VLDB 2026 Research / reviewers in the wild / expert
Chun-I Fan
dblp:34/1432
· DBLP profile ↗
45ranked-venue papers
33as first author
13since 2021 · last 2026
0000-0002-7512-1291ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 11 first-author · 6 since 2021Computer networks · 13 · 10 first-author · 4 since 2021Systems, architecture and hardware · 7 · 6 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Maliciously Secure and Fully Decentralized Threshold FHE Scheme with Native RNS Acceleration
Ting-Yu Chen 0001, Arijit Karati, Er-Shuo Zhuang, Chun-I Fan |
SECRYPT (1) | 4 |
| 2025 | Attribute-Based Encryption Supporting Multi-Keyword Search With Effective User Revocation in Public Cloud StorageabstractCloud computing has become a prevalent service for data proprietors to outsource their data to public cloud servers while allowing data consumers to retrieve cloud-stored data. While encrypting cloud data helps individuals ensure the security and privacy of cloud data, all-or-nothing encryption hinders effective access control and data search. To address this issue, this paper proposes fine-grained attribute-based encryption supporting multi-keyword-based data search to circumvent critical issues, including the assumption of online third-party authority, expensive user revocation, and a lack of expressiveness on keyword search problems. The proposed protocol empowers users to authorize cloud servers to perform keyword searches on encrypted data without forfeiting data privacy. Besides, the length of the ciphertext and the user key is short and fixed, having no noteworthy impact on the user growth in the system. The proposed protocol is formally secure against the indistinguishability under chosen-plaintext (IND-CPA) attack under the standard model with the generalized decisional Diffie-Hellman assumption. The comprehensive performance analysis of the proposed scheme demonstrates that it outperforms state-of-the-art solutions. Thus, our system is suitable for real-world applications due to its enhanced security characteristics, adaptability, and efficacy. Chun-I Fan, Si-Jing Wu, Yi-Fan Tseng, Arijit Karati |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | PISTON: PUF-Integrated Secure, Throughput-Optimized Network Protocol for IoVabstractThis research introduces PISTON, a novel protocol designed to enhance the security, efficiency, and performance of Internet of Vehicles (IoV) networks. PISTON integrates advanced authentication mechanisms utilizing Physically Unclonable Functions (PUFs) and multifactor authentication with dynamic challenges and zero-knowledge proof-based authentication to ensure robust security and mitigate various cyber threats, including Denial-of-Service (DoS) attacks. The protocol further incorporates sleep-wake scheduling, priority-based scheduling, and adaptive modulation and coding to optimize network performance. The communication overhead in PISTON is derived through a formula that incorporates latency, energy consumption, and throughput, demonstrating the protocol’s efficiency in dynamic vehicular environments. Comparative analysis against existing protocols highlights PISTON’s superiority in seamless handover, provable security, and DoS attack resilience. Experimental results show that PISTON reduces energy consumption by 30% and achieves 20% higher data throughput while maintaining low latency, essential for real-time IoV applications. The empirical findings underscore PISTON’s advancements in establishing a new benchmark for future IoV deployments, ensuring secure, energy-efficient, low-latency, and high-throughput communication. Koustav Kumar Mondal, Ashi Gupta, Debasis Das 0001, Chun-I Fan |
APCC | 4 |
| 2024 | CAKE-PUF: A Collaborative Authentication and Key Exchange Protocol Based on Physically Unclonable Functions for Industrial Internet of ThingsabstractThe Industrial Internet of Things (IIoT) is widely used in smart factories, enabling smart manufacturing and improving productivity. Although the application of IIoT has significantly altered a number of industries, increased connectivity has also given rise to security concerns. For example, information is collected from different domains in smart industrial environments and transmitted through public IoT channels. However, this phase can lead to communication security and privacy leakage issues when applied to resource-constrained smart industrial devices. This work proposes a novel collaborative authentication and key exchange protocol based on physically unclonable functions (PUFs) to enable safe and efficient communication amongst smart industrial devices in an IIoT context. The proposed protocol uses PUF to enhance the security of smart industrial devices. Additionally, to mitigate difficult situations, such as device loss, the proposed protocol combines an elliptic curve Diffie-Hellman key exchange scheme to achieve forward security and collaborative authentication between the domain server and smart industrial devices during the key exchange phase. We analyze and provide security proofs for the proposed protocol. Furthermore, performance analysis is conducted to evaluate the computational costs of the protocol. The results of this work contribute to the development of secure and reliable authentication and key exchange protocols within the context of IIoT, promoting the adoption of IIoT technology in smart factories while reducing potential security threats. Chun-I Fan, Chien-I Lai, Darshan Vishwasrao Medhane |
