Hui Cui 0001

dblp:17/3482-1 · DBLP profile ↗
← Back
50ranked-venue papers
29as first author
21since 2021 · last 2026
0000-0002-5820-2233ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 28 · 14 first-author · 13 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 5 first-author · 2 since 2021Systems, architecture and hardware · 5 · 3 first-author · 2 since 2021Computer networks · 5 · 3 first-author · 3 since 2021Databases, data management, data science and information retrieval · 4 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Theory of computation · 2 · 2 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 DKCIA-B: A dynamic keyword-based cloud data integrity auditing framework with backtracking support
Feng Wang 0020, Chenbin Zhao, Jiguo Li 0001, Hui Cui 0001
J. Netw. Comput. Appl.5
2026 $\mathsf {DisIMS}$DisIMS: A Distributed Identity Management System via Blockchain
abstract
The increasing incidents of data breaches and personal data misuse highlight the urgent need for robust identity management systems. Self-Sovereign Identity (SSI) emerges as the future solution for digital identity management, underpinned by anonymous credentials (AC) and the distributed ledger technology (DLT) for security measures. However, current SSI models only achieve partial decentralization and none of them can fully meet the complex security requirements of real-world applications. In this paper, we address these limitations by constructing a Decentralized Anonymous Credential (DAC) scheme inspired by large universe attribute-based cryptographic primitives. Building on this foundation, we design a distributed identity management system (DisIMS), a comprehensive SSI system built on blockchain, achieving attribute flexibility, anonymity, unlinkability, revocability and selective disclosure. Compared to earlier blockchain-based identity management systems, our DisIMS allows users to selectively link previous transactions to generate verifiable eligibility proofs for the current transaction without leaking their real identities. We also implement DisIMS on both permissioned (Hyperledger Fabric v2.5) and permissionless (Ethereum Sepolia testnet) blockchains. Experimental results show that batch verification outperforms single verification by reducing execution times by approximately 76% to 81% on Hyperledger Fabric and 50% to 71% on Ethereum, based on 200 tests with 10 to 50 credentials containing 50 attributes each, which demonstrates DisIMS practicality for real-world batch verification scenarios.
Zoey Ziyi Li, Hui Cui 0001, Alven C. Y. Leung, Dennis Y. W. Liu, Joseph K. Liu, Jiangshan Yu, Dragan Gasevic
IEEE Trans. Dependable Secur. Comput.2
2026 An Unbiased and Robust Privacy-Preserving Fingerprinting Scheme for Relational Databases
abstract
Sharing relational databases is essential in today’s data-driven world for fostering collaboration, enhancing efficiency, and enabling real-time data access. However, privacy and copyright issues arise when sharing privacy-sensitive or valuable data. Additionally, high utility is required in shared data to enable accurate data mining and analysis. Entry-level differentially private fingerprinting schemes (DPFS) could address these concerns. In a DPFS, data can be securely shared without leaking original values while still supporting accurate analysis. Moreover, detectable fingerprints can deter unauthorized redistribution. However, existing DPFSs often lack utility—due to format changes and entry-wise bias—or robustness, as fingerprints can be removed undetected. In this paper, we propose an unbiased and robust differential privacy-based fingerprinting scheme (DPFS), which ensures that the fingerprinted copy remains an unbiased estimate of the original data. By incorporating differential privacy noise, our scheme effectively mitigates alteration, collusion, and hybrid attacks. Our DPFS satisfies ϵ-entry-level differential privacy, enabling clients to conduct unbiased analysis. To improve robustness, we design group-based fingerprint detection, which estimates the mean of injected noise per group with error tolerance. We provide a theoretical robustness analysis and propose a method for achieving optimal robustness. Experiments on four real-world databases show that our scheme consistently detects fingerprints and improves accuracy by up to 20% on machine learning tasks compared to existing DPFSs.
Shujie Cui, Hui Cui 0001, Jiabao Qiu, Shuguang Yuan 0003, Xiaojie Zhu, Jing Yu 0007, Chi Chen 0001, Xun Yi
IEEE Trans. Inf. Forensics Secur.3
2025 Enhancing Privacy in Face Recognition With Dual-Path Feature Compression and Homomorphic Encryption
abstract
Face recognition offers seamless human-machine interaction and efficiency. However, its widespread adoption has heightened security and privacy concerns due to the risks associated with compromised biometric data, such as spoofing and unauthorized tracking. To mitigate these concerns, this paper introduces a novel privacy-preserving face recognition framework that integrates an enhanced dual-path feature compression approach with homomorphic encryption (HE) for secure and efficient authentication. We leverage the robust deep neural network model FaceNet to extract discriminative 512-dimensional feature vectors and propose two significantly improved complementary feature compression methods tailored specifically for encrypted biometric systems: (1) Partitioned Principal Component Analysis (P-PCA), which employs a novel segment-wise PCA transformation, preserving localized discriminative information and supporting revocable biometric templates; and (2) Segment-wise Locality-Sensitive Hashing (S-LSH), introducing segment-specific hashing optimized for efficient binary representation and privacy-preserving encrypted-domain computations. Both compressed real-valued and binary features are securely encrypted using HE, enabling direct encrypted-domain similarity computations without exposing sensitive biometric data. Extensive experiments demonstrate that our method achieves competitive authentication performance while maintaining computational efficiency and practical feasibility.
