Fengqun Wang

dblp:300/9936 · DBLP profile ↗
← Back
15ranked-venue papers
5as first author
15since 2021 · last 2026
0000-0003-2465-7982ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 2 first-author · 6 since 2021Computer networks · 5 · 2 first-author · 5 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A large-language-model-guided progressive error-correction framework for structured process modeling
Ruilong Xu, Huan Fang 0001, Fengqun Wang, Chenbin Zhao
Expert Syst. Appl.4
2026 Runtime Threshold Signature-Based Unmanned Aerial Vehicle Swarm Authentication With Autonomous Splitting Support
abstract
Recently, unmanned aerial vehicles (UAVs) have undergone rapid development, demonstrating significant potential in various fields, including logistics, military operations, and entertainment. By collaborating to form swarms, UAVs can undertake more complex tasks such as mapping and disaster relief. To address the limited flexibility of UAV swarm identity authentication and the requirement for swarm splitting during task execution, we propose a runtime threshold signature (RTS) scheme. Unlike traditional threshold signatures, RTS defers the selection of the threshold from the initialization phase to the signing phase, allowing verifiers to dynamically adjust the threshold as required, thus achieving an effective balance between efficiency and security. Moreover, the RTS has the same signature size as the Schnorr signature, which is a non-interactive threshold signature. Building on the RTS primitive, we designed a novel identity authentication scheme that supports the autonomous splitting of UAV swarms. This scheme enables secure swarm-level identity authentication while adapting naturally to dynamic swarm restructuring. Furthermore, we demonstrate that the proposed scheme satisfies unforgeability under the t-VCDH assumption. To evaluate its performance, we implemented our scheme in C++ on AmovLab Prometheus 600 (P600) UAVs and assessed it under varying network latency and bandwidth conditions. Comparative results with existing schemes demonstrate that our approach achieves lower computational overhead and high practical applicability. Notably, even with the threshold set to 128, the authentication process takes only 2.6 ms per UAV.
Mingwei Zeng, Hong Zhong 0001, Qingyang Zhang 0001, Fengqun Wang, Jiaxin Li 0001, Jie Cui 0004
IEEE Trans. Dependable Secur. Comput.4
2026 MPDA-HPR: Multi-Dimensional Privacy-Preserving Data Aggregation Based on Homomorphic Proxy Re-Encryption for Industrial Internet of Things
abstract
As modern communication technologies advance, the Industrial Internet of Things (IIoT) is progressively evolving towards greater intelligence. The extensive implementation of smart grids has significantly affected IIoT factories. Data aggregation is commonly used to protect the factory's privacy. However, existing multi-dimensional data aggregation schemes lack flexibility and are vulnerable to internal attacks, where private data from certain smart devices may be decrypted by insiders. Moreover, replacing related devices necessitates updating the keys of the entire system, which incurs heavy overhead. To address these issues, a multi-dimensional privacy-preserving data aggregation scheme based on homomorphic proxy re-encryption (MPDA-HPR) is proposed. Using a modified Paillier encryption algorithm supported by proxy re-encryption and super-increasing sequences, the proposed scheme enhances flexibility and scalability. Security analyses demonstrate that the proposed scheme can withstand various security threats and effectively preserve the privacy of devices. Finally, the prototype is implemented and evaluated, demonstrating that the proposed scheme is robust, efficient, and feature-rich.
Qingyang Zhang 0001, Jie Cui 0004, Hulin Jin, Fengqun Wang, Debiao He
IEEE Trans. Dependable Secur. Comput.5
2026 Anonymous Integrity Auditing Scheme Based on Trusted Execution Environment for Distributed Edge Computing
abstract
Multi-replica data storage is widely adopted in edge computing to improve both data availability and access efficiency for latency-sensitive applications. Integrity auditing is a critical mechanism for ensuring data reliability in this distributed setting. However, existing schemes face a trade-off between security and efficiency: ensuring replica authenticity typically requires users to generate unique tags for all copies, creating a bottleneck for resource-constrained devices. Delegation schemes reduce this burden but struggle to prevent collusion or on-the-fly generation attacks. Therefore, this study proposes ATRIA to resolve this dilemma. Uniquely, ATRIA leverages the Trusted Execution Environments (TEEs) not only for isolation but to securely offload the intensive replica tag generation from the user, ensuring authentic physical storage with minimal user overhead. By leveraging the hardware isolation of the TEEs, this mechanism ensures authentic physical storage and protects against on-the-fly and collusion attacks. In addition, the scheme incorporates a privacy-preserving identity management solution that balances anonymity and traceability. It employs a traceable anonymous identity mechanism whereby users interact via pseudonyms, hiding their real identities while allowing a trusted Key Generation Center (KGC) to perform identity tracing only when authorized. Our security analysis demonstrates that the proposed scheme achieves its security objectives and resists various attacks. Furthermore, a comprehensive performance evaluation demonstrates that ATRIA outperforms related schemes in terms of computational overhead.
