VLDB 2026 Research / reviewers in the wild / expert
Tianyu Zhaolu
dblp:336/4677
· DBLP profile ↗
6ranked-venue papers
4as first author
6since 2021 · last 2026
0009-0003-3996-5299ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Single Proof for Multi-Authentication: Decentralized Anonymous Functional Credentials Based on fNIZKabstractWeb3 has attracted considerable attention in fields including DeFi, DApps, and NFTs due to its decentralization, enhanced privacy, and user-centricity. However, interoperability and scalability challenges hinder its widespread adoption. While deploying anonymous credentials across Web3 networks to enable cross-network service access is a potential solution to these challenges, existing credential systems remain limited by centralized management, high energy consumption, and credential abuse, making them unsuitable for Web3 environments. To overcome these limitations, we propose a decentralized anonymous functional credential (DAFC) scheme that is efficient, privacy-preserving, and linkable. Unlike existing schemes, DAFC enables users to generate a single proof embedding attributes$x$for requesting services under different access policies. Each provider can use the functional key$sk_{F}$associated with their respective access policy$F$to extract$F(x)$for attribute verification. This significantly reduces authentication computational overhead. Furthermore, DAFC's linkability effectively mitigates credential abuse risks. As an additional contribution, we propose a novel construction of non-interactive zero-knowledge functional proof (fNIZK) based on one-out-of-many proofs and functional encryption for inner products, which is the building block of DAFC. Security analysis demonstrates that DAFC achieves anonymity, unforgeability, and linkability. Performance evaluation shows that DAFC outperforms prior schemes in both computational and communication overhead when requesting at least 6 services with distinct access policies. Tianyu Zhaolu, Huaqun Wang, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | ABP-DKM: An Efficient Decentralized Key Management Scheme Based on Asymmetric Bivariate PolynomialabstractWith the development of the industrial Internet, industrial Internet data has been growing rapidly, and so has the need for secure communications. In the context of industrial communication, it is essential to establish an effective session key between untrusted nodes. The prevailing key management schemes concentrate on key negotiation with the assistance of a central node through a man-in-the-middle approach. However, industrial field environments are typically characterised by harsh conditions, and any node may be damaged or subject to malicious compromise. This can result in the complete paralysis of communication within the entire system. Consequently, existing key management schemes are unable to fulfil the requisite performance requirements. In contrast to previous centralized or polycentric schemes, we propose an asymmetric bivariate polynomials-based novel efficient decentralized key management scheme (ABP-DKM). ABP-DKM achieves threshold switching through a twice-distribution method, which is more secure than other existing schemes. During the whole key negotiation process, ABP-DKM is decentralized. ABP-DKM is capable of not only peer-to-peer communication but also intra-group communication with forward and backward secrecy. The proposed scheme is more secure and efficient than the existing schemes. Yang Shi 0002, Huaqun Wang, Tianyu Zhaolu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | Post-Quantum Rollup: Falcon Signature Aggregation Based on SNARG With Enhanced GatesabstractBlockchain layer 2 solutions aim to address scalability issues in Layer 1 networks by improving transaction efficiency and alleviating congestion. The rollup, a well-known Layer 2 scaling protocol, uses an aggregate signature scheme based on the succinct non-interactive argument of knowledge (SNARG) to package transactions. The further promotion of rollup faces the challenge of balancing computation efficiency and communication costs. In addition, with the continuous development of quantum computing, a transition to post-quantum cryptography is considered crucial for long-term security. Our main contribution is an aggregate Falcon signature scheme for post-quantum rollup based on a novel SNARG scheme. The proposed SNARG is based on the Plonkish circuit with enhanced custom gates, referred to as the ECG circuit, and a post-quantum multilinear polynomial commitment scheme (PolyCom). The former can represent more complex operations while also controlling the witness scale. The latter realizes quantum-resistant security for the proposed