VLDB 2026 Research / reviewers in the wild / expert
Yunguo Guan
dblp:227/7868
· DBLP profile ↗
67ranked-venue papers
15as first author
65since 2021 · last 2026
0000-0002-3965-3389ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 32 · 10 first-author · 30 since 2021Security and privacy · 21 · 3 first-author · 21 since 2021Software engineering, systems software and programming languages · 9 · 1 first-author · 9 since 2021Systems, architecture and hardware · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ECDRS: Efficient certificateless deniable ring signature with privacy preserving based on SM2 in smart grids
Dengzhi Liu, Geng Yu, Haowen Tan, Yunguo Guan |
Comput. Networks | 5 |
| 2026 | Privacy-Preserving Cross-Cloud LDoS Threat Identification via Labelled-Threshold Private Set IntersectionabstractIndustrial Internet of Things (IIoT) systems in sectors like manufacturing, energy, and healthcare are increasingly deployed in cloud-assisted operational environments, where network telemetry and security analytics are routinely processed in the cloud. However, these systems remain highly vulnerable to cyber threats from shared threat actors. Among these, low-rate Denial of Service (LDoS) attacks, marked by subtle periodic traffic patterns, are particularly challenging to detect when analyzed in isolation. Cross-organization collaborative detection across cloud platforms can improve identification accuracy, but sharing threat intelligence risks exposing sensitive operational information. To tackle this challenge, we propose Labelled-Threshold Private Set Intersection (LT-PSI), a cryptographic framework that allows two organizational clouds to securely identify common elements whose associated label vectors satisfy a similarity threshold, without revealing any additional data. Our LT-PSI protocol introduces an innovative combination of position encoding, Diffie-Hellman Oblivious Pseudorandom Functions (DH-OPRF), and Bloom filters, effectively transforming threshold-based label similarity matching into efficient and privacy-preserving set membership tests. Particularly, our protocol achieves sublinear online complexity and is well-suited for cloud execution, integrating an adaptive early termination strategy that significantly reduces the number of OPRF invocations. We provide formal security proofs under the semi-honest model and validate the protocol through extensive experiments across diverse similarity thresholds and dataset sizes. Results show that LT-PSI is significantly more efficient than brute-force threshold matching while preserving privacy. The framework naturally supports cloud-to-cloud collaborative security analytics and generalizes to broader cloud and edge threat intelligence scenarios requiring private, threshold-based feature matching. Xinrui Zhang 0009, Rongxing Lu, Pincan Zhao, Yunguo Guan, Suprio Ray |
IEEE Trans. Cloud Comput. | 4 |
| 2025 | An Efficient Private Set Frequency Query Scheme Under Local Differential PrivacyabstractCrowdsourcing has become a widely utilized method for data collection and analysis; however, privacy concerns remain a significant challenge. In this paper, we introduce a novel and efficient private set frequency (PSF) query scheme designed for crowdsourcing scenarios. Our proposed scheme is based on edge computing and leverages local differential privacy (LDP) and Bloom filter techniques to ensure both query privacy and high communication efficiency. Specifically, we employ two non-colluding edge devices to assist the server in achieving highaccuracy query result estimation while preserving the privacy of both the server's query set and users' sensitive data. A comprehensive security analysis confirms that the query value remains confidential, and users' privacy is guaranteed under$\varepsilon$-LDP. Additionally, performance evaluations demonstrate the efficiency and improved accuracy of our proposed scheme. Ellen Z. Zhang, Yunguo Guan, Rongxing Lu, Harry Zhang |
ICC | 2 |
| 2025 | Privacy-Preserving Fine-Grained Data Sharing With Dynamic Service for the Cloud-Edge IoTabstractThe cloud-edge computing model has been expected to play a revolutionary role in promoting the quality of future generation large-scale Internet of Things (IoT) services. However, security and privacy in data sharing remain crucial issues hindering the success of cloud-edge IoT services. While some solutions based on attribute-based encryption (ABE) have been proposed to address these issues, they still face practical challenges such as attribute privacy leakage, resource-constrained devices, dynamic user groups, inflexible and inefficient service response. To address these challenges, this paper proposes a privacy-preserving fine-grained data sharing scheme with dynamic service (PF2DS), which implements access control by calculating the inner product between an attribute vector and an access vector. PF2DS is also capable of providing dynamic user group services through an efficient and indirect user revocation mechanism that periodically updates the key-embedded leaf nodes. Building on PF2DS, edge-assisted PF2DS (EPF2DS) delegates most of the operations to the edge device, which facilitates the performance of resource-constrained IoT devices. EPF2DS also supports efficient and asynchronous keyword search over the ciphertexts stored in the cloud. We demonstrate the security by the rigorous security proof. Both theoretical comparisons and experimental simulations demonstrate the practicality and superiority of our schemes over existing works. Jianfei Sun, Yangyang Bao, Weidong Qiu, Rongxing Lu, Songnian Zhang, Yunguo Guan, Xiaochun Cheng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Optimized Sparse Vector Aggregation Under Local Differential PrivacyabstractIn crowdsourcing applications, gathering and analyzing users’ strong positive (1) or negative (-1) reactions to a large number of items is crucial for improving service quality, particularly in recommendation systems. However, protecting users’ privacy while handling diverse sparse patterns in contexts with a large dimension sizedposes significant challenges for efficient and privacy-preserving data aggregation. To address these challenges, in this paper, we propose an optimizedk-sparse vector mean estimation scheme under Local Differential Privacy (LDP), ensuring that each user’s entire set of up tokprivate values from {−1, 1} satisfies ε-LDP. Specifically, our proposed scheme employs a seed mining technique in conjunction with PRNG Randomizer, which allows users to send their data only once while enabling the server to accurately estimate any value’s mean in the domain. Our scheme achieves an asymptotically optimal error ofO( 1/ε√n), equivalent to that of a 1-sparse case, while also ensuring efficient communication costs. The communication cost remains at a minimal level ofO(1) (only 2 bytes per user’s report) for smallerkvalues and scales toO(k) for largerk, due to efficient binning strategies. Extensive experimental results confirm that our results align with theoretical expectations, demonstrating that our scheme not only preserves user privacy but also ensures higher accuracy compared to other schemes. Ellen Z. Zhang, Yunguo Guan, Rongxing Lu, Harry Zhang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Efficient Privacy-Preserving Edge-based Dynamic Aggregation Query Over Crowdsensed DataabstractAggregation query, which is one of the most crucial data analysis tools applied to vehicular crowdsensed data, is expected to extract valuable insights and support smart decision-making. Meanwhile, the edge servers are deployed to cope with the escalation of service scale, which however raises privacy concerns about the query requests and reported data. Previously reported privacy-preserving aggregation query schemes are either tailored for static datasets or lack an index structure for deployed queries, which makes them impractical in vehicular crowdsensing (VCS) scenarios characterized by large volumes of real-time data and high data update frequencies. To tackle these challenges, we propose an efficient privacy-preserving edge-based dynamic aggregation query scheme with an encrypted tree-based index. Concretely, we first design two building blocks, namely the balanced spatial encoding quadtree (BSEQtree) and a predicate encryption scheme for membership testing (PEMT), which enable the edge servers to obliviously match data and queries by traversal over the encrypted BSEQtree. Based on the above blocks and arithmetic secret sharing (ASS), we construct our scheme, in which the edge servers can efficiently and securely aggregate newly reported data to related query results. Our security analysis shows the privacy preservation of our scheme, and the experiment results on a real dataset validate the efficiency of our scheme. Yunguo Guan, Xiaoping Xue 0002, Rongxing Lu |
GLOBECOM | 2 |
| 2024 | A Communication-efficient Conjunctive Query Scheme under Local Differential PrivacyabstractCrowdsourcing has become a widely used method for data collection and analysis, yet its privacy remains a challenge. In this paper, we present a new efficient and privacy-preserving conjunctive query scheme for crowdsourcing scenarios. The scheme employs the Local Differential Privacy (LDP) technique to ensure both query privacy and high communication efficiency. Specifically, when an aggregator launches a conjunctive query to a set of crowdsourcing users, the query condition will not be leaked. To respond the query, each user just needs to return one bit back to the aggregator. By integrating prefix encoding technique, our proposed scheme can also efficiently support conjunctive queries with one range query condition. Detailed security analysis shows our proposed scheme can achieve desirable security requirements. In addition, performance evaluations also indicate its efficiency. Furthermore, extensive experiments demonstrate our proposed scheme can achieve high accuracy while ensuring ε-LDP. Ellen Z. Zhang, Yunguo Guan, Rongxing Lu, Harry Zhang |
GLOBECOM | 2 |
| 2024 | Efficient Privacy-Preserving Multi-Location Task Allocation in Fog-Assisted Vehicular CrowdsourcingabstractMulti-location task allocation is one of the most crucial issues in vehicular crowdsourcing (VCS). To ensure service quality, the VCS service provider prefers to assign multi-location tasks to the workers whose future trajectories have high spatial proximity with the task locations. However, this process requires workers and task owners to upload their precise locations to a not-fully-trusted service provider, thereby raising location privacy concerns. Although several privacy-preserving trajectory similarity evaluation schemes have been proposed, they either fail to match the multi-location task allocation scenario, or incur nontrivial computational costs due to homomorphic encryption. To address these challenges, we propose a novel efficient privacy-preserving multi-location task allocation scheme in fog-assisted VCS. Specifically, we design a lightweight secure Euclidean distance computation protocol based on arithmetic secret sharing (ASS), which can compute Euclidean distance without revealing the two input locations. Then, based on this protocol, we build our scheme that supports multi-location task allocation based on Hausdorff semi-distance (HSD). Our security analysis demonstrates the location privacy preservation of our scheme, and the experiment results on a real dataset also validate the efficiency of our scheme. Yunguo Guan, Xiaoping Xue 0002, Jingxiao Ma, Ellen Z. Zhang, Rongxing Lu |
ICC | 2 |
| 2024 | An Efficient Range Sum Query Scheme Under Local Differential PrivacyabstractCrowdsourcing has received considerable attention in recent years; however, privacy in crowdsourcing remains a challenge. In this paper, we present a privacy-preserving range sum query scheme under Local Differential Privacy (LDP) that not only enhances accuracy but also guarantees privacy in crowdsourcing applications. Specifically, our proposed scheme employs keyed hash, prefix encoding, and garbled bloom filter techniques to convert a large query range into a small domain, independent of the range length, thus improving accuracy. For the query response, the Optimal Unary Encoding (OUE) technique is applied to achieve ε-LDP. Security analysis shows that our proposed scheme can achieve the desirable privacy requirement for users' private items and the server's query range. In addition, performance evaluations also confirm the efficiency of our scheme in terms of computational costs and communication overhead. Furthermore, extensive experiments validate that our proposed scheme outperforms a potential strawman solution in terms of accuracy. Ellen Z. Zhang, Yunguo Guan, Rongxing Lu, Harry Zhang |
ICC | 2 |