Qingyang Zhang 0001, Jie Cui 0004, Fengqun Wang, Jiaxin Li 0001, Hong Zhong 0001
IEEE Trans. Dependable Secur. Comput.4
2026 Distributed Multi-Attribute Anonymous Certificate Management Scheme With Fine-Grained Revocation for Uncrewed Aerial Vehicles
abstract
In unmanned aerial vehicle (UAV) scenarios, the execution of specific flight missions requires anonymous certificates containing multiple attributes as proof of authorization. However, existing certificate- management schemes are ineffective in achieving an optimal trade-off between verification overhead and attribute-level revocation. First, most existing schemes bind multiple attributes to a single certificate but typically lack the capability of fine-grained revocation at the individual attribute level. Second, most existing schemes rely on centralized certificate authorities, necessitating UAVs to apply for certificates from multiple regions separately when performing cross-regional access. This scenario increases the certificate management burden. To address these challenges, this paper proposes a distributed multiattribute anonymous certificate management scheme for UAVs. First, the proposed scheme integrates redactable signatures and dynamic accumulators, enabling the selective disclosure and fine-grained revocation of attributes within a single certificate. Second, the proposed scheme utilizes a distributed key-generation mechanism, enabling decentralized certificate issuance and secure management.
Qingyang Zhang 0001, Hong Zhong 0001, Fengqun Wang, Mingwei Zeng, Jie Cui 0004
IEEE Trans. Dependable Secur. Comput.4
2026 Distributed and Autonomous Group Management Supporting Group Fusion for UAVs
abstract
With increasingly complex tasks, cooperation among multiple unmanned aerial vehicle (UAV) groups has become more significant. However, in complex operational environments, UAVs may operate outside the communication coverage of the trusted authority (TA), making continuous online TA services unavailable. Under such circumstances, most existing group management methods have difficulty achieving group fusion and cannot flexibly update post-fusion member certificates. Therefore, we propose an autonomous UAV group management scheme based on mobile proactive secret sharing. First, the scheme achieves autonomous group fusion by updating the subsecrets of UAVs. Second, without the participation of a TA, the scheme supports the dynamic self-updating of certificates, ensuring secure communication in the new group and continuous availability of certificates. Security proofs and analyses show that the proposed scheme is secure under the random oracle model and can resist several common attacks. The experimental results demonstrate that the proposed scheme outperforms related schemes in computational performance and is suitable for secure and efficient UAV group management scenarios.
Fengqun Wang, Manting Gan, Hong Zhong 0001, Qingyang Zhang 0001, Jie Cui 0004, Debiao He
IEEE Trans. Mob. Comput.1
2026 Forward Secure Data Sharing Based on Proxy Re-Encryption in Industrial Internet of Things
abstract
In the Industrial Internet of Things (IIoT), data is shared among different production segments for collaborative production. However, industrial production processes often involve corpus sensitive information, and during data sharing, every flow of data between different subjects increases its exposure to vulnerabilities. Proxy re-encryption offers a practical approach to enabling secure data exchange, thereby partially mitigating the tension between information sharing and privacy protection. Many scholars have proposed data-sharing schemes utilizing proxy re-encryption technologies. However, existing schemes still face issues, such as excessive communication and computational overhead, and cannot guarantee forward security. Therefore, this study proposes a lightweight and forward-secure data-sharing scheme. First, the proxy generates the re-encryption key, substantially alleviating the overhead on the data owner. Second, whenever the time node changes or a data user is revoked, the data user loses access to historical data, which effectively ensures forward security. The security proof confirms the scheme’s IND-CPA security under the DBDH assumption. Performance analyses reveals that the proposed scheme achieves higher security in data sharing with a lower computational overhead.
