VLDB 2026 Research / reviewers in the wild / expert
Ke Huang 0002
dblp:40/4385-2
· DBLP profile ↗
23ranked-venue papers
9as first author
17since 2021 · last 2026
0000-0002-5102-610XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 1 first-author · 5 since 2021Security and privacy · 6 · 3 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 first-author · 1 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Efficient Dual-Revocation CP-ABE for Secure and Fine-Grained Data Sharing in IoMTabstractThe Internet of Medical Things (IoMT) enables large-scale sensing and cloud-based sharing of sensitive medical data, where access control must remain fine-grained, dynamic, and robust. In practical healthcare scenarios, access privileges frequently change due to real-world incidents such as physician resignation, role reassignment, emergency response, or patient consent withdrawal, which require both user-level and attribute-level revocation mechanisms. To address these challenges, we propose a Dual Revocable CP-ABE (DABE) scheme that unifies direct and indirect revocation within a single framework, to support diverse medical data sharing scenarios. The proposed system allows data owners to flexibly select revocation modes based on operational needs: indirect revocation efficiently handles large-scale updates for remote medical records via a semi-trusted cloud server, while direct revocation enables immediate access termination through ciphertext updates for highly sensitive data. This dual-mode design improves system robustness and fault tolerance, thus avoiding a single point of failure. Moreover, DABE supports verifiable outsourced decryption to accommodate resource-constrained IoMT devices. Formal security analysis proves IND-CPA security and resistance to collusion attacks, while experimental results demonstrate practical efficiency: the decryption time remains nearly constant (approximately 15–20 ms) regardless of policy complexity, achieving an improvement of over two orders of magnitude compared to existing schemes, with only modest overhead in other phases. These results show that DABE is well-suited for large-scale, dynamic IoMT systems. Lei Mei, Ke Huang 0002, Xiong Li 0002, Xiaosong Zhang 0001 |
IEEE Internet Things J. | 2 |
| 2026 | Time Updatable Policy-Based Chameleon Hash for Traceable and Accountable Redactable BlockchainabstractAteniese et al. (EuroS&P 2017) proposed the notion of redactable blockchains (RBs), in which a designated party uses a secret key to modify blockchain history without causing a hard fork. Nevertheless, redactions may be performed mistakenly or maliciously due to misbehavior or operational errors. From a regulatory perspective, any RB design must therefore incorporate accountability and traceability mechanisms to ensure that redactions are non-abusive and publicly verifiable. As a countermeasure, we propose the notion of time-updatable policy-based chameleon hash (TPCH). This construction addresses regulatory concerns by enabling publicly verifiable proofs of redaction and traceable user identities. Our basic building block, termed time-updatable chameleon hash (TUCH), provides redaction accountability through an intrinsic property formalized as Type-2 Trapdoor Collisions. TUCH is functionally versatile and achieves acceptably efficient performance compared to peer chameleon hash schemes. Following the heuristics of Camenisch et al. (PKC 2017) and Derler et al. (NDSS 2019), we further extend TUCH by integrating attribute-based encryption (ABE) to obtain a time-updatable, policy-based variant, namely TPCH. The resulting scheme overcomes the limitations of coarse-grained redaction and the impracticality of specifying the exact modifier in advance. Overall, TPCH provides a secure, efficient, and comprehensive solution for accountable and traceable redactable blockchains under practical regulatory requirements. Our systematic analysis further demonstrates the suitability of TPCH for small scale deployment. Ke Huang 0002, Xiong Li 0002, Fatemeh Rezaeibagha, Linghao Zhang, Xiaosong Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Vupsi: Verifiable Unbalanced Private Set Intersection Based on Homomorphic EncryptionabstractABSTRACT Unbalanced private set intersection (UPSI), a cryptographic technique for securely computing set intersections in asymmetrical setups while preserving privacy, has been extensively studied. However, existing protocols often require clients with small sets to participate in computations, are highly interactive, and lack result verifiability. In this paper, we propose VuPSI, a verifiable unbalanced PSI scheme designed to overcome the limitations of existing protocols. VuPSI offloads the computational burden to the server, reducing client‐side processing