Kan Yang 0001

dblp:26/6407 · DBLP profile ↗
← Back
70ranked-venue papers
16as first author
34since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 38 · 6 first-author · 18 since 2021Security and privacy · 16 · 3 first-author · 9 since 2021Systems, architecture and hardware · 7 · 4 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
YearPublicationVenuePosition
2026 How to Unleash the Value of Cloud Data? Secure and Efficient Data Delivery for Subscription-Based Entrusted Trading
abstract
Exchange-assisted cloud-based data trading (ECDT) is a promising paradigm in current marketplaces, where an exchange provides underlying trading services while the cloud serves as a fundamental base for data sellers, brokers, and data buyers to enable them to benefit from data trading. However, directly integrating existing commercial cloud services into an exchange system suffers from practicality issues. In existing ECDT systems, the data outsourced to the cloud generally follows an “encrypt-then-outsource” paradigm, and the encrypted database makes it impractical for brokers to generate and deliver on-demand data products to the buyer, thereby hindering subscription-based data trading. In this paper, we propose a secure and efficient data delivery scheme, dubbed ESECDT, for subscription-based ECDT. ESECDT consists of data entrustment and data delivery and supports continuous data entrustment and customized data delivery while freeing the broker from heavy costs in terms of computation and communication. We formally define and prove the security of ESECDT in the random oracle model. We also implement an ESECDT prototype and conduct a comprehensive performance evaluation, which demonstrates the efficiency and practicality of ESECDT.
Yuan Zhang 0006, Yaqing Song, Ningyuan Ma, Nan Cheng 0001, Kan Yang 0001, Hongwei Li 0001
IEEE Trans. Computers6
2025 Identifying the Truth of Global Model: A Generic Solution to Defend Against Byzantine and Backdoor Attacks in Federated Learning
Sheldon C. Ebron Jr., Meiying Zhang, Kan Yang 0001
ACISP (3)3
2025 PKChain: Compromise-Tolerant and Verifiable Public Key Management System
abstract
Public key management systems enable users to create, validate, and revoke public keys, serving as the foundation of public key cryptography. Traditional public key infrastructure (PKI) systems rely on centralized certificate authorities (CAs) to validate users and manage public keys, but this centralization creates a single point of failure. If a CA is compromised, it can register fake public keys or alter legitimate ones, leading to counterfeit certificates. While blockchain-based approaches decentralize CA authority across multiple entities, these solutions are largely reactive, focusing on certificate issuance and relying on user signatures for validation. They lack a robust mechanism to authenticate and authorize requests before certificate issuance, a crucial step typically managed by registration authorities (RAs) in CA-based PKI systems. To address this gap, we introduce PKChain, a novel compromise-tolerant and verifiable public key management system built on blockchain. PKChain addresses two key challenges: 1) it uses a threshold block validation (TBV) scheme for key request validation, where validators partially validate requests and 2) collaborate for full validation. Once a request gains majority approval, it advances to the aggregated commitment signature (ACS) scheme, where validators collectively issue certificates. By requiring majority approval in the TBV stage before moving to certificate issuance, PKChain ensures proactive security throughout the process. To achieve consensus on validation and issuance, we propose a threshold cryptography-based consensus mechanism called the practical Byzantine compromise-tolerant and verifiable (pBCTV) consensus model, integrating the TBV and ACS schemes with the practical Byzantine fault-tolerance (pBFT) protocol. Security analysis, performance evaluation, and prototype implementation validate PKChain’s security, efficiency, and resilience.
Jamal Mosakheil, Kan Yang 0001
IEEE Internet Things J.2
2025 Building Efficient and Flexible Voting Protocols: An Approach to Fairness and Anonymity
abstract
Voting protocols are fundamental in modern society. With the ongoing evolution of communication technology and the Internet of Things, the importance of electronic voting protocols is anticipated to experience a significant rise in the advancement of smart cities. Leveraging the blockchain’s tamper-resistant and publicly verifiable properties, along with the concept of enabling all participants to tally election results, blockchain-based self-tallying voting protocols effectively address the shortcomings of centralized traditional electronic voting. However, existing voting protocols still face the dual challenge of security and efficiency. The primary issues include the difficulty in ensuring voter anonymity and election fairness, as well as the insufficient system robustness and low tallying efficiency resulting from security design. To tackle these concerns, we propose a novel approach to constructing efficient and flexible voting protocols that concurrently ensure fairness and anonymity. Specifically, we encapsulate the decryption private keys corresponding to the public keys of encrypted ballots in time capsules to safeguard voting fairness. Additionally, based on our proposed approach, we construct an efficient and flexible score voting protocol for smart cities. The protocol employs traceable ring signature to protect the voter anonymity and public traceability, utilizes a dual-key additive homomorphic ElGamal encryption to encapsulate ballots. We also improve signature-based set membership proofs to verify the validity of ballots. Furthermore, through security analysis and performance evaluation, we demonstrate that our proposed protocol meets all security objectives with reasonable costs.
Yijie Shi, Kai Fan 0001, Yuhan Bai, Chonglin Zhang, Kan Yang 0001, Hui Li 0006, Yintang Yang
IEEE Internet Things J.5
2025 EpiOracle: Privacy-Preserving Cross-Facility Early Warning for Unknown Epidemics
abstract
Syndrome-based early epidemic warning plays a vital role in preventing and controlling unknown epidemic outbreaks. It monitors the frequency of each syndrome, issues a warning if some frequency is aberrant, identifies potential epidemic outbreaks, and alerts governments as early as possible. Existing systems adopt a cloud-assisted paradigm to achieve cross-facility statistics on the syndrome frequencies. However, in these systems, all symptom data would be directly leaked to the cloud, which causes critical security and privacy issues. In this paper, we first analyze syndrome-based early epidemic warning systems and formalize two security notions, i.e., symptom confidentiality and frequency confidentiality, according to the inherent security requirements. We propose extsf{EpiOracle}, a cross-facility early warning scheme for unknown epidemics. EpiOracle ensures that the contents and frequencies of syndromes will not be leaked to any unrelated parties; moreover, our construction uses only a symmetric-key encryption algorithm and cryptographic hash functions (e.g., [CBC]AES and SHA-3), making it highly efficient. We formally prove the security of EpiOracle in the random oracle model. We also implement an EpiOracle prototype and evaluate its performance using a set of real-world symptom lists. The evaluation results demonstrate its practical efficiency.
Shiyu Li 0002, Yuan Zhang 0006, Yaqing Song, Fan Wu 0014, Feng Lyu 0001, Kan Yang 0001, Qiang Tang 0005
Proc. Priv. Enhancing Technol.6
2025 Dynamic Multi-User Authorization in Ciphertext Retrieval With Proxy Re-Encryption
abstract
Ciphertext retrieval technology has been widely explored with the increasing popularity of cloud computing. Proxy re-encryption with Keyword search (PREKS) can support multi-user retrieval without increasing data owner's overhead, but users can continue searching once they have obtained search rights. It is difficult for a data owner to revoke a user's access rights because the data is stored in the cloud. In general, under the premise of forward and backward security, the user's search permission can be revoked by updating the ciphertext. Nevertheless, this approach may expose user or data privacy to cloud servers. In this paper, we utilize the Chinese Remainder Theorem to generate DO-Authorization and DU-Authentication factors, and realizes the authorization and revocation of a specific single user by adding or deleting authorization items. In addition, we use a designated tester algorithm in the ciphertext retrieval process to improve system security. Subsequent security analysis proves that the proposed scheme can resist the Chosen Keyword Attack and Keyword Guessing Attack. Simulation results indicate that the proposed scheme has high efficiency, especially in the user revocation phase
Nan Gao 0003, Kai Fan 0001, Haoyang Wang 0005, Yintang Yang, Kan Yang 0001, Hui Li 0006
IEEE Trans. Dependable Secur. Comput.5
2025 Deniable Time Signature Forward Secure Searchable Encryption With Flexible Retrieval and Traceable Authorization in Sharable EHR
abstract
Electronic Health Record (EHR) sharing can improve the accuracy of medical diagnosis and promote the development of the public medical field. However, plaintext medical records expose patient privacy, and it is challenging to share medical records between different hospitals, making it difficult for doctors to securely retrieve medical records and massively analyze the same diseases from different patients. In this paper, we propose a flexible ciphertext retrieval scheme in electronic health sharing system that supports multi-patient and multi-keyword medical records retrieval. The proxy free ciphertext retrieval technology based on cloud servers enables doctors to retrieve multiple patients' medical records simultaneously. On this basis, we utilize the time encoding algorithm to ensure that the trapdoor associated with the old time cannot retrieve the ciphertext index bound with the latest time, so as to realize the lightweight forward security. Besides, the encoding time signed by the deniable signature can avoid forgery by malicious users or adversaries. In addition, the scheme supports evil user traceable and revocable. The security analysis indicates that the scheme can satisfy the keyword privacy, the forward security of updated ciphertexts, and the deniability of time encoding signatures. Experimental evaluation illustrates that our scheme is lightweight and efficient
Nan Gao 0003, Kai Fan 0001, Kan Yang 0001, Hui Li 0006, Yintang Yang
IEEE Trans. Dependable Secur. Comput.3
2024 SilentProof: Anonymous Authentication with Blockchain-Backed Offloading
Jamal Mosakheil, Kan Yang 0001
AsiaCCS2
2024 A Game Theory Reward Model for Federated Learning with Probabilistic Verification
abstract
In Federated Learning, a Central Node (CN) coordinates a group of agents to collectively train a shared neural network.However, due to the inherent information asymmetry, some agents may behave as free riders and exploit the system by reaping rewards or by passively benefiting from the common model without contributing to the training process.Proof-of-Training (PoT) effectively allows the CN to verify that an agent has completed training honestly and correctly.However, this method incurs high costs, including proof generation by the agent, communication expenses, and proof verification by the CN.Conducting Proof-of-Training in each FL round is impractical due to these expenses.To enhance verification efficiency, a feasible strategy is to conduct probabilistic verification, where only a subset of agents is sampled for verification in each FL round.This paper aims to design a new incentive mechanism to motivate the agents behave honestly and potentially mitigate free riders.Our model hinges on two parameters: (i) the reward allocated to the local trainers, namely 𝑅, and (ii) a probability vector, denoted as ì 𝑝, indicating the likelihood of subjecting each agent to PoT scrutiny.We show that it is possible to characterize a set of parameters 𝑅 and ì 𝑝 that minimizes the total CN cost and makes the routine Individually Rational and Incentive Compatible, so that every agent will actively train their local model.Finally, we validate our model through extensive experiments.Our findings show that our characterization of the best reward and validation scheme is correct as they minimize the cost of the training routine without compromising the convergence speed.All our experiments are conducted on various datasets, demonstrating the wide applicability of our results.
