VLDB 2026 Research / reviewers in the wild / expert
Junzuo Lai
dblp:20/2135
· DBLP profile ↗
80ranked-venue papers
22as first author
35since 2021 · last 2026
0000-0001-5780-8463ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 58 · 18 first-author · 22 since 2021Computer networks · 5 · 4 since 2021Databases, data management, data science and information retrieval · 5 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Systems, architecture and hardware · 3 · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multi-authority Attribute-Based Anonymous Credentials with Public Traceability and Revocation
Mingmei Zheng, Junzuo Lai, Xiaohan Mo |
ACISP (2) | 3 |
| 2025 | IvyAPC: Auditable Generalized Payment Channels
Ming Li 0049, Jian Weng 0001, Yingjiu Li, Jia-Si Weng 0001, Junzuo Lai, Robert H. Deng |
FC | 6 |
| 2025 | Zero-Knowledge Protocols with PVC Security: Striking the Balance Between Security and Efficiency
Yi Liu 0053, Yipeng Song, Anjia Yang, Junzuo Lai |
ICICS (1) | 4 |
| 2025 | Towards a Lattice-Based Non-interactive Aggregate Signature Scheme Following the Fiat-Shamir with Aborts Paradigm
Mingmei Zheng, Masahiro Mambo, Junzuo Lai, Xinyi Huang 0001 |
ISPEC | 3 |
| 2025 | Highly Efficient Actively Secure Two-Party Computation with One-Bit Advantage BoundabstractSecure two-party computation (2PC) enables two parties to jointly evaluate a function while maintaining input privacy. Despite recent significant progress, a notable efficiency gap remains between actively secure and passively secure protocols. In S&P'12, Huang, Katz, and Evans formalized the notion of active security with one-bit leakage, providing a promising approach to bridging this gap. Protocols derived from this notion have become foundational in designing highly efficient actively secure 2PC protocols. However, a critical challenge identified by Huang, Katz, and Evans remains unexplored: these protocols face significant weaknesses in ensuring fairness for honest parties when employed in standalone settings rather than as components within larger protocols. While the authors proposed two potential solutions to mitigate this issue, both approaches are prohibitively expensive and lack formalization of security guarantees. In this paper, we first formally define an enhanced notion called active security with one-bit-advantage bound, in which the adversaries' advantages are strictly bounded to at most one bit beyond what honest parties obtain. This bound is enforced through a progressive revelation mechanism, where the evaluation result is disclosed incrementally bit by bit. In addition, we propose a novel approach leveraging label structures within garbled circuits to design a highly efficient constant-round 2PC protocol that achieves active security with one-bit advantage bound. Our protocol demonstrates runtime performance nearly identical to that of passively secure garbled-circuit counterparts in duplex networks (e.g., 1.033 × for the SHA256 circuit in LAN), with low overhead for output progressive revelation (only 80 communicated bytes per bit release). With its strengthened security guarantees and minimal overhead, our protocol is highly suitable for practical 2PC applications. Yi Liu 0053, Junzuo Lai, Peng Yang 0016, Qi Wang 0012, Anjia Yang, Siu-Ming Yiu, Jian Weng 0001 |
SP | 2 |
| 2025 | Privacy-preserving cross-domain point-of-interests recommendation based on friendship in LBSs
Lulu Han, Weiqi Luo 0002, Anjia Yang, Yudan Cheng, Junzuo Lai, Jiaquan Shen |
Comput. Networks | 5 |
| 2025 | Linkable and traceable anonymous authentication with fine-grained access control
Peng Li 0059, Junzuo Lai, Dehua Zhou, Lianguan Huang, Wei Wu 0001 |
Frontiers Comput. Sci. | 2 |
| 2025 | Secure and Editable: A Blockchain Voting System Based on Chameleon Hash With Ephemeral TrapdoorsabstractBlockchain technology has become a popular choice for electronic voting systems due to its transparency, security, and decentralization. However, it is not a perfect solution, as its inherent immutability poses challenges in blockchain‐based e‐voting systems. Specifically, without the physical security provided by traditional polling stations, preventing bribery and coercion becomes more difficult. Additionally, because of blockchain’s immutability, voters who are coerced or mistakenly vote cannot correct their choice. To address these issues, this paper proposes a secure blockchain‐based voting system with editable ballots. The system uses chameleon hashes with ephemeral trapdoors and a timestamp mechanism, allowing voters to modify their ballots within a legitimate timeframe. Additionally, a modified Paillier cryptosystem and blind signature technology are used to ensure that any modifications leave no trace. We simulate and evaluate the system using Fabric 2.2, focusing on computational complexity and system stability. Analysis of experimental results shows that the blockchain‐based voting system with an editable ballot mechanism proposed in this article has good computational cost and stability performance under normal use pressure. Qiankun Zheng, Junyao Ye, Peng Li 0059, Junzuo Lai |
IET Inf. Secur. | 4 |
| 2025 | RPC-MPKET: Location-based revocable encryption with ciphertext equality test for multi-user Internet of Vehicles
