VLDB 2026 Research / reviewers in the wild / expert
Kai Fan 0001
dblp:20/3825-1
· DBLP profile ↗
76ranked-venue papers
35as first author
46since 2021 · last 2026
0000-0001-6870-6657ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 44 · 22 first-author · 28 since 2021Security and privacy · 19 · 5 first-author · 12 since 2021Systems, architecture and hardware · 6 · 5 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Mask: An Efficient and Tunable Volume-Pattern Hiding AlgorithmabstractWe present Mask, an efficient and tunable algorithm for hiding volume patterns in multi-maps. Volume-pattern leakage, referring to the observable size of data returned by a query, enables adversaries to infer sensitive dataset information, posing severe privacy risks in multi-map scenarios. Designed to address this issue, Mask focuses on balancing storage/query overhead and privacy (a key trade-off in this field), allowing users to define parameters for random data distribution across buckets to realize fine-grained control over storage and query performance, integrating Bloom filters with a bounded cache for efficient indexing (optimizing performance under skewed query workloads); extended to MaskIO for reduced client-side storage, it obfuscates query indexes and uploads them to the server, achieving constant-bounded client storage overhead, and experiments show Mask outperforms the bucket-based peer Veil with 2–4 × higher performance and a lower stash ratio. Kai Fan 0001, Shiyuan Ji, Hui Li 0006, Yintang Yang, Lianhai Wang |
IEEE Internet Things J. | 1 |
| 2026 | Multidimensional Auditable Lattice-Based Privacy-Preserving Data Aggregation Scheme in Smart GridsabstractThe massive growth of data has brought vigorous vitality to Internet-of-Things (IoT). It has also brought new challenges, such as confidentiality privacy protection and redundant data transmission. Concerning this regard, data aggregation serves as an efficient technique to minimize the transmission frequency among massive objects in smart grid(SG). By aggregating a large amount of the same type of data while satisfying the protection of user privacy. With the advent of the post-quantum era, a good aggregation scheme must provide quantum resistance while ensuring the secure aggregation of ciphertext power data. However, the excessive overhead limits anti-quantum algorithms from being widely used in SG where resource devices are limited. Therefore, it is an important part of the current private data security aggregation technology to find a low cost and lightweight inverse quantum algorithm to achieve user data security aggregation. In this paper, we propose an improved NTRU-based cryptosystem with multidimensional coding, referred to as multidimensional coding NTRU (MC-NTRU). and use the lattice batch signature technique, which improves the efficiency of the scheme while satisfying the anti-quantum attack. Based on these, we design the multidimensional auditable lattice-based privacy-preserving data aggregation scheme(MA-PPDA) for privacy data on resource-limited IoT devices such as smart grids. In addition to this, the scheme achieves fault tolerance of the scheme by adding zeros and random numbers to the user data. The comparative study against existing approaches demonstrates that the proposed scheme not only adheres to critical security aspects including user privacy, data confidentiality, integrity, and authenticity, but also decreases both communication and computational burdens on the system. This makes our scheme particularly apt for IoT environments characterized by constrained device resources. Kai Fan 0001, Xuyang Ma, Guanglu Wei, Kuan Zhang 0001, Hui Li 0006, Yintang Yang, Lianhai Wang |
IEEE Internet Things J. | 1 |
| 2026 | NeuDFL: Efficient Neuron-Based Defense Against Label Flipping Attacks on Non-IID DataabstractFederated Learning (FL) enables collaborative model training while preserving data privacy, making it particularly attractive for large-scale Internet of Things (IoT) systems. However, in practical deployments, data collected by distributed clients are often non-independent and identically distributed (Non-IID), which amplifies the vulnerability of FL to poisoning attacks. Among them, Label-Flipping Attacks (LFA) are especially stealthy, as they can induce targeted misclassification without noticeably affecting overall accuracy, posing serious risks to safety-critical IoT applications. In this paper, we propose NeuDFL, a lightweight and robust defense framework against LFA under Non-IID settings. Unlike many existing defenses that primarily rely on gradient analysis over the full model update space or auxiliary clean datasets, NeuDFL exploits lightweight class-wise parameter statistics extracted from the final fully connected layer. By leveraging the cumulative and task-aligned nature of model parameters, NeuDFL enables reliable identification of attacked classes and filters malicious clients via an adaptive statistical threshold, improving robustness to data heterogeneity while incurring low computational overhead. Extensive experiments on multiple datasets demonstrate that NeuDFL offers an effective and efficient defense against label-flipping attacks, providing a robust solution for federated learning in complex real-world environments. Kai Fan 0001, Huixuan Wang, Wenjie Li 0008, Hui Li 0006, Kuan Zhang 0001, Yintang Yang, Lianhai Wang |
IEEE Internet Things J. | 1 |
| 2026 | HBA: Hijacking-Based Backdoor Attack for Vertical Federated LearningabstractVertical Federated Learning (VFL) is a distributed machine learning paradigm designed for scenarios with vertically partitioned data features, making it highly compatible with Internet of Things (IoT) ecosystems. While promoting collaborative modeling among IoT devices, VFL also introduces new security risks, particularly backdoor attacks. Existing VFL backdoor attacks typically establish associations between triggers and target labels during the training phase by manipulating intermediate model outputs, making them easily detectable by advanced defense mechanisms. This paper proposes Hijacking-based Backdoor Attack (HBA), which for the first time innovatively achieves backdoor attack by exchanging the forward embeddings during VFL prediction phase, without embedding traditional triggers. HBA leverages intrinsic semantic relationships in the embedding space to hijack the decision-making process of the top model during inference. HBA’s effectiveness depends on the discriminative nature of the features extracted by the bottom model, and since it does not alter the training process, it can evade most defense mechanisms based on training behavior monitoring. Experiments demonstrate that HBA achieves an attack success rate of 99.9% in classification tasks without compromising the original task’s accuracy. Furthermore, existing defense mechanisms struggle to effectively counter HBA without degrading the model’s original task performance. Pingle Zhang, Kai Fan 0001, Xiang Li 0214, Kuan Zhang 0001, Hui Li 0006, Yintang Yang, Lianhai Wang |
IEEE Internet Things J. | 2 |
| 2026 | Cancelable Biometrics and Quantum-Resistant Two-Factor Authenticated Key Agreement for Mobile Device
Guanglu Wei, Kai Fan 0001, Kuan Zhang 0001, Yuhan Bai, Zhanpeng Guo, Hui Li 0006, Yintang Yang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | Enhancing Security and Privacy in Multi-Server Federated LearningabstractFederated learning is a distributed learning approach designed to train models across multiple client devices with local data while preserving the privacy of that data. However, traditional federated learning suffers from three major f laws: 1.Vulnerability to Byzantine Attacks. 2.Privacy Leakage Risks. 3.Assumption of Third-Party Server Reliability. Few solutions currently address all three of these flaws at the same time. To address the above issues simultaneously, this paper introduces a multi-server federated learning approach that enhances security and privacy. We first set up a multi-server architecture to address the performance issues and single point of failure in traditional federated learning frameworks. And we set up and update different servers reputation on both the server and participant sides, which work together to resist aggregation attacks that can be implemented by malicious servers. It is also worth noting that we split models to be uploaded into two segments, each of which is uploaded to two different servers in conjunction with the last model of the previous round to defend against privacy attacks and keep model as complete as possible. Experiments on MNIST, IMDB, CIFAR10, and Adult indicate this method maintains accuracy, defends against label-flipping and Gaussian noise, and protects privacy. Xingwen Zhao, Yongfeng Bu, Kai Fan 0001, Hui Li 0006 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Dynamic Asymmetric Group Key Agreement Without Pairing for Distributed Online Social NetworksabstractOnline social networks (OSN) such as Twitter, Facebook, etc. have an overall user base of more than 5 billion as of today. Traditional centralized OSN users’ data and content are stored in centralized servers, which has the risk of data leakage and privacy violation. Distributed OSN (DOSN) address the single-point-of-failure and user data privacy concerns faced by centralized OSN by enabling the operation of network infrastructures and services without centralized ownership or control. However, DOSN face privacy protection issues. The group key agreement (GKA) is an important method to construct secure channels to protect the secure communication of network group members. Asymmetric GKA methods allow external members to securely communicate with group members without having to join the group. However, it is worth noting that existing AGKA schemes rely on bilinear pairing, resulting in a high computational overhead. Meanwhile, considering scenarios where external users join, or group members leave, we design a dynamic asymmetric group key agreement (DAGKAwP) scheme based on Schnorr batch multi-signature that does not depend on bilinear pairing. During the key generation phase, the members generate self-authenticating public-private key pairs to resist malicious public key attacks. For group key agreement, new hash functions are embedded in Schnorr signatures to generate aggregated public keys, and this scheme supports external member addition and internal member exit. In group message encryption, sender anonymity and message non-repudiation are realized. The security comparison with related DAGKA schemes reveals that the DAGKAwP scheme offers more comprehensive security. Performance evaluations suggest that this scheme offers computational efficiency and lower communication overhead than related Dynamic AGKA schemes. Kai Fan 0001, Guanglu Wei, Kuan Zhang 0001, Hui Li 0006, Yintang Yang |
