VLDB 2026 Research / reviewers in the wild / expert
Qi Li 0011
dblp:181/2688-11
· DBLP profile ↗
41ranked-venue papers
9as first author
24since 2021 · last 2026
0000-0002-7280-7378ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 13 · 4 first-author · 7 since 2021Security and privacy · 12 · 3 first-author · 5 since 2021Systems, architecture and hardware · 4 · 3 since 2021Software engineering, systems software and programming languages · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CodeSpeak: Improving smart contract vulnerability detection via LLM-assisted code analysis
Shuyu Chang, Haiping Huang, Rui Wang 0043, Qi Li 0011 |
J. Syst. Softw. | 5 |
| 2026 | A Controllable, Publicly Auditable, and Redactable Blockchain With a Main-Auxiliary ArchitectureabstractRedactable blockchains are challenging the core principle of traditional blockchains: immutability. One such example is the chameleon hash-based blockchain. Despite rapid academic advances, most solutions have not yet simultaneously considered four key aspects: the degree of modification privileges, the transparency of the modification process, the consistency in the post-redaction global state, and system security after redaction. In this paper, we present a controllable, publicly auditable, and redactable blockchain with a main-auxiliary architecture. Specifically, we integrate weighted secret sharing, digital signature, and non-interactive zero-knowledge proof technologies to propose a verifiable and controllable chameleon hash primitive. To encourage logical nodes, it includes a reputation evaluation mechanism and a DAO-based governance model. Additionally, we construct a redactable bi-directionally anchored main-auxiliary blockchain structure, where the auxiliary chain exclusively maintains the modification proofs associated with each block of main chain. Any node can audit the modification history or, in the event of an accusation, self-prove. This structure also simplifies global state updates for newly joined or restarted nodes. Finally, we provide comprehensive security proofs for our construction, conduct extensive experiments to evaluate its functionality and performance, and compare it with analogous solutions to demonstrate its superiority. Lingyan Xue, Haiping Huang, Fu Xiao 0001, Qi Li 0011, Wenming Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | STORChain: A Clustered-MPT-Based Blockchain for Data Service and Efficient Storage in HealthcareabstractThe adoption of blockchain technology in healthcare has significantly enhanced data integrity, transparency, and user privacy. However, high storage overhead and resource-intensive operations remain major challenges to its widespread deployment, particularly in large-scale or resource-constrained healthcare environments. To address these challenges, we propose STORChain, a storage-optimized blockchain framework designed for data services in healthcare. The framework introduces the Clustered Merkle Patricia Tree (C-MPT), a novel logical structure that aggregates similar transaction types to maximize storage efficiency while ensuring Proof of Inclusion (PoI). A Selective Transaction Pruning Strategy (STPS) is employed to prioritize and prune essential historical data, improving data access efficiency. Additionally, an incentive-based Delegated Proof-of-Stake (DPoS) consensus algorithm is utilized, integrating a probabilistic election mechanism to promote fairness and node inclusivity. Comprehensive theoretical analysis and practical experiment results indicate that STORChain significantly reduces storage overhead, optimizes data access, and outperforms existing schemes. Hancheng Gao, Mohammad S. Obaidat, Haiping Huang, Yizheng Xing, Fu Xiao 0001, Qi Li 0011 |
IEEE Trans. Serv. Comput. | 6 |
| 2026 | A Blockchain-Assisted Revocable and Efficient ABSE Scheme for Secure Medical Data SharingabstractEfficient and privacy-preserving medical data sharing remains a key challenge in the era of digital healthcare. Existing schemes often suffer from limited access control, substantial computational overhead, and reliance on trusted third parties. This article proposes a revocable Attribute-Based Searchable Encryption (ABSE) scheme built upon a hierarchical blockchain architecture, which enables a secure keyword search over encrypted data via expressive attribute-based access policies, and a revocation mechanism is integrated to support dynamic user management. We design a lightweight and privacy-preserving computation framework that offloads expensive cryptographic operations to the cloud, thereby reducing the burden on user-side devices. Furthermore, we propose a lightweight consensus protocol, termed lottery consensus, which replaces traditional proof-of-work hash computations with meaningful operations that are tied to the ABSE-based data-sharing process. Extensive theoretical analysis and simulation experiments demonstrate the superior efficiency of the proposed scheme, and formal security proofs demonstrate its robustness against threats. Hancheng Gao, Wu Xiaoyu, Haiping Huang, Qi Li 0011, Yizheng Xing |
ACM Trans. Web | 4 |
| 2025 | DIPE: a diagnosis-assisted inquiry point extractor towards medical dialogues
Qi Li 0011, Faliang Huang, Jie Zhao 0011 |
Appl. Intell. | 1 |