| 2024 | Blockchain-Based Lightweight and Privacy-Preserving Quality Assurance Framework in Crowdsensing SystemsabstractThe novel sensing paradigm known as crowdsensing leverages ubiquitous smart devices to collect data in Internet of Things (IoT) applications. Traditional crowdsensing schemes assume a central framework to execute truth discovery algorithm to assure data quality, which may introduce reliability and privacy issues. Blockchain is a promising technology that provides a decentralized, transparent, and immutable platform. However, designing a blockchain-based quality assurance scheme in crowdsensing is not a trivial problem. First, truth discovery is a time-consuming iterative algorithm, which is not practical to execute on blockchain. Second, privacy-preserving schemes always require that the participants join in multiround communications, which is not acceptable in open blockchain because of users’ highly unpredictable behaviors. Finally, on-chain data are publicly accessible, and achieving a good balance between data utility and privacy is an important issue. In this article, we propose a lightweight quality assurance framework atop blockchain to build a reliable, privacy preserving, and fair crowdsensing system. Specifically, we carefully design two kinds of smart contracts to cooperatively maintain a long-term reliable platform to execute crowdsensing tasks. In the contracts, we devise a reputation-based aggregator selection algorithm to reach the consensus on truthful results while avoiding expensive on-chain iterative processes. The participant selection scheme and reward policy are further utilized to filter appropriate participants to complete the task. Our scheme also protects data privacy and does not require communications between participants. Finally, we implement and deploy the contracts on Ethereum and conduct extensive experiments to demonstrate that the contracts can practically execute crowdsensing tasks. Chang Xu 0004, Liehuang Zhu, Rongxing Lu, Yunguo Guan, Xiaoming Zhang 0001 |
IEEE Internet Things J. | 5 |
| 2024 | EPTS: Efficient and Privacy-Preserving Outsourced Task Scheduling in Vehicular CrowdsourcingabstractThe flourishing of intelligent connected vehicles (ICVs) has fostered the emergence of vehicular crowdsourcing (VCS) applications, in which ICVs function as workers to execute diverse spatio-temporal critical tasks. As a vital service of VCS, task scheduling aims to assign tasks to the most suitable workers. To cope with the escalation of service scale, the service provider tends to outsource the service to powerful cloud servers, which however triggers the privacy concerns of workers, task owners, and the service provider. Previously reported privacy-preserving task allocation schemes can mainly be divided into single-attribute-aware and multiattribute-aware schemes. Nevertheless, the former suffers from practicality issues, while the latter either fails to achieve single-dimensional privacy and access pattern privacy or introduces substantial computational costs. To tackle the above challenges, we propose an efficient privacy-preserving outsourced task scheduling scheme (EPTS) for VCS, in which two cloud servers can cooperate to efficiently and securely conduct multiattribute-aware task scheduling. To this end, we devise five lightweight secure two-party protocols under the additive secret sharing (ASS) setting, which enable cloud servers to obliviously filter workers that meet multiple constraints and traverse the candidate worker set to obtain the optimal worker without revealing the input and output. Rigorous security analysis proves that our EPTS scheme effectively preserves user privacy, single-dimensional privacy, and access pattern privacy. Extensive experimental results validate its superior efficiency compared with the state-of-the-art scheme. Yunguo Guan, Xiaoping Xue 0002, Jingxiao Ma, Rongxing Lu |
IEEE Internet Things J. | 2 |
| 2024 | Efficient Privacy-Preserving Task Allocation With Secret Sharing for Vehicular CrowdsensingabstractVehicular crowdsensing (VCS) has emerged as a promising paradigm, in which spatio-temporal-based sensing tasks are outsourced to intelligent connected vehicles (ICVs) carrying sensor-equipped devices. A critical issue of VCS is to guarantee the spatio-temporal sensing coverage by assigning tasks to appropriate vehicles, which inevitably requires vehicles’ precise locations or trajectories and thus raises location privacy concerns. To address this problem, we propose a novel secret sharing-based efficient privacy-preserving task allocation scheme for VCS, which can select sensing vehicles with approximately optimal total spatio-temporal coverage based on their future trajectories while achieving strong location privacy preservation for users (customers and sensing vehicles). With a grid-based region encoding method, a user’s location information is encoded as a binary array, termed as the region code. Based on the idea of secret sharing, we design a bit-wise XOR-based secret splitting method to split a user’s region code into two random shares and separately transmit them to two fog servers, thereby perfectly hiding the original location information. With a carefully-designed code permutation mechanism and a greedy task allocation algorithm, the cloud server and fog servers can efficiently collaborate and complete task allocation based on permuted region codes without revealing users’ location information. Detailed security analysis shows that our proposed scheme effectively preserves users’ location privacy. Extensive experiments conducted on a realistic traffic scenario data set also demonstrate that it is efficient in communication and computation while achieving large total spatio-temporal coverage. Xiaoping Xue 0002, Jingxiao Ma, Ellen Z. Zhang, Yunguo Guan, Rongxing Lu |
IEEE Internet Things J. | 5 |
| 2024 | An Efficient Heap Tree-Based Range Query Scheme Under Local Differential PrivacyabstractCrowdsourcing, which is regarded as one of the most important data collection techniques in Internet of Things (IoT) and Big Data era, has received significant attention in recent years. However, privacy concerns persist across various crowdsourcing scenarios. In this paper, aiming to address users’ privacy issues in crowdsourcing scenarios, we propose an efficient and privacy-preserving range query scheme under Local Differential Privacy (LDP) setting. Specifically, given a domain V = {0, 1, 2, ..., d – 1} where d = 2w, our proposed scheme integrates binary heap tree, prefix encoding, randomized response, and pseudo-random number generator techniques to enable each user to report only w bits as a query response, which is sufficient for a server to efficiently compute the range query result for any range [a, b] in the domain V. Security analysis demonstrates that our proposed scheme can achieve ε-LDP, effectively preserving the privacy of users’ private items. In addition to its low communication overhead, performance evaluation also indicates our proposed scheme is computationally efficient when the pre-computation is implemented at the server. Furthermore, our proposed scheme exhibits higher accuracy compared to previously reported flat and tree-based methods, especially for a large domain size d and a large range length m = b – a + 1. Ellen Z. Zhang, Yunguo Guan, Rongxing Lu, Harry Zhang |
IEEE Internet Things J. | 2 |
| 2024 | Efficient and Privacy-Preserving Aggregate Query Over Public Property GraphsabstractGraph data structures’ ability of representing vertex relationships has made them increasingly popular in recent years. Amid this trend, many property graph datasets have been collected and made public to facilitate a variant of queries such as the aggregate queries that will be extensively exploited in this paper. While cloud deployment of both the datasets and query services is intriguing, it could raise privacy concerns related to user queries and results. In past years, many works on graph privacy have been put forth, however they either do not consider query privacy or cannot be adapted for aggregate queries. Some others consider queries over encrypted graphs but cannot protect access pattern privacy. In particular, when deploying them to handle queries over public graph datasets, the cloud server can infer additional information related to user queries. Aiming at this challenge, we propose a privacy-preserving property graph aggregate query scheme in this paper. Specifically, we first design new privacy-preserving vertex matching and matching update techniques, which securely initialize and update the mapping between vertices in the dataset and the user-specified patterns, respectively. Based on them, we construct our proposed scheme to achieve aggregate queries over public property graphs. Rigid security analysis shows that our proposed scheme can protect the privacy of user queries and results as well as achieve access pattern privacy. In addition, extensive experiments also demonstrate the efficiency of our scheme in terms of computational overheads. Yunguo Guan, Rongxing Lu, Songnian Zhang, Yandong Zheng, Jun Shao 0001, Guiyi Wei |
IEEE Trans. Big Data | 1 |
| 2024 | $k$kTCQ: Achieving Privacy-Preserving $k$k-Truss Community Queries Over Outsourced DataabstractCommunity search over graphs, which is believed as a powerful tool for locating subgraphs of closely related vertices, has received considerable attention in recent years, and$k$-truss is such a popular community search metric to obtain subgraphs in which every edge forms$(k-2)$triangles. In this paper, we particularly consider$k$-truss community query services, which will return all$k$-truss communities containing a given query vertex. As is known, when the size of graph grows, for achieving better performance, it is natural for a service provider to outsource the services to a powerful cloud. However, this stresses the need for privacy-preserving$k$-truss community query services, as the cloud server is not fully trustable. Over the past years, many schemes focusing on privacy-preserving graph computation have been put forth, but none of them can well support privacy-preserving$k$-truss community queries. Aiming at this challenge, we first propose a privacy-preserving$k$-truss community query scheme ($k$TCQ) by constructing boolean circuits with homomorphic encryption technique and a table-based index. After that, we also design an efficiency-enhanced version ($k$TCQ+) based on a stream cipher scheme to reduce the encrypted index's size and improve the query efficiency. Detailed security analysis shows that both$k$TCQ and$k$TCQ+ can well preserve data privacy and access pattern privacy, and extensive experimental results also demonstrate that$k$TCQ+ can observably reduce the size of encrypted index and the query time by$12\times$and$5.9\times$, respectively. Yunguo Guan, Rongxing Lu, Songnian Zhang, Yandong Zheng, Jun Shao 0001, Guiyi Wei |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | PHRkNN: Efficient and Privacy-Preserving Reverse kNN Query Over High-Dimensional Data in CloudabstractBig data and bursting cloud computing technologies have facilitated an increasing trend of outsourcing data-driven services to the cloud, where the reverse kNN (RkNN) query is a popularly outsourced query service. The RkNN query aims to retrieve objects having the query object as kNN and widely applied in the product recommendation. Considering privacy concerns, the outsourced query services are demanded to protect data privacy, and consequently a series of privacy-preserving query solutions have been put forth. Nevertheless, RkNN query over high-dimensional data has not been studied to date. In this work, we design the first efficient and privacy-preserving RkNN query scheme over encrypted high-dimensional data, named PHRkNN. Specifically, we first introduce a pivot filter condition for the RkNN query and utilize it to deliberately design a pivot filter R-tree (PFR-tree) to organize the high-dimensional dataset such that the RkNN query has sublinear query efficiency. Then, we propose our PHRkNN scheme by designing some homomorphic encryption based private algorithms and applying them to privately achieve PFR-tree based RkNN query. After that, we propose an oblivious PHRkNN scheme on the basis of the PHRkNN scheme by designing a private random tree permutation (PRTP) algorithm to protect the access pattern privacy. The security of our PHRkNN scheme and oblivious PHRkNN scheme is proved by the simulation-based security analysis. The performance is verified through computational costs and communication overheads evaluation. Yandong Zheng, Hui Zhu 0001, Rongxing Lu, Yunguo Guan, Songnian Zhang, Fengwei Wang, Jun Shao 0001, Hui Li 0006 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Performance Enhanced Secure Spatial Keyword Similarity Query With Arbitrary Spatial RangesabstractThe increasing prevalence of cloud computing drives the exploration of various secure query schemes over encrypted data, among which secure spatial keyword query has drawn a great deal of attention due to its broad application in location-based services. However, most existing schemes are either limited to the boolean keyword test or incapable of protecting access pattern privacy. Although the state-of-the-art secure spatial keyword query scheme can support keyword similarity while preserving access pattern privacy, it is unable to cope with the arbitrary spatial range, which is more general, and has limitations in efficiency and security. In this paper, we propose a new secure spatial keyword similarity query scheme that can support arbitrary spatial ranges and enhance the efficiency and security of the state-of-the-art scheme at the same time. Specifically, we first present a new homomorphic encryption technique by improving the popular symmetric homomorphic encryption (SHE). After that, we propose a novel approach to make supporting arbitrary spatial ranges over encrypted data possible, in which a spatial encoding technique is designed to improve performance. Finally, by designing a pack-based solution