Yang Lu 0001

dblp:16/6317-1 · DBLP profile ↗
← Back
37ranked-venue papers
15as first author
22since 2021 · last 2026
0000-0003-4860-8384ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 2 first-author · 7 since 2021Computer networks · 8 · 3 first-author · 7 since 2021Databases, data management, data science and information retrieval · 8 · 3 first-author · 2 since 2021Systems, architecture and hardware · 4 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Theory of computation · 2 · 1 first-author
YearPublicationVenuePosition
2026 Three-Patterns-Protected Searchable Encryption Supporting Disjunctive Keyword Search
abstract
Searchable encryption (SE) enables the client to execute keyword searches in encrypted data stored on the untrusted server and has been widely studied in cloud storage. To achieve higher efficiency and more functionalities, most SE schemes allowed the client to leak some information to the server. These leaked information are commonly referred to as leakage patterns. There are three important leakage patterns: search pattern, access pattern and volume pattern. Recent research has exploited at least one of these three patterns to attack SE schemes, resulting in the compromise of the confidentiality of encrypted data and queried keywords. Although existing SE schemes support conjunctive keyword search and protect these three patterns, these schemes do not support disjunctive keyword search and have a higher computational cost. In this paper, we use a private set union protocol based on additively symmetric homomorphic encryption to construct an SE scheme, which not only protects three patterns but also supports disjunctive keyword search. Specifically, we design an efficient token generation algorithm to protect the search pattern and a non-naive padding method to protect the volume pattern. Furthermore, we prove the correctness of our scheme through theoretical analysis and strictly prove the security under the leakage function. Finally, performance evaluation demonstrates that our scheme supports disjunctive keyword search while achieving a favorable trade-off between leakage protection and efficiency. Moreover, for components that exhibit relatively higher overhead during evaluation, we introduce optimization strategies that effectively enhance search efficiency and scalability.
Jiguo Li 0001, Licheng Ji, Wuwei Weng, Yichen Zhang 0003, Yang Lu 0001
IEEE Trans. Dependable Secur. Comput.5
2026 Expressive and Fully Policy-Hidden Attribute-Based Searchable Encryption Scheme for Multi-Owner
abstract
As cloud computing advances, data owners increasingly upload large volumes of data to the cloud. Attribute-based searchable encryption (ABSE) empowers data owners to manage fine-grained access over encrypted cloud files, and supports keyword-based search for authorized users. However, current multi-owner searchable encryption schemes often suffer from efficiency limitations and vulnerabilities to keyword guessing attacks. Furthermore, access policies are typically stored in plain form, exposing confidential details about data owners and authorized users. To tackle the aforementioned issues, we put forward an expressive attribute-based searchable encryption scheme with full policy concealment. Our design leverages the reduced ordered binary decision diagram (ROBDD) for access control targeting multi-user and multi-owner environments. In our scheme, users can flexibly select data owners and utilize a single trapdoor to search across shared datasets. The integration of a warrant server that signs obfuscated keywords prevents the cloud server from launching effective keyword guessing attacks. The adoption of ROBDD enables complex access policies via boolean operations, thereby significantly enhancing the efficiency and flexibility of access control. Full policy hiding is achieved by mapping ROBDD paths to an improved bloom filter, preventing access policy leakage. We present formal definitions and security models of the proposed approach, along with rigorous security proofs. Performance evaluation is conducted through theoretical analysis and simulations. Experimental indicate that our scheme achieves superior efficiency over state-of-the-art alternatives, offering a robust solution for secure and flexible cloud data management.
