VLDB 2026 Research / reviewers in the wild / expert
Yuling Chen 0002
dblp:37/4474-2
· DBLP profile ↗
47ranked-venue papers
5as first author
45since 2021 · last 2027
0000-0002-8674-8356ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 18 · 1 first-author · 18 since 2021Security and privacy · 11 · 1 first-author · 10 since 2021Artificial intelligence and machine learning · 9 · 2 first-author · 9 since 2021Databases, data management, data science and information retrieval · 6 · 2 first-author · 6 since 2021Systems, architecture and hardware · 5 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | Federated learning based on personalized differential privacy and parameter selection
Nisuo Du, Yangyang Long, Haiwei Sang, Yuling Chen 0002 |
Expert Syst. Appl. | 5 |
| 2026 | Privacy-preserving in cloud networks: An efficient, revocable and authenticated encrypted search scheme
Yibo Cao, Shiyuan Xu, Gang Xu 0006, Yuling Chen 0002, Siu-Ming Yiu |
Comput. Networks | 5 |
| 2026 | CTI-Thinker: an LLM-driven system for CTI knowledge graph construction and attack reasoningabstractAbstract With the increasing frequency of APT attacks, cyber defense urgently demands high-quality threat intelligence support. Cyber threat intelligence (CTI) knowledge graphs have demonstrated significant potential in aiding threat detection and behavioral reasoning. However, existing CTI data often suffer from unstructured formats, fragmented knowledge, a reliance on manual annotation, and limited semantic mapping to attack techniques. These limitations hinder the robustness and accuracy of downstream reasoning tasks (e.g., attack attribution and intent inference). Moreover, traditional information extraction methods struggle to generalize in scenarios involving cross-paragraph dependencies, emerging threats, and low-resource samples, exhibiting weaknesses in context awareness and sensitivity to prompt variations. To this end, we propose CTI-Thinker, a novel system that integrates large language models with semantic alignment to the ATT&CK framework for CTI knowledge graph construction and threat reasoning. First, CTI-Thinker leverages in-context learning and LoRA-based fine-tuning to extract structured threat entities and relations. Then, it adopts vector-based alignment strategies to unify heterogeneous expressions, enabling entity normalization and knowledge fusion for constructing a high-quality CTI knowledge graph. Finally, a GraphRAG-based reasoning engine is built by incorporating the structured knowledge graph and external ATT&CK resources into a retrieval-augmented generation (RAG) framework, enabling tactical-level inference and CTI-driven question answering. Experimental results demonstrate that CTI-Thinker accurately extracts threat entities and relations and constructs a reliable CTI knowledge graph. It also effectively infers attack intent and supports intelligent reasoning. The system outperforms state-of-the-art methods in precision, robustness, and generalizability, offering a scalable and semantically enriched solution for cyber threat analysis and defense. Graphical abstract Xiuzhang Yang, Ruijie Zhong, Yuling Chen 0002, Guojun Peng, Dongni Zhang |
Cybersecur. | 3 |
| 2026 | CTIExpert: Towards expert-level cyber threat intelligence extraction for constructing cybersecurity knowledge graphs
Ruijie Zhong, Yuling Chen 0002, Xiuzhang Yang, Xinyang Zhong, Zhongxiang He |
Expert Syst. Appl. | 2 |
| 2026 | Blockchain-Based Trustworthy Verifiable Federated Learning for 6G Internet of VehiclesabstractWithin the realm of 6G Internet of Vehicles (6G-IoV), Federated Learning (FL) has become a notable machine learning framework, providing a decentralized method to protect data privacy while allowing cooperative model training. Specifically, with 6G technology, FL will benefit from ultra-low latency, high reliability and massive connectivity, enabling real-time model updates and efficient data sharing in the 6G-IoV ecosystem. However, FL faces challenges like the single points of failure and potential privacy leakage from data providers. To tackle the aforementioned challenges, we propose a blockchain-based trustworthy verifiable FL scheme for 6G-IoV, that is, AVBFL. Firstly, we introduce blockchain technology to address the issue of decentralization by storing transactions on-chain. Furthermore, to protect the privacy of local gradients, we utilize the Burmester-Desmedt (BD) multi-party key agreement protocol to negotiate a shared key and encrypt the gradients with the AES encryption algorithm. We also sign transactions using the ECDSA signature algorithm. Additionally, we design a time-sensitive Proof of Stake (TPoS) consensus mechanism based on Newton’s cooling law to boost participants’ enthusiasm for training and select the miner with the highest stake to mine the block. Finally, experiments have demonstrated the effectiveness of AVBFL. In the presence of malicious nodes, the average accuracy rate is increased by 71.8% compared to the VFL scheme and by 8.6% compared to the VBFL scheme. Mian Ahmad Jan, Haiwei Sang, Yuling Chen 0002 |
IEEE Internet Things J. | 5 |
| 2026 | FedCoguard: A Defense Framework for Federated Learning Against Untargeted Poisoning Attacks in Sustainable Agricultural IoTabstractThe convergence of Federated Learning (FL), a nascent decentralized machine learning paradigm, with the Internet of Things (IoT) presents unprecedented opportunities for promoting sustainable agricultural development. However, this synergy faces severe challenges from untargetd poisoning attacks which undermine the performance of global models. Due to factors such as seasonality and location, agricultural data exhibit a high degree of non-IID characteristics which further exacerbates this risk. In this context, the model updates submitted by benign clients tend to become dispersed, allowing malicious updates to blend in and go undetected. This dispersion renders traditional defense frameworks based on global anomaly detection ineffective, preventing FL from realizing its full potential in the agricultural domain. In this article, we propose FedCoguard, aimed at ensuring the integrity of FL in smart agriculture. FedCoguard shifts the perspective of defense from the server to the client. By leveraging the intrinsic differences in training objectives between benign and malicious clients, it excludes malicious updates spontaneously, thereby protecting the global model. Experiments on five benchmark datasets demonstrate that even in scenarios of highly non-IID data and a substantial presence of malicious clients, FedCoguard can achieve high accuracy and robust performance. By addressing security issues in the collaborative training process, this research alleviates the challenge of data silos in agricultural data sharing, unlocking the potential of collaborative intelligence and promoting the development of sustainable agricultural systems. Hongjie Luo, Yuling Chen 0002, Dapeng Lan, Keshi Xiong, Celimuge Wu |
IEEE Internet Things J. | 2 |
| 2026 | Dual-Trust Graph Attention Network for Malicious Device Detection in Internet of ThingsabstractInternet of Things (IoT) systems face escalating security threats as the number of connected devices surpassed 18.5 billion in 2024 and is projected to reach 39 billion by 2030. The dynamic and heterogeneous characteristics of IoT networks create vulnerabilities to sophisticated attacks. Existing trust management approaches struggle with these threats due to static graph construction, feature redundancy between direct and indirect trust, and inflexible fusion strategies. This paper proposes a Dual-Trust graph attention network-based malicious device detection method for IoT environments, named DTEM. The proposed scheme constructs dynamic temporal graphs based on real interaction history. Then it designs a completely decoupled dual-trust learning architecture. Finally it introduces a hybrid fusion mechanism. Overall, the improvements significantly enhance the detection accuracy of malicious devices in complex environments and adaptability to heterogeneous scenarios. Experimental results on the UNSW-NB15 dataset demonstrate that DTEM achieves an average F1-Score of 0.973 and ROC-AUC of 0.994 across three threat scenarios, outperforming traditional methods. Weijie Tan, Zhi Ouyang, Xiuzhang Yang, Yuling Chen 0002, Zhen Li 0036, Gang Xu 0006 |