| 2025 | GeoFed: Geometry-Aware Byzantine Robust Federated Learning on SPD Manifolds in Heterogeneous EnvironmentsabstractFederated learning (FL) has been increasingly applied in the Internet of Things (IoT), leveraging its decentralized nature to facilitate collaboration among clients and enable resource-constrained clients to jointly train a globally optimal model based on consensus. However, it is difficult to confirm data authenticity and participant integrity due to the unobservability of local training procedures and the inaccessibility of local training data. As a result, FL is highly susceptible to Byzantine attacks, including data poisoning and model poisoning, which can manipulate the training process and degrade model performance. Moreover, IoT data is often highly heterogeneous and high-dimensional, rendering most existing Byzantine-robust FL approaches ineffective in practical scenarios. To address this challenge, we propose GeoFed, which iteratively filters out malicious clients based on the geodesic distance between clients. This geodesic distance is measured on the Riemannian manifold spanned by the covariance of local gradient update. To further mitigate the impact of data heterogeneity, GeoFed assigns a weight factor to each client after removing Byzantine attackers, optimizing the accuracy and flexibility of global model aggregation according to the quality of client data. We conduct extensive experimental evaluations of GeoFed under various Byzantine attack scenarios and highly heterogeneous data environments. To validate the efficacy of GeoFed, we provide a theoretical analysis of its convergence properties. The results demonstrate that GeoFed outperforms state-of-the-art Byzantine-robust FL approaches in heterogeneous IoT settings. Especially, under different Byzantine attacks, the accuracy of detecting malicious clients on the heterogeneous MNIST dataset approaches 100%. Qi Li 0011, Zhenzhen Wu, Jinbo Xiong, Anxiao Song, Tao Zhang 0029 |
IEEE Internet Things J. | 1 |
| 2025 | A Privacy-Enhanced Traceable Anonymous Transaction Scheme for BlockchainabstractBlockchain transaction privacy is a highly researched topic across various application scenarios. Current privacy-preserving schemes in blockchain employ advanced cryptographic techniques, such as homomorphic encryption and zero-knowledge proofs, to balance transaction privacy with regulatory requirements. However, these schemes encounter challenges, including computational inefficiency, data expansion, and overlooked metadata privacy, such as timestamp protection. In this paper, we first propose a privacy-enhanced traceable anonymous transaction scheme based on data transaction scenarios. This scheme integrates ring signature and Merkle hash tree techniques, effectively shortening the signature size and optimizing the verification process compared to existing combinations of ring signatures and zero-knowledge proofs. A novel verifiable timestamp privacy protection method is introduced, which obfuscates timestamps to prevent tampering without compromising integrity. To enhance scalability, this method extends to multiple transaction processing scenarios and implements a timestamp-sharing strategy to reduce the computational burden. It also allows tracking authorities to monitor the long-term addresses of both transaction parties if necessary. Rigorous security analysis and extensive experimental evaluations demonstrate that this scheme achieves superior privacy, traceability, and scalability compared to existing approaches. Lingyan Xue, Haiping Huang, Fu Xiao 0001, Qi Li 0011, Zhiwei Wang 0003 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | FedADDP: Privacy-Preserving Personalized Federated Learning with Adaptive Dimensional Differential Privacy
Tao Zhang 0029, Xutong Mu, Haoshuo Li, Xuewen Dong, Qi Li 0011 |
ICA3PP (5) | 6 |
| 2024 | Modeling Sentiment-Speaker-Dependency for Emotion Recognition in ConversationabstractEmotion Recognition in Conversations (ERC) plays a crucial role in the development of human-machine interaction. Conversations are a multi-party, multi-emotion, and multi-turn process of information propagation. However, existing works, which focus on designing models and algorithms for better learning representations of dialogue context and speakers, but rarely care about the key element of the strong correlation and inseparable interdependence of emotional states on the sentiment polarity in the process. To address this issue, we propose a novel model, named S2D-ERC (Sentiment-Speaker-Dependency for Emotion Recognition in Conversation), for ERC task. The proposed model constructs a conversation as a directed acyclic graph and represents both speaker- and sentiment- dependencies between utterances with heterogeneous edges. Additionally, to capture the information interaction dynamics in conversation context, we employ a cross-attention mechanism where latent representations of speaker and sentiment are learned with two different directions of information flow. The experimental results on two benchmarks, compared with state-of-the-art models, demonstrate the superiority and effectiveness of our model. Faliang Huang, Qi Li 0011, Yihua Ye |
IJCNN | 3 |
| 2024 | Decentralized Access Control for Privacy-Preserving Cloud-Based Personal Health Record With Verifiable Policy UpdateabstractWith the advancement of cloud computing technology, cloud-based personal health record (CB-PHR) has become an increasingly popular way for modern patients to flexibly manage and share their health records with doctors. However, the confidentiality of CB-PHR privacy is vulnerable to threats due to unauthorized users and untrusted cloud service provider (CSP). Additionally, patients and doctors may be constrained by changes in access permissions and limited device resources. To address these challenges, we propose an efficient decentralized privacy-preserving attribute-based access control scheme with verifiable policy update (DPVPU) for CB-PHR systems. DPVPU supports large attribute universe and safeguards the privacy of both the access policy and the doctor’s identity through partially hiding the access policy and employing a one-way anonymous key agreement technique. Unlike re-encrypting ciphertext, it can dynamically update policy by fully utilizing the previous policy and outsourcing the computation of ciphertext update to the CSP. Also, we design an efficient verification algorithm enabling patients to check the correctness of updated ciphertext. For devices with limited resources, we use online/offline and outsourced decryption techniques to reduce system costs. Finally, we provide formal security proofs and performance analysis to demonstrate the security and practicality of DPVPU. Haoyuan Fan, Qi Li 0011, Jinbo Xiong, Rui Li 0047, Wei Chen 0006, Haiping Huang |
IEEE Internet Things J. | 2 |