IEEE Internet Things J. | 1 |
| 2024 | A Privacy-Aware Provably Secure Smart Card Authentication Protocol Based on Physically Unclonable FunctionsabstractFor many industrial applications, the smart card is a necessary safety component in user authentication. Smart cards provided to the users are used in open and public places, making them susceptible to physical and cloning attacks. Thus, the opponent can break the authentication process without the smart card if the information is exposed. In addition, many existing authentication systems employ challenge-response pairs (CRPs) to identify users by creating large numbers of data on the server and spending much time looking for and comparing responses. To address these concerns, we propose a lightweight privacy-preserving authentication protocol in which the physically unclonable function is considered a necessary tool. The suggested technique avoids creating a significant number of CRPs on the server to identify users uniquely. Under formal security models, the proposed protocol is resistant to user impersonation attacks and session key disclosure attacks and achieves robust mutual authentication. Nonetheless, it is immune to other essential security vulnerabilities. Empirical performance analysis demonstrates its viability in comparison to prior works. Chun-I Fan, Arijit Karati, Shou-Li Wu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | An Efficient Data Protection Scheme Based on Hierarchical ID-Based Encryption for MQTTabstractAs Internet of Things (IoT) thrives over the whole world, more and more IoT devices and IoT-based protocols have been designed and proposed in order to meet people’s needs. Among those protocols, message queueing telemetry transport (MQTT) is one of the most emerging and promising protocols, which provides many-to-many message transmissions based on the “publish/subscribe” mechanism. It has been widely used in industries such as the energy industry, chemical engineering, self-driving, and so on. While transporting important messages, MQTT specification recommends the use of TLS protocol. However, the computation cost of TLS is too heavy. Since topics in a broker are stored with a hierarchical structure, in this manuscript, we propose a novel data protection protocol for MQTT from hierarchical ID-based encryption. Our protocol adopts the intrinsic hierarchical structures of MQTT, and achieves constant-size keys, i.e., independent of the depth in hierarchical structures. Besides, the formal security model for the proposed protocol have been defined in the manuscript. The proposed protocol have been formally proven chosen-plaintext secure under the ℓ-wBDHI assumption. Chun-I Fan, Cheng-Han Shie, Yi-Fan Tseng, Hui-Chun Huang |
ACM Trans. Sens. Networks | 1 |
| 2022 | Fast keyword search over encrypted data with short ciphertext in clouds
Yi-Fan Tseng, Chun-I Fan, Zi-Cheng Liu 0001 |
J. Inf. Secur. Appl. | 2 |
| 2022 | Reliable Data Sharing by Certificateless Encryption Supporting Keyword Search Against Vulnerable KGC in Industrial Internet of ThingsabstractOutsourcing Industrial Internet of Things (IIoT) data on the cloud extends the diversity of data analysis for decision making with minimized costs in communications and storage. However, it is adverse to the confidentiality of IIoT data from the owner as access control is performed by honest-but-curious platforms. Although the encryption strategy guarantees data security, it hinders deliverance due to its inbred all-or-nothing decryption. Certificateless encryption supporting keyword search eliminates the overhead of certificates and privileges to retrieve the required data through encrypted keyword search. However, most of the prior works are precarious against a malicious key generation center, which exposes data protected by users’ private keys. We design a certificateless secure data sharing by uniting the functionalities of encryption and access control on search. Our technique resists in/outside keyword guessing attacks and sustains on-demand user revocation. Besides, it achieves Girault’s Level-3 security in the standard model. Nonetheless, empirical performance analysis under a suitable scenario exhibits its feasibility compared to the other related schemes. Arijit Karati, Chun-I Fan, Er-Shuo Zhuang |
IEEE Trans. Ind. Informatics | 2 |
| 2022 | ID-Based Multireceiver Homomorphic Proxy Re-Encryption in Federated LearningabstractData privacy has become a growing concern with advances in machine learning. Federated learning (FL) is a type of machine learning invented by Google in 2016. In FL, the main aim is to train a high-accuracy global model by aggregating the local models uploaded by participants, and all data in the process are kept locally. However, compromises to security in the cloud server or among participants render this process insufficiently secure. To solve the problem, this article presents an identity-based multireceiver homomorphic proxy re-encryption (IMHPRE) scheme that utilizes homomorphism operations and re-encryption to provide improved encrypted-data processing and access control. When this scheme is employed, participants can directly use public identities for encryption. The IMHPRE scheme is also secure against the chosen-plaintext attacks. Comparison results indicated that the IMHPRE outperforms its counterparts because it allows a cloud server to perform model aggregation on re-encrypted models for multiple receivers. Chun-I Fan, Ya-Wen Hsu, Cheng-Han Shie, Yi-Fan Tseng |