IEEE Internet Things J. | 5 |
| 2026 | PidTree: A Pseudonym-Only Approach for Anonymous AKA in Vehicular NetworksabstractIn vehicular networks, pseudonyms are a fundamental mechanism for achieving anonymous communication. However, existing Authentication and Key Agreement (AKA) schemes typically require each pseudonym to be cryptographically bound to private information, such as a certificate or a secret key, to ensure authenticity. This approach leads to significant challenges, including complex certificate management and the inherent risks of secret key escrow. Furthermore, to maintain unlinkability, vehicles must store a large pool of pseudonyms and their associated private information–leading to prohibitive storage costs. The high computation and communication costs of such schemes are also ill-suited for the delay-sensitive nature of vehicular environments. To address these limitations, we propose a pseudonym-only approach for anonymous AKA in vehicular networks. The primary contribution of our scheme is its novel "pseudonym-only" approach to authentication, without the need to combine it with other private information. PidTree provides an efficient pseudonym generation method. Our scheme involves lightweight computation operations such as hash functions and Lagrange interpolation. The security analysis shows that our scheme satisfies the essential security and privacy requirements of vehicular networks. Our scheme reduces the storage cost for the trusted party fromO(MN)toO(M)and the storage cost for a vehicle by at least 86.50%. The performance analysis also shows that our scheme outperforms the representative schemes in terms of computation cost and simulation results. Jinyu Fan, Yuling Chen 0002, Xia Feng, Liangmin Wang 0001 |
IEEE Internet Things J. | 3 |
| 2026 | Thwarting gradient inversion in federated learning via generative shadow mapping defense
Hui Zhou 0014, Yuling Chen 0002, Zheng Qin 0001, Ziyu Peng |
J. Syst. Archit. | 2 |
| 2026 | FreqMambaMark: Wavelet-Mamba-driven robust medical image watermarking
Zhongxiang He, Yuling Chen 0002, Yixian Yang, Zhi Ouyang, Long Chen 0038 |
Knowl. Based Syst. | 2 |
| 2026 | AuthGraph: Authorized Search Over Encrypted Social Graph Database With Trusted HardwareabstractPrivacy-preserving social graph search allows the retrieval of relationships within social networks while not com promising individuals' private information. Although numerous solutions enable conjunctive queries for relationships on encrypted social networks, the multi-client model is neglected despite its crucial role in collaborative data sharing, and personalized recommendations. In this paper, we present AuthGraph, a privacy-preserving and conjunctive social graph search system with trusted hardware in the multi-client (i.e., multi-writer/multi reader) model. In AuthGraph, a data owner delegates update rights to writers for maintaining dynamic social relationships, while readers are allowed to perform edge-weighted conjunctive queries via writer-enforced access policy. Technically, AuthGraph builds a multi-writer/multi-reader model with access control delegation for writers via a set-constrained pseudo-random function, and uses attribute-based encryption to configure authorizations for readers. To give a provably secure conjunctive search system over a dynamic social graph database, AuthGraph revisits oblivious dynamic cross tag protocol via providing comprehensive forward privacy and Type-O backward privacy. Different from previous solutions, in AuthGraph, the semi-black-box deployment of trusted hardware effectively ensures system security while maintaining performance. Finally, we demonstrate the performance of AuthGraph through extensive experiments on real social network datasets on AliCloud, revealing that the writer enforced access policy has minimal impact on search time cost. Jiawen Wu 0001, Yifan Xu 0010, Kai Zhang 0016, Pengfei Wu 0003, Yuling Chen 0002, Jianting Ning |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | LHRS-LTW: A Load-Aware Hybrid-Cloud Resource Scheduling Framework for Large-Scale Training Workloads
Ao Wei, Jing Yang 0017, Pu Pang, Shixuan Sun, Xiaoli Ruan, Yuling Chen 0002, Minyi Guo |
IEEE Trans. Parallel Distributed Syst. | 6 |
| 2025 | A PUF-Enhanced Fog-Enabled Hierarchical Authentication Protocol for Internet of VehiclesabstractInternet of Vehicles (IoV) has become the key technology to improve road safety and traffic efficiency. However, with the explosion of the number of vehicles and more frequent authentication, computing and communication costs increase. Nevertheless, most of the traditional IoV authentication protocols lack scalability and are vulnerable to physical attacks and internal attacks, so they are difficult to meet the needs of modern IoV environment. To address these issues, this paper proposes a hierarchical mutual authentication protocol for the IoV based on physical unclonable function (PUF) and fog computing. In this protocol, we design a three-layer architecture for IoV supported by fog computing, where the fog node (FN) acts as an intermediate authentication layer, managing a group of roadside units (RSUs) and sharing the computational tasks of the trusted authority (TA) to alleviate its burden. Moreover, PUFs are embedded in entity devices to encrypt sensitive parameters, preventing internal data leakage. Based on this architecture, our protocol implements both vehicle-to-infrastructure (V2I) authentication and group authentication. In the V2I authentication, the FN distributes session keys in bulk to a group of RSUs and multiple vehicles, significantly reducing the repetitive authentication overhead between vehicles and RSUs. In the group authentication, the RSU authenticates vehicles and distributes group key, thereby avoiding the need for frequent authentication. We have also implemented fast updates of session keys and group keys, independently completed by the FN and RSU, reducing reliance on the TA and enhancing key security. We have conducted both formal and informal security analyses of the proposed protocol and used the ProVerif tool to verify its security. The results demonstrate that the protocol meets the security requirements needed for IoV. The evaluation results shows that the proposed protocol can significantly reduce the computation and communication overhead, and improve the overall performance of the system. Chunzhi Jia, Weijie Tan, Zhen Li 0036, Yuling Chen 0002, Rui Zhao 0002, Qixiang Niu, Chunguo Li |
IEEE Internet Things J. | 5 |
| 2025 | Cross-Chain Privacy Preserving for BIoMT With Designated Verifier Proxy SignatureabstractBlockchain-enabled Internet of Medical Things (BIoMT) has received extensive attention and in-depth research to solve the centralized, data island problems with the rapid developments of blockchain-related technologies. However, many different chains with different data structures, consensus protocols, and cryptographic algorithms are constructed, which brings a new “data island” problem. Meanwhile, the cryptographic algorithms used in most current BIoMT systems are weak against quantum attacks. In this article, a cross-chain privacy-preserving (CCPP) model and a designated verifier proxy signature (DVPS) scheme have been proposed. This CCPP model is equipped with the relay chain technology and DVPS to achieve secure cross-chain medical data-sharing among different BIoMT systems. The DVPS scheme is constructed with lattice theory, which can achieve signer proxy, designated user verification, and anti-quantum attack. Then, the security proof shows that the proposed DVPS can capture the security properties of correctness, unforgeability, the signer’s anonymity, and nontransferability. The performance evaluations show that the cross-chain transactions are efficient and stable with the transaction number increasing, and the proposed DVPS is efficient about the key size, time consumption, and energy consumption. This work can also improve the privacy security of system users and medical data in BIoMT systems and promote the value play of medical data. Chaoyang Li 0001, Bohao Jiang, Mianxiong Dong, Yuling Chen 0002, Xiangjun Xin 0002, Kaoru Ota |
