VLDB 2026 Research / reviewers in the wild / expert
Jinhua Ma
dblp:167/8292
· DBLP profile ↗
12ranked-venue papers
4as first author
9since 2021 · last 2023
0000-0002-6870-048XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 2 first-author · 8 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | An Adaptively Secure and Efficient Data Sharing System for Dynamic User Groups in CloudabstractCloud computing has been widely accepted as a computing paradigm to offer high-quality data services on demand. However, it suffers from various attacks as the cloud service provider and data owners are not in the same trusted domain. To support data confidentiality, existing cloud-based systems apply cryptographic tools to issue the decryption key to data users to share data in a controlled way. However, fine-grained cloud data sharing still faces many challenges, especially when dealing with dynamic user groups. In this paper, we introduce a secure and efficient cloud-based data-sharing system with fine-grained access control and dynamic user groups. Our system enjoys 1) adaptive security in prime-order groups, 2) forward secrecy against revoked user fetches data generated before being revoked, and 3) decryption key exposure resistance against the compromise of the frequently used decryption key, where the previous solutions only concentrate on one or two above-mentioned properties. More specifically, we introduce two timestamp management mechanisms that manage the timestamp in each ciphertext to support dynamic user groups with forward secrecy. By applying the proposed timestamp management mechanisms, we introduce two novel designs of attribute-based encryption schemes with formal definition and security analyses. The proposed schemes are adaptively secure in prime-order groups under a standard assumption and support decryption key exposure resistance. We conduct theoretical analysis and experimental simulation to demonstrate the outperformance of our solutions. Guowen Xu, Shengmin Xu, Jinhua Ma, Jianting Ning, Xinyi Huang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Catch me if you can: A Secure Bilateral Access Control System With Anonymous CredentialsabstractBilateral access control model, emerging as a novel paradigm in access control, has garnered extensive deployment within the domain of fog computing. This model offers on-demand data services, enabling the efficient identification of sensitive data without resorting to resource-intensive decryption procedures. Nonetheless, prevailing solutions exhibit impracticalities. Specifically, they fall short in supporting adaptive security, while presuming unwavering trustworthiness of the central authority. In this paper, we introduce a pioneering fine-grained and adaptively secure bilateral access control system through enhancements to the matchmaking attribute-based encryption (MABE) framework. We give a formalized definition of MABE, incorporating desirable security features such as blindness and unlinkability, aimed at capturing potential misconduct by the central authority. We propose a generic construction of MABE, drawing upon attribute-based encryption (ABE) and anonymous credential schemes (ACS), with provable security via formal security reduction in the adaptive model. We present an efficient instantiation of the MABE framework by introducing a practical ACS solution, wherein a cryptographic accumulator is employed to enhance performance. Experimental simulations substantiate that our solution not only has superior functionalities but also demonstrates performance on par with state-of-the-art solutions. Jinhua Ma, Shengmin Xu, Jianting Ning, Xinyi Huang 0001, Robert H. Deng |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | Authenticated Data Redaction With Accountability and TransparencyabstractA common practice in data redaction is removing sensitive information prior to data publication or release. In data-driven applications, one must be convinced that the redacted data is still trustworthy. Meanwhile, the data redactor must be held accountable for (malicious) redaction, which could change/hide the meaning of the original data. Motivated by these concerns, we present a novel solution for authenticated data redaction based on a new Redactable Signature Scheme with Implicit Accountability ($\mathsf {RSS}$RSS-$\mathsf {IA}$IA). In the event of a dispute, not only the original data signer but also the redactor can generate an evidence tag to unequivocally identify the party who produced the data/signature pair. Without the evidence tag, the redaction operation is transparent. Furthermore, the redactor can independently prove the trustworthiness of the redacted data, without any interaction with the original data signer. Our design is built on a new approach which adds accountability to any transparent redactable signature schemes. We show that the proposed design satisfies all the security goals with affordable cost. As an extension, we show how to realize accountable, transparent and authenticated data redaction in the multi-redactor setting. Jinhua Ma, Xinyi Huang 0001, Yi Mu 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Redactable Blockchain in Decentralized SettingabstractImmutability has been widely accepted as a fundamental property protecting the security of blockchain technology. However, this property impedes the development of blockchain because of the abuse of blockchain storage and legal obligations. To mitigate this issue, a novel construction of blockchain, calledredactable blockchain, was introduced. It enables a central authority to issue the rewriting privilege to a particular party who can rewrite a registered object, e.g., a block or a transaction, in a controlled way. Unfortunately, the central authority must be fully trusted and is an obvious target suffering from various attacks. In this paper, we introduce a redactable blockchain controlled at a fine-grained level in a decentralized setting. In our solution, the rewriting privilege is issued by multiple authorities for reducing the vulnerability of the centralized setting. To formalize our solution, we introduce a novel cryptographic notion, calleddecentralized policy-based chameleon hash(DPCH), with the formal definition and security model. By applying several simple cryptographic tools, such as chameleon hash, digital signature, and multi-authority attribute-based encryption, we present the generic construction of DPCH along with rigorous security proofs. By applying RSA-based chameleon hash and BLS short signature, we give a practical instantiation of DPCH with performance evaluation. The comprehensive evaluation shows that our solution has superior performance than the state-of-the-art solution. Jinhua Ma, Shengmin Xu, Jianting Ning, Xinyi Huang 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | Revocable Policy-Based Chameleon Hash