Jiguo Li 0001, Yang Lu 0001, Hang Cheng, Yichen Zhang 0003, Jian Shen 0001
IEEE Trans. Inf. Forensics Secur.3
2026 Privacy-Preserving Healthcare Cloud Access Control: Registered Attribute-Based Encryption With Auditable Policy Updating
Wuwei Weng, Jiguo Li 0001, Yichen Zhang 0003, Yang Lu 0001, Jinguang Han, Jian Shen 0001
IEEE Trans. Inf. Forensics Secur.4
2026 A Lightweight Blockchain-Assisted Certificateless Cloud Data Integrity Auditing Scheme Without Third-Party Auditor
abstract
Data Integrity Auditing (DIA) enables users to remotely verify whether their data saved in third-party clouds has been maliciously tampered with or compromised. As an extension of DIA in certificateless cryptography, certificateless DIA (CL-DIA) integrates the merits of conventional public-key cryptography (no key escrow) and identity-based cryptography (no certificates). However, CL-DIA schemes depend on a reliable third-party auditor (TPA) to perform integrity audits, inevitably suffering from performance bottleneck and single-point failure problems. Moreover, almost all current CL-DIA schemes were designed with computationally expensive bilinear pairings. Cryptanalysis demonstrates that the existing unique pairing-free CL-DIA scheme fails to achieve the unforgeable security of auditing proofs. In this work, we put forward a lightweight blockchain-assisted CL-DIA scheme. The scheme achieves DIA through the blockchain instead of a single TPA, thereby overcoming the problems caused by the TPA-based centralized auditing model. Then, by avoiding time-consuming pairing operations and employing edge servers in generating verifiable tags for the uploaded data of users, its performance surpasses previous pairing-based CL-DIA schemes, particularly in terms of computation efficiency. Furthermore, we provide formal proofs in the random oracle model demonstrating that our scheme achieves unforgeability of verifiable tags and auditing proofs, ensures data privacy secrity, and is resistant to collusion attacks between the EN and the CSP. Finally, experimental results show that when auditing 25 file blocks, our scheme only costs 0.29s, which reduces the total time cost of integrity auditing phase by 48.2%-85.5% compared to current pairing-based CL-DIA schemes.
Yang Lu 0001, Nian Xia, Jiguo Li 0001, Yinxia Sun
IEEE Trans. Inf. Forensics Secur.2
2025 Revocable Registered Attribute-Based Encryption With User Deregistration
abstract
Many businesses are putting their sensitive data in the cloud with the fast growth of cloud computing and storage. To ensure user privacy, it is necessary to keep encrypted data only in the cloud. Attribute-based encryption (ABE) is a popular mean in cloud storage scenarios. ABE is not only faced with key escrow problem but also suffers from user revocation issue when he or she is no longer authorized to access to encrypted data. In order to address these two issues, we propose a revocable registered attribute-based encryption scheme, which not only avoids key escrow problem but also supports precise revocation of a user’s access to a file as well as permanent deregistration of a user from the system. Furthermore, we prove the semantic security of the scheme and conduct a performance experiment to show the efficiency.
Jiguo Li 0001, Shaobo Chen, Yang Lu 0001, Jianting Ning, Jian Shen 0001, Yichen Zhang 0003
IEEE Internet Things J.3
2025 Efficient Key Escrow-Free Attribute-Based Signature for Anonymous Access Control in IIoT
abstract
Industrial Internet of Things (IIoT) processes industrial information anytime and anywhere by deploying smart devices, which inevitably confronts with potential challenges for access control and secure authentication issues. Attribute-based signature (ABS) utilizes a collection of attributes instead of the user’s identity to achieve identity authentication, which supports anonymous access control, data integrity and nonrepudiation. However, ABS schemes exist inherent key escrow problem because all users’ private keys are generated via key authority. In addition, most ABS schemes use time consuming pairing operations, which is unsuitable for resource-constrained IIoT devices. To solve above problems, we present a key escrow-free ABS scheme and utilize server-aided technology to run most of pairing operations in the verification phase, which reduces computation overhead in recursive algorithm based on tree. Furthermore, we utilize tree-based access policy to implement flexible access control. We design a key distribution protocol. By executing this protocol, the key authority cannot derive a whole private key independently without no user’s secret value, which solves key escrow problem. We demonstrate that the presented scheme is existentially unforgeable under adaptive chosen-policy attack in the standard model. Performance analysis shows that the designed scheme is more efficient compared with the existing ABS schemes.
Jiguo Li 0001, Yang Lu 0001, Jianting Ning, Yichen Zhang 0003, Jian Shen 0001
IEEE Internet Things J.3
2025 User-Friendly Field-Free Multikeyword Searchable Certificateless Encryption With Keyword Guessing Attack Security
abstract
Searchable public key encryption (SPKE) is a beneficial supplement to traditional public key encryption, which offers a viable method to address the retrieval issue over enciphered data. As a development of SPKE, searchable certificateless encryption enjoys good features of no burdensome certificate management and no key escrow. However, existing searchable certificateless encryption schemes suffer some limitations. Some only support single-keyword search, which often yields inaccurate results. Others enable conjunctive keyword search, which is difficult to cope with data lacking unified keyword fields. In the work, we present a user-friendly certificateless authenticated encryption with field-free multi-keyword search scheme. The proposed scheme eliminates time-consuming operations like bilinear pairing and hash-to-point calculations for data owners and data users. It also enables data users to make multi-keyword searches flexibly on resource-limited mobile devices without concern for keyword orders or positions. As far as we know, it is the first certificateless encryption scheme that supports field-free multi-keyword search. We demonstrate that it has the keyword guessing attack security by formal proofs and show its superior performance by comparisons and experiments. Compared to the state-of-the-art scheme with field-free multi-keyword search, our scheme reduces computation cost for creating a search token and communication cost for sending the search token by about 60% and 56%, respectively.
