Qinlong Huang

dblp:22/8338 · DBLP profile ↗
← Back
27ranked-venue papers
19as first author
19since 2021 · last 2026
0000-0002-0378-0941ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 8 · 7 first-author · 5 since 2021Software engineering, systems software and programming languages · 6 · 5 first-author · 5 since 2021Security and privacy · 5 · 3 first-author · 3 since 2021Computer networks · 4 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Sublinear generic Boolean keyword search with enhanced security in cloud-assisted IoMT
Guanyu Yan, Qinlong Huang, Rui Jian
J. Inf. Secur. Appl.2
2026 FSEdit: Privacy-Preserving and Security-Enhanced Controllable Editing Framework for Cloud Storage
Qinlong Huang, Caiqun Shi, Xiyu Liang
IEEE Trans. Computers1
2026 TSFlow: Time-Aware Secure Flow Control for Fine-Grained Data Sharing in Mobile Edge-Cloud
abstract
The rise of edge-cloud computing has accelerated data sharing among mobile users. To resist malicious senders within organizations from leaking sensitive data, access control encryption (ACE) schemes have been employed to secure data f lows, in which each sender obtains an encryption key according to the access control policy to encrypt the data, and a sanitizer (i.e., the edge node) inspects all shared data between the sender and receiver. Although attribute-based ACE schemes have been put forward to support fine-grained data sharing, they lack temporal constraints on write control, which is crucial in mobile data sharing scenarios, and have high sanitization overhead at the edge node. In addition, they only provide selective security and are therefore vulnerable to adaptive adversaries. To this end, we propose TSFlow, a time-aware secure flow control framework in mobile edge-cloud that regulates which senders can transmit data to which receivers during the authorized time interval, preventing malicious sending by expired senders. At its core is TA-ACE, a time-aware attribute-based ACE that issues each sender an encryption key tied to an expressive access structure and a time interval. Encrypted data can be sanitized at the edge only if it is well-formed with a valid encryption key and encrypted within the time interval, and any legitimate receiver satisfying the access structure can decrypt the sanitized ciphertext. We formally prove that TA-ACE satisfies the adaptive no-read and no-write rules, and demonstrate the reasonable efficiency of TSFlow through experiments for secure flow control in mobile edge-cloud.
Qinlong Huang, Caiqun Shi, Yudi Zhang 0001, Willy Susilo
IEEE Trans. Mob. Comput.2
2025 Content-Moderated Bilateral Access Control for Privacy-Preserving Cloud Data Sharing Services
abstract
Cloud computing facilitates scalable data sharing across multiple organizations and users, but also raises concerns about data privacy. Matchmaking encryption (ME) is a prominent technique that enforces bilateral access control in cloud services such as cloud marketplace, allowing both senders and receivers to specify policies for the encrypted data to be revealed. However, receivers may be at risk of being exposed to malicious or harmful content, thus undermining their trust in cloud service platforms. To this end, we introduce MBAC, a content-moderated bilateral access control framework for privacy-preserving cloud data sharing services, which allows receivers to acquire data from authentic senders while preserving their anonymity, and report malicious content in a verifiable manner, i.e., empowering the service provider to hold senders accountable. MBAC is built upon a novel primitive called franking broadcast ME (FBME), which generates a franking signature for the data by designating the service provider as the moderator to ensure accountability and deniability, and encrypts both the data and its franking signature while embedding the sender secret key for privacy and authenticity. We then present a concrete construction of FBME from key-private public key encryption, strongly unforgeable one time signature and non-interactive zero-knowledge proof. Formal security analysis and extensive experiments demonstrate that MBAC provides efficient bilateral access control and content moderation for cloud data sharing services.