Wencheng Yang, Song Wang 0003, Di Wu 0050, Xu Yang 0002, Hui Cui 0001, Michael N. Johnstone, Yan Li 0002
IJCB6
2025 SEARCHAIN: Searchable Encryption As Rewarded-Useful-Work on Blockchain
Jiangshan Yu, Xingliang Yuan, Joseph K. Liu, Cong Zuo 0001, Hui Cui 0001
ProvSec6
2025 Asteroid X: A Decentralized Finance Platform for Mining Sectors
abstract
The mining sector faces persistent funding challenges due to high risk, low liquidity, and limited transparency. Traditional financing methods are costly, slow, and inaccessible for small or early-stage ventures. This paper presents a platform Asteroid X, a blockchain-based Decentralized Finance (DeFi) platform tailored to these challenges. Asteroid X has an architecture that combines semi-centralized governance model to ensure rigorous projects on boarding and legal compliance – with fully on chain settlement mechanisms to facilitate transparent, secure, and efficient capital flows. Built on the ERC-1155 multi-token standard, Asteroid X tokenizes real-world mining rights and supports fractional ownership through a modular smart contract framework. Its layered architecture includes an API gateway, decentralized marketplace, and oracle integration to bridge off-chain geological data. Asteroid X is validated through test deployments on HashKey Chain and Ethereum Sepolia. Comparative analysis against traditional exchanges, such as the Australian Securities Exchange (ASX), highlights significant gains in cost efficiency, transaction speed, and investor inclusivity. The results substantiate the applicability and transformative potential of blockchain-driven DeFi frameworks within capital-intensive industries such as mining, offering enhanced security, transparency, and inclusivity.
Hui Cui 0001, Joseph K. Liu
TrustCom3
2025 FM-DPDP: Fine-grained Multicopy Dynamic Provable Data Possession with flexible storage
Caiyuan Tang, Feng Wang 0020, Chenbin Zhao, Hui Cui 0001, Zuobin Ying, Ching-Chun Chang, Chin-Chen Chang 0001
J. Inf. Secur. Appl.4
2024 SecuPath: A Secure and Privacy-Preserving Multiparty Path Planning Framework in UAV Applications
Joseph K. Liu, Xingliang Yuan, Shifeng Sun 0001, Hui Cui 0001
ACISP (3)5
2024 BDEC: Enhancing Learning Credibility via Post-quantum Digital Credentials
Zoey Ziyi Li, Hui Cui 0001
ProvSec (2)3
2024 Secure Internet of Things in Cloud Computing via Puncturable Attribute-Based Encryption With User Revocation
abstract
With significant achievements of Internet of Things (IoT) in cloud services, IoT devices are becoming primary targets of cyber attackers. To protect security of previous messages generated by IoT devices in cloud computing, puncturable attribute-based encryption (PABE) was introduced which achieves fine-grained access control and supports self-update to private keys to disable the decryption capability to existing ciphertexts. Users in PABE are identified by their attributes and authenticated via the attribute authority (AA) which issues them attribute keys. But PABE does not consider any attribute revocation which should be managed by the AA. To address such a concern, this article presents a primitive called PABE with user revocation (PAER) which is the first light-weight PABE scheme with the user revocation achieved by the AA broadcasting the information for the key update. In addition to the light calculation of users in the decrypting process, another prominent advantage in PAER is that the AA does not need to communicate with users to revoke their attributes but broadcasts regular updates in the network. We present a concrete construction of PAER, and then implement the given scheme to evaluate its practicability in the real world.