Yang Lu 0001, Yinxia Sun, Nian Xia, Jiguo Li 0001
IEEE Internet Things J.1
2025 EABE-PUFPH: Efficient Attribute-Based Encryption With Reliable Policy Updating Under Full Policy Hiding
Chenghao Gu, Jiguo Li 0001, Yichen Zhang 0003, Yang Lu 0001, Jian Shen 0001
IEEE Trans. Computers4
2025 Response-Hiding and Volume-Hiding Verifiable Searchable Encryption With Conjunctive Keyword Search
abstract
Verifiable searchable encryption (VSE) not only allows the client to search encrypted data, but also allows the client to verify whether the server honestly executes search operations. Currently, VSE scheme has been widely studied in cloud storage. However, most existing VSE schemes did not hide the access pattern and volume pattern, which respectively refer to the document identifiers and the number of documents matching the queried keywords. Recent studies have exploited these two patterns to launch attacks on searchable encryption schemes, resulting in compromising the confidentiality of encrypted data and queried keywords. In order to solve above issues, we utilize additively symmetric homomorphic encryption scheme and private set intersection protocol to construct a VSE scheme that supports conjunctive keyword search and hides the access pattern and volume pattern (i.e., response-hiding and volume-hiding). Our security model assumes that the server is malicious in the sense that it might deliberately carry out incorrect search operations. Formal security analysis demonstrates that our scheme achieves the desired security properties under our leakage function. Compared to previous schemes, our scheme has advantages in terms of performance and functionality. In an experimental setup with a security parameter of 128 bits and$2^{23}$keyword/document pairs, the search time is approximately only 7.18 seconds.
Jiguo Li 0001, Licheng Ji, Yichen Zhang 0003, Yang Lu 0001, Jianting Ning
IEEE Trans. Computers4
2025 Pairing-Free Attribute-Based Signature With Message Recovery for Industrial Internet of Things
abstract
Industrial Internet of Things (IIoT) has become a smart application for the Internet of Things (IoT), which promotes the industrial enterprises development. The smart devices deploy the IIoT to collect, manage and analyze data through sensors, which are inevitably confronted with access control and secure authentication issues. Attribute-based signature (ABS), in which every signer utilizes an attribute set to sign the message, is a graceful technology to achieve data authentication and anonymous access control. Nevertheless, in some existing ABS schemes, exponentiation and pairing operations are executed. Notably, pairing operations are time consuming and cannot be executed on constrained devices well, e.g. sensors. In addition, these ABS schemes generally need to send the signed message and signature together to the verifiers, which results in additional communication cost. The communication cost is more expensive than computing cost in wireless sensor of IIoT networks, which are unsuitable to IIoT devices. In order to reduce computation overhead and communication cost, we provide a novel pairing-free ABS scheme with message recovery, in which the signed message does not need to be transmitted. Furthermore, we utilize linear secret sharing scheme as access policy, which achieves flexible access control. The presented scheme is proven to be unforgeable and anonymous under the chosen-policy. The security of our scheme is reduced to elliptic curve discrete logarithm (DL) hard issue. The designed scheme is more efficient contrasted with existing ABS schemes with pairings at aspect of theoretical analysis and experimental simulation.
