Yichen Zhang 0003

dblp:36/1838-3 · DBLP profile ↗
← Back
59ranked-venue papers
0as first author
27since 2021 · last 2026
0000-0002-0907-7827ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 18 · 8 since 2021Databases, data management, data science and information retrieval · 10 · 3 since 2021Computer networks · 9 · 8 since 2021Software engineering, systems software and programming languages · 8 · 3 since 2021Systems, architecture and hardware · 6 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 4Artificial intelligence and machine learning · 2Theory of computation · 2
YearPublicationVenuePosition
2026 Attribute-Based Sanitizable Signature With Key-Exposure Resistance for Mobile Cloud Data
Jiguo Li 0001, Yichen Zhang 0003, Jian Shen 0001
IEEE Trans. Dependable Secur. Comput.3
2026 Three-Patterns-Protected Searchable Encryption Supporting Disjunctive Keyword Search
abstract
Searchable encryption (SE) enables the client to execute keyword searches in encrypted data stored on the untrusted server and has been widely studied in cloud storage. To achieve higher efficiency and more functionalities, most SE schemes allowed the client to leak some information to the server. These leaked information are commonly referred to as leakage patterns. There are three important leakage patterns: search pattern, access pattern and volume pattern. Recent research has exploited at least one of these three patterns to attack SE schemes, resulting in the compromise of the confidentiality of encrypted data and queried keywords. Although existing SE schemes support conjunctive keyword search and protect these three patterns, these schemes do not support disjunctive keyword search and have a higher computational cost. In this paper, we use a private set union protocol based on additively symmetric homomorphic encryption to construct an SE scheme, which not only protects three patterns but also supports disjunctive keyword search. Specifically, we design an efficient token generation algorithm to protect the search pattern and a non-naive padding method to protect the volume pattern. Furthermore, we prove the correctness of our scheme through theoretical analysis and strictly prove the security under the leakage function. Finally, performance evaluation demonstrates that our scheme supports disjunctive keyword search while achieving a favorable trade-off between leakage protection and efficiency. Moreover, for components that exhibit relatively higher overhead during evaluation, we introduce optimization strategies that effectively enhance search efficiency and scalability.
Jiguo Li 0001, Licheng Ji, Wuwei Weng, Yichen Zhang 0003, Yang Lu 0001
IEEE Trans. Dependable Secur. Comput.4
2026 A Traceable and Revocable Ciphertext Policy Attribute-Based Encryption With Policy Authentication
abstract
With the rapid advancement of cloud technology, ciphertext-policy attribute-based encryption (CP-ABE) schemes are highly suited to cloud storage environments. In order to protect sensitive information, policy-hidden CP-ABE has garnered significant attention. However, these schemes are vulnerable to fake policy attacks, where an attacker may introduce false policy and leak system information. To address this issue, we propose a traceable and revocable CP-ABE scheme with policy authentication (TR-PA-ABE). This scheme incorporates a policy checker, which is able to verify whether a ciphertext is encrypted under the correct access policy without revealing any confidential information. Additionally, it features a traceability mechanism that leverages white-box tracing to identify users who leak their keys by embedding user identities within their attribute keys. Our direct revocation method efficiently updates ciphertexts associated with revoked users without impacting the keys of other users, thus minimizing computing overhead. We formally prove that TR-PA-ABE is indistinguishable secure under chosen plaintext attacks (IND-CPA) based on the decision parallel$q$-bilinear Diffie-Hellman exponent assumption. Furthermore, our performance evaluation illustrates the practicality and efficiency of TR-PA-ABE.
Jiguo Li 0001, Enfan Zhang, Yichen Zhang 0003, Jianting Ning, Jian Shen 0001
IEEE Trans. Dependable Secur. Comput.3
2026 Expressive and Fully Policy-Hidden Attribute-Based Searchable Encryption Scheme for Multi-Owner
abstract
As cloud computing advances, data owners increasingly upload large volumes of data to the cloud. Attribute-based searchable encryption (ABSE) empowers data owners to manage fine-grained access over encrypted cloud files, and supports keyword-based search for authorized users. However, current multi-owner searchable encryption schemes often suffer from efficiency limitations and vulnerabilities to keyword guessing attacks. Furthermore, access policies are typically stored in plain form, exposing confidential details about data owners and authorized users. To tackle the aforementioned issues, we put forward an expressive attribute-based searchable encryption scheme with full policy concealment. Our design leverages the reduced ordered binary decision diagram (ROBDD) for access control targeting multi-user and multi-owner environments. In our scheme, users can flexibly select data owners and utilize a single trapdoor to search across shared datasets. The integration of a warrant server that signs obfuscated keywords prevents the cloud server from launching effective keyword guessing attacks. The adoption of ROBDD enables complex access policies via boolean operations, thereby significantly enhancing the efficiency and flexibility of access control. Full policy hiding is achieved by mapping ROBDD paths to an improved bloom filter, preventing access policy leakage. We present formal definitions and security models of the proposed approach, along with rigorous security proofs. Performance evaluation is conducted through theoretical analysis and simulations. Experimental indicate that our scheme achieves superior efficiency over state-of-the-art alternatives, offering a robust solution for secure and flexible cloud data management.
Jiguo Li 0001, Yang Lu 0001, Hang Cheng, Yichen Zhang 0003, Jian Shen 0001
IEEE Trans. Inf. Forensics Secur.5
2026 Privacy-Preserving Healthcare Cloud Access Control: Registered Attribute-Based Encryption With Auditable Policy Updating
Wuwei Weng, Jiguo Li 0001, Yichen Zhang 0003, Yang Lu 0001, Jinguang Han, Jian Shen 0001
IEEE Trans. Inf. Forensics Secur.3
2025 Revocable Registered Attribute-Based Encryption With User Deregistration
abstract
Many businesses are putting their sensitive data in the cloud with the fast growth of cloud computing and storage. To ensure user privacy, it is necessary to keep encrypted data only in the cloud. Attribute-based encryption (ABE) is a popular mean in cloud storage scenarios. ABE is not only faced with key escrow problem but also suffers from user revocation issue when he or she is no longer authorized to access to encrypted data. In order to address these two issues, we propose a revocable registered attribute-based encryption scheme, which not only avoids key escrow problem but also supports precise revocation of a user’s access to a file as well as permanent deregistration of a user from the system. Furthermore, we prove the semantic security of the scheme and conduct a performance experiment to show the efficiency.
