Bidi Ying

dblp:30/5561 · DBLP profile ↗
← Back
16ranked-venue papers
8as first author
6since 2021 · last 2024
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 11 · 6 first-author · 5 since 2021Security and privacy · 1 · 1 since 2021Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2024 Collaborative and Verifiable VNF Management for Metaverse With Efficient Modular Designs
abstract
The metaverse is envisioned to create immersive and virtual worlds for people to experience interoperable 3D applications. However, the real-time, interactive, and multimedia characteristics of the metaverse applications require strict quality-of-service (QoS) on the underlying networking architecture, including high throughput, ultra-low delay, and human-centric service configurations. Network function virtualization (NFV)-enabled networking resource management can provide a promising solution to service-oriented QoS satisfaction for metaverse users. In this paper, we propose a blockchain-based collaborative and verifiable virtualized network function (VNF) management scheme for metaverse, named BVNF+. BVNF+ enables multiple network providers across different trust domains to abstract their services as VNFs and collaboratively manage end-to-end network slices for human-centric network services in metaverse. To address the design challenge of balancing the on-chain and off-chain overheads, we decouple the computations of VNF queries into modular components based on software and hardware verifiable computation (vc) approaches. Our modular strategy can achieve on/off-chain computation and communication efficiency while keeping low usage of the secure hardware. We conduct security analysis and extensive experiments based on a real-world blockchain testing network. The analysis and experimental results demonstrate that BVNF+ is both secure and efficient as compared with the existing works.
Cheng Huang 0001, Weihua Zhuang, Xuemin Shen, Bidi Ying
IEEE J. Sel. Areas Commun.6
2024 Data Protection: Privacy-Preserving Data Collection With Validation
abstract
The ubiquitous data collection has raised potential risks of leaking physical and private attribute information associated with individuals in a collected dataset. A data collector who wants to collect data for provisioning its machine learning (ML)-based services requires establishing a privacy-preserving data collection protocol for data owners. In this work, we design, implement, and evaluate a novel privacy-preserving data collection protocol. Specifically, we validate the functionality of the data collection protocol on behalf of data owners. First, the ML-based services are not always predefined, it is challenging for a data collector to combat inference of private attributes and user identity from the collected data while maintaining the utility of data. To address the challenge, we reconstruct the data by designing a data transformation model based on the autoencoder and clustering. Second, it is necessary to ensure that the reconstructed data satisfy certain privacy-preserving properties as untrusted data collectors can provide the data transformation models. Therefore, we utilize detection models and design an efficient enclave-based mechanism to validate that the reconstructed data's private attribute estimation probability is bounded by the predefined thresholds. Extensive experiments demonstrate our protocol's effectiveness, such as significantly reducing the accuracy of private attribute detection
Jiahui Hou, Cheng Huang 0001, Weihua Zhuang, Xuemin Shen, Rob Sun, Bidi Ying
IEEE Trans. Dependable Secur. Comput.7
2022 Secure and Flexible Data Sharing for Distributed Storage with Efficient Key Management
abstract
In this paper, we propose a Secure and Flexible Data Sharing (SFDS) scheme for distributed storage, where data owners can outsource their data to a distributed storage network and share the data with authorized users. To preserve confidentiality, all data are encrypted by data owners’ secret keys before being outsourced, and fine-grained access policies are enforced on the encrypted data (ciphertexts) to achieve flexible data sharing. Furthermore, based on the ciphertext puncturable encryption and the hierarchical identity-based encryption, we design an efficient key and ciphertext update mechanism, which enables data owners to update their secret keys and the corresponding ciphertexts periodically to deal with side-channel attacks and system vulnerabilities. Update tokens are constructed to directly derive new keys and ciphertexts. Through detailed security analysis, it is demonstrated that SFDS can achieve all three essential security properties, i.e., forward security, post-compromise security, and collusion attack resistance.
Cheng Huang 0001, Xuemin Shen, Weihua Zhuang, Rob Sun, Bidi Ying
ICC7
2022 Blockchain-Assisted Transparent Cross-Domain Authorization and Authentication for Smart City
abstract
Secure cross-domain authorization and authentication (AA) enable application service providers (ASPs) to allow users for resource access from different trusted domains. In this article, we propose a unified blockchain-assisted secure cross-domain AA framework for smart city, which can guarantee transparent cross-domain resource access while preserving user privacy. In the framework, ASPs can flexibly delegate their authentication capabilities to the blockchain, and users authorized by different ASPs can be authenticated by the blockchain where the authentication events are publicly audited and traced. Since the blockchain is publicly accessible, users’ sensitive identity attributes may be exposed during the authentication process. To address privacy leakage caused by the authentication events, several privacy-preserving techniques, including threshold-based homomorphic encryption, zero-knowledge proof, and random permutation, are exploited to hide users’ sensitive information on the blockchain. Moreover, to improve user revocation efficiency, we integrate a cryptographic accumulator and secure hash functions into the framework where ASPs are allowed to revoke their users through a global revocation contract. Our security analysis shows that the proposed framework can achieve all desirable security and privacy properties, and a proof-of-concept prototype has been developed to demonstrate the correctness and efficiency of the proposed framework.