Jiguo Li 0001, Yang Lu 0001, Yichen Zhang 0003
IEEE Trans. Dependable Secur. Comput.3
2025 Verifiable Searchable Symmetric Encryption Over Additive Homomorphism
abstract
Searchable symmetric encryption (SSE) allows the client to search encrypted documents on an untrusted server without revealing the document content and queried keywords. To improve search efficiency and enrich expressiveness, most SSE schemes leak some information that could be exploited for attacks, characterized by leakage patterns. The traditional leakage patterns encompass the search pattern, the access pattern and the response length pattern. Recent research has demonstrated that these three patterns could be exploited to launch attacks, resulting in a high probability of compromising the confidentiality of encrypted documents and queried keywords. Moreover, while there exist SSE schemes that hide multiple leakage patterns, most of them do not resist the malicious server, which may carry out incorrect search operations. In this paper, we propose a leakage-suppressed verifiable SSE (VSSE) scheme that not only hides the three patterns but also allows the client to verify the server’s response. We utilize the privacy set intersection based on polynomial coding and additive symmetric homomorphism encryption to construct a VSSE scheme that supports a conjunctive query. Specifically, we design an efficient random token generation algorithm to protect the search pattern and a verification algorithm that does not require server-generated proofs. Formal security analysis shows that our scheme achieves the desired correctness, security and verifiability. Lastly, we simulate the proposed scheme and compare it with the recent leakage suppression schemes in multiple aspects. The comparison results show that our scheme achieves a good balance in expressiveness, efficiency and security.
Licheng Ji, Jiguo Li 0001, Yichen Zhang 0003, Yang Lu 0001
IEEE Trans. Inf. Forensics Secur.4
2025 User-Friendly and Expressive Forward-Secure Attribute-Based Signature With Server-Aided Signature and Outsourced Verification
abstract
Attribute-based signature (ABS) is an attractive variation of digital signature that enables signers to sign messages with fine-grained signature predicates. In ABS, a signer is able to perform signing operations without revealing personal attributes, and verifiers can only confirm that the signature was created by someone with attributes satisfying a specific signature predicate. However, traditional ABS suffers from key exposure, and the compromise of a signer’s signature key results in invalidating all signatures from him/her. To address this problem, forward-secure ABS (FS-ABS) was introduced. Nevertheless, existing FS-ABS schemes have the shortcomings of low policy expressiveness and high computation costs, and thus are not suitable to be employed on mobile devices with limited resources. In this paper, we propose a user-friendly and expressive FS-ABS (UEFS-ABS) scheme that is proven secure in the standard model. The proposed scheme not only supports expressive signature predicates based on the linear secret sharing scheme, but also provides server-aided signature and outsourced verification functions, significantly reducing the workload of user terminals at both signature generation and verification stages. The experiments indicate that compared with the up-to-date FS-ABS scheme, our scheme reduces the computation costs for signature generation (on signers’ devices) and verification (on verifiers’ devices) by about 85% and 68%, respectively. This makes our scheme more suitable for user terminals in mobile computing scenarios.
Chao Guo 0008, Yang Lu 0001, Nian Xia, Jiguo Li 0001
IEEE Trans. Knowl. Data Eng.2
2025 Efficient Registered Attribute Based Access Control With Same Sub-Policies in Mobile Cloud Computing
abstract
Ciphertext-policy attribute-based encryption (CP-ABE) has long been considered as a promising access control technology for cloud storage. However, CP-ABE depends on a central trusted authority to generate and distribute decryption keys, resulting in the key escrow issue. Most existing solutions only mitigate this problem but fail to resolve it entirely. Registered attribute-based encryption (RABE), a new cryptographic primitive, fundamentally addresses the key escrow problem by modifying the trust model, but its high computational overhead limits its practical application. Inspired by this challenge, we present an efficient registered attribute-based access control scheme designed for data encrypted with access policies containing the same sub-policy. In our scheme, users generate their own keys, while a key manager, who does not hold keys, replaces the central authority in managing users. Additionally, for data encrypted with the same sub-policy, the user’s initial decryption stores the relevant parameters, which can be used for subsequent decryptions to reduce computational overhead. The proposed scheme is proven to achieve semantic security. Performance analysis demonstrates that our scheme enhances decryption efficiency by roughly 41.4$\%$compared to existing RABE scheme, with a minimal storage trade-off, making it more practical for cloud storage application.
