VLDB 2026 Research / reviewers in the wild / expert
Jiguo Li 0001
dblp:33/31-1
· DBLP profile ↗
99ranked-venue papers
35as first author
51since 2021 · last 2026
0000-0002-6532-2081ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 30 · 10 first-author · 15 since 2021Computer networks · 17 · 4 first-author · 16 since 2021Databases, data management, data science and information retrieval · 15 · 6 first-author · 4 since 2021Systems, architecture and hardware · 10 · 4 first-author · 8 since 2021Software engineering, systems software and programming languages · 10 · 5 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 4 first-author · 3 since 2021Theory of computation · 4 · 1 first-authorArtificial intelligence and machine learning · 3 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Blockchain-Based Puncturable Attribute-Based Encryption Scheme With Policy Hiding for the Internet of ThingsabstractThe Internet of Things (IoT) has been widely adopted for its efficient data processing capabilities, but it also poses significant data security challenges. Attribute-Based Encryption (ABE) has attracted attention for enabling fine-grained, attribute-based access control. However, traditional ABE schemes fall short in revoking decryption privileges and protecting policy privacy, especially in scenarios where users’ private keys are exposed over a long period or sensitive access policies are at risk of leakage. To address these issues, this paper proposes an attribute-based encryption scheme that integrates puncturable encryption with policy hiding. In the proposed scheme, users can independently update their private keys without relying on the key distributor, and can revoke decryption capabilities of old keys by puncturing tags embedded in the ciphertext. This mechanism not only significantly reduces communication overhead between users and IoT devices but also ensures the security of previously generated data even if private keys are compromised. It simplifies key management and provides flexible forward security. Moreover, the scheme achieves full access policy hiding through attribute-mapping obfuscation and leverages the immutability of blockchain to ensure that users can verify the integrity of the policy before decryption, thereby further enhancing data privacy and system trustworthiness. We formally prove the scheme's security under the decisional bilinear Diffie-Hellman assumption. Finally, experimental results demonstrate that our scheme offers advantages in both storage overhead and computational efficiency. Yuyan Guo, Ziyao Peng, Jiguo Li 0001 |
IEEE Internet Things J. | 4 |
| 2026 | DKCIA-B: A dynamic keyword-based cloud data integrity auditing framework with backtracking support
Feng Wang 0020, Chenbin Zhao, Jiguo Li 0001, Hui Cui 0001 |
J. Netw. Comput. Appl. | 4 |
| 2026 | Attribute-Based Sanitizable Signature With Key-Exposure Resistance for Mobile Cloud Data
Jiguo Li 0001, Yichen Zhang 0003, Jian Shen 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | Three-Patterns-Protected Searchable Encryption Supporting Disjunctive Keyword SearchabstractSearchable encryption (SE) enables the client to execute keyword searches in encrypted data stored on the untrusted server and has been widely studied in cloud storage. To achieve higher efficiency and more functionalities, most SE schemes allowed the client to leak some information to the server. These leaked information are commonly referred to as leakage patterns. There are three important leakage patterns: search pattern, access pattern and volume pattern. Recent research has exploited at least one of these three patterns to attack SE schemes, resulting in the compromise of the confidentiality of encrypted data and queried keywords. Although existing SE schemes support conjunctive keyword search and protect these three patterns, these schemes do not support disjunctive keyword search and have a higher computational cost. In this paper, we use a private set union protocol based on additively symmetric homomorphic encryption to construct an SE scheme, which not only protects three patterns but also supports disjunctive keyword search. Specifically, we design an efficient token generation algorithm to protect the search pattern and a non-naive padding method to protect the volume pattern. Furthermore, we prove the correctness of our scheme through theoretical analysis and strictly prove the security under the leakage function. Finally, performance evaluation demonstrates that our scheme supports disjunctive keyword search while achieving a favorable trade-off between leakage protection and efficiency. Moreover, for components that exhibit relatively higher overhead during evaluation, we introduce optimization strategies that effectively enhance search efficiency and scalability. Jiguo Li 0001, Licheng Ji, Wuwei Weng, Yichen Zhang 0003, Yang Lu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | A Traceable and Revocable Ciphertext Policy Attribute-Based Encryption With Policy AuthenticationabstractWith the rapid advancement of cloud technology, ciphertext-policy attribute-based encryption (CP-ABE) schemes are highly suited to cloud storage environments. In order to protect sensitive information, policy-hidden CP-ABE has garnered significant attention. However, these schemes are vulnerable to fake policy attacks, where an attacker may introduce false policy and leak system information. To address this issue, we propose a traceable and revocable CP-ABE scheme with policy authentication (TR-PA-ABE). This scheme incorporates a policy checker, which is able to verify whether a ciphertext is encrypted under the correct access policy without revealing any confidential information. Additionally, it features a traceability mechanism that leverages white-box tracing to identify users who leak their keys by embedding user identities within their attribute keys. Our direct revocation method efficiently updates ciphertexts associated with revoked users without impacting the keys of other users, thus minimizing computing overhead. We formally prove that TR-PA-ABE is indistinguishable secure under chosen plaintext attacks (IND-CPA) based on the decision parallel$q$-bilinear Diffie-Hellman exponent assumption. Furthermore, our performance evaluation illustrates the practicality and efficiency of TR-PA-ABE. Jiguo Li 0001, Enfan Zhang, Yichen Zhang 0003, Jianting Ning, Jian Shen 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Expressive and Fully Policy-Hidden Attribute-Based Searchable Encryption Scheme for Multi-OwnerabstractAs cloud computing advances, data owners increasingly upload large volumes of data to the cloud. Attribute-based searchable encryption (ABSE) empowers data owners to manage fine-grained access over encrypted cloud files, and supports keyword-based search for authorized users. However, current multi-owner searchable encryption schemes often suffer from efficiency limitations and vulnerabilities to keyword guessing attacks. Furthermore, access policies are typically stored in plain form, exposing confidential details about data owners and authorized users. To tackle the aforementioned issues, we put forward an expressive attribute-based searchable encryption scheme with full policy concealment. Our design leverages the reduced ordered binary decision diagram (ROBDD) for access control targeting multi-user and multi-owner environments. In our scheme, users can flexibly select data owners and utilize a single trapdoor to search across shared datasets. The integration of a warrant server that signs obfuscated keywords prevents the cloud server from launching effective keyword guessing attacks. The adoption of ROBDD enables complex access policies via boolean operations, thereby significantly enhancing the efficiency and flexibility of access control. Full policy hiding is achieved by mapping ROBDD paths to an improved bloom filter, preventing access policy leakage. We present formal definitions and security models of the proposed approach, along with rigorous security proofs. Performance evaluation is conducted through theoretical analysis and simulations. Experimental indicate that our scheme achieves superior efficiency over state-of-the-art alternatives, offering a robust solution for secure and flexible cloud data management. Jiguo Li 0001, Yang Lu 0001, Hang Cheng, Yichen Zhang 0003, Jian Shen 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | Privacy-Preserving Healthcare Cloud Access Control: Registered Attribute-Based Encryption With Auditable Policy Updating
Wuwei Weng, Jiguo Li 0001, Yichen Zhang 0003, Yang Lu 0001, Jinguang Han, Jian Shen 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | A Lightweight Blockchain-Assisted Certificateless Cloud Data Integrity Auditing Scheme Without Third-Party AuditorabstractData Integrity Auditing (DIA) enables users to remotely verify whether their data saved in third-party clouds has been maliciously tampered with or compromised. As an extension of DIA in certificateless cryptography, certificateless DIA (CL-DIA) integrates the merits of conventional public-key cryptography (no key escrow) and identity-based cryptography (no certificates). However, CL-DIA schemes depend on a reliable third-party auditor (TPA) to perform integrity audits, inevitably suffering from performance bottleneck and single-point failure problems. Moreover, almost all current CL-DIA schemes were designed with computationally expensive bilinear pairings. Cryptanalysis demonstrates that the existing unique pairing-free CL-DIA scheme fails to achieve the unforgeable security of auditing proofs. In this work, we put forward a lightweight blockchain-assisted CL-DIA scheme. The scheme achieves DIA through the blockchain instead of a single TPA, thereby overcoming the problems caused by the TPA-based centralized auditing model. Then, by avoiding time-consuming pairing operations and employing edge servers in generating verifiable tags for the uploaded data of users, its performance surpasses previous pairing-based CL-DIA schemes, particularly in terms of computation efficiency. Furthermore, we provide formal proofs in the random oracle model demonstrating that our scheme achieves unforgeability of verifiable tags and auditing proofs, ensures data privacy secrity, and is resistant to collusion attacks between the EN and the CSP. Finally, experimental results show that when auditing 25 file blocks, our scheme only costs 0.29s, which reduces the total time cost of integrity auditing phase by 48.2%-85.5% compared to current pairing-based CL-DIA schemes. Yang Lu 0001, Nian Xia, Jiguo Li 0001, Yinxia Sun |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Revocable Registered Attribute-Based Encryption With User DeregistrationabstractMany businesses are putting their sensitive data in the cloud with the fast growth of cloud computing and storage. To ensure user privacy, it is necessary to keep encrypted data only in the cloud. Attribute-based encryption (ABE) is a popular mean in cloud storage scenarios. ABE is not only faced with key escrow problem but also suffers from user revocation issue when he or she is no longer authorized to access to encrypted data. In order to address these two issues, we propose a revocable registered attribute-based encryption scheme, which not only avoids key escrow problem but also supports precise revocation of a user’s access to a file as well as permanent deregistration of a user from the system. Furthermore, we prove the semantic security of the scheme and conduct a performance experiment to show the efficiency. Jiguo Li 0001, Shaobo Chen, Yang Lu 0001, Jianting Ning, Jian Shen 0001, Yichen Zhang 0003 |
IEEE Internet Things J. | 1 |
| 2025 | Efficient Key Escrow-Free Attribute-Based Signature for Anonymous Access Control in IIoTabstractIndustrial Internet of Things (IIoT) processes industrial information anytime and anywhere by deploying smart devices, which inevitably confronts with potential challenges for access control and secure authentication issues. Attribute-based signature (ABS) utilizes a collection of attributes instead of the user’s identity to achieve identity authentication, which supports anonymous access control, data integrity and nonrepudiation. However, ABS schemes exist inherent key escrow problem because all users’ private keys are generated via key authority. In addition, most ABS schemes use time consuming pairing operations, which is unsuitable for resource-constrained IIoT devices. To solve above problems, we present a key escrow-free ABS scheme and utilize server-aided technology to run most of pairing operations in the verification phase, which reduces computation overhead in recursive algorithm based on tree. Furthermore, we utilize tree-based access policy to implement flexible access control. We design a key distribution protocol. By executing this protocol, the key authority cannot derive a whole private key independently without no user’s secret value, which solves key escrow problem. We demonstrate that the presented scheme is existentially unforgeable under adaptive chosen-policy attack in the standard model. Performance analysis shows that the designed scheme is more efficient compared with the existing ABS schemes. Jiguo Li 0001, Yang Lu 0001, Jianting Ning, Yichen Zhang 0003, Jian Shen 0001 |