and simplifying the overall workflow. In addition, VuPSI incorporates an efficient zero‐knowledge verification mechanism that allows clients to efficiently verify the correctness of intersection results with minimal computational overhead. This approach significantly improves the reliability of PSI outcomes. Our design implements a low‐interaction protocol that ensures scalability and efficiency, especially for large‐scale dynamic datasets. Experimental evaluations show that VuPSI is both efficient and practical. Specifically, VuPSI can process 1,024 client‐side items and 1,000,000 server‐side items within seconds using 32 threads, achieving 40× the communication efficiency of comparable protocols such as DiPSI. Its lower computational overhead and faster data preprocessing make it well‐suited for real‐time, dynamic server environments. Ruirui Gao, Shuai Shang, Ke Huang 0002, Xiong Li 0002 |
Concurr. Comput. Pract. Exp. | 5 |
| 2025 | Authenticable Distributed Homomorphic Private Counter and its application in data analysis of edge computingabstractThe rapid proliferation of advanced technologies, including the Internet of Things (IoT), cloud computing , and edge computing , has led to an exponential growth in structured and unstructured data, generated and collected across diverse applications. It is important to develop secure techniques that can efficiently process large volumes of data while preserving privacy. Privacy-preserving data analytics on encrypted data have gained popularity for performing essential calculations within cloud storage servers . However, applying these techniques to fully homomorphic encryption introduces inefficiencies and computational overheads. While homomorphic encryption allows for delegated execution of arithmetic operations directly on ciphertexts via cloud services, ensuring both efficiency and correctness in data computations remains a challenging endeavor. Most existing studies overlook simultaneous data aggregation while maintaining integrity and privacy for analytical purposes. In response, we propose an Authenticable Distributed Homomorphic Private Counter Scheme (ADHPC) for privacy-preserving data analysis in cloud computing. Our scheme securely and efficiently aggregates encrypted data within distributed edge computing environments, subsequently allowing authorized parties to decrypt and validate it. To authenticate the encrypted data, we employ an authenticable additive homomorphic encryption scheme based on online and offline setup stages. We demonstrate the applicability and efficiency of our proposed approach through implementation results and a comprehensive security analysis. Fatemeh Rezaeibagha, Leyou Zhang, Ke Huang 0002, Lanxiang Chen |
J. Inf. Secur. Appl. | 3 |
| 2024 | Towards Efficient Delegated Private Set Intersection Cardinality ProtocolabstractPrivate set intersection cardinality (PSI-CA) can compute the intersection cardinality of sets held by two participants in a privacy-preserving manner, and it has a wide range of applications in life. Since the existing PSI-CA protocol is often difficult to apply in real life due to its high communication overhead and computational cost, we designed an efficient PSI-CA protocol based on technologies such as PRF and OKVS. The security analysis shows that our PSI-CA protocol is secure under the semi-honest security model and does not leak the private information of the participants. Extensive experiments and performance evaluation analysis show that our protocol is much more efficient than other related protocols in terms of communication and computation. Specifically, for the intersection cardinality computation of two sets both of size 220, the running time (62.2s) of our PSI-CA protocol is only 3.3% (1854s) and 10.3% (601s) of other PSI-CA protocols, and the communication overhead of our PSI-CA protocol is 48.5% and 48.7% of related protocols. Xiong Li 0002, Shuai Shang, Ke Huang 0002, Xiaosong Zhang 0001 |
CSCWD | 5 |
| 2024 | Versatile Remote Data Checking Scheme for Cloud-Assisted Internet of ThingsabstractInternet of Things (IoT) revolutionizes data collection, especially in e-healthcare, where patients data from wearables and sensors improves medical services. However, IoT’s limitations in computing and storage require cloud outsourcing. Combining IoT with the cloud has potential but raises concerns about data security. Leveraging cloud storage presents an attractive solution for accommodating the substantial volume of data outsourced by IoT devices. As the outsourcing of real-time data to cloud storage becomes commonplace, the adoption of data auditing schemes emerges as a means to ensure data integrity. To curtail operational expenses, various deduplication techniques are commonly employed on