Gennaro Auricchio, Harry J. Clough, Christopher Ho, Kaigui Bian, Changyu Dong, Kan Yang 0001, Jie Zhang 0008
DAI6
2024 Towards Fair, Robust and Efficient Client Contribution Evaluation in Federated Learning
abstract
Federated Learning (FL) is widely applied in communication networks. The performance of clients in FL can vary due to various reasons. Assessing the contributions of each client is crucial for client selection and compensation. It is challenging because clients often have non-independent and identically distributed (non-iid) data, leading to potentially noisy or divergent updates. The risk of malicious clients amplifies the challenge especially when there’s no access to clients’ local data or a benchmark root dataset. In this paper, we introduce a novel method called Fair, Robust, and Efficient Client Assessment (FRECA) for quantifying client contributions in FL. FRECA employs a framework called FedTruth to estimate the global model’s ground truth update, balancing contributions from all clients while filtering out impacts from malicious ones. This approach is robust against Byzantine attacks and incorporates a Byzantine-resilient aggregation algorithm. FRECA is also efficient, as it operates solely on local model updates and requires no validation operations or datasets. Our experimental results show that FRECA can accurately and efficiently quantify client contributions in a robust manner.
Meiying Zhang, Sheldon C. Ebron Jr., Kan Yang 0001
GLOBECOM4
2024 STAGE: Secure and Efficient Data Delivery for Exchange-Assisted Data Marketplaces
abstract
Cloud-based exchange-assisted data trading (EADT) has become the most important paradigm to trade data, where the exchange builds a bridge between data owners, brokers, and buyers to enable them to gain benefits from data, and cloud storage services serve as a key component to deliver data. With cloud-based EADT, the data can be traded in a customized way and the value of data can be unleashed as much as possible. Despite the great advantages of such a paradigm, critical issues also arise. The data content is confronted with leakage, leading to privacy violation. Conventional encryption can be utilized to resolve this tension, but it makes customized data trading inefficient and even impossible. In this paper, we propose a secure data delivery scheme, dubbed STAGE, for cloud-based EADT. STAGE supports customized data trading while freeing the broker from heavy costs in terms of computation and communication. We formally define the security notions of STAGE and prove that STAGE is secure against various attacks. We also implement a STAGE prototype and conduct a comprehensive performance evaluation to demonstrate its efficiency and practicality.
Yuan Zhang 0006, Yaqing Song, Nan Cheng 0001, Kan Yang 0001
ICC5
2024 PPoD: Practical Proofs of Dealership for Authorized Data Trading
abstract
Three-layer data trading, where a data broker collects “data materials” from multiple data owners, and then provides customized data products to buyers, remains the most prevalent paradigm in current data marketplaces. However, a profit-driven broker may generate “low-quality” data products based on scratched data but sell them at a high price. Worse still, a malicious broker would pirate others' data products to disrupt data marketplaces. In this paper, we propose a practical proof of dealership scheme, dubbed PPoD, to resist malicious brokers. The key technique behind PPoD is a redactable certification generation mechanism, which enables a broker to prove its dealership of a customized data product in an efficient way. We provide a formal security proof of PPoD, which demonstrates that various attacks, e.g., piracy and deception, launched by a malicious broker can be thwarted. We also implement a PPoD prototype and conduct a comprehensive performance evaluation to show its efficiency and practicality.
Yuan Zhang 0006, Yaqing Song, Nan Cheng 0001, Kan Yang 0001
ICC5
2024 Ensuring Fairness in Federated Learning Services: Innovative Approaches to Client Selection, Scheduling, and Rewards
abstract
Federated Learning (FL) Services enable customers (requesters) to outsource their FL tasks to the FL service provider, who will recruit a group of clients with appropriate datasets to complete the FL task. For a given FL task, how to select appropriate clients fairly becomes a challenging problem due to budget restrictions and client heterogeneity. In this paper, we propose a new client selection, scheduling, and rewarding scheme to ensure fairness through a three-stage process: 1) multicriteria initial client pool selection, 2) data quality-oriented perround client scheduling, and 3) performance-based rewarding. Specifically, we first define a client selection metric with multiple criteria, such as client resources, data quality, and client behaviors. Then, we formulate the initial client pool selection problem into an optimization problem that aims to maximize the overall scores of selected clients within a given budget and propose a greedy algorithm to solve it. Furthermore, we formulate the per-round client selection problem into a data quality-oriented scheduling problem that aims to improve model quality and guarantee fairness. We propose a heuristic algorithm to divide the pool into several subsets such that the federated dataset in a subset is close to an independent and identical distribution (iid) while guaranteeing each client is selected at least once in a scheduling period. In addition, we propose a performance-based payment adjustment protocol with a bonus and punishment mechanism, such that the final payment reflects the actual performance of each selected client. Our fairness analysis and experimental results show that our scheme not only can guarantee fairness but also can improve the model quality especially when data are non-iid.
Meiying Zhang, Sheldon C. Ebron Jr., Ruitao Xie, Kan Yang 0001
ICDCS5
2024 Seamless group handover authentication protocol for vehicle networks: Services continuity
Ye Bi, Kai Fan 0001, Zhilin Zeng, Kan Yang 0001, Hui Li 0006, Yintang Yang
Comput. Networks4
2024 EIV-BT-ABE: Efficient Attribute-Based Encryption With Black-Box Traceability Based on Encrypted Identity Vector
abstract
The fine grain of ciphertext-policy attribute-based encryption (CP-ABE) offers advantages through the amalgamation of key and user attributes; however, it also brings the issue of key misuse. To circumvent the tracking mechanisms of the white-box algorithm, malicious users manipulate the decryption key and encryption algorithm, encapsulating them to create a black-box decryption device. This necessitates black-box traceability for supervision purposes. In this article, we employ$n$-bit encrypted binary vectors to depict the user’s identity and subsequently convert it into partial decryption privileges. When encrypting plaintext, data owners can utilize a “vague specification” to define the identity vector of qualified decryptors. Furthermore, based on the vague specification mechanism, we have devised a pioneering active black-box tracing algorithm. Integrating this algorithm with CP-ABE, we propose the black-box traceable CP-ABE (EIV-BT-ABE) scheme. Our EIV-BT-ABE scheme attains strong traceability with low time complexity, effectively reducing decryption and encryption time costs. The experiment substantiated the efficiency of our scheme while demonstrating its adherence to IND-CPA security.
Kai Fan 0001, Yuhan Bai, Yintang Yang, Kan Yang 0001, Hui Li 0006
IEEE Internet Things J.5
2024 PBFL: Privacy-Preserving and Byzantine-Robust Federated-Learning-Empowered Industry 4.0
abstract
In Industry 4.0, artificial intelligence (AI) has been successfully applied in scenarios, such as fault prediction, traffic analysis, and production decision making. However, due to the sensitivity and security of data, privacy regulations prohibit the transfer and exchange of industrial data between entities, resulting in training data being fragmented into data silos that limit the accuracy of AI models. FL can effectively break the data silo effect, but naive federated learning (FL) (FedAvg) is vulnerable to inference attacks from aggregators and Byzantine attacks from participants. To address these issues, we propose a privacy-preserving and Byzantine-robust federated learning scheme (PBFL) for Industry 4.0. Under the setting of an benign-majority participants, PBFL can always identify benign direction and magnitude of updates. Extensive experiments demonstrate that PBFL is more robust than state-of-the-art schemes, even with extreme proportion (49%) of malicious participants. Moreover, PBFL contains a series of well-optimized 2-party computation (2PC) protocols, causing it reduces total runtime of the unoptimized implementation by around$3 \times \sim 4 \times $and$9 \times \sim 10 \times $for 32-bit and 64-bit circuits, respectively.
Wenjie Li 0008, Kai Fan 0001, Kan Yang 0001, Yintang Yang, Hui Li 0006
IEEE Internet Things J.3
2024 Guest Editorial Special Issue on Recent Advances of Security, Privacy, and Trust in Mobile Crowdsourcing
abstract
With the rapid advances in mobile and communication technologies, mobile devices are equipped with powerful processors, various sensors, large memories, and fast wireless communication modules. By taking advantage of powerful mobile devices and human intelligence, mobile crowdsourcing is an emerging paradigm that enables users to outsource tasks (usually difficult to accomplish individually) to a group of people (workers) at an affordable price. Specifically, human mobility offers unprecedented opportunities to sense the surroundings wherever their holders arrive, and human capabilities also offer intelligent human-assisted computation with their devices, e.g., human perception, intelligence, cognition, knowledge, visual recognition, and experiences.