IEEE Internet Things J. | 1 |
| 2025 | PH-MG-ABE: A Flexible Policy-Hidden Multigroup Attribute-Based Encryption Scheme for Secure Cloud StorageabstractCiphertext-policy attribute-based encryption (CP-ABE) has attracted significant attention due to its fine-grained access control capabilities, which are highly compatible with cloud computing. Most enterprises utilizing cloud storage technology consist of multiple user groups. However, the current multigroup CP-ABE scheme may pose a risk of sensitive information leakage due to the plaintext access policy mechanisms. To mitigate this issue, it is necessary to conceal access policies. In this article, we propose a flexible policy-hidden multigroup attribute-based encryption (PH-MG-ABE) scheme that enables unique multigroup operations, such as group merging and splitting without affecting user keys. Each attribute in the access policy is divided into attribute values and attribute names. The proposed scheme achieves partial policy hiding by concealing the attribute values. Our scheme allows to directly revoke and join arbitrary numbers of users. In order to reduce the local decryption burden for users, the heavy decryption tasks are outsourced to cloud servers and correctness of the outsourced decryption is verifiable. We prove that our scheme is indistinguishable against under chosen plaintext attacks secure (IND-CPA) based on the decisional q-bilinear Diffie-Hellman exponent assumption. In addition, the proposed scheme appears to be efficient through the performance evaluation. Jiguo Li 0001, Enfan Zhang, Jinguang Han, Yichen Zhang 0003, Jian Shen 0001 |
IEEE Internet Things J. | 1 |
| 2025 | User-Friendly Field-Free Multikeyword Searchable Certificateless Encryption With Keyword Guessing Attack SecurityabstractSearchable public key encryption (SPKE) is a beneficial supplement to traditional public key encryption, which offers a viable method to address the retrieval issue over enciphered data. As a development of SPKE, searchable certificateless encryption enjoys good features of no burdensome certificate management and no key escrow. However, existing searchable certificateless encryption schemes suffer some limitations. Some only support single-keyword search, which often yields inaccurate results. Others enable conjunctive keyword search, which is difficult to cope with data lacking unified keyword fields. In the work, we present a user-friendly certificateless authenticated encryption with field-free multi-keyword search scheme. The proposed scheme eliminates time-consuming operations like bilinear pairing and hash-to-point calculations for data owners and data users. It also enables data users to make multi-keyword searches flexibly on resource-limited mobile devices without concern for keyword orders or positions. As far as we know, it is the first certificateless encryption scheme that supports field-free multi-keyword search. We demonstrate that it has the keyword guessing attack security by formal proofs and show its superior performance by comparisons and experiments. Compared to the state-of-the-art scheme with field-free multi-keyword search, our scheme reduces computation cost for creating a search token and communication cost for sending the search token by about 60% and 56%, respectively. Yang Lu 0001, Yinxia Sun, Nian Xia, Jiguo Li 0001 |
IEEE Internet Things J. | 4 |
| 2025 | A Traceable Privacy-Preserving Transaction Protocol With Evolutionary Threshold AuthenticationabstractDecentralized payment systems, such as Bitcoin, enable immutable, and transparent payments in a distributed manner. To address the issue of user privacy leakage due to transaction transparency, some efforts have enhanced privacy protection in decentralized payment systems. However, the lack of regulatory functions in these systems allows malicious users to engage in illegal activities. To balance user privacy protection and the regulation of malicious users, some efforts have attempted to introduce decentralized agencies. However, they have not considered the issue of agency corruption. In this article, we propose a new traceable privacy-preserving transaction protocol, which tracks the addresses and transaction amounts of anonymous parties through decentralized institutions. To address the problem of committee corruption, we present a traceable privacy-preserving protocol with evolving threshold authentication based on a distributed random beacon (TPETA-to-DRB), enabling committee member updates. Furthermore, we prove that the protocol is secure under the random oracle model and conduct a comprehensive performance evaluation. Ninghai Xie, Jiguo Li 0001, Chao Lin 0003, Yichen Zhang 0003, Jian Shen 0001 |
IEEE Internet Things J. | 2 |
| 2025 | Efficient Verifiable Dynamic Searchable Symmetric Encryption With Forward and Backward SecurityabstractIn the realm of secure data outsourcing, verifiable dynamic searchable symmetric encryption (VDSSE) enables a client to verify search results obtained from an untrusted server while protecting the data privacy. Nevertheless, the storage cost of verification structure in some schemes escalates linearly with the number of keywords, and the generation of proofs demands a substantial number of exponentiation operations. Moreover, some schemes overlook forward and backward security in the dynamic database. In this article, we introduce FB-VDSSE, an advanced VDSSE scheme that ensures both forward and backward security. Specifically, we introduce an efficient accumulation commitment verification structure (AC-VS) that attains a commitment verification value with a constant-size storage cost. Based on the AC-VS, we further propose a forward and backward secure VDSSE scheme. Within this scheme, the server exclusively generates a membership proof at the corresponding index of the vector, reducing the computation cost associated with the search operation. Finally, we provide the security proof and functional comparison, demonstrating that our scheme effectively ensures forward security, backward security, and verifiability. Additionally, the experimental evaluations underscore the efficiency of our scheme, showcasing its superior performance compared to relevant schemes in practical scenarios. Chenbin Zhao, Ruiying Du, Kun He 0008, Jing Chen 0003, Jiguo Li 0001, Ximeng Liu, Jianting Ning |
IEEE Internet Things J. | 5 |
| 2025 | EABE-PUFPH: Efficient Attribute-Based Encryption With Reliable Policy Updating Under Full Policy Hiding
Chenghao Gu, Jiguo Li 0001, Yichen Zhang 0003, Yang Lu 0001, Jian Shen 0001 |
IEEE Trans. Computers | 2 |
| 2025 | Response-Hiding and Volume-Hiding Verifiable Searchable Encryption With Conjunctive Keyword SearchabstractVerifiable searchable encryption (VSE) not only allows the client to search encrypted data, but also allows the client to verify whether the server honestly executes search operations. Currently, VSE scheme has been widely studied in cloud storage. However, most existing VSE schemes did not hide the access pattern and volume pattern, which respectively refer to the document identifiers and the number of documents matching the queried keywords. Recent studies have exploited these two patterns to launch attacks on searchable encryption schemes, resulting in compromising the confidentiality of encrypted data and queried keywords. In order to solve above issues, we utilize additively symmetric homomorphic encryption scheme and private set intersection protocol to construct a VSE scheme that supports conjunctive keyword search and hides the access pattern and volume pattern (i.e., response-hiding and volume-hiding). Our security model assumes that the server is malicious in the sense that it might deliberately carry out incorrect search operations. Formal security analysis demonstrates that our scheme achieves the desired security properties under our leakage function. Compared to previous schemes, our scheme has advantages in terms of performance and functionality. In an experimental setup with a security parameter of 128 bits and$2^{23}$keyword/document pairs, the search time is approximately only 7.18 seconds. Jiguo Li 0001, Licheng Ji, Yichen Zhang 0003, Yang Lu 0001, Jianting Ning |
IEEE Trans. Computers | 1 |
| 2025 | Pairing-Free Attribute-Based Signature With Message Recovery for Industrial Internet of ThingsabstractIndustrial Internet of Things (IIoT) has become a smart application for the Internet of Things (IoT), which promotes the industrial enterprises development. The smart devices deploy the IIoT to collect, manage and analyze data through sensors, which are inevitably confronted with access control and secure authentication issues. Attribute-based signature (ABS), in which every signer utilizes an attribute set to sign the message, is a graceful technology to achieve data authentication and anonymous access control. Nevertheless, in some existing ABS schemes, exponentiation and pairing operations are executed. Notably, pairing operations are time consuming and cannot be executed on constrained devices well, e.g. sensors. In addition, these ABS schemes generally need to send the signed message and signature together to the verifiers, which results in additional communication cost. The communication cost is more expensive than computing cost in wireless sensor of IIoT networks, which are unsuitable to IIoT devices. In order to reduce computation overhead and communication cost, we provide a novel pairing-free ABS scheme with message recovery, in which the signed message does not need to be transmitted. Furthermore, we utilize linear secret sharing scheme as access policy, which achieves flexible access control. The presented scheme is proven to be unforgeable and anonymous under the chosen-policy. The security of our scheme is reduced to elliptic curve discrete logarithm (DL) hard issue. The designed scheme is more efficient contrasted with existing ABS schemes with pairings at aspect of theoretical analysis and experimental simulation. Jiguo Li 0001, Yang Lu 0001, Yichen Zhang 0003 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | TERCT: A Traceable and Editable Ring Confidential Transaction for BlockchainabstractAnonymous cryptocurrency, as a distributed application utilizing blockchain technology, aims to enhance the level of anonymity in user transactions, but it may also be used for illegal activities. Existing anonymous transaction protocols lack effective public verification of transaction traceability, which means that malicious users have the ability to avoid being tracked by creating counterfeit incomplete evidence. In addition, there is a conflict between the immutability of blockchain and privacy regulations such as General Data Protection Regulation (GDPR), and revision of on-chain data is urgently needed. In order to solve above issues, we propose a trackable and editable anonymous transaction protocol TERCT, which is used to trace the addresses and transaction amounts of participants in anonymous transactions and enable editability of transaction content. Compared with previous work, TERCT enables the editability of transaction content while maintaining anonymity and publicly verifiable traceability of transactions. This ensures that users not only can edit usergenerated transaction content but also cannot fabricate pertinent evidence to evade tracing. We prove the proposed TERCT protocol satisfies unforgeability, balance, anonymity and traceability. We compare its effectiveness with the original RingCT protocol, Wolverine scheme and Trct scheme by experiments. The results show that TERCT has less additional computational overhead. Jiguo Li 0001, Ninghai Xie, Yichen Zhang 0003, Huaqun Wang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Verifiable Searchable Symmetric Encryption Over Additive HomomorphismabstractSearchable symmetric encryption (SSE) allows the client to search encrypted documents on an untrusted server without revealing the document content and queried keywords. To improve search efficiency and enrich expressiveness, most SSE schemes leak some information that could be exploited for attacks, characterized by leakage patterns. The traditional leakage patterns encompass the search pattern, the access pattern and the response length pattern. Recent research has demonstrated that these three patterns could be exploited to launch attacks, resulting in a high probability of compromising the confidentiality of encrypted documents and queried keywords. Moreover, while there exist SSE schemes that hide multiple leakage patterns, most of them do not resist the malicious server, which may carry out incorrect search operations. In this paper, we propose a leakage-suppressed verifiable SSE (VSSE) scheme that not only hides the three patterns but also allows the client to verify the server’s response. We utilize the privacy set intersection based on polynomial coding and additive symmetric homomorphism encryption to construct a VSSE scheme that supports a conjunctive query. Specifically, we design an efficient random token generation algorithm to protect the search pattern and a verification algorithm that does not require server-generated proofs. Formal security analysis shows that our scheme achieves the desired