outsourced data, effectively sidestepping redundant data and resulting in storage and bandwidth efficiencies. Although real-time data typically remains distinct due to its diverse origins, scenarios, such as data sharing or trading in data-driven services and datamarkets, can lead to data redundancy. Moreover, in order to fortify against any potential information leakage, encryption is implemented prior to deduplication. Convergent encryption (CE) stands as a prominent exemplar of this approach. Effectively integrating data auditing, deduplication, and encryption for wireless sensor devices is no trivial task. To efficiently and securely accommodate data while authenticating them through a heterogeneous framework, we present a novel remote data checking scheme, denoted as the VRDC scheme. This scheme empowers IoT data to be encrypted, updated, deduplicated, and audited, aligning with the imperatives of security, privacy, and efficiency. Through comprehensive security analysis, we establish that our VRDC scheme is fortified against potential threats. Our experimental findings highlight the efficiency of our approach in the realms of auditing, deduplication, and updates. Furthermore, the evidence highlights the potential for optimization within our scheme when compared to related works. This is achieved through the careful management of dynamic update scales within a file. Ying Xie 0008, Ke Huang 0002, Sheng Yuan, Xiong Li 0002, Fagen Li |
IEEE Internet Things J. | 2 |
| 2024 | Monero With Multi-Grained RedactionabstractMonero is a privacy-centric cryptocurrency that allows users to obscure their transactions with multiple input and output addresses. Current research on Monero mainly focuses on identifying design vulnerabilities or optimizing towards stronger privacy, security, etc. For example, improving the design of ring confidential transaction (RingCT) protocol proposed by Noether et al. As revealed by Ali et al. in USENIX 2016, new blockchains have inadequate nodes and network computing resources to resist powerful attack (e.g., 51% attack). Obviously, Monero blockchain is not an exception. Ateniese et al. proposed the notion of redactable blockchain in EuroS$ \& amp;$P 2017, which begins the trend of formalizing blockchain with extra cryptographic primitives. The motivation is to turn an immutable blockchain into a mutable ledger by adapting the blockchain design and integrating with new cryptographic schemes. In such a setting, users could use their private keys to perform the secure multi-party computation to reverse blockchain history. The idea of redactable blockchain has attracted many researchers to pursuit this topic. However, few works have considered the privacy-preserving setting. Even fewer have practised their designs in an actual cryptocurrency. In this paper, we seek to adapt the RingCT protocol with several building blocks. Our proposal achieves most of the desired properties for blockchain redaction. It allows multiple tracing authorities to collaboratively trace users’ identities, and a system manager to perform multi-grained (including block-level, transaction-level, accumulator-level and commitment-level) redaction on block contents. Our proposal can be seen as an extension of RingCT protocol. We give rigorous security requirements and comprehensive analysis of our scheme. The performance evaluation suggested that our scheme suffers from some unscalabilities in large-scale implementations. A more elegant design to achieve stronger security and ideal scalability is deemed as a challenging and interesting future work. Ke Huang 0002, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaosong Zhang 0001, Xiong Li 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Toward Secure Data Computation and Outsource for Multi-User Cloud-Based IoTabstractCloud computing has promoted the success of Internet of Things (IoT) with offering abundant storage and computation resources where the data from IoT sensors can be remotely outsourced to the cloud servers, whereas storing, exchanging and processing data collected through IoT sensors via centralised or decentralised cloud servers make cloud-based IoT systems prone to internal or external attacks. To protect IoT data against potential malicious users and adversaries, some cryptographic schemes have been applied to ensure confidentiality and integrity of IoT data. It is however a challenging task to perform any arithmetical computations once data items are encrypted. Fully-homomorphic encryption which is based on lattices can, in principle, provide a solution, but it is unfortunately inefficient in computation and hence cannot be applied to IoT. Fully-homomorphic encryption is feasible when we allow the involvement of a semi-trusted server. However, it is challenging to provide such a system in the situation of distributed environments for shared IoT data. We solve this problem and provide a fully-homomorphic encryption scheme for cloud-based IoT applications. We introduce a new method with the aid of a semi-trusted server that can help compute the homomorphic multiplications without gaining any useful information of the encrypted data. We show how our scheme is applied to multi-user IoT security and prove its semantic security. We also conduct experiments to justify its efficiency and applicability to multi-user cloud-based IoT systems. Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen, Leyou Zhang |