ACM Trans. Sens. Networks | 1 |
| 2021 | Reliable file transfer protocol with producer anonymity for Named Data Networking
Chun-I Fan, Arijit Karati, Pei-Shan Yang |
J. Inf. Secur. Appl. | 1 |
| 2021 | Anonymous Multireceiver Identity-Based Encryption against Chosen-Ciphertext Attacks with Tight Reduction in the Standard ModelabstractMultireceiver identity-based encryption is a cryptographic primitive, which allows a sender to encrypt a message for multiple receivers efficiently and securely. In some applications, the receivers may not want their identities to be revealed. Motivated by this issue, in 2010, Fan et al. first proposed the concept of anonymous multireceiver identity-based encryption (AMRIBE). Since then, lots of literature studies in this field have been proposed. After surveying the existing works, however, we found that most of them fail to achieve provable anonymity with tight reduction. A security proof with tight reduction means better quality of security and better efficiency of implementation. In this paper, we focus on solving the open problem in this field that is to achieve the ANON-IND-CCA security with tight reduction by giving an AMRIBE scheme. The proposed scheme is proven to be IND-MID-CCA and ANON-MID-CCA secure with tight reduction under a variant of the DBDH assumption. To the best of our knowledge, this is the first scheme proven with tight reducible full CCA security in the standard model. Yi-Fan Tseng, Chun-I Fan |
Secur. Commun. Networks | 2 |
| 2021 | Dependable Data Outsourcing Scheme Based on Cloud-of-Clouds Approach with Fast RecoveryabstractCloud computing is increasingly popular today. Cloud services such as data-outsourcing services provide a growing number of users access to cloud storage for large quantities of data, and enterprises are turning to cloud storage for cost-effective remote backup. In 2011, DEPSKY shows and overcomes four limitations hinder the effectiveness of cloud storage: loss of availability, loss and corruption of data, loss of privacy, and vendor lock-in. Unfortunately, DEPSKY lacks an error detection mechanism and comes with heavy computing costs. Therefore, we propose a new data-outsourcing scheme overcoming not only the four limitations, but also the shortcomings of DEPSKY. In this paper, we modify Nyberg's accumulator and apply it to our three proposed error-detection methods. Moreover, we specially design a fast recovery method that is faster than DEPSKY and alternative methods. Chun-I Fan, Jheng-Jia Huang, Shang-Wei Tseng, I-Te Chen |
IEEE Trans. Cloud Comput. | 1 |
| 2021 | Cross-Network-Slice Authentication Scheme for the 5th Generation Mobile Communication SystemabstractThe fifth-generation mobile network (5G) integrates various application services in a heterogeneous network environment. Compared to the traditional networks, 5G is not just an extension of the 4th generation, which contains three important properties, enhanced mobile broadband (eMBB), massive machine type communications (mMTC), and ultra-reliable and low latency communications (URLLC). 5G applies the functionalities of Network Function Virtualization and Software-Defined Networking to support multiple services and proposes a new concept called Network Slicing. Users can access different services quickly in the 5G network supported by network slicing. In a traditional network like 4G, if a user wants to access different services, it will be necessary to perform different authentication procedures that cause additional burden and operation cost in the user's device. However, the 5G network inherits the previous network architecture. Hence, the user's device still needs to be authenticated by the core network. Besides, providing a guarantee of connecting to a correct network slice is one of the prime concerns. The paper presents an authentication scheme tailored for the 5G network. In the proposed scheme, the authentication is decentralized to the edge clouds to achieve low latency. Moreover, the authentication flow is no longer attached to the operator all the time to reduce time latency. The proposed scheme is secure against the attackers who aim to impersonate users, network operators, or even network slices, and it also provides secure session key exchange. Empirical performance assessment in terms of its functionalities gains better acceptability of the proposed scheme than other existing ones. Chun-I Fan, Yu-Tse Shih, Jheng-Jia Huang, Wan-Ru Chiu |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2020 | ReHand: Secure Region-Based Fast Handover With User Anonymity for Small Cell Networks in Mobile CommunicationsabstractDue to the fact that the higher density of mobile devices is expected, the fifth generation (5G) mobile networks introduce small cell networks (SCNs) to prevent exhausting radio resources. SCNs improve radio spectrum utilization by deploying more base stations (BSs) in the networks. Even though authenticated key exchange (AKE) is still essential to ensure entity authentication