Willy Susilo, Yudi Zhang 0001, Yumei Li 0003, Qinlong Huang
IEEE Trans. Cloud Comput.5
2025 Privacy-Preserving and Autonomous-Path Access Delegation for Mobile Cloud Healthcare Systems
abstract
Mobile cloud healthcare systems are gaining popularity due to their remote data collection through mobile devices and flexible data access through cloud services. The collected electronic health records (EHRs) are generally encrypted on mobile devices before being uploaded to the cloud, and accessed only by specific users. This incurs inconvenience when re-sharing EHRs with new receivers, especially in heterogeneous scenarios. Although cross-domain proxy re-encryption (CD-PRE) schemes have been studied to transform ciphertexts between different cryptosystems, they can neither support EHRs' controlled multi-hop delegation between trusted delegatees chosen by the delegator nor prevent EHRs' privacy inference through delegatees' information. To this end, we present CAP-PRE for mobile cloud healthcare systems, which is a multi-hop CD-PRE scheme that supports lightweight encryption and re-encryption key generation on mobile devices, as well as privacy-preserving and autonomous-path access delegation. In CAP-PRE, the delegator creates a delegation path that includes preferred delegatees, and generates corresponding re-encryption keys which enables the cloud server to convert the collected ciphertext to an inner product ciphertext for privacy-preserving EHR re-sharing and pass the access rights along the delegation path for controlled multi-hop delegation. We finally prove the security of CAP-PRE and show the better performance of CAP-PRE with extensive experiments.
Genghui Chi, Qinlong Huang, Caiqun Shi
IEEE Trans. Mob. Comput.2
2024 An Efficient and Verifiable Encrypted Data Filtering Framework Over Large-Scale Storage in Cloud Edge
abstract
The rapid growth of edge computing is accelerating data subscriptions between cloud platforms and mobile subscribers, but sensitive information in these data faces security and privacy concerns. Fortunately, matchmaking attribute-based encryption (MABE) as a new type of encrypted data filtering mechanism has been introduced in cloud edge, which not only enforces fine-grained access control over the encrypted data, but also allows subscribers to dynamically filter data of interest from authentic publishers through edge nodes. However, filtering entire ciphertext collection in linear time is not feasible for large-scale data storage, and edge nodes may return mismatched or incomplete results due to corruption or compromise. To this end, we propose VDFilter, an efficient and verifiable encrypted data filtering framework over large-scale storage in cloud edge. VDFilter first introduces a verifiable MABE as the underlying primitive, which achieves efficient data filtering in edge nodes with an inverted collection from the ciphertext collection, and verifies the soundness and completeness of filtered results with an accumulation tree. To accommodate the ciphertext collection from multiple publishers, VDFilter deploys the construction of the accumulation tree on the Intel SGX enclave within the cloud server, and utilizes authenticated data structures to guarantee secure and efficient filtered result verification. Finally, we provide formal security proofs for VDFilter and demonstrate its efficiency with extensive experiments. Compared with existing schemes, VDFilter is much more efficient in data storing and filtering even with verification operations, and its computational and communication overhead on the subscriber is also low.
Qinlong Huang, Boyu Lu
IEEE Trans. Inf. Forensics Secur.1
2024 Cross-Domain Inner-Product Access Control Encryption for Secure EMR Flow in Cloud Edge
abstract
The quality of medical services is improved by sharing electronic medical records (EMRs) across multiple medical institutions via cloud edge. However, EMRs contain private information about patients, and cloud servers are untrustworthy, thus they cannot be shared arbitrarily among senders and receivers. Access control encryption (ACE) is a preferred technique that produces encrypted EMRs and then restricts the capabilities of both senders and receivers to enforce the EMR flow via sanitizers. However, existing cross-domain ACE schemes employ a single sender authority to issue encryption keys for senders, which suffers from single point of failure and encryption key escrow that the sender authority can public EMRs arbitrarily. Moreover, they only support coarse-grained access structures such as AND gates, which is not suitable for flexible EMR sharing among medical institutions. To this end, we propose a cross-domain inner-product ACE (CD-IPACE) scheme that features decentralized encryption key generation and fine-grained access structures. Specifically, we construct CD-IPACE from inner-product encryption, threshold structure-preserving signature instantiated with a distributed key generation protocol, and non-interactive zero-knowledge proof, which prevents individual sender authorities from sending ciphertexts, and also protects both data and receiver privacy. Then, we design a secure EMR flow system in cloud edge named ESFlow based on CD-IPACE, which employs edge nodes as sanitizers to check encrypted EMRs and discard illegal ones. Finally, we demonstrate the security and practicality of ESFlow via formal security analysis and extensive experiments.
