, which do not support delegation needed in real deployments. In this article, we present the first delegatable multi-authority attribute-based anonymous credential system, which simultaneously achieves revocation and traceability. We also give the security analysis of our construction. Finally, we implement our system, and the experimental results show its efficiency. Junzuo Lai, Xiaohan Mo, Peng Li 0059, Cheng-Kang Chu, Robert H. Deng |
IEEE Trans. Cloud Comput. | 6 |
| 2025 | How to Securely Delegate and Revoke Partial Authorization CredentialsabstractAn attribute-based credential (ABC) system allows a user, obtaining a credential on a set of attributes from an issuer, to anonymously prove a subset of attributes to a service provider. Nowadays, delegation is an important requirement of ABC, which allows a user to delegate his credentials to other users. However, traditional delegatable ABC systems only support delegating a credential with all attributes. In many scenarios, an appropriate delegation is a user can delegate his credential on parts of attributes to others. Another requirement is revocation of credentials in case of unexpected events. In this article, we propose a delegatable and revocable attribute-based credential, which simultaneously achieves: (1) a user can delegate a credential on parts of attributes to other entities (devices/users); (2) a user can efficiently revoke his credentials or those delegated by him; (3) a user can selectively disclose some attributes and also can prove that the non-disclosed attributes satisfy some relations. To achieve our delegatable and revocable attribute-based credential, we introduce a new primitive, called purgeable signature (PS). We formally define the security model of PS. We then give an efficient construction with a constant-size signature and present the security proofs of PS. Finally, the experimental results show the efficiency of our system. Junzuo Lai, Wei Wu 0001, Cheng-Kang Chu, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Bandwidth-Efficient Zero-Knowledge Proofs For Threshold ECDSAabstractAbstract In most threshold Elliptic Curve Digital Signature Algorithm (ECDSA) signatures using additively homomorphic encryption, the zero-knowledge (ZK) proofs related to the ciphertext or the message space are the bottleneck in terms of bandwidth as well as computation time. In this paper, we propose a compact ZK proof for relations related to the Castagnos–Laguillaumie (CL) encryption, which is 33% shorter and 29% faster than the existing work in PKC 2021. We also give new ZK proofs for relations related to homomorphic operations over the CL ciphertext. These new ZK proofs are useful to construct a bandwidth-efficient universal composable-secure threshold ECDSA without compromising the proactive security and the non-interactivity. In particular, we lowered the communication and computation cost of the key refresh algorithm in the Paillier-based counterpart from $O(n^3)$ to $O(n^2)$. Considering a 5-signer setting, the bandwidth is better than the Paillier-based counterpart for up to 99, 95 and 35% for key generation, key refreshment and pre-signing, respectively. Handong Cui, Kwan Yin Chan, Tsz Hon Yuen, Xin Kang 0001, Cheng-Kang Chu |
Comput. J. | 5 |
| 2023 | Abnormal Traffic Detection: Traffic Feature Extraction and DAE-GAN With Efficient Data AugmentationabstractAbnormal traffic detection is the core component of the network intrusion detection system. Although semisupervised methods can detect zero-day attack traffic, previous work suffers from high false alarms because the trained model is simply based on normal traffic. In this article, we propose an accurate abnormal traffic detection method using pseudoanomaly, consisting of an efficient feature extraction framework and a novel denoise autoencoder-generative adversarial network (DAE-GAN) model. The feature extraction framework adopts an innovative packet window scheme to extract spatial and temporal features from traffic flows. The DAE-GAN model has multiple DAEs to achieve efficient data augmentation and generate high-quality pseudoanomalies. The pseudoanomalies are obtained by adding noise on normal traffic and enhanced by adversarial learning in DAE-GAN. Our semisupervised detection method, exploiting both normal data and generated pseudoanomalies, achieves a precision of 98.6% on the NSL-KDD dataset and 98.5% on the UNSW-NB15 dataset. Compared with the state-of-the-art, the detection precision and recall under different user behaviors are significantly improved. The evaluation on four attack datasets shows that our method has a high flow-wise precision of over 99% and a high recall of 60.6%. Zecheng Li 0001, Shengyuan Chen, Hongshu Dai, Dunyuan Xu, Cheng-Kang Chu, Bin Xiao 0001 |
IEEE Trans. Reliab. | 5 |
| 2022 | Towards Secure and Trustworthy Flash Loans: A Blockchain-Based Trust Management Approach
Yining Xie, Xin Kang 0001, Tieyan Li, Cheng-Kang Chu |
NSS | 4 |
| 2019 | Keyed Non-parametric Hypothesis Tests
Cheng-Kang Chu, Hsiao-Ying Lin, Marius Lombard-Platet, David Naccache |
NSS | 2 |