Qingyang Zhang 0001, Siqi Fu, Jie Cui 0004, Fengqun Wang, Jiaxin Li 0001, Hong Zhong 0001
IEEE Trans. Netw. Serv. Manag.4
2025 A Secure Anonymous Authentication and Key Agreement Scheme for UAV Swarms in Emergency Rescue Environments
abstract
To achieve secure communication in unmanned aerial vehicle (UAV) swarms during emergency rescue operations, A wide range of authentication key agreement (AKA) schemes has emerged in recent research. However, these schemes generally face three critical limitations. First, UAVs may struggle to maintain persistent communication with the trusted authority in complex environments, and efficient authentication cannot be guaranteed when the TA is offline. Second, most existing schemes lack traceability, preventing the TA from revealing the true identity of malicious UAVs. Finally, UAVs are constrained by limited computational and communication resources. So we propose an AKA scheme that enables secure communication between the UAV and BS. Specifically, proposed scheme eliminates reliance on a trusted authority during the AKA phase, while still ensuring the establishment of a secure communication channel. In addition, by combining the Chinese remainder theorem with the chameleon hash function, the scheme not only enables mutual authentication between UAVs and base stations but also enhances overall computational efficiency in complex environments. Formal security analysis and rigorous proof indicate this design upholds various protective attributes and effectively withstands diverse known attacks. Finally, experimental evaluations validate efficiency and practicality about proposed scheme in some environments.
Fengqun Wang, Hang Hai, Jie Cui 0004, Wuquan Wen, Qingyang Zhang 0001, Hong Zhong 0001
ICPADS1
2025 Conditional Privacy-Preserving Transaction for the Unspent Transaction Output-Based Multi-Chain Blockchain System
abstract
The anonymity of blockchain may be exploited by criminals for illegal fund transfers, thus a conditional privacy-preserving scheme is important for blockchain regulation. Currently, sharding technology under a multi-chain architecture is used to improve blockchain scalability. However, current conditional privacy-preserving schemes cannot work on this architecture. To protect the privacy of the transaction, we present a conditional privacy-preserving transaction scheme (MC-CPPT) for multi-chain blockchain system. In this system, we proposed a zero-knowledge proof based anonymous transaction, in terms of the identities of transaction participants and amounts, which also enables the unlinkability of transactions and indistinguishability between cross-chain and intra-chain transactions in multi-chain blockchain system. In addition, a multi-node regulatory agency is introduced to control the transaction amount and frequency in the system without a single point of failure. Moreover, an ECC-based encryption scheme is proposed to achieve the traceability of suspicious transactions. A security model is defined and the security of MC-CPPT is demonstrated to meet the expected security goals. Evaluating the prototype revealed acceptable performance and additional security features.
Jie Cui 0004, Wenting Zhuang, Hong Zhong 0001, Qingyang Zhang 0001, Fengqun Wang, Debiao He
IEEE Trans. Computers5
2025 Blockchain-Based Privacy-Preserving Deduplication and Integrity Auditing in Cloud Storage
abstract
Ensuring cloud data security and reducing cloud storage costs have become particularly important. Many schemes expose user file ownership privacy when deduplicating authentication tags and during integrity auditing. Moreover, key management becomes more difficult as the number of files increases. Also, many audit schemes rely on third-party auditors (TPAs), but finding a fully trustworthy TPA is challenging. Therefore, we propose a blockchain-based integrity audit scheme supporting data deduplication. It protects file tag privacy during deduplication of ciphertexts and authentication tags, safeguards audit proof privacy, and effectively protects user file ownership privacy. To reduce key management costs, we introduce identity-based broadcast encryption (IBBE) that does not require interaction with key servers, eliminating additional communication costs. Additionally, we use smart contracts for integrity auditing, eliminating the need for a fully trusted TPA. We evaluate the proposed scheme through security and theoretical analyses and a series of experiments, demonstrating its efficiency and practicality.
Qingyang Zhang 0001, Shuai Qian, Jie Cui 0004, Hong Zhong 0001, Fengqun Wang, Debiao He
IEEE Trans. Computers5
2024 Verifiable Data Sharing Based on Autonomous Path Proxy Re-Encryption for Industrial Internet of Things
abstract
In the Industrial Internet of Things (IIoT), massive amounts of data are generated and shared among different industrial entities, and it is crucial to realize the security and flexibility of data sharing. Autonomous path proxy re-encryption technology enables the autonomous creation of an ordered data-sharing path as specified by the data owner, supporting multi-hop re-encryption. However, the security of this technology requires further enhancement. Therefore, we propose a verifiable data-sharing scheme. To prevent data leakage due to collusion between the proxy and users, we introduce blockchain technology to supervise the decryption behavior of users in the autonomous path. Second, we verify the proxy re-encryption computation, ensuring its validity. Finally, a security analysis demonstrates that the proposed scheme meets the security requirements. Furthermore, we evaluated the performance of the proposed scheme, and the results show that our scheme has only increased less overhead, but has enhanced security.