Hui Cui 0001, Xun Yi
IEEE Internet Things J.1
2024 Pay-Per-Proof: Decentralized Outsourced Multi-User PoR for Cloud Storage Payment Using Blockchain
abstract
Cloud computing has been widely applied in data storage, but cloud computing is not armed with an efficient integrity check mechanism for users to learn whether their large volumes of data have been kept intact by the cloud. The concept of proofs of retrievability (PoR) was introduced to address such an issue by enabling users to check the integrity of their data stored by the cloud. But PoR requires users to regularly send queries to the cloud, and its integrity check method cannot be extended to share the verification responsibility in the multi-user setting where different users store the same data to the cloud. With such concerns in mind, we put forth a notion called outsourced multi-user proofs of retrievability ($\mathtt {OMTPoR}$) which allows users with the same data stored by the cloud to share the information for the integrity check, and a third party is required to regularly check data integrity on behalf of users using the shared information. We give a concrete construction of$\mathtt {OMTPoR}$based on the homomorphic property of an existing property and analyze its security. To enforce honest integrity checks, we build the concrete$\mathtt {OMTPoR}$construction over the blockchain using smart contracts to guarantee the honesty of participants, yielding a decentralized outsourced multi-user PoR solution that utilizes the blockchain miners as the third parties. Furthermore, our solution enables the cloud server to obtain payment for the storage service if the PoR is verified by the miners. We fully implement the$\mathtt {OMTPoR}$scheme over the blockchain to evaluate its performance, which demonstrates obvious superiority over traditional PoR schemes without the detection of data duplication.
Hui Cui 0001, Zhiguo Wan, Tianyu Zhaolu, Huaqun Wang, Atsuko Miyaji
IEEE Trans. Cloud Comput.1
2024 Outsourced Privately Verifiable Proofs of Retrievability via Blockchain
abstract
Outsourced Proofs of Retrievability (OPoR) with private verification enables a third party verifier to periodically check cloud data on behalf of users. However, such a scheme requires the verifier to keep a copy of the user's data and generate tags for the data like the data owner. In other words, in addition to storing the data and tags from the user, the cloud server also needs to store tags uploaded by the verifier. To overcome this limitation, we propose a concrete construction of outsourced privately verifiable PoR (OPVPoR) without requiring the additional tag storage from the verifier. Furthermore, we extend the OPVPoR scheme to the multi-user setting and build a MOPVPoR scheme, where users storing the same data to the cloud server also share the tag information to further reduce the storage cost. Finally, we implement both schemes to evaluate their performance in practice.
Hui Cui 0001, Zhiguo Wan, Rui Gao 0007, Huaqun Wang
IEEE Trans. Dependable Secur. Comput.1
2023 Revocable Policy-Based Chameleon Hash for Blockchain Rewriting
abstract
Abstract Policy-based chameleon hash is a useful primitive for blockchain rewriting systems. It allows a user to create a mutable transaction associated with an access policy, whereas a modifier who possesses sufficient rewriting privileges from a trusted authority satisfying the access policy can rewrite the mutable transaction. However, it lacks a revocation mechanism. The modifiers can always rewrite the mutable transactions even if their given rewriting privileges are compromised. In this work, we introduce revocable policy-based chameleon. The property of revocation allows some modifiers’ rewriting privileges to be revoked, regardless of whether their rewriting privileges are compromised or not.
Yangguang Tian, Atsuko Miyaji, Koki Matsubara, Hui Cui 0001, Nan Li 0007
Comput. J.4
2023 Secure and Efficient Smart Healthcare System Based on Federated Learning
abstract
The rapid development of smart healthcare system in the Internet of Things (IoT) has made the early detection of many chronic diseases more convenient, quick, and economical. However, when healthcare organizations collect users’ health data through deployed IoT devices, there are issues of compromising users’ privacy. In view of this situation, this paper introduces federated learning technology to solve the problem of data security. In this paper, we consider the two main problems of federated learning applications in IoT smart healthcare system: (1) how to reduce the time overhead of system running and (2) how to authenticate that the user device uploading data is deployed by the system itself. To solve the above problems, we propose the first federated learning scheme based on full dynamic secret sharing. First, we use a two‐mask protocol to keep the user’s local model parameters confidential during federated learning. Then, based on homogeneous linear recursive equation, homomorphic hash function, and elliptic curve cryptosystem, the full dynamic secret sharing and user identity authentication are realized. In addition, our scheme allows users to join or quit during training. Finally, we have carried out simulation test on this scheme. The experimental results show that the efficiency of our scheme is improved by about 60% on average in the case of no user dropping and by about 30% in the case of some users dropping.