IEEE Trans. Cloud Comput. | 3 |
| 2023 | Authenticable Additive Homomorphic Scheme and its Application for MEC-Based IoTabstractThe integration of Internet of Things (IoT) and cloud computing are always seen as promising technologies to enhance streamlined data collection, share and exchange. Although the advances in edge computing, particularly mobile edge computing (MEC), could enhance the performance of data collection and computation via computing offloading, security and privacy impediments have made new challenges to data integrity and confidentiality, in particular when multiple edges or nodes at different locations collect IoT data. Homomorphic encryption therefore has shown promising advantages for cloud computing, offering arithmetic operations to be carried out on the encrypted data without revealing the secret key. While fully homomorphic encryption introduced by Gentry, in 2009, allows both additive and multiplicative operations, it has shown significant implementation drawbacks due to the parameters generation and memory consumption. In this work, we focus on partially homomorphic encryption, which can be efficiently computed. However, it is challenging to add authentication feature for the verification and aggregation capability. We propose a novel secure and privacy preserving authenticable homomorphic encryption (AHEC) scheme. We demonstrate an application of our AHEC scheme for MEC-based IoT systems and provide security analysis to prove that our scheme is secure against chosen plaintext attack (IND-CPA) and unforgeability (UNF) under DDH-ZN2 and Lift-DH-ZN2 assumptions. Experimental results show that our proposed scheme is efficient for practical applications. Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen, Leyou Zhang |
IEEE Trans. Serv. Comput. | 3 |
| 2022 | Defending Data Poisoning Attack via Trusted Platform Module and Blockchain OracleabstractWith the development of Internet of Things (IoT) technology, the digital pill has been employed as an IoT system for emerging remote health monitoring to detect the impact of medicine intake on patients’ biological index. The medical data is then used for model training with federated learning. An adversary can launch poisoning attacks by tampering with patients’ medical data, which will lead to misdiagnosis of the patients’ conditions. Lots of studies have been conducted to defend against poisoning attacks based on blockchain or hardware. However, 1) Blockchain-based schemes can only exploit on-chain data to deal with poisoning attacks due to the lack of off-chain trusted entities. 2) Typical hardware-based schemes have the bottleneck of single point of failure. To overcome these defects, we propose a defense scheme via multiple Trusted Platform Modules (TPMs) and blockchain oracle. Benefitting from multiple TPMs verification results, a distributed blockchain oracle is proposed to obtain off-chain verification results for smart contracts. Then, the smart contracts could utilize the off-chain verification result to identify poisoning attacks and store the unique identifiers of the non-threatening IoT device immutably on the blockchain as a whitelist of federated learning participants. Finally, we analyze the security features and evaluate the performance of our scheme, which shows the robustness and efficiency of the proposed work. Mingyuan Huang, Xiong Li 0002, Ke Huang 0002, Xiaosong Zhang 0001 |
ICC | 4 |