Jie Cui 0004, Xiaoxi Sun, Qingyang Zhang 0001, Fengqun Wang, Hong Zhong 0001
MSN4
2024 Lightweight and Secure Data Sharing Based on Proxy Re-Encryption for Blockchain-Enabled Industrial Internet of Things
abstract
In the Industrial Internet of Things (IIoT), data sharing is crucial for promoting the intelligent development of industrial production. To achieve effective data supervision, introducing blockchain into traditional cloud-based data-sharing frameworks has attracted widespread attention. However, existing blockchain-based data-sharing schemes still have issues with security and efficiency. Therefore, we propose a blockchain-enabled data-sharing scheme based on proxy re-encryption. First, the scheme considers both storage and access authentication, guaranteeing data sources’ trustworthiness and preventing data misuse. Second, the scheme uses an on-chain and off-chain cooperative storage mechanism, saving the storage resources of the blockchain. Third, the scheme supports data packing, which effectively improves data storage efficiency. The security analysis shows that our scheme satisfies the security requirements. Finally, we build a blockchain platform using the hyperledger fabric. The performance evaluation shows that our scheme is more advantageous regarding computational overhead than other related schemes.
Fengqun Wang, Jie Cui 0004, Qingyang Zhang 0001, Debiao He, Chengjie Gu, Hong Zhong 0001
IEEE Internet Things J.1
2024 Blockchain-Based Lightweight Message Authentication for Edge-Assisted Cross-Domain Industrial Internet of Things
abstract
In edge-assisted cross-domain Industrial Internet of Things (IIoT), blockchain-based authentication is an effective way to build cross-domain trust and secure cross-domain data. However, existing authentication schemes still have serious challenges in terms of efficiency and security. In this paper, we propose a blockchain-based lightweight message authentication scheme. First, to address efficiency challenges, we build a blockchain-enabled edge-assisted lightweight authentication framework. This framework uses edge servers to assist smart devices in achieving cross-domain authentication and effectively reduce redundant interactions between entities. Second, to resolve the security challenges, we design a lightweight message authentication algorithm for cross-domain IIoT. The algorithm guarantees message security with low computational overhead and is suitable for multi-receiver cross-domain IIoT. The security proof and analysis demonstrate that the proposed scheme is secure under the random oracle model and can resist various attacks. The performance evaluation shows that our proposed scheme is superior in terms of computation and communication overhead when compared with other related schemes.
Fengqun Wang, Jie Cui 0004, Qingyang Zhang 0001, Debiao He, Chengjie Gu, Hong Zhong 0001
IEEE Trans. Dependable Secur. Comput.1
2024 Blockchain-Based Secure Cross-Domain Data Sharing for Edge-Assisted Industrial Internet of Things
abstract
In the Industrial Internet of Things (IIoT), blockchain-based data-sharing frameworks can effectively build cross-domain trust and facilitate data sharing. However, secure data-sharing schemes are lacking for the IIoT scenario, in which smart devices cannot communicate across domains and can only access data through edge servers. In this study, we propose a lightweight and secure data-sharing scheme for the blockchain-enabled cross-domain IIoT, in which authorized smart devices can access cross-domain data anonymously. First, smart devices can dynamically generate pseudonyms by themselves and without the online participation of domain authorization centers, effectively reducing the storage overhead of smart devices and the workload of domain authorization centers. Second, the scheme combines broadcast encryption and proxy re-encryption techniques, which realize flexible data sharing across domains while protecting the privacy of smart devices. Detailed security proofs and analyses demonstrate that the proposed scheme is secure and resistant to various attacks. The performance analysis shows that our proposed scheme is efficient and performs better than related schemes.
Fengqun Wang, Jie Cui 0004, Qingyang Zhang 0001, Debiao He, Hong Zhong 0001
IEEE Trans. Inf. Forensics Secur.1
2023 Efficient Batch Authentication Scheme Based on Edge Computing in IIoT
abstract
In the industrial Internet of Things (IIoT) environment (e.g., a smart factory), smart devices with limited computing power can bring large amounts of privacy-sensitive data into insecure networks when they interact. If a network attacker intercepts and tampers with this data, it may cause chaos in production and even paralyze the entire IIoT system. Therefore, to ensure the regular operation of intelligent production, data receivers must authenticate the data before using them. However, existing message authentication schemes in the IIoT environment authenticate each message individually, which creates many redundant operations. Hence, to ensure data security among smart devices and reduce the computational overhead of data processing, we propose a batch authentication scheme based on edge computing in IIoT. Specifically, we design a lightweight batch authentication algorithm and use edge servers to assist smart devices in authenticating data, thus reducing the computational burden on smart devices and improving the efficiency of message authentication. The security analysis shows that the proposed scheme is secure in the random oracle model and meets the series of security requirements of the IIoT. In addition, we illustrate the efficiency of the scheme through experiments.
Jie Cui 0004, Fengqun Wang, Qingyang Zhang 0001, Chengjie Gu, Hong Zhong 0001
IEEE Trans. Netw. Serv. Manag.2