Kan Yang 0001, Rongxing Lu, Mohamed Mahmoud 0001, Xiaohua Jia
IEEE Internet Things J.1
2024 Lower rounds lattice-based anonymous AKA under the seCK model for the IoT
Guanglu Wei, Kai Fan 0001, Kuan Zhang 0001, Haoyang Wang 0005, Kan Yang 0001, Hui Li 0006, Yintang Yang
Peer Peer Netw. Appl.6
2024 Blockchain-Based Portable Authenticated Data Transmission for Mobile Edge Computing: A Universally Composable Secure Solution
abstract
In mobile edge computing (MEC) systems, data is frequently transmitted between MEC servers and users holding mobile devices for supporting related services. However, critical threats towards data confidentiality and authenticity are raised: adversaries always attempt to extract data content from the transmission and impersonate others to spread malicious data for profits. Furthermore, users have to store the (secret and public) keys used for data transmission locally. Consequently, only devices maintaining the keys can be utilized to access the services provided by MEC servers, and “portability” cannot be achieved. In this paper, we propose a portable authenticated data transmission scheme (dubbed Biplane) via blockchain for MEC systems. Biplane is based on two techniques. One is a blockchain-based authenticated hybrid encryption mechanism, which guarantees data authenticity and confidentiality without requiring a third party (e.g., a Certificate Authority) to assist the MEC servers in certifying users’ public keys. The other one is a blockchain-based portable key management mechanism, which enables the user to transmit data without maintaining any parameter in her/his local devices. We formally prove that Biplane achieves confidential and authenticated data transmission in the universally composable (UC) framework. We also conduct a comprehensive evaluation to demonstrate that Biplane is efficient.
Shiyu Li 0002, Yuan Zhang 0006, Yaqing Song, Nan Cheng 0001, Kan Yang 0001, Hongwei Li 0001
IEEE Trans. Computers5
2024 Beyond Security: Achieving Fairness in Mailmen-Assisted Timed Data Delivery
abstract
Timed data delivery is a critical service for time-sensitive applications that allows a sender to deliver data to a recipient, but only be accessible at a specific future time. This service is typically accomplished by employing a set of mailmen to complete the delivery mission. While this approach is commonly used, it is vulnerable to attacks from realistic adversaries, such as a greedy sender (who accesses the delivery service without paying the service charge) and malicious mailmen (who release the data prematurely without being detected). Although some research works have been done to address these adversaries, most of them fail to achieve fairness. In this paper, we formally define the fairness requirement for mailmen-assisted timed data delivery and propose a practical scheme, dubbed DataUber, to achieve fairness. DataUber ensures that honest mailmen receive the service charge, lazy mailmen do not receive the service charge, and malicious mailmen are punished. Specifically, DataUber consists of two key techniques: 1) a new cryptographic primitive, i.e., Oblivious and Verifiable Threshold Secret Sharing (OVTSS), enabling a dealer to distribute a secret among multiple participants in a threshold and verifiable way without knowing any one of the shares; and 2) a smart-contract-based complaint mechanism, allowing anyone to become a reporter to complain about a mailman’s misbehavior to a smart contract and receive a reward. Furthermore, we formally prove the security of DataUber and demonstrate its practicality through a prototype implementation.
Shiyu Li 0002, Yuan Zhang 0006, Yaqing Song, Hongbo Liu 0002, Nan Cheng 0001, Dahai Tao, Hongwei Li 0001, Kan Yang 0001
IEEE Trans. Inf. Forensics Secur.8
2023 A Novel Blockchain-Assisted Aggregation Scheme for Federated Learning in IoT Networks
abstract
With the wide range of Internet of Things (IoT) applications, federated learning (FL) is commonly adopted to protect the privacy of IoT data. FL enables privacy-preserving model training while keeping the data locally available. To alleviate the additional load caused by FL, an improved hierarchical aggregation framework is presented in this article to decentralize the model aggregation tasks based on end-device clusters. However, when applying FL to IoT networks, how to keep high efficiency and reliability remains open challenges due to a large number and vulnerability of IoT end devices. In this article, we propose a blockchain-assisted aggregation scheme for FL in IoT networks, where the aggregation node selection is applied for efficiency improvement as well as blockchain for performance verification. During model aggregation, a selection strategy is obtained by the deep deterministic policy gradient (DDPG) algorithm and aims to select the optimal subset of IoT end devices based on multiple metrics. Furthermore, a new performance verification based on the characteristics of blockchain is applied to achieve mutual verification among a number of untrustworthy nodes with the optimal stopping theory, which provides reliable model performance proofs. Simulation results show that the proposed scheme can maintain FL efficiency and reduce the system latency while protecting data privacy.
Zhiming Liu 0014, Kan Zheng, Lu Hou 0001, Haojun Yang, Kan Yang 0001
IEEE Internet Things J.5
2023 Clustered Federated Multitask Learning on Non-IID Data With Enhanced Privacy
abstract
Federated learning is a machine learning prgadigm that enables the collaborative learning among clients while keeping the privacy of clients’ data. Federated multitask learning (FMTL) deals with the statistic challenge of non-independent and identically distributed (IID) data by training a personalized model for each client, and yet requires all the clients to be always online in each training round. To eliminate the limitation of full-participation, we explore multitask learning associated with model clustering, and first propose a clustered FMTL to achieve the multual-task learning on non-IID data, while simultaneously improving the communication efficiency and the model accuracy. To enhance its privacy, we adopt a general dual-server architecture and further propose a secure clustered FMTL by designing a series of secure two-party computation protocols. The convergence analysis and security analysis is conducted to prove the correctness and security of our methods. Numeric evaluation on public data sets validates that our methods are superior to state-of-the-art methods in dealing with non-IID data while protecting the privacy.
Jiangang Shu, Tingting Yang 0001, Xinying Liao, Farong Chen, Kan Yang 0001, Xiaohua Jia
IEEE Internet Things J.6
2023 Blockchain-based cloud-edge clock calibration in IoT
Kai Fan 0001, Zeyu Shi, Yicen Yang, Liyang Bai, Yintang Yang, Kan Yang 0001, Hui Li 0006
Peer Peer Netw. Appl.6
2023 Efficient and Provably Secure Data Selective Sharing and Acquisition in Cloud-Based Systems
abstract
Towards the large amount of data generated everyday, data selective sharing and acquisition is one of the most significant data services in cloud-based systems, which enables data owners to selectively share their data to some particular users, and users to selectively acquire some interested data. However, it is challenging to protect data security and user privacy during data selective sharing and selective acquisition, because cloud servers are curious about the data or user’s interests, and even send data to some unauthorized users or some uninterested users. In this paper, we propose an efficient and provably secure Data selective Sharing and Acquisition (${\sf DSA}$) scheme for cloud-based systems. Specifically, we first formulate a generic data selective sharing and acquisition problem in cloud-based systems by identifying several design goals in terms of correctness, soundness, security and efficiency. Then, we propose the${\sf DSA}$scheme to enable data owners to control the access of their data in a fine-grained manner, and enable users to refine the data acquisition without revealing their interests. Technically, a brand new cryptographic framework is developed to integrate attribute-based encryption with searchable encryption. Finally, we prove that the proposed${\sf DSA}$scheme is correct, sound, secure in the random oracle model, and efficient in practice.
Kan Yang 0001, Jiangang Shu, Ruitao Xie
IEEE Trans. Inf. Forensics Secur.1
2022 A new RFID ultra-lightweight authentication protocol for medical privacy protection in smart living
Xingmiao Wang, Kai Fan 0001, Kan Yang 0001, Xiaochun Cheng, Qingkuan Dong, Hui Li 0006, Yintang Yang
Comput. Commun.3
2022 Reputation-Based Truth Discovery With Long-Term Quality of Source in Internet of Things
abstract
Although the Internet of Things (IoT) devices have been widely used for data collection in various applications, the observed data of an object from each IoT device (i.e., source) may vary from the ground truth due to the different qualities of IoT devices and sensing environments. Truth discovery has become a promising technology to extract the truth among multiple conflicting pieces of data from different sources. Existing methods usually assume the quality of source (source reliability) is unknowna prioriand will be estimated as the weight for calculating the truth during each truth discovery task. However, in a long-term data observation scenario, the quality of source can be accumulated and utilized in the future truth discovery process. Aiming to take the long-term quality of source into consideration, in this article, we propose a reputation-based truth discovery method to derive the truth from the conflicting data. Specifically, we propose a generalized formulation with linear constraint for the truth discovery problem, which can cope with different regulations on the source reliability. Instead of directly using weight as the source reliability, we also define the reliability of a source by its contribution to the loss function. Then, we propose a novel reputation model to quantify the newly defined source reliability, which will be accumulated as the long-term source quality. Finally, we propose a reputation-based truth discovery model, where initial weights are assigned based on source reputations. Experiments conducted on real-weather conditions and GPS data sets demonstrate that our reputation-based truth discovery can reduce the number of iterations during truth discovery and achieve high accuracy.