IEEE Trans. Netw. | 1 |
| 2025 | Blockchain-based anonymous and self-tallying voting with time-bounded ballot secrecy
Yijie Shi, Kai Fan 0001, Yuhan Bai, Chonglin Zhang, Kuan Zhang 0001, Hui Li 0006, Yintang Yang |
Comput. Networks | 2 |
| 2025 | Building Efficient and Flexible Voting Protocols: An Approach to Fairness and AnonymityabstractVoting protocols are fundamental in modern society. With the ongoing evolution of communication technology and the Internet of Things, the importance of electronic voting protocols is anticipated to experience a significant rise in the advancement of smart cities. Leveraging the blockchain’s tamper-resistant and publicly verifiable properties, along with the concept of enabling all participants to tally election results, blockchain-based self-tallying voting protocols effectively address the shortcomings of centralized traditional electronic voting. However, existing voting protocols still face the dual challenge of security and efficiency. The primary issues include the difficulty in ensuring voter anonymity and election fairness, as well as the insufficient system robustness and low tallying efficiency resulting from security design. To tackle these concerns, we propose a novel approach to constructing efficient and flexible voting protocols that concurrently ensure fairness and anonymity. Specifically, we encapsulate the decryption private keys corresponding to the public keys of encrypted ballots in time capsules to safeguard voting fairness. Additionally, based on our proposed approach, we construct an efficient and flexible score voting protocol for smart cities. The protocol employs traceable ring signature to protect the voter anonymity and public traceability, utilizes a dual-key additive homomorphic ElGamal encryption to encapsulate ballots. We also improve signature-based set membership proofs to verify the validity of ballots. Furthermore, through security analysis and performance evaluation, we demonstrate that our proposed protocol meets all security objectives with reasonable costs. Yijie Shi, Kai Fan 0001, Yuhan Bai, Chonglin Zhang, Kan Yang 0001, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 2 |
| 2025 | Dynamic Multi-User Authorization in Ciphertext Retrieval With Proxy Re-EncryptionabstractCiphertext retrieval technology has been widely explored with the increasing popularity of cloud computing. Proxy re-encryption with Keyword search (PREKS) can support multi-user retrieval without increasing data owner's overhead, but users can continue searching once they have obtained search rights. It is difficult for a data owner to revoke a user's access rights because the data is stored in the cloud. In general, under the premise of forward and backward security, the user's search permission can be revoked by updating the ciphertext. Nevertheless, this approach may expose user or data privacy to cloud servers. In this paper, we utilize the Chinese Remainder Theorem to generate DO-Authorization and DU-Authentication factors, and realizes the authorization and revocation of a specific single user by adding or deleting authorization items. In addition, we use a designated tester algorithm in the ciphertext retrieval process to improve system security. Subsequent security analysis proves that the proposed scheme can resist the Chosen Keyword Attack and Keyword Guessing Attack. Simulation results indicate that the proposed scheme has high efficiency, especially in the user revocation phase Nan Gao 0003, Kai Fan 0001, Haoyang Wang 0005, Yintang Yang, Kan Yang 0001, Hui Li 0006 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Deniable Time Signature Forward Secure Searchable Encryption With Flexible Retrieval and Traceable Authorization in Sharable EHRabstractElectronic Health Record (EHR) sharing can improve the accuracy of medical diagnosis and promote the development of the public medical field. However, plaintext medical records expose patient privacy, and it is challenging to share medical records between different hospitals, making it difficult for doctors to securely retrieve medical records and massively analyze the same diseases from different patients. In this paper, we propose a flexible ciphertext retrieval scheme in electronic health sharing system that supports multi-patient and multi-keyword medical records retrieval. The proxy free ciphertext retrieval technology based on cloud servers enables doctors to retrieve multiple patients' medical records simultaneously. On this basis, we utilize the time encoding algorithm to ensure that the trapdoor associated with the old time cannot retrieve the ciphertext index bound with the latest time, so as to realize the lightweight forward security. Besides, the encoding time signed by the deniable signature can avoid forgery by malicious users or adversaries. In addition, the scheme supports evil user traceable and revocable. The security analysis indicates that the scheme can satisfy the keyword privacy, the forward security of updated ciphertexts, and the deniability of time encoding signatures. Experimental evaluation illustrates that our scheme is lightweight and efficient Nan Gao 0003, Kai Fan 0001, Kan Yang 0001, Hui Li 0006, Yintang Yang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | MU-MRQ: Enabling Multi-User Verifiable and Secure Multi-Dimensional Range Query Over Encrypted DataabstractIn recent years, multi-dimensional range query (MRQ) over encrypted data has been increasingly applied in various scenarios, making it one of the mainstream services for secure large-scale data storage and sharing in cloud computing. However, although existing privacy-preserving MRQ schemes can ensure query and data privacy, they still fail to fully protect single-dimensional privacy and path pattern. Moreover, most schemes lack mechanisms to verify the completeness and correctness of query results, making it impossible to guarantee their validity. To address these issues, this paper proposes a secure and efficient MRQ scheme with result verification for multiple users (MU-MRQ). First, we design a secure and efficient multi-dimensional data index based on the G-tree, incorporating a timestamp mechanism to verify the correctness and completeness of query results. Additionally, we propose two novel intersection predicate encryption protocols to achieve efficient retrieval while preserving single-dimensional privacy and path pattern. Rigorous security analysis demonstrates that our MU-MRQ scheme achieves security under the known background model. Comprehensive experiments on real-world datasets validate the efficiency of the MU-MRQ scheme. Haoyang Wang 0005, Kai Fan 0001, Kuan Zhang 0001, Fenghua Li 0001, Hui Li 0006, Yintang Yang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Conjunctive Keyword Search With Dynamic Group-UserabstractIn order to ensure data security and improve data usability, searchable encryption has been widely used in cloud computing systems. However, the evil single users with search privileges bring heavy privacy threats to the system. Threshold searchable encryption provides a collaborative search service for group users; a single user cannot search for ciphertext. However, the threshold searchable encryption based on the Shamir secret sharing mechanism cannot achieve flexible user dynamic since the Lagrange interpolation polynomial for recovering the secret value changes with the group user add or delete, resulting in the ciphertext or trapdoor containing Lagrange interpolation formula needs to be recreated. In this paper, the conjunctive keyword search with dynamic group-user scheme (CKSDGU) is proposed to realize group-user flexible addition and deletion. The proposed CKSDGU scheme can match successfully without the data owner resetting ciphertext and the original data user generating trapdoors. In addition, multi-keyword conjunctive retrieval is implemented in the CKSDGU scheme, and group users can search the target ciphertexts that contain all users’ query keyword sets. The security analysis illustrates that the CKSDGU scheme can resist chosen keyword attacks and keyword guessing attacks. The performance analysis presents that our scheme has considerable overhead and efficient computational cost in the user dynamic stage. Nan Gao 0003, Kai Fan 0001, Zhen Zhao 0005, Willy Susilo, Zhoutong Xiong, Hui Li 0006 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Beyond Access Pattern: Efficient Volume-Hiding Multi-Range Queries Over Outsourced Data ServicesabstractMulti-range query (MRQ) is a typical multi-attribute data query widely used in various practical applications. It is capable of searching all data objects contained in a query request. Many privacy-preserving MRQ schemes have been proposed to realize MRQ on encrypted data. However, existing MRQ schemes only consider the security threat caused by access pattern leakage, not the harm of volume pattern leakage. Moreover, most existing schemes cannot achieve efficient queries and updates while preserving the access pattern. In this paper, we propose an efficient MRQ scheme for hiding volume and access patterns. We first design a joint data index using Order-Revealing Encryption (ORE) and Pseudo-random