Wuwei Weng, Jiguo Li 0001, Yichen Zhang 0003, Yang Lu 0001, Jian Shen 0001, Jinguang Han
IEEE Trans. Mob. Comput.4
2024 Efficient Certificateless Aggregate Designated Verifier Signature With Conditional Privacy Preserving in VANETs
abstract
Vehicular ad hoc networks (VANETs) serve as the foundation of intelligent transportation systems, aiming to improve communication efficiency and safety among vehicles. With the expanding applications, security and privacy have become apparent, and the large-scale message transmission imposes substantial computation and communication overheads. The technology of aggregate signature can realize message authentication and reduce both the bandwidth and computation costs significantly. In IEEE 802.11p-based VANETs, most existing aggregate signature schemes require roadside units (RSUs) to verify single signatures before calculating aggregate signatures, which is very inefficient. Furthermore, even with a valid aggregated signature, the validity of individual signatures cannot be assured. In this paper, we propose an efficient certificateless aggregate signature scheme, where RSUs do not need to validate single signatures but compute aggregate signature directly. The successful verification of the aggregated signature implies the validity of each individual signature. Additionally, to further protect data security and user privacy, this scheme employs designated verifiers for both individual and aggregate signatures. Both formal and informal security analysis are given, and performance evaluation shows our scheme exhibits lower computation and communication costs, along with more comprehensive security attributes in VANETs.
Qiu Zhang, Yinxia Sun, Yang Lu 0001, Nian Xia, Ge Wu 0001
IEEE Internet Things J.3
2024 Revocable certificateless proxy re-signature with signature evolution for EHR sharing systems
Qiu Zhang, Yinxia Sun, Yang Lu 0001
J. Inf. Secur. Appl.3
2024 Lightweight Searchable and Equality-Testable Certificateless Authenticated Encryption for Encrypted Cloud Data
abstract
Public key encryption with equality test (PKE-ET) is a novel cryptosystem to deal with the problem of multi-public-key encrypted data computing. It can be used to verify if different ciphertexts are encryptions of same plaintext under different public keys without decryption. As an extension of PKE-ET, certificateless encryption with equality test (CLE-ET) has the merits of no key escrow and no certificate. However, the existing CLE-ET schemes are vulnerable to the message recovery (MR) attack and suffer from low efficiency due to using the computationally expensive bilinear pairing. In this work, an elliptic-curve-based certificateless authenticated encryption with keyword search and equality test (CLAE-KS&ET) scheme is developed. The scheme not only provides resistance to the MR attack, but also satisfies the lightweight requirement of the resources-restricted environments. Moreover, it supports a ciphertext retrieval function resisting keyword guessing attacks. This function enables a user to seek out the desired ciphertexts on the cloud server firstly before making ciphertext equality test with others. Based on the computational Diffie-Hellman (CDH) and decisional Diffie-Hellman (DDH) problems, we formally prove its security. Compared with the existing CLE-ET schemes, it significantly improves computational efficiency and is more suited to the user terminals with limited resources in cloud.
Jinmei Tian, Yang Lu 0001, Jiguo Li 0001
IEEE Trans. Mob. Comput.2
2024 Comment on an Attribute-Based Searchable Encryption Scheme With Receiver Anonymity
abstract
Privacy protection of search keywords is one of the challenges in building keyword-based searchable encryption schemes. In IEEE Transactions on Services Computing (Vol. 15, No.2, March/April 2022), Chaudhariet al. proposed an attribute-based searchable encryption (ABSE) scheme (named KeySea), which was claimed to provide an effective solution to solve the problem of privacy-preserving search over cloud encrypted data. However, we demonstrate that the scheme fails to protect the privacy of search keywords by proposing three attacks on it. Our attacks show that an adversary (an untrusted cloud server or a malicious user) can successfully extract the keyword from a search trapdoor by keyword guessing in an offline or online manner. After analyzing the reasons that cause such attacks, we provide the potential solutions to overcome similar security vulnerabilities in the ABSE schemes.
Guangao Zu, Yang Lu 0001, Jiguo Li 0001
IEEE Trans. Serv. Comput.2
2023 Privacy-Preserving and Forward Public Key Encryption With Field-Free Multi-Keyword Search for Cloud Encrypted Data
abstract
With the excessive growth of data and the rapid development of cloud technology, cloud adoption is expanding rapidly nowadays. To achieve the purpose of privacy protection, the cloud data may be transmitted, stored and retrieved in enciphered form. Public key searchable encryption (PKSE) provides a feasible solution for efficient retrieval over enciphered data without decryption. However, traditional PKSE suffers from some problems, such as keyword guessing (KG) attack and unauthorized ciphertext retrieval. In this paper, we present a practical PKSE scheme named forward public key authenticated encryption with field-free conjunctive keyword search (FW-PAE-FCKS). The scheme enjoys several good properties (e.g., flexible multi-keyword search with no keyword fields, forward ciphertext retrieval) and can effectively withstand the KG attack and the unauthorized ciphertext retrieval. Moreover, the executive overhead of the scheme is very friendly to the user terminals with limited resources as it totally avoids the operations with high computation cost (such as hash-to-point, bilinear pairing) on the user side. Based on the infeasibility assumption of the hash Diffie-Hellman problem, we formally prove its security without using the random oracle. Comparison analysis and experimental results show that it outperforms the existing related schemes.