Cheng Huang 0001, Xuemin Shen, Weihua Zhuang, Rob Sun, Bidi Ying
IEEE Internet Things J.7
2022 Blockchain-Based Data Sharing With Key Update for Future Networks
abstract
Future networks incorporate artificial intelligence to enable smart resource management and adaptive service provisioning. With a heterogeneous architecture and a large number of users in future networks, transparent and decentralized data sharing is required to promote data circulation and break data silos, for which blockchain is a potential solution to allow intelligent access permission control. However, it remains a challenging task to achieve flexible authorization management for blockchain-based data sharing and efficient key update for multi-users in case of key exposure. In this paper, we propose an intelligent blockchain-based data-sharing scheme with key update for future networks. First, we design a new encryption scheme, where keywords of data are extracted using machine learning algorithms that are published on the blockchain. Then, keywords of data and time validity are used to encrypt different types of data for flexible data authorization. Second, using hierarchical identity-based encryption, we construct an efficient key update mechanism, where update tokens are generated by invoking a smart contract deployed on the blockchain to facilitate key and ciphertext updates. We formally prove that the proposed scheme can guarantee three essential security properties: forward security, post-compromise security, and collusion attack resistance. On-chain and off-chain experiment results are provided to demonstrate that the proposed scheme can achieve computational and communication efficiency for key and ciphertext updates.
Cheng Huang 0001, Xuemin Shen, Weihua Zhuang, Rob Sun, Bidi Ying
IEEE J. Sel. Areas Commun.7
2022 Authenticated and Prunable Dictionary for Blockchain-Based VNF Management
abstract
Network function virtualization is a key enabling technology in future wireless networks for flexible and efficient sharing of network resources. Due to the increasing heterogeneity of network resource providers, a blockchain-based distributed architecture is a promising solution to enable reliable and transparent virtualized network function (VNF) management. However, since on-chain storage and computation are costive, it becomes a challenging task to achieve efficient VNF management with blockchain. In this paper, we first introduce a consortium blockchain for collaborative VNF management among network resource providers. Then, we propose an authenticated VNF dictionary that can be stored as a succinct authenticator on blockchain to support rich VNF query functionalities and efficient verifications of query results. Moreover, we design a dictionary pruning strategy to securely generate a compact authenticator for a given query, which reduces unnecessary memory accesses of the original dictionary when VNF queries are represented as arithmetic circuits. Finally, we conduct extensive experiments with a consortium blockchain network. The experimental results demonstrate that our pruning strategy is efficient for both on-chain and off-chain VNF management.
Cheng Huang 0001, Jiahui Hou, Xuemin Shen, Weihua Zhuang, Rob Sun, Bidi Ying
IEEE Trans. Wirel. Commun.8
2019 Privacy Protection for E-Health Systems using Three-Factor User Authentication
abstract
Since electronic health records transmitted in e-health systems are exposed to public networks, it is critical to protect patients' privacy health information. In our work, we provide an efficient and anonymous user authentication protocol to negotiate a session key for secure communications in public networks. Without using complex operations (e.g., scalar multiplication operations, pairing operations), our protocol can enhance performance efficiency. Performance analysis further illustrates that our protocol has a lower communication and computational overhead. Furthermore, a dynamic identity and a masked identity are provided to protect patient anonymity and patient untraceability. Besides, biometric information is hidden in a biohash function and a random number. Thus, all related to patient's privacy information is completely protected in our protocol. Security analysis shows that our protocol could resist impersonation attack, trace attack, off-line password guessing attack, replay attack.
Bidi Ying, Nada Radwan Mohsen, Amiya Nayak
ICC1
2019 Lightweight remote user authentication protocol for multi-server 5G networks using self-certified public key cryptography
Bidi Ying, Amiya Nayak
J. Netw. Comput. Appl.1
2018 ACP: An Efficient User Location Privacy Preserving Protocol for Opportunistic Mobile Social Networks
abstract
Users face location-privacy risks when accessing Location-Based Services (LBSs) in an Opportunistic Mobile Social Networks (OMSNs). In order to protect the original requester's identity and location, we propose a location privacy obfuscation protocols, called Appointment Card Protocol (ACP), utilizing social ties between users. To facilitate the obfuscation operations of queries, we introduce the concept called Appointment Card (AC). The original requesters can send their queries to the LBS directly using the information in the AC, ensuring that the original requester is not detected by the LBS. Also, a path for reply message is kept when the query is sent, to help reduce the time for replying queries. Simulation results show that our protocol preserves location privacy and has a higher query success ratio than its counterparts.
