VLDB 2026 Research / reviewers in the wild / expert
Hu Xiong
dblp:41/1980
· DBLP profile ↗
83ranked-venue papers
34as first author
48since 2021 · last 2026
0000-0001-6137-6667ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 22 · 9 first-author · 16 since 2021Security and privacy · 19 · 9 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 14 · 8 first-author · 10 since 2021Databases, data management, data science and information retrieval · 11 · 4 first-author · 2 since 2021Systems, architecture and hardware · 8 · 1 first-author · 6 since 2021Theory of computation · 5 · 3 first-authorArtificial intelligence and machine learning · 3 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Blockchain-Based Heterogeneous Signcryption With Proxy Re-Encryption and CRF for Secure WBANs
Negalign Wake Hundera, Rashad Elhabob, Adhikari Deepak, Hu Xiong |
IEEE Internet Things J. | 5 |
| 2026 | Blockchain-enabled heterogeneous communication protocol with identifiable abort in federated learning for artificial intelligence of things
Hu Xiong, Qiyong Xian, Kuo-Hui Yeh |
J. Inf. Secur. Appl. | 1 |
| 2026 | Leakage-Resilient Multi-Party Signatures for Industrial IoT via Cryptographic Reverse FirewallsabstractThe rapid growth of Industrial Internet of Things (IIoT) systems has heightened the need for secure cryptographic operations, particularly multi-party digital signatures for decentralized trust. However, existing multi-party signature schemes are vulnerable to insider attacks, and no current solutions address insider-induced data exfiltration effectively. Cryptographic Reverse Firewalls (CRFs) provide a promising solution but face challenges in integration with digital signatures, especially with hash-dependent components. We propose MCRF, a CRF-enhanced multi-party signature scheme designed for IIoT environments. MCRF uses a commitment-based mechanism to optimize the signing process, enabling output-side CRF to re-randomize signatures without compromising correctness. The two-stage CRF architecture-input-side CRF for sanitizing messages and output-side CRF for re-randomizing signatures-ensures efficient protection against both input-triggered and output-stealth exfiltration attacks. MCRF offers strong leakage resistance with minimal computational and communication overhead, making it a scalable solution for secure multi-party signing in IIoT systems. Zengxiang Wang, Yunfan Hu, Zhen Qin 0002, Hu Xiong |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Efficient and Unbounded Public-Key Encryption With Keyword Search Based on Arithmetic Span Programs in Cloud StorageabstractPublic-key Encryption with Keyword Search (PEKS) enables users to search encrypted data stored on an untrusted server without revealing any sensitive information. However, existing PEKS schemes are typically inefficient and lack the flexibility to support complex search policies. To address this, a novel PEKS scheme based on Arithmetic Span Programs (PEKS-ASP) is proposed in this paper. This is the first scheme to enable flexible and efficient search policies by using directed acyclic graphs. This approach enhances the efficiency of complex search queries that implement AND, OR, and NOT gates, enabling a more efficient representation of complicated search policies without redundancy in keyword usage. And our proposed PEKS-ASP scheme guarantees constant-size public parameters regardless of the number of keywords. Additionally, the proposed scheme achieves adaptive security under the matrix decisional Diffie-Hellman (MDDH) assumption, employing dual system encryption techniques. Both theoretical analysis and experimental results demonstrate that PEKS-ASP significantly improves efficiency and practicality, making it well-suited for practical applications in various cloud environments. Hu Xiong, Jun Feng 0007, Kehan Gao, Keshav Sood |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Blockchain-Oriented Certificateless Threshold Signature With Identifiable Abort for Federated Learning in Digital Twin-Assisted IoVabstractAs a promising subdomain of intelligent transportation systems (ITS), Internet of Vehicles (IoV) can be empowered by digital twin (DT) technology for real-time traffic simulation and artificial intelligence (AI)-driven predictive analytics in evolutionary trend projection, demonstrating significant potential in dynamic transportation optimization. Among various machine learning paradigms, federated learning (FL) not only aligns well with IoV, but also provides it with privacy protection. Traditional FL faces single point of failure due to the existence of an aggregation center, so blockchain-based FL with multiple aggregators is utilized to mitigate this issue. Nevertheless, in such distributed environments, both aggregators and model parameters exposed to network are vulnerable to