to protect access pattern privacy, our proposed scheme can hide the number of query results while optimizing performance. We formally prove the security of our proposed scheme and conduct experiments to evaluate its performance. The results indicate that our proposed scheme outperforms the state-of-the-art scheme in both the computational costs and communication overhead. Songnian Zhang, Rongxing Lu, Hui Zhu 0001, Yandong Zheng, Yunguo Guan, Fengwei Wang, Jun Shao 0001, Hui Li 0006 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Secure Similarity Queries Over Vertically Distributed Data via TEE-Enhanced Cloud ComputingabstractOutsourcing big data to cloud servers has gained prominence, and growing concerns about privacy, alongside privacy-related regulations, underscore the need to encrypt data before sending them to the cloud. Nevertheless, encryption significantly hampers the query capabilities of data, particularly in the case of vertically distributed data. This paper focuses on developing secure and efficient similarity query schemes for vertically distributed data in cloud environments. As is known, current solutions are constrained by limitations in query efficiency, approximate query results, and their ability to support vertical data. To address these issues, we introduce two novel schemes: a Fast Similarity Query Scheme (FSQ) and a Non-interactive Similarity Query Scheme (NoSQ) for outsourced distributed data. In the FSQ scheme, we enhance query efficiency by designing a trusted execution environment (TEE) assisted fast secret sharing (FSS) scheme and a series of FSS-based private algorithms, enabling secure data index construction and fast similarity query processing. For the NoSQ scheme, we eliminate communication overheads by designing a TEE assisted non-interactive secret sharing (NoSS) scheme and a series of NoSS-based private algorithms. Both schemes have undergone rigorous security validation using a simulation-based real/ideal worlds model, and their efficiency has been confirmed through comprehensive experiments. Yandong Zheng, Hui Zhu 0001, Rongxing Lu, Songnian Zhang, Yunguo Guan, Fengwei Wang, Jun Shao 0001, Hui Li 0006 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | A Federated Learning Architecture for Blockchain DDoS Attacks DetectionabstractThe rapid development of blockchain technology has led to a constant increase in its financial and technological value. However, this has also led to malicious attacks. Distributed denial-of-service attacks pose a considerable threat to blockchain technology out of many attacks due to its effectiveness and distributed nature. To protect the blockchain from DDoS attacks, researchers have proposed a large number of defensive schemes. However, these schemes are not well-suited for use in practical situations. In this work, we propose a DDoS attack detection scheme based on centralized federated learning, where multiple participating nodes locally train models and upload them to a central node for aggregation. Additionally, we propose a more suitable method for blockchain scenarios, using decentralized federated learning technology, where multiple nodes exchange models in a peer-to-peer manner to complete model training without a central server. We simulate DDoS attacks in blockchain and generate a large dataset by combining it with traditional network layer DDoS attack data to evaluate the effectiveness of our schemes. The experimental results show that the proposed schemes perform well in classification accuracy, demonstrating that our techniques can detect DDoS attacks effectively. Chang Xu 0004, Guoxie Jin, Rongxing Lu, Liehuang Zhu, Yunguo Guan, Kashif Sharif |
IEEE Trans. Serv. Comput. | 6 |
| 2024 | EPSet: Efficient and Privacy-Preserving Set Similarity Range Query Over Encrypted DataabstractSet similarity query is a fundamental query type in various applications, such as clinical diagnosis, online shopping, and mobile crowdsensing. Meanwhile, as the prevalence of outsourced query services, privacy-preserving set similarity query has been considerablely studied. However, to the best of our knowledge, most previously reported solutions suffer from applicability, efficiency, or security issues. Aiming at addressing these issues, we propose an efficient and privacy-preserving set similarity range query scheme (EPSet), where Jaccard similarity is employed as the similarity metric. Specifically, the set similarity range query is first transformed into multi-dimensional range queries by leveraging the triangle inequality of Jaccard distance. Then, a pivot-based k-d tree is designed for indexing the dataset and processing the set similarity query. After that, we design homomorphic encryption based privacy-preserving filter/refinement protocols, respectively named as PPF and PPR, to protect set similarity query privacy, and propose our EPSet scheme. The security of our scheme is proved under the simulation-based real/ideal model, and the performance is validated thorugh the extensive experiment evaluation. Yandong Zheng, Rongxing Lu, Yunguo Guan, Songnian Zhang, Jun Shao 0001, Fengwei Wang, Hui Zhu 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2023 | Achieve Edge-Based Privacy-Preserving Dynamic Aggregation Query in Smart Transportation SystemsabstractAs the proliferation of smart vehicles has fostered an abundance of real-time data, various data analysis tools, such as aggregation queries, are expected to be deployed to extract insights and make transportation systems much smarter. Meanwhile, to cope with the growing service scale, edge servers are employed to collect data and deliver the service, which however provokes privacy concerns related to the reported data and user queries. Previously reported solutions on privacy-preserving aggregation queries focus on static datasets or require data persistence, leading to storage pressure and slower query responses. In this paper, we propose a privacy-preserving dynamic aggregation query scheme using edge servers, specifically addressing the problem of online aggregation queries. By combining homomorphic encryption and predicate encryption, our scheme enables the edge server to aggregate real-time data and respond to queries, safeguarding sensitive information from vehicles and data users. The integration of advanced cryptographic primitives ensures data and query privacy and integrity. Comprehensive theoretical analyses demonstrate our scheme's effectiveness in privacy preservation, boasting a manageable computational and communication overhead. The scheme, thus, presents a practical solution for privacy-preserving dynamic aggregation queries, fulfilling an unmet need in real-time transportation systems. Yunguo Guan, Ellen Z. Zhang, Pulei Xiong, Rongxing Lu |
GLOBECOM | 1 |
| 2023 | Improving Decision Tree Privacy with Bloom FiltersabstractOutsourcing decision tree (DT) inference to cloud servers can be beneficial for model providers who wish to share their model with potential clients. However, model owners may not want to publicly disclose all model details due to the investment of time and money that is put into training their models. Therefore, ensuring model privacy while making models available to clients is of grave importance to the model provider. To ensure the privacy of the DT models, the client query, and the final classification of the model, several privacy preserving DT schemes have been proposed. However, most existing schemes require significant communication or computational overhead. In this paper, we propose a privacy preserving scheme for DT inference, which is characterized by employing Bloom filters to hide the original DT structure while providing reliable classification results. Security and performance analysis verify the security and efficiency of our proposed scheme. Sean Lalla, Rongxing Lu, Yunguo Guan, Songnian Zhang |
GLOBECOM | 3 |
| 2023 | ERQ: An Efficient Range Query Scheme Under Local Differential PrivacyabstractCrowdsourcing has recently become a popular method of outsourcing tasks to many individuals in data-oriented applications. However, privacy is still a significant concern as crowdsourcing relies on individual responses. This paper focuses on range queries in crowd sourcing scenarios and proposes an efficient range query scheme, called ERQ, under Local Differential Privacy (LDP). ERQ is characterized by employing i) the accumulated encoding and perturbation techniques to protect the privacy of user data, and ii) the k-anonymity technique to conceal the real endpoints of a range query. Detailed security analysis shows that ERQ can achieve the desirable privacy requirements. In addition, performance evaluation also indicates ERQ is efficient in terms of low computational costs and communication overhead, and can achieve better accuracy while preserving privacy. Ellen Z. Zhang, Yunguo Guan, Rongxing Lu, Harry Zhang |
GLOBECOM | 2 |
| 2023 | Towards Efficient and Privacy-Preserving Federated Learning for HMM TrainingabstractThe hidden Markov model (HMM) has played a pivotal role in various IoT applications due to its ability to model time-varying sequences. Since the datasets usually live in isolated islands and their privacy naturally demands to be seriously considered, the HMM should be trained in a privacy-preserving manner. A typical HMM training framework is federated learning, in which a federated server and many data owners collaboratively train an HMM without revealing data owners' data to the federated server and the trained model to data owners. Since existing HMM training schemes are computationally intensive, we propose an efficient and privacy-preserving federated learning scheme for HMM training to address the efficiency issue in this paper. First, we transform all HMM training computations into matrices- and vectors-based computations over real domains. Then, we introduce our federated HMM training scheme by applying matrix encryption to protect the HMM training privacy. After that, we show that our scheme is privacy-preserving through a rigorous analysis on the security of our scheme. We illustrate that our scheme is efficient through extensive experimental evaluation on the performance of our scheme. Yandong Zheng, Hui Zhu 0001, Rongxing Lu, Songnian Zhang, Yunguo Guan, Fengwei Wang |
GLOBECOM | 5 |
| 2023 | Efficient and Privacy-Preserving Subgraph Matching Queries in Graph FederationabstractGraph technology has been attracting interest due to its ability in modeling complex network and real-world relationships in various applications. Subgraph matching queries are useful tools that can be used to extract structural insights from graph dataset. As the accuracy of subgraph matching queries increases with graph size, it is natural to consider providing subgraph matching query services over a graph federation, which can form a larger graph by combining graphs from multiple data owners. However, the downside combining data is that it may provoke privacy concerns related to the graph datasets and user queries. Although many schemes have been proposed for privacy-preserving subgraph matching queries, they either cannot be extended to graph federation scenarios or do not consider query privacy. Aiming at this challenge, in this paper we construct an efficient and privacy-preserving subgraph matching query scheme in graph federation with two data owners. In the proposed scheme, the two data owners jointly compute the neighboring signatures of all vertices without disclosing their graph datasets to each other. Upon receiving a subgraph matching query, the data owners together respond with a subgraph which includes all subgraphs matching the pattern in the combined graph. Security analysis shows that our proposed scheme can well preserve data and query privacy. Extensive experiments further demonstrate that the scheme is efficient in terms of computation and communication. Yunguo Guan, Rongxing Lu, Songnian Zhang, Sean Lalla |
ICC | 1 |
| 2023 | Traceable and Privacy-Preserving Worker Selection Scheme with Arbitrary Spatial Ranges in MCSabstractWorker selection that is often outsourced to a cloud server is crucial for the success of the Mobile Crowdsensing (MCS) system, in which the spatial constraint plays a fundamental role in selecting workers. To protect the location information involved in the spatial constraint, several privacy-preserving worker selection schemes were proposed. However, they either only support a specific spatial range or cannot trace the workers who leak secret keys. In this paper, we propose a traceable and privacy-preserving worker selection scheme that can support arbitrary spatial ranges when selecting workers and trace the worker when his/her secret key is leaked to the cloud server for inferring location information. Security analysis demonstrates the privacy preservation and traceability of our proposed scheme, and the evaluation results illustrate its efficiency. Songnian Zhang, Suprio Ray, Rongxing Lu, Yunguo Guan, Sean Lalla |
ICC | 4 |