| 2024 | DScPA: A Dynamic Subcluster Privacy-Preserving Aggregation Scheme for Mobile Crowdsourcing in Industrial IoTabstractMobile crowdsourcing (MCS) is a promising new paradigm for intelligent data perception in large-scale sensor applications such as the Industrial Internet of Things (IIoT). This approach assigns industrial perception tasks to mobile devices for data collection and sharing, creating a bright outlook for building strong industrial systems and improving industrial services. However, the particular IIoT network environment is vulnerable to a range of malicious attacks, including the manipulation or deletion of data. Moreover, industry-aware nodes, which have limited energy resources, are susceptible to various failures that can result in distorted data and inaccurate trend analysis. To tackle the above issues, we propose a dynamic sub-cluster privacy-preserving aggregation (DScPA) scheme for the crowdsourced industrial virtual areas, by exploring the equilibrium between privacy security and data benefits for industrial users. Specifically, we propose joining and exiting the virtual area aggregation system protocol, and design low-cost privacy-preserving aggregation algorithm to achieve flexible and dynamic construction of virtual areas. Additionally, we propose a supervised mechanism-based subset aggregation protocol that takes into account the remaining energy of the nodes in the virtual areas aggregation system and their distance from the base station. We employ the relevant characteristics of polynomial functions and binary data to achieve data privacy protection and integrity verification at a lower computational cost. Furthermore, we develop an asymmetric information iterative static non-cooperative game model to verify the soundness of DScPA. Finally, security analysis demonstrates that the DScPA scheme meets the security objectives. Simulations show that implementing DScPA in the industrial virtual area can improve the network lifetime by about 16.7% compared to existing solutions, while also increasing the average remaining energy of industry-aware nodes. Tao Feng 0007, Jinbo Xiong, Qi Li 0011, Youliang Tian |
IEEE Internet Things J. | 4 |
| 2023 | Achieving Lightweight and Privacy-Preserving Object Detection for Connected Autonomous VehiclesabstractConnected autonomous vehicles (CAVs) are capable of capturing high-definition images from onboard sensors, which can be used to facilitate the detection of objects in the vicinity. Such images may, however, contain sensitive information (e.g., human faces and license plates) as well as the indirect location of CAVs. To protect the object privacy of images shared by CAVs, this article proposes a privacy-preserving object detection (P2OD) framework. Specifically, we propose multiple secure computing protocols designed to construct a privacy-preserving Faster$R$-convolutional neural network (CNN) model to securely extract features and bounding-boxes of objects in an image. By leveraging edge computing (with higher performance computation and lower latency, in comparison to cloud-based solutions), CAVs randomly split the captured images and upload them to two noncollusive edge servers. Both servers will then perform the P2OD framework cooperatively to directly detect objects over random image shares without exposing sensitive information. The theoretical analysis demonstrates the security, correctness, and efficiency of the P2OD framework, and the experimental findings show that the P2OD framework can effectively protect the classification and location privacy of image objects for CAVs. Compared with the original Faster R-CNN model, the classification and regression errors of the P2OD framework can be controlled within 10−12 and 10−14, respectively. Renwan Bi, Jinbo Xiong, Youliang Tian, Qi Li 0011, Kim-Kwang Raymond Choo |
IEEE Internet Things J. | 4 |
| 2023 | Blockchain-Enabled Fine-Grained Searchable Encryption With Cloud-Edge Computing for Electronic Health Records SharingabstractThe integration of Internet of Things (IoT) with cloud–edge computing in cyber–physical systems has revolutionized the way healthcare enterprises manage electronic health records (EHRs). With more healthcare enterprises outsourcing encrypted EHRs to the cloud, searchable encryption (SE) is utilized to retrieve encrypted data, especially attribute-based SE (ABSE) can achieve fine-grained access control. However, ABSE usually requires a lot of computation, which imposes a serious burden on resource-limited devices. Moreover, ensuring fairness in data access is crucial in the healthcare domain, where both data users and owners may have conflicting interests. In order to overcome these problems, this article proposes an SE scheme with fine-grained access control for cloud-based EHRs sharing assisted by blockchain. It transfers computing tasks to edge servers and enables users to control who has access to their EHRs. The adoption of blockchain and smart contracts guarantees data integrity and transaction fairness. Moreover, a consensus algorithm is designed for the higher efficiency of the proposed scheme. Finally, security analysis proves that the proposed scheme resists adaptive chosen keyword attacks (CKAs). Performance analysis further confirms that it has more functionalities and is efficient for smart healthcare. Hancheng Gao, Haiping Huang, Lingyan Xue, Fu Xiao 0001, Qi Li 0011 |
IEEE Internet Things J. | 5 |
| 2023 | Anomaly traffic detection in IoT security using graph neural networks
Mengnan Gao, Lifa Wu, Qi Li 0011, Wei Chen 0006 |
J. Inf. Secur. Appl. | 3 |