attacks, impeding the normal operation of FL. In this paper, for blockchain-enabled FL with multiple aggregators in IoV, we propose CLTSwNI&IA, the first non-interactive certificateless threshold signature with identifiable abort. This scheme eliminates certificate management and key escrow, adopts a blockchain-oriented approach by utilizing a fully distributed signing paradigm. Additionally, the proposed signing scheme is capable of identifying malicious FL aggregators during the entire process through distributed fine-grained verification and ensuring the integrity of aggregation results. Finally, theoretical and experimental comparisons with related literature demonstrate the advanced functionality and the acceptable efficiency of our approach. Yunfan Hu, Zengxiang Wang, Hu Xiong, Liming Fang 0001, Changgen Peng, Abubaker Wahaballa, Zhen Qin 0002, Zhiguang Qin |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2026 | Efficient and Privacy-Enhanced Asynchronous Federated Learning for Multimedia Data in Edge-Based IoTabstractWith the rapid development of smart device technology, the current version of the Internet of Things (IoT) is moving towards a multimedia IoT because of multimedia data. This innovative concept seamlessly integrates multimedia data with the IoT-Edge Continuum. Recently, a distributed learning framework has shown promise in revolutionizing various industries, including smart cities, healthcare, etc. However, these applications may face challenges, such as the presence of malicious devices that invade the privacy of other devices or corrupt uploaded model parameters. Additionally, the existing synchronous federated learning (FL) methods face challenges in effectively training models on local datasets due to the diversity of IoT devices. To tackle these concerns, we propose an efficient and privacy-enhanced asynchronous FL approach for multimedia data in edge-based IoT. In contrast to traditional FL methods, our approach combines revocable attribute-based encryption (RABE) and differential privacy (DP). This guarantees the privacy of the entire process while allowing seamless collaboration between multiple devices and the aggregation server during model training. Also, this combination brings a dynamic nature to the system. Furthermore, we utilize an asynchronous weight-based aggregation algorithm to improve the efficiency of training and the quality of the final returned model. Our proposed scheme is confirmed by theoretical safety proofs and experimental results with multimedia data. Performance evaluation shows that our framework reduces the cryptography runtime by 63.3% and the global model aggregation time by 61.9% compared to cutting-edge schemes. Moreover, our accuracy is comparable to the most primitive FL schemes, maintaining 86.7%, 70.8%, and 86.1% on MNIST, CIFAR-10, and Fashion-MNIST, respectively. The experimental results highlight the remarkable practicality, resilience and effectiveness of the proposed scheme. Hu Xiong, Hang Yan 0009, Mohammad S. Obaidat, Jingxue Chen, Mingsheng Cao 0001, Sachin Kumar 0002, Kadambri Agarwal, Saru Kumari |
ACM Trans. Multim. Comput. Commun. Appl. | 1 |
| 2025 | Efficient and provably secured puncturable attribute-based signature for Web 3.0abstractWeb 3.0 is a grand design with intricate data interchange, implying the requirement of versatile network protocol to ensure its security. Attribute-based signature (ABS) allows a user, who is featured with a set of attributes, to sign messages under a predicate. The validity of the ABS signature demonstrates that this signature is generated by the user whose attributes satisfy the corresponding predicate, and thus flexibly achieves anonymous authentication. Similar to other digital signatures, the security of ABS is broken in case the private key of the user is leaked out. To address the threat brought by the key leakage, this paper proposes a puncturable attribute-based signature scheme that allows the private key generator to revoke the signing right associated with specific tags. This paper firstly elaborates the construction of the proposed ABS scheme with puncturable property, and then proves its security theoretically by reducing the involved security to the computational Diffie–Hellman assumption. This paper then experimentally shows that the suggested puncturable ABS scheme owns a more efficient storage cost and superior performance. Yuetong Wu, Hu Xiong, Fazlullah Khan, Salman Ijaz 0002, Ryan Alturki, Abeer Aljohani |
Future Gener. Comput. Syst. | 2 |