and confidentiality in mobile communications. Besides, user anonymity is required to guarantee the footprints of mobile communications being concealed. However, AKE with user anonymity may increase the latency of communications dramatically in total due to several times more frequency in SCNs. The increase of latency will be more serious when an AKE protocol supports user anonymity, where traceability and revocability to users are necessary. Thus, this paper presents a secure region-based handover scheme (ReHand) with user anonymity and fast revocation for SCNs. ReHand greatly reduces the communication latency when user equipments (UEs) roam between small cells within the region of a macro BS, i.e., eNB, and the computation costs due to the employment of symmetry-based cryptographic operations. Compared to the three related prior arts, ReHand dramatically reduces the latency from 82.92% to 99.99% by region-based secure handover. Nevertheless, this paper demonstrates the security of ReHand by theoretically formal proofs. Chun-I Fan, Jheng-Jia Huang, Min-Zhe Zhong, Ruei-Hau Hsu, Wen-Tsuen Chen, Jemin Lee 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | Provably Secure and Generalized Signcryption With Public Verifiability for Secure Data Transmission Between Resource-Constrained IoT DevicesabstractThe Internet of Things (IoT) is revolutionizing our modern lives by introducing active connection between smart devices. However, IoT devices are repeatedly exhibiting many security flaws, which will inevitably lead to eavesdropping and impersonation attacks. Thus, providing a proper security in IoT becomes a prime focus for the researchers. In cryptography, certificateless signcryption (CLSC) is one of the recent public key techniques for the security requirements of the authenticity and confidentiality of any message between the parties. In this article, a new generalized CLSC (gCLSC) is introduced to provide the functions of digital signature and encryption to fulfill the authenticity and confidentiality for the resource-constrained IoT devices. Besides, the gCLSC supports the property of public verifiability and security of an ideal signcryption under the strong Diffie-Hellman and bilinear Diffie-Hellman inversion problems without random oracle model. Performance assessment of the gCLSC gives satisfactory results after comparing with other competitive CLSC schemes in terms of its functionality. Therefore, the gCLSC can be adopted in the IoT networks where authenticity, confidentiality, and lightweight are the essential factors. Arijit Karati, Chun-I Fan, Ruei-Hau Hsu |
IEEE Internet Things J. | 2 |
| 2019 | A Practical Privacy-Preserving Data Aggregation (3PDA) Scheme for Smart GridabstractThe real-time electricity consumption data can be used in value-added service such as big data analysis, meanwhile the single user's privacy needs to be protected. How to balance the data utility and the privacy preservation is a vital issue, where the privacy-preserving data aggregation could be a feasible solution. Most of the existing data aggregation schemes rely on a trusted third party (TTP). However, this assumption will have negative impact on reliability, because the system can be easily knocked down by the denial of service attack. In this paper, a practical privacy-preserving data aggregation scheme is proposed without TTP, in which the users with some extent trust construct a virtual aggregation area to mask the single user's data, and meanwhile, the aggregation result almost has no effect for the data utility in large scale applications. The computation cost and communication overhead are reduced in order to promote the practicability. Moreover, the security analysis and the performance evaluation show that the proposed scheme is robust and efficient. Yi-Ning Liu 0002, Wei Guo 0012, Chun-I Fan, Liang Chang 0003, Chi Cheng 0003 |
IEEE Trans. Ind. Informatics | 3 |
| 2019 | FGAC-NDN: Fine-Grained Access Control for Named Data NetworksabstractNamed data network (NDN) is one of the most promising information-centric networking architectures, where the core concept is to focus on the named data (or contents) themselves. Users in NDN can easily send a request packet to get the desired content regardless of its address. The routers in NDN have cache functionality to make the users instantly retrieve the desired file. Thus, the user can immediately get the desired file from the nearby nodes instead of the remote host. Nevertheless, NDN is a novel proposal and there are still some open issues to be resolved. In view of previous research, it is a challenge to achieve access control on a specific user and support potential receivers simultaneously. In order to solve it, we present a fine-grained access control mechanism tailored for NDN, supporting data confidentiality, potential receivers, and mobility. Compared to previous works, this is the first to support fine-grained access control and potential receivers. Furthermore, the proposed scheme achieves provable security under the DBDH assumption. Yi-Fan Tseng, Chun-I Fan, Chin-Yu Wu |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2018 | Privacy Preserved Spectral Analysis Using IoT mHealth Biomedical Data for Stress EstimationabstractIn recent years, quantitative analysis of sleep quality and stress estimation during