| 2022 | Blockchain-enabled Secure Distributed Data Aggregation and Verification Mechanism for IIoTabstractThe traditional Industrial Internet of Things (IIoT) is a centralized system that fully trusts and relies on a central cloud server to process and store the data collected by the equipments. As the number of devices increases, this centralized model not only faces severe network load issues and single point of failure crises, but also raises various security and privacy concerns. Fortunately, blockchain can provide decentral-ization, high trustworthiness and security. Therefore, to design a distributed IIoT system, a blockchain-based IIoT would be a reasonable choice. This paper combines the consortium chain and the homomorphic Paillier algorithm, and proposes a secure distributed data aggregation and verfication (SDAV) mechanism based on the consortium chain. This mechanism combines edge computing and blockchain technology to build a distributed data aggregation framework, which effectively supports the secure collection and storage of data, and avoids single point of failure and tampering crisis. Secondly, based on the (k, t)-threshold Paillier algorithm, a secure cryptographic verification mechanism is designed to protect the privacy and confidentiality of data on the blockchain. Finally, the analysis proves the security of the proposed mechanism and demonstrates the efficiency advantage through simulation experiments. Tao Feng 0007, Qi Li 0011, Jinbo Xiong |
GLOBECOM | 3 |
| 2022 | HyperMean: Effective Multidimensional Mean Estimation with Local Differential PrivacyabstractMultidimensional mean estimation with local differential privacy (LDP) extracts the numerical features from groups while protecting users’ personal information without relying on a trusted server. However, the increase of dimensionality would lead to a deficiency in the allocable privacy budget, resulting in excessive accuracy loss. To solve this problem, we propose HyperMean, an effective privacy-preserving mean estimation mechanism for multidimensional data whose accuracy is at least no worse (and better in most cases) than existing solutions. We first design a multidimensional staircase function to obfuscate users’ data, significantly reducing the output variance. Second, an adaptive dimensionality reduction is performed on users’ data to allocate the privacy budget to some focused dimensions. Finally, the server averages all users’ obfuscated outputs to obtain an unbiased estimate of the mean results. Theoretical analysis reveals that HyperMean effectively reduces the worst-case variance of multidimensional mean estimation under LDP while maintaining low computational complexity. Experiments on both simulated and real-world datasets show that HyperMean outperforms existing multidimensional mean estimation mechanisms in terms of aggregated error. Tao Zhang 0029, Lele Zheng, Ze Tong, Qi Li 0011 |
TrustCom | 5 |
| 2022 | Secure, Efficient, and Weighted Access Control for Cloud-Assisted Industrial IoTabstractIn the cloud-assisted Industrial Internet of Things (IIoT), ciphertext-policy attribute-based encryption (CP-ABE) could help the data owner (DO) share his sensitive data via the cloud under self-defined access structures. Among general CP-ABE schemes, the decryption overhead, the key generation cost, and the ciphertext length increase with the number of involved attributes. Additionally, only regular attributes are taking into consideration rather than weighted attributes. In this article, we proposed a secure, efficient, and weighted access control scheme (SEWAC) for cloud-assisted IIoT applications. SEWAC enables the DO to formulate any fine-grained access structure over weighted attributes without making it more complicated. Furthermore, such weighted attributes would not add the length of ciphertext. SEWAC also supports online/offline key generation to alleviate the computational cost of the authority from answering mass key requests in the online phase, while most computational tasks are executed in the offline phase. The heavy decryption overhead is offloaded to the cloud. To ensure the cloud to honestly execute the process of outsourced decryption, we design an efficient batch verification method, which allows the user to spend only three bilinear pairing operations in checking the correctness of batch results. We also give the formal security proof of the proposed scheme. Comprehensive comparisons and implementation results indicate that SEWAC can better achieve weighted access control, compressed ciphertext length, efficient key generation, and the assurance of the outsourced decryption result. Qi Li 0011, Haiping Huang, Wei Zhang 0122, Wei Chen 0006, Huaqun Wang |
IEEE Internet Things J. | 1 |
| 2022 | Differential privacy protection scheme based on community density aggregation and matrix perturbation
Haiping Huang, Xiong Tang, Fu Xiao 0001, Qi Li 0011 |
Inf. Sci. | 5 |
| 2022 | TRAC: Traceable and Revocable Access Control Scheme for mHealth in 5G-Enabled IIoTabstractMobile healthcare (mHealth) enables people to collect and share their personal health records (PHRs) and gain rapid medical treatment via mobile 5G-enabled Industrial Internet of Things (IIoT) devices, which also brings the challenge of keeping the PHRs confidentiality and preventing unauthorized access. By the emerging ciphertext-policy attribute-based encryption (CP-ABE), the PHR owner can encrypt his/her PHR data under self-defined access policies. However, existing CP-ABE schemes are suffering from either heavy computation cost and storage overhead or traitor tracing and direct revocation. In this article, we propose an efficient, traceable, and revocable access control scheme named TRAC for mHealth in 5G-enabled IIoT. In TRAC, the ciphertext is composed of the attribute-relevant ciphertext encrypted under anand-gate access structure and the identity-relevant ciphertext associated with some potential receivers. The malicious user who leaks his/her privilege to unauthorized entities will be precisely tracked and added in the revocation list, by which the cloud server can update the identity-relevant ciphertext by itself. The length of final ciphertext and the time of bilinear pairing operations used in decryption are constant. The security analysis and performance evaluation indicate the security, efficiency, and practicality of TRAC. Qi Li 0011, Bin Xia 0003, Haiping Huang, Yinghui Zhang 0002, Tao Zhang 0029 |
IEEE Trans. Ind. Informatics | 1 |