| 2025 | Equality Test on Identity-Based Encryption With Cryptographic Reverse Firewalls for Telemedicine SystemsabstractThe emergence of the COVID-Omicron XBB variant has intensified the need for wireless body area networks (WBANs) in telemedicine, underscoring their critical role in remote patient monitoring and demanding robust security solutions to protect health data and patient privacy. To address this need, we introduce the equality test on identity-based encryption with cryptographic reverse firewalls (ET-IBE-CRFs). This protocol allows the medical server in a telemedicine system to execute the equality test on the encrypted data and retrieve the result without knowing any relevant information about the ciphertext. By incorporating cryptographic reverse firewalls (CRFs), the ET-IBE-CRF protocol effectively counters offline message recovery attacks (OMRAs) and algorithm substitution attacks (ASAs) without requiring secure communication channels. Our evaluation indicates that ET-IBE-CRF not only meets the strict requirements for confidentiality and privacy in telemedicine applications but also maintains high efficiency. This makes it well-suited for high-performance telemedicine systems. Rashad Elhabob, Nabeil Eltayieb, Hu Xiong, Saru Kumari |
IEEE Internet Things J. | 3 |
| 2025 | PassGAT: A Graph Attention Network Framework for Device Authentication in AIoT-Enabled Supply Chain Risk MitigationabstractIn AIoT-enabled secure and green supply chain systems, robust device authentication measures are crucial to maintaining the integrity of the ecosystem. One key challenge in this context is mitigating password guessing attacks—a scenario that can be modeled as a specialized sequence prediction task demanding high character-level accuracy and computational efficiency to safeguard devices and data. Although natural language processing (NLP) models, particularly GPT-based approaches, have excelled in sequence prediction tasks, they often lack the precision needed for password guessing due to their reliance on broad contextual dependencies. To address these limitations, we propose PassGAT, a novel framework that leverages Graph Attention Networks (GAT) to enhance password prediction performance. PassGAT transforms passwords into graph representations, where each character is treated as a node, enabling selective computation of attention coefficients between characters. This approach captures both local dependencies essential for character-level accuracy and global patterns that enhance the understanding of password structures. Experimental results demonstrate that PassGAT achieves an average improvement of 15.58% in accuracy over an existing GPT-based password guessing model while reducing computational overhead by 85.19%. By significantly enhancing authentication accuracy and efficiency, PassGAT provides a robust and sustainable solution to mitigate password-related security risks in AIoT-enabled supply chain systems. Yurun Miao, Erqiang Zhou, Wulong Fan, Bander A. Alzahrani, Hu Xiong |
IEEE Internet Things J. | 6 |
| 2025 | Efficient and Decentralized Dual Access Control for Cloud-Based Industrial Internet of ThingsabstractAs an essential application of the Internet of Things (IoT), the Industrial IoT (IIoT) makes it possible to monitor and manage factories more efficiently. With the development of IIoT, cloud storage services are being implemented to exchange large amounts of data. However, determining how to control access to malicious cloud servers is a critical problem. Thus, the ciphertext policy attribute-based encryption (CP-ABE) is proposed to solve this problem. Unfortunately, the corruption of authorities, the Distributed Denial-of-Service (DDoS) attacks, and the Economic Denial of Sustainability (EDoS) attacks bring about an extreme challenge to using the CP-ABE scheme on the cloud-based IIoT system. Due to these problems, in this article, we proposed a new decentralized dual access control system for the cloud-based IIoT by introducing a new decentralized CP-ABE (DABE) scheme. In our scheme, there are multiple authorities, the scheme is secure even though some of the authorities are corrupt. At the same time, our scheme can resist DDoS/EDoS attacks with dual access control technology. Finally, we give security and efficiency analysis in this article. The results show that our scheme can achieve adaptive security and is more efficient than the proposed schemes. Hu Xiong |
IEEE Internet Things J. | 2 |
| 2025 | Open-world multi-modal machine learning decision model based on uncertain data analysis for fetal heart diagnosis
Guosong Zhu, Zhen Qin 0002, Hu Xiong, Saru Kumari, Mohammed J. F. Alenazi, Yingkun Guo, Chien-Ming Chen 0001 |
Inf. Sci. | 3 |
