VLDB 2026 Research / reviewers in the wild / expert
Haoyang Wang 0005
dblp:277/1178
· DBLP profile ↗
18ranked-venue papers
10as first author
16since 2021 · last 2025
0000-0002-6663-0692ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 3 first-author · 6 since 2021Security and privacy · 7 · 5 first-author · 7 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Private Spatial Range Queries Over Outsourced Data: A Survey
Haoyang Wang 0005, Wei Hu 0008, Yue Quan |
IEEE Big Data | 1 |
| 2025 | Dynamic Multi-User Authorization in Ciphertext Retrieval With Proxy Re-EncryptionabstractCiphertext retrieval technology has been widely explored with the increasing popularity of cloud computing. Proxy re-encryption with Keyword search (PREKS) can support multi-user retrieval without increasing data owner's overhead, but users can continue searching once they have obtained search rights. It is difficult for a data owner to revoke a user's access rights because the data is stored in the cloud. In general, under the premise of forward and backward security, the user's search permission can be revoked by updating the ciphertext. Nevertheless, this approach may expose user or data privacy to cloud servers. In this paper, we utilize the Chinese Remainder Theorem to generate DO-Authorization and DU-Authentication factors, and realizes the authorization and revocation of a specific single user by adding or deleting authorization items. In addition, we use a designated tester algorithm in the ciphertext retrieval process to improve system security. Subsequent security analysis proves that the proposed scheme can resist the Chosen Keyword Attack and Keyword Guessing Attack. Simulation results indicate that the proposed scheme has high efficiency, especially in the user revocation phase Nan Gao 0003, Kai Fan 0001, Haoyang Wang 0005, Yintang Yang, Kan Yang 0001, Hui Li 0006 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | MU-MRQ: Enabling Multi-User Verifiable and Secure Multi-Dimensional Range Query Over Encrypted DataabstractIn recent years, multi-dimensional range query (MRQ) over encrypted data has been increasingly applied in various scenarios, making it one of the mainstream services for secure large-scale data storage and sharing in cloud computing. However, although existing privacy-preserving MRQ schemes can ensure query and data privacy, they still fail to fully protect single-dimensional privacy and path pattern. Moreover, most schemes lack mechanisms to verify the completeness and correctness of query results, making it impossible to guarantee their validity. To address these issues, this paper proposes a secure and efficient MRQ scheme with result verification for multiple users (MU-MRQ). First, we design a secure and efficient multi-dimensional data index based on the G-tree, incorporating a timestamp mechanism to verify the correctness and completeness of query results. Additionally, we propose two novel intersection predicate encryption protocols to achieve efficient retrieval while preserving single-dimensional privacy and path pattern. Rigorous security analysis demonstrates that our MU-MRQ scheme achieves security under the known background model. Comprehensive experiments on real-world datasets validate the efficiency of the MU-MRQ scheme. Haoyang Wang 0005, Kai Fan 0001, Kuan Zhang 0001, Fenghua Li 0001, Hui Li 0006, Yintang Yang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Beyond Access Pattern: Efficient Volume-Hiding Multi-Range Queries Over Outsourced Data ServicesabstractMulti-range query (MRQ) is a typical multi-attribute data query widely used in various practical applications. It is capable of searching all data objects contained in a query request. Many privacy-preserving MRQ schemes have been proposed to realize MRQ on encrypted data. However, existing MRQ schemes only consider the security threat caused by access pattern leakage, not the harm of volume pattern leakage. Moreover, most existing schemes cannot achieve efficient queries and updates while preserving the access pattern. In this paper, we propose an efficient MRQ scheme for hiding volume and access patterns. We first design a joint data index using Order-Revealing Encryption (ORE) and Pseudo-random functions (PRFs) to realize volume-hiding range queries. Then, we combine the private set intersection (PSI) and hardware Software Guard Extensions (SGX) to compute each attribute’s intersection of query results. In addition, we preserve access patterns during queries by designing a batch refresh algorithm and an update protocol. Finally, rigorous security analysis and extensive experiments demonstrate the security and performance of our scheme in real-world scenarios. Haoyang Wang 0005, Kai Fan 0001, Chong Yu 0002, Kuan Zhang 0001, Fenghua Li 0001, Haojin Zhu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Hide Yourself: Multi-Dimensional Range Queries for Responses-Hiding Over Outsourced DataabstractMulti-dimensional range query (MRQ) over outsourced data has been extensively applied in various domains. However, security and efficiency are still two aspects that cannot be easily balanced in private MRQs, as improving security inevitably incurs high computation, storage, and communication costs. Several schemes perform encrypted data retrieval in the trusted execution environment (TEE), which balances security and performance. Unfortunately, they focused on keywords or single-dimensional range queries, failing to address private MRQs. With the TEE (i.e., Intel SGX), we propose a response-hiding MRQ scheme over encrypted data (SGX-MRQ) in this paper. We first design an index structure called SDic, which can achieve efficient range queries while hiding the responses to each query from the server. Moreover, based on the security properties of SGX, we construct the encrypted polynomials of each dimension on the enclave and implement the intersection computation of multi-attribute queries by the server, which greatly improves the system efficiency. We present the formal definition of SGX-MRQ and perform a rigorous proof. We implement a prototype of SGX-MRQ and conduct extensive experiments on real datasets. The evaluation results validate the feasibility of our scheme in practical applications. Haoyang Wang 0005, Kai Fan 0001, Chong Yu 0002, Kuan Zhang 0001, Fenghua Li 0001, Haojin Zhu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | VDPSRQ: Achieving Verifiable and Dynamic Private Spatial Range Queries over Outsourced Database
Haoyang Wang 0005, Kai Fan 0001, Yue Quan, Fenghua Li 0001, Hui Li 0006 |
TrustCom | 1 |
| 2024 | DMASP: Dynamic Multi-keyword Searchable Encryption for Protected Access and Search Patterns with Differential PrivacyabstractIn recent years, cloud computing services have grown rapidly, with people outsourcing huge amounts of private data to cloud servers. Searchable encryption(SE) facilitates people’s use of data while protecting data privacy. To balance the efficiency, current SE schemes still leak information such as access, search and volume patterns to cloud servers, and most dynamic SE schemes leak forward and backward privacy, and these leaks create serious security threats. In this paper, we propose a dynamic SE scheme DMASP with suppressed leakage, which protects access pattern, search pattern and volume pattern simultaneously. We utilize the differential privacy mechanism to obfuscate databases, and introduce the CKKS algorithm to protect access and volume patterns during queries. Meanwhile, we design a secure structure to index databases efficiently, and protect forward and backward privacy during updates. We rigorously analyse the security of DMASP. Furthermore, comprehensive experimental evaluation show that DMASP can reduce the accuracy of attacks against patterns leakage in real-world databases. Yue Quan, Kai Fan 0001, Haoyang Wang 0005, Hui Li 0006, Yintang Yang |
TrustCom | 3 |
| 2024 | Ciphertext Retrieval With Identity Bidirectional Authentication and Matrix Index in IoTabstractCiphertext retrieval for cloud-based Internet of Things has been widely explored with the increasing popularity of cloud computing. However, in most existing solutions, the security and efficiency of the retrieval process are difficult to achieve simultaneously. To this end, we develop a novel secure matrix index, and we utilize identity-based encryption to encrypt keywords and homomorphic encryption to encrypt matrix values. The former can guarantee the security of the keyword, and the latter can realize the efficiency of the operation while ensuring safety. Then, we develop an identity-based bidirectional authentication algorithm to ensure that only authenticated users can retrieve ciphertext. In addition, we use different scoring formulas to calculate the relevance scores of documents with different lengths, ensuring that the documents are appropriately returned to users. Finally, we design a new retrieval structure to protect the privacy of the correspondence between keywords and ciphertexts. The security proof shows that the index and trapdoor can resist chosen keyword attack and keyword Guessing attack. The extensive simulation shows that our scheme is efficient. Nan Gao 0003, Kai Fan 0001, Haoyang Wang 0005, Kuan Zhang 0001, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 3 |
| 2024 | Public-Key Inverted-Index Keyword Search With Designated Tester and Multiuser Key Decryption in IoTabstractSearchable encryption for Cloud-based Internet of Things has been widely explored with the increasing popularity of cloud computing. The public-key encryption with keyword search (PEKS) system support multiuser retrieval. However, the PEKS search time is linearly increasing as the index keyword number growth, and the search time would be huge if the index keywords consistently increase. In this article, we introduce a novel scheme named as public-key inverted-index keyword search with designated tester and multiuser key decryption (IDPEKS). First of all, we design an inverted index based on B-plus tree to reduce the search time to a logarithmic level. On this basis, we optimized the TF-IDF formula and added user preference factor and font size factor to make the relevance score calculation more consistent with needs of receiver. Besides, we design a multiuser key decryption algorithm to protect the system symmetric key. In addition, we set index server to perform the index-trapdoor retrieval process. The designated index server tester can resist the attack of the cloud server on keywords. The security proof shows that the scheme can resist the chosen keyword attack (CKA), keyword guessing attack (KGA), and key guessing attack (KeyGA). The experimental results show that the algorithm can improve retrieval efficiency while have a short encryption time. Nan Gao 0003, Kai Fan 0001, Haoyang Wang 0005, Kuan Zhang 0001, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 3 |