Caiqun Shi, Qinlong Huang, Rui Jian, Genghui Chi
IEEE Trans. Inf. Forensics Secur.2
2023 Privacy-Preserving Traceable Attribute-Based Keyword Search in Multi-Authority Medical Cloud
abstract
In cloud-based electronic medical record (EMR) systems, attribute-based encryption (ABE) has been utilized to protect the confidentiality of EMRs and provide keyword search over the encrypted EMRs. However, existing schemes are designed for a single attribute authority, and lack sufficient user privacy protection. In this article, we introduce TABKS, a privacy-preserving traceable attribute-based keyword search scheme in multi-authority medical cloud. First, we propose an anonymous EMR access control framework with multiple authorities, which provides user anonymity against the untrusted authorities. Second, we achieve traceable attribute-based Boolean keyword search, which enables the authorized user who satisfies the policy to conduct Boolean keyword search over the encrypted EMRs. In this process, TABKS improves the efficiency of legitimate users by partially decrypting the matched results, and also achieves efficient traitor trace by revealing the user identity from the trapdoor. Finally, we prove the security of TABKS against chosen plaintext attack and chosen keyword attack, and conduct extensive experiments with two real-world datasets to show the feasibility of TABKS.
Qinlong Huang, Guanyu Yan, Yixian Yang
IEEE Trans. Cloud Comput.1
2023 Secure and Fine-Grained Flow Control for Subscription-Based Data Services in Cloud-Edge Computing
abstract
With the popularity of cloud computing services, an increasing number of users begin to use subscription-based services. Due to the semi-trusted cloud servers that may access the outsourced data, and malicious senders who may publish unauthorized data or junk data, access control encryption (ACE) schemes have been studied recently to enforce secure data write control as well as read control. However, their access control policies are specified by the authority or publishers, which do not apply to the subscriptions. In this paper, we propose DSFlow, a secure and fine-grained flow control system for subscription-based data services. DSFlow is designed in the cloud-edge computing architecture, which employs edge nodes to control the communications between publishers and cloud servers by sanitizing the original ciphertexts to resist malicious publishers, and allows any valid subscriber to decrypt the sanitized ciphertexts in cloud. We introduce a receiver-policy attribute-based ACE (RA-ACE) scheme for DSFlow, which embeds the fine-grained access control policy within the receiver's decryption key. We give a concrete construction of RA-ACE from key-policy attribute-based encryption, structure-preserving signature and non-interactive zero-knowledge proof, and formally prove the no-read rule and no-write rule of RA-ACE. The experiments demonstrate the efficiency of DSFlow compared with existing schemes.
Qinlong Huang, Lixuan Chen
IEEE Trans. Serv. Comput.1
2023 Fast and Privacy-Preserving Attribute-Based Keyword Search in Cloud Document Services
abstract
Currently, various encryption techniques have been employed to protect the documents in cloud storage. In particular, attribute-based keyword search (ABKS) is a practical encryption primitive that can realize fine-grained access control and keyword based searching over encrypted documents. However, the search time in most of the existing ABKS schemes increases linearly with the size of document collection, which hinders the wide application of ABKS in cloud computing. To this end, we propose FAKS, a fast and privacy-preserving attribute-based keyword search system for cloud document services. Specifically, FAKS builds a Bloom filter tree structure from the document collection, which avoids matching keywords by traversing the entire collection. Then we introduce an attribute-based authenticated index retrieval (ABAIR) scheme to encrypt the Bloom filters in the tree node and retrieve the documents with the encrypted Bloom filters of the query keywords. Further, we give a concrete construction of FAKS from ABAIR to execute the keyword matching operations sublinearly in a top-down manner, and prove the security of FAKS against chosen keyword attack and keyword guessing attack. Finally, we conduct extensive experiments over the Wikipedia dataset, which show better and more stable search efficiency of FAKS compared to existing schemes.