| 2015 | Time-Bound Anonymous Authentication for Roaming NetworksabstractWe propose an anonymous authentication protocol that supports time-bound credentials for an efficient revocation. It is especially suitable for large-scale network in roaming scenario. With our newly designed group signature scheme as a building block, a timestamp can be embedded to user secret key. No expired key can be used to authenticate, and hence naturally revoked users (e.g., due to contract expiration) are not required to be put into the revocation list. This makes our protocol much faster than previous roaming protocols in terms of revocation checking, which is a main part in verification. Joseph K. Liu, Cheng-Kang Chu, Sherman S. M. Chow, Xinyi Huang 0001, Man Ho Au, Jianying Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2014 | Chosen-ciphertext secure multi-hop identity-based conditional proxy re-encryption with constant-size ciphertexts
Kaitai Liang, Cheng-Kang Chu, Xiao Tan 0003, Duncan S. Wong, Chunming Tang 0003, Jianying Zhou 0001 |
Theor. Comput. Sci. | 2 |
| 2014 | Key-Aggregate Cryptosystem for Scalable Data Sharing in Cloud StorageabstractData sharing is an important functionality in cloud storage. In this paper, we show how to securely, efficiently, and flexibly share data with others in cloud storage. We describe new public-key cryptosystems that produce constant-size ciphertexts such that efficient delegation of decryption rights for any set of ciphertexts are possible. The novelty is that one can aggregate any set of secret keys and make them as compact as a single key, but encompassing the power of all the keys being aggregated. In other words, the secret key holder can release a constant-size aggregate key for flexible choices of ciphertext set in cloud storage, but the other encrypted files outside the set remain confidential. This compact aggregate key can be conveniently sent to others or be stored in a smart card with very limited secure storage. We provide formal security analysis of our schemes in the standard model. We also describe other application of our schemes. In particular, our schemes give the first public-key patient-controlled encryption for flexible hierarchy, which was yet to be known. Cheng-Kang Chu, Sherman S. M. Chow, Wen-Guey Tzeng, Jianying Zhou 0001, Robert H. Deng |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2013 | CloudHKA: A Cryptographic Approach for Hierarchical Access Control in Cloud Computing
Yi-Ruei Chen, Cheng-Kang Chu, Wen-Guey Tzeng, Jianying Zhou 0001 |
ACNS | 2 |
| 2013 | Privacy-preserving smart metering with regional statistics and personal enquiry servicesabstractIn smart grid, households may send the readings of their energy usage to the utility and a third-party service provider which provides analyzed statistics data to users. User privacy becomes an important issue in this application. In this paper, we propose a new cryptographic-based solution for the privacy issue in smart grid systems. The advantages of our system are twofold: Households can send authenticated energy consumption readings to a third-party service provider anonymously. The service provider learns only the region where the readings come from but not their respective identities. On the other hand, users with personal secret information can enquiry their usage history records or regional statistics. Cheng-Kang Chu, Joseph K. Liu, Jun Wen Wong, Yunlei Zhao, Jianying Zhou 0001 |
AsiaCCS | 1 |
| 2012 | Verifier-local revocation group signatures with time-bound keysabstractA prominent issue in group signatures is revoking a group member's signing capability. To solve this issue, the group manager can send revocation messages only to signature verifiers, known as group signatures with verifier-local revocation (VLR). In existing VLR designs, the cost of revocation check grows linearly with the size of revocation messages. This paper introduces time-bound keys into group signatures to reduce the size of revocation messages and speed up the revocation check. In the new notion, the secret key of each group member is associated with an expiration date, and verifiers can tell (at a constant cost) whether or not a group signature is produced using an expired key. Consequently, revocation messages only need to provide the information about group members revoked prematurely (e.g., due to key compromise) but not those with expired keys. This will lead to a significant saving on revocation check in situations where prematurely revoked members are only a small fraction of revoked members. Following this approach, we give two concrete designs of group signatures with VLR to demonstrate the trade-offs between efficiency and privacy. Cheng-Kang Chu, Joseph K. Liu, Xinyi Huang 0001, Jianying Zhou 0001 |
AsiaCCS | 1 |