Jiguo Li 0001, Shaobo Chen, Yang Lu 0001, Jianting Ning, Jian Shen 0001, Yichen Zhang 0003
IEEE Internet Things J.6
2025 Efficient Key Escrow-Free Attribute-Based Signature for Anonymous Access Control in IIoT
abstract
Industrial Internet of Things (IIoT) processes industrial information anytime and anywhere by deploying smart devices, which inevitably confronts with potential challenges for access control and secure authentication issues. Attribute-based signature (ABS) utilizes a collection of attributes instead of the user’s identity to achieve identity authentication, which supports anonymous access control, data integrity and nonrepudiation. However, ABS schemes exist inherent key escrow problem because all users’ private keys are generated via key authority. In addition, most ABS schemes use time consuming pairing operations, which is unsuitable for resource-constrained IIoT devices. To solve above problems, we present a key escrow-free ABS scheme and utilize server-aided technology to run most of pairing operations in the verification phase, which reduces computation overhead in recursive algorithm based on tree. Furthermore, we utilize tree-based access policy to implement flexible access control. We design a key distribution protocol. By executing this protocol, the key authority cannot derive a whole private key independently without no user’s secret value, which solves key escrow problem. We demonstrate that the presented scheme is existentially unforgeable under adaptive chosen-policy attack in the standard model. Performance analysis shows that the designed scheme is more efficient compared with the existing ABS schemes.
Jiguo Li 0001, Yang Lu 0001, Jianting Ning, Yichen Zhang 0003, Jian Shen 0001
IEEE Internet Things J.5
2025 PH-MG-ABE: A Flexible Policy-Hidden Multigroup Attribute-Based Encryption Scheme for Secure Cloud Storage
abstract
Ciphertext-policy attribute-based encryption (CP-ABE) has attracted significant attention due to its fine-grained access control capabilities, which are highly compatible with cloud computing. Most enterprises utilizing cloud storage technology consist of multiple user groups. However, the current multigroup CP-ABE scheme may pose a risk of sensitive information leakage due to the plaintext access policy mechanisms. To mitigate this issue, it is necessary to conceal access policies. In this article, we propose a flexible policy-hidden multigroup attribute-based encryption (PH-MG-ABE) scheme that enables unique multigroup operations, such as group merging and splitting without affecting user keys. Each attribute in the access policy is divided into attribute values and attribute names. The proposed scheme achieves partial policy hiding by concealing the attribute values. Our scheme allows to directly revoke and join arbitrary numbers of users. In order to reduce the local decryption burden for users, the heavy decryption tasks are outsourced to cloud servers and correctness of the outsourced decryption is verifiable. We prove that our scheme is indistinguishable against under chosen plaintext attacks secure (IND-CPA) based on the decisional q-bilinear Diffie-Hellman exponent assumption. In addition, the proposed scheme appears to be efficient through the performance evaluation.
Jiguo Li 0001, Enfan Zhang, Jinguang Han, Yichen Zhang 0003, Jian Shen 0001
IEEE Internet Things J.4
2025 A Traceable Privacy-Preserving Transaction Protocol With Evolutionary Threshold Authentication
abstract
Decentralized payment systems, such as Bitcoin, enable immutable, and transparent payments in a distributed manner. To address the issue of user privacy leakage due to transaction transparency, some efforts have enhanced privacy protection in decentralized payment systems. However, the lack of regulatory functions in these systems allows malicious users to engage in illegal activities. To balance user privacy protection and the regulation of malicious users, some efforts have attempted to introduce decentralized agencies. However, they have not considered the issue of agency corruption. In this article, we propose a new traceable privacy-preserving transaction protocol, which tracks the addresses and transaction amounts of anonymous parties through decentralized institutions. To address the problem of committee corruption, we present a traceable privacy-preserving protocol with evolving threshold authentication based on a distributed random beacon (TPETA-to-DRB), enabling committee member updates. Furthermore, we prove that the protocol is secure under the random oracle model and conduct a comprehensive performance evaluation.
Ninghai Xie, Jiguo Li 0001, Chao Lin 0003, Yichen Zhang 0003, Jian Shen 0001
IEEE Internet Things J.4
2025 EABE-PUFPH: Efficient Attribute-Based Encryption With Reliable Policy Updating Under Full Policy Hiding
Chenghao Gu, Jiguo Li 0001, Yichen Zhang 0003, Yang Lu 0001, Jian Shen 0001
IEEE Trans. Computers3
2025 Response-Hiding and Volume-Hiding Verifiable Searchable Encryption With Conjunctive Keyword Search
abstract
Verifiable searchable encryption (VSE) not only allows the client to search encrypted data, but also allows the client to verify whether the server honestly executes search operations. Currently, VSE scheme has been widely studied in cloud storage. However, most existing VSE schemes did not hide the access pattern and volume pattern, which respectively refer to the document identifiers and the number of documents matching the queried keywords. Recent studies have exploited these two patterns to launch attacks on searchable encryption schemes, resulting in compromising the confidentiality of encrypted data and queried keywords. In order to solve above issues, we utilize additively symmetric homomorphic encryption scheme and private set intersection protocol to construct a VSE scheme that supports conjunctive keyword search and hides the access pattern and volume pattern (i.e., response-hiding and volume-hiding). Our security model assumes that the server is malicious in the sense that it might deliberately carry out incorrect search operations. Formal security analysis demonstrates that our scheme achieves the desired security properties under our leakage function. Compared to previous schemes, our scheme has advantages in terms of performance and functionality. In an experimental setup with a security parameter of 128 bits and$2^{23}$keyword/document pairs, the search time is approximately only 7.18 seconds.