| 2022 | Edge-Cooperative Privacy-Preserving Object Detection Over Random Point Cloud Shares for Connected Autonomous VehiclesabstractConnected autonomous vehicles (CAVs) employ the point cloud data captured by LiDAR to enhance the capability of object recognition and detection. Edge computing with its inherent advantages can help CAVs alleviate resource constraints and enable faster situational awareness and data processing. However, the point cloud data contains private information, such as vehicle identity, location and trajectory, directly uploading the raw point cloud to the edge nodes or other vehicle will lead to serious privacy leakage. To the best of our knowledge, we are the first to try to tackle this challenge and propose a privacy-preserving object detection framework over random point cloud shares for CAVs (referred to SecPCV), aiming to guarantee the privacy of both point cloud and object detection results. In SecPCV, CAVs split point cloud into two random shares based on additive secret sharing (ASS) and upload them to two competing edge nodes, respectively, which greatly compress the computational load of CAVs. Without changing the object detection network in plaintext environment, the edge nodes can cooperatively and securely extract, regress, and classify over point cloud shares. Theoretical analysis ensure the efficiency and security of the SecPCV framework. Experimental results with the real KITTI point cloud dataset indicate that SecPCV can achieve the consistent object detection accuracy as that in plaintext environment, and provide a feasible solution for CAVs secure sharing of point cloud data. Renwan Bi, Jinbo Xiong, Youliang Tian, Qi Li 0011, Ximeng Liu |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2021 | Blockchain-assisted handover authentication for intelligent telehealth in multi-server edge computing environment
Wenming Wang 0001, Haiping Huang, Lingyan Xue, Qi Li 0011, Reza Malekian, Youzhi Zhang 0004 |
J. Syst. Archit. | 4 |
| 2021 | Computation-transferable authenticated key agreement protocol for smart healthcare
Wenming Wang 0001, Haiping Huang, Fu Xiao 0001, Qi Li 0011, Lingyan Xue, Jiansheng Jiang |
J. Syst. Archit. | 4 |
| 2021 | Towards Time-Sensitive and Verifiable Data Aggregation for Mobile CrowdsensingabstractMobile crowdsensing systems use the extraction of valuable information from the data aggregation results of large-scale IoT devices to provide users with personalized services. Mobile crowdsensing combined with edge computing can improve service response speed, security, and reliability. However, previous research on data aggregation paid little attention to data verifiability and time sensitivity. In addition, existing edge-assisted data aggregation schemes do not support access control of large-scale devices. In this study, we propose a time-sensitive and verifiable data aggregation scheme (TSVA-CP-ABE) supporting access control for edge-assisted mobile crowdsensing. Specifically, in our scheme, we use attribute-based encryption for access control, where edge nodes can help IoT devices to calculate keys. Moreover, IoT devices can verify outsourced computing, and edge nodes can verify and filter aggregated data. Finally, the security of the proposed scheme is theoretically proved. The experimental results illustrate that our scheme outperforms traditional ones in both effectiveness and scalability under time-sensitive constraints. Tao Zhang 0029, Xiongfei Song, Lele Zheng, Yani Han, Kai Zhang 0044, Qi Li 0011 |
Secur. Commun. Networks | 6 |
| 2021 | Provable Data Possession with Outsourced Data TransferabstractWith the rapid development of cloud computing, more and more enterprises would like to upload and store their data in the public cloud. When the parts of the business of an enterprise are purchased by another enterprise, the corresponding data will be transferred to the acquiring enterprise. For the usual case, how to outsource the computation cost of data transfer to the cloud? How to ensure the remote purchased data integrity? Thus, it is important to study provable data possession with outsourced data transfer (DT-PDP). In this paper, for the first time, we propose the novel concept: DT-PDP. By taking use of DT-PDP, the following three security requirements can be satisfied: (1) the other un-purchased data security of acquired enterprise can be ensured; (2) the purchased data integrity and privacy can be ensured; (3) the data transferability’s computation can be outsourced to the public cloud servers. For the security concept of DT-PDP, we give its motivation, system model and security model. Then, we design a concrete DT-PDP scheme based on the bilinear pairings. At last, we analyze the security, efficiency and flexibility of the concrete DT-PDP scheme. It shows that our scheme is provably secure and efficient. Huaqun Wang, Debiao He, Anmin Fu, Qi Li 0011, Qihua Wang |
IEEE Trans. Serv. Comput. | 4 |
| 2020 | An Improved Broadcast Authentication Protocol for Wireless Sensor Networks Based on the Self-Reinitializable Hash ChainsabstractBroadcast authentication is a fundamental security primitive in wireless sensor networks (WSNs), which is a critical sensing component of IoT. Although symmetric-key-based μ TESLA protocol has been proposed, some concerns about the difficulty of predicting the network lifecycle in advance and the security problems caused by an overlong long hash chain still remain. This paper presents a scalable broadcast authentication scheme named DH- μ TESLA, which is an extension and improvement of μ TESLA and Multilevel μ TESLA, to achieve several vital properties, such as infinite lifecycle of hash chains, security authentication, scalability, and strong tolerance of message loss. The proposal consists of the t,n -threshold-based self-reinitializable hash chain scheme (SRHC-TD) and the d -left-counting-Bloom-filter-based authentication scheme (AdlCBF). In comparison to other broadcast authentication protocols, our proposal achieves more security properties such as fresh node’s participation and DoS resistance. Furthermore, the reinitializable hash chain constructed in SRHC-TD is proved to be secure and has less computation and communication overhead compared with typical solutions, and efficient storage is realized based on AdlCBF, which can also defend against DoS attacks. Haiping Huang, Qinglong Huang, Fu Xiao 0001, Wenming Wang 0001, Qi Li 0011 |
Secur. Commun. Networks | 5 |