| 2023 | An Efficient Bloom Filter-based Range Query Scheme Under Local Differential PrivacyabstractWhile crowdsourcing for data collection has become increasingly popular in data-driven applications, privacy remains a significant challenge. This paper presents an effective scheme for conducting range queries under local differential privacy (LDP) in crowdsourcing applications, which addresses the privacy challenges that arise in such scenarios. In particular, our proposed scheme utilizes Prefix Encoding (PE) and Bloom Filter (BF) techniques to convert a large domain into a binary domain for improved query accuracy. When responding to the query, individual users can check a Bloom filter to determine whether their private item is within the query range and use the Basic Randomized Response (BRR) technique to perturb their result for achieving ε-LDP. Detailed security analysis shows that our proposed scheme can preserve user’s item privacy and also keep an external passive attacker from learning the query range. In addition, performance evaluation shows that the proposed scheme is efficient in terms of computational cost and communication overhead, while effectively balancing range query accuracy and privacy. Ellen Z. Zhang, Yunguo Guan, Rongxing Lu, Harry Zhang |
PIMRC | 2 |
| 2023 | Achieving Efficient and Privacy-Preserving ($\alpha,\beta$α,β)-Core Query Over Bipartite Graphs in CloudabstractBipartite graphs have been widely adopted in applications such as e-healthcare thanks to their ability to model various real-world relationships. Meanwhile, (,)-core query services over bipartite graphs are recognized as a promising approach for finding communities, i.e., closely related sets of vertices in a bipartite graph. As the bipartite graph grows, service providers tend to outsource the services to the cloud. However, there are privacy concerns related to the dataset, queries, and results. Although many schemes have been proposed for privacy-preserving graph analysis, they cannot be directly adopted to handle accurate (,)-core queries. Aiming at the challenges, under the two-server setting, this paper constructs two privacy-preserving schemes with different security levels to handle (,)-core queries. In the proposed schemes, a graph is represented as an index containing two tables and further encrypted by a symmetric homomorphic encryption scheme, and then the servers securely traverse the index. Detailed security analysis shows that both schemes can achieve access pattern privacy, while the security-enhanced one can further protect the structure of the query requests and results. In addition, extensive performance evaluations are conducted to indicate the efficiency of our proposed schemes. Yunguo Guan, Rongxing Lu, Yandong Zheng, Songnian Zhang, Jun Shao 0001, Guiyi Wei |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Achieving Privacy-Preserving Discrete Fréchet Distance Range QueriesabstractThe advances in Internet of Things, Big Data, and machine learning technologies have greatly transformed our daily lives into much more intelligent ones by offering various promising services. Among those services, the discrete Fréchet distance (DFD) range query, which aims to obtain a set of trajectories whose distances to a given query trajectory do not exceed a given threshold, has been widely applied to support applications such as vehicle trajectory clustering and other data processing tasks. Meanwhile, due to the huge data volume issue in the Big Data era, there is a trend towards outsourcing various query services to the cloud for achieving a better performance. However, since the cloud is not fully trustable, designing privacy-preserving query services becomes a research focus. Over the past years, many schemes focusing on privacy-preserving trajectory analysis have been proposed, but none of them can well support privacy-preserving DFD range queries. Aiming at addressing this challenge, this paper proposes a novel privacy-preserving DFD range query scheme, in which queries are conducted in a filtration-and-verification manner and the privacy of the dataset and queries can be preserved. Specifically, by indexing the dataset with two R-trees, a query can be conducted by i) querying the two R-trees to obtain a candidate set and ii) verifying each trajectory in the set, which involve two basic operations, namely, rectangle intersection detection and proximity detection. To preserve the privacy of the dataset and queries, we build the two basic operations upon a novel Inner-Product Preserving Encryption (IPPE) scheme, which is proved to be selectively secure with trivial leakages. Besides, extensive experiments are conducted, and the results demonstrate that our proposed scheme can significantly reduce the computational cost by effectively reducing the candidate set’s size. Yunguo Guan, Rongxing Lu, Yandong Zheng, Songnian Zhang, Jun Shao 0001, Guiyi Wei |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Efficient and Privacy-Preserving Spatial Keyword Similarity Query Over Encrypted DataabstractAs a popular and practical query type in location-based services, the spatial keyword query has been extensively studied in both academia and industry. Meanwhile, with the growing demand for data privacy, many privacy-preserving spatial keyword query schemes have been proposed to deal with queries over encrypted data. However, none of the existing schemes preserve access pattern privacy, and the recent research illustrates that leaking such privacy may incur inference attacks and thus disclose sensitive information. In addition, most existing schemes only consider the boolean keyword search, which is not quite practical and flexible in real-world applications. To address the above issues, in this paper, we propose two privacy-preserving spatial keyword similarity query schemes that can preserve full and partial access pattern privacy, respectively. First, we present a basic privacy-preserving spatial keyword similarity query scheme (PPSKS) by integrating a secure set membership test (SSMT) technique with secure circuits. After that, to improve performance, we propose a tree-based scheme (PPSKS+) by employing a new index called FR-tree together with a predicate encryption technique that can encrypt FR-tree. Formal security analysis shows that: i) our proposed schemes can protect outsourced data, query requests, and query results; ii) our PPSKS scheme can hide full access patterns, while the PPSKS+ scheme preserves$m$-access pattern privacy. Extensive experiments are also conducted, and the results indicate that our tree-based PPSKS+ scheme is much more efficient, almost two orders of magnitude better than our linear search PPSKS scheme in performing queries. Songnian Zhang, Suprio Ray, Rongxing Lu, Yunguo Guan, Yandong Zheng, Jun Shao 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Towards Efficient and Privacy-Preserving User-Defined Skyline Query Over Single CloudabstractSkyline queries, especially those variants that allow users to define their own query criteria, are very promising and practical techniques in multi-criteria decision making applications. Meanwhile, the growing data volume drives the service providers to outsource their data to the cloud for reaping economic benefits. However, privacy concerns compel the outsourced data to be encrypted and require to perform the skyline queries over encrypted data. To achieve the privacy-preserving skyline queries, many schemes were proposed in the literature. However, those existing solutions cannot fully support the user-defined query criteria in skyline queries, and most of them employ a two-server model to support skyline queries over ciphertexts, which needs multi-round communications between the deployed two servers. In this article, we propose a privacy-preserving user-defined skyline query scheme in a single-server model, which eliminates extra communications. Specifically, we first formally define the user-defined skyline query. Then, based on the idea of converting order relations into computing the inner products of two multi-dimensional points, we design three predicate encryption schemes. Finally, we adopt these predicate encryption schemes to construct our proposed scheme. Detailed security analysis shows that these predicate encryption schemes are selectively secure, and the proposed user-defined skyline query scheme is privacy-preserving. In addition, extensive experiments are conducted, and the results show that our proposed scheme outperforms the alternative scheme by up to an order of magnitude in terms of computational costs when performing user-defined skyline queries. Songnian Zhang, Suprio Ray, Rongxing Lu, Yandong Zheng, Yunguo Guan, Jun Shao 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | Towards Efficient and Privacy-Preserving Interval Skyline Queries Over Time Series DataabstractOutsourcing encrypted time series data and query services to a cloud has been widely adopted by data owners for economic considerations. However, it inevitably lowers data utility and query efficiency. Existing secure skyline query schemes either leak critical information or are inefficient. In this paper, we propose an efficient and privacy-preserving interval skyline query scheme by employing symmetric homomorphic encryption (SHE). Specifically, we first devise a secure sort protocol to sort the encrypted dataset and a secure high-dimensional dominance check protocol to securely determine dominance relations of time series data, in which a dominance check tree is presented. With these secure protocols, we propose our secure skyline computation protocol that can ensure both security and efficiency. Furthermore, to deal with the characteristics of time series data, we design a look-up table to index time series for quick query response. The security analysis shows that our proposed scheme can protect outsourced data, query results, and single-dimensional privacy and hide access patterns. In addition, we evaluate our proposed scheme and compare the core component of our scheme with the state-of-the-art solution, and the results indicate that our protocol outperforms the compared solution by two orders of magnitude in the computational cost and at least 23× in the communication cost. Songnian Zhang, Suprio Ray, Rongxing Lu, Yandong Zheng, Yunguo Guan, Jun Shao 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | PRkNN: Efficient and Privacy-Preserving Reverse kNN Query Over Encrypted DataabstractThe advance of cloud computing has driven an emerging trend of outsourcing the rapidly growing data and query services to a powerful cloud for easing the local storage and computing pressure. Meanwhile, when taking data privacy into account, data are usually outsourced to the cloud in an encrypted form. As a result, query services have to be performed over the encrypted data. Among all kinds of query services, the reverse kNN query is highly popular in various applications, such as taxi dispatching and targeted push of multimedia information, but its privacy has not received sufficient attention. To our best knowledge, many existing privacy-preserving reverse kNN query schemes still have some limitations on the query result accuracy, dataset privacy, and flexible support for the choice of the query object and the parameter k. Aiming at addressing these limitations, in this paper, we propose an efficient and privacy-preserving reverse kNN query scheme over encrypted data, named PRkNN. Specifically, we first design a modified M-tree (MM-tree) to index the dataset and further present an MM-Tree based reverse kNN query algorithm in the filter and refinement framework. Then, we leverage the lightweight matrix encryption to carefully design a filter predicate encryption scheme (FPE) and a refinement predicate encryption scheme (RPE); and propose our PRkNN scheme by applying them to protect the privacy of the MM-Tree based reverse kNN query algorithm. Detailed security analysis shows that FPE and RPE schemes are selectively secure, and our PRkNN scheme can preserve both query privacy and dataset privacy. In addition, we conduct extensive experiments to evaluate the performance of our scheme, and the results demonstrate that our scheme is efficient. Yandong Zheng, Rongxing Lu, Songnian Zhang, Yunguo Guan, Fengwei Wang, Jun Shao 0001, Hui Zhu 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | TCPP: Achieving Privacy-Preserving Trajectory Correlation With Differential PrivacyabstractThe prevalence of mobile Internet, smart terminal devices, and GPS positioning technology has generated a vast number of trajectory data that location-based applications can utilize. However, delivering LBSs based on trajectories without extra protection may expose the personal information of users and even their social ties. Despite the fact that many works have been offered to achieve differential privacy for trajectory correlation, the vast majority of them only consider the trajectory correlation of a single user, and privacy protection for trajectory correlation amongst multiple users is not considered. Directly applying these works to protect correlation amongst multiple users may lead to the low availability of published trajectory data. To address the above challenges, we propose a trajectory correlation privacy-preserving mechanism (TCPP) that fulfills differential privacy. Specifically, we first apply the Euclidean distance to filter out a set of trajectories whose correlation needs to be protected. Then, we employ the Kalman filter to generate a dataset with high availability from the set of trajectories. Finally, we present a mechanism for publishing trajectories that preserves the trajectory correlation based on a customized privacy budget allocation strategy. Rigid security analysis shows that our proposed mechanism can well preserve the correlation privacy of trajectories. Experimental