Pan Yang 0025, Junzuo Lai, Lianguan Huang, Qiong Huang 0001, Guomin Yang |
J. Syst. Archit. | 2 |
| 2025 | Delegatable Multi-Authority Attribute-Based Anonymous CredentialsabstractIn cloud computing, users need to authenticate to access various resources. Attribute-based anonymous credentials (ABCs) provide a tool for privacy-preserving authentication, allowing users to prove possession of a set of attributes to cloud service providers anonymously. Most existing works on ABC deal with credentials on attributes issued by a single authority (issuer). In reality, it is more practical for users to obtain credentials on attributes from multiple authorities. There are a few works on multi-authority ABC, which do not support delegation needed in real deployments. In this article, we present the first delegatable multi-authority attribute-based anonymous credential system, which simultaneously achieves revocation and traceability. We also give the security analysis of our construction. Finally, we implement our system, and the experimental results show its efficiency. Junzuo Lai, Xiaohan Mo, Peng Li 0059, Cheng-Kang Chu, Robert H. Deng |
IEEE Trans. Cloud Comput. | 2 |
| 2025 | Privacy-Preserving Ridge Regression Over Encrypted Data Under Multiple Keys
Junzuo Lai, Beibei Song, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | How to Securely Delegate and Revoke Partial Authorization CredentialsabstractAn attribute-based credential (ABC) system allows a user, obtaining a credential on a set of attributes from an issuer, to anonymously prove a subset of attributes to a service provider. Nowadays, delegation is an important requirement of ABC, which allows a user to delegate his credentials to other users. However, traditional delegatable ABC systems only support delegating a credential with all attributes. In many scenarios, an appropriate delegation is a user can delegate his credential on parts of attributes to others. Another requirement is revocation of credentials in case of unexpected events. In this article, we propose a delegatable and revocable attribute-based credential, which simultaneously achieves: (1) a user can delegate a credential on parts of attributes to other entities (devices/users); (2) a user can efficiently revoke his credentials or those delegated by him; (3) a user can selectively disclose some attributes and also can prove that the non-disclosed attributes satisfy some relations. To achieve our delegatable and revocable attribute-based credential, we introduce a new primitive, called purgeable signature (PS). We formally define the security model of PS. We then give an efficient construction with a constant-size signature and present the security proofs of PS. Finally, the experimental results show the efficiency of our system. Junzuo Lai, Wei Wu 0001, Cheng-Kang Chu, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | AuditPCH: Auditable Payment Channel Hub With Privacy ProtectionabstractAnonymous Payment Channel Hub (PCH), one of the most promising layer-two solutions, settles the scalability issue in blockchain while guaranteeing the unlinkability of transacting parties. However, such developments bring conflicting requirements, i.e., hiding the sender-to-receiver relationships from any third party but opening the relationship to the auditor. Existing works do not support these requirements simultaneously since off-chain transactions are not recorded in the blockchain. Further, the privacy protection strategies hinder auditors from capturing the payment relationships. Thus, it is still a challenge to audit the finance activities of PCH transacting parties. This paper proposes a novel anonymous PCH solution called AuditPCH to achieve privacy and auditability. Concretely, we design a Linkable Randomizable Puzzle scheme for constructing conditional transactions, allowing a sender to pay for a receiver via the hub. As such, AuditPCH, with the new LRP scheme, ensures that 1) payment relationships can be protected from the hub and 2) an auditor with necessary trapdoors can associate the sender and receiver of a payment. We prove the security of AuditPCH under the Global Universal Composability framework. The extensive experimental evaluations on AuditPCH are established to demonstrate its functionality and flexibility. Jian Weng 0001, Junzuo Lai, Yingjiu Li, Jiahe Wu, Ming Li 0049, Jianfei Sun, Pengfei Wu 0003, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | EncryIP: A Practical Encryption-Based Framework for Model Intellectual Property ProtectionabstractIn the rapidly growing digital economy, protecting intellectual property (IP) associated with digital products has become increasingly important. Within this context, machine learning (ML) models, being highly valuable digital assets, have gained significant attention for IP protection. This paper introduces a practical encryption-based framework called EncryIP, which seamlessly integrates a public-key encryption scheme into the model learning process. This approach enables the protected model to generate randomized and confused labels, ensuring that only individuals with accurate secret keys, signifying authorized users, can decrypt and reveal authentic labels. Importantly, the proposed framework not only facilitates the protected model to multiple authorized users without requiring repetitive training of the original ML model with IP protection methods but also maintains the model's performance without compromising its accuracy. Compared to existing methods like watermark-based, trigger-based, and passport-based approaches, EncryIP demonstrates superior effectiveness in both training protected models and efficiently detecting the unauthorized spread of ML models. Xin Mu, Zhengan Huang, Junzuo Lai, Yehong Zhang |