Wei Liu 0149, Yinghui Zhang 0002, Jin Cao 0001, Hui Cui 0001, Dong Zheng 0001
Int. J. Intell. Syst.5
2023 Password-authenticated proofs of retrievability for multiple devices checking cloud data
Hui Cui 0001, Zhiguo Wan, Huayi Qi, Baodong Qin, Xun Yi
J. Inf. Secur. Appl.1
2023 Multi-Keyword Searchable and Verifiable Attribute-Based Encryption Over Cloud Data
abstract
In cloud data sharing systems, Searchable Encryption (SE) schemes ensure data confidentiality with retrieving, but it faces several issues in practice. First, most of the previous Ciphertext-Policy Attribute-Based Keyword Search (CP-ABKS) systems enable users to initiate search requests with a single keyword, which results in many inaccurate results to be returned, thereby wasting computing and bandwidth resources. Second, untrusted cloud servers may return a small portion of incomplete search results to compress communication overhead. Besides, most CP-ABKS schemes only support an unshared multi-owner setting, which incurs a large amount of computational and storage overhead. Furthermore, when the keyword space is a polynomial, most of the previous schemes suffer from offline keyword guessing attacks. To address these issues, we focus on a multi-keyword search scheme which supports the verification of search results without losing efficiency by combining Ciphertext Policy Attribute-Based Encryption (CP-ABE) technology under the shared multi-owner mechanism. We show the security of our scheme, which achieves selective security against offline keyword guessing attacks and guarantees the unforgeability of signatures. The comparison of experimental results illustrates that our scheme is effective and enjoys superior functionalities than the most relevant solutions.
Yinghui Zhang 0002, Rui Guo 0005, Shengmin Xu, Hui Cui 0001, Jin Cao 0001
IEEE Trans. Cloud Comput.5
2023 HIBEChain: A Hierarchical Identity-Based Blockchain System for Large-Scale IoT
abstract
Internet-of-Things enables interconnection of billions of devices, which perform autonomous operations and collect various types of data. These things, along with their generated huge amount of data, need to be handled efficiently and securely. Centralized solutions are not desired due to security concerns and scalability issue. In this article, we propose HIBEChain, a hierarchical blockchain system that realizes scalable and accountable management of IoT devices and data. HIBEChain consists of multiple permissioned blockchains that form a hierarchical tree structure. To support the hierarchical structure of HIBEChain, we design a decentralized hierarchical identity-based signature (DHIBS) scheme, which enables IoT devices to use their identities as public keys. Consequently, HIBEChain achieves high scalability through parallel processing as blockchain sharding schemes, and it also implements accountability by use of identity-based keys. Identity-based keys not only make HIBEChain more user-friendly, they also allow private key recovery by validators when necessary. We provide detailed analysis of its security and performance, and implement HIBEChain based on Ethereum source code. Experiment results show that a 6-ary, (7,10)-threshold, 4-level HIBEChain can achieve 32,000 TPS, and it needs only 9 seconds to confirm a transaction.
Zhiguo Wan, Wei Liu 0149, Hui Cui 0001
IEEE Trans. Dependable Secur. Comput.3
2023 Vehicloak: A Blockchain-Enabled Privacy-Preserving Payment Scheme for Location-Based Vehicular Services
abstract
The Internet of Vehicles (IoV) technology enables vehicles to communicate with each other, with pedestrians and with roadside infrastructures, to realize more efficient, safer and more environmentally friendly transportation. IoV also promises rich location-based services for vehicles, such as parking and toll highway. However, preserving privacy for location-based service payments emerges as a critical and challenging problem in IoV. Existing schemes rely on centralized banks for payment processing, resulting in location privacy leakage to centralized entities. In this paper, we propose a decentralized privacy-preserving payment scheme named Vehicloak for IoV based on the blockchain technology. The biggest challenge is to provide location privacy for vehicles while guaranteeing correct service payments using the transparent blockchain. To tackle this challenge, we introduce a new cryptographic technique called zk-GSigproof that integrates zero-knowledge proof with group signature. Vehicloak implements this technique in a smart contract to process payment, which verifies zero-knowledge proof and group signature without leaking location information. It is not limited to IoV and can be applied in many payment scenarios. To evaluate the performance of our scheme, we implement Vehicloak on a private blockchain of 100 nodes on Aliyun, and conduct a test with up to 4,000 transactions. The experimental results prove the feasibility of Vehicloak.
Zhiguo Wan, Hui Cui 0001, Xiuzhen Cheng, Falko Dressler
IEEE Trans. Mob. Comput.3
2021 Forward-Secure Revocable Identity-Based Encryption
Baodong Qin, Dong Zheng 0001, Hui Cui 0001, Yiyuan Luo
ICICS (2)4
2021 Improved Security Model for Public-Key Authenticated Encryption with Keyword Search
Baodong Qin, Hui Cui 0001, Dong Zheng 0001
ProvSec2
2021 Two-Factor Decryption: A Better Way to Protect Data Security and Privacy
abstract
Abstract Biometric information is unique to a human, so it would be desirable to use the biometric characteristic as the private key in a cryptographic system to protect data security and privacy. In this paper, we introduce a notion called two-factor decryption (TFD). Informally speaking, a TFD scheme is a variant of the public-key encryption (PKE) scheme. In a TFD scheme, messages are encrypted under public keys as that in a standard PKE scheme, but both private keys (i.e. the first factor) and biometric inputs (i.e. the second factor) are required to decrypt the ciphertexts and obtain the underlying plaintexts. We first describe a framework of TFD, and then define a formal security model for TFD. Thereafter, we present a generic construction on TFD based on the cryptographic primitives of linear sketch and functional encryption (FE) with certain properties and analyse its security. In addition, we give instantiations of TFD by applying concrete FE schemes into the generic construction and show their applications.
