Syh-Yuan Tan

dblp:37/7974 · DBLP profile ↗
← Back
21ranked-venue papers
11as first author
7since 2021 · last 2025
0000-0003-1182-1210ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 6 first-author · 6 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 1 since 2021Theory of computation · 2 · 1 first-authorComputer networks · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 MoniPoly - An Expressive $q$q-SDH-Based Anonymous Attribute-Based Credential System With Constant-Size Proofs
abstract
Modern anonymous attribute-based credential (ABC) systems benefit from expressive and efficient show proofs on logical statements. Camenisch and Groß pioneered such statements with an Strong RSA-based ABC system on a restricted message space that offers efficient$\mathsf{AND}$,$\mathsf{OR}$and$\mathsf{NOT}$proofs. While other ABC frameworks have adopted constructions in the same vein, the Camenisch-Groß ABC has been the most expressive and asymptotically most efficient proof system to date. Due to its use of prime numbers as message space, however, it is constrained by the requirement of a trusted message-space setup and an inherent restriction to pre-defined finite-set attributes. In this paper, we present a provably secure ABC system that supports show proofs for complex logical statements on an unrestricted message space. Our construction is founded on the commit-and-sign paradigm and offers a novel commitment scheme. This construction is not only more expressive than existing approaches, but also highly efficient. Its ECC protocols only require a constant number of bilinear pairings by the verifier; none by the prover. As the security models for the existing approaches do not capture the expressiveness of this scheme, we introduce strong security models for impersonation resilience and unlinkability under adaptive active and concurrent attacks. Based on the$q$-(co-)SDH assumption, we prove the scheme's security with respect to both properties with tight reductions.
Syh-Yuan Tan, Thomas Groß 0001
IEEE Trans. Dependable Secur. Comput.1
2024 Efficient Fork-Free BLS Multi-signature Scheme with Incremental Signing
Syh-Yuan Tan, Tiong-Sik Ng, Swee-Huay Heng
ProvSec (1)1
2024 K-Resilient Public Key Authenticated Encryption with Keyword Search
abstract
The public key encryption with keyword search (PEKS) scheme is a cryptographic primitive introduced to securely store and allow specific searches within encrypted data. Traditional encryption prioritises confidentiality but complicates search operations, requiring decryption before searches can be conducted. PEKS scheme addresses this limitation by enabling authorised users to search for specific keywords within encrypted data without compromising the underlying encryption. This facilitates efficient and secure data retrieval without the need to decrypt the entire dataset. However, PEKS is susceptible to the keyword guessing attack (KGA), exploiting the deterministic nature of the PEKS trapdoor so the adversary can correctly guess the keyword encrypted in a trapdoor. To enhance PEKS security to counter KGA, various schemes have been proposed. A notable one is public key authenticated encryption with keyword search (PAEKS). PAEKS combines authentication and encryption with keyword-bas ed search functionalities, ensuring data source authentication, encrypted information security, and keyword-based searches. This approach offers a more robust and secure alternative to traditional PEKS. However, many existing PAEKS schemes rely on computationally exhaustive bilinear pairing. In this paper, we propose a PAEKS scheme based on k-resilient identity-based encryption without bilinear pairing. By using the provable security approach, we show that our proposed PAEKS scheme satisfies keyword privacy and trapdoor privacy. Furthermore, we also present a performance evaluation of our proposed PAEKS scheme with other related PAEKS schemes and show the efficiency of our proposed scheme.
Koon-Ming Chan, Swee-Huay Heng, Syh-Yuan Tan, Shing Chiang Tan
SECRYPT3
2024 Comment on "An efficient identity-based signature scheme with provable security"
Syh-Yuan Tan, Swee-Huay Heng
Inf. Sci.1
2023 New Identity-Based Identification and Signature Schemes in the Standard Model
abstract
In this paper, we propose an efficient identity-based identification (IBI) scheme provably secure against impersonation under active and concurrent attacks in the standard model. Based on the proposed IBI scheme and two-tier signature technique, we construct an efficient IBS scheme that is provably secure against strong existential forgery under chosen message attack in the standard model. The security for our proposed IBI and IBS schemes are based on the established q-SDH assumption. The comparison analysis shows that our proposed schemes outperform some state-of-the-art schemes which are also provably secure in the standard model.