correctness, security and verifiability. Lastly, we simulate the proposed scheme and compare it with the recent leakage suppression schemes in multiple aspects. The comparison results show that our scheme achieves a good balance in expressiveness, efficiency and security. Licheng Ji, Jiguo Li 0001, Yichen Zhang 0003, Yang Lu 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Lightweight Multi-User Public-Key Authenticated Encryption With Keyword SearchabstractData confidentiality, a fundamental security element for dependable cloud storage, has been drawing widespread concern. Public-key encryption with keyword search (PEKS) has emerged as a promising approach for privacy protection while enabling efficient retrieval of encrypted data. One of the typical applications of PEKS is searching sensitive electronic medical records (EMR) in healthcare clouds. However, many traditional countermeasures fall short of balancing privacy protection with search efficiency, and they often fail to support multi-user EMR sharing. To resolve these challenges, we propose a novel lightweight multi-user public-key authenticated encryption scheme with keyword search (LM-PAEKS). Our design effectively counters the inside keyword guessing attack (IKGA) while maintaining the sizes of ciphertext and trapdoor constant in multi-user scenarios. The novelty of our approach relies on introducing a dedicated receiver server that skillfully transforms the complex many-to-many relationship between senders and receivers into a streamlined one-to-one relationship. This transformation prevents the sizes of ciphertext and trapdoor from scaling linearly with the number of participants. Our approach ensures ciphertext indistinguishability and trapdoor privacy while avoiding bilinear pairing operations on the client side. Comparative performance analysis demonstrates that LM-PAEKS features significant computational efficiency while meeting higher security requirements, positioning it as a robust alternative to existing solutions. Yongliang Xu, Hang Cheng, Jiguo Li 0001, Ximeng Liu, Xinpeng Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | User-Friendly and Expressive Forward-Secure Attribute-Based Signature With Server-Aided Signature and Outsourced VerificationabstractAttribute-based signature (ABS) is an attractive variation of digital signature that enables signers to sign messages with fine-grained signature predicates. In ABS, a signer is able to perform signing operations without revealing personal attributes, and verifiers can only confirm that the signature was created by someone with attributes satisfying a specific signature predicate. However, traditional ABS suffers from key exposure, and the compromise of a signer’s signature key results in invalidating all signatures from him/her. To address this problem, forward-secure ABS (FS-ABS) was introduced. Nevertheless, existing FS-ABS schemes have the shortcomings of low policy expressiveness and high computation costs, and thus are not suitable to be employed on mobile devices with limited resources. In this paper, we propose a user-friendly and expressive FS-ABS (UEFS-ABS) scheme that is proven secure in the standard model. The proposed scheme not only supports expressive signature predicates based on the linear secret sharing scheme, but also provides server-aided signature and outsourced verification functions, significantly reducing the workload of user terminals at both signature generation and verification stages. The experiments indicate that compared with the up-to-date FS-ABS scheme, our scheme reduces the computation costs for signature generation (on signers’ devices) and verification (on verifiers’ devices) by about 85% and 68%, respectively. This makes our scheme more suitable for user terminals in mobile computing scenarios. Chao Guo 0008, Yang Lu 0001, Nian Xia, Jiguo Li 0001 |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2025 | Efficient Registered Attribute Based Access Control With Same Sub-Policies in Mobile Cloud ComputingabstractCiphertext-policy attribute-based encryption (CP-ABE) has long been considered as a promising access control technology for cloud storage. However, CP-ABE depends on a central trusted authority to generate and distribute decryption keys, resulting in the key escrow issue. Most existing solutions only mitigate this problem but fail to resolve it entirely. Registered attribute-based encryption (RABE), a new cryptographic primitive, fundamentally addresses the key escrow problem by modifying the trust model, but its high computational overhead limits its practical application. Inspired by this challenge, we present an efficient registered attribute-based access control scheme designed for data encrypted with access policies containing the same sub-policy. In our scheme, users generate their own keys, while a key manager, who does not hold keys, replaces the central authority in managing users. Additionally, for data encrypted with the same sub-policy, the user’s initial decryption stores the relevant parameters, which can be used for subsequent decryptions to reduce computational overhead. The proposed scheme is proven to achieve semantic security. Performance analysis demonstrates that our scheme enhances decryption efficiency by roughly 41.4$\%$compared to existing RABE scheme, with a minimal storage trade-off, making it more practical for cloud storage application. Wuwei Weng, Jiguo Li 0001, Yichen Zhang 0003, Yang Lu 0001, Jian Shen 0001, Jinguang Han |
IEEE Trans. Mob. Comput. | 2 |
| 2025 | Conditional Identity-Based Broadcast Proxy Re-Encryption With Anonymity and RevocationabstractIn recent years, many extended identity-based broadcast proxy re-encryption (IBPRE) schemes have been put forward. These schemes are flexible enough and feasible to various application scenarios, including conditional IBPRE, revocable IBPRE, and anonymous IBPRE. However, the existing extended IBPRE schemes are not able to simultaneously achieve fine-grained data sharing, identity privacy protection for authorized data users (DUs) and access privilege revocation. To this end, we put forward conditional identity-based broadcast proxy re-encryption with anonymity and revocation (CIBPRE-AR) and construct a concrete CIBPRE-AR scheme. The scheme implements fine-grained data sharing by associating conditions with the re-encryption key. The identity privacy protection for authorized DUs is provided by using Lagrange interpolation. Further, the access privileges of the violated DU are revoked by updating the re-encryption key. The indistinguishability of ciphertexts against chosen-plaintext attack and anonymity of the DUs are proved rigidly. Compared with existing similar schemes, only the CIBPRE-AR scheme simultaneously achieves fine-grained data access control, anonymity as well as revocation. The proposed scheme also has advantage with respect to computation cost. Liqing Chen, Jiguo Li 0001 |
IEEE Trans. Reliab. | 3 |
| 2025 | Practical Multiuser Dynamic Searchable Symmetric Encryption With Collusion ResistanceabstractAs data sharing becomes more prevalent, there is growing interest in multiuser dynamic searchable symmetric encryption (MU-DSSE). It enables multiple authorized users to search the encrypted database while safeguarding data privacy. However, most existing schemes are inefficient due to complex computation operations and unaffordable storage burdens. In addition, some are susceptible to collusion attacks between cloud server and compromised users, leading to the leakage of search privacy from other legitimate users. To overcome these challenges, we propose a practical MU-DSSE scheme featuring an unlinkable key derivation mechanism to thwart collusion attacks. Moreover, the MU-DSSE scheme ensures both forward and backward securities in the dynamic setting. To enhance efficiency, we introduce an innovative identity-based key encapsulation mechanism for distributing authorization information to multiple users, significantly optimizing computation and storage costs on user sides and the data owner. Furthermore, we provide the formal security proof and performance analyses. The experimental results demonstrate that MU-DSSE incurs the constant-size storage cost on user sides and the data owner, and outperforms the existing schemes in practice. Chenbin Zhao, Ruiying Du, Jing Chen 0003, Kun He 0008, Li Xu 0002, Jiguo Li 0001 |
IEEE Trans. Reliab. | 6 |
| 2024 | Efficient Revocable Attribute-Based Encryption With Verifiable Data IntegrityabstractNowadays, cloud computing and cloud storage services that can reduce the local workload are becoming increasingly popular, allowing individual and corporate users to upload data to the cloud. Since the user’s permissions in the system are not immutable, the users should have dynamic access. Revocation of users who have been granted access to data is also a strong need for cloud computing systems. In addition, we should ensure the data integrity after the cloud server performs a revocation. To address the above issues, we propose a revocable attribute-based encryption scheme that protects the data integrity (RABE-DI). Our scheme is more efficient compared with existing RABE-DI schemes. In addition, we prove the semantic security and integrity of the scheme. Experimental result shows that the similar scheme is not as efficient as ours. Shaobo Chen, Jiguo Li 0001, Yichen Zhang 0003, Jinguang Han |
IEEE Internet Things J. | 2 |
| 2024 | OABS: Efficient Outsourced Attribute-Based Signature Scheme With Constant SizeabstractAttribute-based signature (ABS) extends the identity-based signature, in which the unique identity for the signer is expanded into an attribute set composed of multiple attributes. The current ABS schemes supporting linear secret-sharing scheme (LSSS) matrix are flexible, but the computational cost of the signing algorithm is linear with the number of required attributes. Therefore, it is inappropriate to constrained devices (mobile phone, tablet, etc.) which have limited computation power. For the sake of solving the above issue, we devise an key-policy outsourced ABS (OABS) scheme supporting LSSS access structure. The designed scheme provides the outsourced key for the cloud service provider (CSP) which computes most of module exponentiation in the signing phase. The signer only needs to perform lightweight calculations to endorse a message. The presented OABS scheme is proved secure against the q-Diffie-Hellman exponentiation (q-DHE) assumption under the standard model. In addition, the devised OABS scheme fulfills the signer privacy. Moreover, the signature length for the designed scheme is invariable and unrelated to the number of required attributes, which reduces communication cost. Performance analysis demonstrates that the designed OABS scheme is more high efficiency in the aspect of the computational cost. Zhaozhe Kang, Jiguo Li 0001, Yuting Zuo, Yichen Zhang 0003, Jinguang Han |
IEEE Internet Things J. | 2 |
| 2024 | Fine-Grained and Sanitizable Access Control Service for IoT-Based Digital SubscriptionsabstractIn the digital era, one of the most significant changes in the IoT world is the popularity of digital subscriptions, where service providers upload encrypted service information to the cloud for sharing. In practice, the untrustworthy service providers may intentionally leak their private keys used to encrypt service information (for profits), allowing unauthorized subscribers to enjoy valuable service. The malicious behavior described above has become a severe obstacle to the widespread application of IoT-based digital subscriptions. To address this issue, we propose a fine-grained and sanitizable access control system (FSAC), in which service information could only be accessed by authorized subscribers. To thwart potential threats from malicious service providers, we design a sanitizable mechanism to transform the original ciphertext, ensuring that a subscriber is unable to decrypt the sanitized ciphertext solely using the leaked key of the service provider. For resource-constrained IoT devices, we further extend FSAC with outsourced decryption (FSACO) that relieves subscribers from the burden of decryption. In particular, FSACO allows subscribers to perform two exponentiation operations rather than time-consuming paring operations (as that in FSAC) to decrypt sanitized ciphertext. We conduct rigorous security analysis of our systems and demonstrate their efficient performance through extensive experiments. Specifically, the enhanced system FSACO has a minimum decryption time of approximately 0.08 ms. Jianting Ning, Shengmin Xu, Jiguo Li 0001, Kai Zhang 0016 |
IEEE Internet Things J. | 4 |