Hui Cui 0001, Russell Paulet, Surya Nepal, Xun Yi, Butrus Mbimbi
Comput. J.1
2020 Server-aided revocable attribute-based encryption for cloud computing services
abstract
Summary Attribute‐based encryption (ABE) has been regarded as a promising solution in cloud computing services to enable scalable access control without compromising the security. Despite of the advantages, efficient user revocation has been a challenge in ABE. One suggestion for user revocation is using the binary tree in the key generation phase of an ABE scheme, which enables a trusted key generation center to periodically distribute the key update information to all nonrevoked users over a public channel. This revocation approach reduces the size of key updates from linear to logarithmic in the number of users. But it requires each user to keep a private key of the logarithmic size, and asks each nonrevoked user to periodically update his/her decryption key for each new time period. To further optimize user revocation in ABE, a server‐aided revocable ABE (SR‐ABE) scheme has been proposed, in which almost all workloads of users incurred by the user revocation are outsourced to an untrusted server, and each user only needs to store a private key of the constant size. In addition, SR‐ABE does not require any secure channel for the key transmission, and a user only needs to perform a small amount of calculations to decrypt a ciphertext. In this paper, we revisit the notion of SR‐ABE, and present a generic construction of SR‐ABE, which can transform a revocable ABE (RABE) scheme to an SR‐ABE scheme. In addition, we give an instantiation of SR‐ABE by applying the generic construction on a concrete RABE scheme, and implement an instantiation of SR‐ABE and an RABE scheme to evaluate the performance of SR‐ABE.
Hui Cui 0001, Tsz Hon Yuen, Robert H. Deng, Guilin Wang
Concurr. Comput. Pract. Exp.1
2020 Key regeneration-free ciphertext-policy attribute-based encryption and its application
Hui Cui 0001, Robert H. Deng, Baodong Qin, Jian Weng 0001
Inf. Sci.1
2020 Robust digital signature revisited
Hui Cui 0001, Baodong Qin, Willy Susilo, Surya Nepal
Theor. Comput. Sci.1
2020 Pay as You Decrypt: Decryption Outsourcing for Functional Encryption Using Blockchain
abstract
The concept of functional encryption (FE) has been introduced to address the shortcomings of public-key encryption (PKE) in many emerging applications which require both data storage and data sharing (e.g., cloud storage service). One of the major issues existing in most FE schemes is the efficiency, as they are built from bilinear pairings of which the computation is very expensive. A widely accepted solution to this problem is outsourcing the heavy workloads to a powerful third party and leaving the user with the light computation. Nevertheless, it is impractical to assume that the third party (e.g., the cloud) will provide free services. To our knowledge, no attention has been paid to the payment procedure between the user and the third party in an FE with outsourced decryption (FEOD) scheme under the assumption that neither of them should be trusted. Leveraging the transactions on cryptocurrencies supported by the blockchain technology, in this paper, we aim to design FE with payable outsourced decryption (FEPOD) schemes. The payment in an FEPOD scheme is achieved through a blockchain-based cryptocurrency, which enables the user to pay a third party when it correctly completes the outsourced decryption. We define the adversarial model for FEPOD schemes, and then present a generic construction of FEPOD schemes. Also, we evaluate the performance of the proposed generic construction by implementing a concrete FEPOD scheme over a blockchain platform.
Hui Cui 0001, Zhiguo Wan, Xinlei Wei, Surya Nepal, Xun Yi
IEEE Trans. Inf. Forensics Secur.1
2019 A new privacy-preserving authentication protocol for anonymous web browsing
abstract
Summary Anonymous authentication technique receives wide attention in recent years since it can protect users' privacy. Anonymous web browsing refers to utilization of the World Wide Web that hides a user's personally identifiable information from the websites visited. Even if a user can hide the IP address and other physical information with anonymity programs such as Tor, the web server can always monitor the user on the basis of the identity. In this paper, we firstly give an overview and cryptanalysis on the protocol of Yang et al and point out the security weaknesses of their protocol. Then, we propose a new authentication protocol for anonymous web browsing. In the proposed protocol, we take the advantages of a pseudo identity mechanism and an identity‐based elliptic curve cryptography algorithm to achieve user anonymity, robust security, and high efficiency. The result of security analysis and performance evaluation indicate the feasibility and practicality of our proposed anonymous authentication protocol.