Syh-Yuan Tan, Swee-Huay Heng
ARES1
2023 Privacy-Preserving Biometric Authentication: Cryptanalysis and Countermeasures
abstract
In this article, we cryptanalyzed a Verifiable Threshold Predicate Encryption (VTPE) enabled Privacy-Preserving Biometric Authentication (PPBA) protocol reported in IEEE-TDSC and revealed discrepancies between its security claims and our security analysis. To be precise, the underlying authentication and key agreement scheme which is based on a challenge-response mechanism and watermark signal unsatisfactorily meets the following security scenario: (a) resistance to man-in-the-middle attacks, (b) biometric template protection, and (c) user anonymity and untraceability. To address these issues, we utilize Physical Unclonable Functions (PUF) to design a PUF driven Verifiable Threshold Predicate Encryption (PUF-VTPE) scheme and a secure PPBA protocol. The PUF-VTPE-based PPBA protocol equips with dual authentication using biometric and mobile device, which offers strong authenticity before establishing the session key. Simultaneously, the non-invertible property of PUF protects the biometric templates in the physical layer. The proposed storage-free mechanism that hides the challenge of device PUF in biometric template alleviates data leakage caused by storage challenges in PUF-based authentication protocols. Moreover, the experimental analysis suggests that the proposed PPBA protocol possesses ISO/IEC 24745 criteria of non-invertibility, unlinkability, and revocability. Additionally, the proposed PPBA protocol reduces the computational cost by about 50% compared to that of the cryptanalyzed scheme.
Hui Zhang 0039, Xuejun Li 0001, Syh-Yuan Tan, Ming Jie Lee, Zhe Jin 0001
IEEE Trans. Dependable Secur. Comput.3
2021 ECQV-IBI: Identity-based identification with implicit certification
An Braeken, Ji-Jian Chin, Syh-Yuan Tan
J. Inf. Secur. Appl.3
2020 MoniPoly - An Expressive q-SDH-Based Anonymous Attribute-Based Credential System
Syh-Yuan Tan, Thomas Groß 0001
ASIACRYPT (3)1
2019 Improving Signature Schemes with Tight Security Reductions
Tiong-Sik Ng, Syh-Yuan Tan, Ji-Jian Chin
ISPEC2
2019 Enhancement of a Lightweight Attribute-Based Encryption Scheme for the Internet of Things
abstract
In this paper, we present the enhancement of a lightweight key-policy attribute-based encryption (KP-ABE) scheme designed for the Internet of Things (IoT). The KP-ABE scheme was claimed to achieve ciphertext indistinguishability under chosen-plaintext attack in the selective-set model but we show that the KP-ABE scheme is insecure even in the weaker security notion, namely, one-way encryption under the same attack and model. In particular, we show that an attacker can decrypt a ciphertext which does not satisfy the policy imposed on his decryption key. Subsequently, we propose an efficient fix to the KP-ABE scheme as well as extending it to be a hierarchical KP-ABE (H-KP-ABE) scheme that can support role delegation in IoT applications. An example of applying our H-KP-ABE on an IoT-connected healthcare system is given to highlight the benefit of the delegation feature. Lastly, using the NIST curves secp192k1 and secp256k1, we benchmark the fixed (hierarchical) KP-ABE scheme on an Android phone and the result shows that the scheme is still the fastest in the literature.
Syh-Yuan Tan, Kin-Woon Yeow, Seong Oun Hwang
IEEE Internet Things J.1
2018 A Generic Framework for Accountable Optimistic Fair Exchange Protocol
Jia-Ch'ng Loh, Swee-Huay Heng, Syh-Yuan Tan
ISPEC3
2016 Cryptanalysis of a CP-ABE scheme with policy in normal forms
Syh-Yuan Tan, Wun-She Yap
Inf. Process. Lett.1
2015 Reset-Secure Identity-Based Identification Schemes Without Pairings
Ji-Jian Chin, Hiroaki Anada, Syh-Yuan Tan
ProvSec3
2015 An implementation of enhanced public key infrastructure
Syh-Yuan Tan, Wei-Chuen Yau, Boon-Hock Lim
Multim. Tools Appl.1
2015 On the security of a lightweight authentication and encryption scheme for mobile ad hoc network
abstract
In 2011, Eissa, Razak and Ngadi proposed a lightweight authentication and encryption scheme to enhance the performance for mobile ad hoc network in Wireless Network, Vol. 17, No. 4, 2011. The main building block of such scheme is an identity-based encryption scheme. The scheme was proven secure in the random oracle model assuming the computational Diffie–Hellman assumption is hard. In this paper, we show that the proposed scheme is not even secure against chosen plaintext attack, which is the lowest acceptable level of security. In addition, we demonstrate the RSA parameter suggested by Eissa et al. to yield a better network performance is not appropriate under a wrong security assumption that each mobile node is totally trusted. Such short RSA parameter leads to a key recovery attack.
Wun-She Yap, Joseph K. Liu, Syh-Yuan Tan, Bok-Min Goi
Secur. Commun. Networks3
2013 An authentication framework for peer-to-peer cloud
abstract
Cloud computing provides on demand computation and storage services delivered via applications, system software and hardware rendered as services. Due to its on demand nature, it has high variable workloads and requires real-time efficiency and availability. Most cloud computing systems use a centralised model to provision services, but reliance on a central entity to control scheduling decision and maintain all cloud hosts may constitute a computing bottleneck. A system failure will cause service outage, sometimes for a few hours as had happened before. In addition, the central entity needs to support heavy workloads in terms of service provisioning to all resource hosts. These issues can be addressed by distributing cloud resources using structured peer-to-peer (P2P) overlay networks as was recently proposed. However these proposals do not examine potential security issues of a P2P-based cloud, one of them being how peers verify the identities of one another over a decentralised setting. Therefore we propose an authentication framework for P2P cloud consisting of various approaches for authenticating entities and messages. The framework combines cryptographic primitives and security mechanisms proposed for existing structured P2P network.