| 2022 | Blockchain-based deduplication with arbitration and incentivesabstractAbstract Cloud storage is an ideal platform to accommodate massive data. However, with the increasing number of various devices and improved processing power, the amount of generated data is becoming gigantic. Therefore, this calls for a cost‐effective way to outsource massively generated data to a remote server. Cloud service providers utilise deduplication technique which deduplicates redundant data by aborting identical uploading requests and deleting redundant files. However, current deduplication mechanisms mainly focus on the storage saving of the server, and ignore the sustainable and long‐term financial interests of servers and users. This is not helpful to expand outsourcing and deduplication services. Blockchain is an ideal solution to achieve an economical and incentive‐driven deduplication system. Though some current research studiess have integrated deduplication with blockchain, they did not utilise blockchain as a financial tool. Meanwhile, it lacks an arbitration mechanism to settle disputes between the server and the user, especially in a Bitcoin payment where the payment is not confirmed immediately and a dispute may occur. This creates a burden to achieve fair and transparent incentive‐based deduplication service. In this work, we construct a deduplication system with financial incentives for the server and the user based on Bitcoin. The data owner will pay money via Bitcoin to the server for outsourcing the file, but this fee can be compensated by charging deduplication users with some fees to acquire the deduplication service. The server and the user can receive revenues using deduplication service. Disputes on the fair distribution of incentives can be settled by our arbitration protocol with chameleon hashes as arbitration tags. We give concrete construction and security requirements for our proposed . The security analysis shows that our is theoretically secure. The performance evaluation shows that our proposed is acceptably efficient for the deduplication. Meanwhile, we evaluate and conclude that 1% of outsourcing fee (or less) is a reasonable and preferable price for each deduplication user to pay as compensation for data owner. Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Yongcheng Gong |
IET Inf. Secur. | 1 |
| 2022 | Bidirectional and Malleable Proof-of-Ownership for Large File in Cloud StorageabstractCloud storage is a cost-effective platform to accommodate massive data at low cost. However, advances of cloud services propel data generation, which pushes storage servers to its limit. Deduplication is a popular technique enjoyed by most current cloud servers, which detects and deletes redundant data to save storage and bandwidth. For security concerns, proof-of-ownership (PoW) can be used to guarantee ownership of data such that no malicious user could pass deduplication easily or utilize such mechanism for malicious purposes. Generally, PoW is implemented in static data archive where the data file is supposed to be read-only. However, to satisfy users’ needs for dynamical manipulation on data and support real-time data services, it is required to devise efficient PoW for dynamic archive. Inspired by malleable signature, which offers authentication even after its committed message changes, we propose the notion of bidirectional and malleable proof-of-ownership ($\sf {BM\mbox{-}PoW}$) for the above challenge. Our proposed$\sf {BM\mbox{-}PoW}$consists of bidirectional PoW (${\mbox{B-PoW}}$), malleable PoW (${\mbox{M-PoW}}$) and dispute arbitration protocol$\sf {DAP}$. While our${\mbox{B-PoW}}$is proposed for a static setting, the${\mbox{M-PoW}}$caters specifically for dynamic manipulation of data. In addition, our proposed arbitration protocol$\sf {DAP}$achieves accountable redaction which can arbitrate the originality of file ownership. We provide the security analysis of our proposal, and performance evaluation that suggests our proposed${\mbox{B-PoW}}$is secure and efficient for large file in static data archive. In addition, our proposed${\mbox{M-PoW}}$achieves acceptable performance under dynamic setting where data is supposed to be outsourced first and updated later in dynamic data archive. Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaojiang Du |
IEEE Trans. Cloud Comput. | 1 |
| 2022 | Blockchain-Enabled Federated Learning Data Protection Aggregation Scheme With Differential Privacy and Homomorphic Encryption in IIoTabstractWith rapid growth in data volume generated from different industrial devices in IoT, the protection for sensitive and private data in data sharing has become crucial. At present, federated learning for data security has arisen, and it can solve the security concerns on data sharing by model sharing on Internet of mutual distrust. However, the hackers still launch attack aiming at the security vulnerabilities (e.g., model extraction attack and model reverse attack) in federated learning. In this article, to address the above problems, we first design an application model of blockchain-enabled federated learning in Industrial Internet of Things (IIoT), and formulate our data protection aggregation scheme based on the above model. Then, we give the distributed K-means clustering based on differential privacy and homomorphic encryption, and the distributed random forest with differential privacy and the distributed AdaBoost with homomorphic encryption methods, which enable multiple data protection in data sharing and model sharing. Finally, we integrate the methods with blockchain and federated learning, and provide the complete security analysis. Extensive experimental results show that our aggregation scheme and working mechanism have the better performance in the selected indicators. Xiaosong Zhang 0001, Jiewen Liu, Yang Zhang 0091, Ke Huang 0002, Yongquan Liang 0001 |