functions (PRFs) to realize volume-hiding range queries. Then, we combine the private set intersection (PSI) and hardware Software Guard Extensions (SGX) to compute each attribute’s intersection of query results. In addition, we preserve access patterns during queries by designing a batch refresh algorithm and an update protocol. Finally, rigorous security analysis and extensive experiments demonstrate the security and performance of our scheme in real-world scenarios. Haoyang Wang 0005, Kai Fan 0001, Chong Yu 0002, Kuan Zhang 0001, Fenghua Li 0001, Haojin Zhu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Hide Yourself: Multi-Dimensional Range Queries for Responses-Hiding Over Outsourced DataabstractMulti-dimensional range query (MRQ) over outsourced data has been extensively applied in various domains. However, security and efficiency are still two aspects that cannot be easily balanced in private MRQs, as improving security inevitably incurs high computation, storage, and communication costs. Several schemes perform encrypted data retrieval in the trusted execution environment (TEE), which balances security and performance. Unfortunately, they focused on keywords or single-dimensional range queries, failing to address private MRQs. With the TEE (i.e., Intel SGX), we propose a response-hiding MRQ scheme over encrypted data (SGX-MRQ) in this paper. We first design an index structure called SDic, which can achieve efficient range queries while hiding the responses to each query from the server. Moreover, based on the security properties of SGX, we construct the encrypted polynomials of each dimension on the enclave and implement the intersection computation of multi-attribute queries by the server, which greatly improves the system efficiency. We present the formal definition of SGX-MRQ and perform a rigorous proof. We implement a prototype of SGX-MRQ and conduct extensive experiments on real datasets. The evaluation results validate the feasibility of our scheme in practical applications. Haoyang Wang 0005, Kai Fan 0001, Chong Yu 0002, Kuan Zhang 0001, Fenghua Li 0001, Haojin Zhu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Enhancing Security and Privacy in Federated Learning Using Low-Dimensional Update Representation and Proximity-Based DefenseabstractFederated Learning (FL) is a promising privacy-preserving machine learning paradigm that allows data owners to collaboratively train models while keeping their data localized. Despite its potential, FL faces challenges related to the trustworthiness of both clients and servers, particularly against curious or malicious adversaries. In this paper, we introduce a novel framework namedFederatedLearning with Low-DimensionalUpdateRepresentation andProximity-Based defense (FLURP), designed to address privacy preservation and resistance to Byzantine attacks in distributed learning environments. FLURP employs$\mathsf {LinfSample}$method, enabling clients to compute the$l_{\infty }$norm across sliding windows of updates, resulting in a Low-Dimensional Update Representation (LUR). Calculating the shared distance matrix among LURs, rather than updates, significantly reduces the overhead of Secure Multi-Party Computation (SMPC) by three orders of magnitude while effectively distinguishing between benign and poisoned updates. Additionally, FLURP integrates a privacy-preserving proximity-based defense mechanism utilizing optimized SMPC protocols to minimize communication rounds. Our experiments demonstrate FLURP's effectiveness in countering Byzantine adversaries with low communication and runtime overhead. FLURP offers a scalable framework for secure and reliable FL in distributed environments, facilitating its application in scenarios requiring robust data management and security. Wenjie Li 0008, Kai Fan 0001, Hui Li 0006, Wei Yang Bryan Lim, Qiang Yang 0001 |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2024 | VDPSRQ: Achieving Verifiable and Dynamic Private Spatial Range Queries over Outsourced Database
Haoyang Wang 0005, Kai Fan 0001, Yue Quan, Fenghua Li 0001, Hui Li 0006 |
TrustCom | 2 |
| 2024 | DMASP: Dynamic Multi-keyword Searchable Encryption for Protected Access and Search Patterns with Differential PrivacyabstractIn recent years, cloud computing services have grown rapidly, with people outsourcing huge amounts of private data to cloud servers. Searchable encryption(SE) facilitates people’s use of data while protecting data privacy. To balance the efficiency, current SE schemes still leak information such as access, search and volume patterns to cloud servers, and most dynamic SE schemes leak forward and backward privacy, and these leaks create serious security threats. In this paper, we propose a dynamic SE scheme DMASP with suppressed leakage, which protects access pattern, search pattern and volume pattern simultaneously. We utilize the differential privacy mechanism to obfuscate databases, and introduce the CKKS algorithm to protect access and volume patterns during queries. Meanwhile, we design a secure structure to index databases efficiently, and protect forward and backward privacy during updates. We rigorously analyse the security of DMASP. Furthermore, comprehensive experimental evaluation show that DMASP can reduce the accuracy of attacks against patterns leakage in real-world databases. Yue Quan, Kai Fan 0001, Haoyang Wang 0005, Hui Li 0006, Yintang Yang |
TrustCom | 2 |
| 2024 | Seamless group handover authentication protocol for vehicle networks: Services continuity
Ye Bi, Kai Fan 0001, Zhilin Zeng, Kan Yang 0001, Hui Li 0006, Yintang Yang |
Comput. Networks | 2 |
| 2024 | SC-Chain: An Efficient Blockchain Framework for Smart CityabstractTo overcome the challenges of urbanization and population growth, smart cities use cutting-edge technologies, such as IoT and AI to offer improved public services. Although these advancements have brought convenience, they have raised security and privacy concerns. Blockchain technology has the potential to address these concerns, but existing blockchain frameworks have issues of scalability and efficiency that hinder their ability to meet the smart city demands. In this article, we propose a novel blockchain framework for smart cities, named SC-Chain. Specifically, SC-Chain incorporates a decentralized access mechanism that leverages threshold signatures and BFT-like consensus for efficient node registration and authentication in decentralized systems. Furthermore, we propose a consensus mechanism that utilizes the verifiable random function (VRF) to achieve efficient miner node election, ensuring efficiency, fairness, and security in large-scale smart city systems. We demonstrate the effectiveness and feasibility of the SC-Chain through theoretical analysis and simulations, showcasing its potential to enable the development of secure and efficient smart city infrastructure. Kai Fan 0001, Hengrui Lu, Yuhan Bai, Yintang Yang, Kuan Zhang 0001, Hui Li 0006 |
IEEE Internet Things J. | 1 |
| 2024 | CR-FH-CPABE: Secure File Hierarchy Attribute-Based Encryption Scheme Supporting User Collusion Resistance in Cloud ComputingabstractThe attribute-based encryption (ABE) scheme, which can set specific conditions to control user access to data, has been widely studied and applied to cloud storage services. Considering file hierarchy in practical scenarios, the ABE scheme can set a hierarchical access control policy so multiple files can be associated with one access structure to reduce users’ computing overhead and save the cloud server’s storage space. However, the existing systems have the risk of user collusion due to the hierarchical access control structure parameters. This paper proposes a secure file hierarchy ABE scheme supporting user collusion resistance (CR-FH-CPABE) in cloud computing. We add a data noise vector without changing the hierarchical access control structure to prevent user ultra vires. Technically, we break the relationships that colluding users could exploit, prevent malicious users from colluding with their computing results, and extract meaningful information from the ciphertext. In addition, we provide an improved CR-FH-CPABE scheme with outsourced decryption, which helps resource-limited devices obtain computing services. Finally, we demonstrate our scheme is CPA secure and show outstanding performance through simulation results. Yuhan Bai, Kai Fan 0001, Kuan Zhang 0001, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 2 |
| 2024 | A Dynamic and Efficient Self-Certified Authenticated Group Key Agreement Protocol for VANETabstractAuthenticated group key agreement (AGKA) protocols protect the security of communications among a group of users. Dutta and Barua proposed a dynamic AGKA protocol, but it fails to the leaving user attacks and the attacks by two malicious users. In this paper, we propose a dynamic AGKA protocol based on the computational Diffie-Hellman problem. The proposed AGKA protocol achieves sound dynamicity and efficiency. With 10 users in a group, the improvements in computation and communication overheads achieve 82.5% and 72.6 %, respectively. Then the proposed AGKA protocol is applied to vehicular ad hoc network (VANET). SC-AGKA, a self-certified authentication and key agreement protocol for VANET is presented. Pseudonyms are employed with care in SC-AGKA to provide conditional privacy. It is suitable for SC-AGKA to protect the vehicular group communications in VANET considering its security strength and efficiency. Xuefei Cao, Lanjun Dang, Kai Fan 0001, Xingwen Zhao, Yingzi Luan |
IEEE Internet Things J. | 3 |