Xu Yang 0002, Xun Yi, Ibrahim Khalil 0001, Hui Cui 0001, Xuechao Yang, Surya Nepal, Xinyi Huang 0001, Yali Zeng
Concurr. Comput. Pract. Exp.4
2019 (Dual) server-aided revocable attribute-based encryption with decryption key exposure resistance
Baodong Qin, Qinglan Zhao, Dong Zheng 0001, Hui Cui 0001
Inf. Sci.4
2019 DABKE: Secure deniable attribute-based key exchange framework
abstract
We introduce the first deniable attribute-based key exchange (DABKE) framework that is resilient to impersonation attacks. We define the formal security models for DABKE framework, and propose a generic compiler that converts any attribute-based key exchanges into deniable ones. We prove that it can achieve session key security and user privacy in the standard model, and strong deniability in the simulation-based paradigm. In particular, the proposed generic compiler ensures: 1) a dishonest user cannot impersonate other user’s session participation in conversations since implicit authentication is used among authorized users; 2) an authorized user can plausibly deny his/her participation after secure conversations with others; 3) the strongest form of deniability is achieved using one-round communication between two authorized users.
Yangguang Tian, Yingjiu Li, Guomin Yang, Willy Susilo, Yi Mu 0001, Hui Cui 0001, Yinghui Zhang 0002
J. Comput. Secur.6
2019 Attribute-Based Storage Supporting Secure Deduplication of Encrypted Data in Cloud
abstract
Attribute-based encryption (ABE) has been widely used in cloud computing where a data provider outsources his/her encrypted data to a cloud service provider, and can share the data with users possessing specific credentials (or attributes). However, the standard ABE system does not support secure deduplication, which is crucial for eliminating duplicate copies of identical data in order to save storage space and network bandwidth. In this paper, we present an attribute-based storage system with secure deduplication in a hybrid cloud setting, where a private cloud is responsible for duplicate detection and a public cloud manages the storage. Compared with the prior data deduplication systems, our system has two advantages. First, it can be used to confidentially share data with users by specifying access policies rather than sharing decryption keys. Second, it achieves the standard notion of semantic security for data confidentiality while existing systems only achieve it by defining a weaker security notion. In addition, we put forth a methodology to modify a ciphertext over one access policy into ciphertexts of the same plaintext but under other access policies without revealing the underlying plaintext.
Hui Cui 0001, Robert H. Deng, Yingjiu Li
IEEE Trans. Big Data1
2019 An Attribute-Based Framework for Secure Communications in Vehicular Ad Hoc Networks
abstract
In this paper, we introduce an attribute-based framework to achieve secure communications in vehicular ad hoc networks (VANETs), which enjoys several advantageous features. The proposed framework employs attribute-based signature (ABS) to achieve message authentication and integrity and protect vehicle privacy, which greatly mitigates the overhead caused by pseudonym/private key change or update in the existing solutions for VANETs based on symmetric key, asymmetric key, and identity-based cryptography and group signature. In addition, we extend a standard ABS scheme with traceability and revocation mechanisms and seamlessly integrate them into the proposed framework to support vehicle traceability and revocation by a trusted authority, and thus, the resulting scheme for vehicular communications does not suffer from the anonymity misuse issue, which has been a challenge for anonymous credential-based vehicular protocols. Finally, we implement the proposed ABS scheme using a rapid prototyping tool called Charm to evaluate its performance.
Hui Cui 0001, Robert H. Deng, Guilin Wang
IEEE/ACM Trans. Netw.1
2018 An efficient and expressive ciphertext-policy attribute-based encryption scheme with partially hidden access structures, revisited
Hui Cui 0001, Robert H. Deng, Junzuo Lai, Xun Yi, Surya Nepal
Comput. Networks1
2018 Attribute-based cloud storage with secure provenance over encrypted data
Hui Cui 0001, Robert H. Deng, Yingjiu Li
Future Gener. Comput. Syst.1
2018 Efficient and Expressive Keyword Search Over Encrypted Data in Cloud
abstract
Searchable encryption allows a cloud server to conduct keyword search over encrypted data on behalf of the data users without learning the underlying plaintexts. However, most existing searchable encryption schemes only support single or conjunctive keyword search, while a few other schemes that are able to perform expressive keyword search are computationally inefficient since they are built from bilinear pairings over the composite-order groups. In this paper, we propose an expressive public-key searchable encryption scheme in the prime-order groups, which allows keyword search policies (i.e., predicates, access structures) to be expressed in conjunctive, disjunctive or any monotonic Boolean formulas and achieves significant performance improvement over existing schemes. We formally define its security, and prove that it is selectively secure in the standard model. Also, we implement the proposed scheme using a rapid prototyping tool called Charm [37], and conduct several experiments to evaluate it performance. The results demonstrate that our scheme is much more efficient than the ones built over the composite-order groups.
