Peng Zeng 0002

dblp:18/6295-2 · DBLP profile ↗
← Back
18ranked-venue papers
2as first author
7since 2021 · last 2025
0000-0002-3904-9245ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 1 first-author · 4 since 2021Security and privacy · 5 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Systems, architecture and hardware · 2 · 1 first-authorTheory of computation · 1
YearPublicationVenuePosition
2025 Bilateral Privacy-Aware Proxy Re-Encryption With Traceability and Revocation for IoMT
abstract
Internet of Medical Things (IoMT) serves as a pivotal cornerstone for intelligent healthcare services by extending communication networks into medical settings. Within smart hospitals, IoMT facilitates the interconnectedness among essential healthcare elements, including individuals, equipment, and objects, thereby enabling the intelligent application of medical data irrespective of temporal or spatial constraints. IoMT is distinguished by its stringent data privacy and security requisites stemming from the sensitive nature of protected health information (PHI), dynamic healthcare environments, and time-critical medical interventions. It emphasizes the paramount importance of preserving patient confidentiality through partially hidden access policies, enabling time-sensitive authority delegation in emergency scenarios, and maintaining audit trails for regulated medical workflows. To address this varied challenge, this work introduces a novel framework, PTR-CP-ABPRE, designed to effectively navigate the complexities of this evolving digital ecosystem. PTR-CP-ABPRE is featured by its bilateral and distributed access control which involves partially hidden access policy, thereby hiding sensitive attribute values contained in the access control policies. This feature serves to balance the dual objectives of access transparency and information confidentiality required for PHI. In addition, PTR-CP-ABPRE fulfills white-box traceability and revocation mechanisms, critical for maintaining chain-of-custody and enabling immediate privilege revocation. Finally, PTR-CP-ABPRE is designed for anti-collusion attacks, particularly crucial in healthcare ecosystems where multiple entities require differentiated access levels to share PHI.
Jiaying Luo, Peng Zeng 0002, Xingwang Wang 0002
IEEE Internet Things J.2
2024 CoinFA: an efficient coin mixing scheme with flexible amounts
abstract
Abstract Coin mixing is an efficient anonymization technology of cryptocurrency used to eliminate the linkability of transaction parties by hiding their addresses in an anonymous set. However, a common weakness with most existing coin mixing schemes is that the amount of mixed coins must be the same for all requests within a mixing cycle, otherwise it is easy for an attacker to restore the linkability of transaction parties. In this paper, we design a stage-payable puzzle solution mechanism, named CoinFA, which reverses the control of the requesting amounts to the users for flexible mixing amounts. In our design, the payee (with an output address) first requests a puzzle from the mixers and the latter are the only ones who know the solution of the puzzle. If the payee solves the puzzle successfully, he can be rewarded with the corresponding Bitcoins. The payer (allowed to have multiple input addresses) then requests the solution by paying in installments. We achieve better security by weakening the rights of the involved third parties, while the hierarchical structure allows our solution to have better efficiency and robustness. We perform a security analysis on CoinFA based on the standard Rivest-Shamir-Adleman (RSA) assumption and Elliptic Curve Digital Signature Algorithm unforgeability. We also analyze the performance of CoinFA by comparing it with two related schemes, and the results show that our CoinFA scheme has a greater advantage when the mixing amount is relatively small.
Peng Zeng 0002, Kim-Kwang Raymond Choo, Chengju Li, Yanzhao Yang
Comput. J.2
2023 Security Analysis of a User Authentication Scheme for IoT-Based Healthcare
abstract
Very recently, Masud et al. (2022) proposed a lightweight and anonymity-preserving user authentication scheme to establish secure communication between the doctor, the gateway, and sensor nodes in IoT-based healthcare, aiming to ensure the privacy of the patients’ physiological data. In this article, however, we carefully revisit their scheme and first point out that the scheme is not practically implementable in its current form, and second we show that it is vulnerable to session key disclosure attacks, off-line password guessing attacks, and traceability attacks, under the assumption that the attacker can gain access to the sensor nodes and the doctor’s device. We also propose fixes for each of these issues or vulnerabilities.