Kan Yang 0001, Shouyi Yang
IEEE Internet Things J.2
2022 Delegating Authentication to Edge: A Decentralized Authentication Architecture for Vehicular Networks
abstract
Secure and efficient access authentication is one of the most important security requirements for vehicular networks, but it is difficult to fulfill due to potential security attacks and long authentication delay caused by high vehicle mobility, etc. Most of the existing authentication protocols, either do not consider attacks like single point of failure or do not focus on reducing authentication delay. To address these issues, we introduce an edge-assisted decentralized authentication (EADA) architecture, which provides secure and more communication-efficient authentication by enabling an authentication server to delegate its authentication capability to distributed edge nodes (ENs) such as roadside units (RSUs) and base stations (BSs). Under the architecture, we propose a threshold mutual authentication protocol that supports fast handover, which involves two scenarios, Auth-I and Auth-II. Auth-I only happens once when a vehicle tries to access the network for the first time, while Auth-II happens when a vehicle seamlessly roams between two ENs, i.e., handover. Specifically, for Auth-I, each vehicle can be cooperatively authenticated by$t$out of$n$ENs with identity-based signature techniques to obtain an authentication token and the involved ENs can be efficiently authenticated in a batch by the vehicle. For Auth-II, the vehicle can utilize the token as its private credential to achieve fast handover based on identity-based signature without interacting with multiple ENs, which further reduces the authentication delay significantly. In addition, we design a flexible method to support dynamic joining and leaving of ENs without the assistance of a trusted center. We demonstrate that the proposed protocol is secure and efficient through security analysis and performance evaluation.
Anjia Yang, Jian Weng 0001, Kan Yang 0001, Cheng Huang 0001, Xuemin Shen
IEEE Trans. Intell. Transp. Syst.3
2021 A Trust-aware Fog Offloading Game with Long-term Trustworthiness of Users
abstract
The novel fog computing can save substantial resources for resource-constrained mobile users with computation offloading. However, in the existing on-demand schemes, the fog node cannot satisfy the users' demands during peak time due to its limited resources. Therefore, an efficientallocation scheme is desirable, in which the users' priority is evaluated and sorted based on their features, e.g., trustworthiness. In terms of the trust, allocating resources and motivating users to behave cooperatively are important for network efficiency and fairness. In this paper, a long-term trust-based offloading scheme (LTOS) is proposed with a resource allocation scheme and a non-cooperative game. Firstly, a long-term trust evaluation scheme is designed considering the users' behaviors in the task assignment process. In the offloading process, the computation and transmission resources are allocated to users based on their trust values. In addition, a non-cooperative offloading game is formulated to maximize users' utilities, which considers the joint optimization of energy cost and delay. The simulation results demonstrate that our proposed long-term trust-based offloading scheme is more efficient than existing on-demand methods in terms of energy cost and delay. Moreover, the task acceptance and trust level of users can be improved with the proposed LTOS.
Kan Yang 0001, Shouyi Yang, Zhuo Han
GLOBECOM2
2021 Secure and Efficient Task Matching with Multi-keyword in Multi-requester and Multi-worker Crowdsourcing
abstract
Crowdsourcing enables users (task requesters) to outsource complex tasks to an unspecified crowd of workers. To guarantee the quality of crowdsourcing service, it is necessary to select the most appropriate task workers to complete the tasks. To this end, the crowdsourcing platform (broker) must conduct the mutual matching between tasks and workers based on the task requirements and worker preferences. However, both task requirements and worker preferences may contain sensitive information (e.g., time, location of the task, etc.), which should not be revealed to the broker and other adversaries. In this paper, we propose a secure and efficient task matching scheme to enable the broker to conduct the mutual matching between tasks and workers, according to task requirements and worker preferences with multiple keywords, while preserving the privacy of keywords contained in task requirements and worker preferences. Specifically, we design a new multi-reader and multi-writer searchable encryption primitive that can support the batch matching of multiple keywords. The security proof shows that our proposed task matching scheme is provably secure in the random oracle model under the Bilinear Diffie-Hellman (BDH) assumption. The performance evaluation shows that our multi-keyword batch matching can significantly reduce the computation cost compared to existing methods.
Kan Yang 0001, Senjuti Dutta
IWQoS1
2021 PMAB: A Public Mutual Audit Blockchain for Outsourced Data in Cloud Storage
abstract
With the rapid growth of data, limited by the storage capacity, more and more IoT applications choose to outsource data to Cloud Service Providers (CSPs). But, in such scenarios, outsourced data in cloud storage can be easily corrupted and difficult to be found in time, which brings about potential security issues. Thus, Provable Data Possession (PDP) protocol has been extensively researched due to its capability of supporting efficient audit for outsourced data in cloud. However, most PDP schemes require the Third-Party Auditor (TPA) to audit data for Data Owners (DOs), which requires the TPA to be trustworthy and fair. To eliminate the TPA, we present a Public Mutual Audit Blockchain (PMAB) for outsourced data in cloud storage. We first propose an audit chain architecture based on Ouroboros and an incentive mechanism based on credit to allow CSPs to audit each other mutually with anticollusion (any CSP is not willing to help other CSPs conceal data problems). Then, we design an audit protocol to achieve public audit efficiently with low cost of audit verification. Rigorous analysis explains the security of PMAB using game theory, and performance analysis shows the efficiency of PMAB using the real-world dataset.
Ruidan Su, Pei Huang 0013, Yuhan Bai, Kai Fan 0001, Kan Yang 0001, Hui Li 0006, Yintang Yang
Secur. Commun. Networks6
2021 Proxy-Free Privacy-Preserving Task Matching with Efficient Revocation in Crowdsourcing
abstract
Task matching in crowdsourcing has been extensively explored with the increasing popularity of crowdsourcing. However, privacy of tasks and workers is usually ignored in most of exiting solutions. In this paper, we study the problem of privacy-preserving task matching for crowdsourcing with multiple requesters and multiple workers. Instead of utilizing proxy re-encryption, we propose a proxy-free task matching scheme for multi-requester/multi-worker crowdsourcing, which achieves task-worker matching over encrypted data with scalability and non-interaction. We further design two different mechanisms for worker revocation including Server-Local Revocation (SLR) and Global Revocation (GR), which realize efficient worker revocation with minimal overhead on the whole system. The proposed scheme is provably secure in the random oracle model under the Decisional q-Combined Bilinear Diffie-Hellman (q-DCDBH) assumption. Comprehensive theoretical analysis and detailed simulation results show that the proposed scheme outperforms the state-of-the-art work.
Jiangang Shu, Kan Yang 0001, Xiaohua Jia, Ximeng Liu, Cong Wang 0001, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.2
2021 Anonymous and Privacy-Preserving Federated Learning With Industrial Big Data
abstract
Many artificial intelligence technologies have been applied for extracting useful information from massive industrial big data. However, the privacy issues are usually overlooked in many existing methods. In this article, we propose an anonymous and privacy-preserving federated learning scheme for the mining of industrial big data. We explored the effect of the proportion of shared parameters on the accuracy through experiments, and found that sharing partial parameters can almost achieve the accuracy of sharing all the parameters. On this basis, our proposed federated learning scheme reduces the privacy leakage by sharing fewer parameters between the server and each participant. Specifically, we leverage differential privacy on shared parameters with Gaussian mechanism to provide strict privacy preservation; the effect of different ε and δ on accuracy is tested; and we keep track of δ-when it reaches a certain threshold, training shall be stopped. What's more, we employ a proxy server as the middle layer between the server and all the participants to achieve anonymity of participants; it is worth noting that this can also reduce the communication burden on the federated learning server. Finally, we provide the security analysis and performance evaluations by comparing with other schemes.
Kai Fan 0001, Kan Yang 0001, Zilong Wang 0001, Hui Li 0006, Yintang Yang
IEEE Trans. Ind. Informatics3
2021 PROTECT: Efficient Password-Based Threshold Single-Sign-On Authentication for Mobile Users against Perpetual Leakage
abstract
Password-based single-sign-on authentication has been widely applied in mobile environments. It enables an identity server to issue authentication tokens to mobile users holding correct passwords. With an authentication token, one can request mobile services from related service providers without multiple registrations. However, if an adversary compromises the identity server, he can retrieve users' passwords by performing dictionary guessing attacks (DGA) and can overissue authentication tokens to break the security. In this paper, we propose a password-based threshold single-sign-on authentication scheme dubbed PROTECT that thwarts adversaries who can compromise identity server(s), where multiple identity servers are introduced to authenticate mobile users and issue authentication tokens in a threshold way. PROTECT supports key renewal that periodically updates the secret on each identity server to resist perpetual leakage of the secret. Furthermore, PROTECT is secure against off-line DGA: a credential used to authenticate a user is computed from the password and a server-side key. PROTECT is also resistant to online DGA and password testing attacks in an efficient way. We conduct a comprehensive performance evaluation of PROTECT, which demonstrates the high efficiency on the user side in terms of computation and communication and proves that it can be easily deployed on mobile devices.
Yuan Zhang 0006, Chunxiang Xu, Hongwei Li 0001, Kan Yang 0001, Nan Cheng 0001, Xuemin Shen
IEEE Trans. Mob. Comput.4
2021 Privacy-Preserving Task Recommendation Services for Crowdsourcing
abstract
Crowdsourcing is a distributed computing paradigm that utilizes human intelligence or resources from a crowd of workers. Existing solutions of task recommendation in crowdsourcing may leak private and sensitive information about both tasks and workers. To protect privacy, information about tasks and workers should be encrypted before being outsourced to the crowdsourcing platform, which makes the task recommendation a challenging problem. In this paper, we propose a privacy-preserving task recommendation scheme (PPTR) for crowdsourcing, which achieves the task-worker matching while preserving both task privacy and worker privacy. In PPTR, we first exploit the polynomial function to express multiple keywords of task requirements and worker interests. Then, we design a key derivation method based on matrix decomposition, to realize the multi-keyword matching between multiple requesters and multiple workers. Through PPTR, user accountability and user revocation are achieved effectively and efficiently. Extensive privacy analysis and performance evaluation show that PPTR is secure and efficient.
