Hechuan Guo

dblp:278/2738 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
10since 2021 · last 2026
0000-0003-0397-1382ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 6 since 2021Systems, architecture and hardware · 3 · 2 first-author · 3 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 PIR-DSN: A Decentralized Storage Network Supporting Private Information Retrieval
Jiahao Zhang 0003, Minghui Xu 0001, Hechuan Guo, Xiuzhen Cheng
INFOCOM3
2025 EC-Chain: Cost-Effective Storage Solution for Permissionless Blockchains
Minghui Xu 0001, Hechuan Guo, Ye Cheng, Chun-Chi Liu, Dongxiao Yu, Xiuzhen Cheng
INFOCOM2
2024 FileDES: A Secure, Scalable and Succinct Decentralized Encrypted Storage Network
abstract
Decentralized Storage Network (DSN) is an emerging technology that challenges traditional cloud-based storage systems by consolidating storage capacities from independent providers and coordinating to provide decentralized storage and retrieval services. However, current DSNs face several challenges associated with data privacy and efficiency of the proof systems. To address these issues, we propose FileDES ( Decentralized Encrypted Storage), which incorporates three essential elements: privacy preservation, scalable storage proof, and batch verification. FileDES provides encrypted data storage while maintaining data availability, with a scalable Proof of Encrypted Storage (PoES) algorithm that is resilient to Sybil and Generation attacks. Additionally, we introduce a rollup-based batch verification approach to simultaneously verify multiple files using publicly verifiable succinct proofs. We conducted a comparative evaluation on FileDES, Filecoin, Storj and Sia under various conditions, including a WAN composed of up to 120 geographically dispersed nodes. Our protocol outperforms the others in terms of proof generation/verification efficiency, storage costs, and scalability.
Minghui Xu 0001, Jiahao Zhang 0003, Hechuan Guo, Xiuzhen Cheng, Dongxiao Yu, Qin Hu 0001, Yipu Wu
INFOCOM3
2024 SoK: Decentralized storage network
abstract
Decentralized Storage Networks (DSNs) represent a paradigm shift in data storage methodology, distributing and housing data across multiple network nodes rather than relying on a centralized server or data center architecture. The fundamental objective of DSNs is to enhance security, reinforce reliability, and mitigate censorship risks by eliminating a single point of failure. Leveraging blockchain technology for functions such as access control, ownership validation, and transaction facilitation, DSN initiatives aim to provide users with a robust and secure alternative to traditional centralized storage solutions. This paper conducts a comprehensive analysis of the developmental trajectory of DSNs, focusing on key components such as Proof of Storage protocols, consensus algorithms, and incentive mechanisms. Additionally, the study explores recent optimization tactics, encountered challenges, and potential avenues for future research, thereby offering insights into the ongoing evolution and advancement within the DSN domain.
Chuanlei Li, Minghui Xu 0001, Jiahao Zhang 0003, Hechuan Guo, Xiuzhen Cheng
High Confid. Comput.4
2024 BFT-DSN: A Byzantine Fault-Tolerant Decentralized Storage Network
abstract
With the rapid development of blockchain and its applications, the amount of data stored on decentralized storage networks (DSNs) has grown exponentially. DSNs bring together affordable storage resources from around the world to provide robust, decentralized storage services for tens of thousands of decentralized applications (dApps). However, existing DSNs do not offer verifiability when implementing erasure coding for redundant storage, making them vulnerable to Byzantine encoders. Additionally, there is a lack of Byzantine fault-tolerant consensus for optimal resilience in DSNs. This paper introduces BFT-DSN, a Byzantine fault-tolerant decentralized storage network designed to address these challenges. BFT-DSN combines storage-weighted BFT consensus with erasure coding and incorporates homomorphic fingerprints and weighted threshold signatures for decentralized verification. The implementation of BFT-DSN demonstrates its comparable performance in terms of storage cost and latency as well as superior performance in Byzantine resilience when compared to existing industrial decentralized storage networks.
