VLDB 2026 Research / reviewers in the wild / expert
Guohua Tian
dblp:245/3781
· DBLP profile ↗
13ranked-venue papers
5as first author
12since 2021 · last 2026
0000-0002-9775-695XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 4 first-author · 6 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Computer networks · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Verifiable and Controllable Data Sharing With Compliance Checking in Cloud ComputingabstractData capsule provides a feasible solution for controllable data sharing, where data owners outsource their data capsules containing encrypted data and compliance-checking policies to the cloud server, and only valid users can run a compliant analysis program to process the decrypted data capsules in the Trusted Execution Environment (TEE), without obtaining the raw data. However, existing schemes cannot achieve verifiable accesses and updates, which means that malicious servers may use corrupted/old data capsules to deceive users and TEE. In this paper, we introduce the concept of Verifiable Data Capsule (VDC) for secure and controllable data sharing. Specifically, we first design a lightweight authentication tag, dubbed Locally Verifiable Chameleon Tag (LVCT), which allows the data owner to bind all data capsules to a constant-size tag and enables users to recover the local tags for validating data capsules. On this basis, we present a concrete VDC scheme that utilizes a dual-level authentication structure to realize verifiable data updates, and verifiable state updates triggered by regular access without the aid of the data owner. Furthermore, we propose an efficient trust evaluation protocol to judge the credibility of cloud servers. Finally, both security analysis and performance evaluation demonstrate the practicability of the proposed scheme. Guohua Tian, Meixia Miao, Jianghong Wei, Zheli Liu, Liang Guo 0013, Xiaofeng Chen 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Verifiable Data Streaming Protocol Supporting Keyword QueriesabstractThe rapid deployment of emerging networks, such as the Internet of Things and cloud computing, has generated massive amounts of data. Data streaming is significant among these various data types due to its widespread use in many critical applications, such as gene sequencing, network intrusion detection, and stock trading. On the other hand, the continuously increased size of data streaming makes it impractical to store and manage the data locally, especially for those resource-constrained devices. Outsourcing the data streaming to cloud servers provides an ideal solution to the above storage issue. However, this raises the problem of how to guarantee the integrity of the outsourced data, as cloud servers may maliciously modify the data. To this end, the primitive of verifiable data streaming (VDS) was introduced to preserve the integrity of the outsourced data streaming, enabling data users to ensure that queried data items, including the contents and corresponding positions, are correct. Despite many proposed VDS protocols, most can only use the position index to query outsourced data streaming. Consequently, they fail to fulfill the requirements of those practical applications that need keyword queries. For example, in the setting of network intrusion detection, the data analyst would like to query all access records from the same IP address. In this paper, we extend the original VDS protocol to support keyword queries, i.e., allowing data users to retrieve outsourced data items with particular keywords. Specifically, we use a prefix tree to maintain keywords and another chameleon authentication tree to store data items. The two trees are bound together with cryptographic query proofs, ensuring the consistency between the position index and keyword queries. The proposed VDS protocol, which supports keyword queries, is proven secure in the standard model and outperforms previous VDS protocols in terms of functionality. The experimental results indicate that our proposal is also efficient and practical. Meixia Miao, Peihong Qiang, Siqi Zhao, Jiawei Li 0011, Guohua Tian, Jianghong Wei |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2025 | Lightweight 0-RTT Session Resumption Protocol for Constrained DevicesabstractWith the growing popularity of various Internet of Things (IoT) applications, securing data transmission over these networks become critical. The authenticated key exchange (AKE) protocol is a fundamental cryptographic primitive that achieves this goal by creating a shared session key. However, since IoT end devices are usually resource-constrained, devising secure and efficient AKE protocols for IoT applications remains challenging. In this paper, we investigate the design of zero round-trip time (0-RTT) session resumption protocols based on pre-shared keys, which enables an end device to send encrypted data to a server without prior key exchange. Specifically, we first propose a new construction of puncturable pseudo-random function (PRF), and prove its security under the RSA assumption. Then, based on the proposed puncturable PRF and authenticated encryption with associated data, we put forward a new construction of 0-RTT session resumption protocol that simultaneously provides forward security and resistance against replay attacks. We further demonstrate how to combine the proposed 0-RTT session resumption protocol with other symmetric AKE protocols for IoT applications. Both theoretical comparisons and experimental results indicate that our proposal has significant advantages in terms of computation and storage costs for practical parameter settings. Thus, it is especially desirable for constrained devices. Jianghong Wei, Guohua Tian, Xiaofeng Chen 0001, Willy Susilo |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Pixel+ and Pixel++: Compact and Efficient Forward-Secure Multi-Signatures for PoS Blockchain Consensus
Jianghong Wei, Guohua Tian, Ding Wang 0002, Fuchun Guo, Willy Susilo, Xiaofeng Chen 0001 |