Jiangang Shu, Xiaohua Jia, Kan Yang 0001, Hua Wang 0002
IEEE Trans. Serv. Comput.3
2020 Secure and Verifiable Inference in Deep Neural Networks
abstract
Outsourced inference service has enormously promoted the popularity of deep learning, and helped users to customize a range of personalized applications. However, it also entails a variety of security and privacy issues brought by untrusted service providers. Particularly, a malicious adversary may violate user privacy during the inference process, or worse, return incorrect results to the client through compromising the integrity of the outsourced model. To address these problems, we propose SecureDL to protect the model’s integrity and user’s privacy in Deep Neural Networks (DNNs) inference process. In SecureDL, we first transform complicated non-linear activation functions of DNNs to low-degree polynomials. Then, we give a novel method to generate sensitive-samples, which can verify the integrity of a model’s parameters outsourced to the server with high accuracy. Finally, We exploit Leveled Homomorphic Encryption (LHE) to achieve the privacy-preserving inference. We shown that our sensitive-samples are indeed very sensitive to model changes, such that even a small change in parameters can be reflected in the model outputs. Based on the experiments conducted on real data and different types of attacks, we demonstrate the superior performance of SecureDL in terms of detection accuracy, inference accuracy, computation, and communication overheads.
Guowen Xu, Hongwei Li 0001, Hao Ren 0001, Jianfei Sun, Shengmin Xu, Jianting Ning, Haomiao Yang, Kan Yang 0001, Robert H. Deng
ACSAC8
2020 A Weight-based k-prototypes Algorithm for Anomaly Detection in Smart Grid
abstract
Anomaly detection is a typical method to find abnormal behaviors in smart grid, where the data may contain both categorical and numerical attributes with distinct significance. The k-prototypes algorithm is one of the most common algorithms for clustering mixed categorical and numerical data, however, it does not consider the significance of different attributes towards the clustering process. In this paper, we propose a weight based k-prototypes algorithm for anomaly detection in smart grid. Specifically, we first introduce an improved cost function to measure the categorical and numerical attributes uniformly and assign the weight to each attribute. We also propose two entropy metrics to calculate weight values and embed them into the k-prototypes algorithm for mixed data clustering in smart grid. Finally, we compare our proposed algorithm with existing clustering algorithms and the experimental results show that our algorithm is effective for anomaly detection in smart grid.
Kai Fan 0001, Kan Yang 0001, Zilong Wang 0001, Hui Li 0006
ICC4
2020 VerifyNet: Secure and Verifiable Federated Learning
abstract
As an emerging training model with neural networks, federated learning has received widespread attention due to its ability to update parameters without collecting users' raw data. However, since adversaries can track and derive participants' privacy from the shared gradients, federated learning is still exposed to various security and privacy threats. In this paper, we consider two major issues in the training process over deep neural networks (DNNs): 1) how to protect user's privacy (i.e., local gradients) in the training process and 2) how to verify the integrity (or correctness) of the aggregated results returned from the server. To solve the above problems, several approaches focusing on secure or privacy-preserving federated learning have been proposed and applied in diverse scenarios. However, it is still an open problem enabling clients to verify whether the cloud server is operating correctly, while guaranteeing user's privacy in the training process. In this paper, we propose VerifyNet, the first privacy-preserving and verifiable federated learning framework. In specific, we first propose a double-masking protocol to guarantee the confidentiality of users' local gradients during the federated learning. Then, the cloud server is required to provide the Proof about the correctness of its aggregated results to each user. We claim that it is impossible that an adversary can deceive users by forging Proof, unless it can solve the NP-hard problem adopted in our model. In addition, VerifyNet is also supportive of users dropping out during the training process. The extensive experiments conducted on real-world data also demonstrate the practical performance of our proposed scheme.
Guowen Xu, Hongwei Li 0001, Sen Liu 0007, Kan Yang 0001, Xiaodong Lin 0001
IEEE Trans. Inf. Forensics Secur.4
2019 Blockchain-Based Secure Time Protection Scheme in IoT
abstract
Internet of Things (IoT) has been developed rapidly to make our life easier. In many IoT applications (e.g., smart homes, healthcare, etc.), all the IoT devices should be synchronized in time. However, some malicious nodes located in the IoT network can influence the time synchronization, which may interrupt the IoT system and lead to serious accidents. Therefore, it is critical and challenging to guarantee the accuracy and consistency of time during the time synchronization among all the IoT devices. In this paper, we propose a blockchain-based scheme to assure the security during time synchronization in IoT. Specifically, a publicly verifiable ledger is utilized to record and broadcast time, which can minimize many attacks from external environments. The use of multiple time sources can avoid the vulnerabilities caused by the centralized generation of accurate time. Moreover, the decentralized structure of this scheme has the advantage of adapting the changes of network topology. By employing an improved practical Byzantine fault tolerance consensus mechanism, time synchronization can be implemented efficiently. At last, the analysis results show that our proposed scheme can achieve the desired security with high efficiency.
Kai Fan 0001, Shangyang Wang, Yanhui Ren, Kan Yang 0001, Zheng Yan 0002, Hui Li 0006, Yintang Yang
IEEE Internet Things J.4
2019 SybSub: Privacy-Preserving Expressive Task Subscription With Sybil Detection in Crowdsourcing
abstract
The past decade has witnessed the rise of crowdsourcing, and privacy in crowdsourcing has also gained rising concern in the meantime. Task matching or task subscription is one of indispensable services in crowdsourcing, but few mechanisms can achieve the expressive task subscription while protecting the privacy. In this paper, we focus on the privacy leaks and attacks during task subscription in crowdsourcing, and propose a privacy-preserving task subscription scheme with sybil detection, called SybSub. The SybSub scheme achieves the expressiveness of task subscription in the multisubscriber and multipublisher crowdsourcing while protecting the privacy of both subscribers and publishers against the semi-honest crowdsourcing service provider, and meanwhile supports the sybil attack detection against greedy subscribers. We implement the SybSub scheme and evaluate it thoroughly. Performance results validate that the SybSub scheme is efficient and feasible.
Jiangang Shu, Ximeng Liu, Kan Yang 0001, Yinghui Zhang 0002, Xiaohua Jia, Robert H. Deng
IEEE Internet Things J.3
2019 Blockchain-Based Decentralized Trust Management in Vehicular Networks
abstract
Vehicular networks enable vehicles to generate and broadcast messages in order to improve traffic safety and efficiency. However, due to the nontrusted environments, it is difficult for vehicles to evaluate the credibilities of received messages. In this paper, we propose a decentralized trust management system in vehicular networks based on blockchain techniques. In this system, vehicles can validate the received messages from neighboring vehicles using Bayesian Inference Model. Based on the validation result, the vehicle will generate a rating for each message source vehicle. With the ratings uploaded from vehicles, roadside units (RSUs) calculate the trust value offsets of involved vehicles and pack these data into a “block.” Then, each RSU will try to add their “blocks” to the trust blockchain which is maintained by all the RSUs. By employing the joint proof-of-work (PoW) and proof-of-stake consensus mechanism, the more total value of offsets (stake) is in the block, the easier RSU can find the nonce for the hash function (PoW). In this way, all RSUs collaboratively maintain an updated, reliable, and consistent trust blockchain. Simulation results reveal that the proposed system is effective and feasible in collecting, calculating, and storing trust values in vehicular networks.
Zhe Yang 0006, Kan Yang 0001, Lei Lei 0004, Kan Zheng, Victor C. M. Leung
IEEE Internet Things J.2
2019 Enabling Efficient and Geometric Range Query With Access Control Over Encrypted Spatial Data
abstract
As a basic query function, range query has been exploited in many scenarios such as SQL retrieves, location-based services, and computational geometry. Meanwhile, with explosive growth of data volume, users are increasingly inclining to store data on the cloud for saving local storage and computational cost. However, a long-standing problem is that the user's data may be completely revealed to the cloud server because it has full data access right. To cope with this problem, a frequently-used method is to encrypt raw data before outsourcing them, but the availability and operability of data will be reduced significantly. In this paper, we propose an efficient and geometric range query scheme (EGRQ) supporting searching and data access control over encrypted spatial data. We employ secure KNN computation, polynomial fitting technique, and order-preserving encryption to achieve secure, efficient, and accurate geometric range query over cloud data. Then, we propose a novel spatial data access control strategy to refine user's rights in our EGRQ. To improve the efficiency, R-tree is adopted to reduce the searching space and matching times in whole search process. Finally, we theoretically prove the security of our proposed scheme in terms of confidentiality of spatial data, privacy protection of index and trapdoor, and the unlinkability of trapdoors. In addition, extensive experiments demonstrate the high efficiency of our proposed model compared with existing schemes.
Guowen Xu, Hongwei Li 0001, Yuan-Shun Dai, Kan Yang 0001, Xiaodong Lin 0001
IEEE Trans. Inf. Forensics Secur.4
2018 SybMatch: Sybil Detection for Privacy-Preserving Task Matching in Crowdsourcing
abstract
The past decade has witnessed the rise of crowdsourcing, and privacy in crowdsourcing has also gained rising concern in the meantime. In this paper, we focus on the privacy leaks and sybil attacks during the task matching, and propose a privacy-preserving task matching scheme, called SybMatch. The SybMatch scheme can simultaneously protect the privacy of publishers and subscribers against semi-honest crowdsourcing service provider, and meanwhile support the sybil detection against greedy subscribers and efficient user revocation. Detailed security analysis and thorough performance evaluation show that the SybMatch scheme is secure and efficient.