Qinlong Huang, Qinglin Wei, Guanyu Yan, Yixian Yang
IEEE Trans. Serv. Comput.1
2023 Attribute-Based Expressive and Ranked Keyword Search Over Encrypted Documents in Cloud Computing
abstract
Attribute-based keyword search (ABKS) has been proposed to realize fine-grained access control and provide search service in cloud computing. However, most ABKS schemes focus on single or conjunctive keyword search, while the recent Boolean keyword search schemes only support monotonic query formula mainly involving AND, OR and threshold operators. How to support more expressive Boolean query formulas and return the corresponding accurate search results to users have become challenges for practical ABKS over ciphertexts. In this paper, we introduce an attribute-based expressive and ranked keyword search scheme over encrypted documents named ABERKS, which allows authorized users to submit expressive Boolean query formulas involving AND, OR, NOT and threshold operators. ABERKS utilizes a non-monotonic access tree structure to construct the query formula, and further leverages extended Boolean model to rank the search results. Specifically, the users are able to define the weights in the query formula, and get the relevance score of each matched ciphertext if the attributes and keywords are both satisfied. We prove the security of ABERKS against chosen keyword attack under selective ciphertext policy model and against keyword guessing attack, and also conduct extensive experiments to show the efficiency and practicality of ABERKS.
Qinlong Huang, Guanyu Yan, Qinglin Wei
IEEE Trans. Serv. Comput.1
2022 Unsupervised Acoustic-to-Articulatory Inversion with Variable Vocal Tract Anatomy
Qinlong Huang, Xihong Wu
INTERSPEECH2
2022 Unsupervised Inference of Physiologically Meaningful Articulatory Trajectories with VocalTractLab
Qinlong Huang, Xihong Wu
INTERSPEECH2
2022 P2GT: Fine-Grained Genomic Data Access Control With Privacy-Preserving Testing in Cloud Computing
abstract
With the rapid development of bioinformatics and the availability of genetic sequencing technologies, genomic data has been used to facilitate personalized medicine. Cloud computing, features as low cost, rich storage and rapid processing can precisely respond to the challenges brought by the emergence of massive genomic data. Considering the security of cloud platform and the privacy of genomic data, we first introduce P2GT which utilizes key-policy attribute-based encryption to realize genomic data access control with unbounded attributes, and employs equality test algorithm to achieve personalized medicine test by matching digitized single nucleotide polymorphisms (SNPs) directly on the users' ciphertext without encrypting multiple times. We then propose an enhanced scheme P2GT+, which adopts identity-based encryption with equality test supporting flexible joint authorization to realize privacy-preserving paternity test, genetic compatibility test and disease susceptibility test over the encrypted SNPs with P2GT. We prove the security of proposed schemes and conduct extensive experiments with the 1,000 Genomes dataset. The results show that P2GT and P2GT+ are practical and scalable enough to meet the privacy-preserving and authorized genetic testing requirements in cloud computing.