Hechuan Guo, Minghui Xu 0001, Jiahao Zhang 0003, Chun-Chi Liu, Rajiv Ranjan 0001, Dongxiao Yu, Xiuzhen Cheng
IEEE Trans. Computers1
2024 TBAC: A Tokoin-Based Accountable Access Control Scheme for the Internet of Things
abstract
Overprivilege Attack, a widely reported phenomenon in IoT that accesses unauthorized or excessive resources, is notoriously hard to prevent, trace and mitigate. In this paper, we propose TBAC, a Tokoin-Based Access Control model enabled by blockchain and Trusted Execution Environment (TEE) technologies, to offer fine-grained access control and strong auditability for IoT. TBAC materializes the virtual access power into a definite-amount, secure and accountable cryptographic coin, termed “tokoin” (token+coin), and manages it using atomic and accountable state-transition functions in a blockchain. A tokoin carries a fine-grained policy defined by the resource owner to specify the requirements to be satisfied before an access is granted, and the behavioral constraints that describe the correct procedure to follow during access. The strong-auditability is achieved with blockchain and a TEE-enabled trusted access control object (TACO) to ensure that all access activities are securely monitored and auditable. We prototype TBAC by implementing all its functions with well-studied cryptographic primitives over different blockchain platforms, building a TACO on top of the ARM Cortex-M33 TEE microcontroller, and constructing a user-friendly APP for regular users. A case study is finally presented to demonstrate how TBAC is employed to enable autonomous and secure in-home cargo delivery.
Chun-Chi Liu, Minghui Xu 0001, Hechuan Guo, Xiuzhen Cheng, Yinhao Xiao, Dongxiao Yu, Bei Gong, Arkady Yerukhimovich, Shengling Wang 0001, Weifeng Lyu
IEEE Trans. Mob. Comput.3
2023 An Efficient Revocable and Searchable MA-ABE Scheme With Blockchain Assistance for C-IoT
abstract
Internet of Things (IoT) devices usually stores data on clouds for computational overhead offloading and easy data sharing. The data owners, as a result, usually have concerns about the security and privacy of their data stored in such cloud-assisted IoT (C-IoT) systems. Traditional encryption and search primitives, including attribute-based encryption (ABE) and public-key encryption with keyword search (PEKS), however, suffer from high overheads in decryption and revocation, and privacy leakage in search. To address these issues, we propose an efficient revocable and searchable multiauthority ABE (MA-ABE) scheme named ERS-ABE, which utilizes blockchain (BC) technology to implement keyword-based search and dynamic user management. ERS-ABE also adopts cloud-assisted decryption to improve the efficiency of IoT devices. It has been proven to be secure against the selective replayable chosen-ciphertext attacks and the chosen-keyword attacks under the random oracle model. The feasibility and efficiency of ERS-ABE have been evaluated through theoretical analysis and extensive simulation studies. The results indicate that EAR-ABE performs better over the state-of-the-art in both storage and computational overheads. Particularly, the operations that are usually done by a central server but taken by a BC in EAR-ABE cost only a few seconds.
Jiguo Yu, Suhui Liu, Minghui Xu 0001, Hechuan Guo, Fangtian Zhong, Wei Cheng 0001
IEEE Internet Things J.4
2023 FileDAG: A Multi-Version Decentralized Storage Network Built on DAG-Based Blockchain
abstract
Decentralized Storage Networks (DSNs) can gather storage resources from mutually untrusted providers and form worldwide decentralized file systems. Compared to traditional storage networks, DSNs are built on top of blockchains, which can incentivize service providers and ensure strong security. However, existing DSNs face two major challenges. First, deduplication can only be achieved at the directory-level. Missing file-level deduplication leads to unavoidable extra storage and bandwidth cost. Second, current DSNs realize file indexing by storing extra metadata while blockchain ledgers are not fully exploited. To overcome these problems, we propose FileDAG, a DSN built on DAG-based blockchain to support file-level deduplication in storing multi-versioned files. When updating files, we adopt an increment generation method to calculate and store only the increments instead of the entire updated files. Besides, we introduce a two-layer DAG-based blockchain ledger, by which FileDAG can provide flexible and storage-saving file indexing by directly using the blockchain database without incurring extra storage overhead. We implement FileDAG and evaluate its performance with extensive experiments. The results demonstrate that FileDAG outperforms the state-of-the-art industrial DSNs considering storage cost and latency.