IEEE Internet Things J. | 4 |
| 2025 | CUBE-PUF-Based Anonymous Mutual Authentication Protocol for Internet of VehiclesabstractThe Internet of Vehicle (IoV) is a core component of smart city development. However, data interactions between IoV entities involve personal privacy, and once maliciously attacked, they may threaten the stable operation of the entire transportation system. Traditional authentication protocols suffer from high computational and communication overheads and are vulnerable to various threats, including physical attacks, entity impersonation, and replay attacks. Moreover, due to their reliance on centralized trusted authority(TA), traditional protocols are prone to single-point failures, especially when handling large-scale vehicle access. To address these challenges, this paper proposes a lightweight mutual authentication protocol based on physical unclonable function(PUF), which not only ensures vehicle anonymity and traceability but also supports a pseudonym update function after authentication. The protocol employs an architecture in which the main TA(MTA) is responsible for registration and data storage, while the sub-TA(STA) handles authentication, thereby effectively mitigating the risk of a single-point failure. Additionally, to counter the exposure of a large number of challenge-response pairs in traditional PUF-based authentication—making them susceptible to machine learning(ML)-based modeling attacks—this paper introduces a CUBE-PUF scheme based on digital Rubik’s Cube and random numbers. This approach enhances response unpredictability and randomness. We conduct both formal and informal security analyses of the proposed protocol and rigorously verify its security using the ProVerif verification tool. Furthermore, comparative evaluations with existing protocols demonstrate that our approach significantly reduces communication and computational overhead while offering enhanced security. Weijie Tan, Chunzhi Jia, Yuling Chen 0002, Kun Niu, Chunguo Li, Yangmei Zhang 0001 |
IEEE Internet Things J. | 4 |
| 2025 | XLM4Detector: Multistage Deobfuscation and Semantic-Driven Excel 4.0 Macro Malware DetectionabstractExcel 4.0 Macro leverages XLM code to directly invoke system APIs and automate complex tasks, making it a widely used tool in phishing attacks, APT campaigns, and IoT intrusions in recent years. By constructing various obfuscated macro malware, attackers can easily evade firewalls and detection systems, thereby achieving persistent attacks. However, existing XLM malware defense mechanisms lack in-depth analysis of XLM malware families and behaviors, failing to integrate multi-dimensional features and semantic relationships effectively. As a result, detection systems struggle to accurately identify malicious operations in real-world attacks, leading to low robustness and accuracy. To this end, we propose XLM4Detector, a novel Excel 4.0 Macro malware detection framework based on multi-stage deobfuscation and multi-view semantic fusion. First, XLM4Detector integrates AST analysis, simulated execution, and regular expression matching to construct a multi-stage deobfuscation algorithm, enabling precise deobfuscation and XLM code extraction. Second, we introduce four feature extraction methods that capture fine-grained features at the word (string), token (function), abstract syntax tree, and semantic relationship levels. Then, we design four embedding representations (XlmWord2Vec, XlmToken2Vec, XlmAst2Vec, XlmRela2Vec) and employ a multi-view semantic fusion algorithm for feature alignment. Finally, we develop an MHSACNN-BiGRU model to capture hierarchical semantic relationships, effectively enabling XLM malware behavior detection and family classification. Experimental results demonstrate that XLM4Detector effectively reconstructs obfuscated XLM source code and accurately detects XLM malware families and behaviors. It outperforms state-of-the-art methods in detection accuracy, robustness, and generalization. Our framework provides critical technical support for IoT security defense, malicious document detection, and APT tracking. Xiuzhang Yang, Yuling Chen 0002, Zhi Ouyang, Guojun Peng |
IEEE Internet Things J. | 2 |
| 2025 | Verifiable and Redactable Blockchain for Internet of Vehicles Data SharingabstractBlockchain enhances the security and interoperability of Internet of Vehicles (IoV) systems by serving as a secure and decentralized platform for data sharing. The rapid growth of IoV data makes it challenging to store the entire blockchain on edge nodes with limited storage resources due to the blockchain’s immutability. Redactable blockchain represents a potential solution for enabling the controlled modification of data on blocks. However, current redactable blockchain schemes suffer from high-computational overhead and lack support for stateful redaction and consistency checking. In this article, we propose a secure and efficient decentralized chameleon hash scheme (CHSTS) based on Schnorr threshold signatures. CHSTS allows${t}$-out-of-${n}$edge nodes to collaborate with the transaction proposer to compute chameleon hash collisions, enabling modification and deletion of block data without breaking the hash links between the blocks. We then construct a redactable blockchain utilizing CHSTS to alleviate the storage limitations of edge nodes. To ensure consistency checking and stateful redaction of the redactable blockchain, we design a novel modification verification mechanism based on vector commitments. Finally, we provide detailed security analysis of the CHSTS scheme and integrate the proposed scheme into hyperledger fabric to evaluate the redactable blockchain through extensive experiments. The results demonstrate that our scheme incurs less computational overhead compared to the state-of-the-art chameleon hash schemes. Furthermore, our scheme maintains close efficiency compared to immutable blockchain, incurring negligible storage overhead. Yuxiang Yang 0006, Yuling Chen 0002, Zhiquan Liu 0001, Chaoyue Tan |
IEEE Internet Things J. | 2 |
| 2025 | Quantum-safe identity-based designated verifier signature for BIoMT
Chaoyang Li 0001, Yuling Chen 0002, Mianxiong Dong, Jian Li 0035, Xiangjun Xin 0002, Kaoru Ota |
J. Syst. Archit. | 2 |
| 2025 | P-EVFL: Efficient verifiable federated learning with privacy
Xiangshen Ma, Yuling Chen 0002 |
Knowl. Based Syst. | 3 |