Jiguo Li 0001, Licheng Ji, Yichen Zhang 0003, Yang Lu 0001, Jianting Ning
IEEE Trans. Computers3
2025 Pairing-Free Attribute-Based Signature With Message Recovery for Industrial Internet of Things
abstract
Industrial Internet of Things (IIoT) has become a smart application for the Internet of Things (IoT), which promotes the industrial enterprises development. The smart devices deploy the IIoT to collect, manage and analyze data through sensors, which are inevitably confronted with access control and secure authentication issues. Attribute-based signature (ABS), in which every signer utilizes an attribute set to sign the message, is a graceful technology to achieve data authentication and anonymous access control. Nevertheless, in some existing ABS schemes, exponentiation and pairing operations are executed. Notably, pairing operations are time consuming and cannot be executed on constrained devices well, e.g. sensors. In addition, these ABS schemes generally need to send the signed message and signature together to the verifiers, which results in additional communication cost. The communication cost is more expensive than computing cost in wireless sensor of IIoT networks, which are unsuitable to IIoT devices. In order to reduce computation overhead and communication cost, we provide a novel pairing-free ABS scheme with message recovery, in which the signed message does not need to be transmitted. Furthermore, we utilize linear secret sharing scheme as access policy, which achieves flexible access control. The presented scheme is proven to be unforgeable and anonymous under the chosen-policy. The security of our scheme is reduced to elliptic curve discrete logarithm (DL) hard issue. The designed scheme is more efficient contrasted with existing ABS schemes with pairings at aspect of theoretical analysis and experimental simulation.
Jiguo Li 0001, Yang Lu 0001, Yichen Zhang 0003
IEEE Trans. Dependable Secur. Comput.4
2025 TERCT: A Traceable and Editable Ring Confidential Transaction for Blockchain
abstract
Anonymous cryptocurrency, as a distributed application utilizing blockchain technology, aims to enhance the level of anonymity in user transactions, but it may also be used for illegal activities. Existing anonymous transaction protocols lack effective public verification of transaction traceability, which means that malicious users have the ability to avoid being tracked by creating counterfeit incomplete evidence. In addition, there is a conflict between the immutability of blockchain and privacy regulations such as General Data Protection Regulation (GDPR), and revision of on-chain data is urgently needed. In order to solve above issues, we propose a trackable and editable anonymous transaction protocol TERCT, which is used to trace the addresses and transaction amounts of participants in anonymous transactions and enable editability of transaction content. Compared with previous work, TERCT enables the editability of transaction content while maintaining anonymity and publicly verifiable traceability of transactions. This ensures that users not only can edit usergenerated transaction content but also cannot fabricate pertinent evidence to evade tracing. We prove the proposed TERCT protocol satisfies unforgeability, balance, anonymity and traceability. We compare its effectiveness with the original RingCT protocol, Wolverine scheme and Trct scheme by experiments. The results show that TERCT has less additional computational overhead.
Jiguo Li 0001, Ninghai Xie, Yichen Zhang 0003, Huaqun Wang
IEEE Trans. Dependable Secur. Comput.3
2025 Verifiable Searchable Symmetric Encryption Over Additive Homomorphism
abstract
Searchable symmetric encryption (SSE) allows the client to search encrypted documents on an untrusted server without revealing the document content and queried keywords. To improve search efficiency and enrich expressiveness, most SSE schemes leak some information that could be exploited for attacks, characterized by leakage patterns. The traditional leakage patterns encompass the search pattern, the access pattern and the response length pattern. Recent research has demonstrated that these three patterns could be exploited to launch attacks, resulting in a high probability of compromising the confidentiality of encrypted documents and queried keywords. Moreover, while there exist SSE schemes that hide multiple leakage patterns, most of them do not resist the malicious server, which may carry out incorrect search operations. In this paper, we propose a leakage-suppressed verifiable SSE (VSSE) scheme that not only hides the three patterns but also allows the client to verify the server’s response. We utilize the privacy set intersection based on polynomial coding and additive symmetric homomorphism encryption to construct a VSSE scheme that supports a conjunctive query. Specifically, we design an efficient random token generation algorithm to protect the search pattern and a verification algorithm that does not require server-generated proofs. Formal security analysis shows that our scheme achieves the desired correctness, security and verifiability. Lastly, we simulate the proposed scheme and compare it with the recent leakage suppression schemes in multiple aspects. The comparison results show that our scheme achieves a good balance in expressiveness, efficiency and security.
Licheng Ji, Jiguo Li 0001, Yichen Zhang 0003, Yang Lu 0001
IEEE Trans. Inf. Forensics Secur.3
2025 Efficient Registered Attribute Based Access Control With Same Sub-Policies in Mobile Cloud Computing
abstract
Ciphertext-policy attribute-based encryption (CP-ABE) has long been considered as a promising access control technology for cloud storage. However, CP-ABE depends on a central trusted authority to generate and distribute decryption keys, resulting in the key escrow issue. Most existing solutions only mitigate this problem but fail to resolve it entirely. Registered attribute-based encryption (RABE), a new cryptographic primitive, fundamentally addresses the key escrow problem by modifying the trust model, but its high computational overhead limits its practical application. Inspired by this challenge, we present an efficient registered attribute-based access control scheme designed for data encrypted with access policies containing the same sub-policy. In our scheme, users generate their own keys, while a key manager, who does not hold keys, replaces the central authority in managing users. Additionally, for data encrypted with the same sub-policy, the user’s initial decryption stores the relevant parameters, which can be used for subsequent decryptions to reduce computational overhead. The proposed scheme is proven to achieve semantic security. Performance analysis demonstrates that our scheme enhances decryption efficiency by roughly 41.4$\%$compared to existing RABE scheme, with a minimal storage trade-off, making it more practical for cloud storage application.
Wuwei Weng, Jiguo Li 0001, Yichen Zhang 0003, Yang Lu 0001, Jian Shen 0001, Jinguang Han
IEEE Trans. Mob. Comput.3
2024 Efficient Revocable Attribute-Based Encryption With Verifiable Data Integrity
abstract
Nowadays, cloud computing and cloud storage services that can reduce the local workload are becoming increasingly popular, allowing individual and corporate users to upload data to the cloud. Since the user’s permissions in the system are not immutable, the users should have dynamic access. Revocation of users who have been granted access to data is also a strong need for cloud computing systems. In addition, we should ensure the data integrity after the cloud server performs a revocation. To address the above issues, we propose a revocable attribute-based encryption scheme that protects the data integrity (RABE-DI). Our scheme is more efficient compared with existing RABE-DI schemes. In addition, we prove the semantic security and integrity of the scheme. Experimental result shows that the similar scheme is not as efficient as ours.