results on real-world datasets further demonstrate the privacy, availability and time efficiency advantages of our mechanism. Lei Wu 0011, Chengyi Qin, Zihui Xu, Yunguo Guan, Rongxing Lu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | SetRkNN: Efficient and Privacy-Preserving Set Reverse kNN Query in CloudabstractThe advance of cloud computing has driven a new paradigm of outsourcing large-scale data and data-driven services to public clouds. Due to the increased awareness of privacy protection, many studies have focused on addressing security and privacy issues in outsourced query services. Although many privacy-preserving schemes have been proposed for various query types, the set reverse k nearest neighbors (RkNN) query is still an unexplored area. Even if some existing schemes can be adapted to achieve privacy-preserving set RkNN queries, they will suffer from linear search efficiency. As a steppingstone, in this paper, we propose an efficient and privacy-preserving set RkNN query scheme over encrypted data with sublinear query efficiency. Specifically, we first design an inverted prefix index to organize the set dataset and propose an algorithm to traverse the index with sublinear search efficiency. Then, we propose two oblivious data comparison protocols based on a symmetric homomorphic encryption (SHE) scheme and design the private filter/refinement protocols to preserve the privacy of index searching. After that, we propose an access pattern privacy-preserving set RkNN query scheme by using private filter/refinement protocols. Rigorous security analysis demonstrates that our scheme can protect data privacy and access pattern privacy. Experimental results indicate that our scheme is more efficient than the available naive solution in terms of computational costs and communication overheads. Yandong Zheng, Rongxing Lu, Hui Zhu 0001, Songnian Zhang, Yunguo Guan, Jun Shao 0001, Fengwei Wang, Hui Li 0006 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | PGSim: Efficient and Privacy-Preserving Graph Similarity Query Over Encrypted Data in CloudabstractThe boom of cloud computing has stimulated the prevalence of outsourced query services, and privacy concerns further motivate extensive studies on privacy-preserving queries in the cloud. Graph similarity query is one critical query type, in which the similarity between two graphs is usually measured by graph edit distance (GED). Although many schemes have been proposed for GED computation/graph similarity query, they do not consider data privacy and are not applicable to the cloud computing scenario. To address this issue, in this paper, we propose the first efficient and privacy-preserving graph similarity query (PGSim) scheme in the filter and verification framework. Specifically, we first identify the pivot filter property of GED and use the property to design a pivot R-tree based filter algorithm, which can efficiently retrieve candidate graphs for graph similarity query. Then, we design a vertex mapping (VM) tree to index all vertex mappings between two graphs and develop a GED query verification algorithm to verify candidate graphs. After that, we design a suite of private algorithms based on a symmetric homomorphic encryption scheme and apply them to propose a pivot R-tree based filter predicate encryption (PRFilter) scheme and a private GED query verification (PGQVerify) algorithm. Based on the PRFilter scheme and the PGQVerify algorithm, we propose our PGSim scheme. Rigorous security analysis shows that our scheme is selectively secure. Performance evaluation also demonstrates the high efficiency of our scheme. Yandong Zheng, Hui Zhu 0001, Rongxing Lu, Yunguo Guan, Songnian Zhang, Fengwei Wang, Jun Shao 0001, Hui Li 0006 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Efficient and Privacy-Preserving Aggregated Reverse kNN Query Over Crowd-Sensed DataabstractThe aggregated reverse kNN (ARkNN) query aims to identify one query record with the maximum influence set and has become a powerful tool to support optimal decision-making in crowdsensing. Considering data privacy and query privacy, ARkNN queries should be performed in a private manner. Unfortunately, existing schemes cannot support privacy-preserving ARkNN queries over crowd-sensed data. To address this issue, we propose two efficient and privacy-preserving ARkNN query schemes with different security levels, named the BARQ scheme and the EARQ scheme, where the former can only protect data privacy while the latter can protect both data privacy and query privacy. Specifically, we first formalize the models of privacy-preserving ARkNN queries and propose our BARQ scheme based on a random response (RR) frequency oracle. Then, we design a privacy-preserving hardware-assisted reverse kNN query determination (PRkD) scheme for privately determining whether a query record is among the RkNN of a data record. After that, we present our EARQ scheme by leveraging the PRkD scheme to protect query privacy and integrating the RR frequency oracle to protect data privacy. In addition, our rigorous security analysis demonstrates that the BARQ scheme can well protect data privacy, and the EARQ scheme can protect both data privacy and query privacy. Extensive experimental results illustrate that they have high accuracy in query results and are efficient in computational costs and communication overheads. Yandong Zheng, Hui Zhu 0001, Rongxing Lu, Yunguo Guan, Songnian Zhang, Fengwei Wang, Jun Shao 0001, Hui Li 0006 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | SecBerg: Secure and Practical Iceberg Queries in CloudabstractSecure queries are fundamental to data security, particularly in cloud databases. In data analytics, one of the common and practical queries is the iceberg query that can find aggregate values above a specified threshold. However, existing secure aggregate query schemes: 1) are unable to support secure iceberg queries equipped with the HAVING clause; 2) only consider additive aggregate functions; and 3) suffer from performance issues due to the use of homomorphic encryption to encrypt databases. In this article, we present a secure iceberg query scheme, SecBerg, to support both addition-based and comparison-based aggregate functions and ensure high efficiency and security simultaneously. To make it possible, we propose a secure bitmap index system to encode database values and pioneer the use of the arithmetic secret sharing technique to protect databases in the cloud environment. Furthermore, we carefully design efficient and secure protocols over arithmetic secret sharing to construct our SecBerg. Extensive evaluations are conducted, and the results indicate that SecBerg is significantly more efficient than the state-of-the-art relevant scheme in computational overhead and can attain orders of magnitude performance improvement at best. Songnian Zhang, Suprio Ray, Rongxing Lu, Yunguo Guan, Yandong Zheng, Jun Shao 0001 |
IEEE Trans. Serv. Comput. | 4 |
| 2023 | Non-Interactive Multi-Client Searchable Symmetric Encryption With Small Client StorageabstractConsiderable attention has been paid to dynamic searchable symmetric encryption (DSSE) which allows users to search on dynamically updated encrypted databases. To improve the performance of real-world applications, recent non-interactive multi-client DSSE schemes are targeted at avoiding per-query interaction between data owners and data users. However, existing non-interactive multi-client DSSE schemes do not consider forward privacy or backward privacy, making them exposed to leakage abuse attacks. Besides, most existing DSSE schemes with forward and backward privacy rely on keeping a keyword operation counter or an inverted index, resulting in a heavy storage burden on the data owner side. To address these issues, we propose a non-interactive multi-client DSSE scheme with small client storage, and our proposed scheme can provide both forward privacy and backward privacy. Specifically, we first design a lightweight storage chain structure that binds all keywords to a single state to reduce the storage cost. Then, we present a Hidden Key technique, which preserves non-interactive forward privacy through time range queries, ensuring that data with newer timestamps cannot match earlier time ranges. We conduct extensive experiments to validate our methods, which demonstrate computational efficiency. Moreover, security analysis proves the privacy-preserving property of our methods. Chang Xu 0004, Rongxing Lu, Liehuang Zhu, Chuan Zhang 0003, Yunguo Guan |
IEEE Trans. Serv. Comput. | 6 |
| 2023 | Efficient and Privacy-Preserving Spatial-Feature-Based Reverse kNN QueryabstractReverse k nearest neighbor (RkNN) query has been widely applied in the targeted push of information. Many schemes for the RkNN query on encrypted data have been proposed for coordinating the emerging trend of outsourcing data to the cloud. However, none of them supports the spatial data with many features, a prevalent data type in location-based services, e.g., each user in online dating apps usually has a spatial location and many personality trait features. Meanwhile, incorporating features with the spatial data endows the spatial-feature-based RkNN query to provide more precise services than the spatial-based RkNN query. Therefore, as a steppingstone, we propose an efficient and privacy-preserving spatial-feature-based RkNN scheme in this work for the first time. Specifically, we first design a modified intersection and union R tree (MIUR-tree) to index the spatial and feature data. Then, we introduce an MIUR-tree based RkNN query algorithm in the filter and refinement framework to efficiently process RkNN queries. After that, based on a symmetric homomorphic encryption (SHE) scheme, we design a private filter protocol and a private refinement protocol, and leverage them to propose our RkNN query scheme. Rigorous security analysis demonstrates that our scheme is privacy-preserving, and extensive experiments indicate that our scheme is computationally efficient. Yandong Zheng, Rongxing Lu, Yunguo Guan, Songnian Zhang, Jun Shao 0001, Fengwei Wang, Hui Zhu 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2023 | EPPFM: Efficient and Privacy-Preserving Querying of Electronic Medical Records With Forward Privacy in Multiuser SettingabstractWith the application of the Internet of Things (IoT) and cloud computing, the eHealthcare industry has developed markedly, attracting many patients to seek medical treatment in an eHealthcare system. However, for patients who first register in the system, due to lack of experience, an important aspect is to choose appropriate medical services. Considering the sensitivity of health care data and the semi-honest nature of the cloud server, it is a good solution to use searchable encryption (SE) to obtain some historical electronic medical records (EMRs) that are consistent with the patient's symptom keyword combination and have high service scores for reference. However, existing SE schemes still have issues meeting the requirements of the eHealthcare system for flexible authorization and revocation, efficiency, and forward privacy. To resolve these issues, we propose two efficient and privacy-preserving electronic medical records query schemes with forward privacy in a multiuser setting (EPPFM). First, we present the basic scheme EPPFM-I to achieve a multiuser multikeyword exact match query under linear search complexity. In EPPFM-I, we also use the pseudorandom function (PRF) to perform the function of forward privacy. Then, we use a bucket structure to construct the improved scheme EPPFM-II, which has a faster-than-linear search complexity. Finally, we use detailed security analysis and extensive simulations to show the security and efficiency of the proposed schemes, respectively. Chang Xu 0004, Zijian Chan, Liehuang Zhu, Can Zhang 0002, Rongxing Lu, Yunguo Guan |
IEEE Trans. Sustain. Comput. | 6 |
| 2023 | Non-Interactive DSSE for Medical Data Sharing With Forward and Backward PrivacyabstractIn medical cloud computing, more medical data owners are preferred to outsource their sensitive data to the cloud after encryption. Meanwhile, dynamic searchable symmetric encryption (DSSE) provides the capability for data users to query over the dynamically-updated encrypted database. To reduce update leakage, a secure DSSE scheme usually requires forward and backward privacy. However, existing multi-client DSSE schemes with forward and backward privacy require the data owner to keep online to respond to per-query interaction from data users. To address this issue, we propose a multi-client non-interactive DSSE scheme with forward and backward privacy, namely MCNI. The core design of MCNI is leveraging time range queries to achieve non-interactive forward privacy since the past queries cannot be used to search the newly-added timestamps. To enable efficient time range queries, we convert the timestamp and time range into the boolean wildcard form and develop Boolean Wildcard Matching (BWM) algorithm that formulates the match as a dot product calculation problem. Finally, we combine the polynomial fitting technique, time range query, and random matrix multiplication technique to achieve efficient keyword searches without revealing sensitive information. Theoretical analysis and extensive experiments demonstrate the security and effectiveness of our proposed scheme, respectively. Chang Xu 0004, Liehuang Zhu, Chuan Zhang 0003, Rongxing Lu, Yunguo Guan, Kashif Sharif |