AAAI | 4 |
| 2024 | Mild Asymmetric Message Franking: Illegal-Messages-Only and Retrospective Content Moderation
Zhengan Huang, Junzuo Lai, Gongxian Zeng, Jian Weng 0001 |
ASIACRYPT (2) | 2 |
| 2024 | Lattice codes for lattice-based PKE
Shanxiang Lyu, Ling Liu 0003, Cong Ling 0001, Junzuo Lai, Hao Chen 0029 |
Des. Codes Cryptogr. | 4 |
| 2024 | Secure and efficient multi-key aggregation for federated learning
Junzuo Lai |
Inf. Sci. | 2 |
| 2024 | Flexible and secure access control for EHR sharing based on blockchain
Peng Li 0059, Dehua Zhou, Haobin Ma, Junzuo Lai |
J. Syst. Archit. | 4 |
| 2024 | Privacy-Preserving Travel Recommendation Based on Stay Points Over Outsourced Spatio-Temporal DataabstractWith the pervasiveness of GPS-enabled devices, mobile users can directly visit the best travel routes matching their interests and obtain a better user experience via location-based travel recommendation services. As the number of queries grows, the travel agency for location-based travel recommendations tends to outsource its recommendation services to the cloud server. Since the travel agency’s popular travel routes and raw trajectory data from mobile users contain sensitive information, privacy protection should be guaranteed. Although some schemes have been proposed to solve the privacy problems, no previous works related to the location-based recommendation are proposed over mobile users’ raw trajectories. To solve this problem, we propose a privacy-preserving travel recommendation scheme based on stay points over the raw encrypted trajectory data. Specifically, we first propose an adapted longest common subsequence computation algorithm to measure the similarity of two trajectories. Second, to support some computations under ciphertext, we design several secure two-party computation (S2PC) primitives (e.g., secure division, secure mean coordinate, and secure comparison) based on the Paillier cryptosystem. Third, we implement secure stay points extraction and adapted longest common subsequence computation protocols via these secure computation primitives. Finally, we analyze the security of our proposed scheme in the semi-honest model and show that the privacy of mobile users’ trajectories, query results, and the travel agency’s popular travel routes are well protected. Meanwhile, we evaluate the performance of each secure computation primitive and conduct extensive experiments on synthetic datasets, and the experimental results show that our scheme is practical in the real applications. Lulu Han, Weiqi Luo 0002, Rongxing Lu, Yandong Zheng, Anjia Yang, Junzuo Lai, Yudan Cheng |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2023 | Robust Publicly Verifiable Covert Security: Limited Information Leakage and Guaranteed Correctness with Low Overhead
Yi Liu 0053, Junzuo Lai, Qi Wang 0012, Xianrui Qin, Anjia Yang, Jian Weng 0001 |
ASIACRYPT (1) | 2 |
| 2023 | Non-interactive Zero-Knowledge Functional Proofs
Gongxian Zeng, Junzuo Lai, Zhengan Huang, Linru Zhang, Xiangning Wang, Kwok-Yan Lam, Huaxiong Wang, Jian Weng 0001 |
ASIACRYPT (5) | 2 |
| 2023 | Asymmetric Group Message Franking: Definitions and Constructions
Junzuo Lai, Gongxian Zeng, Zhengan Huang, Siu-Ming Yiu, Xin Mu, Jian Weng 0001 |
EUROCRYPT (5) | 1 |
| 2023 | Fully privacy-preserving location recommendation in outsourced environments
Lulu Han, Weiqi Luo 0002, Anjia Yang, Yandong Zheng, Rongxing Lu, Junzuo Lai, Yudan Cheng |
Ad Hoc Networks | 6 |
| 2023 | Attribute-based anonymous credential: Delegation, traceability, and revocation
Peng Li 0059, Junzuo Lai, Wei Wu 0001, Xiaowei Yuan |
Comput. Networks | 2 |
| 2023 | Multi-authority anonymous authentication with public accountability for incentive-based applicationsabstractIncentive-based applications enable users to obtain rewards after they complete a task, but how to balance the privacy and accountability is one of the most serious concerns currently. Publicly accountable anonymous authentication provides an excellent way verifying a user’s identity in a privacy-preserving way while ensuring public accountability in case of dispute. Although different kinds of these schemes have been proposed, they all assume that there is a single centralized certificate authority issuing a certificate to users, and are not suitable for an actual scenario which always involves multiple authorities. Therefore, a new primitive called multi-authority linkable and traceable anonymous authentication is proposed to address this issue, enabling privacy protection while holding public accountability under a multi-authority setting. We formally define a security model for this new notion and simultaneously design a generic construction while giving the security proof. Additionally, we implement the proposed scheme to show its efficiency. Peng Li 0059, Junzuo Lai, Dehua Zhou, Wei Wu 0001 |