| 2020 | A Personalized Privacy Protection Framework for Mobile Crowdsensing in IIoTabstractWith the rapid digitalization of various industries, mobile crowdsensing (MCS), an intelligent data collection and processing paradigm of the industrial Internet of Things, has provided a promising opportunity to construct powerful industrial systems and provide industrial services. The existing unified privacy strategy for all sensing data results in excessive or insufficient protection and low quality of crowdsensing services (QoCS) in MCS. To tackle this issue, in this article we propose a personalized privacy protection (PERIO) framework based on game theory and data encryption. Initially, we design a personalized privacy measurement algorithm to calculate users' privacy level, which is then combined with game theory to construct a rational uploading strategy. Furthermore, we propose a privacy-preserving data aggregation scheme to ensure data confidentiality, integrity, and real-timeness. Theoretical analysis and ample simulations with real trajectory dataset indicate that the PERIO scheme is effective and makes a reasonable balance between retaining high QoCS and privacy. Jinbo Xiong, Lei Chen 0029, Youliang Tian, Qi Li 0011, Ximeng Liu |
IEEE Trans. Ind. Informatics | 5 |
| 2020 | Location Privacy-Preserving Method Based on Historical Proximity LocationabstractWith the rapid development of Internet services, mobile communications, and IoT applications, Location-Based Service (LBS) has become an indispensable part in our daily life in recent years. However, when users benefit from LBSs, the collection and analysis of users’ location data and trajectory information may jeopardize their privacy. To address this problem, a new privacy-preserving method based on historical proximity locations is proposed. The main idea of this approach is to substitute one existing historical adjacent location around the user for his/her current location and then submit the selected location to the LBS server. This method ensures that the user can obtain location-based services without submitting the real location information to the untrusted LBS server, which can improve the privacy-preserving level while reducing the calculation and communication overhead on the server side. Furthermore, our scheme can not only provide privacy preservation in snapshot queries but also protect trajectory privacy in continuous LBSs. Compared with other location privacy-preserving methods such as k -anonymity and dummy location, our scheme improves the quality of LBS and query efficiency while keeping a satisfactory privacy level. Xueying Guo, Wenming Wang 0001, Haiping Huang, Qi Li 0011, Reza Malekian |
Wirel. Commun. Mob. Comput. | 4 |
| 2020 | An Authentication Scheme Based on Novel Construction of Hash Chains for Smart Mobile DevicesabstractWith the increasing number of smart mobile devices, applications based on mobile network take an indispensable role in the Internet of Things. Due to the limited computing power and restricted storage capacity of mobile devices, it is very necessary to design a secure and lightweight authentication scheme for mobile devices. As a lightweight cryptographic primitive, the hash chain is widely used in various cryptographic protocols and one-time password systems. However, most of the existing research work focuses on solving its inherent limitations and deficiencies, while ignoring its security issues. We propose a novel construction of hash chain that consists of multiple different hash functions of different output lengths and employ it in a time-based one-time password (TOTP) system for mobile device authentication. The security foundation of our construction is that the order of the hash functions is confidential and the security analysis demonstrates that it is more secure than other constructions. Moreover, we discuss the degeneration of our construction and implement the scheme in a mobile device. The simulation experiments show that the attacker cannot increase the probability of guessing the order by eavesdropping on the invalid passwords. Qinglong Huang, Haiping Huang, Wenming Wang 0001, Qi Li 0011, Yuhan Wu 0002 |
Wirel. Commun. Mob. Comput. | 4 |
| 2019 | Spoofing Attacks on Speaker Verification Systems Based Generated Voice using Genetic AlgorithmabstractSpeaker verification has played a significant role in authentication with the booming development of smartphones and intelligent terminals in recent years. However, most speaker verification systems directly store the users original voiceprint template data (or called acoustic features). In this paper, we reveal the insecurity and sensitiveness of voiceprint template data by carrying out spoofing attacks on speaker verification systems using genetic algorithm. Meanwhile, multiple generation models based on different genetic algorithms (standard genetic algorithm, multiple population genetic algorithm) are proposed, but also the effects of these generation models are compared. Moreover, experimental results on state-of-the-art text-independent speaker verification techniques (such as i-vector, GMM-UBM) clearly demonstrate that our generated attack voice with leaked voiceprint template data can completely imitate users and pass the speaker verification. Qi Li 0011, Hui Zhu 0001, Ziling Zhang, Rongxing Lu, Fengwei Wang, Hui Li 0006 |
ICC | 1 |
| 2019 | BBARS: Blockchain-Based Anonymous Rewarding Scheme for V2G NetworksabstractIn vehicle-to-grid (V2G) networks, battery-powered vehicle (BV) provides service to the power grid. In order to encourage more BVs to provide the service for power grid, it is necessary to reward the BVs from the power grid. To extensively deploy V2G networks, some security and privacy problems must be solved. In this paper, for the first time, we propose the novel concept of blockchain-based anonymous rewarding scheme (BBARS) for V2G networks. The novel concept comes from the application requirement which has not been solved by now. We give the formal system model and security model of BBARS. Then, we design the concrete BBARS scheme by making use of two different public key cryptosystem. Through security analysis and performance analysis, the designed scheme is provably secure and efficient. The analysis results also show the designed BBARS scheme is practical for secure V2G networks in smart grid. Huaqun Wang, Qihua Wang, Debiao He, Qi Li 0011, Zhe Liu 0001 |