| 2024 | Privacy-Preserving Decentralized Functional Encryption for Inner ProductabstractTo support secure data mining and privacy-preserving computation, partial access and selective computation on encrypted data are desirable. Functional encryption (FE) is a new paradigm of public-key encryption and allows authorized users to compute specific functions on encrypted data without knowing the data. However, in some FE schemes, a trusted central authority (CA) is required to generate secret keys for users according to the description of functions. In this paper, to reduce trust on the CA and protect users' privacy, a privacy-preserving decentralised FE for inner product (PPDFEIP) scheme is proposed where multiple authorities co-exist and work independently without any interaction. Especially, to resist collusion attacks, all secret keys of the same user are tied to his/her global identifier (GID), but authorities cannot know any information of the GID even if they collaborate. We formalize the definition and security model of our PPFEIP scheme, and propose a concrete construction. Furthermore, the proposed scheme is implemented and evaluated. Finally, the security of our PPDFEIP scheme is reduced to well-known complexity assumptions. The novelty is to reduce trust on the CA, protect users' privacy and enable authorized users to compute inner product on encrypted data without compromising confidentiality. Jinguang Han, Liqun Chen 0002, Aiqun Hu, Liquan Chen, Jiguo Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | PAESS: Public-Key Authentication Encryption With Similar Data Search for Pay-Per-QueryabstractIn recent years, many cloud service providers adopt the pay-per-query model to offer paid search services to the public. The data owner rents the resources of cloud service providers and charges the data user a fee based on the data volume to be queried. While this commercial model offers flexibility, convenience, and cost-effectiveness, it comes with a significant vulnerability to data breaches. Public-key authentication encryption with keyword search (PAEKS) is a technology which is well applied in the pay-per-query model. But there is no PAEKS scheme applicable to this scenario. For this purpose, we present public-key authentication encryption with similar data search for pay-per-query (PAESS) and construct the first idiographic scheme PAESS-I. PAESS-I utilizes Shamir secret sharing and locality sensitive hashing to implement similar data search, has the verifiability of results, adds the charge function to prevent cloud servers and data users from colluding to deny deductions. We propose the second scheme PAESS-II based on PAESS-I, which is a mobile-friendly lightweight PAESS. Our second scheme operates in the pay-per-query model without pairing and exponential operations. PAESS-I satisfies ciphertext indistinguishability and trapdoor indistinguishability, and sacrifices the computational performance in favor of the pay-per-query model. The optimized PAESS-II is resistant to adaptively-chosen-targets attack, and satisfies ciphertext indistinguishability and trapdoor indistinguishability. PAESS-II distinguishes itself from other existing similar schemes by having the same characteristics as PAESS-I, along with the benefits when it comes to the calculation cost. Liqing Chen, Jiguo Li 0001, Jian Weng 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | DTACB: Dynamic Threshold Anonymous Credentials With Batch-ShowingabstractThreshold anonymous credentials enable users to acquire credentials in a decentralized manner while upholding their privacy. However, distributed network environments, such as electronic voting systems and federated identity management systems, have pressing needs for enhancing security, reducing reliance on fixed-group issuers, and achieving scalability. These requirements expose the significant constraints of existing threshold anonymous credential systems, which struggle to support dynamic threshold settings. This struggle leads to the necessity of system rewinding whenever an issuer is included or excluded. Moreover, the communication and computation complexities involved in showing credentials exhibit a linear relationship with the number of credentials possessed by each user. In this paper, we present a novel dynamic threshold anonymous credential system, named DTACB, to tackle the aforementioned challenges. DTACB enables the dynamic adjustment of thresholds, allowing issuer adjustments without rewinding the system. DTACB additionally supports batch-showing of credentials and proof of credential quantity values while preserving the user’s credentials collection remains undisclosed. We conduct rigorous security analysis and validate our efficiency claims via implementing and benchmarking. In particular, DTACB effectively reduces the cost of batch-proof verification to 3.78 ms, independent of the user’s proof size. Jianting Ning, Shengmin Xu, Chao Lin 0003, Jiguo Li 0001, Jian Shen 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Lightweight Searchable and Equality-Testable Certificateless Authenticated Encryption for Encrypted Cloud DataabstractPublic key encryption with equality test (PKE-ET) is a novel cryptosystem to deal with the problem of multi-public-key encrypted data computing. It can be used to verify if different ciphertexts are encryptions of same plaintext under different public keys without decryption. As an extension of PKE-ET, certificateless encryption with equality test (CLE-ET) has the merits of no key escrow and no certificate. However, the existing CLE-ET schemes are vulnerable to the message recovery (MR) attack and suffer from low efficiency due to using the computationally expensive bilinear pairing. In this work, an elliptic-curve-based certificateless authenticated encryption with keyword search and equality test (CLAE-KS&ET) scheme is developed. The scheme not only provides resistance to the MR attack, but also satisfies the lightweight requirement of the resources-restricted environments. Moreover, it supports a ciphertext retrieval function resisting keyword guessing attacks. This function enables a user to seek out the desired ciphertexts on the cloud server firstly before making ciphertext equality test with others. Based on the computational Diffie-Hellman (CDH) and decisional Diffie-Hellman (DDH) problems, we formally prove its security. Compared with the existing CLE-ET schemes, it significantly improves computational efficiency and is more suited to the user terminals with limited resources in cloud. Jinmei Tian, Yang Lu 0001, Jiguo Li 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Comment on an Attribute-Based Searchable Encryption Scheme With Receiver AnonymityabstractPrivacy protection of search keywords is one of the challenges in building keyword-based searchable encryption schemes. In IEEE Transactions on Services Computing (Vol. 15, No.2, March/April 2022), Chaudhariet al. proposed an attribute-based searchable encryption (ABSE) scheme (named KeySea), which was claimed to provide an effective solution to solve the problem of privacy-preserving search over cloud encrypted data. However, we demonstrate that the scheme fails to protect the privacy of search keywords by proposing three attacks on it. Our attacks show that an adversary (an untrusted cloud server or a malicious user) can successfully extract the keyword from a search trapdoor by keyword guessing in an offline or online manner. After analyzing the reasons that cause such attacks, we provide the potential solutions to overcome similar security vulnerabilities in the ABSE schemes. Guangao Zu, Yang Lu 0001, Jiguo Li 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2023 | Toward Forward and Backward Private Dynamic Searchable Symmetric Encryption Supporting Data Deduplication and Conjunctive QueriesabstractIn Internet of Things (IoT) application scenarios, such as intelligent logistics, secure data access control, and sharing based on dynamic searchable symmetric encryption (DSSE) has become a research hotspot in recent years. DSSE is an encryption technology which gratifies the above requirements, while protecting the sensitive data during the operation. The existing DSSE schemes do not achieve data deduplication and conjunctive queries concurrently, and exist problems, such as complex update process, inflexible query method, and privacy disclosure. For this purpose, this article proposes DSSE for data deduplication and conjunctive queries (DSSE-DC), and constructs a concrete DSSE-DC scheme. Our scheme uses symmetric encryption with homomorphic addition and bitmap index to develop a secure and reliable search architecture, and updates through modular addition. Meanwhile, we add a deduplication mechanism to realize data deduplication which avoids the waste of cloud storage resources. Furthermore, we introduce the idea of inner product matching to achieve efficient conjunctive queries. The adaptive security of the DSSE-DC scheme is proved in the random oracle model. While our scheme satisfies forward and backward privacy. In comparison to the existing DSSE schemes for conjunctive queries, our scheme has advantage in update and search performances, which is applicable to IoT applications like intelligent logistics. Liqing Chen, Jiguo Li 0001 |
IEEE Internet Things J. | 3 |
| 2023 | Revocable Blockchain-Aided Attribute-Based Encryption With Escrow-Free in Cloud StorageabstractThe massive amount of data generated by the Internet of Things (IoT) and the need to store that data presents a huge challenge for storage. However, meeting this challenge has also driven the development of storage technologies, especially those related to cloud storage. Although attribute-based encryption (ABE) schemes are commonly used to achieve data confidentiality and fine-grained access control in cloud storage, there is still an inherent problem with ABE schemes, namely the key escrow problem. In this paper, we propose a revocable blockchain-aided ABE with escrow-free (BC-ABE-EF) system that resolves the key escrow problem by replacing the traditional key authority with a consortium blockchain. The keys are generated between the blockchain and the data user through a secure key issuing protocol, and the blockchain cannot obtain the user's full key alone. Furthermore, utilize the decryption cloud server to schedule pre-decryption operations in cloud and introduce a group manager to update the group keys of unrecovered users and generate re-encryption keys. The security analysis shows that our scheme is secure under the Decisional Computation Diffie Hellman (DCDH) assumption. The effectiveness of the scheme is demonstrated by simulating the BC-ABE-EF scheme and comparing it based on performance analysis. Yuyan Guo, Zhenhua Lu, Jiguo Li 0001 |
IEEE Trans. Computers | 4 |
| 2023 | Privacy-Preserving and Forward Public Key Encryption With Field-Free Multi-Keyword Search for Cloud Encrypted DataabstractWith the excessive growth of data and the rapid development of cloud technology, cloud adoption is expanding rapidly nowadays. To achieve the purpose of privacy protection, the cloud data may be transmitted, stored and retrieved in enciphered form. Public key searchable encryption (PKSE) provides a feasible solution for efficient retrieval over enciphered data without decryption. However, traditional PKSE suffers from some problems, such as keyword guessing (KG) attack and unauthorized ciphertext retrieval. In this paper, we present a practical PKSE scheme named forward public key authenticated encryption with field-free conjunctive keyword search (FW-PAE-FCKS). The scheme enjoys several good properties (e.g., flexible multi-keyword search with no keyword fields, forward ciphertext retrieval) and can effectively withstand the KG attack and the unauthorized ciphertext retrieval. Moreover, the executive overhead of the scheme is very friendly to the user terminals with limited resources as it totally avoids the operations with high computation cost (such as hash-to-point, bilinear pairing) on the user side. Based on the infeasibility assumption of the hash Diffie-Hellman problem, we formally prove its security without using the random oracle. Comparison analysis and experimental results show that it outperforms the existing related schemes. Yang Lu 0001, Jiguo Li 0001 |
IEEE Trans. Cloud Comput. | 2 |