SNARG and the aggregate signature. In comparison to the aggregate signature based on Orion, our scheme achieves lower aggregation and communication costs. Performance analysis indicates a 38 % decrease in aggregation time and a 88 % decrease in communication costs. As an additional contribution, we introduce a novel polynomial interactive oracle proof (PolyIOP) protocol for the ECG circuit, which can combine with a multilinear PolyCom scheme to form a SNARG protocol with lower computation and communication overhead compared to existing schemes. Tianyu Zhaolu, Zhiguo Wan, Huaqun Wang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Post-quantum anonymous authentication for Web3: a lattice-based decentralized linkable anonymous credential scheme
Tianyu Zhaolu, Huaqun Wang |
J. Supercomput. | 1 |
| 2024 | Pay-Per-Proof: Decentralized Outsourced Multi-User PoR for Cloud Storage Payment Using BlockchainabstractCloud computing has been widely applied in data storage, but cloud computing is not armed with an efficient integrity check mechanism for users to learn whether their large volumes of data have been kept intact by the cloud. The concept of proofs of retrievability (PoR) was introduced to address such an issue by enabling users to check the integrity of their data stored by the cloud. But PoR requires users to regularly send queries to the cloud, and its integrity check method cannot be extended to share the verification responsibility in the multi-user setting where different users store the same data to the cloud. With such concerns in mind, we put forth a notion called outsourced multi-user proofs of retrievability ($\mathtt {OMTPoR}$) which allows users with the same data stored by the cloud to share the information for the integrity check, and a third party is required to regularly check data integrity on behalf of users using the shared information. We give a concrete construction of$\mathtt {OMTPoR}$based on the homomorphic property of an existing property and analyze its security. To enforce honest integrity checks, we build the concrete$\mathtt {OMTPoR}$construction over the blockchain using smart contracts to guarantee the honesty of participants, yielding a decentralized outsourced multi-user PoR solution that utilizes the blockchain miners as the third parties. Furthermore, our solution enables the cloud server to obtain payment for the storage service if the PoR is verified by the miners. We fully implement the$\mathtt {OMTPoR}$scheme over the blockchain to evaluate its performance, which demonstrates obvious superiority over traditional PoR schemes without the detection of data duplication. Hui Cui 0001, Zhiguo Wan, Tianyu Zhaolu, Huaqun Wang, Atsuko Miyaji |
IEEE Trans. Cloud Comput. | 3 |
| 2024 | Division of Regulatory Power: Collaborative Regulation for Privacy-Preserving BlockchainsabstractDecentralized anonymous payment schemes may be exploited for illicit activities, such as money laundering, bribery and blackmail. To address this issue, several regulatory-friendly decentralized anonymous payment schemes have been proposed. However, most of these solutions lack restrictions on the regulator’s authority, which could potentially result in power abuse and privacy breaches. In this paper, we present a decentralized anonymous payment scheme with collaborative regulation (DAPCR). Unlike existing solutions, DAPCR reduces the risk of power abuse by distributing regulatory authority to two entities: Filter and Supervisor, neither of which can decode transactions to access transaction privacy without the assistance of the other one. Our scheme enjoys three major advantages over others: 1) Universality, achieved by using zk-SNARK to extend privacy-preserving transactions for regulation. 2) Collaborative regulation, attained by adding the ring signature with controllable linkability to the transaction. 3) Efficient aggregation of payment amounts, achieved through amount tags. As a key technology for realizing collaborative regulation in DAPCR, the ring signature with controllable linkability (CLRS) is proposed, where a user needs to specify a linker and an opener to generate a signature. The linker can extract pseudonyms from signatures and link signatures submitted by the same signer based on pseudonyms, without leaking the signer’s identity. The opener can recover the signer’s identity from a given pseudonym. The experimental results reflect the efficiency of DAPCR. The time overhead for transaction generation is 1231.2ms, representing an increase of less than 50% compared to ZETH. Additionally, the time overhead for transaction verification is only 1.2ms. Tianyu Zhaolu, Zhiguo Wan, Huaqun Wang |
IEEE Trans. Inf. Forensics Secur. | 1 |