VLDB 2026 Research / reviewers in the wild / expert
Zirui Qiao
dblp:286/9605
· DBLP profile ↗
25ranked-venue papers
9as first author
25since 2021 · last 2026
0000-0003-3602-4066ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 3 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 3 first-author · 6 since 2021Security and privacy · 5 · 1 first-author · 5 since 2021Systems, architecture and hardware · 2 · 2 first-author · 2 since 2021Theory of computation · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Leakage-resilient attribute-based encryption scheme with CCA security
Yanwei Zhou, Ran Xu 0012, Zirui Qiao, Bo Yang 0003 |
Theor. Comput. Sci. | 3 |
| 2026 | Leakage-Resilient Data Transmission Protocol With Multi-Receiver for Internet of ThingsabstractThe Internet of Things (IoT) is transforming lives, making daily tasks more convenient and efficient than ever before. However, the true potential of IoT can only be realized if its nodes interact with robust security, ensuring that sensitive data and personal information remain protected. While many data transmission protocols have been proposed in recent years, most fail to deliver on their security promises in real-world scenarios. Adversaries can exploit vulnerabilities through sophisticated leakage attacks such as side channel attacks or cold boot attacks to compromise encryption keys and undermine system integrity. Without advanced, resilient protocols, the promise of IoT is put at serious risk. In addition, the corresponding protocols deployed in IoT should enjoy high computational efficiency, because the mobile terminals have weak computing power. Also, from the viewpoint of actual application, the proposed data transmission protocol should have wider universality and can be used in multiple scenarios of IoT. Therefore, to further address the above problems, we propose a general construction of a leakage-resilient data transmission protocol with multi-receiver from an identity-based hash proof system (IB-HPS) and identity-based signature (IBS) scheme. For our proposal, the unforgeability, anonymity, and confidentiality can be proved based on the security of the underlying cryptography tools. Compared with the existing protocols, our proposal has better performance, such as dynamic anonymity, leakage resilience, traceability, etc. Furthermore, to guarantee the highest levels of security and efficiency, we have developed a novel IB-HPS construction that offers continuous leakage resilience and perfect key updates. Alongside this, our new leakage-resilient IBS scheme delivers the computational efficiency essential for practical deployment in IoT networks, ensuring that security enhancements do not come at the expense of performance. Both performance analysis and security analysis show that our data transmission protocol is secure, efficient, and highly practical. Yanwei Zhou, Zirui Qiao, Bo Yang 0003, Zhe Xia, Mingwu Zhang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | CLR-IA: An Efficient Identity Authentication Protocol With Continuous Leakage Resilience for Mobile Edge Computing
Yanwei Zhou, Yasi Zhu, Zirui Qiao, Xianxiang Liu, Guangjin Zhang, Bo Yang 0003, Tianqing Zhu, Mingwu Zhang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | MRDT: An Enhanced Multireceiver Secure Data Transmission Protocol for WBANsabstractWireless Body Area Networks (WBANs) have gained significant attention due to their numerous advantages in healthcare monitoring and applications. However, WBANs also face challenges related to data transmission security and privacy protection. Many researchers have proposed solutions to address these issues, but most of them are based on one-to-one communication models, which suffer from security vulnerabilities. Hence, we first review the previous protocol and show potential attack scenarios. Building upon their work, we propose an enhanced certificateless multi-receiver secure data transmission protocol for WBANs. Our proposal addresses security concerns and improves the efficiency and practicality of data transmission in WBANs. The security analysis and performance evaluation demonstrate that the proposed protocol achieves higher security levels, increases efficiency, and enhances practicality compared to existing approaches. Furthermore, our protocol provides a reliable framework for secure data transmission in WBANs, ensuring the privacy of users and maintaining the integrity and confidentiality of sensitive medical information. Zirui Qiao, Yanwei Zhou, Yong Yu 0002, Dong Zheng 0001 |
IEEE Internet Things J. | 1 |
| 2025 | A Provably Secure Certificateless Signature Scheme With Anonymity for Healthcare IIoTabstractThe Industrial Internet of Things (IIoT) is changing our way of life and work. As the number of mobile devices connected to IIoT increases, users will face many security challenges, such as insecure communication environments. The certificateless signature (CLS) scheme can ensure the integrity and validity of data and provide secure identity authentication for the IIoT, and several pairing-free CLS schemes have been proposed in recent years. However, we find they are vulnerable to the signature forgery attack of malicious key generation centers by safety analysis, which does not realize the security they have claimed. To solve this problem, we show an improved CLS scheme that achieves anonymity and formally proves its security under the hardness of the discrete logarithm problem in the random oracle. Comprehensive performance analysis and comparison show that our scheme has less communication and computation costs with higher security, and our construction is suitable for scenarios with limited resources. Finally, we apply this scheme to construct a mutual identity authentication protocol in the healthcare IIoT environment. Zirui Qiao, Ran Xu 0012, Yanwei Zhou, Bo Yang 0003, Tianqing Zhu, Mingwu Zhang |