| 2025 | Synergistic Multi-Modal Keystroke Eavesdropping in Virtual Reality With Vision and Wi-FiabstractIn panoramic and immersive virtual reality (VR) scenarios, users type on a floating and invisible keyboard, which cannot be observed by external adversaries, creating the illusion that their input is confidential. While recent studies have demonstrated the feasibility of leveraging side-channel information (e.g., vision, Wi-Fi) to eavesdrop on keystrokes in VR, they assume users typically type with fixed gestures, similar to using traditional physical keyboards. However, in real world scenarios, VR creates a 3D immersive environment, allowing users to type from varying orientations. This variation significantly degrades the quality of side-channel information (e.g., occlusion in vision, instability in Wi-Fi channels), leading to ineffective inference. In this study, we propose a multi-modal keystroke eavesdropping attack called WiViLeak, which combines Wi-Fi and vision information to complement each other. To address low-quality side-channel data caused by users’ varying orientations, we develop a theoretical model to explore the relationship between users’ hand movements in physical space (from the vision modality) and fluctuating Wi-Fi signals (from the wireless modality) as users change orientation. Based on this, we design a fully transformer based orientation calibration module to recover users’ vision data, aligning it as if they were facing the camera (i.e., in a front-facing view). Meanwhile, WiViLeak reconstructs Wi-Fi data to correspond to the front-facing view, utilizing the orientation angle derived from vision data. Finally, WiViLeak extracts effective features from reconstructed, high-quality vision and Wi-Fi data to predict keystrokes. We implement a WiViLeak prototype, achieving 89.2% accuracy in eavesdropping keystrokes and 93.6% top-100 password theft accuracy, while also demonstrating robustness across various real world VR scenarios, including payments, chatting, and meetings. Jiachun Li 0001, Yan Meng 0001, Fazhong Liu, Tian Dong 0003, Suguo Du, Guoxing Chen, Yuling Chen 0002, Haojin Zhu |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | Privacy-Enhanced High-Fidelity Separable Lossless Reversible Data HidingabstractObtaining commercial value of private information from big data has become commonplace, which leads to misuse of information knowledge as well as violation of information owners’ rights, and curbing such behaviors has become a challenge. In this paper, we design an embedding scheme that can be applied to privacy protection of secret information, i.e., embedding confidential information such as copyright as secret information in cover images. The secret information is divided into multiple clusters, encrypted and compressed through the use of multiple-zone folding method to optimize the embedding efficiency and minimize the distortion caused by the embedding process, it realizes the privacy feature of traceability and security protection of secret information in circulation. Evaluated by security analysis and experimental results, this proposed scheme achieves IND-CPA high information security level for information protection. Compared with the state-of-the-art scheme, the computational complexity of this proposed scheme isO(Y) (Ydenotes the total number of pixels), at least 6 bits of information can be embedded per pixel which improves the efficiency of embedding. In terms of the impact on the quality of cover image information after the embedding of secret information, it has better performance, and improves the manageable traceability of information. Yuling Chen 0002, Zhi Ouyang, Weijie Tan, Xiuzhang Yang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Einocchio: Efficiently Outsourcing Polynomial Computation With Verifiable Computation and Optimized Newton InterpolationabstractCloud computing, as a promising service platform, has gained significant popularity in addressing emerging data privacy issues in applications such as machine learning and data mining. Researchers have proposed the verifiable computing that allows the cloud users to delegate their computation tasks to the cloud server. Then, the cloud server computes the cryptographic proofs that verify the correctness of the results, a process that is generally faster ompared to local manual computation. However, performing computation tasks or verifying the correctness of encrypted data, such as multivariate polynomial functions, remains a significant challenge. To solve this problem, we propose Einocchio: a verifiable computation scheme that combines the efficient Pinocchio system with homomorphic encryption, which allows the public verification of the computational results on the server side while ensuring data confidentiality and the results. Compared with the existing solutions, Einocchio does not reveal the client’s input. Furthermore, we extrapolate Einocchio by optimizing the Pinocchio’s quadratic arithmetic program component using a differential optimization method, which reduces the computational workload owing to the conversion from quadratic to linear complexity, thereby increasing the efficiency of the quadratic arithmetic program preprocessing stage. Security analysis demonstrates that Einocchio achieves IND-CPA security. Finally, the performance evaluation confirmed its effectiveness and suitability for cloud computing environments. Compared to the corresponding scheme based on Newton interpolation, Einocchio achieves a threefold greater computational efficiency, with the generation of interpolation polynomials for 50 data inputs occurring in a mere 0.31 ms, while simultaneously reducing the number of computations. Xintao Pei, Yuling Chen 0002, Yangyang Long, Haiwei Sang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | A Redactable Blockchain-Based Anonymous Announcement Scheme for VANETsabstractBlockchain serves as a trust layer for data exchange in Vehicular Ad-hoc Networks (VANETs) due to its immutability and transparency. However, it can also be abused to spread false and inaccurate information. Additionally, the explosive growth of data in VANETs and the limited storage capacity of edge nodes make it challenging to maintain the entire blockchain. To address these challenges, we propose an anonymous vehicle announcement scheme based on redactable blockchain. Specifically, we propose a novel ephemeral trapdoor revocable chameleon hash scheme (ETRCH) that enables decentralized management and enforced revocation of redaction privileges. ETRCH deploys multiple regulators, each capable of creating multiple ephemeral trapdoors. These regulators enable${\boldsymbol}{k}$-out-of-${\boldsymbol}{n}$edge nodes associated with the same ephemeral trapdoor to collaboratively rewrite blockchain data, thereby addressing storage limitations. In addition,${\boldsymbol}{k}$-out-of-${\boldsymbol}{n}$regulators can cooperate to update the ephemeral trapdoor and revoke the redaction privileges of any malicious regulator discovered to be abusing their privileges. To facilitate the threshold authentication of announcement messages, we construct a redactable threshold ring signature scheme (RTRS) based on ETRCH, enabling anonymous signing of announcements in VANETs. Additionally, if a regulator detects a false or misleading message, the content can be promptly rewritten. Finally, we conducted rigorous security analysis and comprehensive experiments to evaluate the performance of the proposed scheme. The results demonstrate that compared to VANETs systems based on immutable blockchains, our scheme is both secure and efficient. Yuxiang Yang 0006, Yuling Chen 0002, Zhiquan Liu 0001, Yan Meng 0001, Haiwei Sang |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2024 | Diffusion Model-based Metaverse Rendering in UAV-Enabled Edge Networks With Dual ConnectivityabstractMetaverse is an immersive, seamless, interactive, comprehensive virtual world, as well as a replication, extension, and transcendence of the real world. Unmanned aerial vehicle (UAV)-enabled mobile edge computing (MEC) is becoming a key technology for ubiquitous Metaverse services. To enhance network resource utilization, we introduce dual connectivity (DC) technologies in UAV-enabled MEC, which increases the time complexity associated with resource management. Considering the specific features of DC communication channels, we propose a UAV-assisted Metaverse rendering problem to enhance the Metaverse service experience and reduce the energy cost of edge devices. To solve the rendering problem with low complexity, we propose a diffusion model-based Metaverse rendering algorithm, where a novel diffusion model is used to generate integer rendering decisions with the aid of the gradient provided by the model-based Metaverse rendering problem. Moreover, with the given rendering decisions, the communication and computation resource allocation results are derived by the model-based optimization method. Finally, we conduct extensive simulation experiments based on real-world datasets. Comprehensive simulation results demonstrate that the diffusion model-based Metaverse rendering algorithm can reduce the Metaverse frame rendering time and improve user experience. Guoquan Wu, Jiangtian Nie, Jianhang Tang, Yuling Chen 0002, Yang Zhang 0025, Luchao Han, Zehui Xiong |