Qinlong Huang, Wei Yue 0004, Yixian Yang, Lixuan Chen
IEEE ACM Trans. Comput. Biol. Bioinform.1
2022 A Parallel Secure Flow Control Framework for Private Data Sharing in Mobile Edge Cloud
abstract
Nowadays, the rapid development of edge computing is accelerating the data sharing between cloud computing platforms and mobile users. These data often contain sensitive information, which faces severe leakage risks not only from the semi-trusted cloud servers but also from the malicious senders in the organizations. Fortunately, access control encryption (ACE) has been utilized to secure the data with access control policies, in which a sanitizer (e.g., the edge node) is employed to check all the communications between the sender and receiver, and drop illegal ciphertexts according to the access control policy. However, previous schemes have some limitations in mobile edge cloud, e.g., the sender's attributes are not strictly authenticated in the attribute-based access control policy, or the sanitization time is the bottleneck of fast data sharing. To this end, we introduce PSFlow, a parallel secure flow control framework for private data sharing in mobile edge cloud. First, we propose an attribute-based outsourced ACE (AOACE) scheme, which achieves secure fine-grained data read and write control, and reduces the computational cost of the sender and receiver with outsourced computations in edge nodes. Then, we propose a concrete construction of PSFlow from AOACE, and accelerate the sanitization process with parallel computing. Specifically, PSFlow parallelizes the sanitization operations with a multi-server model in each edge node, and optimizes the sanitization efficiency in each edge server by constructing a shared pool from the attribute universe. The experimental results show that PSFlow is more efficient and practical than previous schemes in mobile edge cloud.
Qinlong Huang, Lixuan Chen
IEEE Trans. Parallel Distributed Syst.1
2022 Privacy-Preserving Spatio-Temporal Keyword Search for Outsourced Location-Based Services
abstract
With the popularization of location-based services (LBS), encryption techniques have been utilized to protect data security when outsourcing LBS to cloud. However, existing schemes only consider spatial range search or keyword search, while expressive and practical search over encrypted LBS data is still a challenging problem. In this article, we introduce PrivSTL, a privacy-preserving spatio-temporal keyword search framework over the encrypted LBS data based on attribute-based encryption, linear encryption and RSA encryption. It allows mobile users to submit LBS query with spatial range, time interval and Boolean keyword expression, and provides accurate and authorized search by matching these query conditions and also the access policy. Then we introduce an extended scheme PrivSTG, which utilizes Geohash to divide the locations into grids, and outsources an encrypted index tree to cloud servers. PrivSTG improves the service efficiency by searching only over the ciphertexts in the surrounding grids of mobile user. Finally, we analyze the security of PrivSTL against chosen-plaintext, chosen-keyword and outside keyword-guessing attacks in generic bilinear group model, and show that PrivSTL guarantees the spatio-temporal keyword profile privacy, and also protects the query privacy. The experimental results indicate that our scheme is practical and efficient for outsourced LBS.
Qinlong Huang, Jiabao Du, Guanyu Yan, Yixian Yang, Qinglin Wei
IEEE Trans. Serv. Comput.1
2021 Secure Data Group Sharing and Conditional Dissemination with Multi-Owner in Cloud Computing
abstract
With the rapid development of cloud services, huge volume of data is shared via cloud computing. Although cryptographic techniques have been utilized to provide data confidentiality in cloud computing, current mechanisms cannot enforce privacy concerns over ciphertext associated with multiple owners, which makes co-owners unable to appropriately control whether data disseminators can actually disseminate their data. In this paper, we propose a secure data group sharing and conditional dissemination scheme with multi-owner in cloud computing, in which data owner can share private data with a group of users via the cloud in a secure way, and data disseminator can disseminate the data to a new group of users if the attributes satisfy the access policies in the ciphertext. We further present a multiparty access control mechanism over the disseminated ciphertext, in which the data co-owners can append new access policies to the ciphertext due to their privacy preferences. Moreover, three policy aggregation strategies, including full permit, owner priority and majority permit, are provided to solve the privacy conflicts problem caused by different access policies. The security analysis and experimental results show our scheme is practical and efficient for secure data sharing with multi-owner in cloud computing.