| 2023 | TFS-ABS: Traceable and Forward-Secure Attribute-Based Signature Scheme With Constant-SizeabstractAttribute-based signature (ABS) is a versatile and useful cryptogrammic technology. In an ABS scheme, every signer is distributed a signing secret key in term of her/his attributes, and endorses a message in relation to some signing policy fulfilled by the signer's attributes. The verifier checks that the signature is indeed endorsed by the signer whose attributes match with the signing policy. However, existing ABS schemes suffer from the issue of abusing signature and key exposure. To address the above issues, we provide a traceable and forward-secure attribute-based signature (TFS-ABS) scheme with constant-size supporting flexible threshold predicates. Furthermore, we prove that the presented TFS-ABS scheme is existential unforgeability against selective predicate attack under the standard model. We reduce the security for the provided scheme to$q$-Diffie-Hellman exponentiation assumption. The designed scheme can be used to alleviate the damage induced by key exposure and traces the real identity of signer by attribute authority (AA) when the signer occurs abusing behavior. Furthermore, the signature size in presented scheme keeps constant and is independent of the number of attributes. Experimental evaluations exhibit that the presented TFS-ABS scheme is efficient in term of the communication and computation overhead. Zhaozhe Kang, Jiguo Li 0001, Jian Shen 0001, Jinguang Han, Yuting Zuo, Yichen Zhang 0003 |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2022 | Decentralized Attribute-Based Server-Aid Signature in the Internet of ThingsabstractDevices of Internet of Things (IoT) play a significant role in people’s daily life. A large scale of data is generated, collected, and analyzed in these devices, which inevitably faces secure authentication and access control problem. Attribute-based signature (ABS), where a signer signs a message over a set of attributes, plays an elegant tool for privacy-preserving access control and data authentication. In multiauthority ABS scheme, multiple authorities distribute users’ private keys over their different attributes and these attribute authorities are managed by a central authority. Nevertheless, the whole ABS system can be broken if the central authority is compromised. Besides, the multiauthority ABS scheme needs a lot of pairing and exponentiation operations in the verification and signature algorithms. Therefore, it is very expensive for resource-limited devices (e.g., sensors in IoT) to utilize the ABS scheme. In order to solve above problems, we present a decentralized attribute-based server-aid signature (DABSAS) scheme. In the DABSAS scheme, a server can help users execute heavy computation in the signature and verification algorithms. The proposed scheme provides anonymity and unforgeability. In addition, our scheme mitigates the burden of the signature and verification phase. The proposed scheme is proved secure under the well-known computational co-Diffie–Hellman (co-CDH) assumption. Compared with the existing schemes, the presented DABSAS scheme is efficient. Jiguo Li 0001, Jinguang Han, Chengdong Liu, Yichen Zhang 0003, Huaqun Wang |
IEEE Internet Things J. | 1 |
| 2022 | Key escrow-free attribute based encryption with user revocation
Ruyuan Zhang, Jiguo Li 0001, Yang Lu 0001, Jinguang Han, Yichen Zhang 0003 |
Inf. Sci. | 2 |
| 2022 | Fully Secure ID-Based Signature Scheme with Continuous Leakage ResilienceabstractThe side channel attacks will lead to the destruction of the security of the traditional cryptographic scheme. Leakage-resilient identity-based signature has attracted great attention. Based on the dual system encryption technology, we construct an identity-based signature scheme that can resist continuous private key leakage. In the standard model, the security of the scheme is proved. The key points of our leakage-resilient signature scheme are as follows: (1) The private key can be extended according to the security requirements. In other words, when the leakage is serious, we can select a bigger value n, where n is a parameter related to the leakage rate. (2) An elaborate key update algorithm makes the scheme resist continuous leakage attacks. Furthermore, the updated private key has the same distribution as the previous private key. (3) The proposed scheme is fully secure in the standard model rather than in the random oracle model or in the general group model. In order to achieve this goal, we use dual system encryption technology. Thus, the security of the constructed scheme does not depend on the number of queries of the attacker. Qihong Yu, Jiguo Li 0001, Sai Ji |
Secur. Commun. Networks | 2 |
| 2022 | Efficient CP-ABE Scheme With Shared Decryption in Cloud StorageabstractAttribute-based encryption (ABE) is a preferred technology used to access control the data stored in the cloud servers. However, in many cases, the authorized decryption user may be unable to decrypt the ciphertext in time for some reason. To be on the safe side, several alternate users are delegated to cooperate to decrypt the ciphertext, instead of one user doing that. We provide a ciphertext-policy ABE scheme with shared decryption in this article. An authorized user can recover the messages independently. At the same time, these alternate users (semi-authorized users) can work together to get the messages. We also improve the basic scheme to ensure that the semi-authorized users perform the decryption tasks honestly. An integrated access tree is used to improve the efficiency for our scheme. The new scheme is proved CPA-secure in the standard model. The experimental result shows that our scheme is very efficient on both computational overhead and storage cost. Ningyu Chen, Jiguo Li 0001, Yichen Zhang 0003, Yuyan Guo |
IEEE Trans. Computers | 2 |
| 2022 | Efficient Identity-Based Provable Multi-Copy Data Possession in Multi-Cloud StorageabstractTo increase the availability and durability of the outsourced data, many customers store multiple copies on multiple cloud servers. To guarantee the integrity of multi-copies, some provable data possession (PDP) protocols for multi-copy are presented. However, most of previous PDP protocols consider all copies to be stored on only one cloud storage server. In some degree, multi-copy makes little sense in such circumstance. Furthermore, many PDP protocols depend on the technique of public key infrastructure (PKI), which suffers many types of security vulnerabilities and also brings heavy communicational and computational cost. To increase the security and efficiency, we provide a novel identity-based PDP scheme of multi-copy on multiple cloud storage servers. In our scheme, all copies are delivered to different cloud storage servers, which work cooperatively to store the customer's data. By the homomorphic verifiable tags, the integrity of all copies can be checked simultaneously. The system model and security model of our scheme are provided in the paper. The security for our scheme is proved based on the computation Diffie-Hellman (CDH) hard problem. Analysis and experimental evaluation show that our scheme is efficient and practical. The proposed scheme is the first identity-based PDP scheme for multi-copy and multi-cloud servers. Jiguo Li 0001, Yichen Zhang 0003 |
IEEE Trans. Cloud Comput. | 1 |
| 2022 | Attribute Based Encryption with Privacy Protection and Accountability for CloudIoTabstractThe pervasive, ubiquitous, and heterogeneous properties of IoT make securing IoT systems a very challenging task. More so when access and storage are performed through a cloud-based IoT system. IoT data stored on cloud should be encrypted to ensure data privacy. It is also crucial to allow only authorized entities to access and decrypt the encrypted data. In this article, we propose a ciphertext-policy attribute-based encryption (CP-ABE) scheme that enables fine-grained access control of encrypted IoT data on cloud. CP-ABE is regarded as a highly promising approach to provide flexible and fine-grained access control, which is quite suited to secure cloud based IoT systems. We first present an access control system model of CloudIoT platform based on ABE. Based on the presented system model, we construct a ciphertext-policy hiding CP-ABE scheme, which guarantees the privacy of the users. We further construct a white-box traceable CP-ABE scheme with accountability in order to address the user key abuse and authorization center key abuse. Experiment illustrates the proposed systems are efficient. Jiguo Li 0001, Yichen Zhang 0003, Jianting Ning, Xinyi Huang 0001, Geong Sen Poh, Debang Wang |
IEEE Trans. Cloud Comput. | 1 |
| 2022 | Lightweight Public/Private Auditing Scheme for Resource-Constrained End Devices in Cloud StorageabstractData integrity protection, an important feature in cloud storage services, can be achieved using auditing schemes. However, existing public and private auditing schemes are somewhat inefficient in practice. For example, in private auditing schemes, the trusted third-party is generally not able to settle disputes between users and the cloud storage server. In most existing public auditing schemes, it takes a user tens of seconds to generate data tags for every MB of file outsourced, which is clearly impractical particularly on resource-constrained end devices. Since the user is likely to have information than the auditor, we divide the verification phase into private verification and public verification phases. Then, we propose a public/private auditing model and a security model for public/private auditing. In our public/private auditing model, the user uses private verification phase to audit outsourced data promptly in most cases, and the auditor uses public verification phase to audit outsourced data only when dispute occurs or the user is not available to audit. Then, we propose a public/private auditing scheme, and present its security proof in the random oracle model under the discrete logarithm assumption. Experimental findings demonstrate that our scheme only need tens of microseconds to generate data tags for every MB file outsourced. In other words, the efficiency of our scheme is almost as high as existing high-performing private auditing schemes, and our scheme is more effective in comparison to existing efficient public auditing schemes. Feng Wang 0020, Li Xu 0002, Jiguo Li 0001, Kim-Kwang Raymond Choo |
IEEE Trans. Cloud Comput. | 3 |
| 2022 | Lightweight Public Key Authenticated Encryption With Keyword Search Against Adaptively-Chosen-Targets Adversaries for Mobile DevicesabstractCloud storage services have grown extensively in recent years. For security and privacy purposes, sensitive data need to be outsourced to clouds in encrypted form. Searchable public key encryption (SPKE) enables data ciphertexts to be retrieved by keyword(s) without decryption. Unfortunately, most of the existing SPKE schemes cannot withstand the keyword guessing attack. To combat such attack, public key authenticated encryption with keyword search (PAEKS) was presented. However, the existing PAEKS schemes were proven secure under a designated-targets security model, in which an adversary only can attack a sender and a recipient designated by the challenger. Our cryptanalysis indicates that such a scheme may be insecure against the practical attacks where the adversaries choose their targets by themselves. To fight against adaptively-chosen-targets adversaries, we refine the adversary model for PAEKS by permitting the adversaries to choose their targets adaptively, and then formalize the security definitions under the improved security model. After that, we devise a lightweight PAEKS scheme that avoids the time-consuming bilinear pairing operations and give the security proofs. The comparisons show that it outperforms the existing bilinear pairing-based PAEKS schemes in both the computation and communication performance, and therefore is more suitable for the resource-constrained mobile devices. Yang Lu 0001, Jiguo Li 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2022 | Efficient Attribute Based Server-Aided Verification SignatureabstractAttribute based signature (ABS) is a novel cryptographic primitive, which permits users to sign a message over attributes without revealing other information. A signature only reveals that it is signed by a signer whose some attributes meet an access policy. However, some ABS schemes only support the threshold access policy, where the signing algorithms are limited by the threshold. The threshold access policy can not express precise access control well. In addition, the computation cost of the verification algorithm is heavy since pairing operations are required. Pairing is costly operation comparing to exponentiation. Therefore, existing ABS schemes are not suitable to resource-limited devices, such as RFID tags and smart cards. In order to solve the issues above, we present a novel ABS scheme by using the attribute tree as access policy that expresses flexible access control. We utilize server-aid technique to help the verifier to verify signatures and reduce the computation burden. Our scheme is proved secure against unforgeable and anonymous under chosen-policy selective-message attack in the standard model. Compared with existing schemes, our scheme is more efficient in terms of private key generation and verification. The proposed scheme reduces users’ calculation burden and expresses more flexible access policy. Jiguo Li 0001, Chengdong Liu, Jinguang Han, Yichen Zhang 0003 |
IEEE Trans. Serv. Comput. | 2 |
| 2022 | Cryptographic Solutions for Cloud Storage: Challenges and Research OpportunitiesabstractWhile cloud computing is relatively mature and its potential benefits well understood by individual, industry and government consumers, a number of security and privacy concerns remain. Unsurprisingly, designing cryptographic solutions to ensure the security of cloud services and the privacy of data outsourced to the cloud remains an ongoing research area. This paper provides a critique of the wide range of cryptographic schemes designed for securing sensitive data in the cloud computing environment, as well as outlining the research opportunities in the use of cryptographic techniques in cloud computing. Lei Zhang 0009, Hu Xiong, Qiong Huang 0001, Jiguo Li 0001, Kim-Kwang Raymond Choo, Jiangtao Li 0003 |
IEEE Trans. Serv. Comput. | 4 |
| 2021 | An efficient identity-based signature scheme with provable security
Jiguo Li 0001, Chengdong Liu, Jinguang Han, Huaqun Wang, Yichen Zhang 0003 |
Inf. Sci. | 2 |