| 2025 | Heterogeneous Privacy-Preserving Blockchain-Enabled Federated Learning for Social FintechabstractSocial fintech integrates financial technology with social networking to enhance financial services’ accessibility and personalization by leveraging social interactions and user data. This approach raises privacy security concerns, particularly in application based on centralized artificial intelligence systems. To address these issues, blockchain-enabled federated learning (BEFL) offers a decentralized solution, improving robustness and privacy but facing challenges such as privacy attacks and heterogeneous crypto system. In response, a novel PKI and identity-based heterogeneous authenticated asymmetric group key agreement (PKI-IB-HAAGKA) protocol was proposed, which resolves crypto system heterogeneity issues. What's more, a PKI and identity-based heterogeneous batch multisignature (PKI-IB-HBMS) was proposed as a building block of PKI-IB-HAAGKA. This article presents the heterogeneous privacy-preserving blockchain-enabled federated learning (HPP-BEFL) system, designed to enhance privacy, security, and efficiency in social fintech applications. It effectively mitigates man-in-the-middle and inference attacks while improving overall system performance. Through security analysis and experiment results, it is demonstrated that the proposed PKI-IB-HAAGKA, PKI-IB-HBMS, and HPP-BEFL are provably secure and highly efficient, which can be applied to large-scale heterogeneous privacy-preserving model training scenarios. Hu Xiong, Yaxin Zhao, Abubaker Wahaballa, Kuo-Hui Yeh |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2025 | Heterogeneous Parallel Key-Insulated Multi-Receiver Signcryption Scheme for IoVabstractThe rapid growth of electric vehicle and autonomous vehicle populations has led to explosive expansion of IoV data being transmitted in the wireless communication infrastructure. Advances in IoV technologies also resulted in more complex and dynamic communication protocols/patterns, which are hard for the underlying wireless network to satisfy. Besides, security considerations of IoV communications require that key management must be stringently prohibit global failure mode of key management, meaning that, if a single IoV node compromises its private key, it will not lead to total security failure of the entire IoV network. To address these issues, in this paper, we propose a heterogeneous parallel key-insulated multi-receiver signcryption scheme for IoV (HPKI-MRSC). Firstly, the proposed scheme can realize one-to-many heterogeneous transmission, in which RSUs are deployed on certificateless cryptography (CLC) system, while vehicles are allocated in identity-based cryptography (IBC) system. In this manner, we observe that message transmission efficiency is improved greatly. Secondly, the parallel key-insulated mechanism can employ two helper keys to update private key periodically, and then solve key disclosure problem. Finally, when the number of receiver n is greater than or equal to 3, the proposed scheme has a lower signcryption overhead than other comparative schemes, and thus it is more suitable for IoV. Yingzhe Hou, Yue Cao 0002, Hu Xiong, Debiao He, Chihung Chi, Kwok-Yan Lam |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Improving Password Guessing With Isomorphism ModelingabstractPasswords remain one of the most widely used forms of authentication in modern systems. However, their inherent predictability, stemming from common user behaviors in password creation, renders password-based authentication vulnerable to guessing attacks. To balance memorability and security, users often construct isomorphic variants of a base password by altering its structure, such as transforming 123abc into 1a2b3c. These variants pose significant challenges to traditional password guessing models. In particular, mainstream approaches such as Markov model and Probabilistic Context-Free Grammar (PCFG) model struggle to capture the structural relationships among these variants. To address this challenge, we propose PassGIN, a password guessing framework based on Graph Isomorphism Networks (GIN). By modeling a password as a graph, PassGIN captures both local adjacency and character rearrangement patterns, enabling the model to distinguish subtle structural differences between base passwords and their isomorphic variants. To further enhance performance, we introduce PassCluster, a dynamic edge-weighting mechanism that leverages adjacency frequencies observed in large-scale password datasets. This allows GIN to more effectively learn structural variations and generate accurate guesses. Extensive experiments on eight real-world datasets demonstrate that PassGIN consistently outperforms state-of-the-art models in both intra-site and cross-site password guessing scenarios, achieving relative improvements of 23.49% and 74.53%, respectively. Zhenjia Xiao, Kaiwen Xing, Tao Yang 0015, Kaitai Liang, Hu Xiong |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2025 | Multi-Authority CP-ABE Scheme With Cryptographic Reverse Firewalls for Internet of VehiclesabstractInternet of vehicles, featured with widely distributed vehicle nodes and limited computing power, usually have high