WCNC | 4 |
| 2024 | VC-MAKA: Mutual Authentication and Key Agreement Protocol Based on Verifiable Commitment for Internet of VehiclesabstractThe Internet of Vehicles (IoV) is a specific instance of the Internet of Things (IoT) in the transportation field, driven by application requirements, such as intelligent traffic services and automatic vehicle control, can improve road safety and enhancing transmission efficiency. However, highly open networks tend to bring more security threats, and secure authentication becomes an important guarantee for reliable communication. Traditional IoT authentication and key agreement methods are costly, inefficient, and rely on the third-party trusted institutions, making them unsuitable for direct application in IoV systems. To meet the security authentication needs of IoV, and improve authentication efficiency and anonymity, this article proposes a verifiable commitment-based mutual authentication and key agreement protocol, called mutual authentication and key agreement protocol based on verifiable commitment (VC-MAKA). In VC-MAKA, we construct a verifiable commitment scheme where the verifier can verify the committed secret. Furthermore, based on this verifiable commitment scheme, we implement secure authentication and session key agreement, allowing vehicles to freely negotiate secure session keys and achieving conditional anonymous protection. Additionally, the proposed VC-MAKA also achieves rapid session key updates, enhancing the security of the session keys. We have conducted formal and informal security analysis, and the results show that VC-MAKA meets security requirements, such as mutual authentication, anonymity, traceability, and untraceability. Moreover, we have used the ProVerif tool for security experiment and performance comparison analysis, and the results indicate that compared to other schemes, the VC-MAKA protocol offers higher security and better efficiency. Weijie Tan, Yangyang Long, Yuling Chen 0002, Kun Niu, Chunguo Li, Weiqiang Tan |
IEEE Internet Things J. | 4 |
| 2024 | Efficient Designated Verifier Signature for Secure Cross-Chain Health Data Sharing in BIoMTabstractBlockchain technology brings a method for cross-institution health data sharing through the systems of the Internet of Medical Things (IoMT). As different medical institutions compete to establish their own blockchain ledgers, it leads to new problems of “data island”. In this paper, a relay chain-based multi-chain fusion (MCF) model has been designed for blockchain-enabled IoMT (BIoMT), which can achieve cross-institution health data sharing by composing different blockchains together. In this MCF model, the existing patient private health chain, medical institution chain, and government supervision chain compose a cross-chain health data-sharing platform, which extends the storage capacity of health data, and the capacity of data sharing among different departments, institutions, and fields. Meanwhile, a cross-chain transaction model has been established which helps to achieve secure cross-chain transactions among different medical institutions. Then, to guarantee user privacy in the cross-chain transaction process, a designated verifier signature (DVS) scheme is proposed. Only the designated verifier can verify this DVS and other users cannot identify the real signer. This DVS also can achieve the anonymity of the signer as the third party cannot distinguish the signature generated by the signer or the verifier. Moreover, the proposed DVS scheme can be proved to capture the unforgeability, non-transferability, and signer anonymity with the random oracle model. The theoretical analyses and efficiency comparisons are given which show the efficiency of the proposed DVS scheme compared with similar schemes. The performance simulation of the cross-chain transaction shows that the MCF model is secure and practical for cross-chain health data sharing among different BIoMT systems. Chaoyang Li 0001, Bohao Jiang, Mianxiong Dong, Yuling Chen 0002, Xiangjun Xin 0002, Kaoru Ota |
IEEE Internet Things J. | 4 |
| 2024 | BFFDT: Blockchain-Based Fair and Fine-Grained Data Trading Using Proxy Re-Encryption and Verifiable CommitmentabstractFair data trading is a complex process that is often hindered by a fundamental issue of trust between data suppliers and collectors. This mistrust can lead to an impasse: data collectors hesitate to pay upfront without the data in hand, while data suppliers hold back the data until they are assured of payment. Though enlisting a trusted third party may mitigate these issues, it also presents distinct security challenges that must be carefully considered. Observing that the blockchain technique has great potential to improve security, efficiency, and transparency of data trading, we present a blockchain-based fair data trading scheme, called BFFDT, which allows the data seller trade its data in part with an interested purchaser through a smart contract for revenue. In BFFDT, the data publisher first generates the authenticated tags based on the data fields and corresponding attribute values, then encrypts the corresponding attribute values individually and generates a dynamic Merkle hash tree (D-MHT) to ensure the consistency of the attributes and attribute values. In addition, we design an innovative pairing-based proxy re-encryption mechanism to transmit the ciphertext of a symmetric key to the purchaser’s public key via a re-encryption key without any third-party intermediary, and verifies the re-encryption key using the verifiable commitment. Furthermore, the BFFDT is formally proven to be secure against the deceitful actions of both the fraudulent seller and buyer, and the experimental outcomes further confirm that BFFDT offers high efficiency and practical applicability. Yangyang Long, Changgen Peng, Yuling Chen 0002, Weijie Tan |
IEEE Internet Things J. | 3 |
| 2024 | Mutual Authentication Protocols Based on PUF and Multitrusted Authority for Internet of VehiclesabstractInternet of Vehicles (IoV) is a critical component of the transportation field, which can greatly facilitate the current transportation system. Meanwhile, more and more vehicles connect to the IoV and the security and privacy need to be guaranteed. Traditional authentication protocols based on bilinear pairs are computatively heavy and difficult to protect user identity and privacy in IoV environment. In addition, most existing protocols only consider the authentication between vehicles and infrastructure, but not consider between vehicles and vehicles, as well as single point of failure in the traditional single trusted authority (TA). To address these issues, this article proposes two lightweight mutual authentication protocols (MAPs) based on physical unclonable function (PUF) and multi-TA. The first protocol named V2I-MAP and is applied to vehicle-to-infrastructure (V2I) communication. The second is named V2V-MAP and is applied to vehicle-to-vehicle (V2V) communication. The protocols solve the interference of noise on PUF signals by fuzzy extractor, reduce the communication overhead and computation overhead of vehicles by utilizing PUF’s lightweight computation characteristics, deal with the problems of impersonation attack with the help of the unclonable characteristics of PUF, and work out single TA single point of failure problems with the multi-TA model. Finally, the security analysis and informal security analysis of the proposed protocols are demonstrates that the proposed protocols meet the security requirements of the IoV system. ProVerif is used to verify the security of the protocols. Performance analysis shows that the protocols can reduce the communication and computation overhead than the comparable protocols. Weijie Tan, Zhen Li 0036, Yuling Chen 0002, Chunguo Li |