Comput. Networks | 2 |
| 2023 | Receiver selective opening security for identity-based encryption in the multi-challenge setting
Zhengan Huang, Junzuo Lai, Gongxian Zeng, Xin Mu |
Des. Codes Cryptogr. | 2 |
| 2023 | Accountable attribute-based authentication with fine-grained access control and its application to crowdsourcing
Peng Li 0059, Junzuo Lai, Yongdong Wu |
Frontiers Comput. Sci. | 2 |
| 2023 | Attacks and Countermeasures on Privacy-Preserving Biometric Authentication SchemesabstractBased on the Threshold Predicate Encryption (TPE), the biometric authentication schemePassBioaims to correctly authenticate genuine end-users without leaking their biometric privacy information. However, this article proposes two impersonation attacks toPassBioby merely sending very few query messages. Specifically, an attacker is able to cheat the authentication server with probability 50% by sending the server a random query, or almost 100% by sending the server a collusion of old genuine queries, without being identified. Moreover, in order to defeat the impersonation attacks, this article presents a Verifiable Threshold Predicate Encryption (VTPE) scheme which includes three components: (1) a multi-segment TPE for reducing the computational cost and communication overhead significantly; (2) a segment-wise watermarking for defeating the random attacks; and (3) a challenge-response mechanism for defeating the replay and collusion attacks. In addition, the watermarking also creates a secure channel between the querying user and the server. The experiments on both simulated feature vectors and real face images demonstrate that the present attacks and countermeasures are effective and efficient. Yongdong Wu, Jian Weng 0001, Zhengxia Wang, Kaimin Wei, Jinming Wen, Junzuo Lai |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2023 | PPOLQ: Privacy-Preserving Optimal Location Query With Multiple-Condition Filter in Outsourced EnvironmentsabstractThe optimal location selection is one type of the location-based services (LBS) that aims to find the best location for a new facility from some candidate facilities given a set of existing facilities and a set of customers. Due to reliable and flexible cloud services, outsourcing such heavy-computation tasks has been a popular trend. However, since the cloud is not fully trusted, and the location data contains the sensitive information, privacy protection becomes an essential requirement for these services. Although some related works have been proposed to provide privacy protection, the privacy of data and queries, accuracy of query results, and multiple features of location data are not considered by them simultaneously. In this paper, we propose a privacy-preserving optimal location query scheme PPOLQ that supports multiple-condition filter and queries over multiple data providers in outsourced environments. Specifically, we first design a secure division protocol and a secure inner product protocol based on the Paillier algorithm and the random masking technique, respectively. After that, based on the proposed algorithms, the additive homomorphic encryption, and the secure two-party computation techniques, we develop a privacy-preserving optimal location query scheme. Finally, we analyze the security of our proposed algorithms and scheme in the semi-honest model. Meanwhile, we implement all algorithms and the proposed scheme, and our implementation is open source at Gitee. We also evaluate their performances using synthetic datasets, and extensive experiments show that our scheme is practical for the real-world applications. Lulu Han, Weiqi Luo 0002, Yaxi Yang, Anjia Yang, Rongxing Lu, Junzuo Lai, Yandong Zheng |
IEEE Trans. Serv. Comput. | 6 |
| 2022 | Anonymous Public Key Encryption Under Corruptions
Zhengan Huang, Junzuo Lai, Shuai Han 0001, Lin Lyu 0001, Jian Weng 0001 |
ASIACRYPT (3) | 2 |
| 2022 | DAG-Σ: A DAG-Based Sigma Protocol for Relations in CNF
Gongxian Zeng, Junzuo Lai, Zhengan Huang, Zhiming Zheng 0001 |
ASIACRYPT (2) | 2 |
| 2022 | Practical Federated Learning for Samples with Different IDs
Junzuo Lai, Xiaowei Yuan, Beibei Song |
ProvSec | 2 |
| 2021 | Simulation-Based Bi-Selective Opening Security for Public Key Encryption
Junzuo Lai, Rupeng Yang, Zhengan Huang, Jian Weng 0001 |
ASIACRYPT (2) | 1 |
| 2021 | Event-oriented linkable and traceable anonymous authentication and its application to voting
Peng Li 0059, Junzuo Lai, Yongdong Wu |
J. Inf. Secur. Appl. | 2 |