sleep have been important social issues due to sleep deprivation. Conventionally, sleep quality is mainly subjectively evaluated by pittsburgh questionnaire, while stress is estimated by power spectral analysis of electrocardiogram. However, measurement is difficult during sleep since restrictions on respiration rate and body motion. Sleep depth transition presumable by heart rate variability is achieved, however, the correlation between heart rate and sleep quality during sleep is not clarified. In this paper, heart rate and sleep depth data are collected by wearable IoT devices. Then, stress index during sleep is estimated by autonomic balance evaluation index and correlation is analyzed using the collected biomedical data. Furthermore, homomorphic cryptography is applied to analysis for privacy preserving approach. Xuping Huang, Hiroaki Kikuchi, Chun-I Fan |
AINA | 3 |
| 2018 | Local Authentication and Access Control Scheme in M2M Communications With Computation OffloadingabstractLocal user access is important to machine-to-machine (M2M) communication because it possesses unique advantages over remote access in that it offers instant services, provides reliable connection, and offloads the traffic of M2M access networks. Local access control is also essential for authorized users to access M2M devices. In this paper, we propose a local authentication and access control scheme (LACS), which allows M2M devices to locally verify the access rights and access privileges of the users. In particular, the property of device heterogeneity is considered in our LACS. The resource-constrained M2M devices can securely outsource heavy computation to user equipment with or without the help of a gateway for energy saving. Our LACS satisfies the security criteria of: 1) user anonymity; 2) mutual authentication; 3) secure key agreement; and 4) securely outsourcing computation. All of these criteria are theoretically proved using a formal model. Experimental data also demonstrates the efficiency of the proposed LACS and the effectiveness of the design with regard to computation offloading. Yi-Hui Lin, Jheng-Jia Huang, Chun-I Fan, Wen-Tsuen Chen |
IEEE Internet Things J. | 3 |
| 2017 | Deniable Searchable Symmetric Encryption
Huige Li, Fangguo Zhang, Chun-I Fan |
Inf. Sci. | 3 |
| 2016 | Enabled/disabled predicate encryption in clouds
Shi-Yuan Huang, Chun-I Fan, Yi-Fan Tseng |
Future Gener. Comput. Syst. | 2 |
| 2016 | Privacy enhancement for fair PayWord-based micropaymentabstractA micropayment scheme provides a secure and efficient solution for electronic payment environments that require frequent transactions with nominal fees. It is particularly suitable for mobile applications in which a customer is charged for either time spent or data volume transferred. Most proposed micropayment schemes are based on by Rivest and Shamir. The security and efficiency of a micropayment scheme can be ensured by adopting the hash chain technique. Recent research on micropayment has introduced additional properties such as user anonymity and fairness. However, the existing schemes may lose efficiency and some of the original desirable properties of PayWord while achieving new ones. We propose an anonymous fair offline micropayment scheme that satisfies user anonymity and fairness and retains the efficiency and properties of PayWord, such as offline broker. A user can make multiple purchases from different vendors without interacting with the broker again. PayWord's postpaid mechanism is adopted in order to make our scheme more attractive to users. To the best of our knowledge, this is the first micropayment scheme to simultaneously offer the aforementioned properties. Copyright © 2012 John Wiley & Sons, Ltd. Chun-I Fan, Yu-Kuang Liang, Chien-Nan Wu |
Secur. Commun. Networks | 1 |
| 2014 | Arbitrary-State Attribute-Based Encryption with Dynamic MembershipabstractAttribute-based encryption (ABE) is an advanced encryption technology where the privacy of receivers is protected by a set of attributes. An encryptor can ensure that only the receivers who match the restrictions on predefined attribute values associated with the ciphertext can decrypt the ciphertext. However, maintaining the correctness of all users’ attributes will take huge cost because it is necessary to renew the users’ private keys whenever a user joins, leaves the group, or updates the value of any of her/his attributes. Since user joining, leaving, and attribute updating may occur frequently in real situations, membership management will become a quite important issue in an ABE system. In this paper, we will present an ABE scheme which is the first ABE scheme that aims at dynamic membership management with arbitrary states, not binary states only, for every attribute. Our work also keeps high flexibility of the constraints on attributes and makes users be able to dynamically join, leave, and update their attributes. It is unnecessary for those users who do not change their attribute statuses to renew their private keys when some user updates the values of her/his attributes. Finally, we also formally prove the security of the proposed scheme without using random oracles. Chun-I Fan, Vincent Shi-Ming Huang, He-Ming Ruan |
IEEE Trans. Computers | 1 |