IEEE Trans. Ind. Informatics | 5 |
| 2021 | Enhanced bitcoin with two-factor authenticationabstractBitcoin transactions rely on digital signatures to prove the ownership of bitcoin. The private signing key of the bitcoin owner is the key component to enable a bitcoin transaction. If the signing key of a bitcoin is stolen, the theft who possesses the key can make a transaction of the bitcoin. In this paper, based on the distance-based encryption (DBE), we propose an enhanced version of bitcoin in order to protect the signing key. Our approach is based on our two-factor authentication, where the signing key cannot be retrieved without being identified via the password and biometric authentication scheme, and the user is only required to enter his password and fingerprint (or other biometric information such as a factual image) to retrieve the key. By doing this, we can effectively improve the bitcoin security and provide stronger authentication. An attractive feature of our scheme is that one of encryption schemes is asymmetric, in the sense that the decryption key (biometric information) is not stored in the device. We also provide the security model and proof to justify the security of our scheme. Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Leyou Zhang |
Int. J. Inf. Comput. Secur. | 3 |
| 2021 | Secure and Efficient Data Aggregation for IoT Monitoring SystemsabstractThe proliferation of Internet of Things (IoT) as a promising paradigm has contributed enormously to modern technology design. The wireless body sensor network (WBSN) technology is an application of IoT in healthcare, whereas data security and privacy impediments have raised some concerns. The collected data via IoT wireless body sensors is vulnerable to a variety of internal and external attacks. One solution is to encrypt or sign the collected data to provide confidentiality and integrity, but the computational complexity hinders the application in the real IoT-based healthcare devices. Although there have been some attempts to provide secure and efficient IoT schemes, there is a lack of achieving secure data analysis in modern healthcare. The aggregated data statistics about the patient's medical status is useful to doctors and healthcare providers. However, the dynamic data continually updating over time is challenging. In this article, we present an efficient and provably secure scheme, which is the first step toward secure data analysis for handling the data collection and analysis for IoT wireless body sensors. The main contribution of our work is a novel cryptographic accumulator based on our novel authenticated additive homomorphic encryption which can collect and accumulate data from IoT wireless wearable devices. These encrypted data can be used for analysis in an encrypted form so that the information is not revealed. To validate security and efficiency, we present security analysis and performance evaluations of our proposed scheme for IoT wireless body sensors. Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen |
IEEE Internet Things J. | 3 |
| 2021 | Secure and Privacy-Preserved Data Collection for IoT Wireless SensorsabstractThe captured data from smart devices via Internet of Things (IoT) wireless sensors are vulnerable to numerous online and offline attacks and unauthorized accesses, hence, some digital signature and encryption solutions have been designed to ensure public verifiability, data integrity, and confidentiality. However, there are still some issues to be addressed. For example, the data source is revealed to the public due to the public verifiability of digital signatures, in which authentication is transferrable. Moreover, computation of these data can only be done after decryption, restricting outsourced computation, such as a computing facility from a cloud. The best approach of private computation, which supports outsourced computation, is based on homomorphic encryption. However, significant computational overhead is a concern. To deal with these issues, in this article, we propose an efficient and provably secure scheme based on designated-verifier proofs, deniable authentication and homomorphic encryption for secure and lightweight data collection, batch verification, and data analysis in the privacy-preserved IoT wireless sensors applications. The main contribution of our work is the privacy-preserved IoT wireless sensors system along with a novel deniable authenticated homomorphic encryption scheme that can securely aggregate data from IoT wireless sensors for secure outsourced applications. To prove the security and efficiency of our proposed scheme, we provide formal security analysis and performance comparisons for IoT wireless sensors. Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Leyou Zhang, Xinyi Huang 0001 |