Shaobo Chen, Jiguo Li 0001, Yichen Zhang 0003, Jinguang Han
IEEE Internet Things J.3
2024 OABS: Efficient Outsourced Attribute-Based Signature Scheme With Constant Size
abstract
Attribute-based signature (ABS) extends the identity-based signature, in which the unique identity for the signer is expanded into an attribute set composed of multiple attributes. The current ABS schemes supporting linear secret-sharing scheme (LSSS) matrix are flexible, but the computational cost of the signing algorithm is linear with the number of required attributes. Therefore, it is inappropriate to constrained devices (mobile phone, tablet, etc.) which have limited computation power. For the sake of solving the above issue, we devise an key-policy outsourced ABS (OABS) scheme supporting LSSS access structure. The designed scheme provides the outsourced key for the cloud service provider (CSP) which computes most of module exponentiation in the signing phase. The signer only needs to perform lightweight calculations to endorse a message. The presented OABS scheme is proved secure against the q-Diffie-Hellman exponentiation (q-DHE) assumption under the standard model. In addition, the devised OABS scheme fulfills the signer privacy. Moreover, the signature length for the designed scheme is invariable and unrelated to the number of required attributes, which reduces communication cost. Performance analysis demonstrates that the designed OABS scheme is more high efficiency in the aspect of the computational cost.
Zhaozhe Kang, Jiguo Li 0001, Yuting Zuo, Yichen Zhang 0003, Jinguang Han
IEEE Internet Things J.4
2023 TFS-ABS: Traceable and Forward-Secure Attribute-Based Signature Scheme With Constant-Size
abstract
Attribute-based signature (ABS) is a versatile and useful cryptogrammic technology. In an ABS scheme, every signer is distributed a signing secret key in term of her/his attributes, and endorses a message in relation to some signing policy fulfilled by the signer's attributes. The verifier checks that the signature is indeed endorsed by the signer whose attributes match with the signing policy. However, existing ABS schemes suffer from the issue of abusing signature and key exposure. To address the above issues, we provide a traceable and forward-secure attribute-based signature (TFS-ABS) scheme with constant-size supporting flexible threshold predicates. Furthermore, we prove that the presented TFS-ABS scheme is existential unforgeability against selective predicate attack under the standard model. We reduce the security for the provided scheme to$q$-Diffie-Hellman exponentiation assumption. The designed scheme can be used to alleviate the damage induced by key exposure and traces the real identity of signer by attribute authority (AA) when the signer occurs abusing behavior. Furthermore, the signature size in presented scheme keeps constant and is independent of the number of attributes. Experimental evaluations exhibit that the presented TFS-ABS scheme is efficient in term of the communication and computation overhead.
Zhaozhe Kang, Jiguo Li 0001, Jian Shen 0001, Jinguang Han, Yuting Zuo, Yichen Zhang 0003
IEEE Trans. Knowl. Data Eng.6
2022 Decentralized Attribute-Based Server-Aid Signature in the Internet of Things
abstract
Devices of Internet of Things (IoT) play a significant role in people’s daily life. A large scale of data is generated, collected, and analyzed in these devices, which inevitably faces secure authentication and access control problem. Attribute-based signature (ABS), where a signer signs a message over a set of attributes, plays an elegant tool for privacy-preserving access control and data authentication. In multiauthority ABS scheme, multiple authorities distribute users’ private keys over their different attributes and these attribute authorities are managed by a central authority. Nevertheless, the whole ABS system can be broken if the central authority is compromised. Besides, the multiauthority ABS scheme needs a lot of pairing and exponentiation operations in the verification and signature algorithms. Therefore, it is very expensive for resource-limited devices (e.g., sensors in IoT) to utilize the ABS scheme. In order to solve above problems, we present a decentralized attribute-based server-aid signature (DABSAS) scheme. In the DABSAS scheme, a server can help users execute heavy computation in the signature and verification algorithms. The proposed scheme provides anonymity and unforgeability. In addition, our scheme mitigates the burden of the signature and verification phase. The proposed scheme is proved secure under the well-known computational co-Diffie–Hellman (co-CDH) assumption. Compared with the existing schemes, the presented DABSAS scheme is efficient.
Jiguo Li 0001, Jinguang Han, Chengdong Liu, Yichen Zhang 0003, Huaqun Wang
IEEE Internet Things J.5
2022 Key escrow-free attribute based encryption with user revocation
Ruyuan Zhang, Jiguo Li 0001, Yang Lu 0001, Jinguang Han, Yichen Zhang 0003
Inf. Sci.5
2022 Efficient CP-ABE Scheme With Shared Decryption in Cloud Storage
abstract
Attribute-based encryption (ABE) is a preferred technology used to access control the data stored in the cloud servers. However, in many cases, the authorized decryption user may be unable to decrypt the ciphertext in time for some reason. To be on the safe side, several alternate users are delegated to cooperate to decrypt the ciphertext, instead of one user doing that. We provide a ciphertext-policy ABE scheme with shared decryption in this article. An authorized user can recover the messages independently. At the same time, these alternate users (semi-authorized users) can work together to get the messages. We also improve the basic scheme to ensure that the semi-authorized users perform the decryption tasks honestly. An integrated access tree is used to improve the efficiency for our scheme. The new scheme is proved CPA-secure in the standard model. The experimental result shows that our scheme is very efficient on both computational overhead and storage cost.
Ningyu Chen, Jiguo Li 0001, Yichen Zhang 0003, Yuyan Guo
IEEE Trans. Computers3
2022 Efficient Identity-Based Provable Multi-Copy Data Possession in Multi-Cloud Storage
abstract
To increase the availability and durability of the outsourced data, many customers store multiple copies on multiple cloud servers. To guarantee the integrity of multi-copies, some provable data possession (PDP) protocols for multi-copy are presented. However, most of previous PDP protocols consider all copies to be stored on only one cloud storage server. In some degree, multi-copy makes little sense in such circumstance. Furthermore, many PDP protocols depend on the technique of public key infrastructure (PKI), which suffers many types of security vulnerabilities and also brings heavy communicational and computational cost. To increase the security and efficiency, we provide a novel identity-based PDP scheme of multi-copy on multiple cloud storage servers. In our scheme, all copies are delivered to different cloud storage servers, which work cooperatively to store the customer's data. By the homomorphic verifiable tags, the integrity of all copies can be checked simultaneously. The system model and security model of our scheme are provided in the paper. The security for our scheme is proved based on the computation Diffie-Hellman (CDH) hard problem. Analysis and experimental evaluation show that our scheme is efficient and practical. The proposed scheme is the first identity-based PDP scheme for multi-copy and multi-cloud servers.
