Can Zhang 0002

dblp:35/1714-2 · DBLP profile ↗
← Back
17ranked-venue papers
3as first author
13since 2021 · last 2025
0000-0001-8127-9282ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 1 first-author · 8 since 2021Security and privacy · 3 · 2 since 2021Systems, architecture and hardware · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Blockchain-Based Group Covert Communication for IoT Network
abstract
The rapid development of the Internet of Things has increased the importance of IoT data privacy. Traditional encryption and access control mechanisms are insufficient for ensuring privacy. Blockchain-based covert communication offers enhanced concealment, anonymity, and immutability for secure information exchange over open networks. However, existing blockchain-based schemes face limitations in point-to-point communication and low screening efficiency and concealment, as well as challenges when extended to group scenarios, such as the existence of leakers. To address these issues, we propose a Blockchain-based Group Covert Communication (BGCC) scheme. BGCC leverages broadcast encryption to revoke leakers and introduces an efficient covert filtering mechanism based on the decisional ℓ-BDHE assumption. We prove its concealment through security reduction, statistical tests, and machine learning test. Experimental results demonstrate that BGCC outperforms existing schemes.
Xiangbo Yuan, Peng Jiang 0007, Zhuo Chen 0001, Can Zhang 0002, Feng Gao 0019, Liehuang Zhu
IEEE Internet Things J.4
2025 PCSR: Enabling Cross-Modal Semantic Retrieval With Privacy Preservation
abstract
Cross-modal semantic retrieval systems face significant privacy risks due to storing plaintext data on cloud servers. We propose PCSR, a privacy-preserving framework enabling semantic search directly on encrypted high-dimensional data. It consists of three essential modules: a cross-modal encoder, an approximate nearest neighbor (ANN) search algorithm, and an encryption algorithm. Specifically, we utilize CLIP, a deep neural network model, to extract features of images and texts. We design two ANN search methods for high-dimensional feature vectors by utilizing the space partitioning technique and Singular Value Decomposition algorithms, respectively. Furthermore, we employ adapted Random Matrix Multiplication (RMM) for efficient and secure vector similarity computations. Our rigorous security analysis demonstrates that our proposed schemes are secure. We conduct experiments on four datasets and systematically compare the performance of different encrypted retrieval methods. The superior performance validates the feasibility and efficiency of our proposed schemes.
Yandong Zheng, Chang Xu 0004, Liehuang Zhu, Can Zhang 0002
IEEE Trans. Inf. Forensics Secur.5
2024 Exploring Unobservable Blockchain-Based Covert Channel for Censorship-Resistant Systems
abstract
Blockchain-based censorship-resistant systems enable the user to access the blocked content through a covert channel while avoiding a suspicious network connection between the user and the proxy. However, state-of-the-art blockchain-based censorship-resistant schemes cannot satisfy both low communication fees and unobservability, and their method of identifying transactions with covert data may inadvertently expose the covert channel. In this paper, we present Hades, a blockchain-based covert channel framework that aims to circumvent censorship. Hades allows users to encode covert data as a transaction field, and identify transactions with covert data by using another transaction field as a label. We also present the security model for Hades, which defines the unobservability of Hades as the indistinguishability of transactions with covert data from normal transactions. We further propose two cost-friendly and unobservable instantiations of Hades: the basic RDSAC and the improved DDSAC. RDSAC uses private keys to encode covert data and utilizes random factors in the signing process as labels, while incurring a communication delay. DDSAC avoids the delay by encoding covert data into random factors and sampling a transaction amount from normal transactions as the label. We implement a prototype system of Hades and evaluate its performance. Experiment results show that our Hades prototype is unobservable, robust, and efficient. RDSAC and DDSAC can identify 1,654 transactions in 6.054 seconds and 0.071 seconds, respectively. Hades supports 1KB data transfer at $0.44 on the Bitcoin mainnet and cost-free data transfer on the Bitcoin testnet.