IEEE Internet Things J. | 3 |
| 2021 | Scalable and redactable blockchain with update and anonymity
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaojiang Du |
Inf. Sci. | 1 |
| 2020 | EVA: Efficient Versatile Auditing Scheme for IoT-Based Datamarket in JointcloudabstractCloud storage offers convenient outsourcing services to users, and it serves as a basic platform to drive Internet-of-Things (IoT) where massive devices are connected to the cloud storage and interact with each other. However, cloud storage is more than a data warehouse. In the literature, data market was proposed as a novel model to empower IoT, where data are circulated as merchandise in the digital marketplace with financial activities. When storing IoT data in cloud storage, security and efficiency rules should be applied. Meanwhile, data dynamics is counted as a critical factor to the feasibility of datamarket as data are supposed to be manipulated through circulation and exploitation for IoT. Another issue is the single-point-of-failure (SPoF) of cloud server in which the initiative of jointcloud was suggested. Since providing data security, efficiency, and dynamics simultaneously is challenging, in this article, we propose a versatile auditing scheme (EVA) as a solution to problems. Our proposal ensures that data are securely, efficiently, and dynamically stored in the jointcloud meanwhile supported by data trades via blockchain. We give a comprehensive security analysis based on our security definitions and experiments to support our claims. The evidence has shown that our EVA is efficient for processing large files when proper parameters are chosen. Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Jingwei Li 0001, Qi Xia 0001, Jing Qin 0002 |
IEEE Internet Things J. | 1 |
| 2020 | HUCDO: A Hybrid User-centric Data Outsourcing SchemeabstractOutsourcing helps relocate data from the cyber-physical system (CPS) for efficient storage at low cost. Current server-based outsourcing mainly focuses on the benefits of servers. This cannot attract users well, as their security, efficiency, and economy are not guaranteed. To solve with this issue, a hybrid outsourcing model that exploits both cloud server and edge devices to store data is needed. Meanwhile, the requirements of security and efficiency are different under specific scenarios. There is a lack of a comprehensive solution that considers all of the above issues. In this work, we overcome the above issues by proposing the first hybrid user-centric data outsourcing (HUCDO) scheme. It allows users to outsource data securely, efficiently, and economically via different CPSs. Brielly, our contributions consist of theories, implementations, and evaluations. Our theories include the first homomorphic collision-resistant chameleon hash (HCCH) and homomorphic designated-receiver signcryption (HDRS). As implementations, we instantiate how to use our proposals to outsource small- or large-scale data through distinct CPS, respectively. Additionally, a blockchain with proof-of-discrete-logarithm (B-PoDL) is instantiated to help improve our performance. Last, as demonstrated by our evaluations, our proposals are secure, efficient, and economic for users to implement while outsourcing their data via CPSs. Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Guangquan Xu, Hao Wang 0003, James Xi Zheng, Guomin Yang, Qi Xia 0001, Xiaojiang Du |
ACM Trans. Cyber Phys. Syst. | 1 |
| 2020 | Achieving Intelligent Trust-Layer for Internet-of-Things via Self-Redactable BlockchainabstractThe advances of artificial intelligence (AI) propels big data processing and transmission for Internet of Things (IoT), by capturing and structuring big data produced by heterogeneous devices. While applying blockchain to manage IoT devices and associated big data, the blockchain itself suffers from abuse of decentralization from anonymous users. Specifically, it has been utilized to facilitate black market trades and illegal activities. Ateniese et al. proposed using the chameleon hash (CH) to derive redactable blockchain (EuroS&P), which works by embedding a trapdoor in the basic hash function so that block content can be rewritten without causing major hard forks. In short, the redacted block hash remains unchanged. However, there is lacking