| 2021 | Privacy-Preserving Attribute-Based Keyword Search in Shared Multi-owner SettingabstractCiphertext-Policy Attribute-Based Keyword Search (CP-ABKS) facilitates search queries and supports fine-grained access control over encrypted data in the cloud. However, prior CP-ABKS schemes were designed to support unshared multi-owner setting, and cannot be directly applied in the shared multi-owner setting (where each record is accredited by a fixed number of data owners), without incurring high computational and storage costs. In addition, due to privacy concerns on access policies, most existing schemes are vulnerable to off-line keyword-guessing attacks if the keyword space is of polynomial size. Furthermore, it is difficult to identify malicious users who leak the secret keys when more than one data user has the same subset of attributes. In this paper, we present a privacy-preserving CP-ABKS system with hidden access policy in Shared Multi-owner setting (basic ABKS-SM system), and demonstrate how it is improved to support malicious user tracing (modified ABKS-SM system). We then prove that the proposed ABKS-SM systems achieve selective security and resist off-line keyword-guessing attack in the generic bilinear group model. We also evaluate their performance using real-world datasets. Yinbin Miao, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng, Jiguo Li 0001, Hongwei Li 0001, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Pairing-Free Certificate-Based Searchable Encryption Supporting Privacy-Preserving Keyword Search Function for IIoTsabstractAs a practical application of the Internet of Things (IoT) in the modern industry, industrial IoT (IIoT) enables industrial enterprises to accelerate the development. Nowadays, the cloud computing technology has been applied to data storage and processing in IIoTs, but how to protect data privacy in the cloud has become a challenge and technical issue. Recently, the certificate-based encryption with keyword search (CBEKS) was presented to handle the cloud ciphertext retrieval. By CBEKS, one can get back all desired ciphertexts from the cloud without decrypting the ciphertexts or leaking the search keywords. However, the existing CBEKS scheme uses the computationally expensive bilinear pairing, which is disgusted by the performance-limited IIoT smart devices. In this article, a pairing-free and privacy-preserving CBEKS scheme is developed. The experimental results show that it has an obvious advantage in the computation performance when compared with the pairing-based CBEKS scheme. In addition, our security proofs indicate that it is secure against keyword guessing attacks. Yang Lu 0001, Jiguo Li 0001 |
IEEE Trans. Ind. Informatics | 2 |
| 2021 | Certificateless Public Integrity Checking of Group Shared Data on Cloud StorageabstractCloud storage service supplies people with an efficient method to share data within a group. The cloud server is not trustworthy, so lots of remote data possession checking (RDPC) protocols are proposed and thought to be an effective way to ensure the data integrity. However, most of RDPC protocols are based on the mechanism of traditional public key infrastructure (PKI), which has obvious security flaw and bears big burden of certificate management. To avoid this shortcoming, identity-based cryptography (IBC) is often chosen to be the basis of RDPC. Unfortunately, IBC has an inherent drawback of key escrow. To solve these problems, we utilize the technique of certificateless signature to present a new RDPC protocol for checking the integrity of data shared among a group. In our scheme, user's private key includes two parts: a partial key generated by the group manager and a secret value chosen by herself/himself. To ensure the right public keys are chosen during the data integrity checking, the public key of each user is associated with her unique identity, for example the name or telephone number. Thus, the certificate is not needed and the problem of key escrow is eliminated too. Meanwhile, the data integrity can still be audited by public verifier without downloading the whole data. In addition, our scheme also supports efficient user revocation from the group. The security of our scheme is reduced to the assumptions of computational Diffie-Hellman (CDH) and discrete logarithm (DL). Experiment results exhibit that the new protocol is very efficient and feasible. Jiguo Li 0001, Yichen Zhang 0003 |
IEEE Trans. Serv. Comput. | 1 |
| 2021 | Secure Channel Free Certificate-Based Searchable Encryption Withstanding Outside and Inside Keyword Guessing AttacksabstractSearchable public key encryption (SPKE) is a useful public key cryptographic primitive that allows a user to perform keyword searches over publicly encrypted messages on an untrusted storage server while guaranteeing the privacy of the original messages as well as the search keywords. However, most of the previously proposed SPKE frameworks suffer from the security vulnerability caused by the keyword guessing attack and some other weaknesses. Inspired by the ideas of certificate-based cryptography and signcryption, we present a new SPKE framework called certificate-based searchable encryption. The new framework not only provides resistance to the existing known types of keyword guessing attacks, but also enjoys some appealing merits, such as implicit authentication, no key escrow and no secure channel. Under this new framework, we devise a concrete searchable certificate-based encryption scheme. In the random oracle model, it is proven to meet the keyword ciphertext indistinguishability, the keyword ciphertext unforgeability and the keyword trapdoor indistinguishability under the adaptive chosen-keyword attack. The comparisons indicate that it is secure and practicable. Yang Lu 0001, Jiguo Li 0001, Yichen Zhang 0003 |
IEEE Trans. Serv. Comput. | 2 |
| 2020 | Privacy-Preserving and Pairing-Free Multirecipient Certificateless Encryption With Keyword Search for Cloud-Assisted IIoTabstractNowadays, cloud-assisted Industrial Internet of Things (IIoT) has become pervasive in modern enterprises, because it supplies a promising way to transform the operation mode of existing industrial facilities, to enhancing the production efficiency and lowering the manufacturing cost. In order to preserve the privacy of enterprises, sensitive industrial data needs to be encrypted prior to being uploaded to the cloud. Recently, certificateless encryption with keyword search (CLKS) was introduced to resolve the problem of encrypted data retrieval in cloud-assisted IIoT. However, the existing CLKS schemes only support a single-recipient keyword search and need to depend on the costly bilinear pairing that is disliked by the resource-constrained IIoT devices. Moreover, most of the existing CLKS schemes are vulnerable to the keyword guessing attack, and thus fail to protect the privacy of searched data. In this article, we develop a privacy-preserving and pairing-free multirecipient CLKS scheme for cloud-assisted IIoT. The proposed scheme has the following merits: 1) supporting multirecipient keyword search function; 2) requiring no costly bilinear pairing operations; and 3) providing resistance against keyword guessing attacks. The performance comparison and analysis demonstrate that it is more efficient than the existing CLKS schemes and is appropriate for the cloud-assisted IIoT. Yang Lu 0001, Jiguo Li 0001, Yichen Zhang 0003 |
IEEE Internet Things J. | 2 |
| 2020 | Adaptively secure certificate-based broadcast encryption and its application to cloud storage service
Liqing Chen, Jiguo Li 0001, Yang Lu 0001, Yichen Zhang 0003 |
Inf. Sci. | 2 |
| 2020 | Certificate-Based Encryption Resilient to Continual Leakage in the Standard ModelabstractThe security for many certificate-based encryption schemes was considered under the ideal condition, where the attackers rarely have the secret state for the solutions. However, with a side-channel attack, attackers can obtain partial secret values of the schemes. In order to make the scheme more practical, the security model for the certificate-based encryption which is resilient to continual leakage is first formalized. The attackers in the security model are permitted to get some secret information continuously through the side-channel attack. Based on the certificate-based key encapsulation scheme, a novel certificate-based encryption scheme is proposed, which is resilient to the continual leakage. In the standard model, the new scheme we propose is proved to be secure under the decisional truncated q-augmented bilinear Diffie–Hellman exponent hard problem and the decisional 1-bilinear Diffie–Hellman inversion hard problem. Additionally, the new scheme can resist the chosen-ciphertext attack. Moreover, a comparison is performed with other related schemes, where the proposed solution further considers the continual leakage-resilient property and exhibits less computation cost. Yuyan Guo, Jiguo Li 0001, Shimin Wei |
Secur. Commun. Networks | 2 |
| 2020 | Adaptively secure efficient broadcast encryption with constant-size secret key and ciphertext
Liqing Chen, Jiguo Li 0001, Yichen Zhang 0003 |
Soft Comput. | 2 |
| 2020 | A decentralized multi-authority ciphertext-policy attribute-based encryption with mediated obfuscation
Jiguo Li 0001, Shengzhou Hu, Yichen Zhang 0003, Jinguang Han |
Soft Comput. | 1 |
| 2020 | Full Verifiability for Outsourced Decryption in Attribute Based EncryptionabstractAttribute based encryption (ABE) is a popular cryptographic technology to protect the security of users' data. However, the decryption cost and ciphertext size restrict the application of ABE in practice. For most existing ABE schemes, the decryption cost and ciphertext size grow linearly with the complexity of access structure. This is undesirable to the devices with limited computing capability and storage space. Outsourced decryption is considered as a feasible method to reduce the user's decryption overhead, which enables a user to outsource a large number of decryption operations to the cloud service provider (CSP). However, outsourced decryption cannot guarantee the correctness of transformation done by the cloud, so it is necessary to check the correctness of outsourced decryption to ensure security for users' data. Current research mainly focuses on verifiability of outsourced decryption for the authorized users. It still remains a challenging issue that how to guarantee the correctness of outsourced decryption for unauthorized users. In this paper, we propose an ABE scheme with verifiable outsourced decryption (called full verifiability for outsourced decryption), which can simultaneously check the correctness for transformed ciphertext for the authorized users and unauthorized users. The proposed ABE scheme with verifiable outsourced decryption is proved to be selective CPA-secure in the standard model. Jiguo Li 0001, Yichen Zhang 0003, Jinguang Han |
IEEE Trans. Serv. Comput. | 1 |
| 2019 | Hierarchical attribute based encryption with continuous leakage-resilience
Jiguo Li 0001, Qihong Yu, Yichen Zhang 0003 |
Inf. Sci. | 1 |
| 2019 | Key-policy attribute-based encryption against continual auxiliary input leakage
Jiguo Li 0001, Qihong Yu, Yichen Zhang 0003, Jian Shen 0001 |
Inf. Sci. | 1 |
| 2019 | Keyword guessing attacks on a public key encryption with keyword search scheme without random oracle and its improvement
Yang Lu 0001, Jiguo Li 0001 |
Inf. Sci. | 3 |
| 2019 | Constructing pairing-free certificateless public key encryption with keyword searchabstractSearchable public key encryption enables a storage server to retrieve the publicly encrypted data without revealing the original data contents. It offers a perfect cryptographic solution to encrypted data retrieval in encrypted data storage systems. Certificateless cryptography (CLC) is a novel cryptographic primitive that has many merits. It overcomes the key escrow problem in identity-based cryptosystems and the cumbersome certificate problem in conventional public key cryptosystems. Motivated by the appealing features of CLC, three certificateless encryption with keyword search (CLEKS) schemes were presented in the literature. However, all of them were constructed with the costly bilinear pairing and thus are not suitable for the devices that have limited computing resources and battery power. So, it is interesting and worthwhile to design a CLEKS scheme without using bilinear pairing. In this study, we put forward a pairing-free CLEKS scheme that does not exploit bilinear pairing. We strictly prove that the scheme achieves keyword ciphertext indistinguishability against adaptive chosen-keyword attacks under the complexity assumption of the computational Diffie-Hellman problem in the random oracle model. Efficiency comparison and the simulation show that it enjoys better performance than the previous pairing-based CLEKS schemes. In addition, we briefly introduce three extensions of the proposed CLEKS scheme. Yang Lu 0001, Jiguo Li 0001 |
Frontiers Inf. Technol. Electron. Eng. | 2 |