USENIX Security Symposium | 2 |
| 2024 | SQL queries over encrypted databases: a surveyabstractLimited by the local storage resource, data users have to encrypt their data and outsource the encrypted databases to cloud servers to enjoy low-cost, professional data management services, which promotes the rapid development of outsourcing database technology. Despite this, the complex underlying setting and loosely coupled database architecture lead to various security risks and performance bottlenecks, while there is currently no work to achieve a comprehensive evaluation of existing encrypted database solutions from the aspects of underlying settings, security levels, functions, etc. In this work, we first propose an evaluation model to assess SQL functionalities and security from multiple dimensions. Secondly, we categorise the existing SQL query schemes into three categories: software-based construction, hardware-based construction, and hybrid-based construction, that is, a combination of software and hardware components. On this basis, we analyse the framework, advantages, and limitations of classic and state-of-the-art schemes. Finally, we summarise the software-based and hardware-based approaches from dimensions of SQL functionality, security, and efficiency, thus clarifying their ideal application scenarios. Notably, SQL query schemes that exhibit minimal equality of pair leakage and support strong obliviousness can achieve higher levels of security. In addition, hardware-based solutions can achieve more complex SQL queries and superior performance without designing complex and functionally-limited cryptographic tools. Bo Sun 0016, Guohua Tian |
Connect. Sci. | 3 |
| 2024 | Blockchain-Based Compact Verifiable Data Streaming With Self-AuditingabstractThe primitive of verifiable data streaming (VDS) provides a secure data outsourcing solution for resource-constrained users, that is, they can stream their continuously-generated data items to untrusted servers while enabling publicly verifiable query and update. However, existing VDS schemes either require the server to store the authentication tags of all data items to support data query and auditing, or bind all data items into a constant-size tag to achieve optimal storage on the server side, but cannot achieve public auditing. To close this gap, in this paper, we first design a novel authentication data structure, dubbed retrievable homomorphic verifiable tags (RHVTs), which allows users to aggregate the authentication tags of all data items into a constant-size tag, and enables them to retrieve the original tags from the aggregated tag when necessary. Based on this, we propose a compact verifiable and auditable data streaming (CVADS) scheme, which adopts a single-level authentication mechanism to achieve more efficient data append and update, as well as optimal storage and public auditing. For better robustness and performance, we introduce a nested dual-level authentication mechanism and propose a blockchain-based CVADS (BCVADS) scheme to achieve a distributed CVADS with self-auditing. Finally, we prove the security of our schemes in the random oracle model and demonstrate their practicality through a visual performance evaluation. Guohua Tian, Jianghong Wei, Meixia Miao, Fuchun Guo, Willy Susilo, Xiaofeng Chen 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Optimal Verifiable Data Streaming Under Concurrent QueriesabstractThe rapid development of both hardware and software has promoted the popularization of various real-time applications like health monitoring and intrusion detection that are widely deployed in outsourcing scenarios, e.g., mobile edge computing and cloud computing. In these applications, end devices continuously generate unbounded sequences of data items at a fast rate, i.e., the so-called streaming data. Nevertheless, storing and processing massive amounts of streaming data poses a challenge for resources-restricted end devices. Although outsourcing data items to edge servers or cloud servers is an attractive solution to the above problem, it also brings a new challenge, i.e., how to guarantee the integrity of outsourced data, since streaming data applications are usually sensitive of both location and the corresponding context, and servers are not completely trusted. To this end, the primitive of verifiable data streaming (VDS) protocol was introduced to maintain outsourced streaming data, while preserving its integrity. However, existing VDS constructions mainly use the structure of Merkle hash tree, and inherently have logarithmic costs. Consequently, they are infeasible for real-time applications that are delay sensitive and generate unpredictable size of streaming data. In this paper, we optimize previous VDS protocols from the aspects of communication overhead and computation cost. Specifically, we adopt a technical route different from Merkle hash tree, i.e, combining the digital signature with the cryptographic accumulator. In our construction, we employ Boneh-Lynn-Shacham (BLS) signature to guarantee the integrity of the context and position of each outsourced data item, and adopt an RSA accumulator to invalidate the old signature after the corresponding data item was updated. This immediately yields an optimal VDS construction that has constant costs even under concurrent queries, which is more desirable for those resource-limited mobile devices. In addition, the aggregability of BLS signature makes our VDS construction capable of data auditing, which enables the user to remotely verify the integrity of outsourced streaming data. We provide a formal security proof of the proposed VDS construction under well-studied complexity assumptions in the random oracle model. As a proof-of-concept, we also implement our proposal, and conduct extensive experiments to demonstrate its practicability. Jianghong Wei, Meixia Miao, Guohua Tian, Jun Shen 0006, Xiaofeng Chen 0001, Willy Susilo |
IEEE Trans. Mob. Comput. | 3 |