Hui Cui 0001, Zhiguo Wan, Robert H. Deng, Guilin Wang, Yingjiu Li
IEEE Trans. Dependable Secur. Comput.1
2018 Server-Aided Attribute-Based Signature With Revocation for Resource-Constrained Industrial-Internet-of-Things Devices
abstract
The industrial Internet-of-things (IIoT) can be seen as the usage of Internet-of-things technologies in industries, which provides a way to improve the operational efficiency. An attribute-based signature (ABS) has been a very useful technique for services requiring anonymous authentication in practice, where a signer can sign a message over a set of attributes without disclosing any information about his/her identity, and a signature only attests to the fact that it is created by a signer with several attributes satisfying some claim predicate. However, an ABS scheme requires exponentiation and/or pairing operations in the signature generation and verification algorithms, and hence, it is quite expensive for resource-constrained devices like a sensor in the IIoT network to run an ABS scheme. To reduce the computational overheads for both signers and verifiers, it has been suggested to introduce a server to help with signature generation and verification, but existing results on the ABS with “server-aided computation” either suffer from the security issues or are not sufficiently efficient. In this paper, we consider server-aided ABS one step further, and propose a notion called server-aided ABS with revocation (SA-ABSR), which not only securely mitigates the workloads of users in generating and verifying signatures, but also enables user revocation by having the server immediately stop signature generations for revoked signers. We formally define the security model for SA-ABSR, present a concrete construction of SA-ABSR based on a standard ABS scheme, and prove its security under the defined security model. Also, we implement the proposed SA-ABSR scheme and the underlying standard ABS scheme to evaluate the performance, from which it is easy to see that the proposed SA-ABSR scheme is more efficient than its underlying ABS scheme.
Hui Cui 0001, Robert H. Deng, Joseph K. Liu, Xun Yi, Yingjiu Li
IEEE Trans. Ind. Informatics1
2017 Attribute-Based Encryption with Expressive and Authorized Keyword Search
Hui Cui 0001, Robert H. Deng, Joseph K. Liu, Yingjiu Li
ACISP (1)1
2017 Server-Aided Revocable Attribute-Based Encryption Resilient to Decryption Key Exposure
Baodong Qin, Qinglan Zhao, Dong Zheng 0001, Hui Cui 0001
CANS4
2017 A Practical Authentication Protocol for Anonymous Web Browsing
Xu Yang 0002, Xun Yi, Hui Cui 0001, Xuechao Yang, Surya Nepal, Xinyi Huang 0001, Yali Zeng
ISPEC3
2017 Fuzzy Public-Key Encryption Based on Biometric Data
Hui Cui 0001, Man Ho Au, Baodong Qin, Robert H. Deng, Xun Yi
ProvSec1
2016 Server-Aided Revocable Attribute-Based Encryption
Hui Cui 0001, Robert H. Deng, Yingjiu Li, Baodong Qin
ESORICS (2)1
2016 An Efficient and Expressive Ciphertext-Policy Attribute-Based Encryption Scheme with Partially Hidden Access Structures
Hui Cui 0001, Robert H. Deng, Junzuo Lai
ProvSec1
2016 Attribute-Based Encryption with Granular Revocation
Hui Cui 0001, Robert H. Deng, Xuhua Ding, Yingjiu Li
SecureComm1
2016 Revocable and Decentralized Attribute-Based Encryption
abstract
In this paper, we propose a revocable and decentralized attribute-based encryption (ABE) system that splits the task of decryption key generation across multiple attribute authorities (AAs) without requiring any central party such that it achieves attribute revocation by simply stopping updating of the corresponding private key. In our system, a party can easily behave as an AA by creating a public and private key pair without any global communication except the creation for the common system parameters, under which it can periodically issue/update private key components for users that reflect their attributes, and an AA can freely leave the system once its corresponding attribute is revoked without communication with other AAs. In addition, to revoke a user, those AAs that have issued private keys to this user easily cease the key updating process for the user without affecting other AAs' execution. For the construction of our system, the technical barrier is to make private keys collusion resistant. Since in our system each component of a user's private key at a time period may come from different AAs and there is no coordination between these AAs, traditional technique of binding together different components (issued by different AAs) of a private key by randomization cannot be employed. To overcome this, we tie the key components together and prevent collusion attacks between different users by embedding distinct identifiers and a commonly shared time attribute in these components.