| 2019 | Hybrid Keyword-Field Search With Efficient Key Management for Industrial Internet of ThingsabstractEquipped with the emerging cloud computing, clients prefer to outsource the increasing number of Industrial Internet of things (IIoT) data to cloud to reduce the high storage and computation burden. However, existing searchable encryption (SE) schemes just apply to IIoT records containing textual keyword fields rather than both digital and textual keyword ones. Besides, the key management issue still impedes the practicality and availability of SE schemes due to high key storage overhead. To this end, we present an outsourced Hybrid Keyword-Field Search over encrypted data with efficient Keys Management (HKFS-KM) scheme by utilizing the relevance score function and keyed hash tree. Formal security analysis proves that the HKFS-KM scheme can achieve keyword privacy and trapdoor unlinkability in both known ciphertexts attack model and known background attack model. Experimental results using real-world dataset show its efficiency and practicality in practice. Yinbin Miao, Ximeng Liu, Robert H. Deng, Hongjun Wu 0001, Hongwei Li 0001, Jiguo Li 0001, Dapeng Wu 0002 |
IEEE Trans. Ind. Informatics | 6 |
| 2018 | Cryptanalysis and Improvement for Certificateless Aggregate SignatureabstractIn order to satisfy application in resource constrained environment, aggregate signature schemes have been widely investigated. Recently, He et al. pointed out that certificateless aggregate signature (CLAS) scheme proposed by Xiong et al. was insecure against the Type II adversary and presented an possible improvement. In this article, we show that their improved scheme is not secure against a malicious-but-passive KGC attack. We analyze attack reason and propose an improved certificateless aggregate signature scheme. Based on the CDH difficult problem assumption, the proposed CLAS scheme is existentially unforgeable against adaptive chosen-message attacks in the random oracle model. Jiguo Li 0001, Yichen Zhang 0003 |
Fundam. Informaticae | 1 |
| 2018 | Anonymous certificate-based broadcast encryption with constant decryption cost
Jiguo Li 0001, Liqing Chen, Yang Lu 0001, Yichen Zhang 0003 |
Inf. Sci. | 1 |
| 2018 | Identity-based broadcast encryption with continuous leakage resilience
Jiguo Li 0001, Qihong Yu, Yichen Zhang 0003 |
Inf. Sci. | 1 |
| 2018 | Two-Party Attribute-Based Key Agreement Protocol with Constant-Size Ciphertext and KeyabstractBased on mutual authentication, the session key is established for communication nodes on the open network. In order to satisfy fine-grained access control for cloud storage, the two-party attribute-based key agreement protocol (TP-AB-KA) was proposed. However, the existing TP-AB-KA protocol is high in the cost of computation and communication and is not unfit for application in a mobile cloud setting because mobile devices are generally resource constrained. To solve the above issue, we propose a TP-AB-KA protocol with constant-size ciphertext and key. Our TP-AB-KA protocol is provable security in the standard model. The concrete proof is given under the augmented multisequence of exponents' decisional Diffie-Hellman (aMSE-DDH) hypothesis in the attribute-based BJM model (AB-BJM). Compared with the existing TP-AB-KA protocols, the computation cost and communication cost of our protocol are largely reduced. Jiguo Li 0001, Shengzhou Hu, Yichen Zhang 0003 |
Secur. Commun. Networks | 1 |
| 2018 | Expressive attribute-based keyword search with constant-size ciphertext
Jinguang Han, Joseph K. Liu, Jiguo Li 0001, Kaitai Liang, Jian Shen 0001 |
Soft Comput. | 4 |
| 2018 | Provably secure certificate-based encryption with leakage resilience
Yuyan Guo, Jiguo Li 0001, Yang Lu 0001, Yichen Zhang 0003, Futai Zhang |
Theor. Comput. Sci. | 2 |
| 2017 | Weakness and Improvement of a Certificate-Based Key-Insulated Signature in the Standard ModelabstractCertificate-based cryptography is a novel cryptographic primitive that has many attractive merits. It solves the certificate revocation problem in conventional public key cryptography and overcomes the key-escrow problem in identity-based cryptography. Recently, Li et al. presented a certificate-based key-insulated signature (CBKIS) scheme in the standard model. However, their scheme suffers from a security vulnerability caused by the malicious certification authority (CA) attack. Our cryptanalysis shows that a malicious CA is able to break its unforgeability by implanting some trapdoors in the public system parameters. To remedy the security weakness in Li et al.’s scheme, we put forward an improved CBKIS scheme. Under the complexity assumption of the square computational Diffie–Hellman problem, the improved scheme is proven to be existentially unforgeable in the standard model. Compared with the original CBKIS scheme proposed by Li et al., it enjoys better performance while offering stronger security guarantee as it can resist the malicious CA attack. Yang Lu 0001, Jiguo Li 0001, Jian Shen 0001 |
Comput. J. | 2 |
| 2017 | Verifiable Outsourced Decryption of Attribute-Based Encryption with Constant Ciphertext LengthabstractOutsourced decryption ABE system largely reduces the computation cost for users who intend to access the encrypted files stored in cloud. However, the correctness of the transformation ciphertext cannot be guaranteed because the user does not have the original ciphertext. Lai et al. provided an ABE scheme with verifiable outsourced decryption which helps the user to check whether the transformation done by the cloud is correct. In order to improve the computation performance and reduce communication overhead, we propose a new verifiable outsourcing scheme with constant ciphertext length. To be specific, our scheme achieves the following goals. (1) Our scheme is verifiable which ensures that the user efficiently checks whether the transformation is done correctly by the CSP. (2) The size of ciphertext and the number of expensive pairing operations are constant, which do not grow with the complexity of the access structure. (3) The access structure in our scheme is AND gates on multivalued attributes and we prove our scheme is verifiable and it is secure against selectively chosen-plaintext attack in the standard model. (4) We give some performance analysis which indicates that our scheme is adaptable for various limited bandwidth and computation-constrained devices, such as mobile phone. Jiguo Li 0001, Fengjie Sha, Yichen Zhang 0003, Xinyi Huang 0001, Jian Shen 0001 |
Secur. Commun. Networks | 1 |
| 2017 | A Novel Efficient Remote Data Possession Checking Protocol in Cloud StorageabstractAs an important application in cloud computing, cloud storage offers user scalable, flexible, and high-quality data storage and computation services. A growing number of data owners choose to outsource data files to the cloud. Because cloud storage servers are not fully trustworthy, data owners need dependable means to check the possession for their files outsourced to remote cloud servers. To address this crucial problem, some remote data possession checking (RDPC) protocols have been presented. But many existing schemes have vulnerabilities in efficiency or data dynamics. In this paper, we provide a new efficient RDPC protocol based on homomorphic hash function. The new scheme is provably secure against forgery attack, replace attack, and replay attack based on a typical security model. To support data dynamics, an operation record table (ORT) is introduced to track operations on file blocks. We further give a new optimized implementation for the ORT, which makes the cost of accessing ORT nearly constant. Moreover, we make the comprehensive performance analysis, which shows that our scheme has advantages in computation and communication costs. Prototype implementation and experiments exhibit that the scheme is feasible for real applications. Jiguo Li 0001, Jinguang Han, Yichen Zhang 0003 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | KSF-OABE: Outsourced Attribute-Based Encryption with Keyword Search Function for Cloud StorageabstractCloud computing becomes increasingly popular for data owners to outsource their data to public cloud servers while allowing intended data users to retrieve these data stored in cloud. This kind of computing model brings challenges to the security and privacy of data stored in cloud. Attribute-based encryption (ABE) technology has been used to design fine-grained access control system, which provides one good method to solve the security issues in cloud setting. However, the computation cost and ciphertext size in most ABE schemes grow with the complexity of the access policy. Outsourced ABE (OABE) with fine-grained access control system can largely reduce the computation cost for users who want to access encrypted data stored in cloud by outsourcing the heavy computation to cloud service provider (CSP). However, as the amount of encrypted files stored in cloud is becoming very huge, which will hinder efficient query processing. To deal with above problem, we present a new cryptographic primitive called attribute-based encryption scheme with outsourcing key-issuing and outsourcing decryption, which can implement keyword search function (KSF-OABE). The proposed KSF-OABE scheme is proved secure against chosen-plaintext attack (CPA). CSP performs partial decryption task delegated by data user without knowing anything about the plaintext. Moreover, the CSP can perform encrypted keyword search without knowing anything about the keywords embedded in trapdoor. Jiguo Li 0001, Xiaonan Lin, Yichen Zhang 0003, Jinguang Han |
IEEE Trans. Serv. Comput. | 1 |
| 2017 | Flexible and Fine-Grained Attribute-Based Data Storage in Cloud ComputingabstractWith the development of cloud computing, outsourcing data to cloud server attracts lots of attentions. To guarantee the security and achieve flexibly fine-grained file access control, attribute based encryption (ABE) was proposed and used in cloud storage system. However, user revocation is the primary issue in ABE schemes. In this article, we provide a ciphertext-policy attribute based encryption (CP-ABE) scheme with efficient user revocation for cloud storage system. The issue of user revocation can be solved efficiently by introducing the concept of user group. When any user leaves, the group manager will update users' private keys except for those who have been revoked. Additionally, CP-ABE scheme has heavy computation cost, as it grows linearly with the complexity for the access structure. To reduce the computation cost, we outsource high computation load to cloud service providers without leaking file content and secret keys. Notably, our scheme can withstand collusion attack performed by revoked users cooperating with existing users. We prove the security of our scheme under the divisible computation Diffie-Hellman assumption. The result of our experiment shows computation cost for local devices is relatively low and can be constant. Our scheme is suitable for resource constrained devices. Jiguo Li 0001, Yichen Zhang 0003, Huiling Qian, Jinguang Han |
IEEE Trans. Serv. Comput. | 1 |
| 2016 | Certificate-Based Key-Insulated Signature in the Standard ModelabstractThe key-insulated signature scheme provides a good method to solve key exposure problem. The key-insulated mechanism has been extended to the identity-based cryptography (IBC) and certificateless cryptography. As a new cryptographic primitive, certificate-based cryptography has unique advantage without key escrow problem in IBC and the complex certificate management problem in traditional PKI. However, certificate-based signature operations are usually performed on insecure environments where the signature key exposure is inevitable. In order to solve this problem, we intro- duce key-insulated idea into certificate-based cryptography and propose the notion and security model of the certificate-based key-insulated signature (CBKIS). In addition, we present a CBKIS scheme that is provably secure in the standard model. Security of scheme is reduced to the hardness of Non Pairing-based Generalized Bilinear DH problem and Many Diffie–Hellman problem. The proposed scheme solves the key exposure problem and improves the security in certificate-based cryptography. Jiguo Li 0001, Haiting Du, Yichen Zhang 0003 |
Comput. J. | 1 |
| 2016 | A Leakage-Resilient CCA-Secure Identity-Based Encryption SchemeabstractIdentity-based encryption (IBE) has many appealing applications. However, some traditional IBE schemes may not be secure in the real world due to the side-channel attacks. Leakage-resilient cryptography can capture these attacks by modeling information leakage that adversary can access. In this paper, we apply a hash proof technique in the existing CCA-secure variant of the Gentry's IBE scheme to construct a new leakage-resilient IBE scheme in the bounded-leakage model. The proposed scheme is more computationally efficient than the original Alwen et al. 's leakage-resilient IBE scheme. It enjoys a shorter key (public/secret key) length, and a higher relative key leakage ratio. The new leakage-resilient scheme is proved semantically secure against adaptive chosen ciphertext attack in the standard model under the truncated augmented bilinear Diffie-Hellman exponent ( |$q$| -TABDHE) assumption. Jiguo Li 0001, Meilin Teng, Yichen Zhang 0003, Qihong Yu |
Comput. J. | 1 |
| 2016 | A pairing-free certificate-based proxy re-encryption scheme for secure data sharing in public clouds
Yang Lu 0001, Jiguo Li 0001 |
Future Gener. Comput. Syst. | 2 |