Qinlong Huang, Yixian Yang, Wei Yue 0004, Yue He 0002
IEEE Trans. Cloud Comput.1
2021 Privacy-Preserving Media Sharing with Scalable Access Control and Secure Deduplication in Mobile Cloud Computing
abstract
Benefiting from cloud computing and mobile devices, a huge number of media contents, such as videos are shared in mobile networks. Although scalable video coding can be utilized to provide flexible adaptation, the cloud poses a serious threat to media privacy. In this paper, we propose a privacy-preserving multi-dimensional media sharing scheme named SMACD in mobile cloud computing. First, each media layer is encrypted with an access policy based on attribute-based encryption, which guarantees media confidentiality as well as fine-grained access control. Then, we present a multi-level access policy construction with secret sharing scheme. It ensures that the mobile consumers who obtain a media layer at a higher access level must satisfy the access trees of its child layers at the lower access level, which is compatible with the characteristics of multi-dimensional media and also reduces the complexity of access policies. Moreover, we introduce decentralized key servers to achieve both intra-server and inter-server deduplication by associating different access policies into the same encrypted media. Finally, we conduct experimental evaluation on mobile device and cloud platform with real-world datasets. The results indicate that SMACD protects media privacy against cloud media center and unauthorized parties, while incurring less computational and storage cost.
Qinlong Huang, Yixian Yang
IEEE Trans. Mob. Comput.1
2021 Secure Data Group Sharing and Dissemination with Attribute and Time Conditions in Public Cloud
abstract
Cloud computing has become increasingly popular among users and businesses around the world. Although cryptographic techniques can provide data protection for users in public cloud, several issues also remain problematic, such as secure data group dissemination and fine-grained access control of time-sensitive data. In this paper, we propose an identity-based data group sharing and dissemination scheme in public cloud, in which data owner could broadcast encrypted data to a group of receivers at one time by specifying these receivers' identities in a convenient and secure way. In order to achieve secure and flexible data group dissemination, we adopt attribute-based and timed-release conditional proxy re-encryption to guarantee that only data disseminators whose attributes satisfy the access policy of encrypted data can disseminate it to other groups after the releasing time by delegating a re-encryption key to cloud server. The re-encryption conditions are associated with attributes and releasing time, which allows data owner to enforce fine-grained and timed-release access control over disseminated ciphertexts. The theoretical analysis and experimental results show our proposed scheme makes a tradeoff between computational overhead and expressive dissemination conditions.
Qinlong Huang, Yixian Yang
IEEE Trans. Serv. Comput.1
2018 DACSC: Dynamic and Fine-Grained Access Control for Secure Data Collaboration in Cloud Computing
abstract
Data collaboration is more and more popular in cloud computing. In a typical collaboration scenario, data owner outsources the data to cloud platforms, and users can access and re-upload the data. In consideration of the semi-trusted cloud platform, attribute-based encryption (ABE) has been utilized to guarantee data confidentiality and fine-grained access control. However, how to allow the collaborative data to be accessed only by authorized users in a flexible and dynamic manner is a challenging problem. In this paper, we propose DACSC, a dynamic and fine-grained access control scheme for secure data collaboration in cloud computing. First of all, we adopt ciphertext-policy ABE technique to define the original access policy of outsourced data. Second, we introduce a tree-based policy extending framework which allows users who satisfy the original access policy to customize a new access policy and add it to current access policies in a non-restrictive or restrictive way. Furthermore, we achieve integrity checking during the policy extending procedure based on ABE with equality test algorithm, which ensures that the added access policy comes from authorized user. The security analysis and experimental results indicate that DACSC is secure and efficient, and is suitable for the data collaboration scenario in cloud computing.