Shengmin Xu, Jianting Ning, Jinhua Ma, Guowen Xu, Jiaming Yuan, Robert H. Deng |
ESORICS (1) | 3 |
| 2021 | Ring Trapdoor Redactable Signatures from Lattice
Shao-Jun Yang, Xinyi Huang 0001, Mingmei Zheng, Jinhua Ma |
ISPEC | 4 |
| 2021 | Expressive Bilateral Access Control for Internet-of-Things in Cloud-Fog ComputingabstractAs a versatile system architecture, cloud-fog Internet-of-Things~(IoT) enables multiple resource-constrained devices to communicate and collaborate with each other. By outsourcing local data and immigrating expensive workloads to cloud service providers and fog nodes (FNs), resource-constrained devices can enjoy data services with low latency and minimal cost. To protect data security and privacy in the untrusted cloud-fog environment, many cryptographic mechanisms have been invented. Unfortunately, most of them are impractical when directly applied to cloud-fog IoT computing, mainly due to the large number of resource-constrained end-devices (EDs). In this paper, we present a secure cloud-fog IoT data sharing system with bilateral access control based on a new cryptographic tool called lightweight matchmaking encryption. Our system enforces both sender access control and receiver access control simultaneously and adapts to resource-constrained EDs by outsourcing costly workloads to FNs. We conduct extensive experiments to demonstrate the superior performance of our system to the most relevant solutions in the literature. Shengmin Xu, Jianting Ning, Jinhua Ma, Xinyi Huang 0001, HweeHwa Pang, Robert H. Deng |
SACMAT | 3 |
| 2021 | Authenticated Medical Documents Releasing with Privacy Protection and Release ControlabstractIn the context of Information Societies, a tremendous amount of information is daily exchanged or released. Among various information-release cases, medical document release has gained significant attention for its potential in improving healthcare service quality and efficacy. However, integrity and origin authentication of released medical documents is the priority in subsequent applications. Moreover, sensitive nature of much of this information also gives rise to a serious privacy threat when medical documents are uncontrollably made available to untrusted third parties. Redactable signatures allow any party to delete pieces of an authenticated document while guaranteeing the origin and integrity authentication of the resulting (released) subdocument. Nevertheless, most of existing redactable signature schemes (RSSs) are vulnerable to dishonest redactors or illegal redaction detection. To address the above issues, we propose two distinct RSSs with flexible release control (RSSs-FRC). We also analyse the performance of our constructions in terms of security, efficiency and functionality. The analysis results show that the performance of our construction has significant advantages over others, from the aspects of security and efficiency. Jianghua Liu 0001, Jinhua Ma, Yang Xiang 0001, Wanlei Zhou 0001, Xinyi Huang 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | K-Time Modifiable and Epoch-Based Redactable BlockchainabstractAs an immutable append-only distributed ledger, blockchain allows a group of participants to reach a consensus in an untrustworthy ecosystem. Immutability is a blockchain feature that persists data forever, but it is no longer legal in reality. Blockchain has unchangeable improper contents that violate laws. Moreover, data regulation toward “the right to be forgotten” requires blockchain must be modifiable. To address this problem, redactable blockchain has been introduced to relax immutability in a controlled way. However, once a participant is authorized, she/he can rewrite any content and no penalty for the malicious behavior that hinders the wide deployment of redactable blockchain in practice. In this paper, we introduce a new notion, dubbed k-time modifiable and epoch-based redactable blockchain (KERB) with a monetary penalty to control rewriting privileges and penalize malicious behaviors. Our solution is built up from simple building blocks: digital signatures and chameleon hashes. We give a formal definition and security models of KERB, and present a generic construction along with formal proofs. The extensive comparison and experimental analysis illustrate that our solution enjoys superior functionalities and performances than the state-of-the-art solutions. Shengmin Xu, Jianting Ning, Jinhua Ma, Xinyi Huang 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2018 | Dissemination of Authenticated Tree-Structured Data with Privacy Protection and Fine-Grained Control in Outsourced Databases
Jianghua Liu 0001, Jinhua Ma, Wanlei Zhou 0001, Yang Xiang 0001, Xinyi Huang 0001 |
ESORICS (2) | 2 |
| 2017 | An Efficient and Secure Design of Redactable Signature Scheme with Redaction Condition Control
Jinhua Ma, Jianghua Liu 0001, Wei Wu 0001 |
GPC | 1 |
| 2017 | Protecting Mobile Health Records in Cloud Computing: A Secure, Efficient, and Anonymous DesignabstractElectronic healthcare (eHealth) systems have replaced traditional paper-based medical systems due to attractive features such as universal accessibility, high accuracy, and low cost. As a major constituent part of eHealth systems, mobile healthcare (mHealth) applies Mobile Internet Devices (MIDs) and Embedded Devices (EDs), such as tablets, smartphones, and other devices embedded in the bodies of individuals, to improve the quality of life and provide more convenient healthcare services for patients. Unfortunately, MIDs and EDs have only limited computational capacity, storage space, and power supply. By taking this into account, we present a new design to guarantee the integrity of eHealth records and the anonymity of the data owner in a more efficient and flexible way. The essence of our design is a general method which can convert any secure Attribute-Based Signature (ABS) scheme into a highly efficient and secure Online/Offline Attribute-Based Signature (OOABS) scheme. We prove the security and analyze the efficiency improvement of the new design. Additionally, we illustrate the proposed generic construction by applying it to a specific ABS scheme. Jianghua Liu 0001, Jinhua Ma, Wei Wu 0001, Xiaofeng Chen 0001, Xinyi Huang 0001, Li Xu 0002 |
ACM Trans. Embed. Comput. Syst. | 2 |