| 2021 | Publicly Traceable Attribute-Based Anonymous Authentication and Its Application to VotingabstractNumerous anonymous authentication schemes are designed to provide efficient authentication services while preserving privacy. Such schemes may easily neglect access control and accountability, which are two requirements that play an important role in some particular environments and applications. Prior designs of attribute-based anonymous authentication schemes did not concentrate on providing full anonymity while at the same time holding public traceability. To address this problem, we formally define and present a new primitive called traceable attribute-based anonymous authentication (TABAA) which achieves (i) full anonymity, i.e., both registration and authentication cannot reveal user’s privacy; (ii) reusable credential, i.e., a registered credential can be repeatedly used without being linked; (iii) access control, i.e., only when the user’s attribute satisfies the access policy can the user be involved in authentication; and (iv) public traceability, i.e., anyone, without help from the trusted third party, can trace a misbehaving user who has authenticated two messages corresponding to a common address. Then, we formally define the security requirements of TABAA, including unforgeability, anonymity, and accountability, and give a generic construction satisfying the security requirements. Furthermore, based on TABAA, we propose the first attribute-based, decentralized, fully anonymous, publicly traceable e-voting, which enables voters to engage in a number of different voting activities without repeated registration. Peng Li 0059, Junzuo Lai, Yongdong Wu |
Secur. Commun. Networks | 2 |
| 2020 | Possibility and Impossibility Results for Receiver Selective Opening Secure PKE in the Multi-challenge Setting
Rupeng Yang, Junzuo Lai, Zhengan Huang, Man Ho Au, Qiuliang Xu, Willy Susilo |
ASIACRYPT (1) | 2 |
| 2020 | Constant-size CCA-secure multi-hop unidirectional proxy re-encryption from indistinguishability obfuscation
Junzuo Lai, Zhengan Huang, Man Ho Au, Xianping Mao |
Theor. Comput. Sci. | 1 |
| 2019 | Collusion Resistant Watermarking Schemes for Cryptographic Functionalities
Rupeng Yang, Man Ho Au, Junzuo Lai, Qiuliang Xu, Zuoxia Yu |
ASIACRYPT (1) | 3 |
| 2019 | LaT-Voting: Traceable Anonymous E-Voting on Blockchain
Peng Li 0059, Junzuo Lai |
NSS | 2 |
| 2019 | Simulation-based selective opening security for receivers under chosen-ciphertext attacks
Zhengan Huang, Junzuo Lai, Wenbin Chen 0003, Man Ho Au, Jin Li 0002 |
Des. Codes Cryptogr. | 2 |
| 2019 | Data security against receiver corruptions: SOA security for receivers from simulatable DEMs
Zhengan Huang, Junzuo Lai, Wenbin Chen 0003, Tong Li 0011, Yang Xiang 0001 |
Inf. Sci. | 2 |
| 2019 | Practical public key encryption with selective opening security for receivers
Zhengan Huang, Junzuo Lai, Wenbin Chen 0003, Muhammad Raees-ul-Haq, Liaoliang Jiang |
Inf. Sci. | 2 |
| 2018 | Constant-Size CCA-Secure Multi-hop Unidirectional Proxy Re-encryption from Indistinguishability Obfuscation
Junzuo Lai, Zhengan Huang, Man Ho Au, Xianping Mao |
ACISP | 1 |
| 2018 | Lattice-Based Universal Accumulator with Nonmembership Arguments
Zuoxia Yu, Man Ho Au, Rupeng Yang, Junzuo Lai, Qiuliang Xu |
ACISP | 4 |
| 2018 | Achieving Flexibility for ABE with Outsourcing via Proxy Re-EncryptionabstractOutsourcing the decryption of attribute-based encryption (ABE) ciphertext is a promising way to tackle the question of how users can perform decryption efficiently. However, existing solutions require the type of the target ciphertext to be determined at the setup of the outsourcing scheme. As such, making the target cryptosystems (or the clients) to be versatile becomes an issue that warrants investigations. In this paper, the problem we wish to tackle is to transform an ABE ciphertext to any client who is using the same, or possibly different, public-key encryption (PKE) system with the sender. The problem is of practical interest since it is hard to require all clients to use the same PKE, especially in the case of remote and cross-system data sharing. In addition, we also consider whether robust client-side decryption scheme can be adopted. This feature is not supported in the existing ABE with outsourcing. Zuoxia Yu, Man Ho Au, Rupeng Yang, Junzuo Lai, Qiuliang Xu |
AsiaCCS | 4 |
| 2018 | Making Any Attribute-Based Encryption Accountable, Efficiently
Junzuo Lai, Qiang Tang 0005 |
ESORICS (2) | 1 |
| 2018 | Anonymous Attribute-Based Conditional Proxy Re-encryption
Xianping Mao, Chuansheng Wang, Junzuo Lai |
NSS | 5 |
| 2018 | An efficient and expressive ciphertext-policy attribute-based encryption scheme with partially hidden access structures, revisited
Hui Cui 0001, Robert H. Deng, Junzuo Lai, Xun Yi, Surya Nepal |
Comput. Networks | 3 |
| 2017 | Verifiable Range Query Processing for Cloud Computing
Junzuo Lai, Chuansheng Wang, Jianghe Zhang |
ISPEC | 2 |
| 2017 | A Secure Cloud Backup System with Deduplication and Assured Deletion
Junzuo Lai, Chuansheng Wang, Guangzheng Wu |
ProvSec | 1 |
| 2017 | Dual trapdoor identity-based encryption with keyword search
Jia-Nan Liu, Junzuo Lai, Xinyi Huang 0001 |
Soft Comput. | 2 |
| 2017 | Adaptable key-policy attribute-based encryption with time interval
Siqi Ma 0001, Junzuo Lai, Robert H. Deng, Xuhua Ding |
Soft Comput. | 2 |
| 2016 | Secret Handshakes with Dynamic Expressive Matching Policy
Junzuo Lai, Lixian Liu |
ACISP (1) | 2 |
| 2016 | An Efficient and Expressive Ciphertext-Policy Attribute-Based Encryption Scheme with Partially Hidden Access Structures
Hui Cui 0001, Robert H. Deng, Junzuo Lai |
