Haifeng Li 0009

dblp:17/246-9 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2023
0000-0002-4475-8310ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2023 An efficient and revocable attribute-based data sharing scheme with rich expression and escrow freedom
Caihui Lan, Caifen Wang, Haifeng Li 0009
Inf. Sci.4
2021 PSCPAC: Post-quantum secure certificateless public auditing scheme in cloud storage
Haifeng Li 0009, Yuxin Wang 0001, Xingbing Fu, Caihui Lan, Caifen Wang, Fagen Li, He Guo 0001
J. Inf. Secur. Appl.1
2021 Comments on "Attribute-Based Data Sharing Scheme Revisited in Cloud Computing"
abstract
In this letter, we discuss the security weakness of Wanget al.’s attribute-based data sharing scheme, in IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY (TIFS) (DOI: 10.1109/TIFS.2016.2549004). Through designing two concrete attacks, we identify two serious security flaws in their scheme. 1) First, we show that their scheme is insecure because in their scheme any authenticated user can freely tamper with the weight of his own attribute to gain higher level decryption privilege to arbitrarily decrypt the ciphertext belonging to another user with higher weight of attribute. 2) Second, we further demonstrate that their scheme is trivial insecure because in their scheme even any malicious authenticated user’s attribute does not match the access policy of a ciphertext, he/she still has the power to decrypt the ciphertext, i.e., the decryption power is independent of attributes, thus, their scheme is not a rigorous attribute-based scheme. The two weaknesses discovered may hinder their scheme infeasible for practical deployment. Accordingly, we present a remedy solution to the issues while preserving all the security features of the original scheme. We hope that our cryptoanalysis and remedy scheme may contribute to avoiding similar design flaws in future designs.
Caihui Lan, Caifen Wang, Haifeng Li 0009
IEEE Trans. Inf. Forensics Secur.3
2021 Analysis of the Comments on "Identity-Based Distributed Provable Data Possession in Multicloud Storage"
abstract
In 2016, Peng et al. pointed out in the literature (IEEE Transactions on Services Computing, Vol. 9, No. 6, pp. 996-998, Nov./Dec. 2016) that Wang's identity-based provable data possessing scheme ID-DPDP(IEEE Transactions on Services Computing, vol. 8, no. 2, pp. 328-340, Mar./Apr. 2015) has security vulnerability, and Peng et al. offered the remedy solutions. Unfortunately, we demonstrate that Peng et al.'s method also has a security loophole that malicious cloud servers can produce valid proof information without original data. Accordingly, we provide a revised solution to the problem while preserving the security features of the ID-DPDP.
Caihui Lan, Haifeng Li 0009, Caifen Wang
IEEE Trans. Serv. Comput.2