IEEE Internet Things J. | 4 |
| 2018 | A Novel Data Secure Deletion Scheme for Mobile DevicesabstractWith the widespread adoption of mobile devices, an increasingly number of personal data are stored in mobile devices that using flash memory as storage medium. Personal data privacy may also be leaked because of unauthorized access or resale of mobile devices. How to effectively protect users' data privacy and securely delete invalid data, which brings a great challenge to the data secure deletion in flash memory. In order to tackle these problems, we propose a novel data secure deletion scheme based on key derivation encryption algorithm for mobile devices. Firstly, we construct a node key tree based on flash hierarchical structure, and propose a key derivation encryption algorithm to generate data key to encrypt user data. Furthermore, we combine partial block erasure with partial key deletion method to delete both the ciphertext data and the partial key component after expired. The security analysis shows that the proposed scheme is able to implement data privacy protect and secure deletion of invalid data. Performance analysis and experimental results indicate that the proposed scheme is effective and efficient. Minshen Wang, Jinbo Xiong, Qi Li 0011, Biao Jin 0004 |
ICCCN | 4 |
| 2018 | Traceable Ciphertext-Policy Attribute-Based Encryption with Verifiable Outsourced Decryption in eHealth CloudabstractIn cloud‐assisted electronic health care (eHealth) systems, a patient can enforce access control on his/her personal health information (PHI) in a cryptographic way by employing ciphertext‐policy attribute‐based encryption (CP‐ABE) mechanism. There are two features worthy of consideration in real eHealth applications. On the one hand, although the outsourced decryption technique can significantly reduce the decryption cost of a physician, the correctness of the returned result should be guaranteed. On the other hand, the malicious physician who leaks the private key intentionally should be caught. Existing systems mostly aim to provide only one of the above properties. In this work, we present a verifiable and traceable CP‐ABE scheme (VTCP‐ABE) in eHealth cloud, which simultaneously supports the properties of verifiable outsourced decryption and white‐box traceability without compromising the physician’s identity privacy. An authorized physician can obtain an ElGamal‐type partial decrypted ciphertext (PDC) element of original ciphertext from the eHealth cloud decryption server (CDS) and then verify the correctness of returned PDC. Moreover, the illegal behaviour of malicious physician can be precisely (white‐box) traced. We further exploit a delegation method to help the resource‐limited physician authorize someone else to interact with the CDS. The formal security proof and extensive simulations illustrate that our VTCP‐ABE scheme is secure, efficient, and practical. Qi Li 0011, Hongbo Zhu 0002, Zuobin Ying, Tao Zhang 0029 |
Wirel. Commun. Mob. Comput. | 1 |
| 2017 | FABSS: Attribute-Based Sanitizable Signature for Flexible Access Structure
Ruo Mo, Jianfeng Ma 0001, Ximeng Liu, Qi Li 0011 |
ICICS | 4 |
| 2016 | Secure, efficient and revocable multi-authority access control system in cloud storage
Qi Li 0011, Jianfeng Ma 0001, Rui Li 0047, Ximeng Liu, Jinbo Xiong, Danwei Chen |
Comput. Secur. | 1 |
| 2016 | Online/offline unbounded multi-authority attribute-based encryption for data sharing in mobile cloud computingabstractIn order to realize attribute-based data sharing in cloud computing, multi-authority attribute-based encryption (MA-ABE) is extremely attractive. However, most of the existing MA-ABE schemes cannot support a fully large attribute universe and are not suitable for resource-constrained mobile data owners in that the computation cost in secret key generation and encryption is extremely heavy. To tackle the earlier challenges, we propose an online/offline MA-ABE scheme, which realizes both the online/offline secret key generation and the online/offline encryption while supporting a fully large attribute universe. In the offline phase, one global-identity authority and multiple attribute authorities do the majority of the work to issue attribute secret keys before knowing users' global identity and attributes. The data owner can perform most of the encryption computation tasks before knowing the actual message and access structure. Furthermore, the online phase can rapidly assemble the final decryption key and ciphertexts when related specifications become known. Particularly, global-identity authority and attribute authorities need not to cooperate in the whole process. Our online/offline MA-ABE scheme allows the access policies encoded in linear secret sharing schemes. The formal selective security proof and extensive performance analysis indicate that our scheme is very suitable for data sharing in mobile cloud computing. Copyright © 2016 John Wiley & Sons, Ltd. Yinghui Zhang 0002, Dong Zheng 0001, Qi Li 0011, Jin Li 0002, Hui Li 0006 |
Secur. Commun. Networks | 3 |
| 2015 | Large universe decentralized key-policy attribute-based encryptionabstractAbstract In multi‐authority attribute‐based encryption (ABE) systems, each authority manages a different attribute universe and issues the private keys to users. However, the previous multi‐authority ABE schemes are subject to such restrictions during initializing the systems: either the attribute universe is polynomially sized and the attributes have to be enumerated or the attribute universe can be exponentially large, but the size of the set of attributes, which will be used in encryption, is not more than a predefined fixed value. These restrictions prevent multi‐authority ABE schemes from being deployed in dynamic practice applications. In this paper, we present a large universe decentralized key‐policy ABE scheme without such additional limitation. In our scheme, there is no requirement of any central authority. Each attribute authority executes independently from the others and can join or depart the system allodiality. Our system supports any monotone access policy. The proposed scheme is constructed on prime order groups and proved selectively secure in the standard model. To the best of our knowledge, our scheme is the first large universe decentralized key‐policy ABE system in the standard model. Copyright © 2014 John Wiley & Sons, Ltd. Qi Li 0011, Jianfeng Ma 0001, Rui Li 0047, Jinbo Xiong, Ximeng Liu |