Jiangang Shu, Ximeng Liu, Kan Yang 0001, Yinghui Zhang 0002, Xiaohua Jia, Robert H. Deng
GLOBECOM3
2018 Anonymous Privacy-Preserving Task Matching in Crowdsourcing
abstract
With the development of sharing economy, crowdsourcing as a distributed computing paradigm has become increasingly pervasive. As one of indispensable services for most crowdsourcing applications, task matching has also been extensively explored. However, privacy issues are usually ignored during the task matching and few existing privacy-preserving crowdsourcing mechanisms can simultaneously protect both task privacy and worker privacy. This paper systematically analyzes the privacy leaks and potential threats in the task matching and proposes a single-keyword task matching scheme for the multirequester/multiworker crowdsourcing with efficient worker revocation. The proposed scheme not only protects data confidentiality and identity anonymity against the crowd-server, but also achieves query traceability against dishonest or revoked workers. Detailed privacy analysis and thorough performance evaluation show that the proposed scheme is secure and feasible.
Jiangang Shu, Ximeng Liu, Xiaohua Jia, Kan Yang 0001, Robert H. Deng
IEEE Internet Things J.4
2018 Exploiting Social Network to Enhance Human-to-Human Infection Analysis without Privacy Leakage
abstract
Human-to-human infection, as a type of fatal public health threats, can rapidly spread, resulting in a large amount of labor and health cost for treatment, control and prevention. To slow down the spread of infection, social network is envisioned to provide detailed contact statistics to isolate susceptive people who has frequent contacts with infected patients. In this paper, we propose a novel human-to-human infection analysis approach by exploiting social network data and health data that are collected by social network and e-healthcare technologies. We enable the social cloud server and health cloud server to exchange social contact information of infected patients and user's health condition in a privacy-preserving way. Specifically, we propose a privacy-preserving data query method based on conditional oblivious transfer to guarantee that only the authorized entities can query users’ social data and the social cloud server cannot infer anything during the query. In addition, we propose a privacy-preserving classification-based infection analysis method that can be performed by untrusted cloud servers without accessing the users’ health data. The performance evaluation shows that the proposed approach achieves higher infection analysis accuracy with the acceptable computational overhead.
Kuan Zhang 0001, Xiaohui Liang 0002, Jianbing Ni, Kan Yang 0001, Xuemin Shen
IEEE Trans. Dependable Secur. Comput.4
2018 HealthDep: An Efficient and Secure Deduplication Scheme for Cloud-Assisted eHealth Systems
abstract
In this paper, we analyze the inherent characteristic of electronic medical records (EMRs) from actual electronic health (eHealth) systems, where we found that first, multiple patients would generate large amounts of duplicate EMRs and second, cross-patient duplicate EMRs would be generated numerously only in the case that the patients consult doctors in the same department. We then propose the first efficient and secure encrypted EMRs deduplication scheme for cloud-assisted eHealth systems (HealthDep). With the integration of our analysis results, HealthDep allows the cloud server to efficiently perform the EMRs deduplication, and enables the cloud server to reduce storage costs by more than 65% while ensuring the confidentiality of EMRs. Security analysis shows that HealthDep provides a stronger security guarantee than Marforio et al.'s scheme (NDSS 2014) and Bellare et al.'s scheme (USENIX Security 2013). Algorithm implementation and performance analysis demonstrate the feasibility and high efficiency of HealthDep.
Yuan Zhang 0006, Chunxiang Xu, Hongwei Li 0001, Kan Yang 0001, Jianying Zhou 0001, Xiaodong Lin 0001
IEEE Trans. Ind. Informatics4
2017 CryptMDB: A practical encrypted MongoDB over big data
abstract
In big data era, data are usually stored in databases for easy access and utilization, which are now woven into every aspect of our lives. However, traditional relational databases cannot address users' demands for quick data access and calculating, since they cannot process data in a distributed way. To tackle this problem, non-relational databases such as MongoDB have emerged up and been applied in various Scenarios. Nevertheless, it should be noted that most MongoDB products fail to consider user's data privacy. In this paper, we propose a practical encrypted MongoDB (i.e., CryptMDB). Specifically, we utilize an additive homomorphic asymmetric cryptosystem to encrypt user's data and achieve strong privacy protection. Security analysis indicates that the CryptMDB can achieve confidentiality of user's data and prevent adversaries from illegally gaining access to the database. Furthermore, extensive experiments demonstrate that the CryptMDB achieves better efficiency than existing relational database in terms of data access and calculating.
Guowen Xu, Hongwei Li 0001, Yuan-Shun Dai, Kan Yang 0001
ICC6
2017 QoE loss probability based game-theoretic approach for spectrum sharing in heterogeneous networks
abstract
With the rapid development of wireless communication and mobile devices, heterogeneous networks have emerged as a promising paradigm to enable users' data services. However, it lacks an experience blocking theory to optimize data services. Furthermore, due to the limited resources of spectrum, the spectrum sharing based on the quality of experience (QoE) in heterogeneous networks becomes a new challenge. Therefore, to tackle the above challenge, we present an experience blocking (EB) ratio based game-theoretic approach for spectrum sharing in heterogeneous networks where the small cell can lease the spare spectrum from macro cell. Specifically, firstly, a novel EB ratio based model is proposed to evaluate the efficiency of spectrum usage in a cell. Then a Stackelberg game is employed to formulate the interaction between macro cell and small cell according to the EB ratio. Finally, an EB table is given to evaluate the blocking status of a cell and simulation results show that the proposed scheme can improve the efficiency of spectrum sharing better than other schemes.
Qichao Xu, Zhou Su 0001, Qiyong Zhao, Jiantao Song, Wenxue Shen, Ying Wang 0002, Kan Yang 0001
ICC7
2017 A blockchain-based reputation system for data credibility assessment in vehicular networks
abstract
The security of vehicular networks has been paid increasing attention to with the rapid development of automobile industry and Internet of Things (IoT). However, existing approaches mainly focus on ensuring data authentication and integrity, which are not sufficient to assess the credibility of received messages. Recently, reputation systems are proved to be effective approaches to solve the above problem. This paper proposes a new reputation system for data credibility assessment based on the blockchain techniques. In this system, vehicles rate the received messages based on observations of traffic environments and pack these ratings into a “block”. Each block is “chained” to the previous one by storing the hash value of the previous block. Then, a temporary center node is elected from vehicles and it is responsible for broadcasting its rating block to others. Based on ratings stored in the blockchain, vehicles are able to calculate the reputation value of the message sender and then evaluate the credibility of the message. Simulation results reveal that the proposed system is reliable in collecting, validating, and storing reputation information in vehicular networks.
Zhe Yang 0006, Kan Zheng, Kan Yang 0001, Victor C. M. Leung
PIMRC3
2017 Achieving efficient and privacy-preserving truth discovery in crowd sensing systems
Guowen Xu, Hongwei Li 0001, Chen Tan, Yuan-Shun Dai, Kan Yang 0001
Comput. Secur.6
2017 An Efficient and Fine-Grained Big Data Access Control Scheme With Privacy-Preserving Policy
abstract
How to control the access of the huge amount of big data becomes a very challenging issue, especially when big data are stored in the cloud. Ciphertext-policy attribute-based encryption (CP-ABE) is a promising encryption technique that enables end-users to encrypt their data under the access policies defined over some attributes of data consumers and only allows data consumers whose attributes satisfy the access policies to decrypt the data. In CP-ABE, the access policy is attached to the ciphertext in plaintext form, which may also leak some private information about end-users. Existing methods only partially hide the attribute values in the access policies, while the attribute names are still unprotected. In this paper, we propose an efficient and fine-grained big data access control scheme with privacy-preserving policy. Specifically, we hide the whole attribute (rather than only its values) in the access policies. To assist data decryption, we also design a novel attribute bloom filter to evaluate whether an attribute is in the access policy and locate the exact position in the access policy if it is in the access policy. Security analysis and performance evaluation show that our scheme can preserve the privacy from any linear secret-sharing schemes access policy without employing much overhead.
Kan Yang 0001, Hui Li 0006, Kan Zheng, Zhou Su 0001, Xuemin Shen
IEEE Internet Things J.1
2017 Identifying the Most Valuable Workers in Fog-Assisted Spatial Crowdsourcing
abstract
In this paper, we study worker selection in spatial crowdsourcing, which is the recruitment of human workers in a specific location to collect geographical data. To achieve better performance, spatial crowdsourcing task relies on both worker's effort and skill. Therefore, to maximize the long-term platform utility, we exploit fog platform as a service to identify valuable workers through learning their performance information. Worker's historical performance data are recorded at local fog server, based on which valuable workers are identified and selected to perform the tasks. During worker selection, we aim at balancing the exploration and exploitation, and propose an online algorithm that promotes workers who are not fully explored. With budget constraint, the proposed algorithm is able to maximize the long-term platform utility. Theoretical analysis indicates that the proposed learning algorithm achieves asymptotically diminishing regret. Finally, extensive simulations on real-world dataset are conducted, which demonstrate the advantage of our algorithm over other methods.
Peng Yang 0004, Ning Zhang 0007, Shan Zhang 0001, Kan Yang 0001, Li Yu 0003, Xuemin Shen
IEEE Internet Things J.4
2017 Privacy-preserving attribute-keyword based data publish-subscribe service on cloud platforms
Kan Yang 0001, Kuan Zhang 0001, Xiaohua Jia, M. Anwar Hasan, Xuemin Shen
Inf. Sci.1
2016 Time-Domain Attribute-Based Access Control for Cloud-Based Video Content Sharing: A Cryptographic Approach
abstract
With the ever-increasing demands on multimedia applications, cloud computing, due to its economical but powerful resources, is becoming a natural platform to process, store, and share multimedia contents. However, the employment of cloud computing also brings new security and privacy issues as few public cloud servers can be fully trusted by users. In this paper, we focus on how to securely share video contents to a certain group of people during a particular time period in cloud-based multimedia systems, and propose a cryptographic approach, a provably secure time-domain attribute-based access control (TAAC) scheme, to secure the cloud-based video content sharing. Specifically, we first propose a provably secure time-domain attribute-based encryption scheme by embedding the time into both the ciphertexts and the keys, such that only users who hold sufficient attributes in a specific time slot can decrypt the video contents. We also propose an efficient attribute updating method to achieve the dynamic change of users' attributes, including granting new attributes, revoking previous attributes, and regranting previously revoked attributes. We further discuss on how to control those video contents that can be commonly accessed in multiple time slots and how to make special queries on video contents generated in previous time slots. The security analysis and performance evaluation show that TAAC is provably secure in generic group model and efficient in practice.