| 2014 | Privacy-Enhanced Data Aggregation Scheme Against Internal Attackers in Smart GridabstractAccording to related research, energy consumption can be effectively reduced by using energy management information of smart grids. In smart grid architecture, electricity suppliers can monitor, predicate, and control energy generation/consumption in real time. Users can know the current price of electrical energy and obtain energy management information from smart meters. It helps users reduce home's energy use. However, electricity consumptions of users may divulge the privacy information of users. Therefore, privacy of users and communication security of the smart grid become crucial security issues. This paper presents a secure power-usage data aggregation scheme for smart grid. Electricity suppliers can learn about the current power usage of each neighborhood to arrange energy supply and distribution without knowing the individual electricity consumption of each user. This is the first scheme against internal attackers, and it provides secure batch verification. Additionally, the security of the proposed scheme is demonstrated by formal proofs. Chun-I Fan, Shi-Yuan Huang, Yih-Loong Lai |
IEEE Trans. Ind. Informatics | 1 |
| 2013 | Controllable privacy preserving search based on symmetric predicate encryption in cloud storage
Chun-I Fan, Shi-Yuan Huang |
Future Gener. Comput. Syst. | 1 |
| 2013 | Design and implementation of privacy preserving billing protocol for smart grid
Chun-I Fan, Shi-Yuan Huang, William Artan |
J. Supercomput. | 1 |
| 2013 | Complete EAP Method: User Efficient and Forward Secure Authentication Protocol for IEEE 802.11 Wireless LANsabstractIt is necessary to authenticate users who attempt to access resources in Wireless Local Area Networks (WLANs). Extensible Authentication Protocol (EAP) is an authentication framework widely used in WLANs. Authentication mechanisms built on EAP are called EAP methods. The requirements for EAP methods in WLAN authentication have been defined in RFC 4017. To achieve user efficiency and robust security, lightweight computation and forward secrecy, excluded in RFC 4017, are desired in WLAN authentication. However, all EAP methods and authentication protocols designed for WLANs so far do not satisfy all of the above properties. This manuscript will present a complete EAP method that utilizes stored secrets and passwords to verify users so that it can 1) fully meet the requirements of RFC 4017, 2) provide for lightweight computation, and 3) allow for forward secrecy. In addition, we also demonstrate the security of our proposed EAP method with formal proofs. Chun-I Fan, Yi-Hui Lin, Ruei-Hau Hsu |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2012 | Attribute-based strong designated-verifier signature scheme
Chun-I Fan, Chien-Nan Wu, Wei-Kuei Chen, Wei-Zhe Sun |
J. Syst. Softw. | 1 |
| 2012 | Privacy protection for vehicular ad hoc networks by using an efficient revocable message authentication schemeabstractABSTRACT Correctness of exchanged information and guaranteeing the privacy of vehicle owners are the two most significant security concerns for VANETs. Pseudonymous public key infrastructure (PPKI) is a practical solution to these two issues. Almost all PPKI technologies are comprehensive schemes, such as the group signature‐based and identity‐based cryptosystems. An applicable PPKI scheme for secure vehicular communication (VC) should support revocability because it is a significant functionality in VANETs to revoke certificates of vehicles for surrendering or transferring the registrations. However, the computation or space complexity in most of the revocable PPKI‐based protocols is linear when the number of vehicles or revoked vehicles increases over time. This drawback markedly degrades the efficiency and stability of secure VC. This work therefore reduces the computation complexities of authentication message verification, certificate tracing, membership revocation, and space complexity of system parameters (e.g., revocation information and public keys), such that they are independent of the number of vehicles or revoked vehicles using a novel and efficient PPKI mechanism based on bilinear mapping. The proposed scheme uses the concept of accumulator schemes and transfers the computation of accumulators from vehicles to certificate authority (CA) for achieving constant computation and storage complexities on vehicles. The computation of accumulators on CA is also low in the proposed scheme. Finally, we formally prove that the proposed scheme, which is based on q‐strong Diffie–Hellman, n‐Diffie–Hellman exponent (DHE), variant n‐DHE, and decision linear Diffie–Hellman assumptions, is secure under the definitions of traceability and anonymity. Copyright © 2011 John Wiley & Sons, Ltd. Chun-I Fan, Ruei-Hau Hsu, Wei-Kuei Chen |
Secur. Commun. Networks | 1 |
| 2011 | Group Signature with Constant Revocation Costs for Signers and Verifiers
Chun-I Fan, Ruei-Hau Hsu, Mark Manulis |
CANS | 1 |