performance requirements. Because of this feature, efficient and reliable access control has raised a challenge in Internet of vehicles. Ciphertext-policy attribute-based encryption (CP-ABE) could be denoted as an efficient solution for this problem. However, directly applying traditional single-authority CP-ABE schemes may result in single-point performance bottleneck. Besides, the secrets of the whole system may be leaked if any node is attacked. To solve these challenging tasks, we proposed MA-CP-ABE-CRF, a multi-authority CP-ABE scheme with cryptographic reverse firewalls. The system is designed to grant vehicles fine-grained access control by encrypting data under vehicle attributes. Besides, load balancing of authorization in distributed systems is achieved based on the characteristic of multi-authority. Meanwhile, specific nodes are equipped with cryptographic reverse firewalls (CRFs) to prevent information leakage. As the first scheme with the above features for Internet of vehicles, the system achieves adaptive CPA-security and ASA-security. Through rigorous theoretical analysis and experimental comparison, MA-CP-ABE-CRF is proved to be highly efficient and practical. Hu Xiong, Hui Su, Kuo-Hui Yeh |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2025 | Decentralized Data Integrity Auditing in Vehicular Cloud ComputingabstractAs Vehicular Cloud Computing (VCC) evolves, ensuring data integrity and availability becomes a critical challenge due to the vast amount of data being shared and stored. These properties are vital for preserving confidence in cloud services, guaranteeing that data is kept intact and readily available when needed. Traditional data auditing mechanisms, such as Proofs of Retrievability (PoR) and Provable Data Possession (PDP), are effective but often rely on centralized models that pose risks like single-point failures and susceptibility to collusion. To mitigate these risks, we introduce a blockchain-assisted protocol that leverages the decentralized and tamper-proof characteristics of blockchain to enhance the security of data auditing in VCC. Our approach incorporates a dynamic key update mechanism to counter key exposure issues prevalent in VCC and introduces a multi-replica mechanism to ensure data redundancy and reliability across different storage nodes. This feature significantly reduces the risk of data loss and improves trust in cloud services by distributing data storage responsibilities and preventing single-point failures. We conduct formal security analysis and implement a prototype of our protocol on the Ethereum blockchain. Experimental evaluations on both Ganache and Sepolia testnets validate its feasibility in decentralized environments. The results demonstrate that our scheme supports stable challenge-response latency, moderate gas consumption, and reliable multi-replica consistency—making it well-suited for VCC deployments with dynamic conditions and limited resources. Tianang Yao, Hu Xiong, Kuo-Hui Yeh, Yong Xiang 0001, Changhai Nie |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2025 | DA-FL: Blockchain Empowered Secure and Private Federated Learning With Anonymous AuthenticationabstractFederated learning (FL) is a secure multiparty machine learning that addresses the issue of data silos by allowing nodes to train locally. Nonetheless, the lack of trusted environments, node supervision, and privacy protection measures in centralized FL limit its large-scale promotion. To address these issues, a blockchain-based decentralized FL framework is proposed, namely, decentralized federated learning with node anonymous authentication (DA-FL). Specifically, DA-FL introduces blockchain for local model storage and global model aggregation in the absence of centralized server, and uses differential privacy to reduce the risk of model privacy leakage. In addition, a consensus mechanism proof of accuracy is designed to effectively reduce the computational load of consensus and mitigate the impact of low-quality models on the aggregation results. To achieve node supervision, distributed key generation and revocable ring signature technologies are being integrated. This ensures the anonymous authentication of nodes while also allowing for the revocation of the anonymity of malicious nodes when necessary. Finally, the security and functionality of DA-FL are evaluated through simulation experiments conducted on real datasets. The numerical results show that the proposed FL scheme has significant performance advantages over other schemes. Hu Xiong, Yaxin Zhao, Kuo-Hui Yeh |
IEEE Trans. Reliab. | 1 |
| 2024 | UFL: Unlinkable Federated Learning Through Shuffle and Shamir's Secret Sharing
Jingxue Chen, Zhiwei Si, Jingcheng Song, Manoranjan Mohanty, Weiqi Wang 0003, Hu Xiong |
ADMA (2) | 6 |