Zhuo Chen 0001, Liehuang Zhu, Peng Jiang 0007, Can Zhang 0002, Feng Gao 0019, Fuchun Guo
IEEE Trans. Inf. Forensics Secur.4
2023 Privacy-Preserving and Traceable Blockchain-Based Charging Payment Scheme for Electric Vehicles
abstract
With the rapid development of the global clean energy industry, the electric vehicle (EV) has gradually replaced the traditional fuel vehicle as a promising modern transportation tool due to its environmental friendliness and competitive prices. Its widespread adoption has led to a substantial increase in demand for subsidiary facilities, such as charging piles and stations. Despite the convenience and accessibility offered by charging services, the privacy of EV users may be compromised in the process, as malicious attackers can infer their true identities and consumption habits from service orders. Existing studies introduce blockchain technology into vehicle charging payment scenarios to protect the privacy of EV users. Unfortunately, it cannot achieve the desired full anonymity and may even hinder electricity regulators’ investigation of suspicious transactions and entities. Therefore, designing a vehicle charging payment scheme that simultaneously supports privacy protection and traceability is a challenge. To address these concerns, this article proposes a privacy-preserving and traceable blockchain-based charging payment (PTB-CP) scheme for EVs. It can protect users’ identity privacy and transaction unlinkability and track abnormal transactions or entities in exceptional circumstances. We conduct a comprehensive analysis of PTB-CP from both theoretical and experimental aspects. The analysis results demonstrate that our scheme can realize privacy protection, reliability and authentication, traceability, scalability, and high efficiency.
Yan Wu 0014, Can Zhang 0002, Liehuang Zhu
IEEE Internet Things J.2
2023 EBDL: Effective blockchain-based covert storage channel with dynamic labels
Can Zhang 0002, Liehuang Zhu, Chang Xu 0004, Zijian Zhang 0001, Rongxing Lu
J. Netw. Comput. Appl.1
2023 Privacy-preserving and fault-tolerant aggregation of time-series data without TA
Chang Xu 0004, Run Yin, Liehuang Zhu, Can Zhang 0002, Kashif Sharif
Peer Peer Netw. Appl.4
2023 A Novel Covert Timing Channel Based on Bitcoin Messages
abstract
Covert channels serve the construction of cyberspace security. By realizing the secure transmission of data, it is widely used in political and financial fields. Blockchain covert channels have higher reliability and concealment compared to traditional network-based covert channels. However, existing blockchain covert storage channels need to create a large number of transactions to transmit covert information. Creating transactions requires a transation fee, which means that the implementation of blockchain covert storage channels requires a high cost. Besides, created transactions remain on-chain permanently, leading to the threat of covert information being detected. To overcome these limitations, we propose a blockchain covert timing channel framework. Specifically, we utilize inv and getdata messages in the Bitcoin transaction broadcast as carriers and propose three modulation modes to achieve covert channels without cost and leaving no trace. We evaluate the concealment of our modes by K-S, KLD tests, and machine learning approaches. Experimental results show the indistinguishability between traffic carrying covert information and normal traffic. Our channels promise a capacity of 2.4 bit/s.
Liehuang Zhu, Qi Liu 0067, Zhuo Chen 0001, Can Zhang 0002, Feng Gao 0019, Zhongliang Yang
IEEE Trans. Computers4
2023 BSDP: Blockchain-Based Smart Parking for Digital-Twin Empowered Vehicular Sensing Networks With Privacy Protection
abstract
The popularity of vehicles brings parking issues, especially in the downtown area. To tackle these issues, the concept of smart parking is presented, which utilizes industrial Internet of Things (IIoT) devices and vehicular sensor networks (VSNs) to monitor the available parking spaces and nearby traffic conditions. Unfortunately, the centralized architecture of existing solutions cannot guarantee data reliability. Besides, some privacy issues still violate the VSN participants' sensitive information. We propose a novelBlockchain-based smart parking scheme in digital-twin empowered VSNs with privacy protection, named BSDP. In BSDP, the digital twin network is introduced to monitor and predict traffic conditions nearby a parking lot. The blockchain and smart contract are utilized to achieve reliable data storage and correct parking response, respectively. Besides, the privacy of both driver and VSN participants can be protected. Experimental result shows that the proposed BSDP scheme achieves acceptable efficiency in resource-constrained vehicular networks.
Can Zhang 0002, Liehuang Zhu, Chang Xu 0004
IEEE Trans. Ind. Informatics1
2023 EPPFM: Efficient and Privacy-Preserving Querying of Electronic Medical Records With Forward Privacy in Multiuser Setting
abstract
With the application of the Internet of Things (IoT) and cloud computing, the eHealthcare industry has developed markedly, attracting many patients to seek medical treatment in an eHealthcare system. However, for patients who first register in the system, due to lack of experience, an important aspect is to choose appropriate medical services. Considering the sensitivity of health care data and the semi-honest nature of the cloud server, it is a good solution to use searchable encryption (SE) to obtain some historical electronic medical records (EMRs) that are consistent with the patient's symptom keyword combination and have high service scores for reference. However, existing SE schemes still have issues meeting the requirements of the eHealthcare system for flexible authorization and revocation, efficiency, and forward privacy. To resolve these issues, we propose two efficient and privacy-preserving electronic medical records query schemes with forward privacy in a multiuser setting (EPPFM). First, we present the basic scheme EPPFM-I to achieve a multiuser multikeyword exact match query under linear search complexity. In EPPFM-I, we also use the pseudorandom function (PRF) to perform the function of forward privacy. Then, we use a bucket structure to construct the improved scheme EPPFM-II, which has a faster-than-linear search complexity. Finally, we use detailed security analysis and extensive simulations to show the security and efficiency of the proposed schemes, respectively.