| 2024 | FLSG: A Novel Defense Strategy Against Inference Attacks in Vertical Federated LearningabstractAs a new machine learning (ML) paradigm, federated learning (FL) empowers different participants to jointly train a more effective model than traditional ML. Unlike horizontal FL (HFL), which expands the sample space by aggregating local models, vertical FL (VFL) is suitable for scenarios where the sample ID between participants is the same but differs in sample characteristics. For a long time, VFL has been considered safe due to no data exchange and heterogeneity between parties. However, the recently proposed label inference attacks pose a significant security threat to VFL. Specifically, by adding randomly initialized layers to the top of local models, the passive label inference attack can infer tens of thousands of local participants’ private data with only 40 auxiliary labels. Since the attack is entirely local, using privacy protection technologies such as differential privacy cannot effectively defend against these attacks. Therefore, we propose a new privacy protection scheme called FL similar gradients (FLSGs) to defend against this attack. Unlike differential privacy, the FLSG scheme randomly generates gradients of a Gaussian distribution similar in dimension to the original gradients and calculates their cosine distance. If the distance is less than a certain threshold, the gradients are used instead of the original gradients to pass to the local participants. We conducted extensive evaluations on six real-world data sets, and the results show that FLSG provides a better defensive effect at lower computational overhead than other known methods when defending the passive label inference attack. Kai Fan 0001, Jingtao Hong, Wenjie Li 0008, Xingwen Zhao, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 1 |
| 2024 | EIV-BT-ABE: Efficient Attribute-Based Encryption With Black-Box Traceability Based on Encrypted Identity VectorabstractThe fine grain of ciphertext-policy attribute-based encryption (CP-ABE) offers advantages through the amalgamation of key and user attributes; however, it also brings the issue of key misuse. To circumvent the tracking mechanisms of the white-box algorithm, malicious users manipulate the decryption key and encryption algorithm, encapsulating them to create a black-box decryption device. This necessitates black-box traceability for supervision purposes. In this article, we employ$n$-bit encrypted binary vectors to depict the user’s identity and subsequently convert it into partial decryption privileges. When encrypting plaintext, data owners can utilize a “vague specification” to define the identity vector of qualified decryptors. Furthermore, based on the vague specification mechanism, we have devised a pioneering active black-box tracing algorithm. Integrating this algorithm with CP-ABE, we propose the black-box traceable CP-ABE (EIV-BT-ABE) scheme. Our EIV-BT-ABE scheme attains strong traceability with low time complexity, effectively reducing decryption and encryption time costs. The experiment substantiated the efficiency of our scheme while demonstrating its adherence to IND-CPA security. Kai Fan 0001, Yuhan Bai, Yintang Yang, Kan Yang 0001, Hui Li 0006 |
IEEE Internet Things J. | 1 |
| 2024 | Fault-Tolerant and Collusion-Resistant Lattice-Based Multidimensional Privacy-Preserving Data Aggregation in Edge-Based Smart GridabstractThe smart grid, which is an important component of smart cities, is developing rapidly nowadays, while the confidentiality and integrity of consumption data of customers become significant security issues. Although existing privacy-preserving aggregation schemes reduce the communication overhead and protect the privacy of users’ multidimensional power data, most of them are vulnerable and possess no quantum-resistant properties. In this article, we combine the Chinese remainder theorem (CRT) and the bit decomposition method to provide multibit homomorphic properties for the quantum-resistant algorithm number theory research unit (NTRU), and propose the partial-homomorphic NTRU (PH-NTRU). Then, based on the algorithm, we design the lattice-based multidimensional data privacy-preserving data aggregation scheme named FTCR-LMPPDA, in which the edge devices work as aggregator gateways. Specifically, smart meters participating in the aggregation process share zero-sum numbers to resist collusion attacks. Error retransmission mechanism and random number reconstruction algorithm are introduced to enhance the robustness of this scheme and provide our system with the ability to recover from faults. In addition, security analysis shows our scheme can resist quantum attacks, collusion attacks, and other internal and external attacks as well as keep the security features, such as confidentiality, privacy and integrity of users’ data. Finally, performance evaluation demonstrates that our scheme is more efficient than existing schemes and is more suitable for devices with constrained resources. Kai Fan 0001, Yuanshuai Ren, Yuhan Bai, Guanglu Wei, Kuan Zhang 0001, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 1 |
| 2024 | Ciphertext Retrieval With Identity Bidirectional Authentication and Matrix Index in IoTabstractCiphertext retrieval for cloud-based Internet of Things has been widely explored with the increasing popularity of cloud computing. However, in most existing solutions, the security and efficiency of the retrieval process are difficult to achieve simultaneously. To this end, we develop a novel secure matrix index, and we utilize identity-based encryption to encrypt keywords and homomorphic encryption to encrypt matrix values. The former can guarantee the security of the keyword, and the latter can realize the efficiency of the operation while ensuring safety. Then, we develop an identity-based bidirectional authentication algorithm to ensure that only authenticated users can retrieve ciphertext. In addition, we use different scoring formulas to calculate the relevance scores of documents with different lengths, ensuring that the documents are appropriately returned to users. Finally, we design a new retrieval structure to protect the privacy of the correspondence between keywords and ciphertexts. The security proof shows that the index and trapdoor can resist chosen keyword attack and keyword Guessing attack. The extensive simulation shows that our scheme is efficient. Nan Gao 0003, Kai Fan 0001, Haoyang Wang 0005, Kuan Zhang 0001, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 2 |
| 2024 | Public-Key Inverted-Index Keyword Search With Designated Tester and Multiuser Key Decryption in IoTabstractSearchable encryption for Cloud-based Internet of Things has been widely explored with the increasing popularity of cloud computing. The public-key encryption with keyword search (PEKS) system support multiuser retrieval. However, the PEKS search time is linearly increasing as the index keyword number growth, and the search time would be huge if the index keywords consistently increase. In this article, we introduce a novel scheme named as public-key inverted-index keyword search with designated tester and multiuser key decryption (IDPEKS). First of all, we design an inverted index based on B-plus tree to reduce the search time to a logarithmic level. On this basis, we optimized the TF-IDF formula and added user preference factor and font size factor to make the relevance score calculation more consistent with needs of receiver. Besides, we design a multiuser key decryption algorithm to protect the system symmetric key. In addition, we set index server to perform the index-trapdoor retrieval process. The designated index server tester can resist the attack of the cloud server on keywords. The security proof shows that the scheme can resist the chosen keyword attack (CKA), keyword guessing attack (KGA), and key guessing attack (KeyGA). The experimental results show that the algorithm can improve retrieval efficiency while have a short encryption time. Nan Gao 0003, Kai Fan 0001, Haoyang Wang 0005, Kuan Zhang 0001, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 2 |
| 2024 | PBFL: Privacy-Preserving and Byzantine-Robust Federated-Learning-Empowered Industry 4.0abstractIn Industry 4.0, artificial intelligence (AI) has been successfully applied in scenarios, such as fault prediction, traffic analysis, and production decision making. However, due to the sensitivity and security of data, privacy regulations prohibit the transfer and exchange of industrial data between entities, resulting in training data being fragmented into data silos that limit the accuracy of AI models. FL can effectively break the data silo effect, but naive federated learning (FL) (FedAvg) is vulnerable to inference attacks from aggregators and Byzantine attacks from participants. To address these issues, we propose a privacy-preserving and Byzantine-robust federated learning scheme (PBFL) for Industry 4.0. Under the setting of an benign-majority participants, PBFL can always identify benign direction and magnitude of updates. Extensive experiments demonstrate that PBFL is more robust than state-of-the-art schemes, even with extreme proportion (49%) of malicious participants. Moreover, PBFL contains a series of well-optimized 2-party computation (2PC) protocols, causing it reduces total runtime of the unoptimized implementation by around$3 \times \sim 4 \times $and$9 \times \sim 10 \times $for 32-bit and 64-bit circuits, respectively. Wenjie Li 0008, Kai Fan 0001, Kan Yang 0001, Yintang Yang, Hui Li 0006 |
IEEE Internet Things J. | 2 |
| 2024 | Volume-Hiding Multidimensional Verifiable Dynamic Searchable Symmetric Encryption Scheme for Cloud ComputingabstractConsiderable attention has been directed toward dynamic searchable symmetric encryption (DSSE) since it has the capability to both search and update the encrypted database. Nevertheless, the majority of DSSE schemes operate in single dimensions, and the server is assumed to be honest but curious. Consequently, there are two significant issues that must be addressed. One concerns how searchable operations can be implemented in a multidimensional space. Another is the construction of a search-result-verifiable DSSE scheme within a malicious server model. In response to the above-mentioned problems, we proposed a multidimensional verifiable DSSE scheme with volume hiding. Our design leverages the combination of various query methods across different dimensions to enable a wide array of search modes. The state chain is used in the scheme to guarantee forward privacy, while backward privacy is ensured through the encryption of the index. Our scheme employs a bitmap index of the same length to represent multiple file addresses that match a keyword, ensuring size consistency in search results, also known as volume hiding. Multiset hash function is used to construct the verifiable search result. The security of the scheme is analyzed using a simulation-based proof method based on leakage functions. Xingwen Zhao, Hui Li 0006, Kai Fan 0001 |