Jiguo Li 0001, Yichen Zhang 0003
IEEE Trans. Cloud Comput.3
2022 Attribute Based Encryption with Privacy Protection and Accountability for CloudIoT
abstract
The pervasive, ubiquitous, and heterogeneous properties of IoT make securing IoT systems a very challenging task. More so when access and storage are performed through a cloud-based IoT system. IoT data stored on cloud should be encrypted to ensure data privacy. It is also crucial to allow only authorized entities to access and decrypt the encrypted data. In this article, we propose a ciphertext-policy attribute-based encryption (CP-ABE) scheme that enables fine-grained access control of encrypted IoT data on cloud. CP-ABE is regarded as a highly promising approach to provide flexible and fine-grained access control, which is quite suited to secure cloud based IoT systems. We first present an access control system model of CloudIoT platform based on ABE. Based on the presented system model, we construct a ciphertext-policy hiding CP-ABE scheme, which guarantees the privacy of the users. We further construct a white-box traceable CP-ABE scheme with accountability in order to address the user key abuse and authorization center key abuse. Experiment illustrates the proposed systems are efficient.
Jiguo Li 0001, Yichen Zhang 0003, Jianting Ning, Xinyi Huang 0001, Geong Sen Poh, Debang Wang
IEEE Trans. Cloud Comput.2
2022 Efficient Attribute Based Server-Aided Verification Signature
abstract
Attribute based signature (ABS) is a novel cryptographic primitive, which permits users to sign a message over attributes without revealing other information. A signature only reveals that it is signed by a signer whose some attributes meet an access policy. However, some ABS schemes only support the threshold access policy, where the signing algorithms are limited by the threshold. The threshold access policy can not express precise access control well. In addition, the computation cost of the verification algorithm is heavy since pairing operations are required. Pairing is costly operation comparing to exponentiation. Therefore, existing ABS schemes are not suitable to resource-limited devices, such as RFID tags and smart cards. In order to solve the issues above, we present a novel ABS scheme by using the attribute tree as access policy that expresses flexible access control. We utilize server-aid technique to help the verifier to verify signatures and reduce the computation burden. Our scheme is proved secure against unforgeable and anonymous under chosen-policy selective-message attack in the standard model. Compared with existing schemes, our scheme is more efficient in terms of private key generation and verification. The proposed scheme reduces users’ calculation burden and expresses more flexible access policy.
Jiguo Li 0001, Chengdong Liu, Jinguang Han, Yichen Zhang 0003
IEEE Trans. Serv. Comput.5
2021 An efficient identity-based signature scheme with provable security
Jiguo Li 0001, Chengdong Liu, Jinguang Han, Huaqun Wang, Yichen Zhang 0003
Inf. Sci.6
2021 Certificateless Public Integrity Checking of Group Shared Data on Cloud Storage
abstract
Cloud storage service supplies people with an efficient method to share data within a group. The cloud server is not trustworthy, so lots of remote data possession checking (RDPC) protocols are proposed and thought to be an effective way to ensure the data integrity. However, most of RDPC protocols are based on the mechanism of traditional public key infrastructure (PKI), which has obvious security flaw and bears big burden of certificate management. To avoid this shortcoming, identity-based cryptography (IBC) is often chosen to be the basis of RDPC. Unfortunately, IBC has an inherent drawback of key escrow. To solve these problems, we utilize the technique of certificateless signature to present a new RDPC protocol for checking the integrity of data shared among a group. In our scheme, user's private key includes two parts: a partial key generated by the group manager and a secret value chosen by herself/himself. To ensure the right public keys are chosen during the data integrity checking, the public key of each user is associated with her unique identity, for example the name or telephone number. Thus, the certificate is not needed and the problem of key escrow is eliminated too. Meanwhile, the data integrity can still be audited by public verifier without downloading the whole data. In addition, our scheme also supports efficient user revocation from the group. The security of our scheme is reduced to the assumptions of computational Diffie-Hellman (CDH) and discrete logarithm (DL). Experiment results exhibit that the new protocol is very efficient and feasible.
Jiguo Li 0001, Yichen Zhang 0003
IEEE Trans. Serv. Comput.3
2021 Secure Channel Free Certificate-Based Searchable Encryption Withstanding Outside and Inside Keyword Guessing Attacks
abstract
Searchable public key encryption (SPKE) is a useful public key cryptographic primitive that allows a user to perform keyword searches over publicly encrypted messages on an untrusted storage server while guaranteeing the privacy of the original messages as well as the search keywords. However, most of the previously proposed SPKE frameworks suffer from the security vulnerability caused by the keyword guessing attack and some other weaknesses. Inspired by the ideas of certificate-based cryptography and signcryption, we present a new SPKE framework called certificate-based searchable encryption. The new framework not only provides resistance to the existing known types of keyword guessing attacks, but also enjoys some appealing merits, such as implicit authentication, no key escrow and no secure channel. Under this new framework, we devise a concrete searchable certificate-based encryption scheme. In the random oracle model, it is proven to meet the keyword ciphertext indistinguishability, the keyword ciphertext unforgeability and the keyword trapdoor indistinguishability under the adaptive chosen-keyword attack. The comparisons indicate that it is secure and practicable.
Yang Lu 0001, Jiguo Li 0001, Yichen Zhang 0003
IEEE Trans. Serv. Comput.3
2020 Privacy-Preserving and Pairing-Free Multirecipient Certificateless Encryption With Keyword Search for Cloud-Assisted IIoT
abstract
Nowadays, cloud-assisted Industrial Internet of Things (IIoT) has become pervasive in modern enterprises, because it supplies a promising way to transform the operation mode of existing industrial facilities, to enhancing the production efficiency and lowering the manufacturing cost. In order to preserve the privacy of enterprises, sensitive industrial data needs to be encrypted prior to being uploaded to the cloud. Recently, certificateless encryption with keyword search (CLKS) was introduced to resolve the problem of encrypted data retrieval in cloud-assisted IIoT. However, the existing CLKS schemes only support a single-recipient keyword search and need to depend on the costly bilinear pairing that is disliked by the resource-constrained IIoT devices. Moreover, most of the existing CLKS schemes are vulnerable to the keyword guessing attack, and thus fail to protect the privacy of searched data. In this article, we develop a privacy-preserving and pairing-free multirecipient CLKS scheme for cloud-assisted IIoT. The proposed scheme has the following merits: 1) supporting multirecipient keyword search function; 2) requiring no costly bilinear pairing operations; and 3) providing resistance against keyword guessing attacks. The performance comparison and analysis demonstrate that it is more efficient than the existing CLKS schemes and is appropriate for the cloud-assisted IIoT.