Shengbao Wang, Kang Wen, Bosen Weng, Peng Zeng 0002
IEEE Internet Things J.5
2023 A Certificateless Provable Data Possession Scheme for Cloud-Based EHRs
abstract
Electronic health records (EHRs: digital collections of patient health status and diagnosis) are generally shared, analyzed and stored on cloud servers. One operational challenge is to ensure that EHRs are stored correctly, for example using provable data possession (PDP). Seeking to contribute to the literature, we propose a certificateless PDP scheme for cloud-based EHRs. In our scheme, we distribute multiple copies of EHRs on different cloud servers to allow for corrupted EHRs to be recoverable from other intact copies. The scheme is also designed to resist copy-summation attack which assures that cloud servers are storing EHRs honestly. In our approach, EHRs are stored in ciphertext form so that only authorized users can decrypt and gain access to the information. We also design a new data structure – map version marker table (MVMT) – for block-level dynamic operations and data traceability. Specifically, MVMT allows an authorized doctor to access historical EHRs to inform their diagnosis and decision-making. The security and performance analyses show that our scheme is secure (assuming the intractability of the computational Diffie-Hellman problem) and is practical to support cloud-based EHR applications.
Jiayan Shen, Peng Zeng 0002, Kim-Kwang Raymond Choo, Chengju Li
IEEE Trans. Inf. Forensics Secur.2
2022 A New Code-Based Blind Signature Scheme
abstract
Abstract Blind signature is an important cryptographic primitive with widespread applications in secure e-commerce, for example to guarantee participants’ anonymity. Existing blind signature schemes are mostly based on number-theoretic hard problems, which have been shown to be solvable with quantum computers. The National Institute of Standards and Technology (NIST) began in 2017 to specify a new standard for digital signatures by selecting one or more additional signature algorithms, designed to be secure against attacks carried out using quantum computers. However, none of the third-round candidate algorithms are code-based, despite the potential of code-based signature algorithms in resisting quantum computing attacks. In this paper, we construct a new code-based blind signature (CBBS) scheme as an alternative to traditional number-theoretic based schemes. Specifically, we first extend Santoso and Yamaguchi’s three pass identification scheme to a concatenated version (abbreviated as the CSY scheme). Then, we construct our CBBS scheme from the CSY scheme. The security of our CBBS scheme relies on hardness of the syndrome decoding problem in coding theory, which has been shown to be NP-complete and secure against quantum attacks. Unlike Blazy et al.’s CBBS scheme which is based on a zero-knowledge protocol with cheating probability $2/3$, our CBBS scheme is based on a zero-knowledge protocol with cheating probability $1/2$. The lower cheating probability would reduce the interaction rounds under the same security level and thus leads to a higher efficiency. For example, to achieve security level $2^{-82}$, the signature size in our CBBS scheme is $1.63$ MB compared to $3.1$ MB in Blazy et al.’s scheme.
Peng Zeng 0002, Kim-Kwang Raymond Choo
Comput. J.2
2022 Multicopy and Multiserver Provable Data Possession for Cloud-Based IoT
abstract
Provable data possession (PDP) is widely considered to be an efficient method in verifying the integrity of remote data. While earlier PDP schemes are generally designed to check the integrity of data copies on a single cloud server (CS), there have been attempts to design multicopy and multiserver PDP (MCMS-PDP) schemes in recent years. However, it is known that MCMS-PDP schemes may be vulnerable to copy-summation attacks or do not support dynamic operations. The former enables a (dishonest) CS to only store a summation of copies for successful verification, while the latter does not allow the data owner to update the stored data. In this article, we propose a new MCMS-PDP scheme based on homomorphic verifiable tags. Specifically, our proposed scheme is designed to check the integrity of all copies in one challenge–response and resist copy-summation attacks. The scheme also supports public verification and block-level dynamic operations, such as modification, insertion, and deletion using the divide-and-conquer table. We then prove the security of our scheme, assuming the intractability of the computational Diffie–Hellman problem, in the random oracle model. We also evaluate the performance of the scheme to demonstrate its efficiency.
Jiayan Shen, Peng Zeng 0002, Kim-Kwang Raymond Choo
IEEE Internet Things J.2
2021 Efficient Policy-Hiding and Large Universe Attribute-Based Encryption With Public Traceability for Internet of Medical Things
abstract
Modern day medical systems are closely integrated and interconnected with other systems, such as those comprising Internet-of-Medical Things (IoMT) devices that facilitate remote healthcare services, say during pandemics (e.g., COVID-19). Attribute-based encryption (ABE) is a promising cryptographic primitive to support fine-grained access control in the ciphertext environment; in other words, ABE can potentially be used to ensure data confidentiality and user privacy in the IoMT ecosystem. In this article, we propose an efficient partially-policy-hidden and large universe ABE scheme with public traceability to construct a practical IoMT system (hereafter referred to as PTIoMT). The system is designed to achieve the following features: 1) the access policy is partially hidden: only nonsensitive attribute labels/names are displayed, while sensitive attribute values are hidden in the encrypted electronic health records (EHRs); 2) the number of the attributes is independent of the public parameters and, thus, can be arbitrarily large; 3) any user who discloses the decryption key can be efficiently tracked; and 4) fewer bilinear pairing operations are required during the decryption process. The security analysis and performance evaluation demonstrate the security and efficiency of PTIoMT.