Yichao Lin, Bidi Ying, Amiya Nayak
COMPSAC (1)3
2018 Protecting location privacy in opportunistic mobile social networks
abstract
Users face location-privacy risks when accessing Location-Based Services (LBSs) in an Opportunistic Mobile Social Networks (OMSNs). In order to protect the original requester's identity and location, we propose a location- privacy obfuscation protocol Multi-Hop Location-Privacy Protection (MHLPP) protocol that utilizes social ties between users. To increase chances of completing obfuscation operations, users detect and make contacts with one-hop or multi-hop neighbor friends in social networks. Encrypted obfuscation queries avoid users learning important information except for the original requester who generates queries and trusted users, especially the original requester's identity and location. Simulation results show that our protocol can give a higher query success ratio compared to its existing counterpart.
Bidi Ying, Amiya Nayak
NOMS2
2015 Reputation-based Pseudonym Change for Location Privacy in vehicular networks
abstract
Location privacy is an important issue in vehicular networks since knowledge of a vehicle's location can result in leakage of sensitive information. A way to protect vehicles' location privacy is to have them change their pseudonyms in pre-determined regions known as mix-zones. However, selfish users may not change their pseudonyms because of the overhead occurring in this process. This could jeopardize the location privacy of those users who are in need of changing their pseudonyms. In order to encourage users to cooperate in changing their pseudonyms, we propose a method named Reputation-based Pseudonym Change for Location Privacy (RPCLP). With RPCLP, users earn reputation “credit” by implementing a change of pseudonym. Performance analysis shows that the RPCLP scheme not only motivates selfish users to cooperate with each other, but also reduces overhead while maintaining the desired location privacy.
Bidi Ying, Dimitrios Makrakis
ICC1
2015 Pseudonym Changes scheme based on Candidate-location-list in vehicular networks
abstract
A way to protect vehicles' location privacy under vehicular networks is to have them change their pseudonyms in pre-determined regions known as fixed mix-zones. However, pre-determined regions make pseudonym changes lack of flexibility. In this paper, we present a novel method named Pseudonym Changes based on Candidate-location-list (PCC). In PCC, a vehicle can form a mix-zone dynamically and change its pseudonym with the help of the candidate-location-list. We also provide the anonymity of our PCC and investigate it by simulations. Simulations based analysis show that our PCC has a good anonymity, low process time and high successful rate.
Bidi Ying, Dimitrios Makrakis
ICC1
2014 Efficient Authentication Protocol for Secure Vehicular Communications
abstract
Efficient authentication in the vehicular networks has been studied by several researchers in the past. However, there are still several issues to be addressed like high communication/ computation overhead, security problems, etc. In this paper, we propose an Efficient Authentication Protocol (EAP) for secure vehicular communication. This protocol employs smart cards based on users(vehicles)' passwords and identities to provide strong user authentication, and uses dynamic login identities to provide the anonymity of authentication. Performance analysis shows that this protocol does not only provide high efficient authentication, but also can resist attacks like offline password guessing attack, smart card loss attack, impersonation attack and so on.
Bidi Ying, Amiya Nayak
VTC Spring1
2013 Privacy preserving broadcast message authentication protocol for VANETs
Bidi Ying, Dimitrios Makrakis, Hussein T. Mouftah
J. Netw. Comput. Appl.1
2011 A Protocol for Sink Location Privacy Protection in Wireless Sensor Networks
abstract
Due to the broadcasting nature of wireless sensor networks, it is relatively easy for an adversary to discover the sinks' location through traffic volume analysis. Traditional encryption and authentication methods are not effective to preserve privacy of a sink's location from a global adversary, capably of monitoring the traffic activity of the network. In this paper, we propose the Sink Location Privacy Protection Protocol (SLPP), which in addition to been effective in achieving its design objective it is also easy to implement. In order to confuse a local or global adversary, each node generates fake messages, the number of which is dependent on the number of the node's children. Simulation results demonstrate clearly that the SLPP protocol can hide effectively the sink's location. However, what is important and interesting is that although transmission of fake messages consumes additional energy from nodes, the network's lifetime is not impacted.
Bidi Ying, Dimitrios Makrakis, Hussein T. Mouftah
GLOBECOM1
2010 Pre-broadcast based time efficient privacy protocol for secure vehicular communications
abstract
Privacy and security are two important issues in vehicular networks. Users wish to maintain location privacy and anonymity, meaning the identity, location/direction of move of their vehicles remains unknown to everybody with possible exception law enforcement authorities responsible by law to know and maintain such private information. In this paper, we propose a Pre-broadcast based Time Efficient Privacy (PTEP) scheme, which, instead of performing any asymmetric verification, uses Message Authentication Code (MAC) functionality and HASH operations to authenticate messages. Moreover, we use two-level key (upper-level hash chain and low-level hash chain) which assists avoiding message losses. Analysis shows that the proposed PTEP scheme superior performance in terms of packet loss rate and packet latency. In addition, it can be used to serve emergency and routine messages as well, while most of existing solutions can only work with routine messages.
Bidi Ying, Dimitrios Makrakis, Hussein T. Mouftah
WiMob1