Yang Lu 0001, Jiguo Li 0001, Yichen Zhang 0003
IEEE Internet Things J.3
2020 Adaptively secure certificate-based broadcast encryption and its application to cloud storage service
Liqing Chen, Jiguo Li 0001, Yang Lu 0001, Yichen Zhang 0003
Inf. Sci.4
2020 Adaptively secure efficient broadcast encryption with constant-size secret key and ciphertext
Liqing Chen, Jiguo Li 0001, Yichen Zhang 0003
Soft Comput.3
2020 A decentralized multi-authority ciphertext-policy attribute-based encryption with mediated obfuscation
Jiguo Li 0001, Shengzhou Hu, Yichen Zhang 0003, Jinguang Han
Soft Comput.3
2020 Full Verifiability for Outsourced Decryption in Attribute Based Encryption
abstract
Attribute based encryption (ABE) is a popular cryptographic technology to protect the security of users' data. However, the decryption cost and ciphertext size restrict the application of ABE in practice. For most existing ABE schemes, the decryption cost and ciphertext size grow linearly with the complexity of access structure. This is undesirable to the devices with limited computing capability and storage space. Outsourced decryption is considered as a feasible method to reduce the user's decryption overhead, which enables a user to outsource a large number of decryption operations to the cloud service provider (CSP). However, outsourced decryption cannot guarantee the correctness of transformation done by the cloud, so it is necessary to check the correctness of outsourced decryption to ensure security for users' data. Current research mainly focuses on verifiability of outsourced decryption for the authorized users. It still remains a challenging issue that how to guarantee the correctness of outsourced decryption for unauthorized users. In this paper, we propose an ABE scheme with verifiable outsourced decryption (called full verifiability for outsourced decryption), which can simultaneously check the correctness for transformed ciphertext for the authorized users and unauthorized users. The proposed ABE scheme with verifiable outsourced decryption is proved to be selective CPA-secure in the standard model.
Jiguo Li 0001, Yichen Zhang 0003, Jinguang Han
IEEE Trans. Serv. Comput.3
2019 Hierarchical attribute based encryption with continuous leakage-resilience
Jiguo Li 0001, Qihong Yu, Yichen Zhang 0003
Inf. Sci.3
2019 Key-policy attribute-based encryption against continual auxiliary input leakage
Jiguo Li 0001, Qihong Yu, Yichen Zhang 0003, Jian Shen 0001
Inf. Sci.3
2018 Cryptanalysis and Improvement for Certificateless Aggregate Signature
abstract
In order to satisfy application in resource constrained environment, aggregate signature schemes have been widely investigated. Recently, He et al. pointed out that certificateless aggregate signature (CLAS) scheme proposed by Xiong et al. was insecure against the Type II adversary and presented an possible improvement. In this article, we show that their improved scheme is not secure against a malicious-but-passive KGC attack. We analyze attack reason and propose an improved certificateless aggregate signature scheme. Based on the CDH difficult problem assumption, the proposed CLAS scheme is existentially unforgeable against adaptive chosen-message attacks in the random oracle model.
Jiguo Li 0001, Yichen Zhang 0003
Fundam. Informaticae3
2018 Anonymous certificate-based broadcast encryption with constant decryption cost
Jiguo Li 0001, Liqing Chen, Yang Lu 0001, Yichen Zhang 0003
Inf. Sci.4
2018 Identity-based broadcast encryption with continuous leakage resilience
Jiguo Li 0001, Qihong Yu, Yichen Zhang 0003
Inf. Sci.3
2018 Two-Party Attribute-Based Key Agreement Protocol with Constant-Size Ciphertext and Key
abstract
Based on mutual authentication, the session key is established for communication nodes on the open network. In order to satisfy fine-grained access control for cloud storage, the two-party attribute-based key agreement protocol (TP-AB-KA) was proposed. However, the existing TP-AB-KA protocol is high in the cost of computation and communication and is not unfit for application in a mobile cloud setting because mobile devices are generally resource constrained. To solve the above issue, we propose a TP-AB-KA protocol with constant-size ciphertext and key. Our TP-AB-KA protocol is provable security in the standard model. The concrete proof is given under the augmented multisequence of exponents' decisional Diffie-Hellman (aMSE-DDH) hypothesis in the attribute-based BJM model (AB-BJM). Compared with the existing TP-AB-KA protocols, the computation cost and communication cost of our protocol are largely reduced.
Jiguo Li 0001, Shengzhou Hu, Yichen Zhang 0003
Secur. Commun. Networks3
2018 Provably secure certificate-based encryption with leakage resilience
Yuyan Guo, Jiguo Li 0001, Yang Lu 0001, Yichen Zhang 0003, Futai Zhang
Theor. Comput. Sci.4
2017 Verifiable Outsourced Decryption of Attribute-Based Encryption with Constant Ciphertext Length
abstract
Outsourced decryption ABE system largely reduces the computation cost for users who intend to access the encrypted files stored in cloud. However, the correctness of the transformation ciphertext cannot be guaranteed because the user does not have the original ciphertext. Lai et al. provided an ABE scheme with verifiable outsourced decryption which helps the user to check whether the transformation done by the cloud is correct. In order to improve the computation performance and reduce communication overhead, we propose a new verifiable outsourcing scheme with constant ciphertext length. To be specific, our scheme achieves the following goals. (1) Our scheme is verifiable which ensures that the user efficiently checks whether the transformation is done correctly by the CSP. (2) The size of ciphertext and the number of expensive pairing operations are constant, which do not grow with the complexity of the access structure. (3) The access structure in our scheme is AND gates on multivalued attributes and we prove our scheme is verifiable and it is secure against selectively chosen-plaintext attack in the standard model. (4) We give some performance analysis which indicates that our scheme is adaptable for various limited bandwidth and computation-constrained devices, such as mobile phone.