Yang Lu 0001, Jiguo Li 0001
IEEE Trans. Cloud Comput.1
2022 Key escrow-free attribute based encryption with user revocation
Ruyuan Zhang, Jiguo Li 0001, Yang Lu 0001, Jinguang Han, Yichen Zhang 0003
Inf. Sci.3
2022 Lightweight Public Key Authenticated Encryption With Keyword Search Against Adaptively-Chosen-Targets Adversaries for Mobile Devices
abstract
Cloud storage services have grown extensively in recent years. For security and privacy purposes, sensitive data need to be outsourced to clouds in encrypted form. Searchable public key encryption (SPKE) enables data ciphertexts to be retrieved by keyword(s) without decryption. Unfortunately, most of the existing SPKE schemes cannot withstand the keyword guessing attack. To combat such attack, public key authenticated encryption with keyword search (PAEKS) was presented. However, the existing PAEKS schemes were proven secure under a designated-targets security model, in which an adversary only can attack a sender and a recipient designated by the challenger. Our cryptanalysis indicates that such a scheme may be insecure against the practical attacks where the adversaries choose their targets by themselves. To fight against adaptively-chosen-targets adversaries, we refine the adversary model for PAEKS by permitting the adversaries to choose their targets adaptively, and then formalize the security definitions under the improved security model. After that, we devise a lightweight PAEKS scheme that avoids the time-consuming bilinear pairing operations and give the security proofs. The comparisons show that it outperforms the existing bilinear pairing-based PAEKS schemes in both the computation and communication performance, and therefore is more suitable for the resource-constrained mobile devices.
Yang Lu 0001, Jiguo Li 0001
IEEE Trans. Mob. Comput.1
2021 Pairing-Free Certificate-Based Searchable Encryption Supporting Privacy-Preserving Keyword Search Function for IIoTs
abstract
As a practical application of the Internet of Things (IoT) in the modern industry, industrial IoT (IIoT) enables industrial enterprises to accelerate the development. Nowadays, the cloud computing technology has been applied to data storage and processing in IIoTs, but how to protect data privacy in the cloud has become a challenge and technical issue. Recently, the certificate-based encryption with keyword search (CBEKS) was presented to handle the cloud ciphertext retrieval. By CBEKS, one can get back all desired ciphertexts from the cloud without decrypting the ciphertexts or leaking the search keywords. However, the existing CBEKS scheme uses the computationally expensive bilinear pairing, which is disgusted by the performance-limited IIoT smart devices. In this article, a pairing-free and privacy-preserving CBEKS scheme is developed. The experimental results show that it has an obvious advantage in the computation performance when compared with the pairing-based CBEKS scheme. In addition, our security proofs indicate that it is secure against keyword guessing attacks.
Yang Lu 0001, Jiguo Li 0001
IEEE Trans. Ind. Informatics1
2021 Secure Channel Free Certificate-Based Searchable Encryption Withstanding Outside and Inside Keyword Guessing Attacks
abstract
Searchable public key encryption (SPKE) is a useful public key cryptographic primitive that allows a user to perform keyword searches over publicly encrypted messages on an untrusted storage server while guaranteeing the privacy of the original messages as well as the search keywords. However, most of the previously proposed SPKE frameworks suffer from the security vulnerability caused by the keyword guessing attack and some other weaknesses. Inspired by the ideas of certificate-based cryptography and signcryption, we present a new SPKE framework called certificate-based searchable encryption. The new framework not only provides resistance to the existing known types of keyword guessing attacks, but also enjoys some appealing merits, such as implicit authentication, no key escrow and no secure channel. Under this new framework, we devise a concrete searchable certificate-based encryption scheme. In the random oracle model, it is proven to meet the keyword ciphertext indistinguishability, the keyword ciphertext unforgeability and the keyword trapdoor indistinguishability under the adaptive chosen-keyword attack. The comparisons indicate that it is secure and practicable.