IEEE Internet Things J. | 4 |
| 2024 | Quantum-Safe Lattice-Based Certificateless Anonymous Authenticated Key Agreement for Internet of ThingsabstractIn recent years, the Internet of Things (IoT) has gained immense popularity in various aspects of work, learning, and daily life. Within the IoT realm, there is a growing concern regarding communication security issues between users and servers. However, addressing the communication security between servers is equally imperative, which has not received as much attention. To this end, we propose a certificateless anonymous authenticated key agreement (AKA) algorithm based on learning with errors (LWEs) and inhomogeneous small integer solution (ISIS) security assumptions. Our scheme provides strong resistance to quantum attacks and protects the privacy of communication servers. It also has constant communication costs and lower computational requirements than existing lattice-based anonymous AKA algorithms on the broadcast channel. Additionally, the proposed scheme eliminates the resource consumption of managing complex certificates and addresses the security risks associated with key escrow in the key generation center (KGC). Through security and performance analysis, we demonstrate that our approach can enhance the security of IoT-based healthcare systems while significantly improving communication efficiency. Our proposed scheme provides a promising solution to security issues related to server communication in IoT systems. Guanglu Wei, Kai Fan 0001, Kuan Zhang 0001, Haoyang Wang 0005, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 2 |
| 2024 | Privacy-Preserving Spatial Keyword Search With Lightweight Access Control in Cloud EnvironmentsabstractAs cloud computing continues to gain popularity, various applications have been deployed under Industrial Internet of Things (IIoT) scenarios. In order to alleviate the heavy burden of local storage and processing, a substantial amount of data is entrusted to the cloud server (CS), but attendant security risks like privacy leakages begin to appear. In addition, another vital security issue, access control, has come to attention. Many existing spatial keyword similarity search schemes are unable to implement access control. To solve these issues, we propose a novel scheme privacy-preserving spatial keyword similarity search with lightweight access control (PSKSSA) scheme. Specifically, we design an efficient access control IR-tree (ACIR-tree) that achieves sublinear query efficiency. Access control is implemented through role-based polynomial technology, which is integrated into the ACIR-tree and the query vector, so that spatial keywords and access control information are uniformly encoded into a vector. Meanwhile, privacy is protected by enhanced asymmetric scalar-product-preserving encryption (EASPE), which guarantees indistinguishability against the chosen-plaintext attack (IND-CPA) model. The most similar$k$results are found by the CS while implementing access control for data users. Through formal analysis and extensive experiments, it has proved that the proposed scheme is safe and effective, with good scalability. Xingwen Zhao, Luhui Gan, Kai Fan 0001 |
IEEE Internet Things J. | 3 |
| 2024 | Lower rounds lattice-based anonymous AKA under the seCK model for the IoT
Guanglu Wei, Kai Fan 0001, Kuan Zhang 0001, Haoyang Wang 0005, Kan Yang 0001, Hui Li 0006, Yintang Yang |
Peer Peer Netw. Appl. | 2 |
| 2024 | LSPSS: Constructing Lightweight and Secure Scheme for Private Data Storage and Sharing in Aerial ComputingabstractAerial computing is gradually playing an essential role in edge and fog computing paradigms by virtue of mobility, availability, scalability, flexibility, and simultaneity, where the Low-altitude Computing (LAC) platform, as the end close to the data sources, is mainly responsible for data collection and storage. However, because of the long physical distance of data transmission and the vulnerability of the transmission link to various attacks, how to efficiently share the stored data while ensuring data privacy is a critical issue for LAC at present. In this paper, we propose a lightweight and secure private data storage and sharing scheme to support range queries over encrypted multi-dimensional data. Specifically, we first propose two data conversion methods for transforming location features and collected log files with multi-dimensional attributes in Unmanned Aerial Vehicles (UAVs). Based on the ideas of asymmetric scalar-product-preserving encryption (ASPE) and inner product comparison (IPC), we design a privacy-preserving storage and sharing technique for the converted data. In addition, to achieve secure and efficient data querying and result verification, we design a secure data index and build a data authentication structure (DAS) with G-tree. Finally, we rigorously analyze the security of our proposed scheme and conduct extensive experiments on a real-world database to prove that our proposed scheme is secure and easy to use in practical application scenarios. Haoyang Wang 0005, Kai Fan 0001, Chong Yu 0002, Kuan Zhang 0001, Fenghua Li 0001, Hui Li 0006, Yintang Yang, Haojin Zhu |
IEEE Trans. Serv. Comput. | 2 |
| 2023 | A Secure and Efficient Two-Party Protocol Enabling Ownership Transfer of RFID ObjectsabstractModern business models improve the efficiency of supply chain management by attaching tags to products. These tagged products typically change owners multiple times during their life cycles. The ownership transfer protocol authorizes the new owner by replacing the old owner’s authentication information stored in the tag with the new owner’s. Until now, a considerable amount of literature has proposed solutions to the problem of RFID ownership transfer. Unfortunately, these existing protocols are either flawed in some security properties especially in protecting new and old owners’ privacy, or are associated with huge computational overheads. In this article, we propose an ultralightweight RFID ownership transfer protocol based on permutation function. The tag and reader only use efficient bit operations, which greatly reduce the computational overhead. An important feature of the proposed protocol is that the new owner can impose calculations on data that has been encrypted by the old owner. The new owner is authorized by the old owner and does not have access to the tag’s key, which protects the old owner’s privacy stored in the tag side. We compare our protocol with existing work, and show the advantages in terms of security, computational overhead, and time cost. Ye Bi, Kai Fan 0001, Kuan Zhang 0001, Yuhan Bai, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 2 |
| 2023 | Blockchain-based cloud-edge clock calibration in IoT
Kai Fan 0001, Zeyu Shi, Yicen Yang, Liyang Bai, Yintang Yang, Kan Yang 0001, Hui Li 0006 |
Peer Peer Netw. Appl. | 1 |
| 2023 | MSIAP: A Dynamic Searchable Encryption for Privacy-Protection on Smart Grid With Cloud-Edge-EndabstractWith the advent of 5G and the Internet of Things, edge computing and cloud computing with their respective strengths are bound as Cloud-Edge-End Orchestrated (CEEO). The CEEO network integrates artificial intelligence and provides innovative technologies for smart grid applications and services. With massive data transmission on the CEEO network, the trustworthiness of the service node exerts an enormous influence on data privacy. To realize securely share data and decrease the local storage, end-user prefer to encrypt data and upload it to the cloud. Meanwhile, the challenge is how to balance efficiency and security perfectly when users need to find relevant documents containing specific keywords from the CEEO network. In this article, we innovatively propose a searchable encryption scheme that supports multi-keyword subset retrieval, named MSIAP. Specifically, we enhance the Apriori, a data mining algorithm, to mine the relevance of files from massive information and build a multi-level index structure. On this basis, we achieve efficient multi-keyword subset retrieval and dynamic update with insignificant information disclosure in the smart grid. Furthermore, our MSIAP strengthens the present data retrieval methods and enormously reduces the time complexity to accommodate the system of distributed smart grid. Finally, we provide the security analysis and performance evaluations by comparing them with existing works. Kai Fan 0001, Ruidan Su, Kuan Zhang 0001, Haoyang Wang 0005, Hui Li 0006, Yintang Yang |
IEEE Trans. Cloud Comput. | 1 |
| 2023 | Joint Biological ID : A Secure and Efficient Lightweight Biometric Authentication SchemeabstractBiometric applications makes biometric authentication replace the traditional password in many cases. Biometric recognition technology has the advantages of convenience and high stability, facilitating identity recognition. However, the shortcoming of biometric authentication is easy to be stolen and leaked, which raises security concerns. In this paper, we design a lightweight joint biometric authentication scheme (SELBA) based on face and fingerprint. We improve searchable encryption (SE) to protect the privacy security of extracted biometric features in the storage and authentication stage. Because of the problem that biometric features cannot be changed or retrieved once leaked in existing schemes, we propose a cancelable mechanism to reconstruct stolen or damaged biometric templates. Moreover, we make a complete security analysis of the SELBA to meet the confidentiality, renewability, revocability, irreversibility and unlinkability of template in biometric recognition. Meanwhile, we conduct experiments on real data sets to show that SELBA is secure, efficient and easy to use in practical application scenarios. Haoyang Wang 0005, Kai Fan 0001, Kuan Zhang 0001, Fenghua Li 0001, Hui Li 0006, Yintang Yang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | A new RFID ultra-lightweight authentication protocol for medical privacy protection in smart living