IEEE Internet Things J. | 4 |
| 2024 | Enhancing privacy management protection through secure and efficient processing of image information based on the fine-grained thumbnail-preserving encryptionabstractThe increase of image information brings the need for secure storage and management, and people are used to uploading images to cloud servers for storage, but the issue of privacy management and protection has become a great challenge because images may contain some sensitive information. To solve this problem, this paper proposes a novel secure and efficient fine-grained TPE scheme (FG-TPE), specifically, the image pixels are firstly divided into blocks, and multiple rounds of neighboring pixel substitution and permutation fine-grained encryption operations are performed in each block to achieve obfuscated protection of sensitive feature information of the image. Then, the state transfer process of image pixel encryption is reduction to the adversarial detection in a stochastic environment, and the optimal encryption rounds bounds are found by Kalman filtering method. Finally, experiments conducted on two face datasets show that, in qualitative and quantitative comparisons, the average encryption time is decreased remarkably, improved encryption efficiency, and the ciphertext expansion rate is reduced by 19.6% on average, possessing a better image spatiality when compared to the state-of-the-art approaches. Excellent resistance to AI restoration performance has been achieved with only 16 × 16 divided block encryption, and face detection recognition has been fully defended against 32 × 32 divided block encryption, achieving a balance between privacy security and usability management of image information. Yuling Chen 0002, Chaoyue Tan, Huiyu Zhou 0001 |
Inf. Process. Manag. | 2 |
| 2024 | Blockchain-assisted full-session key agreement for secure data sharing in cloud computing
Yangyang Long, Changgen Peng, Weijie Tan, Yuling Chen 0002 |
J. Parallel Distributed Comput. | 4 |
| 2024 | Blockchain-Based Anonymous Authentication and Key Management for Internet of Things With Chebyshev Chaotic MapsabstractIn Industry 5.0, there are increasing demands for group communication with low energy consumption and high communication efficiency from a great number of Internet of Things (IoT) devices. However, group communication is still exposed to various security risks. Although some cryptographic schemes have been devised to facilitate secure group communication, the existing schemes generally rely on a trust authority to periodically issue certificates and have led to various issues, such as failing to support anonymity and flexible key management, and cannot resist the single point of failure. Therefore, in this work, leveraging Chebyshev chaotic maps and blockchain, an anonymous authentication and key management scheme is proposed to provide secure and efficient group key generation and management for mutual authentication between communication entities. The scheme exploits the blockchain to save the key materials associated with IoT devices, thereby it ensures data privacy and provides a secure environment for communication. The scheme also employs the Chebyshev polynomial to generate a group key for the IoT devices within a group, and later the group members holding the same group key can use it for secure communication. The formal and informal security analysis demonstrates that the proposed scheme can meet the security and flexible key management requirements. The detailed performance analysis shows that the proposed scheme has acceptable computation and communication energy consumption and provides superior security in comparison with existing schemes. Yangyang Long, Changgen Peng, Weijie Tan, Yuling Chen 0002 |
IEEE Trans. Ind. Informatics | 4 |
| 2024 | Privacy-Preserving Location-Based Advertising via Longitudinal Geo-IndistinguishabilityabstractAs location data have been increasingly adopted in location-based advertising (LBA), revealing locations to untrusted service providers has raised severe privacy concerns. Recent studies propose obfuscation mechanisms built upon geo-indistinguishability (geo-IND) to provide formal privacy guarantee. Unfortunately, due to the high degree of spatiotemporal regularity in human mobility pattern, the privacy cost will be unacceptably high in this situation, leading to accurate inference of user real locations. In this study, we identify this privacy risk in LBA scenarios under long-term and multi-platform assumption. We demonstrate an attacker can infer 75%∼90% of top-1 locations within a range of only 200 meters. To address it, we proposePrivLocAd, a novel system which can provide longitudinal privacy guarantee. The novelty of PrivLocAd stems from a novel surrogate-based obfuscation, which generates multiple surrogate locations to improve the privacy-utility trade-off. In addition, two novel obfuscation mechanisms, the two-stage Gaussian and multi-level surrogate generation mechanism in charge of surrogate generation can achieve the longitudinal privacy guarantee in intra- and inter-platform condition respectively. Our experimental results demonstrate PrivLocAd is able to defend against the attack, which reduces the inference rate to less than 1% of user top-1 locations in the 200 meter range. Le Yu 0002, Shufan Zhang 0001, Yan Meng 0001, Suguo Du, Yuling Chen 0002, Yanli Ren, Haojin Zhu |
IEEE Trans. Mob. Comput. | 5 |
| 2024 | A high-capacity slicing PBFT protocol based on reputation evaluation model
Yuling Chen 0002, Linlin Yuan, Chaoyue Tan, Yuxiang Yang 0006 |
Wirel. Networks | 2 |
| 2023 | Cross-domain vulnerability detection using graph embedding and domain adaptation
Xin Li 0002, Yang Xin 0001, Yixian Yang, Yuling Chen 0002 |
Comput. Secur. | 5 |
| 2023 | A mobile energy trading scheme based on Lightning NetworkabstractAbstract Current blockchain‐based energy trading models raise serious concerns regarding the high and capped transaction latency and expensive service charges. To solve these problems, In this article, we combine Lightning Network (LN) and smart contract to present a mobile energy trading scheme based on LN. The focal point of the scheme lies in transfer of value occurs off‐blockchain, which addresses the problem of transaction latency. Next, to solve the security of proposed scheme, we design a mechanism to delivery secret R. Participants exchange some parameters to calculate R instead of delivery it directly. The found security is guaranteed by committing funds into a multi‐signature address in proposed scheme. Then, we conduct a comprehensive experiment to evaluate the proposed scheme. The simulation and analysis results show that the proposed scheme is efficient than traditional trading. In addition, we analyze our entire scheme and conclude that it defenses anti‐tampering attacks and replay attack capacity effectively. Chaoyue Tan, Yuling Chen 0002, Xiaojun Ren, Changgen Peng |
Concurr. Comput. Pract. Exp. | 2 |
