VLDB 2026 Research / reviewers in the wild / expert
Leixiao Cheng
dblp:210/4920
· DBLP profile ↗
16ranked-venue papers
10as first author
13since 2021 · last 2026
0000-0002-7231-0636ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 5 first-author · 5 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Proxy-Free Public-Key Authenticated Updatable and Searchable Encryption for Cloud StorageabstractPublic key authenticated encryption with keyword search (PAEKS) is a cryptographic primitive applicable in cloud storage systems. It empowers cloud servers to conduct searches on encrypted data without decryption while safeguarding against the brute-force attack known as insider-keyword-guessing attacks (IKGAs). In contrast to the pioneering primitive PEKS, which is vulnerable to IKGAs, PAEKS incurs additional computational and communication overhead due to the sender keys' involvement in encryption and trapdoor-generation processes. Although the recent work improves the efficiency of PAEKS by re-encrypting received ciphertexts, the requirement of a fully trusted proxy is rather costly for users to implement in practice. To reduce the economic cost and to keep a high efficiency, we propose a new primitive ofProxy-free Public-key Authenticated Updatable and Searchable Encryption(PF-AUKS). The key concept is to let the cloud server, instead of the proxy, directly convert different-source ciphertexts into a uniform format securely. We propose a concrete PF-AUKS scheme that supports fast search, constant trapdoor generation, and secure ciphertext update. Theoretical evaluation and experimental results illustrate high algorithm running speed and retrieval efficiency. We formally define the security model of PF-AUKS and prove that our scheme is secure under this model. Hongbo Li 0004, Willy Susilo, Jian Shen 0001, Chen Wang 0015, Leixiao Cheng, Qiong Huang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Cloud-aided attribute-based encryption with efficient tracing and accountability auditing
Fei Meng 0004, Leixiao Cheng |
J. Syst. Archit. | 2 |
| 2025 | TSR-ABE: Traceable and Server-Aided Revocable Ciphertext-Policy Attribute-Based Encryption Under Static AssumptionsabstractThe cloud server is a versatile platform for data storage, with users increasingly uploading personal data to public servers to circumvent costly local storage. However, the server is not entirely honest, as it may potentially compromise user data privacy. Ciphertext-policy attribute-based encryption (CP-ABE) is a highly flexible cryptographic technique for ensuring access control over encrypted data in cloud storage applications. To prevent unauthorized access, traceability and revocability are two necessary requirements for CP-ABE system. Nevertheless, existing white-box traceable and revocable CP-ABE schemes suffer from several imitations: 1) Whether direct revocation or indirect revocation is applied, neither type of the revocation mode is well compatible with the trace function. 2) Moreover, all of the previous white-box traceable CP-ABE schemes rely on non-static assumptions to prove traceability. Ideally, a scheme provably secure under static complexity assumptions is preferable. To deal with these issues, we propose a novel traceable and server-aided revocable CP-ABE (TSR-ABE) scheme based on static assumptions. Specifically, our revocation mode works well with the trace function, and we prove the adaptive chosen-plaintext attack security and traceability of our scheme via the well-known dual system encryption methodology. Compared with many previous traceable CP-ABE schemes, regardless of whether they support revocation or not, we remove the need to introduce an additional l-SDH assumption to prove the traceability of the scheme. In addition, our scheme is more practical due to its lower private key size, lower decryption costs and lower tracing costs. As a result, we strengthen current research from the perspective of both security and efficiency. Fei Meng 0004, Leixiao Cheng |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | STR-ABKS: Server-Aided Traceable and Revocable Attribute-Based Encryption With Keyword SearchabstractAttribute-based encryption with keyword search (ABKS) is a powerful cryptographic primitive achieving search functionality and access control for the encrypted data outsourced to the cloud. Traceability and revocability are two significant requirements for ABKS system that enable tracing the owner of a maliciously leaked secret key and revoking the key. Recently, Varri et al. proposed two ABKS schemes with traceability and revocability in the IEEE Internet of Things Journal and Journal of Systems