| 2024 | Quantum-Safe Lattice-Based Certificateless Anonymous Authenticated Key Agreement for Internet of ThingsabstractIn recent years, the Internet of Things (IoT) has gained immense popularity in various aspects of work, learning, and daily life. Within the IoT realm, there is a growing concern regarding communication security issues between users and servers. However, addressing the communication security between servers is equally imperative, which has not received as much attention. To this end, we propose a certificateless anonymous authenticated key agreement (AKA) algorithm based on learning with errors (LWEs) and inhomogeneous small integer solution (ISIS) security assumptions. Our scheme provides strong resistance to quantum attacks and protects the privacy of communication servers. It also has constant communication costs and lower computational requirements than existing lattice-based anonymous AKA algorithms on the broadcast channel. Additionally, the proposed scheme eliminates the resource consumption of managing complex certificates and addresses the security risks associated with key escrow in the key generation center (KGC). Through security and performance analysis, we demonstrate that our approach can enhance the security of IoT-based healthcare systems while significantly improving communication efficiency. Our proposed scheme provides a promising solution to security issues related to server communication in IoT systems. Guanglu Wei, Kai Fan 0001, Kuan Zhang 0001, Haoyang Wang 0005, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 4 |
| 2024 | Lower rounds lattice-based anonymous AKA under the seCK model for the IoT
Guanglu Wei, Kai Fan 0001, Kuan Zhang 0001, Haoyang Wang 0005, Kan Yang 0001, Hui Li 0006, Yintang Yang |
Peer Peer Netw. Appl. | 4 |
| 2024 | LSPSS: Constructing Lightweight and Secure Scheme for Private Data Storage and Sharing in Aerial ComputingabstractAerial computing is gradually playing an essential role in edge and fog computing paradigms by virtue of mobility, availability, scalability, flexibility, and simultaneity, where the Low-altitude Computing (LAC) platform, as the end close to the data sources, is mainly responsible for data collection and storage. However, because of the long physical distance of data transmission and the vulnerability of the transmission link to various attacks, how to efficiently share the stored data while ensuring data privacy is a critical issue for LAC at present. In this paper, we propose a lightweight and secure private data storage and sharing scheme to support range queries over encrypted multi-dimensional data. Specifically, we first propose two data conversion methods for transforming location features and collected log files with multi-dimensional attributes in Unmanned Aerial Vehicles (UAVs). Based on the ideas of asymmetric scalar-product-preserving encryption (ASPE) and inner product comparison (IPC), we design a privacy-preserving storage and sharing technique for the converted data. In addition, to achieve secure and efficient data querying and result verification, we design a secure data index and build a data authentication structure (DAS) with G-tree. Finally, we rigorously analyze the security of our proposed scheme and conduct extensive experiments on a real-world database to prove that our proposed scheme is secure and easy to use in practical application scenarios. Haoyang Wang 0005, Kai Fan 0001, Chong Yu 0002, Kuan Zhang 0001, Fenghua Li 0001, Hui Li 0006, Yintang Yang, Haojin Zhu |
IEEE Trans. Serv. Comput. | 1 |
| 2023 | MSIAP: A Dynamic Searchable Encryption for Privacy-Protection on Smart Grid With Cloud-Edge-EndabstractWith the advent of 5G and the Internet of Things, edge computing and cloud computing with their respective strengths are bound as Cloud-Edge-End Orchestrated (CEEO). The CEEO network integrates artificial intelligence and provides innovative technologies for smart grid applications and services. With massive data transmission on the CEEO network, the trustworthiness of the service node exerts an enormous influence on data privacy. To realize securely share data and decrease the local storage, end-user prefer to encrypt data and upload it to the cloud. Meanwhile, the challenge is how to balance efficiency and security perfectly when users need to find relevant documents containing specific keywords from the CEEO network. In this article, we innovatively propose a searchable encryption scheme that supports multi-keyword subset retrieval, named MSIAP. Specifically, we enhance the Apriori, a data mining algorithm, to mine the relevance of files from massive information and build a multi-level index structure. On this basis, we achieve efficient multi-keyword subset retrieval and dynamic update with insignificant information disclosure in the smart grid. Furthermore, our MSIAP strengthens the present data retrieval methods and enormously reduces the time complexity to accommodate the system of distributed smart grid. Finally, we provide the security analysis and performance evaluations by comparing them with existing works. Kai Fan 0001, Ruidan Su, Kuan Zhang 0001, Haoyang Wang 0005, Hui Li 0006, Yintang Yang |