ProvSec | 4 |
| 2016 | Ciphertext-policy attribute-based encryption with partially hidden access structure and its application to privacy-preserving electronic medical record system in cloud environmentabstractAbstract With the development of cloud computing, more and more sensitive data are uploaded to cloud by companies or individuals, which brings forth new challenges for outsourced data security and privacy. Ciphertext‐policy attribute‐based encryption (CP‐ABE) provides fine‐grained access control of encrypted data in the cloud; in a CP‐ABE scheme, an access structure, also referred to as ciphertext‐policy, is sent along with a ciphertext explicitly, and anyone who obtains a ciphertext can know the access structure associated with the ciphertext. In certain applications, access structures contain very sensitive information and must be protected from everyone except the users whose private key attributes satisfy the access structures. In this paper, we propose a new model for CP‐ABE with partially hidden access structure (See Figure 2). In our model, each attribute consists of two parts: an attribute name and its value; if the private key attributes of a user do not satisfy the access structure associated with a ciphertext, the specific attribute values of the access structure are hidden, while other information about the access structure is public. Based on the CP‐ABE scheme proposed by Lewko and Waters recently, we then present a concrete construction of CP‐ABE with partially hidden access structure and prove that it is fully secure in the standard model. In addition, we discuss how our new model can be employed to construct a privacy‐preserving electronic medical record system in the cloud environment. Copyright © 2016 John Wiley & Sons, Ltd. Lixian Liu, Junzuo Lai, Robert H. Deng, Yingjiu Li |
Secur. Commun. Networks | 2 |
| 2016 | Fuzzy certificateless signatureabstractAccording to the inspirations from history, we introduce a new cryptography primitive called fuzzy certificateless signature, which not only eliminates the key escrow problem inherently existed in fuzzy identity-based signature but also possesses the error tolerance property of fuzzy identity-based signature that allows for a set of attributes ω to verify a signature produced with a private key for an identity ω′ if and only if the distance between the two identities ω and ω′ is within a certain threshold. In this paper, the concept of fuzzy certificateless signature is first proposed, and then, the syntax and security model of fuzzy certificateless signature are formally defined. In the next step, so far, the first concrete fuzzy certificateless signature scheme is proposed, which may be practicably implemented in biometric identification. In addition, a formal security proof is provided, so as to demonstrate that in the random oracle model, our newly proposed scheme is existentially unforgeable against Types I and II chosen message attacks formalized in the security model under the computational Diffie–Hellman assumption. Copyright © 2016 John Wiley & Sons, Ltd. Liangliang Wang 0001, Junzuo Lai, Hu Xiong, Kefei Chen, Yu Long 0001 |
Secur. Commun. Networks | 2 |
| 2016 | Generic and Efficient Constructions of Attribute-Based Encryption with Verifiable Outsourced DecryptionabstractAttribute-based encryption (ABE) provides a mechanism for complex access control over encrypted data. However in most ABE systems, the ciphertext size and the decryption overhead, which grow with the complexity of the access policy, are becoming critical barriers in applications running on resource-limited devices. Outsourcing decryption of ABE ciphertexts to a powerful third party is a reasonable manner to solve this problem. Since the third party is usually believed to be untrusted, the security requirements of ABE with outsourced decryption should include privacy and verifiability. Namely, any adversary including the third party should learn nothing about the encrypted message, and the correctness of the outsourced decryption is supposed to be verified efficiently. We propose generic constructions of CPA-secure and RCCA-secure ABE systems with verifiable outsourced decryption from CPA-secure ABE with outsourced decryption, respectively. We also instantiate our CPA-secure construction in the standard model and then show an implementation of this instantiation. The experimental results show that, compared with the existing scheme, our CPA-secure construction has more compact ciphertext and less computational costs. Moreover, the techniques involved in the RCCA-secure construction can be applied in generally constructing CCA-secure ABE, which we believe to be of independent interest. Xianping Mao, Junzuo Lai, Qixiang Mei, Kefei Chen, Jian Weng 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2015 | Efficient revocable identity-based encryption from multilinear mapsabstractAbstract In Identity‐Based Encryption (IBE) systems, there is a widespread concern over the issue on how to provide an efficient revocation mechanism. We develop a new approach in constructing an efficient revocable IBE scheme. Our approach utilizes recent advances in multilinear maps and combines a two‐level hierarchical IBE scheme with a revocation encryption system. In our revocable IBE scheme, both the public parameters and the private key are constant‐size. Simultaneously, the size of the update key at some time is only proportional to the number of revoked users at the time. Our proposed scheme is proven secure in the selective revocation list model without relying on random oracles. Copyright © 2015 John Wiley & Sons, Ltd. Xianping Mao, Junzuo Lai, Kefei Chen, Jian Weng 0001, Qixiang Mei |