Kan Yang 0001, Xiaohua Jia, Xuemin Shen
IEEE Trans. Multim.1
2016 Optimal Reliability in Energy Harvesting Industrial Wireless Sensor Networks
abstract
For industrial wireless sensor networks, it is essential to reliably sense and deliver the environmental data on time to avoid system malfunction. While energy harvesting is a promising technique to extend the lifetime of sensor nodes, it also brings new challenges for system reliability due to the stochastic nature of the harvested energy. In this paper, we investigate the optimal energy management policy to minimize the weighted packet loss rate under the delay constraint, where the packet loss rate considers the lost packets, both during the sensing and delivering processes. We show that the above-mentioned energy management problem can be modeled as an infinite horizon average reward constraint Markov decision problem. In order to address the well-known curse of dimensionality problem and facilitate distributed implementation, we use the linear value approximation technique. Moreover, we apply stochastic online learning with a post-decision state to deal with the lack of the knowledge of the underlying stochastic processes. A distributed energy allocation algorithm with a water-filling structure and a scheduling algorithm by an auction mechanism are obtained. Experimental results show that the proposed algorithm achieves nearly the same performance as the optimal offline value iteration algorithm while requiring much less computation complexity and signaling overhead, and outperforms various existing baseline algorithms.
Lei Lei 0004, Yiru Kuang, Xuemin Shen, Kan Yang 0001, Jian Qiao, Zhangdui Zhong
IEEE Trans. Wirel. Commun.4
2016 Exploiting Secure and Energy-Efficient Collaborative Spectrum Sensing for Cognitive Radio Sensor Networks
abstract
Cognitive radio sensor network (CRSN) has emerged as a promising solution to address the spectrum scarcity problem in traditional sensor networks, by enabling sensor nodes to opportunistically access licensed spectrum. To protect the transmission of primary users and enhance spectrum utilization, collaborative spectrum sensing is generally adopted for improving spectrum sensing accuracy. However, as sensor nodes may be compromised by adversaries, these nodes can send false sensing reports to mislead the spectrum sensing decision, making CRSNs vulnerable to spectrum sensing data falsification (SSDF) attacks. Meanwhile, since the energy consumption of spectrum sensing is considerable for energy-limited sensor nodes, SSDF attack countermeasures should be carefully devised with the consideration of energy efficiency. To this end, we propose a secure and energy-efficient collaborative spectrum sensing scheme to resist SSDF attacks and enhance the energy efficiency in CRSNs. Specifically, we theoretically analyze the impacts of two types of attacks, i.e., independent and collaborative SSDF attacks, on the accuracy of collaborative spectrum sensing in a probabilistic way. To maximize the energy efficiency of spectrum sensing, we calculate the minimum number of sensor nodes needed for spectrum sensing to guarantee the desired accuracy of sensing results. Moreover, a trust evaluation scheme, named FastDtec, is developed to evaluate the spectrum sensing behaviors and fast identify compromised nodes. Finally, a secure and energy-efficient collaborative spectrum sensing scheme is proposed to further improve the energy efficiency of collaborative spectrum sensing, by adaptively isolating the identified compromised nodes from spectrum sensing. Extensive simulation results demonstrate that our proposed scheme can resist SSDF attacks and significantly improve the energy efficiency of collaborative spectrum sensing.
Ju Ren 0001, Yaoxue Zhang, Qiang Ye 0002, Kan Yang 0001, Kuan Zhang 0001, Xuemin Shen
IEEE Trans. Wirel. Commun.4
2015 Generalized pattern matching string search on encrypted data in cloud systems
abstract
Searchable encryption is an important and challenging issue. It allows people to search on encrypted data. This is a very useful function when more and more people choose to host their data in the cloud and the cloud server is not fully trustable. Existing solutions for searchable encryption are only limited to some simple functions of search, such as boolean search or similarity search. In this paper, we propose a scheme for Generalized Pattern-matching String-search on Encrypted data (GPSE) in cloud systems. GPSE allows users to specify their search queries by using generalized wildcard-based string patterns (such as SQL-like patterns). It gives users great expressive power in specifying highly targeted search queries. In the framework of GPSE, we particularly implemented two most commonly used pattern matching search functions on encrypted data, the substring matching and the longest-prefix-first matching. We also prove that GPSE is secure under the known-plaintext model. Experiments over real data sets show that GPSE achieves high search accuracy.
Dongsheng Wang 0004, Xiaohua Jia, Cong Wang 0001, Kan Yang 0001, Shaojing Fu, Ming Xu 0002
INFOCOM4
2015 Exploiting mobile social behaviors for Sybil detection
abstract
In this paper, we propose a Social-based Mobile Sybil Detection (SMSD) scheme to detect Sybil attackers from their abnormal contacts and pseudonym changing behaviors. Specifically, we first define four levels of Sybil attackers in mobile environments according to their attacking capabilities. We then exploit mobile users' contacts and their pseudonym changing behaviors to distinguish Sybil attackers from normal users. To alleviate the storage and computation burden of mobile users, the cloud server is introduced to store mobile user's contact information and to perform the Sybil detection. Furthermore, we utilize a ring structure associated with mobile user's contact signatures to resist the contact forgery by mobile users and cloud servers. In addition, investigating mobile user's contact distribution and social proximity, we propose a semi-supervised learning with Hidden Markov Model to detect the colluded mobile users. Security analysis demonstrates that the SMSD can resist the Sybil attackers from the defined four levels, and the extensive trace-driven simulation shows that the SMSD can detect these Sybil attackers with high accuracy.
Kuan Zhang 0001, Xiaohui Liang 0002, Rongxing Lu, Kan Yang 0001, Xuemin Shen
INFOCOM4
2015 Identity-preserving public auditing for shared cloud data
abstract
Cloud storage enables users to remotely store their data and share the data through the cloud. Existing integrity auditing schemes for shared data are often not identity-preserving and have high auditing cost, and hence are still far from practical application. In this work, we propose a public auditing scheme for shared data in cloud storage with identity privacy preservation. To preserve identity privacy against the auditor, we convert signatures computed by different users into signatures computed by the challenge user with proxy re-signature. Our scheme supports user revocation without re-signing signatures computed by revoked users, while the integrity of shared data can still be correctly checked. Furthermore, the auditing is efficient in the sense that the number of pairing operations during auditing is independent of the number of challenged blocks and users. We further present a batch auditing supporting multiple auditing delegations from different groups instead of only the same group. Security analysis demonstrates that our scheme is provably secure. Numeric analysis and simulation results show that both computation and communication costs of our scheme are lower than in existing schemes.
Chuanhe Huang, Kan Yang 0001, Jiaoli Shi
IWQoS3
2015 Secure and Verifiable Policy Update Outsourcing for Big Data Access Control in the Cloud
abstract
Due to the high volume and velocity of big data, it is an effective option to store big data in the cloud, as the cloud has capabilities of storing big data and processing high volume of user access requests. Attribute-based encryption (ABE) is a promising technique to ensure the end-to-end security of big data in the cloud. However, the policy updating has always been a challenging issue when ABE is used to construct access control schemes. A trivial implementation is to let data owners retrieve the data and re-encrypt it under the new access policy, and then send it back to the cloud. This method, however, incurs a high communication overhead and heavy computation burden on data owners. In this paper, we propose a novel scheme that enabling efficient access control with dynamic policy updating for big data in the cloud. We focus on developing an outsourced policy updating method for ABE systems. Our method can avoid the transmission of encrypted data and minimize the computation work of data owners, by making use of the previously encrypted data with old access policies. Moreover, we also propose policy updating algorithms for different types of access policies. Finally, we propose an efficient and secure method that allows data owner to check whether the cloud server has updated the ciphertexts correctly. The analysis shows that our policy updating outsourcing scheme is correct, complete, secure and efficient.
Kan Yang 0001, Xiaohua Jia, Kui Ren 0001
IEEE Trans. Parallel Distributed Syst.1
2014 Enabling efficient access control with dynamic policy updating for big data in the cloud
abstract
Due to the high volume and velocity of big data, it is an effective option to store big data in the cloud, because the cloud has capabilities of storing big data and processing high volume of user access requests. Attribute-Based Encryption (ABE) is a promising technique to ensure the end-to-end security of big data in the cloud. However, the policy updating has always been a challenging issue when ABE is used to construct access control schemes. A trivial implementation is to let data owners retrieve the data and re-encrypt it under the new access policy, and then send it back to the cloud. This method incurs a high communication overhead and heavy computation burden on data owners. In this paper, we propose a novel scheme that enabling efficient access control with dynamic policy updating for big data in the cloud. We focus on developing an outsourced policy updating method for ABE systems. Our method can avoid the transmission of encrypted data and minimize the computation work of data owners, by making use of the previously encrypted data with old access policies. Moreover, we also design policy updating algorithms for different types of access policies. The analysis show that our scheme is correct, complete, secure and efficient.