Xingmiao Wang, Kai Fan 0001, Kan Yang 0001, Xiaochun Cheng, Qingkuan Dong, Hui Li 0006, Yintang Yang |
Comput. Commun. | 2 |
| 2022 | Encrypted Data Retrieval and Sharing Scheme in Space-Air-Ground-Integrated Vehicular NetworksabstractAs a smart transportation application of the Internet of Things, the Internet of Vehicles (IoV) depresses the chances of traffic accidents, while improving transportation efficiency and user driving experience. However, as the number of vehicles continues to grow, the original ground-based IoV system is difficult to meet the ever-increasing demand. To this end, space–air–ground-integrated network (SAGIN) incorporates satellite systems, aerial network and terrestrial communications. However, because SAGIN integrates multiple network services and communication modes, which makes SAGIN more vulnerable to various types of attacks and security threats. This article first presents the dominating security threats in data storage, transmission and sharing of space–air–ground integrated vehicular network (SAGIVN). Moreover, for guaranteeing the safety and effectiveness of the model, we advance a safe and effective encrypted data retrieval and sharing scheme in SAGIVN (ERDSS) for possible threats, the ERDSS can execute fuzzy retrieval over misspelling keywords and sort results by relevance scores to realize precise retrieval. We perform a comprehensive security discussion and execute experiments based on real-world data sets. The consequences demonstrate that the ERDSS is safe and efficient. Haoyang Wang 0005, Kai Fan 0001, Kuan Zhang 0001, Zilong Wang 0001, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 2 |
| 2022 | Secure and Efficient Data-Privacy-Preserving Scheme for Mobile Cyber-Physical SystemsabstractResearch on mobile cyber–physical systems (MCPSs) that have the superiorities of cyber–physical systems (CPSs) and expand their application range has become a trend in recent years. The applications of MCPS in fields, such as intelligent transportation systems, smart home appliances, and mobile education, have also become increasingly mature. However, MCPS also has some shortcomings that need to be solved urgently. Sensors carried on mobile devices collect data and upload huge amounts of data to the cloud for statistics and analysis. Mobile devices need to directly interact with the cloud, causing both parties to bear huge computing and communication costs. Since the interaction process includes data sharing and storage, it is particularly important to protect the data itself and the security of sharing. Searchable encryption ensures the safety of communication among the MPEs and the cloud, while protecting the privacy of data on the cloud. However, the existing searchable encryption technology cannot provide efficient and reliable data storage and sharing services for MPEs in MCPS under the premise of ensuring security. In this article, we present a secure and efficient data sharing and privacy protection scheme in MCPS on the basis of the edge computing model (NESPS). Meanwhile, the introduction of edge computing (EC) significantly reduces the communication consumption between the device and the cloud. Furthermore, attribute-based encryption (ABE) enables the NESPS to achieve fine-grained management of device authorities. Moreover, we have carried out security analysis and simulation on the NESPS, the results demonstrate that the NESPS meets the proposed requirements. Haoyang Wang 0005, Kai Fan 0001, Kuan Zhang 0001, Zilong Wang 0001, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 2 |
| 2022 | Blockchain-based trust management for verifiable time synchronization service in IoT
Kai Fan 0001, Zeyu Shi, Ruidan Su, Yuhan Bai, Pei Huang 0013, Kuan Zhang 0001, Hui Li 0006, Yintang Yang |
Peer-to-Peer Netw. Appl. | 1 |
| 2021 | An ultra light weight and secure RFID batch authentication scheme for IoMT
Junbin Kang, Kai Fan 0001, Kuan Zhang 0001, Xiaochun Cheng, Hui Li 0006, Yintang Yang |
Comput. Commun. | 2 |
| 2021 | Cross-domain access control based on trusted third-party and attribute mapping center
Liyang Bai, Kai Fan 0001, Yuhan Bai, Xiaochun Cheng, Hui Li 0006, Yintang Yang |
J. Syst. Archit. | 2 |
| 2021 | A blockchain-based privacy preservation scheme in multimedia network
Jianxing Liu, Kai Fan 0001, Hui Li 0006, Yintang Yang |
Multim. Tools Appl. | 2 |
| 2021 | PMAB: A Public Mutual Audit Blockchain for Outsourced Data in Cloud StorageabstractWith the rapid growth of data, limited by the storage capacity, more and more IoT applications choose to outsource data to Cloud Service Providers (CSPs). But, in such scenarios, outsourced data in cloud storage can be easily corrupted and difficult to be found in time, which brings about potential security issues. Thus, Provable Data Possession (PDP) protocol has been extensively researched due to its capability of supporting efficient audit for outsourced data in cloud. However, most PDP schemes require the Third-Party Auditor (TPA) to audit data for Data Owners (DOs), which requires the TPA to be trustworthy and fair. To eliminate the TPA, we present a Public Mutual Audit Blockchain (PMAB) for outsourced data in cloud storage. We first propose an audit chain architecture based on Ouroboros and an incentive mechanism based on credit to allow CSPs to audit each other mutually with anticollusion (any CSP is not willing to help other CSPs conceal data problems). Then, we design an audit protocol to achieve public audit efficiently with low cost of audit verification. Rigorous analysis explains the security of PMAB using game theory, and performance analysis shows the efficiency of PMAB using the real-world dataset. Ruidan Su, Pei Huang 0013, Yuhan Bai, Kai Fan 0001, Kan Yang 0001, Hui Li 0006, Yintang Yang |
Secur. Commun. Networks | 5 |
| 2021 | Anonymous and Privacy-Preserving Federated Learning With Industrial Big DataabstractMany artificial intelligence technologies have been applied for extracting useful information from massive industrial big data. However, the privacy issues are usually overlooked in many existing methods. In this article, we propose an anonymous and privacy-preserving federated learning scheme for the mining of industrial big data. We explored the effect of the proportion of shared parameters on the accuracy through experiments, and found that sharing partial parameters can almost achieve the accuracy of sharing all the parameters. On this basis, our proposed federated learning scheme reduces the privacy leakage by sharing fewer parameters between the server and each participant. Specifically, we leverage differential privacy on shared parameters with Gaussian mechanism to provide strict privacy preservation; the effect of different ε and δ on accuracy is tested; and we keep track of δ-when it reaches a certain threshold, training shall be stopped. What's more, we employ a proxy server as the middle layer between the server and all the participants to achieve anonymity of participants; it is worth noting that this can also reduce the communication burden on the federated learning server. Finally, we provide the security analysis and performance evaluations by comparing with other schemes. Kai Fan 0001, Kan Yang 0001, Zilong Wang 0001, Hui Li 0006, Yintang Yang |
IEEE Trans. Ind. Informatics | 2 |
| 2020 | A Weight-based k-prototypes Algorithm for Anomaly Detection in Smart GridabstractAnomaly detection is a typical method to find abnormal behaviors in smart grid, where the data may contain both categorical and numerical attributes with distinct significance. The k-prototypes algorithm is one of the most common algorithms for clustering mixed categorical and numerical data, however, it does not consider the significance of different attributes towards the clustering process. In this paper, we propose a weight based k-prototypes algorithm for anomaly detection in smart grid. Specifically, we first introduce an improved cost function to measure the categorical and numerical attributes uniformly and assign the weight to each attribute. We also propose two entropy metrics to calculate weight values and embed them into the k-prototypes algorithm for mixed data clustering in smart grid. Finally, we compare our proposed algorithm with existing clustering algorithms and the experimental results show that our algorithm is effective for anomaly detection in smart grid. Kai Fan 0001, Kan Yang 0001, Zilong Wang 0001, Hui Li 0006 |
ICC | 2 |
| 2020 | Privacy-preserving searchable encryption in the intelligent edge computing
Kai Fan 0001, Kuan Zhang 0001, Haoyang Wang 0005, Hui Li 0006, Yingtang Yang |
Comput. Commun. | 2 |
| 2020 | Cloud-based lightweight secure RFID mutual authentication protocol in IoT
Kai Fan 0001, Kuan Zhang 0001, Yintang Yang |
Inf. Sci. | 1 |
| 2020 | A secure and efficient outsourced computation on data sharing scheme for privacy computing
Kai Fan 0001, Kuan Zhang 0001, Hui Li 0006, Yintang Yang |
J. Parallel Distributed Comput. | 1 |
| 2020 | A dynamic and verifiable multi-keyword ranked search scheme in the P2P networking environment
Haoyang Wang 0005, Kai Fan 0001, Hui Li 0006, Yintang Yang |
Peer-to-Peer Netw. Appl. | 2 |