IEEE Internet Things J. | 1 |
| 2025 | A continuous leakage-resilient CCA secure identity-based key encapsulation mechanism in the standard model
Zirui Qiao, Yasi Zhu, Yanwei Zhou, Bo Yang 0003 |
J. Syst. Archit. | 1 |
| 2025 | DADD: Direct Authentication With Vehicles From Different DomainsabstractAs Vehicular Ad hoc Networks (VANETs) become integrated into daily life, drivers can conveniently transmit messages to other vehicles. However, since most messages are sent over public channels, they are vulnerable to leakage and tampering, posing risks to user privacy and security. A secure authentication scheme is essential to ensure message authenticity and integrity. Vehicles frequently cross multiple domains while driving, but existing schemes mainly support authentication within a single domain, making it difficult for vehicles from different domains to establish trusted connections. Moreover, many current approaches rely heavily on bilinear pairings, reducing efficiency and increasing communication overhead. To address these issues, we propose an efficient cross-domain authentication scheme for VANETs. Our scheme uses pseudonyms to protect vehicle privacy and allows vehicles to directly authenticate with entities from other domains without relying on a trusted authority, enabling the establishment of a secure session key. We verified the security of our protocol using ProVerif and evaluated its performance with JPBC, a Java-based cryptographic library. Results show that our approach outperforms existing methods and is well-suited for high-traffic, densely populated, and resource-constrained VANET environments. Zirui Qiao, Yasi Zhu, Yanwei Zhou, Xianxiang Liu, Bo Yang 0003 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2025 | Broadcast Authentication: An Efficient Identity Authentication Protocol With Provable Security for VANETsabstractWith the advancement of the Internet of Things (IOT), Vehicular Ad Hoc networks (VANETs) are integrated into intelligent transportation systems to facilitate vehicle communication. However, as the number of vehicles and application diversity increase, significant security concerns have emerged, including message authentication and vehicle privacy protection. Consequently, researchers have devised several identity authentication protocols to ensure legitimate communication between parties. Nevertheless, existing schemes fail to address real-time response identity authentication due to high-speed vehicle movement and the need for traversing multiple domains. This limitation poses challenges in traffic management and even threatens human life. To overcome these issues, we propose a novel identity authentication method called broadcast authentication and design a new protocol incorporating this approach. The confidentiality and unforgeability of our proposal are proven based on classic hardness assumptions. Our protocol enables vehicles to authenticate with multiple roadside units through a single request communication process, thereby avoiding delays in authentication while saving costs associated with communication and computation. Compared with existing schemes, our protocol demonstrates superior computing efficiency and performance. Yanwei Zhou, Yasi Zhu, Zirui Qiao, Chuanyuan Zhao |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2024 | A New Construction of Leakage-Resilient Identity-Based Encryption Scheme
Zirui Qiao, Ran Xu 0012, Yonghui Lu, Yanwei Zhou, Bo Yang 0003 |
ISPEC | 1 |
| 2024 | An Anonymous and Efficient Certificate-Based Identity Authentication Protocol for VANETabstractIn recent years, the development of Internet of Things technology has led to a surge in interest in the vehicular ad hoc network (VANET), which has greatly improved travel efficiency and facilitated vehicle data sharing. To ensure the privacy and security of both vehicles and personnel, researchers have proposed various measures for securing VANET systems. Recently, certificate-based aggregate signature (CBAS) schemes have been proposed to design an identity authentication protocol for the VANET to prevent tampering and corruption of private vehicle data. In this study, we conduct a security analysis of the previous CBAS scheme by presenting a security attack. Afterward, we propose a novel and concrete construction of the CBAS scheme that offers improved performance for VANET, which can enhance protection in the VANET scenario. We also demonstrate its security based on standard cryptographic assumptions. Comparative results from theoretical analysis and experimental evaluation illustrate the practicality of our proposed scheme. Similarly, the identity authentication protocol created based on the above CBAS scheme has the properties of dynamic anonymity, mutual identity authentication, unforgeability. Zirui Qiao, Yanwei Zhou, Qiliang Yang, Zhe Xia, Bo Yang 0003, Mingwu Zhang |