Jiguo Li 0001, Fengjie Sha, Yichen Zhang 0003, Xinyi Huang 0001, Jian Shen 0001
Secur. Commun. Networks3
2017 A Novel Efficient Remote Data Possession Checking Protocol in Cloud Storage
abstract
As an important application in cloud computing, cloud storage offers user scalable, flexible, and high-quality data storage and computation services. A growing number of data owners choose to outsource data files to the cloud. Because cloud storage servers are not fully trustworthy, data owners need dependable means to check the possession for their files outsourced to remote cloud servers. To address this crucial problem, some remote data possession checking (RDPC) protocols have been presented. But many existing schemes have vulnerabilities in efficiency or data dynamics. In this paper, we provide a new efficient RDPC protocol based on homomorphic hash function. The new scheme is provably secure against forgery attack, replace attack, and replay attack based on a typical security model. To support data dynamics, an operation record table (ORT) is introduced to track operations on file blocks. We further give a new optimized implementation for the ORT, which makes the cost of accessing ORT nearly constant. Moreover, we make the comprehensive performance analysis, which shows that our scheme has advantages in computation and communication costs. Prototype implementation and experiments exhibit that the scheme is feasible for real applications.
Jiguo Li 0001, Jinguang Han, Yichen Zhang 0003
IEEE Trans. Inf. Forensics Secur.4
2017 KSF-OABE: Outsourced Attribute-Based Encryption with Keyword Search Function for Cloud Storage
abstract
Cloud computing becomes increasingly popular for data owners to outsource their data to public cloud servers while allowing intended data users to retrieve these data stored in cloud. This kind of computing model brings challenges to the security and privacy of data stored in cloud. Attribute-based encryption (ABE) technology has been used to design fine-grained access control system, which provides one good method to solve the security issues in cloud setting. However, the computation cost and ciphertext size in most ABE schemes grow with the complexity of the access policy. Outsourced ABE (OABE) with fine-grained access control system can largely reduce the computation cost for users who want to access encrypted data stored in cloud by outsourcing the heavy computation to cloud service provider (CSP). However, as the amount of encrypted files stored in cloud is becoming very huge, which will hinder efficient query processing. To deal with above problem, we present a new cryptographic primitive called attribute-based encryption scheme with outsourcing key-issuing and outsourcing decryption, which can implement keyword search function (KSF-OABE). The proposed KSF-OABE scheme is proved secure against chosen-plaintext attack (CPA). CSP performs partial decryption task delegated by data user without knowing anything about the plaintext. Moreover, the CSP can perform encrypted keyword search without knowing anything about the keywords embedded in trapdoor.
Jiguo Li 0001, Xiaonan Lin, Yichen Zhang 0003, Jinguang Han
IEEE Trans. Serv. Comput.3
2017 Flexible and Fine-Grained Attribute-Based Data Storage in Cloud Computing
abstract
With the development of cloud computing, outsourcing data to cloud server attracts lots of attentions. To guarantee the security and achieve flexibly fine-grained file access control, attribute based encryption (ABE) was proposed and used in cloud storage system. However, user revocation is the primary issue in ABE schemes. In this article, we provide a ciphertext-policy attribute based encryption (CP-ABE) scheme with efficient user revocation for cloud storage system. The issue of user revocation can be solved efficiently by introducing the concept of user group. When any user leaves, the group manager will update users' private keys except for those who have been revoked. Additionally, CP-ABE scheme has heavy computation cost, as it grows linearly with the complexity for the access structure. To reduce the computation cost, we outsource high computation load to cloud service providers without leaking file content and secret keys. Notably, our scheme can withstand collusion attack performed by revoked users cooperating with existing users. We prove the security of our scheme under the divisible computation Diffie-Hellman assumption. The result of our experiment shows computation cost for local devices is relatively low and can be constant. Our scheme is suitable for resource constrained devices.
Jiguo Li 0001, Yichen Zhang 0003, Huiling Qian, Jinguang Han
IEEE Trans. Serv. Comput.3
2016 Certificate-Based Key-Insulated Signature in the Standard Model
abstract
The key-insulated signature scheme provides a good method to solve key exposure problem. The key-insulated mechanism has been extended to the identity-based cryptography (IBC) and certificateless cryptography. As a new cryptographic primitive, certificate-based cryptography has unique advantage without key escrow problem in IBC and the complex certificate management problem in traditional PKI. However, certificate-based signature operations are usually performed on insecure environments where the signature key exposure is inevitable. In order to solve this problem, we intro- duce key-insulated idea into certificate-based cryptography and propose the notion and security model of the certificate-based key-insulated signature (CBKIS). In addition, we present a CBKIS scheme that is provably secure in the standard model. Security of scheme is reduced to the hardness of Non Pairing-based Generalized Bilinear DH problem and Many Diffie–Hellman problem. The proposed scheme solves the key exposure problem and improves the security in certificate-based cryptography.
Jiguo Li 0001, Haiting Du, Yichen Zhang 0003
Comput. J.3
2016 A Leakage-Resilient CCA-Secure Identity-Based Encryption Scheme
abstract
Identity-based encryption (IBE) has many appealing applications. However, some traditional IBE schemes may not be secure in the real world due to the side-channel attacks. Leakage-resilient cryptography can capture these attacks by modeling information leakage that adversary can access. In this paper, we apply a hash proof technique in the existing CCA-secure variant of the Gentry's IBE scheme to construct a new leakage-resilient IBE scheme in the bounded-leakage model. The proposed scheme is more computationally efficient than the original Alwen et al. 's leakage-resilient IBE scheme. It enjoys a shorter key (public/secret key) length, and a higher relative key leakage ratio. The new leakage-resilient scheme is proved semantically secure against adaptive chosen ciphertext attack in the standard model under the truncated augmented bilinear Diffie-Hellman exponent ( |$q$| -TABDHE) assumption.
Jiguo Li 0001, Meilin Teng, Yichen Zhang 0003, Qihong Yu
Comput. J.3
2016 Continuous leakage-resilient certificate-based encryption
Jiguo Li 0001, Yuyan Guo, Qihong Yu, Yang Lu 0001, Yichen Zhang 0003, Futai Zhang
Inf. Sci.5
2016 Certificate-based encryption resilient to key leakage
Qihong Yu, Jiguo Li 0001, Yichen Zhang 0003, Wei Wu 0001, Xinyi Huang 0001, Yang Xiang 0001
J. Syst. Softw.3
2016 Hierarchical attribute-based encryption with continuous auxiliary inputs leakage
abstract
Abstract The continuous auxiliary inputs leakage is more strong side‐channel attacks. In this article, we first propose a continuous auxiliary inputs leakage model for the hierarchical attribute‐based encryption scheme. Under the security model, an adversary has ability to gain partial updated master keys and updated secret keys continually by certain leakage attacks. Moreover, a resilient‐leakage hierarchical attribute‐based encryption scheme is constructed. The security proof for this scheme is provided under the standard model. Furthermore, we give the performance comparison between our scheme and relevant scheme. Copyright © 2016 John Wiley & Sons, Ltd.