| 2012 | Enhanced authentication for commercial video servicesabstractABSTRACT The advance in information technology has made video service a market with great commercial value. As an example, in‐vehicle infotainment has been introduced to vehicles with which customers can enjoy subscribed media services wherever they are. This paper investigates the authentication in commercial video services using a recently proposed protocol, the Sun–Leu protocol, as baseline. Several important security and performance requirements are revisited, including mutual authentication, anonymous authentication, one‐to‐many delivery, low communication cost and the security against replay attacks. We provide a detailed analysis of the Sun–Leu protocol against these requirements, based on which an enhanced authentication scheme is proposed. The new scheme is designed within the framework of the Sun–Leu protocol, preserves all merits of the original protocol and provides a higher level of security for video communication services. Copyright © 2012 John Wiley & Sons, Ltd. Xinyi Huang 0001, Cheng-Kang Chu, Jianying Zhou 0001, Robert H. Deng |
Secur. Commun. Networks | 2 |
| 2011 | Identity-Based Server-Aided Decryption
Joseph K. Liu, Cheng-Kang Chu, Jianying Zhou 0001 |
ACISP | 2 |
| 2011 | Secure mobile subscription of sensor-encrypted dataabstractIn an end-to-end encryption model for a wireless sensor network (WSN), the network control center preloads encryption and decryption keys to the sensor nodes and the subscribers respectively, such that a subscriber can use a mobile device in the deployment field to decrypt the sensed data encrypted by the more resource-constrained sensor nodes. This paper proposes SMS-SED, a provably secure yet practically efficient key assignment system featuring a discrete time-based access control, to better support a business model where the sensors deployer rents the WSN to customers who desires a higher flexibility beyond subscribing to strictly consecutive periods. In SMS-SED, a node or a mobile device stores a secret key of size independent of the total number of sensor nodes and time periods. We evaluated the feasibility of deploying 2000 nodes for 4096 time periods at 1024-bit of security as a case study, studied the trade off of increasing the storage requirement of a node to significantly reduce its computation time, and provided formal security argument in the random oracle model. Cheng-Kang Chu, Wen Tao Zhu, Sherman S. M. Chow, Jianying Zhou 0001, Robert H. Deng |
AsiaCCS | 1 |
| 2011 | On Shortening Ciphertexts: New Constructions for Compact Public Key and Stateful Encryption Schemes
Joonsang Baek, Cheng-Kang Chu, Jianying Zhou 0001 |
CT-RSA | 2 |
| 2010 | Practical ID-based encryption for wireless sensor networkabstractIn this paper, we propose a new practical identity-based encryption scheme which is suitable for wireless sensor network (WSN). We call it Receiver-Bounded Online/Offline Identity-based Encryption (RB-OOIBE). It splits the encryption process into two parts -- the offline and the online part. In the offline part, all heavy computations are done without the knowledge of the receiver's identity and the plaintext message. In the online stage, only light computations such as modular operation and symmetric key encryption are required, together with the receiver's identity and the plaintext message. Moreover, since each offline ciphertext can be re-used for the same receiver, the number of offline ciphertexts the encrypter holds only confines the number of receivers instead of the number of messages to be encrypted. In this way, a sensor node (with limited computation power and limited storage) in WSN can send encrypted data easily: A few offline ciphertexts can be computed in the manufacturing stage while the online part is light enough for the sensor to process. Cheng-Kang Chu, Joseph K. Liu, Jianying Zhou 0001, Feng Bao 0001, Robert H. Deng |
AsiaCCS | 1 |
| 2009 | Conditional Proxy Broadcast Re-Encryption
Cheng-Kang Chu, Jian Weng 0001, Sherman S. M. Chow, Jianying Zhou 0001, Robert H. Deng |
ACISP | 1 |
| 2009 | Conditional proxy re-encryption secure against chosen-ciphertext attackabstractIn a proxy re-encryption (PRE) system [4], a proxy, authorized by Alice, can convert a ciphertext for Alice into a ciphertext for Bob without seeing the underlying plaintext. PRE has found many practical applications requiring delegation. However, it is inadequate to handle scenarios where a fine-grained delegation is demanded. To overcome the limitation of existing PRE systems, we introduce the notion of conditional proxy re-encryption (C-PRE), whereby only ci-phertext satisfying a specific condition set by Alice can be transformed by the proxy and then decrypted by Bob. We formalize its security model and propose an efficient C-PRE scheme, whose chosen-ciphertext security is proven under the 3-quotient bilinear Diffie-Hellman assumption. We further extend the construction to allow multiple conditions with a slightly higher overhead. Jian Weng 0001, Robert H. Deng, Xuhua Ding, Cheng-Kang Chu, Junzuo Lai |
AsiaCCS | 4 |
| 2007 | Identity-Committable Signatures and Their Extension to Group-Oriented Ring Signatures
Cheng-Kang Chu, Wen-Guey Tzeng |
ACISP | 1 |
| 2007 | Identity-Based Proxy Re-encryption Without Random Oracles
Cheng-Kang Chu, Wen-Guey Tzeng |
ISC | 1 |
| 2007 | Optimal resilient threshold GQ signatures
Cheng-Kang Chu, Wen-Guey Tzeng |
Inf. Sci. | 1 |
| 2003 | A Threshold GQ Signature Scheme
Li-Shan Liu, Cheng-Kang Chu, Wen-Guey Tzeng |
ACNS | 2 |
| 2002 | Distributed Key Generation as a Component of an Integrated Protocol
Cheng-Kang Chu, Wen-Guey Tzeng |
ICICS | 1 |