IEEE Trans. Sustain. Comput. | 6 |
| 2022 | Privacy-Preserving Outsourced Task Scheduling in Mobile CrowdsourcingabstractWith the proliferation of smart devices with various onboard sensors, mobile crowdsourcing has attracted consider-able interest, in which task scheduling is an essential service for allocating tasks to workers. As the number of workers increases, the service provider prefers to outsource the service to a powerful cloud, and the messages from the workers and the task owners should be protected. Currently, the existing works on privacy-preserving task allocation cannot simultaneously achieve strong privacy protection and dynamic update. Aiming at this challenge, we propose a privacy-preserving outsourced task scheduling scheme, in which the cloud servers can obliviously conduct task scheduling and update the workers' information based on the scheduling results. To this end, we design three secure protocols under a two-server model, which can protect the protocols' input and output against the cloud servers. The security analysis demonstrates that our proposed scheme can achieve strong privacy protection, and the experimental results indicate the scheme's efficiency in computing and communication. Yunguo Guan, Pulei Xiong, Songnian Zhang, Rongxing Lu |
GLOBECOM | 1 |
| 2022 | PPsky: Privacy-Preserving Skyline Queries with Secret Sharing in eHealthcareabstractApplying skyline queries to medical data can considerably benefit medical analysis in eHealthcare. However, as medical data often involves sensitive personal data, privacy concerns have become a significant impediment to the development of eHealthcare. Although several privacy-preserving skyline query schemes in eHealthcare have been put forth, they need a trusted platform to generate and assign secret keys for the multi-source scenario. In addition, those schemes incur non-trivial computational costs on resource-limited entities. To address these limitations, we propose a novel privacy-preserving skyline query scheme, named PPsky, based on arithmetic secret sharing, in which a series of secure protocols are designed to handle the basic operations in skyline queries. Security analysis illustrates that our PPsky scheme is privacy-preserving, and the evaluation results also validate the efficiency of our PPsky scheme. Songnian Zhang, Suprio Ray, Rongxing Lu, Yunguo Guan |
GLOBECOM | 4 |
| 2022 | EVRQ: Achieving Efficient and Verifiable Range Query over Encrypted Traffic DataabstractAs a promising solution in boosting the efficiency of urban traffic, intelligent transportation systems (ITS) have been increasingly deployed. Traffic message dissemination, connecting various services and entities, has been regarded as an essential service in ITS, and range query service has also been frequently used for on-demand traffic message retrieval. Meanwhile, as the dataset grows, the service provider tends to outsource the range query services to fog nodes. However, as the fog nodes are not fully trustable, directly outsourcing the services to them may invoke security concerns: on the one hand, the private information, including the traffic messages, query requests, and results should not be revealed to the fog nodes. On the other hand, the fog nodes may return incorrect and/or incomplete query results. Although many schemes have been proposed to achieve privacy-preserving range queries, few of them can support verifiability over dynamic datasets. Therefore, in this paper, we propose an efficient and verifiable range query (EVRQ) scheme over encrypted traffic messages. Specifically, we first build two techniques to respectively enable the fog nodes to efficiently determine and prove whether two rectangles intersect. Then, based on the two approaches and R-tree technique, we create a Merkle R-tree, which we use to build our EVRQ scheme. Security analysis shows that our proposed scheme is really privacy-preserving and can achieve verifiability of the query results. In addition, extensive experiments are conducted, and the results demonstrate that our proposed scheme is indeed efficient. Yunguo Guan, Pulei Xiong, Rongxing Lu |
ICC | 1 |
| 2022 | EPGQ: Efficient and Private Feature-Based Group Nearest Neighbor Query Over Road NetworksabstractThe rapidly growing location-based services enable service providers to accumulate plentiful descriptions on points of interest (POIs), which can be used to support expressive POI queries. In this article, we study a type of POI query, named feature-based group$k$nearest neighbor query over road networks, in which a user has a feature set and several locations and wishes to find$k$closest POIs that have similar sets of features to the query. As the POI data sets grow, service providers tend to outsource their data sets to a powerful yet not-fully trusted cloud, which calls for privacy preservation on data sets and user queries. Although many schemes have been proposed for privacy-preserving POI queries, none of them can simultaneously support privacy-preserving set similarity and road network distance comparison. To address this challenge, we propose an efficient and private feature-based group nearest neighbor query scheme. In our scheme, we achieve privacy-preserving distance comparison by employing the road network hypercube embedding technique, and design an encrypted index based on B+-tree for privacy-preserving set similarity range queries. Security analysis shows our proposed scheme can preserve the privacy of the data set and queries, and performance evaluation also demonstrates it is computationally efficient. Yunguo Guan, Rongxing Lu, Yandong Zheng, Songnian Zhang, Jun Shao 0001, Guiyi Wei |
IEEE Internet Things J. | 1 |
| 2022 | Achieving Efficient and Privacy-Preserving Dynamic Skyline Query in Online Medical DiagnosisabstractWireless body area network (WBAN) and big data techniques indubitably enable the online medical diagnosis system to be more practical. In the system, to make a more accurate diagnosis, doctors wish to obtain some archived medical data records, which are similar to the sensed patient data, to learn from the prior diagnoses. As a practically useful similarity search, the dynamic skyline query can provide doctors with similar data records having all possible relative weights of attributes. Driven by the powerful cloud, the data owner often outsources encrypted data and the corresponding services, e.g., dynamic skyline query services here, to a third-party cloud. As a result, it is required to perform the dynamic skyline query over encrypted data. However, existing schemes are either insecure or inefficient. To address the issue, in this article, we propose an efficient and privacy-preserving dynamic skyline query scheme and use it in an online medical diagnosis system. Specifically, based on symmetric homomorphic encryption (SHE), we present a set of efficient and secure protocols to achieve various operations, such as less than comparison, equality test, and dominance determination, without leaking any sensitive information to the cloud. With these secure protocols, we carefully design our dynamic skyline query scheme to attain full security and high efficiency at the same time. Detailed security analysis shows that our proposed scheme is indeed privacy-preserving. With extensive experimental evaluations, we show that our proposed scheme outperforms the alternative scheme by two orders of magnitude in the computational cost and at least$8.1\times $in the communication cost. Songnian Zhang, Suprio Ray, Rongxing Lu, Yandong Zheng, Yunguo Guan, Jun Shao 0001 |
IEEE Internet Things J. | 5 |
| 2022 | PPAQ: Privacy-Preserving Aggregate Queries for Optimal Location Selection in Road NetworksabstractAggregate nearest neighbor (ANN) query, which can find an optimal location with the smallest aggregate distance to a group of query users’ locations, has received considerable attention and been practically useful in many real-world location-based applications. Nevertheless, query users still hesitate to use these applications due to privacy concerns, as there is a worrisome that the location-based service (LBS) providers may abuse their locations after collecting them. In this article, to tackle this issue, we propose a novel privacy-preserving aggregate query (PPAQ) scheme to select an optimal location for query users in road networks. Specifically, we first analyze the problem of the ANN query in road networks and identify two basic operations, i.e., addition and comparison, in the query. Then, we carefully design efficient addition and comparison circuits to securely add and compare two bit-based inputs, respectively. With these two secure circuits, we propose our PPAQ scheme, which can simultaneously protect the users’ locations, query results, and access patterns from leaking. Detailed security analysis shows that our proposed scheme is indeed privacy-preserving. In addition, extensive performance evaluations are conducted, and the results indicate that our proposed scheme has an acceptable efficiency for non-real-time applications. Songnian Zhang, Suprio Ray, Rongxing Lu, Yandong Zheng, Yunguo Guan, Jun Shao 0001 |
IEEE Internet Things J. | 5 |
| 2022 | PMRQ: Achieving Efficient and Privacy-Preserving Multidimensional Range Query in eHealthcareabstractHealthcare data explosion and cloud computing booming have motivated healthcare centers to outsource their healthcare data and data-driven services to a powerful cloud. Nevertheless, due to privacy concerns, the data are usually encrypted before being outsourced, which will degrade the data utility and make it challenging to implement data-driven services. Although the multidimensional range query over encrypted data, as one of the most popular outsourced services in eHealthcare, has been extensively studied, existing solutions still have some limitations in efficiency, privacy, and practicality. Aiming at this challenge, in this article, we design an efficient and privacy-preserving multidimensional range query (PMRQ) scheme. We first build an R-tree to index the data set and reduce the R-tree-based range queries to the multidimensional range intersection problem. Then, by delicately designing a data comparison algorithm and a homomorphic encoding technique, we present an encoding-based range intersection algorithm. After that, by employing matrix encryption to protect the privacy of the encoding-based range intersection algorithm, we design a multidimensional range intersection predicate encryption (MRIPE) scheme. Based on the MRIPE scheme, we then propose our PMRQ scheme. A detailed security analysis illustrates that our PMRQ scheme is privacy preserving, and experimental results demonstrate that it is computationally efficient. Yandong Zheng, Rongxing Lu, Songnian Zhang, Yunguo Guan, Jun Shao 0001, Fengwei Wang, Hui Zhu 0001 |
IEEE Internet Things J. | 4 |
| 2022 | Toward Privacy-Preserving Healthcare Monitoring Based on Time-Series Activities Over CloudabstractThe thriving of the Internet of Things (IoT) has become the enabler of smart eHealthcare, which greatly benefits patients by providing various data-driven healthcare monitoring services. Among those promising services, the time-series activities-based healthcare monitoring service is highly regarded due to its popularity. Meanwhile, with the rapidly growing volume of healthcare data, an emerging trend is to outsource the time-series activities-based healthcare monitoring models and the corresponding services to a cloud, which, however, inevitably entails privacy concerns. Although many existing works have put forth some solutions for privacy-preserving time-series activities-based healthcare monitoring, they are not applicable to the outsourced scenario with a single-server setting. To address the challenge, in this article, we propose an efficient and privacy-preserving forward algorithm (PPFA) and further apply PPFA to construct a remote healthcare monitoring scheme over the cloud. To the best of our knowledge, our PPFA is the first privacy-preserving forward algorithm over cloud while without any accuracy loss. In addition, our remote healthcare monitoring scheme is also the first privacy-preserving hidden Markov model-based healthcare monitoring scheme in the single-server setting. Detailed security analysis shows that our PPFA and healthcare monitoring scheme are indeed privacy preserving. In addition, extensive simulations are conducted, and the results also demonstrate their efficiencies. Yandong Zheng, Rongxing Lu, Songnian Zhang, Yunguo Guan, Jun Shao 0001, Hui Zhu 0001 |
IEEE Internet Things J. | 4 |