| 2010 | Anonymous Multireceiver Identity-Based EncryptionabstractRecently, many multireceiver identity-based encryption schemes have been proposed in the literature. However, none can protect the privacy of message receivers among these schemes. In this paper, we present an anonymous multireceiver identity-based encryption scheme where we adopt Lagrange interpolating polynomial mechanisms to cope with the above problem. Our scheme makes it impossible for an attacker or any other message receiver to derive the identity of a message receiver such that the privacy of every receiver can be guaranteed. Furthermore, the proposed scheme is quite receiver efficient since each of the receivers merely needs to perform twice of pairing computation to decrypt the received ciphertext. We prove that our scheme is secure against adaptive chosen plaintext attacks and adaptive chosen ciphertext attacks. Finally, we also formally show that every receiver in the proposed scheme is anonymous to any other receiver. Chun-I Fan, Ling-Ying Huang, Pei-Hsiu Ho |
IEEE Trans. Computers | 1 |
| 2010 | Provably Secure Nested One-Time Secret Mechanisms for Fast Mutual Authentication and Key Exchange in Mobile CommunicationsabstractMany security mechanisms for mobile communications have been introduced in the literature. Among these mechanisms, authentication plays a quite important role in the entire mobile network system and acts as the first defense against attackers since it ensures the correctness of the identities of distributed communication entities before they engage in any other communication activity. Therefore, in order to guarantee the quality of this advanced service, an efficient (especially user-efficient) and secure authentication scheme is urgently desired. In this paper, we come up with a novel authentication mechanism, called thenested one-time secretmechanism, tailored for mobile communication environments. Through maintaining inner and outer synchronously changeable common secrets, respectively, every mobile user can be rapidly authenticated by visited location register (VLR) and home location register (HLR), respectively, in the proposed scheme. Not only does the proposed solution achieve mutual authentication, but it also greatly reduces the computation and communication cost of the mobile users as compared to the existing authentication schemes. Finally, the security of the proposed scheme will be demonstrated by formal proofs. Chun-I Fan, Pei-Hsiu Ho, Ruei-Hau Hsu |
IEEE/ACM Trans. Netw. | 1 |
| 2010 | Provably Secure Integrated On/Off-Line Electronic Cash for Flexible and Efficient PaymentabstractDue to the ubiquity of the Internet and wireless networks, the development of electronic commerce is growing up rapidly. Many payment mechanisms, such as electronic cash (e-cash), credit cards, and electronic wallets, for electronic transactions have been proposed. Especially, e-cash has become popular since it can fully protect the privacy of customers in various electronic transactions. In general, e-cash can be classified into two types, which are on-line e-cash and off-line e-cash, and they are suitable for different applications and environments. All of the proposed e-cash schemes only focus on on-line or off-line e-cash, but not both. In these schemes, users must decide which type of e-cash they will use later when withdrawing. In this paper, we will propose a novel e-cash scheme, which can support each user to withdraw a generic e-cash and decide to spend it as an on-line e-cash or an off-line e-cash when paying. Owing to the integration of on-line and off-line e-cash, our proposed scheme is more convenient for users and more flexible for the bank and shops as compared with the previous schemes. Furthermore, we consider anonymity control, no swindling, tamper resistance, and other key features of e-cash in the proposed scheme. Finally, we also provide formal proofs for the security of the proposed scheme. Chun-I Fan, Vincent Shi-Ming Huang |
IEEE Trans. Syst. Man Cybern. Part C | 1 |
| 2009 | Truly Anonymous Paper Submission and Review SchemeabstractDue to the flush development of academic research, a great deal research results have been published in conference proceedings and journals. However, these articles need to be inspected by some professionals in specific fields. It is the most important that it must keep fair during the entire process of reviewing. However, the privacy of reviewers will be leaked out because that the reviewers must sign their comments on the reviewed papers. The leakage of the reviewers' privacy will affect the fairness of paper reviewing. In addition, the authors need to show their names to the editor of conference proceedings or journals such that it may also make the inspecting results unfair. Unfortunately, the solutions proposed in the literature cannot cope with the problems of fairness well. Therefore, in order to eliminate the drawbacks of the previous schemes, we will deeply analyze the paper review procedure to find the possible reasons that bring about these unfair results. Furthermore, we will present a generic idea, which is independent of the underlying cryptographic components, to achieve the fairness property and other requirements in a paper review scheme. Chun-I Fan, Ming-Te Chen, Lung-Hsien Chen |
ARES | 1 |
| 2009 | Fair anonymous rewarding based on electronic cash
Chun-I Fan, Shi-Yuan Huang, Pei-Hsiu Ho, Chin-Laung Lei |
J. Syst. Softw. | 1 |