Peng Zeng 0002, Zhiting Zhang, Rongxing Lu, Kim-Kwang Raymond Choo
IEEE Internet Things J.1
2020 Large-Universe Attribute-Based Encryption With Public Traceability for Cloud Storage
abstract
Attribute-based encryption (ABE) can be utilized to achieve both data security and fine-grained access control in a cloud computing environment. However, we need to consider the risks of key abuse and key escrow in such a setting. Specifically, the former risk category includes the illegal sharing of user's keys (i.e., user key abuse) and illegal key distribution by an authority (i.e., authority key abuse), and the latter includes the scenario where some ciphertext is decrypted by the authority without the user's approval. Hence, in this article, we seek to address both key abuse and key escrow concerns when deploying ABE in a cloud computing environment. In our construction, two authorities [i.e., a key generation center (KGC) and an attribute authority (AA)] participate in the generation of the user's secret key. Both KGC and AA will not know the full decryption key or have the capability to forge one. As a result, neither KGC nor AA can illegally distribute the user's private key to unauthorized users or decrypt user's ciphertexts without the user's approval. In addition, in our scheme, any private keys modified by malicious users cannot be successfully used for decryption. In the event that some user illegally shares his/her original private key, the scheme has in place a mechanism to trace the abused private key (since the user's identity information is embedded in the private key). Hence, our scheme supports public traceability, key abuse, and key escrow. In addition, our scheme is based on prime order bilinear groups, and is shown to be selectively secure in the standard model.
Zhiting Zhang, Peng Zeng 0002, Bofeng Pan, Kim-Kwang Raymond Choo
IEEE Internet Things J.2
2020 MMDA: Multidimensional and multidirectional data aggregation for edge computing-enhanced IoT
Peng Zeng 0002, Bofeng Pan, Kim-Kwang Raymond Choo
J. Syst. Archit.1
2019 Constructions of Linear Codes With One-Dimensional Hull
abstract
The hull of a linear code is defined to be the intersection of the code and its dual, and was originally introduced to classify finite projective planes. The hull plays an important role in determining the complexity of algorithms for checking permutation equivalence of two linear codes and computing the automorphism group of a linear code. It has been shown that these algorithms are very effective in general if the size of the hull is small. The objective of this paper is to present some sufficient and necessary conditions that linear codes and cyclic codes have one-dimensional hull. It is shown that there are no such binary or ternary cyclic codes. Based on these characterizations, some constructions of linear codes with one-dimensional hull were given by employing quadratic number fields, partial difference sets, and difference sets. We also construct cyclic codes with one-dimensional hull. Some optimal codes with one-dimensional hull are obtained.
Chengju Li, Peng Zeng 0002
IEEE Trans. Inf. Theory2
2018 Efficient Ring Signature and Group Signature Schemes Based on q-ary Identification Protocols
abstract
While designing ring signature and group signature is a relatively mature area, few published schemes are both efficient and quantum attack-resilience. In this paper, we present two new signature schemes based on coding theory. First, we present two new zero-knowledge (ZK) identification protocols based on the construction of (Cayrel, P.L., Véron, P. and Alaoui, S.M.E.Y. (2010) A Zero-Knowledge Identification Scheme Based on the q-ary Syndrome Decoding Problem. Proceedings of SAC 2010, Waterloo, Ontario, Canada, August 12–13, pp. 171–186. Springer, Berlin) in order to improve efficiency of code-based digital signature schemes. We then transform the newly proposed ZK protocols into a ring signature scheme and a group signature scheme. Our schemes enjoy a significant improvement in efficiency since reducing the cheating probability decreases the interaction rounds. Specially, with the security level of 2−87, the sizes of public key and signature are 14.5 KB and 52 KB in our ring signature scheme, while the corresponding sizes are 400 KB and 2384 KB in the scheme of (Cayrel, P. L., Alaoui, S. M. E. Y., Hoffmann, G. and Véron, P. (2012) An improved threshold ring signature scheme based on error correcting codes. Proceedings of WAIFI 2012, Bochum, Germany, July 16–19, pp. 45–63. Springer, Berlin). At the security level of 2−80, the sizes of public key and signature are 32 KB and 113.8 KB in our group signature scheme, as compared with 2.5 MB and 20 MB in the scheme of (Alamélou, Q., Blazy, O., Cauchie, S. and Gaborit, P. (2017) A codebased group signature scheme. Des. Codes Cryptogr., 82, 469–493) and 642 KB and 114 KB in the scheme of (Ezerman, M.F., Lee, H.T., Ling, S., Nguyen, K. and Wang, H. (2015) A provably secure group signature scheme from code-based assumptions. Proc. ASIACRYPT 2015, Auckland, New Zealand, November 29–December 3, pp. 260–285. Springer, Berlin).