IEEE Trans. Cloud Comput. | 5 |
| 2023 | Joint Biological ID : A Secure and Efficient Lightweight Biometric Authentication SchemeabstractBiometric applications makes biometric authentication replace the traditional password in many cases. Biometric recognition technology has the advantages of convenience and high stability, facilitating identity recognition. However, the shortcoming of biometric authentication is easy to be stolen and leaked, which raises security concerns. In this paper, we design a lightweight joint biometric authentication scheme (SELBA) based on face and fingerprint. We improve searchable encryption (SE) to protect the privacy security of extracted biometric features in the storage and authentication stage. Because of the problem that biometric features cannot be changed or retrieved once leaked in existing schemes, we propose a cancelable mechanism to reconstruct stolen or damaged biometric templates. Moreover, we make a complete security analysis of the SELBA to meet the confidentiality, renewability, revocability, irreversibility and unlinkability of template in biometric recognition. Meanwhile, we conduct experiments on real data sets to show that SELBA is secure, efficient and easy to use in practical application scenarios. Haoyang Wang 0005, Kai Fan 0001, Kuan Zhang 0001, Fenghua Li 0001, Hui Li 0006, Yintang Yang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Encrypted Data Retrieval and Sharing Scheme in Space-Air-Ground-Integrated Vehicular NetworksabstractAs a smart transportation application of the Internet of Things, the Internet of Vehicles (IoV) depresses the chances of traffic accidents, while improving transportation efficiency and user driving experience. However, as the number of vehicles continues to grow, the original ground-based IoV system is difficult to meet the ever-increasing demand. To this end, space–air–ground-integrated network (SAGIN) incorporates satellite systems, aerial network and terrestrial communications. However, because SAGIN integrates multiple network services and communication modes, which makes SAGIN more vulnerable to various types of attacks and security threats. This article first presents the dominating security threats in data storage, transmission and sharing of space–air–ground integrated vehicular network (SAGIVN). Moreover, for guaranteeing the safety and effectiveness of the model, we advance a safe and effective encrypted data retrieval and sharing scheme in SAGIVN (ERDSS) for possible threats, the ERDSS can execute fuzzy retrieval over misspelling keywords and sort results by relevance scores to realize precise retrieval. We perform a comprehensive security discussion and execute experiments based on real-world data sets. The consequences demonstrate that the ERDSS is safe and efficient. Haoyang Wang 0005, Kai Fan 0001, Kuan Zhang 0001, Zilong Wang 0001, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 1 |
| 2022 | Secure and Efficient Data-Privacy-Preserving Scheme for Mobile Cyber-Physical SystemsabstractResearch on mobile cyber–physical systems (MCPSs) that have the superiorities of cyber–physical systems (CPSs) and expand their application range has become a trend in recent years. The applications of MCPS in fields, such as intelligent transportation systems, smart home appliances, and mobile education, have also become increasingly mature. However, MCPS also has some shortcomings that need to be solved urgently. Sensors carried on mobile devices collect data and upload huge amounts of data to the cloud for statistics and analysis. Mobile devices need to directly interact with the cloud, causing both parties to bear huge computing and communication costs. Since the interaction process includes data sharing and storage, it is particularly important to protect the data itself and the security of sharing. Searchable encryption ensures the safety of communication among the MPEs and the cloud, while protecting the privacy of data on the cloud. However, the existing searchable encryption technology cannot provide efficient and reliable data storage and sharing services for MPEs in MCPS under the premise of ensuring security. In this article, we present a secure and efficient data sharing and privacy protection scheme in MCPS on the basis of the edge computing model (NESPS). Meanwhile, the introduction of edge computing (EC) significantly reduces the communication consumption between the device and the cloud. Furthermore, attribute-based encryption (ABE) enables the NESPS to achieve fine-grained management of device authorities. Moreover, we have carried out security analysis and simulation on the NESPS, the results demonstrate that the NESPS meets the proposed requirements. Haoyang Wang 0005, Kai Fan 0001, Kuan Zhang 0001, Zilong Wang 0001, Hui Li 0006, Yintang Yang |
IEEE Internet Things J. | 1 |
| 2020 | Privacy-preserving searchable encryption in the intelligent edge computing
Kai Fan 0001, Kuan Zhang 0001, Haoyang Wang 0005, Hui Li 0006, Yingtang Yang |
Comput. Commun. | 4 |
| 2020 | A dynamic and verifiable multi-keyword ranked search scheme in the P2P networking environment
Haoyang Wang 0005, Kai Fan 0001, Hui Li 0006, Yintang Yang |
Peer-to-Peer Netw. Appl. | 1 |