| 2009 | Provably secure remote truly three-factor authentication scheme with privacy protection on biometricsabstractA three-factor authentication scheme combines biometrics with passwords and smart cards to provide high-security remote authentication. Most existing schemes, however, rely on smart cards to verify biometric characteristics. The advantage of this approach is that the user's biometric data is not shared with remote server. But the disadvantage is that the remote server must trust the smart card to perform proper authentication which leads to various vulnerabilities. To achieve truly secure three-factor authentication, a method must keep the user's biometrics secret while still allowing the server to perform its own authentication. Our method achieves this. The proposed scheme fully preserves the privacy of the biometric data of every user, that is, the scheme does not reveal the biometric data to anyone else, including the remote servers. We demonstrate the completeness of the proposed scheme through the GNY (Gong, Needham, and Yahalom) logic. Furthermore, the security of our proposed scheme is proven through Bellare and Rogaway's model. As a further benefit, we point out that our method reduces the computation cost for the smart card. Chun-I Fan, Yi-Hui Lin |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2007 | Nested One-Time Secret Mechanisms for Fast Mutual Authentication in Mobile CommunicationsabstractMany security mechanisms for mobile communications have been introduced in the literature. Among these mechanisms, authentication plays a quite important role in the entire mobile network system and acts as the first defense against attackers since it can ensure the correctness of the identities of distributed communication entities before they engage in any other communication activity. Therefore, in order to guarantee the quality of this advanced service, an efficient (especially, user efficient) and secure authentication scheme is urgently desired. In this paper, we come up with a novel authentication mechanism, called the nested one-time secret mechanism, tailored for mobile communication environments. Through maintaining inner and outer synchronously changeable secrets, respectively, every mobile user can be rapidly authenticated by a VLR and the HLR, respectively, in the proposed scheme. Not only does the proposed solution achieve mutual authentication, but also it greatly reduces the computation and communication cost of the mobile users as compared with the existing authentication schemes. Chun-I Fan, Pei-Hsiu Ho |
WCNC | 1 |
| 2006 | Remote Password Authentication Scheme with Smart Cards and BiometricsabstractMore and more researchers combine biometrics with passwords and smart cards to design remote authentication schemes for the purpose of high-degree security. However, in most of these authentication schemes proposed in the literature so far, biometric characteristics are verified in the smart cards only, not in the remote servers, during the authentication processes. Although this kind of design can prevent the biometric data of the users from being known to the servers, it will result in that they are not real three-factor authentication schemes and therefore some security flaws may occur since the remote servers do not indeed verify the security factor of biometrics. In this paper we propose a truly three-factor remote authentication scheme where all of the three security factors, passwords, smart cards, and biometric data, are examined in the remote servers. Especially, the proposed scheme fully preserves the privacy of the biometric data of every user, that is, the scheme does not reveal the biometric data to anyone else, including the remote servers. Furthermore, we also demonstrate that the proposed scheme is immune to both the replay attacks and the offline-dictionary attacks and it satisfies the requirement of low-computation cost for smart-card users. Chun-I Fan, Yi-Hui Lin, Ruei-Hau Hsu |
GLOBECOM | 1 |
| 2006 | Fair Transaction Protocols Based on Electronic CashabstractIn this paper, we propose a novel fair transaction protocol based on electronic cash. With the extension of untraceable electronic cash, we have designed a fair transaction protocol to satisfy both the anonymity and the fairness properties simultaneously. Under the existence of an off-line trusted third party (FTP), the protocol is efficient and practical. Furthermore, the payment information of each customer is not revealed to anyone else including the TTP, and thus, the anonymity or privacy of the customer is protected completely in our protocol. Especially, the proposed method is independent of the underlying electronic cash (e-cash) scheme such that it can be realized by any e-cash system based on the concept of blind signatures Chun-I Fan, Yu-Kuang Liang, Bo-Wei Lin |
PDCAT | 1 |
| 2006 | Ownership-attached unblinding of blind signatures for untraceable electronic cash,
Chun-I Fan |
Inf. Sci. | 1 |
| 2005 | Robust remote authentication scheme with smart cards
Chun-I Fan, Yung-Cheng Chan, Zhi-Kai Zhang |
Comput. Secur. | 1 |
| 2002 | An unlinkably divisible and intention attachable ticket scheme for runoff elections
Chun-I Fan, Chin-Laung Lei |
J. Netw. Comput. Appl. | 1 |
| 2000 | Date attachable electronic cash
Chun-I Fan, Wei-Kuei Chen, Yi-Shiung Yeh |
Comput. Commun. | 1 |
| 2000 | Randomization enhanced Chaum's blind signature scheme
Chun-I Fan, Wei-Kuei Chen, Yi-Shiung Yeh |
Comput. Commun. | 1 |
| 1996 | A Multi-Recastable Ticket Scheme for Electronic Elections
Chun-I Fan, Chin-Laung Lei |
ASIACRYPT | 1 |