Peng Zeng 0002, Kim-Kwang Raymond Choo, Xiaolei Dong
Comput. J.2
2018 FGDA: Fine-grained data analysis in privacy-preserving smart grid communications
Shanshan Ge, Peng Zeng 0002, Rongxing Lu, Kim-Kwang Raymond Choo
Peer-to-Peer Netw. Appl.2
2017 An Efficient Data Aggregation Scheme in Privacy-Preserving Smart Grid Communications with a High Practicability
Bofeng Pan, Peng Zeng 0002, Kim-Kwang Raymond Choo
CISIS2
2017 An Efficient Code-Based Threshold Ring Signature Scheme with a Leader-Participant Model
abstract
Digital signature schemes with additional properties have broad applications, such as in protecting the identity of signers allowing a signer to anonymously sign a message in a group of signers (also known as a ring). While these number-theoretic problems are still secure at the time of this research, the situation could change with advances in quantum computing. There is a pressing need to design PKC schemes that are secure against quantum attacks. In this paper, we propose a novel code-based threshold ring signature scheme with a leader-participant model. A leader is appointed, who chooses some shared parameters for other signers to participate in the signing process. This leader-participant model enhances the performance because every participant including the leader could execute the decoding algorithm (as a part of signing process) upon receiving the shared parameters from the leader. The time complexity of our scheme is close to Courtois et al.’s (2001) scheme. The latter is often used as a basis to construct other types of code-based signature schemes. Moreover, as a threshold ring signature scheme, our scheme is as efficient as the normal code-based ring signature.
Guomin Zhou, Peng Zeng 0002, Xiaohui Yuan 0001, Kim-Kwang Raymond Choo
Secur. Commun. Networks2
2017 Erratum to "An Efficient Code-Based Threshold Ring Signature Scheme with a Leader-Participant Model"
Guomin Zhou, Peng Zeng 0002, Xiaohui Yuan 0001, Kim-Kwang Raymond Choo
Secur. Commun. Networks2
2016 A Provably Secure Blind Signature Based on Coding Theory
abstract
Blind signature can be deployed to preserve user anonymity and is widely used in digital cash and e-voting. As an interactive protocol, blind signature schemes require high efficiency. In this paper, we propose a code-based blind signature scheme with high efficiency as it can produce a valid signature without many loops unlike existing code-based signature schemes. We then prove the security of our scheme in the random oracle model and analyze the efficiency of our scheme. Since a code-based signature scheme is post-quantum cryptography, therefore, the scheme is also able to resist quantum attacks.
Peng Zeng 0002, Kim-Kwang Raymond Choo
ICPADS2
2015 Optimal codes as Tanner codes with cyclic component codes
Tom Høholdt, Fernando Piñero, Peng Zeng 0002
Des. Codes Cryptogr.3
2014 MDMR-IBE: efficient multiple domain multi-receiver identity-based encryption
abstract
ABSTRACT In The International Conference on Practice and Theory in Public‐Key Cryptography (PKC)'05, Baek et al. proposed the first multi‐receiver identity‐based encryption scheme. Their scheme is highly efficient in that it only needs one pairing computation to encrypt a single message for n receivers. However, the application scenario considered by Baek et al. is merely the ideal “single domain environment,” where all the n receivers are from the same administrative domain. When used in the real‐world application scenario where the n receivers are from l different administrative domains (i.e., a multiple domain environment), their scheme becomes inefficient as it requires l pairing computations for one message. In this paper, we present an efficient multiple domain multi‐receiver identity‐based encryption scheme that only requires “one” pairing computation to encrypt a single message for n receivers from l different administrative domains. We prove the security of the new scheme under the modified decisional bilinear Diffie–Hellman assumption in the random oracle model. In addition, the new scheme can be extended to be adaptive chosen ciphertext secure under the gap modified bilinear Diffie–Hellman assumption. Copyright © 2013 John Wiley & Sons, Ltd.
Peng Zeng 0002, Kim-Kwang Raymond Choo
Secur. Commun. Networks2