Secur. Commun. Networks | 2 |
| 2014 | Fully secure key-policy attribute-based encryption with constant-size ciphertexts and fast decryptionabstractAttribute-based encryption (ABE), introduced by Sahai and Waters, is a promising cryptographic primitive, which has been widely applied to implement fine-grained access control system for encrypted data. In its key-policy flavor, attribute sets are used to annotate ciphertexts and secret keys are associated with access structures that specify which ciphertexts a user is entitled to decrypt. In most existing key-policy attribute-based encryption (KP-ABE) constructions, the size of the ciphertext is proportional to the number of attributes associated with it and the decryption cost is proportional to the number of attributes used during decryption. In this paper, we present a new construction of KP-ABE. Our proposed construction is the first KP-ABE scheme, which has the following features simultaneously: expressive (i.e., supporting arbitrary monotonic access structures); fully secure in the standard model; constant-size ciphertexts and fast decryption. The downside of our construction is that secret keys have quadratic size in the number of attributes. Junzuo Lai, Robert H. Deng, Yingjiu Li, Jian Weng 0001 |
AsiaCCS | 1 |
| 2014 | Verifiable Computation on Outsourced Encrypted Data
Junzuo Lai, Robert H. Deng, HweeHwa Pang, Jian Weng 0001 |
ESORICS (1) | 1 |
| 2014 | Authorized Keyword Search on Encrypted Data
Junzuo Lai, Yingjiu Li, Robert H. Deng, Jian Weng 0001 |
ESORICS (1) | 2 |
| 2014 | Identity-Based Encryption Secure against Selective Opening Chosen-Ciphertext Attack
Junzuo Lai, Robert H. Deng, Shengli Liu 0001, Jian Weng 0001, Yunlei Zhao |
EUROCRYPT | 1 |
| 2014 | Towards semantically secure outsourcing of association rule mining on categorical data
Junzuo Lai, Yingjiu Li, Robert H. Deng, Jian Weng 0001, Chaowen Guan, Qiang Yan 0001 |
Inf. Sci. | 1 |
| 2013 | Verifiable and private top-k monitoringabstractIn a data streaming model, records or documents are pushed from a data owner, via untrusted third-party servers, to a large number of users with matching interests. The match in interest is calculated from the correlation between each pair of document and user query. For scalability and availability reasons, this calculation is delegated to the servers, which gives rise to the need to protect the privacy of the documents and user queries. In addition, the users need to guard against the eventuality of a server distorting the correlation score of the documents to manipulate which documents are highlighted to certain users. Xuhua Ding, HweeHwa Pang, Junzuo Lai |
AsiaCCS | 3 |
| 2013 | Expressive search on encrypted dataabstractDifferent from the traditional public key encryption, searchable public key encryption allows a data owner to encrypt his data under a user's public key in such a way that the user can generate search token keys using her secret key and then query an encryption storage server. On receiving such a search token key, the server filters all or related stored encryptions and returns matched ones as response. Junzuo Lai, Xuhua Zhou, Robert H. Deng, Yingjiu Li, Kefei Chen |
AsiaCCS | 1 |
| 2013 | Accountable Authority Identity-Based Encryption with Public Traceability
Junzuo Lai, Robert H. Deng, Yunlei Zhao, Jian Weng 0001 |
CT-RSA | 1 |
| 2013 | Accountable Trapdoor Sanitizable Signatures
Junzuo Lai, Xuhua Ding, Yongdong Wu |
ISPEC | 1 |
| 2013 | Adaptable Ciphertext-Policy Attribute-Based Encryption
Junzuo Lai, Robert H. Deng, Yanjiang Yang, Jian Weng 0001 |
Pairing | 1 |
| 2013 | Attribute-Based Encryption With Verifiable Outsourced DecryptionabstractAttribute-based encryption (ABE) is a public-key-based one-to-many encryption that allows users to encrypt and decrypt data based on user attributes. A promising application of ABE is flexible access control of encrypted data stored in the cloud, using access polices and ascribed attributes associated with private keys and ciphertexts. One of the main efficiency drawbacks of the existing ABE schemes is that decryption involves expensive pairing operations and the number of such operations grows with the complexity of the access policy. Recently, Greenproposed an ABE system with outsourced decryption that largely eliminates the decryption overhead for users. In such a system, a user provides an untrusted server, say a cloud service provider, with a transformation key that allows the cloud to translate any ABE ciphertext satisfied by that user's attributes or access policy into a simple ciphertext, and it only incurs a small computational overhead for the user to recover the plaintext from the transformed