Yang Lu 0001, Jiguo Li 0001, Yichen Zhang 0003
IEEE Trans. Serv. Comput.1
2020 Privacy-Preserving and Pairing-Free Multirecipient Certificateless Encryption With Keyword Search for Cloud-Assisted IIoT
abstract
Nowadays, cloud-assisted Industrial Internet of Things (IIoT) has become pervasive in modern enterprises, because it supplies a promising way to transform the operation mode of existing industrial facilities, to enhancing the production efficiency and lowering the manufacturing cost. In order to preserve the privacy of enterprises, sensitive industrial data needs to be encrypted prior to being uploaded to the cloud. Recently, certificateless encryption with keyword search (CLKS) was introduced to resolve the problem of encrypted data retrieval in cloud-assisted IIoT. However, the existing CLKS schemes only support a single-recipient keyword search and need to depend on the costly bilinear pairing that is disliked by the resource-constrained IIoT devices. Moreover, most of the existing CLKS schemes are vulnerable to the keyword guessing attack, and thus fail to protect the privacy of searched data. In this article, we develop a privacy-preserving and pairing-free multirecipient CLKS scheme for cloud-assisted IIoT. The proposed scheme has the following merits: 1) supporting multirecipient keyword search function; 2) requiring no costly bilinear pairing operations; and 3) providing resistance against keyword guessing attacks. The performance comparison and analysis demonstrate that it is more efficient than the existing CLKS schemes and is appropriate for the cloud-assisted IIoT.
Yang Lu 0001, Jiguo Li 0001, Yichen Zhang 0003
IEEE Internet Things J.1
2020 Adaptively secure certificate-based broadcast encryption and its application to cloud storage service
Liqing Chen, Jiguo Li 0001, Yang Lu 0001, Yichen Zhang 0003
Inf. Sci.3
2019 Keyword guessing attacks on a public key encryption with keyword search scheme without random oracle and its improvement
Yang Lu 0001, Jiguo Li 0001
Inf. Sci.1
2019 Constructing pairing-free certificateless public key encryption with keyword search
abstract
Searchable public key encryption enables a storage server to retrieve the publicly encrypted data without revealing the original data contents. It offers a perfect cryptographic solution to encrypted data retrieval in encrypted data storage systems. Certificateless cryptography (CLC) is a novel cryptographic primitive that has many merits. It overcomes the key escrow problem in identity-based cryptosystems and the cumbersome certificate problem in conventional public key cryptosystems. Motivated by the appealing features of CLC, three certificateless encryption with keyword search (CLEKS) schemes were presented in the literature. However, all of them were constructed with the costly bilinear pairing and thus are not suitable for the devices that have limited computing resources and battery power. So, it is interesting and worthwhile to design a CLEKS scheme without using bilinear pairing. In this study, we put forward a pairing-free CLEKS scheme that does not exploit bilinear pairing. We strictly prove that the scheme achieves keyword ciphertext indistinguishability against adaptive chosen-keyword attacks under the complexity assumption of the computational Diffie-Hellman problem in the random oracle model. Efficiency comparison and the simulation show that it enjoys better performance than the previous pairing-based CLEKS schemes. In addition, we briefly introduce three extensions of the proposed CLEKS scheme.
Yang Lu 0001, Jiguo Li 0001
Frontiers Inf. Technol. Electron. Eng.1
2018 Anonymous certificate-based broadcast encryption with constant decryption cost
Jiguo Li 0001, Liqing Chen, Yang Lu 0001, Yichen Zhang 0003
Inf. Sci.3
2018 Provably secure certificate-based encryption with leakage resilience
Yuyan Guo, Jiguo Li 0001, Yang Lu 0001, Yichen Zhang 0003, Futai Zhang
Theor. Comput. Sci.3
2017 Weakness and Improvement of a Certificate-Based Key-Insulated Signature in the Standard Model
abstract
Certificate-based cryptography is a novel cryptographic primitive that has many attractive merits. It solves the certificate revocation problem in conventional public key cryptography and overcomes the key-escrow problem in identity-based cryptography. Recently, Li et al. presented a certificate-based key-insulated signature (CBKIS) scheme in the standard model. However, their scheme suffers from a security vulnerability caused by the malicious certification authority (CA) attack. Our cryptanalysis shows that a malicious CA is able to break its unforgeability by implanting some trapdoors in the public system parameters. To remedy the security weakness in Li et al.’s scheme, we put forward an improved CBKIS scheme. Under the complexity assumption of the square computational Diffie–Hellman problem, the improved scheme is proven to be existentially unforgeable in the standard model. Compared with the original CBKIS scheme proposed by Li et al., it enjoys better performance while offering stronger security guarantee as it can resist the malicious CA attack.