Yuyan Guo, Jiguo Li 0001, Yichen Zhang 0003, Jian Shen 0001
Secur. Commun. Networks3
2016 Provably secure identity-based encryption resilient to post-challenge continuous auxiliary input leakage
abstract
The situation for post-challenge continuous auxiliary input leakage has not been considered in the cryptography schemes for previous literature. We present a semantic-security model with post-challenge continuous auxiliary inputs for identity-based encryption. In this model, the adversary is permitted to obtain some information of the private keys constantly and to query more information after seeing the challenge ciphertext through the side-channel attacks. Furthermore, we present an identity-based encryption scheme resilient to leakage under composite order groups. Our scheme is secure against post-challenge continuous auxiliary input, adaptive chosen-identity, and adaptive chosen plaintext attacks under three static assumptions in the standard model. Compared with existing identity-based encryption schemes under security properties and performance, our scheme is practical. Copyright © 2015 John Wiley & Sons, Ltd.
Jiguo Li 0001, Yuyan Guo, Qihong Yu, Yang Lu 0001, Yichen Zhang 0003
Secur. Commun. Networks5
2015 A Forward-Secure Certificate-Based Signature Scheme
abstract
Cryptographic computations are often carried out on insecure devices for which the threat of key exposure raises a serious concern. In an effort to address the key exposure problem, the notion of forward security was first presented by Günther in 1990. In a forward-secure scheme, secret keys are updated at regular periods of time; exposure of the secret key corresponding to a given time period does not enable an adversary to ‘break’ the scheme for any prior time period. In this paper, we first introduce forward security into certificate-based cryptography and define the security model of forward-secure certificate-based signatures (CBSs). Then we propose a forward-secure CBS scheme, which is shown to be secure against adaptive chosen message attacks under the computational Diffie–Hellman assumption in the random oracle model. Our result can be viewed as the first step toward solving the key exposure problem in CBSs and thus improving the security of the whole system.
Jiguo Li 0001, Huiyun Teng, Xinyi Huang 0001, Yichen Zhang 0003, Jianying Zhou 0001
Comput. J.4
2015 Certificateless online/offline signcryption scheme
abstract
Abstract Signcryption is a highly efficient approach to achieve simultaneously confidentiality and authentication of message, which is more feasible than the simple combination of encryption and signature. The online/offline cryptography can further enhance the efficiency of signcryption system process without affecting its security. At present, most online/offline signcryptions focus on the ID‐based setting. However, the key escrow problem is inherent in ID‐based cryptography, which is regarded as the main barrier to affect the implementation of system. In this paper, we propose a brand new certificateless online/offline signcryption scheme. We prove the security of our scheme under q‐mBDHI, CDH and q‐CAA assumptions in the random oracle model. The proposed scheme overcomes the key escrow problem in the ID‐based setting. Copyright © 2014 John Wiley & Sons, Ltd.
Jiguo Li 0001, Yichen Zhang 0003
Secur. Commun. Networks3
2015 Leakage-resilient certificate-based encryption
abstract
Abstract Certificate‐based encryption is a new cryptography primitive, which can be used to construct efficient public key infrastructure. However, side‐channel attacks are not considered in certificate‐based encryption. In order to capture these attacks, we formalize security model of certificate‐based encryption with leakage resilience. Furthermore, we present a leakage‐resilient certificate‐based encryption (LR‐CBE) scheme. To the best of our knowledge, this is the first LR‐CBE scheme. Based on decision bilinear Diffie‐Hellman assumption and decision generalized bilinear Diffie‐Hellman assumption, we prove that our scheme is secure against adaptive chosen ciphertext attacks in the random oracle model. Our scheme includes a certificate‐based key encapsulation algorithm and a symmetric encryption algorithm, where the encapsulated information is a symmetric key that is used to encrypt message. In order to obtain leakage‐resilient property, two‐source extractor is used to randomize the symmetric key. The designed scheme can resist entropy leakage. The performance analysis of leakage resilience shows that the relative leakage ratio almost amounts to 1. Copyright © 2015 John Wiley & Sons, Ltd.
Qihong Yu, Jiguo Li 0001, Yichen Zhang 0003
Secur. Commun. Networks3
2014 Certificate-Based Conditional Proxy Re-Encryption
Jiguo Li 0001, Xuexia Zhao, Yichen Zhang 0003
NSS3
2014 Provably secure certificate-based key-insulated signature scheme
abstract
SUMMARY Certificate‐based signature computation is often performed on insecure devices where the signature key is easy to be exposed. To reduce the influence of key exposure, we introduce key‐insulated mechanism into certificate‐based cryptography and formalize the notion and security model of the certificate‐based key‐insulated signature scheme. We then present a certificate‐based key‐insulated signature scheme, which is proven to be existentially unforgeable against adaptive chosen message attacks in the random oracle model. The proposed scheme has potential applications in trusted computing. Copyright © 2013 John Wiley & Sons, Ltd.
Jiguo Li 0001, Haiting Du, Yichen Zhang 0003, Yuexin Zhang
Concurr. Comput. Pract. Exp.3
2013 Privacy-Preserving Decentralized Ciphertext-Policy Attribute-Based Encryption with Fully Hidden Access Structure
Huiling Qian, Jiguo Li 0001, Yichen Zhang 0003
ICICS3
2013 Forward Secure Certificateless Proxy Signature Scheme
Jiguo Li 0001, Yanqiong Li, Yichen Zhang 0003
NSS3
2013 Provably secure certificate-based signature scheme without pairings
Jiguo Li 0001, Yichen Zhang 0003
Inf. Sci.3
2012 An efficient short certificate-based signature scheme
Jiguo Li 0001, Xinyi Huang 0001, Yichen Zhang 0003
J. Syst. Softw.3
2003 Nonrepudiable Proxy Multi-Signature Scheme
Jiguo Li 0001, Zhenfu Cao, Yichen Zhang 0003
J. Comput. Sci. Technol.3