ciphertext. Security of an ABE system with outsourced decryption ensures that an adversary (including a malicious cloud) will not be able to learn anything about the encrypted message; however, it does not guarantee the correctness of the transformation done by the cloud. In this paper, we consider a new requirement of ABE with outsourced decryption: verifiability. Informally, verifiability guarantees that a user can efficiently check if the transformation is done correctly. We give the formal model of ABE with verifiable outsourced decryption and propose a concrete scheme. We prove that our new scheme is both secure and verifiable, without relying on random oracles. Finally, we show an implementation of our scheme and result of performance measurements, which indicates a significant reduction on computing resources imposed on users. Junzuo Lai, Robert H. Deng, Chaowen Guan, Jian Weng 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2012 | Expressive CP-ABE with partially hidden access structuresabstractAt Eurocrypt 2005, Sahai and Waters [7] introduced the concept of attribute-based encryption (ABE). ABE enables public key based one-to-many encryption and is envisioned as a promising cryptographic primitive for realizing scalable and fine-grained access control systems. There are two kinds of ABE schemes [1], key-policy ABE (KP-ABE) and ciphertext-policy ABE (CP-ABE) schemes. This paper, our concern is on the latter. Junzuo Lai, Robert H. Deng, Yingjiu Li |
AsiaCCS | 1 |
| 2011 | Hierarchical Identity-Based Chameleon Hash and Its Applications
Feng Bao 0001, Robert H. Deng, Xuhua Ding, Junzuo Lai, Yunlei Zhao |
ACNS | 4 |
| 2011 | Fully Secure Cipertext-Policy Hiding CP-ABE
Junzuo Lai, Robert H. Deng, Yingjiu Li |
ISPEC | 1 |
| 2011 | General Construction of Chameleon All-But-One Trapdoor Functions
Shengli Liu 0001, Junzuo Lai, Robert H. Deng |
ProvSec | 2 |
| 2011 | Self-generated-certificate public key encryption without pairing and its application
Junzuo Lai, Weidong Kou, Kefei Chen |
Inf. Sci. | 1 |
| 2011 | On two RFID privacy notions and their relationsabstractPrivacy of RFID systems is receiving increasing attention in the RFID community. Basically, there are two kinds of RFID privacy notions in the literature: one based on the indistinguishability of two tags, denoted as ind-privacy, and the other based on the unpredictability of the output of an RFID protocol, denoted as unp-privacy. In this article, we first revisit the existing unpredictability-based RFID privacy models and point out their limitations. We then propose a new RFID privacy model, denoted as unp * -privacy, based on the indistinguishability of a real tag and a virtual tag. We formally clarify its relationship with the ind-privacy model. It is proven that ind-privacy is weaker than unp * -privacy. Moreover, the minimal (necessary and sufficient) condition on RFID tags to achieve unp * -privacy is determined. It is shown that if an RFID system is unp * -private, then the computational power of an RFID tag can be used to construct a pseudorandom function family provided that the RFID system is complete and sound. On the other hand, if each tag is able to compute a pseudorandom function, then the tags can be used to construct an RFID system with unp * -privacy. In this sense, a pseudorandom function family is the minimal requirement on an RFID tag's computational power for enforcing RFID system privacy. Finally, a new RFID mutual authentication protocol is proposed to satisfy the minimal requirement. Yingjiu Li, Robert H. Deng, Junzuo Lai, Changshe Ma |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2010 | Revisiting Unpredictability-Based RFID Privacy Models
Junzuo Lai, Robert H. Deng, Yingjiu Li |
ACNS | 1 |
| 2010 | Efficient CCA-Secure PKE from Identity-Based Techniques
Junzuo Lai, Robert H. Deng, Shengli Liu 0001, Weidong Kou |
CT-RSA | 1 |
| 2010 | New Constructions for Identity-Based Unidirectional Proxy Re-Encryption
Junzuo Lai, Wen Tao Zhu, Robert H. Deng, Shengli Liu 0001, Weidong Kou |
J. Comput. Sci. Technol. | 1 |
| 2009 | Conditional proxy re-encryption secure against chosen-ciphertext attackabstractIn a proxy re-encryption (PRE) system [4], a proxy, authorized by Alice, can convert a ciphertext for Alice into a ciphertext for Bob without seeing the underlying plaintext. PRE has found many practical applications requiring delegation. However, it is inadequate to handle scenarios where a fine-grained delegation is demanded. To overcome the limitation of existing PRE systems, we introduce the notion of conditional proxy re-encryption (C-PRE), whereby only ci-phertext satisfying a specific condition set by Alice can be transformed by the proxy and then decrypted by Bob. We formalize its security model and propose an efficient C-PRE scheme, whose chosen-ciphertext security is proven under the 3-quotient bilinear Diffie-Hellman assumption. We further extend the construction to allow multiple conditions with a slightly higher overhead. Jian Weng 0001, Robert H. Deng, Xuhua Ding, Cheng-Kang Chu, Junzuo Lai |
AsiaCCS | 5 |
| 2009 | RSA-Based Certificateless Public Key Encryption
Junzuo Lai, Robert H. Deng, Shengli Liu 0001, Weidong Kou |
ISPEC | 1 |