Hechuan Guo, Minghui Xu 0001, Jiahao Zhang 0003, Chun-Chi Liu, Dongxiao Yu, Schahram Dustdar, Xiuzhen Cheng
IEEE Trans. Computers1
2022 Extending On-Chain Trust to Off-Chain - Trustworthy Blockchain Data Collection Using Trusted Execution Environment (TEE)
abstract
Blockchain creates a secure environment on top of strict cryptographic assumptions and rigorous security proofs. It permits on-chain interactions to achieve trustworthy properties such as traceability, transparency, and accountability. However, current blockchain trustworthiness is only confined to on-chain, creating a “trust gap” to the physical, off-chain environment. This is due to the lack of a scheme that can truthfully reflect the physical world in a real-time and consistent manner. Such an absence hinders further blockchain applications in the physical world, especially for the security-sensitive ones. In this paper, we propose a framework to extend blockchain trust from on-chain to off-chain, and take trustworthy vaccine tracing as an example scheme. Our scheme consists of 1) a Trusted Execution Environment (TEE)-enabled trusted environment monitoring system built with the Arm Cortex-M33 microcontroller that continuously senses the inside of a vaccine box through trusted sensors and generates anti-forgery data; and 2) a consistency protocol to upload the environment status data from the TEE system to blockchain in a truthful, real-time consistent, continuous and fault-tolerant fashion. Our security analysis indicates that no adversary can tamper with the vaccine in any way without being captured. We carry out an experiment to record the internal status of a vaccine shipping box during transportation, and the results indicate that the proposed system incurs an average latency of 84 ms in local sensing and processing followed by an average latency of 130 ms to have the sensed data transmitted to and been available in the blockchain.
Chun-Chi Liu, Hechuan Guo, Minghui Xu 0001, Shengling Wang 0001, Dongxiao Yu, Jiguo Yu, Xiuzhen Cheng
IEEE Trans. Computers2
2021 Blockchain-Based Privacy Protection Scheme for IoT-Assisted Educational Big Data Management
abstract
Adoption of the Internet of Things (IoT) in education brings many benefits. However, the poor implementation of access control of educational data produced by the IoT devices has brought students’ and teachers’ privacy into danger. Attackers can access educational data that they are not permitted to access and even erase the records during access. To tackle this problem, we employ blockchain technology to guarantee the integrity of access control rules and trace the records of access events. In this paper, we propose a blockchain‐based access control scheme for the data produced by IoT devices. The scheme consists of three components: (1) a well‐implemented data collection module that is deployed in smart classrooms, which collects and uploads data about the real‐time situation inside the smart classroom to the data center; (2) a MongoDB‐based data center and its control module that makes access control decisions based on the verification of the permissions of visitors, where the permissions are managed by blockchain; and (3) a customized blockchain system that stores and keeps security policy updates of the role‐based access control module and records access events in a trusted way. Our analysis indicates that the proposed access control scheme guarantees the correctness of the access control process and makes the access of collected educational data auditable and responsible. Our system collectively analyzes the context of the smart classroom and is capable of detecting multiple scenarios such as absence, lateness, and gunshot. We show how the scheme preserves students’ and teachers’ privacy by carrying out extensive experimental studies. The results indicate that the proposed data management system can give correct responses as quickly as a traditional data server does while preserving privacy.
Xiaoshuang He, Hechuan Guo, Xueyu Cheng
Wirel. Commun. Mob. Comput.2