Architecture. However, we present a cryptanalysis demonstrating that neither of these two schemes is secure against the chosen keyword attack (CKA), which is a fundamental security requirement for ABKS system. In this article, we put forward a notion called server-aided traceable and revocable ABKS (STR-ABKS) and present a concrete STR-ABKS construction. In addition to traceability, revocability and CKA resistance, our STR-ABKS construction enjoys several notable features: 1) Large Universe Attributes: This property enlarges the practical applications by supporting a flexible number of attributes; 2) Constant User Secret Key: The user’s secret key is not related to attributes as in other ABKS schemes; 3) Fast Tracing: Tracing a constant user secret key only requires two pairing operations; and 4) Constant Trapdoor: The size of the trapdoor inherits the size of the user secret key used to generate it. Overall, our construction offers both security, functionality and practical efficiency. Fei Meng 0004, Leixiao Cheng |
IEEE Internet Things J. | 2 |
| 2024 | Server-Aided Public Key Authenticated Searchable Encryption With Constant Ciphertext and Constant TrapdoorabstractPublic key authenticated encryption with keyword search (PAEKS) is an advanced asymmetric searchable encryption technique secure against inside keyword guessing attacks. A common application of PAEKS is searching for encrypted Electronic Health Records (EHR) within a healthcare cloud. Nevertheless, the standard PAEKS necessitates the sender (e.g., doctor) to separately encrypt the same keyword with each receiver’s public key to enable multiple researchers to search for the encrypted EHR. Similarly, to search for encrypted EHRs from multiple senders, a receiver (e.g., researcher) must create distinct trapdoors for the same keyword, using each sender’s public key separately. These features render the standard PAEKS impractical for use in multi-user scenarios. To resolve this challenge, we introduce the server-aided public key authenticated encryption with keyword search (SA-PAEKS) scheme, the novelty of which lies in the incorporation of two additional servers, specifically a sender server and a receiver server. With the help of these two servers, the sender encrypts the keyword just once, allowing any receiver to search for his encrypted EHR, and the receiver creates a single trapdoor to search for the encrypted EHR of any sender. When multiple sender servers and receiver servers are introduced in the system, our scheme is scalable in the sense that the size of the ciphertext and trapdoor remains constant. Furthermore, we provide a generic approach to achieve ciphertext deduplication and fast search, enhancing the overall efficiency. This approach is compatible with any PAEKS scheme and may be of independent interest. Finally, we provide both theoretical and experimental evaluations of our scheme, demonstrating its competitive performance. Leixiao Cheng, Fei Meng 0004 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Certificateless Public Key Authenticated Searchable Encryption With Enhanced Security Model in IIoT ApplicationsabstractIn Industrial Internet of Things, powerful cloud servers are needed to process substantial sensitive industrial data, which should be encrypted before being uploaded to the cloud. To retrieve encrypted data, certificateless public key authenticated encryption with keyword search (CLPAEKS) is proposed. It has three advantages: 1) no certificate management problem; 2) no key escrow problem; and 3) inside keyword guessing attack resistance. The basic security requirements of current CLPAEKS schemes are ciphertext indistinguishability (CI security) and trapdoor indistinguishability (TI security) in the single-challenge setting. However, these security requirements are incomplete, since some necessary real-world scenarios are not considered: 1) the multichallenge setting to capture scenarios where multiple keywords may be embedded in one file or search query and 2) the fully chosen keyword attack, which allows the adversary to obtain ciphertext or trapdoor of any keyword. In this article, we formalize two enhanced security models for the CLPAEKS system to both capture the multichallenge setting and resist against fully chosen keyword attacks. Then, we provide a cryptanalysis on some of previous CLPAEKS schemes to better understand the necessity of these security models. Furthermore, we propose the first CLPAEKS scheme provably secure in our enhanced security models. Compared with previous CLPAEKS schemes, our scheme provides stronger security guarantee for the privacy of both ciphertext keyword and target keyword. We also evaluate the performance of our CLPAEKS scheme and optimize the efficiency of our scheme by performing most of the computation offline. As a result, the online efficiency of our CLPAEKS scheme is comparable to other schemes optimized using the same techniques. Leixiao Cheng, Fei Meng 0004 |