| 2022 | Efficient and Privacy-Preserving Similarity Range Query Over Encrypted Time Series DataabstractSimilarity query over time series data plays a significant role in various applications, such as signal processing, speech recognition, and disease diagnosis. Meanwhile, driven by the reliable and flexible cloud services, encrypted time series data are often outsourced to the cloud, and as a result, the similarity query over encrypted time series data has recently attracted considerable attention. Nevertheless, existing solutions still have issues in supporting similarity queries over time series data with different lengths, query accuracy and query efficiency. To address these issues, in this article, we propose a new efficient and privacy-preserving similarity range query scheme, where the time warp edit distance (TWED) is used as the similarity metric. Specifically, we first organize time series data into a$k$d-tree by leveraging TWED’s triangle inequality, and design an efficient similarity range query algorithm for the$k$d-tree. Second, based on a symmetric homomorphic encryption technique, we carefully devise a suite of privacy-preserving protocols to provide a security guarantee for$k$d-tree based similarity range queries. After that, by using the similarity range query algorithm and these protocols, we propose our privacy-preserving similarity range query scheme, in which we elaborate on two strategies to make our scheme resist against the cloud inference attack. Finally, we analyze the security of our scheme and conduct extensive experiments to evaluate its performance, and the results indicate that our proposed scheme is indeed privacy-preserving and efficient. Yandong Zheng, Rongxing Lu, Yunguo Guan, Jun Shao 0001, Hui Zhu 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | Achieving Efficient and Privacy-Preserving Exact Set Similarity Search over Encrypted DataabstractSet similarity search, aiming to search the similar sets to a query set, has wide application in today's recommendation services. Meanwhile, the rapid advance in cloud technique has promoted the boom of data outsourcing. However, since the cloud is not fully trustable and the data may be sensitive, data should be encrypted before outsourced to the cloud. Undoubtedly, data encryption will hinder some basic functionalities, e.g., set similarity search. For achieving set similarity search over encrypted data, many solutions were proposed, yet they either only satisfy weak security requirements, or only achieve approximate similarity, or have low efficiency or under the model of two cloud servers. Therefore, in this article, we propose a new efficient and privacy-preserving exact set similarity search scheme under a single cloud server. Specifically, we first design a symmetric-key predicate encryption (SPE-Sim) scheme, which can support similarity search over binary vectors. Then, we represent the set records to be binary vectors and employ the B+ tree to build an index for them. After that, based on SPE-Sim and the B+ tree-based index, we propose our scheme and it can achieve efficient set similarity search while preserving the privacy of set records and query contents. Finally, security analysis and performance evaluation indicate that our scheme is privacy-preserving and efficient. Yandong Zheng, Rongxing Lu, Yunguo Guan, Jun Shao 0001, Hui Zhu 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | Towards Practical and Privacy-Preserving Multi-Dimensional Range Query Over CloudabstractIt is undeniable that Internet of Things (IoT) in big data era can provide us with huge volumes of multi-dimensional data, transforming our society into a much more intelligent one. In order to fit for the multi-dimensional data processing in big data era, multi-dimensional range queries, especially over cloud platform, have received considerable attention in recent years. However, as the cloud server is not fully trustable, designing multi-dimensional range queries over encrypted data becomes a research trend, and many solutions have been proposed in the literature. Nevertheless, most existing solutions suffer from the leakage of the single-dimensional privacy, and such leakage would severely put the data at risk. Although a few existing works have addressed the problem of single-dimensional privacy, they are impractical in some real scenarios due to the issues of inefficiency, inaccuracy, and two-cloud-server requirement. Aiming at solving these issues, in this article, we propose a practical and privacy-preserving multi-dimensional range query (PRQ) scheme. Specifically, in our proposed PRQ scheme, we first index the multi-dimensional dataset with an R-tree and reduce R-tree based range queries to the problem of point intersection and range intersection. Then, by employing the lightweight matrix encryption technique, we design two novel algorithms for PRQ, i.e., multi-dimensional point intersection predicate encryption (PIPE) and multi-dimensional range intersection predicate encryption (RIPE), which can preserve the privacy of the proposed point intersection algorithm and range intersection algorithm, and further preserve the single-dimensional privacy of the proposed PRQ scheme. Detailed security analysis shows that our proposed PRQ scheme is indeed privacy-preserving. In addition, extensive simulations are conducted, and the results also demonstrate its efficiency. Yandong Zheng, Rongxing Lu, Yunguo Guan, Jun Shao 0001, Hui Zhu 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | Toward Privacy-Preserving Aggregate Reverse Skyline Query With Strong SecurityabstractIt has been witnessed that Aggregate Reverse Skyline (ARS) query has recently received a wide range of practical applications due to its marvelous property of identifying the influence of query requests. Nevertheless, the query users may hesitate to participate in such query services as the query requests and query results may leak sensitive personal data or valuable business data assets to the service providers. To tackle the concerns, a promising solution is to encrypt the query requests, conduct the ARS queries over encrypted query requests without decrypting, and return the encrypted query results. Unfortunately, many existing solutions are either deployed over a two-server model or unable to fully preserve query privacy. In this paper, we propose a novel privacy-preserving aggregate reverse skyline query (PPARS) scheme on a single server model while ensuring full query privacy. Specifically, we first transform the problem of ARS query into a combination of set membership test and logical expressions. Then, by employing the prefix encoding technique, bloom filter technique, and fully homomorphic encryption, we run the transformed logical expressions to obtain the encrypted aggregate values without leaking query requests, query results, and access patterns. Furthermore, we propose an interpolation-based packing technique to improve the communication efficiency of PPARS. Detailed and formal security analysis demonstrates that our proposed schemes can guarantee strong security. In addition, extensive experiments are conducted, and the results validate the efficiency of our proposed schemes. Songnian Zhang, Suprio Ray, Rongxing Lu, Yunguo Guan, Yandong Zheng, Jun Shao 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | Efficient and Privacy-Preserving Similarity Query With Access Control in eHealthcareabstractSimilarity queries, giving a way to disease diagnosis based on similar patients, have wide applications in eHealthcare and are essentially demanded to be processed under fine-grained access policies due to the high sensitivity of healthcare data. One efficient and flexible way to implement such queries is to outsource healthcare data and the corresponding query services to a powerful cloud. Nevertheless, considering data privacy, healthcare data are usually outsourced in an encrypted form and required to be accessed in a privacy-preserving way. In the past years, many schemes have been proposed for privacy-preserving similarity queries. However, none of them is applicable to achieve data access control and access pattern privacy preservation. Aiming at this challenge, we propose an efficient and access pattern privacy-preserving similarity range query scheme with access control (named EPSim-AC). In our proposed scheme, we first design a novel tree structure, called$k$-d-PB tree, to index healthcare data and introduce an efficient$k$-d-PB tree based similarity query algorithm with access control. Second, to balance the search efficiency and access pattern privacy of$k$-d-PB tree, we also define a weakened access pattern privacy, called$k$-d-PB tree’s$\beta $-access pattern unlinkability. After that, we preserve the privacy of$k$-d-PB tree based similarity queries with access control through a symmetric homomorphic encryption scheme and present our detailed EPSim-AC scheme. Finally, we analyze the security of our scheme and also conduct extensive experiments to evaluate its performance. The results demonstrate that our scheme can guarantee$k$-d-PB tree’s$\beta $-access pattern unlinkability and has high efficiency. Yandong Zheng, Rongxing Lu, Yunguo Guan, Songnian Zhang, Jun Shao 0001, Hui Zhu 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | Fair Outsourcing Polynomial Computation Based on the BlockchainabstractDue to the big data blowout from the Internet of Things and the rapid development of cloud computing, outsourcing computation has received considerable attention in recent years. Particularly, many outsourcing computation schemes have been proposed to dedicate the outsourcing polynomial computation due to its use in numerous fields, such as data analysis and machine learning. However, none of those schemes are practical enough, as they either require some time-consuming cryptographic operations to achieve fairness between the user and the worker, or cannot allow the user to outsource arbitrary polynomial to the worker, or need two non-collusive workers. To tackle these challenges, in this article, we propose a new outsourcing polynomial computation scheme by employing a variant of Horner’s method and the blockchain technology. Specifically, the former makes the computational cost on the worker side as low as possible, and the latter guarantees the fairness between the user and the worker if the result from the worker can be publicly verified. To achieve the public verifiability property, we apply the sampling technique, which is effective in our proposal according to a game-theoretic analysis. Furthermore, we also implement a prototype of our proposal and run it on an Ethereum test net. The extensive experimental results demonstrate that our proposal is efficient in terms of computational cost. Yunguo Guan, Jun Shao 0001, Rongxing Lu, Guiyi Wei |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | Achieve Efficient and Verifiable Conjunctive and Fuzzy Queries over Encrypted Data in CloudabstractDue to the high demands of searchability over encrypted data, searchable encryption (SE) has recently received considerable attention and been widely suggested in encrypted cloud storage. Typically, the cloud server is assumed to be honest-but-curious in most SE-based cloud storage systems, i.e., the cloud server should follow the protocol to return valid and complete search results to users. However, this trust assumption is not always true due to some unanticipated situations, such as misconfigurations and malfunctions. Therefore, the function of verifiability of search results becomes crucial for the success of SE-based cloud storage systems. For this reason, many verifiable SE schemes have been proposed; however, they either fail to support query operators “OR”, “AND”, “$\ast$” and “?” simultaneously, or require many time-consuming operations. Aiming at addressing this problem, in this paper, we propose a new verifiable SE scheme for encrypted cloud storage. The proposed scheme is characterized by integrating various techniques, i.e., bitmap index, radix tree, format preserving encryption, keyed-hash message authentication code and symmetric key encryption, for achieving efficient and verifiable conjunctive and fuzzy queries over encrypted data in the cloud. Detailed security analysis shows that our proposed scheme holds the confidentiality of data and verifiability of search results at the same time. In addition, extensive experiments are conducted, and the results demonstrate our proposed scheme is efficient and suitable for users to retrieve their data from the cloud to their mobile devices. Jun Shao 0001, Rongxing Lu, Yunguo Guan, Guiyi Wei |
IEEE Trans. Serv. Comput. | 3 |