| 2016 | Improved certificate-based signature scheme without random oraclesabstractCertificate‐based cryptography is a useful primitive that combines traditional public key cryptography (PKC) and identity‐based cryptography (IBC). It not only solves the key escrow problem inherent in IBC, but also simplifies the certificate problem in traditional PKC. So far, several certificate‐based signature (CBS) schemes have been proposed in the literature. However, none of them consider the malicious certificate authority (CA) attack. Cryptanalysis shows that two previous CBS schemes without random oracles fail in achieving unforgeability under such attack. To overcome the security weakness in these schemes, the authors propose an improved CBS scheme that can withstand malicious CA attacks. They prove it to be existentially unforgeable against chosen message attacks under the computational Diffie–Hellman assumption in the standard model. Compared with the previous standard‐model CBS schemes, the proposed scheme has obvious advantages in both the computation and communication efficiency. Yang Lu 0001, Jiguo Li 0001 |
IET Inf. Secur. | 2 |
| 2016 | Accountable mobile E-commerce scheme via identity-based plaintext-checkable encryption
Jinguang Han, Xinyi Huang 0001, Tsz Hon Yuen, Jiguo Li 0001, Jie Cao 0001 |
Inf. Sci. | 5 |
| 2016 | Continuous leakage-resilient certificate-based encryption
Jiguo Li 0001, Yuyan Guo, Qihong Yu, Yang Lu 0001, Yichen Zhang 0003, Futai Zhang |
Inf. Sci. | 1 |
| 2016 | A provably secure certificate-based encryption scheme against malicious CA attacks in the standard model
Yang Lu 0001, Jiguo Li 0001 |
Inf. Sci. | 2 |
| 2016 | Comment on a certificateless one-pass and two-party authenticated key agreement protocol
Yang Lu 0001, Quanling Zhang, Jiguo Li 0001, Jian Shen 0001 |
Inf. Sci. | 3 |
| 2016 | Certificate-based encryption resilient to key leakage
Qihong Yu, Jiguo Li 0001, Yichen Zhang 0003, Wei Wu 0001, Xinyi Huang 0001, Yang Xiang 0001 |
J. Syst. Softw. | 2 |
| 2016 | Hierarchical attribute-based encryption with continuous auxiliary inputs leakageabstractAbstract The continuous auxiliary inputs leakage is more strong side‐channel attacks. In this article, we first propose a continuous auxiliary inputs leakage model for the hierarchical attribute‐based encryption scheme. Under the security model, an adversary has ability to gain partial updated master keys and updated secret keys continually by certain leakage attacks. Moreover, a resilient‐leakage hierarchical attribute‐based encryption scheme is constructed. The security proof for this scheme is provided under the standard model. Furthermore, we give the performance comparison between our scheme and relevant scheme. Copyright © 2016 John Wiley & Sons, Ltd. Yuyan Guo, Jiguo Li 0001, Yichen Zhang 0003, Jian Shen 0001 |
Secur. Commun. Networks | 2 |
| 2016 | Provably secure identity-based encryption resilient to post-challenge continuous auxiliary input leakageabstractThe situation for post-challenge continuous auxiliary input leakage has not been considered in the cryptography schemes for previous literature. We present a semantic-security model with post-challenge continuous auxiliary inputs for identity-based encryption. In this model, the adversary is permitted to obtain some information of the private keys constantly and to query more information after seeing the challenge ciphertext through the side-channel attacks. Furthermore, we present an identity-based encryption scheme resilient to leakage under composite order groups. Our scheme is secure against post-challenge continuous auxiliary input, adaptive chosen-identity, and adaptive chosen plaintext attacks under three static assumptions in the standard model. Compared with existing identity-based encryption schemes under security properties and performance, our scheme is practical. Copyright © 2015 John Wiley & Sons, Ltd. Jiguo Li 0001, Yuyan Guo, Qihong Yu, Yang Lu 0001, Yichen Zhang 0003 |
Secur. Commun. Networks | 1 |
| 2016 | ABKS-CSC: attribute-based keyword search with constant-size ciphertextsabstractAbstract Attribute‐based keyword search (ABKS) was proposed to enable a third party to search encrypted keywords without compromising the security of the original data. Because it can express flexible access policy, ABKS has attracted a lot of attention. Existing ABKS schemes mainly focused on the expression of access structures, while the computation cost and communication cost are linear with the number of required attributes. Therefore, existing ABKS schemes are unsuitable to the devices that have constrained space and computing power, such as smart phone and tablet. In this paper, an ABKS with constant‐size ciphertext scheme is proposed. The proposed scheme captures the following nice features: (1) The index encryption algorithm has constant computation cost; (2) the searchable ciphertexts are constant size; (3) the trapdoors for keywords are constant size; and (4) the test algorithm has constant computation cost. To the best of our knowledge, it is the first time that an ABKS with constant‐size ciphertext scheme is proposed. Copyright © 2016 John Wiley & Sons, Ltd. Jinguang Han, Willy Susilo, Tsz Hon Yuen, Jiguo Li 0001 |
Secur. Commun. Networks | 5 |
| 2016 | Provably secure certificateless proxy signature scheme in the standard model
Yang Lu 0001, Jiguo Li 0001 |
Theor. Comput. Sci. | 2 |
| 2015 | Private Certificate-Based Remote Data Integrity Checking in Public Clouds
Huaqun Wang, Jiguo Li 0001 |
COCOON | 2 |
| 2015 | A Forward-Secure Certificate-Based Signature SchemeabstractCryptographic computations are often carried out on insecure devices for which the threat of key exposure raises a serious concern. In an effort to address the key exposure problem, the notion of forward security was first presented by Günther in 1990. In a forward-secure scheme, secret keys are updated at regular periods of time; exposure of the secret key corresponding to a given time period does not enable an adversary to ‘break’ the scheme for any prior time period. In this paper, we first introduce forward security into certificate-based cryptography and define the security model of forward-secure certificate-based signatures (CBSs). Then we propose a forward-secure CBS scheme, which is shown to be secure against adaptive chosen message attacks under the computational Diffie–Hellman assumption in the random oracle model. Our result can be viewed as the first step toward solving the key exposure problem in CBSs and thus improving the security of the whole system. Jiguo Li 0001, Huiyun Teng, Xinyi Huang 0001, Yichen Zhang 0003, Jianying Zhou 0001 |
Comput. J. | 1 |
| 2015 | Certificateless online/offline signcryption schemeabstractAbstract Signcryption is a highly efficient approach to achieve simultaneously confidentiality and authentication of message, which is more feasible than the simple combination of encryption and signature. The online/offline cryptography can further enhance the efficiency of signcryption system process without affecting its security. At present, most online/offline signcryptions focus on the ID‐based setting. However, the key escrow problem is inherent in ID‐based cryptography, which is regarded as the main barrier to affect the implementation of system. In this paper, we propose a brand new certificateless online/offline signcryption scheme. We prove the security of our scheme under q‐mBDHI, CDH and q‐CAA assumptions in the random oracle model. The proposed scheme overcomes the key escrow problem in the ID‐based setting. Copyright © 2014 John Wiley & Sons, Ltd. Jiguo Li 0001, Yichen Zhang 0003 |
Secur. Commun. Networks | 1 |
| 2015 | Leakage-resilient certificate-based encryptionabstractAbstract Certificate‐based encryption is a new cryptography primitive, which can be used to construct efficient public key infrastructure. However, side‐channel attacks are not considered in certificate‐based encryption. In order to capture these attacks, we formalize security model of certificate‐based encryption with leakage resilience. Furthermore, we present a leakage‐resilient certificate‐based encryption (LR‐CBE) scheme. To the best of our knowledge, this is the first LR‐CBE scheme. Based on decision bilinear Diffie‐Hellman assumption and decision generalized bilinear Diffie‐Hellman assumption, we prove that our scheme is secure against adaptive chosen ciphertext attacks in the random oracle model. Our scheme includes a certificate‐based key encapsulation algorithm and a symmetric encryption algorithm, where the encapsulated information is a symmetric key that is used to encrypt message. In order to obtain leakage‐resilient property, two‐source extractor is used to randomize the symmetric key. The designed scheme can resist entropy leakage. The performance analysis of leakage resilience shows that the relative leakage ratio almost amounts to 1. Copyright © 2015 John Wiley & Sons, Ltd. Qihong Yu, Jiguo Li 0001, Yichen Zhang 0003 |
Secur. Commun. Networks | 2 |
| 2014 | Certificate-Based Conditional Proxy Re-Encryption
Jiguo Li 0001, Xuexia Zhao, Yichen Zhang 0003 |
NSS | 1 |
| 2014 | Provably secure certificate-based key-insulated signature schemeabstractSUMMARY Certificate‐based signature computation is often performed on insecure devices where the signature key is easy to be exposed. To reduce the influence of key exposure, we introduce key‐insulated mechanism into certificate‐based cryptography and formalize the notion and security model of the certificate‐based key‐insulated signature scheme. We then present a certificate‐based key‐insulated signature scheme, which is proven to be existentially unforgeable against adaptive chosen message attacks in the random oracle model. The proposed scheme has potential applications in trusted computing. Copyright © 2013 John Wiley & Sons, Ltd. Jiguo Li 0001, Haiting Du, Yichen Zhang 0003, Yuexin Zhang |
Concurr. Comput. Pract. Exp. | 1 |
| 2013 | Privacy-Preserving Decentralized Ciphertext-Policy Attribute-Based Encryption with Fully Hidden Access Structure
Huiling Qian, Jiguo Li 0001, Yichen Zhang 0003 |
ICICS | 2 |
| 2013 | Forward Secure Certificateless Proxy Signature Scheme
Jiguo Li 0001, Yanqiong Li, Yichen Zhang 0003 |
NSS | 1 |
| 2013 | Provably secure certificate-based signature scheme without pairings
Jiguo Li 0001, Yichen Zhang 0003 |
Inf. Sci. | 1 |
| 2012 | An efficient short certificate-based signature scheme
Jiguo Li 0001, Xinyi Huang 0001, Yichen Zhang 0003 |
J. Syst. Softw. | 1 |
| 2010 | Constructions of certificate-based signature secure against key replacement attacksabstractIn Eurocrypt 2003, Gentry introduced the notion of certificate-based encryption. The merit of certificate-based encryption lies in the following features: (1) providing more efficient public-key infrastructure (PKI) that requires less infrastructure, (2) solving the certificate revocation problem, and (3) eliminating third-party queries in the traditional PKI. Additionally, it also offers the solution to the inherent key escrow problem in the identity-based cryptography. The contributions of this paper are threefold. Firstly, we introduce a new attack called the “Key Replacement Attack” into the certificate-based signature system and refine the security model of certificate-based signature. Secondly, we show that the certificate-based signature scheme presented by Kang, Park and Hahn in CT-RSA 2004 is insecure against key replacement attacks. Thirdly, we present two new certificate-based signature schemes secure against key replacement attacks. Our first scheme is existentially unforgeable against adaptive chosen message attacks under the computational Diffie–Hellman assumption in the random oracle model. Compared with the certificate-based signature scheme in CT-RSA 2004, our first scheme enjoys shorter signature length and less operation cost. Our second scheme is inspired by Waters signature and is the first construction of certificate-based signature secure against key replacement attacks in the standard model. Jiguo Li 0001, Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Qianhong Wu |
J. Comput. Secur. | 1 |
| 2009 | Forward-Secure Certificate-Based EncryptionabstractCertificate-based encryption (CBE) is a new paradigm which overcomes the shortcomings of traditional public-key encryption (PKE) and identity based encryption (IBE). CBE provides an efficient implicit certificate mechanism to eliminate third-party queries for the certificate status and to simplify the certificate revocation problem in traditional PKI. Therefore, CBE can be used to construct an efficient PKI requiring fewer infrastructures. It also solves the key escrow and key distribution problem inherent in IBE. In this paper, we introduce a new notion called Forward-Secure Certificate-Based Encryption. It preserves the advantages of CBE such as implicit certificate and no private key escrow. At the same time it also inherits the properties of the forward-secure public key encryption. We also propose a concrete and efficient forward-secure CBE scheme and prove it to be secure based on the bilinear Diffie-Hellman assumption in the random oracle model. Yang Lu 0001, Jiguo Li 0001 |
IAS | 2 |
| 2003 | Nonrepudiable Proxy Multi-Signature Scheme
Jiguo Li 0001, Zhenfu Cao, Yichen Zhang 0003 |
J. Comput. Sci. Technol. | 1 |