Yang Lu 0001, Jiguo Li 0001, Jian Shen 0001
Comput. J.1
2016 A pairing-free certificate-based proxy re-encryption scheme for secure data sharing in public clouds
Yang Lu 0001, Jiguo Li 0001
Future Gener. Comput. Syst.1
2016 Improved certificate-based signature scheme without random oracles
abstract
Certificate‐based cryptography is a useful primitive that combines traditional public key cryptography (PKC) and identity‐based cryptography (IBC). It not only solves the key escrow problem inherent in IBC, but also simplifies the certificate problem in traditional PKC. So far, several certificate‐based signature (CBS) schemes have been proposed in the literature. However, none of them consider the malicious certificate authority (CA) attack. Cryptanalysis shows that two previous CBS schemes without random oracles fail in achieving unforgeability under such attack. To overcome the security weakness in these schemes, the authors propose an improved CBS scheme that can withstand malicious CA attacks. They prove it to be existentially unforgeable against chosen message attacks under the computational Diffie–Hellman assumption in the standard model. Compared with the previous standard‐model CBS schemes, the proposed scheme has obvious advantages in both the computation and communication efficiency.
Yang Lu 0001, Jiguo Li 0001
IET Inf. Secur.1
2016 Continuous leakage-resilient certificate-based encryption
Jiguo Li 0001, Yuyan Guo, Qihong Yu, Yang Lu 0001, Yichen Zhang 0003, Futai Zhang
Inf. Sci.4
2016 A provably secure certificate-based encryption scheme against malicious CA attacks in the standard model
Yang Lu 0001, Jiguo Li 0001
Inf. Sci.1
2016 Comment on a certificateless one-pass and two-party authenticated key agreement protocol
Yang Lu 0001, Quanling Zhang, Jiguo Li 0001, Jian Shen 0001
Inf. Sci.1
2016 Provably secure identity-based encryption resilient to post-challenge continuous auxiliary input leakage
abstract
The situation for post-challenge continuous auxiliary input leakage has not been considered in the cryptography schemes for previous literature. We present a semantic-security model with post-challenge continuous auxiliary inputs for identity-based encryption. In this model, the adversary is permitted to obtain some information of the private keys constantly and to query more information after seeing the challenge ciphertext through the side-channel attacks. Furthermore, we present an identity-based encryption scheme resilient to leakage under composite order groups. Our scheme is secure against post-challenge continuous auxiliary input, adaptive chosen-identity, and adaptive chosen plaintext attacks under three static assumptions in the standard model. Compared with existing identity-based encryption schemes under security properties and performance, our scheme is practical. Copyright © 2015 John Wiley & Sons, Ltd.
Jiguo Li 0001, Yuyan Guo, Qihong Yu, Yang Lu 0001, Yichen Zhang 0003
Secur. Commun. Networks4
2016 Provably secure certificateless proxy signature scheme in the standard model
Yang Lu 0001, Jiguo Li 0001
Theor. Comput. Sci.1
2009 Forward-Secure Certificate-Based Encryption
abstract
Certificate-based encryption (CBE) is a new paradigm which overcomes the shortcomings of traditional public-key encryption (PKE) and identity based encryption (IBE). CBE provides an efficient implicit certificate mechanism to eliminate third-party queries for the certificate status and to simplify the certificate revocation problem in traditional PKI. Therefore, CBE can be used to construct an efficient PKI requiring fewer infrastructures. It also solves the key escrow and key distribution problem inherent in IBE. In this paper, we introduce a new notion called Forward-Secure Certificate-Based Encryption. It preserves the advantages of CBE such as implicit certificate and no private key escrow. At the same time it also inherits the properties of the forward-secure public key encryption. We also propose a concrete and efficient forward-secure CBE scheme and prove it to be secure based on the bilinear Diffie-Hellman assumption in the random oracle model.
Yang Lu 0001, Jiguo Li 0001
IAS1