| 2023 | Multifactor Incentive Mechanism for Federated Learning in IoT: A Stackelberg Game ApproachabstractIn the era of the Internet of Things (IoT), remote sensors and endpoint appliances generate vast amounts of data. Decentralized and collaborative learning builds on these IoT data to enable classification and recognition tasks by inviting multiple data owners. Federated learning (FL), as a popular collaborative learning framework, can significantly improve the performance of models without collecting the original data. To invite data owners to participate in FL, various incentive mechanisms are designed to address this issue by researchers. However, existing solutions still face high costs and low utility due to information asymmetry, where the reputation, computation power, and data quantity of the data owners are not known in advance. Therefore, we propose a Stackelberg game-based multifactor incentive mechanism for FL (SGMFIFL). First, we design the Top-$K$cost selection algorithm based on reverse auction, which can reduce the cost of selecting data owners. Next, we devise a multifactor reward function based on reputation, accuracy, and reward rate, the data owners with high reputation and high accuracy will be of more reward. In particular, to ensure that SGMFIFL can provide reliable incentives in IoT, we use blockchain to provide a secure and trusted environment. Finally, we construct a two-stage Stackelberg game model for the task publisher and the data owners and derive an optimal Equilibrium solution for both stages of the whole game. Experiments conducted on two well-known data sets, MNIST and CIFAR10, demonstrate the significant performance of the proposed mechanism. Yuling Chen 0002, Hui Zhou 0014, Tao Li 0043, Jin Li 0002, Huiyu Zhou 0001 |
IEEE Internet Things J. | 1 |
| 2022 | DE-RSTC: A rational secure two-party computation protocol based on direction entropyabstractRational secure multi-party computation means two or more rational parties complete a function on private inputs. Unfortunately, players sending false information can prevent the protocol from executing correctly, which will destroy the fairness of the protocol. To ensure the fairness of the protocol, the existing works on achieving fairness by specific utility functions. In this paper, we leverage game theory to propose the direction entropy-based solution. To this end, we utilize the direction entropy to examine the player's strategy uncertainty and quantify its strategy from different dimensions. Then, we provide mutual information to construct a new utility for the players. What's more, we measure the mutual information of players to appraise their strategies. By analyzing and proofing of protocol, we show that the protocol reaches a Nash equilibrium when players choose a cooperative strategy. Furthermore, we solve the fairness of the protocol. Compared to the previous approaches, our protocol is not required deposits and design-specific utility functions. Yuling Chen 0002, Xianmin Wang, Huiyu Zhou 0001 |
Int. J. Intell. Syst. | 1 |
| 2022 | PSSPR: A source location privacy protection scheme based on sector phantom routing in WSNsabstractSource location privacy (SLP) protection is an emerging research topic in wireless sensor networks. Because the source location represents the valuable information of the target being monitored and tracked, it is of great practical significance to achieve a high degree of privacy of the source location. Although many studies based on phantom nodes have alleviates the protection of SLP to some extent. It is urgent to solve the problems, such as complicate the ac path between nodes, improve the centralized distribution of phantom nodes near the source nodes and reduce the network communication overhead. In this paper, protection scheme based on sector phantom routing (PSSPR) routing is proposed as a visible approach to address SLP issues. We use the coordinates of the center node V to divide sector domain, which act an important role in generating a new phantom node. The phantom nodes perform specified routing policies to ensure that they can choose various locations. In addition, the directed random route can ensure that data packets avoid the visible range when they move to the sink node hop by hop. Thus, the source location is protected. Theoretical analysis and simulation experiments show that this protocol achieves higher security of source node location with less communication overhead. Yuling Chen 0002, Yixian Yang, Tao Li 0043, Xinxin Niu, Huiyu Zhou 0001 |
Int. J. Intell. Syst. | 1 |
| 2022 | Is semi-selfish mining available without being detected?abstractSelfish mining attacks get a high prize due to the additional rewards unproportionate to their mining power (mining pools have particular advantages). Generally, this category of attacks stresses decreasing the threshold to maximize the rewards toward the view of attackers. Semi-selfish mining falls into the family of selfish mining attacks, where the threshold value is approximately 15%. However, it gets little attention to implement these attacks in practical. In this paper, we focus on the validity of semi-selfish mining attacks considering the probability of being detected. More specifically, we discuss mining strategies through backward deduction. That is to say that the attacking states derived from the observable states, which with normal forking rate, just as without semi-selfish mining attacks, toward the view of the honest miners. Rewards distribution is further investigated concerning these strategies. The simulation results indicate that it does not necessarily bring rewards advantage over large pools. Instead, the small pools have an advantage over the additional rewards. However, the probability for small pools to successfully implement these strategies is pretty low. That is, it is impossible for the pools, although profitable for them, to sponsor semi-selfish mining attacks without being detected. Tao Li 0043, Yuling Chen 0002, Yanling Jia, Yixian Yang |
Int. J. Intell. Syst. | 3 |
| 2021 | A Dummy Location Selection Algorithm Based on Location Semantics and Physical Distance
Baopeng Ye, Yuling Chen 0002, Huiyu Zhou 0001, Xiaobin Qian |
ISPEC | 3 |
| 2021 | Semi-selfish mining based on hidden Markov decision processabstractSelfish mining attacks sabotage the blockchain systems by utilizing the vulnerabilities of consensus mechanism. The attackers' main target is to obtain higher revenues compared with honest parties. More specifically, the essence of selfish mining is to waste the power of honest parties by generating a private chain. However, these attacks are not practical due to high forking rate. The honest parties may quit the blockchain system once they detect the abnormal forking rate, which impairs their revenues. While selfish mining attacks make no sense anymore with the honest parties' departure. Therefore, selfish miners need to restrain when launch selfish mining attacks such that the forking rate is not preposterously higher than normal level. The crux is how to illustrate the attacks toward the view of honest parties, who are blind to the private chain. Generally, previous works, especially those using Markov decision processes, stress on the increment of attackers' revenues, while overlooking the detection on forking rate. In this paper, we propose, to maintain the benefit from selfish mining, an improved selfish mining based on hidden Markov decision processes (SMHMDP). To reduce the forking rate, we also relax the behaviors of selfish miners (also known as semi-selfish miners), who mine on the private chain, to mine on public chain with a small probability ρ. Simulation results show that SMHMDP can trade off between revenues and forking rate. Put differently, selfish miners benefit from attacking within an acceptable forking rate toward the view of honest parties, without leading selfish mining attacks to be an armchair strategist. Tao Li 0043, Guoyu Yang, Yuling Chen 0002, Xiaomei Yu |
Int. J. Intell. Syst. | 5 |