| 2019 | A Secure Cross-Domain Access Control Scheme in Social NetworksabstractAs the number of people using social networks increases, users are often assigned to different domains for better digital right management. However, they are no longer satisfied with accessing data just in one domain with the rapid expansion of information, so there is an urgent need for a way to access data among different domains while guarantee their privacy and security. In this paper, we propose a cross-domain access control scheme based on multi-authority attribute-based encryption for big data from social networks. In our construction, we use a hybrid encryption algorithm that based on symmetric encryption and CP-ABE not only to achieve cross-domain access control, but also to improve the efficiency of the system. Besides, the trusted proxy users for proper storage of symmetric keys ensures the security of the system. Meanwhile, the use of an inter-domain trusted proxy user, instead of an intra-domain data owner to formulate an access control policy, reduces the huge computational overhead associated with the ciphertext re-encryption technology and greatly improves the efficiency of the entire system. Finally, security analysis and performance analysis show that the proposed scheme is a secure and trusted networking. Kai Fan 0001, Yuhan Bai, Huiyue Xu, Hui Li 0006, Yintang Yang |
ICC | 1 |
| 2019 | A blockchain-based clock synchronization Scheme in IoT
Kai Fan 0001, Shili Sun, Zheng Yan 0002, Hui Li 0006, Yintang Yang |
Future Gener. Comput. Syst. | 1 |
| 2019 | Efficient and privacy preserving access control scheme for fog-enabled IoT
Kai Fan 0001, Huiyue Xu, Longxiang Gao, Hui Li 0006, Yintang Yang |
Future Gener. Comput. Syst. | 1 |
| 2019 | Blockchain-Based Secure Time Protection Scheme in IoTabstractInternet of Things (IoT) has been developed rapidly to make our life easier. In many IoT applications (e.g., smart homes, healthcare, etc.), all the IoT devices should be synchronized in time. However, some malicious nodes located in the IoT network can influence the time synchronization, which may interrupt the IoT system and lead to serious accidents. Therefore, it is critical and challenging to guarantee the accuracy and consistency of time during the time synchronization among all the IoT devices. In this paper, we propose a blockchain-based scheme to assure the security during time synchronization in IoT. Specifically, a publicly verifiable ledger is utilized to record and broadcast time, which can minimize many attacks from external environments. The use of multiple time sources can avoid the vulnerabilities caused by the centralized generation of accurate time. Moreover, the decentralized structure of this scheme has the advantage of adapting the changes of network topology. By employing an improved practical Byzantine fault tolerance consensus mechanism, time synchronization can be implemented efficiently. At last, the analysis results show that our proposed scheme can achieve the desired security with high efficiency. Kai Fan 0001, Shangyang Wang, Yanhui Ren, Kan Yang 0001, Zheng Yan 0002, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 1 |
| 2018 | Blockchain-based efficient privacy preserving and data sharing scheme of content-centric network in 5GabstractNow, the authors’ life is full of vast amount of information, the era of information has arrived. So the content‐centric networks face severe challenges in dealing with a huge range of content requests, bringing protection and sharing concerns of the content. How to protect information in the network efficiently and securely for the upcoming 5G era has become a problem. The authors propose a scheme based on a blockchain to solve the privacy issues in content‐centric mobile networks for 5G. The authors implement the mutual trust between content providers and users. Besides, the openness and tamper‐resistant of the blockchain ledger ensure the access control and privacy of the provider. With the help of a miner, selected from users, the authors can maintain the public ledger expediently. Also, in return, the authors share the interesting data with low overhead, network delay and congestion, and then achieve green communication. Kai Fan 0001, Yanhui Ren, Yue Wang 0043, Hui Li 0006, Yingtang Yang |
IET Commun. | 1 |
| 2018 | Secure and private key management scheme in big data networking
Kai Fan 0001, Shuyang Lou, Ruidan Su, Hui Li 0006, Yintang Yang |
Peer-to-Peer Netw. Appl. | 1 |
| 2018 | Secure ultra-lightweight RFID mutual authentication protocol based on transparent computing for IoV
Kai Fan 0001, Wei Wang 0144, Wei Jiang 0010, Hui Li 0006, Yintang Yang |
Peer-to-Peer Netw. Appl. | 1 |
| 2018 | Secure, efficient and revocable data sharing scheme for vehicular fogs
Kai Fan 0001, Junxiong Wang, Xin Wang 0224, Hui Li 0006, Yintang Yang |
Peer-to-Peer Netw. Appl. | 1 |
| 2018 | Lightweight RFID Protocol for Medical Privacy Protection in IoTabstractTraditional medical privacy data are at a serious risk of disclosure, and many related cases have occurred over the years. For example, personal medical privacy data can be easily leaked to insurance companies, which not only compromises the privacy of individuals, but also hinders the healthy development of the medical industry. With the continuous improvement of cloud computing and big data technologies, the Internet of Things technology has been rapidly developed. Radio frequency identification (RFID) is one of the core technologies of the Internet of Things. The application of the RFID system to the medical system can effectively solve this problem of medical privacy. RFID tags in the system can collect useful information and conduct data exchange and processing with a back-end server through the reader. The whole process of information interaction is mainly in the form of ciphertext. In the context of the Internet of Things, the paper presents a lightweight RFID medical privacy protection scheme. The scheme ensures security privacy of the collected data via secure authentication. The security analysis and evaluation of the scheme indicate that the protocol can effectively prevent the risk of medical privacy data being easily leaked. Kai Fan 0001, Wei Jiang 0010, Hui Li 0006, Yintang Yang |
IEEE Trans. Ind. Informatics | 1 |
| 2017 | Multi-Keyword Fuzzy and Sortable Ciphertext Retrieval Scheme for Big DataabstractMore and more sensitive information of big data are being now stored in the cloud for it offers quality service and convenient management. But the Cloud Server cannot be fully trusted because it may leak information which raises security and privacy concerns of the stored data. Therefore, sensitive data has to be encrypted before shifted to the cloud. It is a great convenience for authorized users to directly retrieve the encrypted data stored in the cloud by keyword search. As we all known, returning all the matching documents is a waste of network bandwidth. Although there are some schemes that support sorting fuzzy multi-keyword search, and they are generally based on edit distance to looking for fuzzy alternatives set, which leads to significantly larger index file size and higher search complexity. Then we rank the search results according to the matching score between keywords and documents. In this paper, we give a novel multi-keyword fuzzy and sortable search scheme. We use n-gram technology to realize fuzzy search and give a novel ranking search scheme based on the fuzzy multi- keyword search. For the matching files may be more than one, there are differences between the original query keywords and the fuzzy keywords. When ranking files, we will not only consider the relevance score between the index keywords and the documents, but also the similarity between the query and keywords. Thus we calculate the comprehensive matching score of the file to the set of query keywords, which is more efficient and accurate. Kai Fan 0001, Junxiong Wang, Hui Li 0006, Yintang Yang |
GLOBECOM | 1 |
| 2017 | An ultra-lightweight RFID authentication scheme for mobile commerce
Kai Fan 0001, Nan Ge, Yuanyuan Gong, Hui Li 0006, Ruidan Su, Yintang Yang |
Peer-to-Peer Netw. Appl. | 1 |
| 2017 | Proxy-assisted access control scheme of cloud data for smart cities
Kai Fan 0001, Junxiong Wang, Xin Wang 0224, Yintang Yang |
Pers. Ubiquitous Comput. | 1 |
| 2017 | NFC Secure Payment and Verification Scheme with CS E-TicketabstractAs one of the most important techniques in IoT, NFC (Near Field Communication) is more interesting than ever. NFC is a short-range, high-frequency communication technology well suited for electronic tickets, micropayment, and access control function, which is widely used in the financial industry, traffic transport, road ban control, and other fields. However, NFC is becoming increasingly popular in the relevant field, but its secure problems, such as man-in-the-middle-attack and brute force attack, have hindered its further development. To address the security problems and specific application scenarios, we propose a NFC mobile electronic ticket secure payment and verification scheme in the paper. The proposed scheme uses a CS E-Ticket and offline session key generation and distribution technology to prevent major attacks and increase the security of NFC. As a result, the proposed scheme can not only be a good alternative to mobile e-ticket system but also be used in many NFC fields. Furthermore, compared with other existing schemes, the proposed scheme provides a higher security. Kai Fan 0001, Panfei Song, Zhao Du, Haojin Zhu, Hui Li 0006, Yintang Yang, Xinghua Li 0001, Chao Yang 0016 |
Secur. Commun. Networks | 1 |