Secur. Commun. Networks | 1 |
| 2015 | Provably secure unbounded multi-authority ciphertext-policy attribute-based encryptionabstractAbstract Multi‐authority attribute‐based encryption (ABE) is a generation of ABE where the descriptive attributes are managed by different authorities. In current multi‐authority ABE schemes, the scale of attribute universe employed in encryption is restricted by various predefined thresholds. In this paper, we propose an unbounded multi‐authority ciphertext‐policy ABE system without such restriction. Our scheme consists of multiple attribute authorities (AAs), one central authority (CA), and users labeled by the set of attributes. Each AA governs a different universe of attributes and operates separately. Moreover, there is no cooperation between the CA and AAs. To provide the private keys for a user, the AAs first issue partial attribute‐related keys according to the attributes; the CA then issues identity‐related keys and links these attribute‐keys with the user's global identifier. Both the identity‐related and the linked attribute‐related keys will be used in decryption. The proposed multi‐authority ciphertext‐policy ABE scheme can support arbitrary linear secret sharing scheme as the access policy. Performance analysis and security proof indicate that our scheme is efficient and secure. Copyright © 2015 John Wiley & Sons, Ltd. Qi Li 0011, Jianfeng Ma 0001, Rui Li 0047, Jinbo Xiong, Ximeng Liu |
Secur. Commun. Networks | 1 |
| 2014 | Trust-based service composition in multi-domain environments under time constraint
Tao Zhang 0029, Jianfeng Ma 0001, Qi Li 0011, Ning Xi 0002, Cong Sun 0001 |
Sci. China Inf. Sci. | 3 |
| 2014 | Threshold attribute-based encryption with attribute hierarchy for lattices in the standard modelabstractAttribute‐based encryption (ABE) has been considered as a promising cryptographic primitive for realising information security and flexible access control. However, the characteristic of attributes is treated as the identical level in most proposed schemes. Lattice‐based cryptography has been attracted much attention because of that it can resist to quantum cryptanalysis. In this study, lattice‐based threshold hierarchical ABE (lattice‐based t ‐HABE) scheme without random oracles is constructed and proved to be secure against selective attribute set and chosen plaintext attacks under the standard hardness assumption of the learning with errors problem. The notion of the HABE scheme can be considered as the generalisation of traditional ABE scheme where all attributes have the same level. Ximeng Liu, Jianfeng Ma 0001, Jinbo Xiong, Qi Li 0011, Tao Zhang 0029, Hui Zhu 0001 |
IET Inf. Secur. | 4 |
| 2014 | A Secure Data Self-Destructing Scheme in Cloud ComputingabstractWith the rapid development of versatile cloud services, it becomes increasingly susceptible to use cloud services to share data in a friend circle in the cloud computing environment. Since it is not feasible to implement full lifecycle privacy security, access control becomes a challenging task, especially when we share sensitive data on cloud servers. In order to tackle this problem, we propose a key-policy attribute-based encryption with time-specified attributes (KP-TSABE), a novel secure data self-destructing scheme in cloud computing. In the KP-TSABE scheme, every ciphertext is labeled with a time interval while private key is associated with a time instant. The ciphertext can only be decrypted if both the time instant is in the allowed time interval and the attributes associated with the ciphertext satisfy the key's access structure. The KP-TSABE is able to solve some important security problems by supporting user-defined authorization period and by providing fine-grained access control during the period. The sensitive data will be securely self-destructed after a user-specified expiration time. The KP-TSABE scheme is proved to be secure under the decision l-bilinear Diffie-Hellman inversion (l-Expanded BDHI) assumption. Comprehensive comparisons of the security properties indicate that the KP-TSABE scheme proposed by us satisfies the security requirements and is superior to other existing schemes. Jinbo Xiong, Ximeng Liu, Jianfeng Ma 0001, Qi Li 0011, Kui Geng, Patrick S. Chen |
IEEE Trans. Cloud Comput. | 5 |
| 2013 | Service Composition in Multi-domain Environment under Time ConstraintabstractTime constrained service composition raises several problems. Researches on QoS-driven service composition provide some preliminary solutions, but there are still some unsolved issues, which can be attributed to the following reasons: (1) the huge time consumption of inter-domain validation, (2) the dynamic execution time of services and (3) the difficulty in defining time constraint due to the opaque feature of composite services. In this paper, we propose a novel service composition algorithm, which models the service composition as multi-domain scheduling problem with minimal service resources and time constraint. Each service is modeled as an exclusive resource during its execution period. By computing the inter-domain communications and available services in each domain, the domain with optimal utilization rate is obtained to arrange services. Meanwhile, loop parallelization is adopted when a service cannot be executed on schedule. Moreover, redundant services of the initial composition are further optimized. Our experiment results show that our approach can effectively achieve service composition with time constraint. Tao Zhang 0029, Jianfeng Ma 0001, Cong Sun 0001, Qi Li 0011, Ning Xi 0002 |
ICWS | 4 |