Kan Yang 0001, Xiaohua Jia, Kui Ren 0001, Ruitao Xie, Liusheng Huang
INFOCOM1
2014 Expressive, Efficient, and Revocable Data Access Control for Multi-Authority Cloud Storage
abstract
Data access control is an effective way to ensure the data security in the cloud. Due to data outsourcing and untrusted cloud servers, the data access control becomes a challenging issue in cloud storage systems. Ciphertext-Policy Attribute-based Encryption (CP-ABE) is regarded as one of the most suitable technologies for data access control in cloud storage, because it gives data owners more direct control on access policies. However, it is difficult to directly apply existing CP-ABE schemes to data access control for cloud storage systems because of the attribute revocation problem. In this paper, we design an expressive, efficient and revocable data access control scheme for multi-authority cloud storage systems, where there are multiple authorities co-exist and each authority is able to issue attributes independently. Specifically, we propose a revocable multi-authority CP-ABE scheme, and apply it as the underlying techniques to design the data access control scheme. Our attribute revocation method can efficiently achieve both forward security and backward security. The analysis and simulation results show that our proposed data access control scheme is secure in the random oracle model and is more efficient than previous works.
Kan Yang 0001, Xiaohua Jia
IEEE Trans. Parallel Distributed Syst.1
2013 Attribute-based fine-grained access control with efficient revocation in cloud storage systems
abstract
A cloud storage service allows data owner to outsource their data to the cloud and through which provide the data access to the users. Because the cloud server and the data owner are not in the same trust domain, the semi-trusted cloud server cannot be relied to enforce the access policy. To address this challenge, traditional methods usually require the data owner to encrypt the data and deliver decryption keys to authorized users. These methods, however, normally involve complicated key management and high overhead on data owner. In this paper, we design an access control framework for cloud storage systems that achieves fine-grained access control based on an adapted Ciphertext-Policy Attribute-based Encryption (CP-ABE) approach. In the proposed scheme, an efficient attribute revocation method is proposed to cope with the dynamic changes of users' access privileges in large-scale systems. The analysis shows that the proposed access control scheme is provably secure in the random oracle model and efficient to be applied into practice.
Kan Yang 0001, Xiaohua Jia, Kui Ren 0001
AsiaCCS1
2013 DAC-MACS: Effective data access control for multi-authority cloud storage systems
abstract
Data access control is an effective way to ensure the data security in the cloud. However, due to data outsourcing and untrusted cloud servers, the data access control becomes a challenging issue in cloud storage systems. Existing access control schemes are no longer applicable to cloud storage systems, because they either produce multiple encrypted copies of the same data or require a fully trusted cloud server. Ciphertext-Policy Attribute-based Encryption (CP-ABE) is a promising technique for access control of encrypted data. It requires a trusted authority manages all the attributes and distributes keys in the system. In cloud storage systems, there are multiple authorities co-exist and each authority is able to issue attributes independently. However, existing CP-ABE schemes cannot be directly applied to data access control for multi-authority cloud storage systems, due to the inefficiency of decryption and revocation. In this paper, we propose DAC-MACS (Data Access Control for Multi-Authority Cloud Storage), an effective and secure data access control scheme with efficient decryption and revocation. Specifically, we construct a new multi-authority CP-ABE scheme with efficient decryption and also design an efficient attribute revocation method that can achieve both forward security and backward security. The analysis and the simulation results show that our DAC-MACS is highly efficient and provably secure under the security model.
Kan Yang 0001, Xiaohua Jia, Kui Ren 0001, Bo Zhang 0036
INFOCOM1
2013 DAC-MACS: Effective Data Access Control for Multiauthority Cloud Storage Systems
abstract
Data access control is an effective way to ensure data security in the cloud. However, due to data outsourcing and untrusted cloud servers, the data access control becomes a challenging issue in cloud storage systems. Existing access control schemes are no longer applicable to cloud storage systems, because they either produce multiple encrypted copies of the same data or require a fully trusted cloud server. Ciphertext-policy attribute-based encryption (CP-ABE) is a promising technique for access control of encrypted data. However, due to the inefficiency of decryption and revocation, existing CP-ABE schemes cannot be directly applied to construct a data access control scheme for multiauthority cloud storage systems, where users may hold attributes from multiple authorities. In this paper, we propose data access control for multiauthority cloud storage (DAC-MACS), an effective and secure data access control scheme with efficient decryption and revocation. Specifically, we construct a new multiauthority CP-ABE scheme with efficient decryption, and also design an efficient attribute revocation method that can achieve both forward security and backward security. We further propose an extensive data access control scheme (EDAC-MACS), which is secure under weaker security assumptions.
Kan Yang 0001, Xiaohua Jia, Kui Ren 0001, Bo Zhang 0036, Ruitao Xie
IEEE Trans. Inf. Forensics Secur.1
2013 An Efficient and Secure Dynamic Auditing Protocol for Data Storage in Cloud Computing
abstract
In cloud computing, data owners host their data on cloud servers and users (data consumers) can access the data from cloud servers. Due to the data outsourcing, however, this new paradigm of data hosting service also introduces new security challenges, which requires an independent auditing service to check the data integrity in the cloud. Some existing remote integrity checking methods can only serve for static archive data and, thus, cannot be applied to the auditing service since the data in the cloud can be dynamically updated. Thus, an efficient and secure dynamic auditing protocol is desired to convince data owners that the data are correctly stored in the cloud. In this paper, we first design an auditing framework for cloud storage systems and propose an efficient and privacy-preserving auditing protocol. Then, we extend our auditing protocol to support the data dynamic operations, which is efficient and provably secure in the random oracle model. We further extend our auditing protocol to support batch auditing for both multiple owners and multiple clouds, without using any trusted organizer. The analysis and simulation results show that our proposed auditing protocols are secure and efficient, especially it reduce the computation cost of the auditor.
Kan Yang 0001, Xiaohua Jia
IEEE Trans. Parallel Distributed Syst.1
2012 Attributed-Based Access Control for Multi-authority Systems in Cloud Storage
abstract
Cipher text-Policy Attribute-base Encryption (CP-ABE) is regarded as one of the most suitable technologies for data access control in cloud storage. In almost all existing CP-ABE schemes, it is assumed that there is only one authority in the system responsible for issuing attributes to the users. However, in many applications, there are multiple authorities co-exist in a system and each authority is able to issue attributes independently. In this paper, we design an access control framework for multi-authority systems and propose an efficient and secure multi-authority access control scheme for cloud storage. We first design an efficient multi-authority CP-ABE scheme that does not require a global authority and can support any LSSS access structure. Then, we prove its security in the random oracle model. We also propose a new technique to solve the attribute revocation problem in multi-authority CP-ABE systems. The analysis and simulation results show that our multi-authority access control scheme is scalable and efficient.
Kan Yang 0001, Xiaohua Jia
ICDCS1
2012 Data storage auditing service in cloud computing: challenges, methods and opportunities
Kan Yang 0001, Xiaohua Jia
World Wide Web1
2010 Threshold Key Redistribution for Dynamic Change of Authentication Group in Wireless Mesh Networks
abstract
Threshold User Authentication is widely used to provide distributed authentication service in Wireless Mesh Networks(WMNs). In a (t, n) threshold authentication scheme, secret authentication keys are shared among n mesh authentication servers (MAS) and any t out of n MASs can collaboratively provide the authentication service. The existing threshold authentication methods usually assume that MASs are static in the system. That is, t and n do not change after system initialization. However, in WMNs, MASs often join or leave the network freely. In this paper, we propose a novel threshold key redistribution protocol, aiming to cope with dynamic change of the authentication group. We also discuss the key redistribution protocol that can tolerate compromised MASs in the network.
Kan Yang 0001, Xiaohua Jia, Bo Zhang 0036, Zhongming Zheng
GLOBECOM1
2010 A Distributed Collaborative Relay Protocol for Multi-Hop WLAN Accesses
abstract
Due to the packet-fairness property of the 802.11 WLANs, the clients with low rates take longer time to transmit a packet and would reduce the overall network throughput, as well as the per-node throughput of those high data rate clients. We propose a collaborative relay method, which allows high data rate clients to relay traffic for the low data rate clients to improve the network throughput. There are three original contributions made by this paper: 1) we develop a generalized model to analyze multi-hop relay for clients. By using this model, clients that are several hops away from each other may take the advantage of concurrent transmissions. 2) We propose a centralized algorithm to compute multi-hop relay topology for the clients and it can achieve the optimal throughput in our defined model. 3) We propose a distributed multi-hop relay protocol for clients dynamically connected to or disconnected from the network. Simulation results show that our algorithm can improve the throughput up to 42% on average, which is significantly better than the previous work. Up to 75% of the clients in the network use 1-hop or multi-hop relay, instead of connecting to the AP directly, for the performance gain; and up to 39% of the links have the opportunities to transmit concurrently with another link.
Bo Zhang 0036, Zhongming Zheng, Xiaohua Jia, Kan Yang 0001
GLOBECOM4
2010 Minimum AP Placement for WLAN with Rate Adaptation Using Physical Interference Model
abstract
There are two widely used interference models to characterize interference in wireless communication, protocol model and physical model. The protocol model simplifies the interference by considering only two concerned communication links (or nodes). It ignores the cumulative interference from other links (or nodes). On the other side, the physical model considers the cumulative interference of the ambiance, but its application is very much limited due to the complexity to compute the physical interference of the whole system. In this paper, we study the AP placement problem in the physical interference model. By assuming a simple scheduling method, we propose a heuristic algorithm aiming to find the placement of minimal number of APs in an indoor region to meet the end users' QoS requirements. From the simulation results, we find that there is a significant difference in performance between the algorithms that use the physical model and the protocol model. It shows that the results obtained from AP placement algorithm in the protocol model are not close to the real situation due to neglect of cumulative interference.
Zhongming Zheng, Bo Zhang 0036, Xiaohua Jia, Jun Zhang 0019, Kan Yang 0001
GLOBECOM5