| 2023 | VRBC: A Verifiable Redactable Blockchain With Efficient Query and Integrity AuditingabstractDriven by various legal obligations and service requirements, the redactable blockchain was introduced to balance the modifiability and immutability of blockchain technology. However, such a blockchain inevitably generates one or even more acceptable versions for the same block data, enabling malicious full nodes to deceive light/new nodes with old data, and even disrupt the consistency of the blockchain ledger. In this paper, we introduce the concept of verifiable redactable blockchain (VRBC) to provide efficient validity verification for on-chain data. To this end, we design a novel authentication data structure, called blockchain authentication tree (BAT), which employs a chameleon hash function and aggregatable vector commitment to bind continuously-appended blocks. Based on this, we propose an efficient VRBC scheme supporting integrity auditing, which not only allows the light nodes to query and validate on-chain data, but also enables new nodes to check the integrity of the blockchain ledger before synchronizing it, effectively avoiding resource waste and security risks caused by invalid queries and ledger synchronization. Furthermore, we introduce some optimized strategies to improve the performance of our scheme and extend it to transaction-level and permissionless VRBC. Finally, we demonstrate the practicability of our scheme through detailed security analysis and visual performance evaluation. Guohua Tian, Jianghong Wei, Miroslaw Kutylowski, Willy Susilo, Xinyi Huang 0001, Xiaofeng Chen 0001 |
IEEE Trans. Computers | 1 |
| 2022 | Blockchain-based cross-user data shared auditingabstractIn cloud storage, public auditing is a more popular data integrity verification technique since it allows users to delegate auditing tasks to a fully trusted third-party auditor (TPA). However, it is difficult to find such a TPA in practical application. Besides, the centralised auditing model makes TPA have to bear burdensome work pressure, which limits the practicability of existing schemes. In this paper, we firstly proposed a blockchain-based generalised shared auditing mechanism BCSA in the cross-user scenario, which aims at achieving available public auditing with a non-fully trusted TPA, and reducing the user's auditing fees and TPA's work pressure by allowing data users to share their auditing procedure with others. Furthermore, we initialise a concrete construction BCSAD with Diffie–Hellman protocol for the cross-user auditing scenario with different data. Likewise, we also propose a novel construction BCSAI for the cross-user auditing scenario with identical data, which utilises a password-authenticated key exchange (PAKE) protocol to achieve shared auditing and ciphertext deduplication, reducing data storage and auditing fees for data users and alleviating service pressure on the cloud server and TPA. Security and performance analysis evaluate the practicability of the proposed scheme. Angtai Li, Guohua Tian, Meixia Miao, Jianpeng Gong |
Connect. Sci. | 2 |
| 2022 | Blockchain-Based Secure Deduplication and Shared Auditing in Decentralized StorageabstractData deduplication and public auditing are significant for providing secure and efficient network storage services. However, the existing data deduplication schemes supporting auditing not only cannot effectively alleviate the threats of the single point of failure and duplicate-faking attack, but also have to bear the massive waste of computation and storage resources caused by metadata redundancy and repetitive audit tasks. In this article, we propose a blockchain-based secure deduplication and shared auditing scheme in decentralized storage. Specifically, our scheme utilizes a novel deduplication protocol based on the double-server storage model to achieve efficient space-saving while protecting data users from losing data under a single point of failure and duplicate-faking attack. Besides, it sharply reduces the computation and storage costs of metadata by introducing a lightweight authenticator generation algorithm and update protocol. On this basis, our scheme further adopts a blockchain-based two-way shared auditing mechanism to achieve decentralized public auditing without the third-party auditor, in which the audit authenticators and results of outsourced data are shared among its users to avoid repetitive audit tasks. Security and performance analysis indicates the practicability of our scheme. Guohua Tian, Yunhan Hu, Jianghong Wei, Zheli Liu, Xinyi Huang 0001, Xiaofeng Chen 0001, Willy Susilo |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | Optimal Verifiable Data Streaming Protocol with Data Auditing
Jianghong Wei, Guohua Tian, Jun Shen 0006, Xiaofeng Chen 0001, Willy Susilo |
ESORICS (2) | 2 |
| 2021 | New proofs of ownership for efficient data deduplication in the adversarial conspiracy modelabstractThe primitive of proofs of ownership (PoWs) enables a prover to efficiently convince a verifier that he/she indeed owns a certain message in a knowledge-proof manner. As a result, it can prevent an adversary who only has a short information of the message from accessing the whole one. We argue that the existing PoWs based on Merkle hash tree and specific encodings are not much efficient if the size of message is sufficiently huge. In this paper, we first propose a new PoW protocol based on the chameleon hash function without key exposure. Interestingly, it is equivalent to having the prover compute a new collision of chameleon hashing as the proof in our construction. Therefore, the proposed protocol is much efficient since the computation and storage overhead of proof is independent of the size of the message. Moreover, we utilize the proposed PoWs to design a deduplication scheme over ciphertext. Meixia Miao, Guohua Tian, Willy Susilo |
Int. J. Intell. Syst. | 2 |
| 2020 | Randomized deduplication with ownership management and data sharing in cloud storage
Guohua Tian, Ying Xie 0010, Zhenhua Liu 0001 |
J. Inf. Secur. Appl. | 1 |