| 2021 | ImpSuic: A quality updating rule in mixing coins with maximum utilitiesabstractvMixing coins strategy can realize the anonymity of user information, thereby protecting the user's privacy. Ideally, the blacklist is public information and all bad coins are recorded in it. However, due to the failure of some bad coins to be registered in the blacklist in time, users can only obtain part of the blacklist information, which allows illegal criminals to take advantage of it. How to prevent illegal activities under the partial information blacklist and how to design coins' quality updating rule rationally have become open issues in mixing coins. The updating rule of coins' quality in mixing is addressed since illegal criminals may carry out illegal activities, for example, money laundering. ImpSuic, an improved suicide strategy, is proposed as a new quality updating rule. The intuition is: all coins of the one who has the highest bad coins according to the blacklist, are recorded as bad coins. On the other hand, the coins' quality of others remain unchanged. Besides, linear programming is introduced into ImpSuic strategy to predict the maximum utility after mixing coins, which facilitates users to make reasonable decisions before mixing coins. Simulation results show that the quality updating rule in ImpSuic strategy can preserve users' privacy and antimoney launder. Xinying Yu, Fengyin Li, Tao Li 0043, Yuling Chen 0002, Youliang Tian, Xiaomei Yu |
Int. J. Intell. Syst. | 6 |
| 2021 | Corrigendum to "Rational Protocols and Attacks in Blockchain System"
Tao Li 0043, Yuling Chen 0002, Minghao Zhao 0001, Haojia Zhu, Youliang Tian, Xiaomei Yu, Yixian Yang |
Secur. Commun. Networks | 2 |
| 2021 | Cross-Platform Strong Privacy Protection Mechanism for Review PublicationabstractAs a review system, the Crowd-Sourced Local Businesses Service System (CSLBSS) allows users to publicly publish reviews for businesses that include display name, avatar, and review content. While these reviews can maintain the business reputation and provide valuable references for others, the adversary also can legitimately obtain the user’s display name and a large number of historical reviews. For this problem, we show that the adversary can launch connecting user identities attack (CUIA) and statistical inference attack (SIA) to obtain user privacy by exploiting the acquired display names and historical reviews. However, the existing methods based on anonymity and suppressing reviews cannot resist these two attacks. Also, suppressing reviews may result in some reiews with the higher usefulness not being published. To solve these problems, we propose a cross-platform strong privacy protection mechanism (CSPPM) based on the partial publication and the complete anonymity mechanism. In CSPPM, based on the consistency between the user score and the business score, we propose a partial publication mechanism to publish reviews with the higher usefulness of review and filter false or untrue reviews. It ensures that our mechanism does not suppress reviews with the higher usefulness of reviews and improves system utility. We also propose a complete anonymity mechanism to anonymize the display name and avatars of reviews that are publicly published. It ensures that the adversary cannot obtain user privacy through CUIA and SIA. Finally, we evaluate CSPPM from both theoretical and experimental aspects. The results show that it can resist CUIA and SIA and improve system utility. Yang Xin 0001, Qifeng Tang, Yuling Chen 0002, Yixian Yang, Guangcan Yang |
Secur. Commun. Networks | 6 |
| 2021 | Dynamic Multi-Key FHE in Asymmetric Key Setting From LWEabstractMulti-key Fully homomorphic encryption (MFHE) schemes allow computation on the encrypted data under different keys. However, traditional multi-key FHE schemes based on Learning with errors (LWE) have the undesirable property that is the number of keys has to be fixed in advance. A dynamic multi-key FHE scheme is the most versatile variant which the information about the participants is not required before key generation. To support further homomorphic computation on extended ciphertexts and ciphertexts encrypted under additional keys, Peikert and Shiehian (TCC ’16) proposed a leveled dynamic multi-key FHE scheme. Nevertheless, it introduces the circular-security assumption for the LWE parameters to ensure its security, which provides weaker security to the scheme. The problem of how to construct a LWE-based dynamic multi-key FHE scheme is still open. To address the above problem, in this work, we present a dynamic multi-key FHE scheme based on the LWE assumption in public key setting. The ciphertext can be extended and performed homomorphic evaluation with the ciphertexts encrypted under additional keys. Compared with current constructions, our proposed method requires fewer “local” memory and the process of ciphertext extension is distributed. Our proposed method provides a new way to extend the ciphertext such that the ciphertext homomorphism computation is more efficient. Our scheme is proven to be secure under standard LWE assumptions without using the circular-security assumption. Yuling Chen 0002, Sen Dong, Tao Li 0043, Huiyu Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Rational Protocols and Attacks in Blockchain SystemabstractBlockchain has been an emerging technology, which comprises lots of fields such as distributed systems and Internet of Things (IoT). As is well known, blockchain is the underlying technology of bitcoin, whose initial motivation is derived from economic incentives. Therefore, lots of components of blockchain (e.g., consensus mechanism) can be constructed toward the view of game theory. In this paper, we highlight the combination of game theory and blockchain, including rational smart contracts, game theoretic attacks, and rational mining strategies. When put differently, the rational parties, who manage to maximize their utilities, involved in blockchain chose their strategies according to the economic incentives. Consequently, we focus on the influence of rational parties with respect to building blocks. More specifically, we investigate the research progress from the aspects of smart contract, rational attacks, and consensus mechanism, respectively. Finally, we present some future directions based on the brief survey with respect to game theory and blockchain. Tao Li 0043, Yuling Chen 0002, Minghao Zhao 0001, Haojia Zhu, Youliang Tian, Xiaomei Yu, Yixian Yang |
Secur. Commun. Networks | 2 |
| 2018 | RoFa: A Robust and Flexible Fine-Grained Access Control Scheme for Mobile Cloud and IoT based Medical MonitoringabstractCloud computing paradigm is becoming very popular these days. However, it does not include wireless sensors and mobile phones which are needed to enable new emerging applications such as remote home medical monitoring. Therefore, a combined Cloud-Internet of Things (IoT) paradigm provides scalable on-demand data storage and resilient computation power at the cloud side as well as anytime, anywhere health data monitoring at the IoT side. As both the privacy of personal medical data and flexible data access should be provided,attackers exploit diverse social engineering and technology attacks ways, access to personal privacy information stored in the home medical monitoring cloud, with more and more social engineering attacks.Therefore, the data in the Cloud are always encrypted and access control must be operated upon encrypted data together with being fine-grained to support diverse accessibility. Since a plain combination of encryption before access control is not robust and flexible, we propose a scheme referred to as RoFa, with tailored design. The scheme is introduced in a step-by-step manner. The basic scheme (BaS) makes use of cipher-policy attributes based encryption to empower robustness and flexibility. We further propose an advanced scheme (AdS) to improve the computation efficiency by taking the advantages of proxy-reencryption. AdS can greatly decrease the computation overhead on hospital servers due to operation migration. We finally propose an enhanced scheme (EnS) to protect integrity by using aggregate signature. RoFa describes a general framework to solve the secure requirements, and leaves the flexibility of concrete constructions intentionally. We finally compare the robustness and the flexibility of the proposed schemes by performance analysis. Yuling Chen 0002, Wei Ren 0002, Yi Ren 0001, Zhiguo Qu |
Fundam. Informaticae | 1 |