| 2016 | Cloud-Based Lightweight RFID Healthcare Privacy Protection ProtocolabstractResearchers and engineers have paid more attention to cloud-based application systems, whose features are virtualization and services provisioning. Fortunately the technology can be just right to healthcare. Meanwhile, security has also become more challenging. Although many cloud-based RFID authentication protocols have been proposed, some of them only improve the function and performance without considering security and privacy, and most of them are heavyweight. It is not appropriate in the field of healthcare, because improving the trustworthiness of anonymous virtual computing services should be the primary consideration. So we propose a lightweight privacy protection authentication scheme which can be applied in the cloud environment, in the scheme, service providers could be anonymous or unknown to the application consumer. Assuming many hospitals build a cloud platform together, the information of patient and his physician will be stored anonymously in the cloud. Patient can go to a doctor in any one hospital with a unique RFID tag. Reader may be fixed or mobile; Readers read tags and upload collected data to the cloud for further processing in real time. Compared with some traditional schemes, our scheme is lightweight, cost-efficient, elastic scalability, real-time, and easy to against synchronization attack. Kai Fan 0001, Wei Wang 0144, Yue Wang 0043, Hui Li 0006, Yintang Yang |
GLOBECOM | 1 |
| 2016 | NFC Secure Payment and Verification Scheme for Mobile Payment
Kai Fan 0001, Panfei Song, Zhao Du, Haojin Zhu, Hui Li 0006, Yintang Yang, Xinghua Li 0001, Chao Yang 0016 |
WASA | 1 |
| 2016 | Lightweight and ultralightweight RFID mutual authentication protocol with cache in the reader for IoT in 5GabstractAs one of the core techniques in 5G, the Internet of Things is more interested than ever. Furthermore, radio frequency identification RFID plays a crucial role in Internet of Things development. Although the low-cost RFID system has wide prospect, it has to face with huge challenges because of potential security risks, privacy problems, and efficiency because of its restrictions on processing, storage, and power in RFID tags. One of the possible solutions in secure authentication of the low-cost RFID system is the lightweight RFID authentication protocol. A lightweight RFID mutual authentication protocol with cache in the reader is proposed in this paper, named LRMAPC. The LRMAPC can greatly reduce the computational and transmission cost. Especially, it can reduce computational costs greatly when a large number of tags want to be authenticated. We prove the correctness of LRMAPC using GNY logic. Compared with some existing works, LRMAPC achieves higher efficiency and stronger security. Furthermore, we developed LRMAPC into ULRMAPC, an ultralightweight RFID mutual authentication protocol with cache in the reader. Compared with SASI and Gossamer protocols, ULRMAPC also achieves higher efficiency and stronger security in storage and computation cost. Copyright © 2015 John Wiley & Sons, Ltd. Kai Fan 0001, Yuanyuan Gong, Hui Li 0006, Yintang Yang |
Secur. Commun. Networks | 1 |
| 2015 | Secure and Efficient Personal Health Record Scheme Using Attribute-Based EncryptionabstractWith the rapid development of the cloud computing, personal health record (PHR) has attracted great attention of many researchers all over the world recently. However, PHR, which is often outsourced to be stored at a third party, has many security and efficiency issues. Therefore, the study of secure and efficient Personal Health Record Scheme to protect users' privacy in PHR files is of great significance. In this paper, we present a secure and efficient Personal Health Record scheme called SE-PHR. In the SE-PHR scheme, we divide the users into personal domain (PSD) and public domain (PUD) logically. In the PSD, the Key-Aggregate Encryption called KAE is exploited. For the users of PUD, we use outsource-able multi-authority attribute-based encryption (MA-ABE) to largely eliminate the overhead for users and support efficient attribute revocation without updating the user's private key. Our scheme also presents a new algorithm which enables dynamic modification of access policies. Function and performance testing results show the security and efficiency of the proposed SE-PHR. Kai Fan 0001, Nana Huang, Yue Wang 0043, Hui Li 0006, Yintang Yang |
CSCloud | 1 |
| 2015 | Ciphertext Retrieval in Super-Peer P2P NetworkabstractSuper-peer p2p networks inherit the advantages of P2P networks, such as pooling together the shared data (documents in our system) across peers, self- organizing, and fault-tolerance. Most of the searches in p2p networks are plaintext-based and do not satisfy the pressing demands for high security in massive information sharing applications. In this paper, a super-peer p2p system is designed that supports ciphertext-based search for relevant documents. In the proposed system, a super-peer which contains all the encrypted index of documents in all the peers subordinate to it is added to the p2p system, and the indexing efficiency is improved by utilizing the indexing structure that binary trees are nested in a B+ tree. Finally, the experimental results demonstrate the proposed scheme can achieve acceptable security and efficiency. Kai Fan 0001, Hai Deng, Hui Li 0006, Yintang Yang |
GLOBECOM | 1 |
| 2015 | ULRAS: Ultra-Lightweight RFID Authentication Scheme for Mobile Device
Kai Fan 0001, Nan Ge, Yuanyuan Gong, Hui Li 0006, Ruidan Su, Yintang Yang |
WASA | 1 |
| 2014 | RSEL: revocable secure efficient lightweight RFID authentication schemeabstractSUMMARY Radio frequency identification (RFID) has been regarded as one of the 10 important technologies in the 21st century. Because of its capability to rapidly and accurately collect and process data in real‐time, RFID has been widely applied in many areas, such as Internet of Things and Smart Grid. However, the existing security threats become more severe toward RFID authentication scheme. The traditional security mechanisms cannot be used in RFID directly because of the limitations of processing capability, storage space, and power supply of RFID tags. In this paper, we propose a revocable secure efficient lightweight RFID authentication scheme (RSEL). To achieve authentication efficiency, the key of the tag is chosen to reduce the number of hash computing in the database. Furthermore, the key is stored in the database and updated constantly with the tag to prevent the tracking and synchronization attacks. The valid period of each tag is stored in the database so that RSEL can revoke the expired tag. The correctness of RSEL has been proved using GNY logic. The performance of RSEL in terms of security and efficiency is evaluated. Compared with other existing approaches, RSEL achieves stronger security and higher efficiency. Copyright © 2013 John Wiley & Sons, Ltd. Kai Fan 0001, Hui Li 0006, Xiaohui Liang 0002, Xuemin Shen, Yintang Yang |
Concurr. Comput. Pract. Exp. | 1 |
| 2010 | Efficient ID-based registration protocol featured with user anonymity in mobile IP networksabstractA secure and efficient ID-based registration protocol with user anonymity is proposed in this paper for IP-based mobile networks. The protocol minimizes the registration delay through a minimal usage of the identity (ID)-based signature scheme that eliminates expensive pairing operations. User anonymity is achieved via a temporary identity (TID) transmitted by a mobile user, instead of its true identity. Additional replay protection from a Foreign Agent (FA) is included in the registration messages to prevent a possible replay attack. A formal correctness proof of the protocol using Protocol Composition Logic (PCL) is presented. Numerical analysis and computer simulation results demonstrate that the proposed protocol outperforms the existing ones in terms of the registration delay, the registration signaling traffic, and the computational load on a Mobile Node (MN) while improving security. For example, the proposed protocol reduces the registration delay up to 49.3 percent approximately, comparing to Yang's protocol. Lanjun Dang, Weidong Kou, Hui Li 0006, Junwei Zhang 0001, Xuefei Cao, Kai Fan 0001 |
IEEE Trans. Wirel. Commun. | 7 |
| 2009 | Security Analysis of the Kerberos Protocol Using BAN LogicabstractKerberos protocol is a famous identity authentication protocol and it is widely used in the network as a standard. But there is still not a strict proof of it base on the Formal method. That is very nervous for the users. So a security analysis of the Kerberos protocol using BAN logic is proposed in this paper, and the reliability, practicability and security of Kerberos protocol are proved. Kai Fan 0001, Hui Li 0006, Yue Wang 0043 |
IAS | 1 |
| 2009 | A New Abuse-Free Fair Electronic Payment ProtocolabstractTo solve the problem of the abuse in electronic payment protocols, a new abuse-free fair electronic payment protocol is proposed in this paper. The proposed protocol solves the problems in Parks' protocol and furthermore it solves the abuse using off-line trusted third party (TTP). The security and fairness are also possessed in the protocol. Kai Fan 0001, Yue Wang 0043, Hui Li 0006 |
IAS | 1 |
| 2007 | A Watermarking Scheme in the Encrypted Domain for Watermarking Protocol
Lanjun Dang, Weidong Kou, Jun Zhang 0010, Zan Li 0001, Kai Fan 0001 |
Inscrypt | 6 |
| 2007 | Mobile ip registration in certificateless public key infrastructureabstractA secure and efficient mobile IP (MIP) registration protocol using certificateless signature scheme is proposed. The protocol minimises the registration time through minimal usage of an efficient certificateless signature scheme between a foreign agent (FA) and a home agent (HA). Protocol parameters can be kept resynchronised by reusing the initial values in the MIP registration in case the synchronisation between a mobile node (MN) and HA is lost. User anonymity is achieved via a temporary identity transmitted by a mobile user, instead of its true identity. Additional replay protection from the FA is included in the registration messages to prevent a possible replay attack. Numerical results and performance analyses demonstrate that the proposed protocol outperforms the existing ones in terms of the registration time, registration signalling traffic and computational load on an MN while providing improved security. For example, the proposed protocol reduces the registration time up to ∼83% compared with the protocol from Yang. Lanjun Dang, Weidong Kou, Nan Dang, Hui Li 0006, Kai Fan 0001 |
IET Inf. Secur. | 6 |