IEEE Internet Things J. | 1 |
| 2023 | A Novel Construction Of Certificateless Aggregate Signature Scheme For Healthcare Wireless Medical Sensor NetworksabstractAbstract To ensure privacy and security of healthcare wireless medical sensor networks (HWMSNs), several concrete constructions of efficient certificateless aggregate signature (CLAS) scheme without bilinear pairing were proposed in the last few years. However, many previous constructions of CLAS scheme were found to be impractical, which either fail to meet the claimed security or contain design flaws. For example, in some of the previous proposals, any adversary can forge a valid signature on any new message. In this paper, we first demonstrate some security issues and design flaws in the previous proposals of CLAS scheme. As follows, to further address the above deficiencies, a new construction of CLAS scheme with improved security is presented, and the formal security proof is given using Forking Lemma in the random oracle model, assuming that the discrete logarithm problem is hard. Compared with the previous CLAS schemes, our construction has similar computational costs, and it provides better security guarantees. Therefore, compared with the existing solutions, our proposal with strong security and high computational efficiency is more suitable for use in HWMSNs. Zirui Qiao, Qiliang Yang, Yanwei Zhou, Bo Yang 0003, Mingwu Zhang |
Comput. J. | 1 |
| 2023 | Identity-Based Encryption With Continuous Leakage-Resilient CCA Security From Static Complexity AssumptionabstractAbstract Although a large number of provably secure cryptographic primitives have been proposed in the literature, many of these schemes might be broken in practice because of various leakage attacks. Therefore, the leakage resilience should be considered in designing these primitives. However, in identity-based cryptography, most of the existing leakage-resilient identity-based encryption (IBE) schemes suffer some limitations: they either resist the leakage attacks in the selective identity security model or achieve the chosen-ciphertext attack (CCA) security based on a non-static assumption. In this paper, an IBE scheme with adaptive leakage-resilient CCA security is proposed, and its security is rigorously proved in the random oracle model under a classic static complexity assumption, e.g. decisional bilinear Diffie–Hellman assumption. In our construction, all elements of ciphertext are randomly distributed in the adversary’s view. Hence, the adversary cannot obtain any useful information of the user’s private key from the given ciphertexts. Moreover, a unique property of our construction is that the leakage parameter is independent of the plaintext space, which contributes a better leakage rate. Yanwei Zhou, Zirui Qiao, Bo Yang 0003, Yi Mu 0001, Mingwu Zhang |
Comput. J. | 3 |
| 2023 | Leakage-resilient identity-based cryptography from minimal assumptions
Yanwei Zhou, Bo Yang 0003, Zirui Qiao, Zhe Xia, Mingwu Zhang, Yi Mu 0001 |
Des. Codes Cryptogr. | 3 |
| 2023 | An Anonymous and Revocable Authentication Protocol for Vehicle-to-Vehicle CommunicationsabstractIn the vehicular ad hoc network (VANET), the communication between the vehicle and other nodes is performed in an open channel, which puts forward the requirements for its privacy security and message integrity. Most previous protocols either frequently verify identities before accepting traffic information or do not involve identity revocation mechanisms, and they may assume that third parties are fully trusted. To further solve the above problem, a certificateless-based anonymous and revocable authentication protocol for vehicle-to-vehicle communications is proposed in this article. Our construction separates the identity authentication process from the traffic message verification, which not only avoids the disadvantage of a frequent identity revocation list (IRL) checking but also reduces the overhead in communication and message authentication. These features can make “identity authentication once, broadcast efficiency” really happen. In addition, since our authentication process is based on certificateless signature, it can resist malicious key generation centers (KGCs) and road-side units (RSUs), which is very necessary for privacy-sensitive application scenarios. Finally, the performance analyses show that our proposal is superior to the existing schemes in terms of authentication speed and communication overhead. Yanwei Zhou, Zirui Qiao, Bo Yang 0003, Yuan Xu 0032, Mingwu Zhang |
IEEE Internet Things J. | 3 |