intelligent design where any mistakes observed in the chain can be corrected universally and automatically. This creates disincentives to use redactable blockchain (RB) for managing big data or any data-driven business mainly due to ineffective chain redaction. To solve this problem, in this article, we propose the notion of the self-redactable blockchain (SRB) to support intelligent execution of chain redaction. Specifically, we propose the first revocable chameleon hash (RCH) to power RB. It enables an ephemeral trapdoor for finding collision without any co-operation. Periodical expiration is applied to committed hash and an ephemeral trapdoor to prevent any abuses of redaction power. We instantiate how to use our RCH to build SRB as an intelligent trust-layer for IoT. We also give a rigorous analysis as well as comprehensive experiments to validate our proposals. The evidence showed that our proposal is secure and acceptably efficient for IoT devices. Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaojiang Du, Nadra Guizani |
IEEE Trans. Ind. Informatics | 1 |
| 2020 | Policy-Driven Blockchain and Its Applications for Transport SystemsabstractBlockchains offer opportunities for developing advanced digital services. While current research on this topic is still growing, various security concerns have been raised and the security of blockchains has been becoming the most important issue which must be well addressed. Blockchain transactions are based on digital signatures, where the public key is associated with the ownership of the digital coin. User management of public or permissionless blockchain is ad hoc, i.e., any user can join and leave the blockchain network and participate in the Proof of Work (PoW). However, in a private blockchain and a permissioned blockchain, there are usually some constraints for users. In this paper, we investigate a scenario which provides a blockchain network with a set of policies where every user's signing key is associated with a policy set. It is particularly interesting while users are working in different sectors. We call our scheme as “policy-driven”, since policies in our scheme restrict users' rights. Our system is featured with a novel and lightweight policy-driven signature (PDS) scheme whose security has been proven formally. To justify our scenario, we provide experimental results and an example for the railway management services. Yi Mu 0001, Fatemeh Rezaeibagha, Ke Huang 0002 |
IEEE Trans. Serv. Comput. | 3 |
| 2019 | Building Redactable Consortium Blockchain for Industrial Internet-of-ThingsabstractApplying consortium blockchain as a trust layer for heterogeneous industrial Internet-of-Things devices is cost-effective. However, with an increase in computing power, some powerful attacks (e.g., the 51% attack) are inevitable and will cause severe consequences. Recent studies also confirm that anonymity and immutability of blockchain have been abused to facilitate black market trades, etc. To operate controllable blockchain for IIoT devices, it is necessary to rewrite blockchain history back to a normal state once the chain is breached. Ateniese et al. proposed redactable blockchain by using chameleon hash (CH) to replace traditional hash function, it allows blockchain history to be written when needed (EuroS&P 2017). However, we cannot apply this idea directly to IIoT without solving the following problems: (1) achieve a decentralized design of CH; (2) update the signatures accordingly to authenticate the redacted contents; (3) satisfy the low-computing need of the individual IIoT device. In this paper, we overcome the above issues by proposing the first threshold chameleon hash (TCH) and accountable-and-sanitizable chameleon signature (ASCS) schemes. Based on them, we build a redactable consortium blockchain which is efficient for IIoT devices to operate. It allows a group of authorized sensors to write and rewrite blockchain without causing any hard forks. Basically, TCH is the first TCH and ASCS is a public-key signature supporting file-level and block-level modifications of signatures without impairing authentications. Additionally, ASCS achieves accountability to avoid abuse of redaction. While security analysis validates our proposals, the simulation results show that redaction is acceptably efficient if it is executed at a small scale or if we adopt a coarse-grained redaction while sacrificing some securities. Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Guomin Yang, Xiaojiang Du, Fatemeh Rezaeibagha, Qi Xia 0001, Mohsen Guizani |
IEEE Trans. Ind. Informatics | 1 |
| 2014 | Identity Privacy-Preserving Public Auditing with Dynamic Group for Secure Mobile Cloud Storage
Yong Yu 0002, Yi Mu 0001, Jianbing Ni, Jiang Deng, Ke Huang 0002 |
NSS | 5 |