Qinlong Huang, Yixian Yang
GLOBECOM1
2018 PRECISE: Identity-based private data sharing with conditional proxy re-encryption in online social networks
Qinlong Huang, Yixian Yang
Future Gener. Comput. Syst.1
2018 Corrigendum to "Secure and efficient data collaboration with hierarchical attribute-based encryption in cloud computing" [Future Gener. Comput. Syst. 72 (2017) 239-249]
Qinlong Huang, Yixian Yang, Mansuo Shen
Future Gener. Comput. Syst.1
2018 Adaptive Secure Cross-Cloud Data Collaboration with Identity-Based Cryptography and Conditional Proxy Re-Encryption
abstract
Data collaboration in cloud computing is more and more popular nowadays, and proxy deployment schemes are employed to realize cross-cloud data collaboration. However, data security and privacy are the most serious issues that would raise great concerns from users when they adopt cloud systems to handle data collaboration. Different cryptographic techniques are deployed in different cloud service providers, which makes cross-cloud data collaboration to be a deeper challenge. In this paper, we propose an adaptive secure cross-cloud data collaboration scheme with identity-based cryptography (IBC) and proxy re-encryption (PRE) techniques. We first present a secure cross-cloud data collaboration framework, which protects data confidentiality with IBC technique and transfers the collaborated data in an encrypted form by deploying a proxy close to the clouds. We then provide an adaptive conditional PRE protocol with the designed full identity-based broadcast conditional PRE algorithm, which can achieve flexible and conditional data re-encryption among ciphertexts encrypted in identity-based encryption manner and ciphertexts encrypted in identity-based broadcast encryption manner. The extensive analysis and experimental evaluations demonstrate the well security and performance of our scheme, which meets the secure data collaboration requirements in cross-cloud scenarios.
Qinlong Huang, Yue He 0002, Wei Yue 0004, Yixian Yang
Secur. Commun. Networks1
2018 DECENT: Secure and fine-grained data access control with policy updating for constrained IoT devices
Qinlong Huang, Licheng Wang 0004, Yixian Yang
World Wide Web1
2017 Secure and efficient data collaboration with hierarchical attribute-based encryption in cloud computing
Qinlong Huang, Yixian Yang, Mansuo Shen
Future Gener. Comput. Syst.1
2017 Secure and Privacy-Preserving Data Sharing and Collaboration in Mobile Healthcare Social Networks of Smart Cities
abstract
Mobile healthcare social networks (MHSN) integrated with connected medical sensors and cloud-based health data storage provide preventive and curative health services in smart cities. The fusion of social data together with real-time health data facilitates a novel paradigm of healthcare big data analysis. However, the collaboration of healthcare and social network service providers may pose a series of security and privacy issues. In this paper, we propose a secure health and social data sharing and collaboration scheme in MHSN. To preserve the data privacy, we realize secure and fine-grained health data and social data sharing with attribute-based encryption and identity-based broadcast encryption techniques, respectively, which allows patients to share their private personal data securely. In order to achieve enhanced data collaboration, we allow the healthcare analyzers to access both the reencrypted health data and the social data with authorization from the data owner based on proxy reencryption. Specifically, most of the health data encryption and decryption computations are outsourced from resource-constrained mobile devices to a health cloud, and the decryption of the healthcare analyzer incurs a low cost. The security and performance analysis results show the security and efficiency of our scheme.
Qinlong Huang, Licheng Wang 0004, Yixian Yang
Secur. Commun. Networks1
2010 Implementation of a Suggested E-commerce Model Based on SET Protocol
abstract
Secure Electronic Transaction (SET) protocol was developed by Visa and MasterCard as a method to protect the security of payment card transactions over open networks, but it failed to be widely promoted. Based on our research about Secure Electronic Transaction (SET) protocol, we designed and implemented a suite of e-commerce system which was improved from Secure Electronic Transaction (SET) protocol. Our main contributions are: firstly, apply the proper network technologies of thin client to build the E-commerce model, secondly, develop a method of database encryption to protect the security of sensitive transaction information, thirdly, give support to debit card payment, also we change the payment process of transaction flow for the aim of practicability and atomicity.
Qinlong Huang
SERA2