Chang Xu 0004, Zijian Chan, Liehuang Zhu, Can Zhang 0002, Rongxing Lu, Yunguo Guan
IEEE Trans. Sustain. Comput.4
2022 Privacy-Preserving and Fault-Tolerant Aggregation of Time-Series Data With a Semi-Trusted Authority
abstract
Time-series data aggregation in Internet of Things applications is a useful operation, where the time-series data is sensed by a group of users, and gathered by the aggregator for real-time analysis. However, some security and privacy challenges still affect the collection and aggregation process. Although existing privacy-preserving solutions achieve strong privacy guarantees, they introduce a fully trusted TA that is difficult to realize in the real world. Besides, they cannot be directly applied in time-series data aggregation scenarios due to unacceptable efficiency. In this article, we propose a privacy-preserving time-series data aggregation scheme with a semi-trusted authority. Moreover, our scheme also supports arbitrary aggregate functions and fault tolerance to enhance the reliability and scalability of data aggregation. Security analysis demonstrates that our proposed scheme achieves$(n-k)$-source anonymity even if$k(k\leq (n-2))$data providers collude with the cloud server. We also conduct thorough experiments based on a simulated data aggregation scenario to show the high computation and communication efficiency of our scheme.
Chang Xu 0004, Run Yin, Liehuang Zhu, Chuan Zhang 0003, Can Zhang 0002, Kashif Sharif
IEEE Internet Things J.5
2021 Blockchain-Based Verifiable DSSE with Forward Security in Multi-server Environments
Chang Xu 0004, Lan Yu, Liehuang Zhu, Can Zhang 0002
WASA (3)4
2021 Enabling privacy-preserving multi-level attribute based medical service recommendation in eHealthcare systems
Chang Xu 0004, Jiachen Wang 0006, Liehuang Zhu, Kashif Sharif, Chuan Zhang 0003, Can Zhang 0002
Peer-to-Peer Netw. Appl.6
2021 A blockchain-based dynamic searchable symmetric encryption scheme under multiple clouds
Chang Xu 0004, Lan Yu, Liehuang Zhu, Can Zhang 0002
Peer-to-Peer Netw. Appl.4
2020 An efficient and privacy-preserving truth discovery scheme in crowdsensing applications
Chuan Zhang 0003, Chang Xu 0004, Liehuang Zhu, Can Zhang 0002, Huishu Wu
Comput. Secur.5
2020 PGAS: Privacy-preserving graph encryption for accurate constrained shortest distance queries
Can Zhang 0002, Liehuang Zhu, Chang Xu 0004, Kashif Sharif, Chuan Zhang 0003, Ximeng Liu
Inf. Sci.1
2020 Blockchain-based multimedia sharing in vehicular social networks with privacy protection
Liehuang Zhu, Can Zhang 0002, Lei Xu 0016, Feng Gao 0019
Multim. Tools Appl.3
2019 Pay as How You Behave: A Truthful Incentive Mechanism for Mobile Crowdsensing
abstract
Mobile crowdsensing (MCS) is widely applied in large-scale distributed networks for collecting sensing data from workers. In an MCS system, workers are recruited to complete tasks for data requesters, and they will get profits. Accordingly, how to establish an effective incentive mechanism has become an important issue to consider. Since workers are naturally selfish, they try to maximize individual benefits while minimize costs. In this article, we propose a truthful incentive mechanism which pays for the workers by the workers' performance in the task just completed and the reputation. For each worker, through the future prediction function, we get the reputation of the worker by utilizing the previous performances. In the proposed scheme, partial payment for the workers is distributed depending on workers' reputation. The final payment is based on punishments and rewards according to the performances. Moreover, data accuracy and response time are introduced to evaluate the worker performance in the task. It can be demonstrated that the mechanism provides continuous incentives to workers compared to the single ex-ante and ex-post pricing schemes. The experimental results show that our mechanism is effective.
Chang Xu 0004, Yayun Si, Liehuang Zhu, Chuan Zhang 0003, Kashif Sharif, Can Zhang 0002
IEEE Internet Things J.6