Geong Sen Poh, Mohd Amril Nurman Mohd Nazir, Bok-Min Goi, Syh-Yuan Tan, Raphael C.-W. Phan, Maryam Safiyah Shamsudin
SIN4
2013 On the security of a modified Beth identity-based identification scheme
Ji-Jian Chin, Syh-Yuan Tan, Swee-Huay Heng, Raphael C.-W. Phan
Inf. Process. Lett.2
2013 Argument on biometrics identity-based encryption schemes
abstract
ABSTRACT Recently, a few biometric identity‐based encryption (BIO‐IBE) schemes have been proposed. BIO‐IBE leverages both fuzzy extractor and Lagrange polynomial to extract biometric feature as a user public key and as a preventive measure of collusion attack, respectively. In this paper, we reveal that BIO‐IBE is not realistic whereby a query of fresh biometrics is needed for each encryption process. Moreover, the use of both fuzzy extractor and Lagrange polynomial in BIO‐IBE simultaneously is a redundancy; it confers no advantage, but simply computational overhead. Therefore, we amend the progression of the BIO‐IBE scheme by eliminating either Lagrange polynomial or fuzzy extractor to alleviate computational complexity. Subsequently, we demonstrate that the amendment does not compromise the security of the BIO‐IBE scheme. Such amendments can be applied to other BIO‐IBE schemes as well. Copyright © 2013 John Wiley & Sons, Ltd.
Syh-Yuan Tan, Zhe Jin 0001, Andrew Beng Jin Teoh
Secur. Commun. Networks1
2012 On the realization of fuzzy identity-based identification scheme using fingerprint biometrics
abstract
ABSTRACT Fuzzy identity‐based identification (FIBI) scheme is a recently proposed cryptographic identification protocol. The scheme utilizes user biometric trait as public keys. The authentication is deemed success in the presence of the genuine query biometric together with the valid private key. Because of the fuzziness nature of biometrics, FIBI does not correct the errors on the query biometric with respect to the public key; instead, it tolerates the errors using Lagrange polynomial interpolation. Therefore, FIBI requires the biometric trait to be represented in a discrete (binary or integer) array that is fixed in length. In this paper, we report the first realization of FIBI scheme by means of fingerprint biometrics using minutia representation where our technique integrates the security features of both biometric and cryptography effectively. The simulation shows that the entire protocol can be completed within 1 s where false acceptance rate (FAR) = 0% and false reject rate (FRR) = 0.25% in FVC2002 DB1, and FAR = 0% and FRR = 0.125% in FVC2002 DB2. Our integration technique may also be applied on other fuzzy identity‐based cryptosystems. Copyright © 2012 John Wiley & Sons, Ltd.
Syh-Yuan Tan, Zhe Jin 0001, Andrew Beng Jin Teoh, Bok-Min Goi, Swee-Huay Heng
Secur. Commun. Networks1
2012 Efficient encryption with keyword search in mobile networks
abstract
ABSTRACT On these days, users tend to access to online content via mobile devices, for example, e‐mails. Because these devices have constrained resources, users may wish to instruct e‐mail gateways to search through new e‐mails and only download those corresponding to particular keywords, such as “urgent.” Yet, this searching should not compromise the user's privacy. A public key encryption with keyword search (PEKS) scheme achieves both these requirements. Most PEKS schemes are constructed on the basis of bilinear pairings. Recently, Khader proposed the first PEKS scheme that does not require bilinear pairings and is provably indistinguishable chosen‐keyword attack (IND‐CKA) secure in the standard model. Such a scheme is more efficient than pairing‐based ones. In this paper, we show a drawback of Khader's scheme in that it depends on an unnecessary security assumption: Its IND‐CKA security requires its underlying identity‐based encryption building block to be indistinguishable chosen‐ciphertext attack secure. We construct a more efficient PEKS scheme that achieves the same level of PEKS security as Khader's but that only requires the underlying identity‐based encryption to be indistinguishable chosen‐plaintext attack secure. We give a direct proof that the proposed scheme is IND‐CKA secure. Our scheme outperforms other recent PEKS schemes in literature. Copyright © 2012 John Wiley & Sons, Ltd.
Wei-Chuen Yau, Swee-Huay Heng, Syh-Yuan Tan, Bok-Min Goi, Raphael C.-W. Phan
Secur. Commun. Networks3
2010 Java Implementation for Pairing-Based Cryptosystems
Syh-Yuan Tan, Swee-Huay Heng, Bok-Min Goi
ICCSA (4)1