| 2023 | An Efficient Identity Authentication Scheme With Dynamic Anonymity for VANETsabstractNowadays, as an essential technique for intelligent transportation, vehicular ad hoc networks (VANETs) has significantly improved people’s travel experience, providing richer, and smarter services for vehicles while ensuring driver safety. However, considering that VANETs are complex, some security challenges still remain, including but not restricted to privacy preserving of vehicles, authentication of messages, limited resources in computational power, and network bandwidth. To address these issues, many privacy-preserving identity authentication schemes for VANETs have been proposed recently. However, these schemes still suffer some limitations. First, their computational overheads are heavy due to the complex calculations. Second, some schemes are vulnerable to various security weaknesses, unable to resist normal attacks. Third, in some schemes, the same pseudonym keeps unchanged and it is linked to the corresponding private key of user. The consequence is that if the user wants to change its pseudonym, the corresponding private key must be changed. In order to further solve the above problems, we propose a novel privacy-preserving identity authentication protocol based on the certificateless aggregate signature scheme, allowing the user to generate a fuzzy identity to hide her real identity, and the private key can be kept unchanged even if the corresponding pseudonym is updated. Furthermore, to achieve efficiency in computation, bilinear mapping is avoided in our proposed scheme. We prove that our protocol satisfies unforgeability in the random oracle based on a classic complexity assumption. Finally, the security and efficiency analyses demonstrate that our construction enjoys more security features and better performance compared with the existing schemes. Yanwei Zhou, Zirui Qiao, Zhe Xia, Bo Yang 0003, Mingwu Zhang, Wenzheng Zhang 0001 |
IEEE Internet Things J. | 3 |
| 2023 | An Efficient and Provably Secure Identity Authentication Scheme for VANETabstractIn recent years, many researchers have applied aggregated signature techniques to resource-constrained vehicular ad hoc networks (VANETs) authentication scenarios. We reviewed two recent VANET authentication schemes based on certificateless aggregated signatures (CLASs) while demonstrating that neither of them is resistant to public key replacement attacks under their security models. An eavesdropper can successfully forge a legitimate signature to perform malicious operation. To further address the above security flaws, we propose an improved CLAS scheme for VANET. Considering that some researchers have briefly or even incorrectly used forking lemmas in their security proofs to prove an insecure CLAS scheme, we further improve and refine the security model and security proof method for CLAS, which make the proof process transparent by using general forking lemma. Based on these improvements, our scheme can resist attacks from two types of adversaries in the CLAS security model. In the final performance analysis, the improved CLAS scheme outperforms the secure-related scheme of recent years in terms of both computational and communication efficiency. Therefore, our proposal is more suitable for resource-constrained VANET environments. Yanwei Zhou, Zirui Qiao, Bo Yang 0003, Mingwu Zhang |
IEEE Internet Things J. | 3 |
| 2023 | An Anonymous and Efficient Multimessage and Multireceiver Certificateless Signcryption Scheme for VANETabstractIn future intelligent transportation systems, vehicular ad hoc network (VANET) is a popular application. They provide early warning of dangers through wireless communication to improve road safety. Therefore, we should protect messages from leakage and changes during transmission. To ensure the security issues in the communication process, we propose a secure and effective certificateless signcryption scheme with multiple messages and multiple receivers and prove its confidentiality and unforgeability based on the hardness of the discrete logarithm problem and the computational Diffie Hellman problem. Our scheme implements the signature and encryption of multiple messages for different receivers and achieves anonymity for the receiver. Based on our signcryption scheme, we design an identity authentication and key agreement protocol applying the construction in VANET. In addition, we also point out that through comprehensive performance analysis, our proposal has higher security and efficiency of computation and communication compared to other signcryption constructions. Yanwei Zhou, Ran Xu 0012, Zirui Qiao, Bo Yang 0003, Zhe Xia, Mingwu Zhang |
IEEE Internet Things J. | 3 |
| 2023 | Quorum controlled homomorphic re-encryption for privacy preserving computations in the cloud
Zhe Xia, Qiliang Yang, Zirui Qiao |
Inf. Sci. | 3 |
| 2023 | A redesigned secure and efficient data transaction protocol for mobile payment system
Zirui Qiao, Qiliang Yang, Yanwei Zhou, Bo Yang 0003, Mingwu Zhang |
J. Syst. Archit. | 1 |
| 2022 | Continuous Leakage-Amplified Public-Key Encryption With CCA SecurityabstractAbstract Secret key leakage has become a security threat in computer systems, and it is crucial that cryptographic schemes should resist various leakage attacks, including the continuous leakage attacks. In the literature, some research progresses have been made in designing leakage resistant cryptographic primitives, but there are still some remaining issues unsolved, e.g. the upper bound of the permitted leakage is fixed. In actual applications, the leakage requirements may vary; thus, the leakage parameter with fixed size is not sufficient against various leakage attacks. In this paper, we introduce some novel idea of designing a continuous leakage-amplified public-key encryption scheme with security against chosen-ciphertext attacks. In our construction, the leakage parameter can have an arbitrary length, i.e. the length of the permitted leakage can be flexibly adjusted according to the specific leakage requirements. The security of our proposed scheme is formally proved based on the classic decisional Diffie–Hellman assumption. Wenzheng Zhang 0001, Zirui Qiao, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang |
Comput. J. | 2 |
| 2022 | An Efficient Verifiable Searchable Encryption Scheme With Aggregating Authorization for Blockchain-Enabled IoTabstractBlockchain-enabled Internet of Things (IoT) provides a secure sharing of data and resources to the various miners of the IoT network, removes centralized control, and can overcome part of the existing challenges in traditional IoT. However, the IoT ecosystem faces some great challenges in terms of security, such as privacy leaking, eavesdropping, and so on, which seriously impede the deployment of the IoT ecosystem. Verifiable searchable encryption (SE) can make data owners (DOs) in the IoT dispel concerns about privacy and make data users (DUs) believe they get correct search results. For the blockchain-enabled IoT, this article proposes an efficient verification SE scheme with aggregation authorization and trusted revocation. With this scheme, DOs are willing to share their data to DUs for reward in a secure, efficient, and trusted way. For the DU, the DO can generate an aggregating key of a subset of encrypted documents, and then the DU has the privilege to search these documents and to verify the search results. By utilizing the trusted execution environment, the DO can revoke the search privilege of the DU. We present the analysis to show our proposed scheme achieves confidentiality, soundness, and fair payment at the same time. With the performance evaluations, we prove our proposal practical for blockchain-enabled IoT in terms of computational and smart contracts overhead. Tao Wang 0039, Qiliang Yang, Bo Yang 0003, Zirui Qiao |
IEEE Internet Things J. | 7 |
| 2021 | Novel Public-Key Encryption with Continuous Leakage AmplificationabstractAbstract Leakage of private information, such as the secret keys, has become a threat to the security of computing systems. It has become a common requirement that cryptographic schemes should withstand various leakage attacks, including the continuous leakage attacks. Although some research progresses have been made toward this area, there are still some unsolved issues. In the literature, the public-key encryption (PKE) constructions with (continuous) leakage resilience normally require the upper bound of leakage to be fixed. However, in many real-world applications, this requirement cannot provide sufficient protection against leakage attacks. In order to mitigate these problems, this paper demonstrates how to design a leakage amplified PKE scheme with continuous leakage resilience and chosen-plaintext attacks security. In our proposed PKE scheme, the leakage parameter can have an arbitrary length. Moreover, the length of permitted leakage in our scheme can be flexibly adjusted according to the leakage requirements of application environment. Its security is formally proved under the classic static assumption. Zirui Qiao, Qiliang Yang, Yanwei Zhou, Zhe Xia, Mingwu Zhang |
Comput. J. | 1 |
| 2021 | Blockchain-based searchable encryption with efficient result verification and fair payment
Tao Wang 0039, Zirui Qiao, Bo Yang 0003, Yueyang Gong, Guoyong Qiu |
J. Inf. Secur. Appl. | 3 |
| 2021 | Continuous leakage-resilient certificate-based signcryption scheme and application in cloud computing
Yanwei Zhou, Yuan Xu 0032, Zirui Qiao, Bo Yang 0003, Mingwu Zhang |
Theor. Comput. Sci. | 3 |
| 2021 | PrivCrowd: A Secure Blockchain-Based Crowdsourcing Framework with Fine-Grained Worker SelectionabstractBlockchain‐based crowdsourcing systems can mitigate some known limitations of the centralized crowdsourcing platform, such as single point of failure and Sybil attacks. However, blockchain‐based crowdsourcing systems still endure the issues of privacy and security. Participants’ sensitive information (e.g., identity, address, and expertise) have the risk of privacy disclosure. Sensitive crowdsourcing tasks such as location‐based data collection and labeling images including faces also need privacy‐preserving. Moreover, current work fails to balance the anonymity and public auditing of workers. In this paper, we present a secure blockchain‐based crowdsourcing framework with fine‐grained worker selection, named PrivCrowd which exploits a functional encryption scheme to protect the data privacy of tasks and to select workers by matching the attributes. In PrivCrowd, requesters and workers can achieve both exchange and evaluation fairness by calling smart contracts. Solutions collection also can be done in a secure, sound, and noninteractive way. Experiment results show the feasibility, usability, and efficiency of PrivCrowd. Qiliang Yang, Tao Wang 0039, Bo Yang 0003, Yong Yu 0002, Zirui Qiao |
Wirel. Commun. Mob. Comput. | 8 |