Hui Cui 0001, Robert H. Deng
Comput. J.1
2016 Escrow free attribute-based signature with self-revealability
Hui Cui 0001, Guilin Wang, Robert H. Deng, Baodong Qin
Inf. Sci.1
2016 Relations between robustness and RKA security under public-key encryption
Hui Cui 0001, Yi Mu 0001, Man Ho Au
Theor. Comput. Sci.1
2015 Proof of retrievability with public verifiability resilient against related-key attacks
abstract
Modern technologies such as cloud computing, grid computing and software as a service all require data to be stored by the third parties. A specific problem encountered in this context is to convince a verifier that a user's data are kept intact at the storage servers. An important approach to achieve this goal is called proof of retrievability, by which a storage server can assure a verifier via a concise proof that a user's file is available. However, for most publicly verifiable systems, existing proof of retrievability solutions do not take physical attacks into consideration, where an adversary can observe the outcome of the computation with methods like fault injection techniques. In fact, the authors find that giving the adversary the ability to obtain the information about the relations between the private keys, those systems are not secure anymore. Motivated by the need of preventing this kind of attacks, they present the security model for related‐key attacks in publicly verifiable proofs of retrievability, where the adversary can subsequently observe the outcome of the publicly verifiable proof of retrievability under the modified key. After pointing out a linear related‐key attack on an existing proof of retrievability system with public verifiability, they present a secure and efficient proof of retrievability with public verifiability, against related‐key attacks.
Hui Cui 0001, Yi Mu 0001, Man Ho Au
IET Inf. Secur.1
2014 Complete Robustness in Identity-Based Encryption
Hui Cui 0001, Yi Mu 0001, Man Ho Au
ProvSec1
2014 Public-Key Encryption Resilient against Linear Related-Key Attacks Revisited
abstract
Wee (PKC'12) proposed a generic public-key encryption scheme in the setting of related-key attacks. Bellare, Paterson and Thomson (Asiacrypt'12) provided a framework enabling related-key attack (RKA) secure cryptographic primitives for a class of non-linear related-key derivation functions. However, in both of their constructions, the instantiations to achieve the full (not weak) RKA security are given under the scenario regarding the private key composed of single element. In other words, each element of the private key shares the same modification. However, this is impractical in real world. In this paper, we concentrate on the security of public-key encryption schemes under linear related-key attacks in the setting of multielement private keys (that is, the private key is composed of more than one element), where an adversary is allowed to tamper any part of this private key stored in a hardware device, and subsequently observes the outcome of a public key encryption system under this targeted modified private key. We define the security model for RKA secure public-key encryption schemes as chosen-cipher text and related-key attack (CC-RKA) security, which means that a public-key encryption scheme remains secure even when an adversary is allowed to issue the decryption oracle on linear shifts of any component of the private key. After that, we present a detailed public key encryption schemes with the private key formed of several elements, of which the CC-RKA security is under the decisional BDH assumption in the standard model.
Hui Cui 0001, Yi Mu 0001, Man Ho Au
TrustCom1
2014 Signcryption Secure Against Linear Related-Key Attacks
abstract
A related-key attack (RKA) occurs when an adversary tampers the private key stored in a cryptographic hardware device, and observes the result of the cryptographic primitive under this modified private key. In this paper, we consider the security of signcryption schemes under linear RKAs, where an adversary is allowed to tamper the private keys of the receiver and the sender, and subsequently observe the outcome of a signcryption system under these modified private keys of both parties. We define two security notions for RKA-secure signcryption schemes: chosen ciphertext RKA and chosen message RKA. We require that a signcryption scheme remains secure even when an adversary is allowed to access the designcryption oracle and the signcryption oracle on linear shifts of the private keys of the receiver and the sender, respectively. After reviewing some basic definitions related to our construction, we give a specific signcryption scheme from bilinear Diffie-Hellman which is secure against RKAs. Furthermore, we extend the security model of signcryption with anonymity, where the ciphertext is anonymous to others except the real receiver given the honest sender and the honest receiver. Fortunately, with a trivial modification to the original signcryption scheme, our proposed signcryption scheme can protect the privacy of both the sender and the receiver.
Hui Cui 0001, Yi Mu 0001, Man Ho Au
Comput. J.1
2013 Anonymous Signcryption against Linear Related-Key Attacks
Hui Cui 0001, Yi Mu 0001, Man Ho Au
ProvSec1
2013 Public-Key Encryption Resilient to Linear Related-Key Attacks
Hui Cui 0001, Yi Mu 0001, Man Ho Au
SecureComm1