IEEE Internet Things J. | 1 |
| 2023 | Public key authenticated searchable encryption against frequency analysis attacks
Leixiao Cheng, Fei Meng 0004 |
Inf. Sci. | 1 |
| 2023 | Security-enhanced public-key authenticated searchable encryption
Leixiao Cheng, Jing Qin 0002, Fei Meng 0004 |
Inf. Sci. | 1 |
| 2023 | An Improvement on "CryptCloud$^{+}$+: Secure and Expressive Data Access Control for Cloud Storage"abstractRecently, Ning et al. proposed the “CryptCloud$^{+}$: Secure and Expressive Data Access Control for Cloud Storage” inIEEE Transaction on Services Computing. This work provided two versatile ciphertext-policy attribute-based encryption (CP-ABE) schemes to achieve flexible access control on encrypted data, namely ATER-CP-ABE and ATIR-CP-ABE, both of which have attractive advantages, such as white-box malicious user traceability, semi-honest authority accountability, public auditing and user revocation. However, we find a bug of access control in both schemes, i.e., a non-revoked user with attribute set$S$can decrypt the ciphertext$ct$encrypted under any access policy$(A,\rho )$, regardless of whether$S$satisfies$(A,\rho )$or not. This paper carefully analyzes the bug, and makes an improvement on Ning's pioneering work, so as to fix it. Leixiao Cheng, Fei Meng 0004 |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | Public Key Authenticated Encryption with Keyword Search from LWE
Leixiao Cheng, Fei Meng 0004 |
ESORICS (1) | 1 |
| 2021 | Server-Aided Revocable Attribute-Based Encryption Revised: Multi-User Setting and Fully Secure
Leixiao Cheng, Fei Meng 0004 |
ESORICS (2) | 1 |
| 2021 | ABDKS: attribute-based encryption with dynamic keyword search in fog computing
Fei Meng 0004, Leixiao Cheng |
Frontiers Comput. Sci. | 2 |
| 2021 | Security analysis of Pan et al.'s "Public-key authenticated encryption with keyword search achieving both multi-ciphertext and multi-trapdoor indistinguishability"
Leixiao Cheng, Fei Meng 0004 |
J. Syst. Archit. | 1 |
| 2020 | SKCN: Practical and Flexible Digital Signature from Module Lattice
Boru Gong, Leixiao Cheng, Yunlei Zhao |
ACISP | 2 |
| 2020 | AKC-Based Revocable ABE Schemes from LWE AssumptionabstractThe emergence of quantum computing threatens many classical cryptographic schemes, leading to the innovations in public-key cryptography for postquantum cryptography primitives and protocols that resist to quantum attacks. Lattice-based cryptography is considered to be one of the promising mathematical approaches to achieving security resistant to quantum attacks, which could be built on the learning with errors (LWE) problem and its variants. The fundamental building blocks of protocols for public-key encryption (PKE) and key encapsulation mechanism (KEM) submitted to the National Institute of Standards and Technology (NIST) based on LWE and its variants are called key consensus (KC) and asymmetric key consensus (AKC) by Jin et al. They are powerful tools for constructing PKE schemes. In this work, we further demonstrate the power of KC/AKC by proposing two special types of PKE schemes, namely, revocable attribute-based encryption (RABE). To be specific, on the basis of AKC and PKE/KEM protocols submitted to the NIST based on LWE and its variants, combined with full-rank difference, trapdoor on lattices, sampling algorithms, leftover hash lemma, and binary tree structure, we propose two directly revocable ciphertext-policy attribute-based encryption (DR-ABE) schemes from LWE, which support flexible threshold access policies on multivalued attributes, achieving user-level and attribute-level user revocation, respectively. Specifically, the construction of the ciphertext is derived from AKC, and the revocation list is defined and embedded into the ciphertext by the message sender to revoke a user in the user-level revocable scheme or revoke some attributes of a certain user in the attribute-level revocable scheme. We also discuss how to outsource decryption and reduce the workload for the end user. Our schemes proved to be secure in the standard model, assuming the hardness of the LWE problem. The two schemes imply the versatility of KC/AKC. Leixiao Cheng, Fei Meng 0004, Xianmeng Meng |
Secur. Commun. Networks | 1 |
| 2017 | Compact Lossy and All-but-One Trapdoor Functions from Lattice
Leixiao Cheng, Quanshui Wu, Yunlei Zhao |
ISPEC | 1 |