| 2022 | Achieving Efficient and Privacy-Preserving Set Containment Search Over Encrypted DataabstractSet containment search, which aims to retrieve all set records containing a specific query set, has received considerable attention. Meanwhile, due to the dramatic growth of data, data owners tend to outsource their data to the cloud and deploy the cloud server to offer the set containment search services. However, as the cloud server is not fully trustable and the data may be sensitive, a straightforward strategy for the data owners is to encrypt the data before outsourcing them. Although the encryption technique can preserve data privacy, it inevitably hinders the functionality of set containment search. Many existing studies on the set containment search over outsourced data still suffer from the search efficiency and security issues. In this article, aiming at the above issues, we propose an efficient and privacy-preserving set containment search scheme. Specifically, we first deploy an asymmetric scalar-product-preserving encryption technique to design a set containment/intersection encryption (SCIE-Enc) scheme. Then, we build a radix tree to represent the set records. Based on the radix tree and SCIE-Enc construction, we present our scheme that can achieve efficient set containment search while preserving the privacy of set records, query sets, and query results, as indicated in our security analysis and performance evaluation. Yandong Zheng, Rongxing Lu, Yunguo Guan, Jun Shao 0001, Hui Zhu 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2022 | Efficient Privacy-Preserving Similarity Range Query With Quadsector Tree in eHealthcareabstractAs a consequence of advance in the Internet of Things (IoT) and big data technology, smart eHealthcare has emerged and greatly enabled patients to enjoy high-quality healthcare services in disease prediction, clinical decision making and healthcare surveillance. Meanwhile, in order to support the dramatic increase of healthcare data, healthcare centers often outsource the on-premises data to a powerful cloud and deploy the cloud server to manage the data. However, since the healthcare data usually contain some sensitive information and also the cloud server is not fully trusted, healthcare centers need to encrypt the data before outsourcing them to the cloud. Unfortunately, data encryption inevitably hinders some advanced applications of the data like the similarity range query in cloud. Although many studies on similarity range query over encrypted data have been reported, most of them still have some limitations in security, efficiency and practicality. Aiming at this challenge, in this article, we propose a new efficient privacy-preserving similarity range query (EPSim) scheme. Specifically, we first present a modified asymmetric scalar-product-preserving encryption (ASPE) scheme and prove it is selectively secure. Then, we introduce a Quadsector tree to represent the data, and employ a filtration condition to design an efficient algorithm for efficient similarity range queries over the Quadsector tree. Finally, we propose our EPSim scheme by integrating the modified ASPE scheme and Quadsector tree. Detailed security analysis indicates that our proposed EPSim scheme is really secure. In addition, extensive performance evaluations are conducted, and the results also demonstrate it is efficient and practical. Yandong Zheng, Rongxing Lu, Yunguo Guan, Jun Shao 0001, Hui Zhu 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2021 | Privacy-Preserving Fog-Based Multi-Location Task Allocation in Mobile CrowdsourcingabstractAs a wave of the rapidly approaching future, vehicles are becoming increasingly “smarter” via equipping with abundant resources for data sensing, processing, and transmitting. To fully make use of these resources, mobile crowdsourcing applications have attracted particular interests from academia and industry, and they are extensively integrated with fog computing for obtaining low latency and location sensitivity. In this paper, we consider a fog-based task allocation service for mobile crowdsourcing tasks with multiple locations, where a task is allocated to the worker whose future trajectory has the smallest Hausdorff semi-distance to the task locations. However, as fog nodes are not fully trusted, there may exist privacy concerns related to the workers and the task owners. To the best of our knowledge, although Hausdorff semi-distance has been applied in various applications, none of the existing works can support privacy-preserving Hausdorff semi-distance evaluation or$k$nearest neighbor queries. Aiming at this issue, we design a privacy-preserving fog-based multi-location task allocation scheme. Specifically, based on a symmetric homomorphic encryption technique, we build two privacy-preserving protocols for i) computing min/max value from an array and ii) retrieving the key linked to the minimum value from an array of key-value pairs. Then, the proposed scheme is built upon these two protocols. After that, we conduct rigid security analysis and extensive experiments to demonstrate the security and efficiency of our proposed scheme, respectively. The results indicate that our proposed scheme is not only privacy-preserving, but also efficient in terms of both computation and communication costs. Yunguo Guan, Pulei Xiong, Rongxing Lu |
GLOBECOM | 1 |
| 2021 | Towards Private Similarity Query based Healthcare Monitoring over Digital Twin Cloud PlatformabstractAs the growing proportion of aging population, the demand for sustainable, high quality, and timely healthcare services has become increasingly pressing, especially since the outbreak of COVID-19 pandemic in the early of 2020. To meet this demand, a promising strategy is to introduce cloud computing and digital twin techniques into the healthcare systems, where the cloud server is employed for storing healthcare data and offering efficient query services, and the digital twin is used for building digital representation for patients and leverages the query services of the cloud server to monitor healthcare states of patients. Although several cloud computing and digital twin based healthcare monitoring frameworks have been proposed, none of them has considered the data privacy issue, yet the leakage of the private healthcare information may cause catastrophic losses to patients. Aiming at the challenge, in this paper, we propose an efficient and privacy-preserving similarity query based healthcare monitoring scheme over digital twin cloud platform, named PSim-DTH. Specifically, we first formalize a similarity query based healthcare monitoring model over digital twin cloud platform. Then, we deploy a partition-based tree (PB-tree) to index the healthcare data and introduce matrix encryption to propose a privacy-preserving PB-tree based similarity range query (PSRQ) algorithm. Based on PSRQ algorithm, we propose our PSim-DTH scheme. Both security analysis and performance evaluation are extensively conducted, and the results demonstrate that our proposed PSim-DTH scheme is really privacy-preserving and efficient. Yandong Zheng, Rongxing Lu, Yunguo Guan, Songnian Zhang, Jun Shao 0001 |
IWQoS | 3 |
| 2021 | Achieve space-efficient key management in lightning network
Guiyi Wei, Xiaohang Mao, Rongxing Lu, Jun Shao 0001, Yunguo Guan, Genhua Lu |
Comput. Networks | 5 |
| 2021 | Toward Oblivious Location-Based k-Nearest Neighbor Query in Smart CitiesabstractEnabled by the flourishing Internet-of-Things technology, smart cities can offer a variety of smart services to our daily lives and have received considerable attention in recent years. As a pivotal component of smart cities, location-based services (LBSs) have been deeply exploited by both academia and industry. Meanwhile, since cloud computing can provide reliable and flexible IT resources, many LBS services have been outsourced to the cloud for offering better services. Nevertheless, as the cloud is not fully trusted, privacy preservation becomes an essential requirement for these services. Over the past years, many privacy-preserving location-based k-nearest neighbor ( kNN) query schemes over the cloud have been proposed. However, most of them are subjected to an inevitable design defect, i.e., whenever a user queries twice at the same location, the cloud can identify and return the same query result to the query user, and such information together with third-party data breaches could be exploited by the cloud for some location disclosures. Although some existing schemes can cope with the issue, they are not quite practical, as they will bring heavy overheads on the query user side. In this article, aiming to address the above challenge, we propose a novel oblivious location-based kNN query scheme, in which the cloud cannot link two queries even if they are initiated by query users at the same location. Specifically, based on the modified Paillier cryptosystem, we first present three privacy-preserving protocols, namely, oblivious absolute value calculation, sorting, and top- k extraction. Then, by integrating these three protocols, we propose our novel oblivious location-based kNN query scheme. The detailed security analysis shows that our proposed scheme really enhances the privacy preservation in LBS queries. In addition, extensive performance analysis and experiments are conducted, and the results indicate that our proposed scheme is also efficient for the query user. Yunguo Guan, Rongxing Lu, Yandong Zheng, Jun Shao 0001, Guiyi Wei |
IEEE Internet Things J. | 1 |
| 2021 | Toward Privacy-Preserving Cybertwin-Based Spatiotemporal Keyword Query for ITS in 6G EraabstractThe sixth-generation (6G) communication technology has been attracting great interests from both industry and academia, as it is regarded as a promising approach to achieve more stable and low-latency communication. These promising features of 6G make it an enabler for cybertwin, a technique to create digital representations for physical objects to implement various functionalities. In this article, we consider a cybertwin-based spatiotemporal keyword query service over a dynamic message data set in intelligent transportation system (ITS) scenarios. Particularly, in the considered service, publishers upload messages to the cloud, and each cybertwin predictively launches queries to retrieve messages on behalf of the corresponding vehicle, such that each vehicle can timely receive messages that are of its interest whenever it arrives at a location. Nevertheless, as the cloud is not fully trustable, there exist privacy concerns related to the messages and queries. Up to now, although many schemes have been proposed to handle privacy-preserving spatial, temporal, or keyword queries, none of them can simultaneously support queries containing both spatial, temporal, and keyword criteria on dynamic data sets. Aiming at the issue, we design a layered index based on segment trees to dynamically organize messages containing both spatial, temporal, and keyword information. Moreover, based on a symmetric homomorphic encryption scheme, we encrypt the messages and queries and present a two-server privacy-preserving spatiotemporal keyword query scheme. We analyze the security of the proposed scheme and also conduct extensive experiments to evaluate its performance. The results show that our proposed scheme is indeed privacy preserving and computationally efficient. Yunguo Guan, Rongxing Lu, Yandong Zheng, Songnian Zhang, Jun Shao 0001, Guiyi Wei |
IEEE Internet Things J. | 1 |
| 2021 | Efficient and privacy-preserving range-max query in fog-based agricultural IoT
Yandong Zheng, Yunguo Guan, Rongxing Lu |
Peer-to-Peer Netw. Appl. | 3 |
| 2020 | Achieving Privacy-Preserving Vehicle Selection for Effective Content Dissemination in Smart CitiesabstractBy integrating various connected devices, it is possible for smart cities to optimize the efficiency of various aspects of city operations. In particular, connected vehicles in smart cities, which are coordinated by Intelligent Transportation Systems (ITS), can not only enjoy enhanced safety and efficiency, but also offer content dissemination services through smart cities. In order to achieve effective content dissemination, a vehicle selection approach usually needs to be involved to select a limited number of vehicles while disseminating content to a city as wide as possible. However, such an approach inevitably requires the trajectories of vehicles, which are private to the vehicles. In this paper, to preserve the trajectory privacy of the vehicles during the vehicle selection, we propose a privacy-preserving vehicle selection scheme for effective content dissemination. Specifically, in the proposed scheme, given encrypted trajectories of n vehicles, a cloud with two non-collusive servers can select k vehicles that jointly cover an approximately optimal area of the city. Detailed security analysis and performance evaluation show that our proposed scheme can not only preserve the privacy of vehicles' trajectories, but also achieve efficient vehicle selection with an approximately optimal coverage. Yunguo Guan, Rongxing Lu, Yandong Zheng, Jun Shao 0001, Guiyi Wei |
GLOBECOM | 1 |
| 2020 | Achieving Efficient and Privacy-Preserving Max Aggregation Query for Time-Series DataabstractThe vision of future intelligent information society will be globally data driven, enabled by Internet of Things (IoT) techniques. In any IoT-enabled applications, huge volumes of time-series data are continuously generated by IoT devices, which will be fed for high-level functions. Among these functions, the max aggregation query over a specific time interval is one of the frequently used operations. However, due to the limited resources in IoT devices, a common way to deal with the max aggregation query is to involve powerful cloud servers. Nevertheless, as the sensed data from IoT devices and its pattern (e.g., local ranking sequences) are usually private and the cloud servers are not fully trusted, the data should be encrypted before being outsourced to cloud servers. Obviously, the data encryption will incur some efficiency issues. In this paper, to mitigate the privacy and efficiency issues, we propose an efficient and privacy-preserving max aggregation query scheme for time-series data in IoT scenarios. Specifically, we first employ a segment tree based data structure to represent the data collected by IoT devices. Then, to protect the privacy, we leverage two encryption techniques to encrypt the data structure. With the encrypted data structure, our proposed scheme can handle a ranged max aggregation query with O(log L) time complexity, where L is the range length of the query. Detailed security analysis and performance evaluation show that our scheme can not only preserve the privacy of data and its local ranking sequences, but also achieve efficient ranged max aggregation query. Yunguo Guan, Rongxing Lu, Yandong Zheng, Jun Shao 0001, Guiyi Wei |
ICC | 1 |