| 2024 | Heterogeneous Signcryption Scheme With Group Equality Test for Satellite-Enabled IoVsabstractWith the growing popularization of the Internet of Vehicles (IoVs), the combination of satellite navigation system and IoVs is also in a state of continuous improvement. In this article, we present a heterogeneous signcryption scheme with group equality test for IoVs (HSC-GET), which avoids the adversaries existing in the insecure channels to intercept, alter or delete messages from satellite to vehicles. The satellite is arranged in an identity-based cryptographic (IBC) system to ensure safe and fast transmission of instruction, while the vehicles are arranged in certificateless cryptosystem (CLC) to concern the security of the equipment. In addition, the group granularity authorization is integrated to ensure the cloud server can only execute the equality test on ciphertext generated by the same group of vehicles. Through rigorous performance and security analyses, we observe that our proposed construction reduces the equality test overhead by about 63.96%, 81.23%, 80.84%, and 54.98% in comparison to other competitive protocols. Furthermore, the confidentiality, integrity and authenticity of messages are guaranteed. Yingzhe Hou, Yue Cao 0002, Hu Xiong, Yulin Hu, Max Eiza |
IEEE Internet Things J. | 3 |
| 2024 | Heterogeneous and plaintext checkable signcryption for integrating IoT in healthcare system
Abdalla Hadabi, Kuo-Hui Yeh, Chien-Ming Chen 0001, Saru Kumari, Hu Xiong |
J. Syst. Archit. | 6 |
| 2024 | Traceable Attribute-Based Encryption With Equality Test for Cloud Enabled E-Health SystemabstractThe emerging Internet of Things (IoTs) and cloud technologies spark dramatic growth in efficiency and productivity for the conventional e-health sector. However, the extensive applications of the communication network also expose the sensitive medical data to the unprecedented cyber threats. To protect the data privacy in IoTs-based e-health cloud environments, we propose an adaptively secure data sharing scheme with traceability and equality test (T-ABEET). The T-ABEET not only allows flexible access control to the massive data but also provides the functionality of traitor tracing to identity the users who leak their decryption keys. Meanwhile, through carrying out the equality test, the target ciphertext can be retrieved efficiently without revealing anything about the plaintext. Particularly, distinct from previous traceable ABE works, the tracing cost in our T-ABEET scheme keeps constant even with the increasing number of users. Also, by introducing the multi-authority mechanism, our T-ABEET can avoid the inherent key escrow problem of ABE. Furthermore, our T-ABEET is demonstrated adaptively secure under subgroup decision assumption. Finally, performance comparison reveals that our T-ABEET has superior practicality, efficiency, and security in cloud-enabled e-health systems. Saru Kumari, Mohammad S. Obaidat, Bander A. Alzahrani, Hu Xiong |
IEEE J. Biomed. Health Informatics | 5 |
| 2024 | A Conditional Privacy-Preserving Mutual Authentication Protocol With Fine-Grained Forward and Backward Security in IoVabstractWith the rise of intelligent transportation, various mobile value-added services can be provided by the service provider (SP) in the Internet of Vehicles (IoV). To guarantee the dependability of services, it is essential to implement a mutual authentication protocol between the vehicles and the SP. Existing mutual authentication protocols to secure the communication between the SP and the vehicle raise challenges such as providing fine-grained forward security for the SP and achieving backward security for the vehicle. To handle these challenges, this paper proposes a conditional privacy-preserving mutual authentication protocol featured with fine-grained forward security and backward security for IoV, which can be implemented via two building blocks we have constructed. Specifically, we present a new puncturable signature (PS) scheme without false-positive probability and the update of the public key as well as the first proxy re-signature scheme with parallel key-insulation (PKI-PRS). What’s more, both the proposed PKI-PRS and PS still have interest beyond this protocol. Then, an anonymous mutual authentication protocol with resistance to key leakage is constructed by incorporating the above signature schemes. The proposed protocol not only provides fine-grained forward security for the SP, but also ensures forward security as well as backward security for the vehicles. Besides, the approach to achieving anonymous authentication can efficiently provide conditional privacy-preserving for the vehicles. With the support of the random oracle model and experimental simulations, the formal security proof and the superiority of the proposed protocol is explicitly given. Hu Xiong, Ting Yao 0002, Yaxin Zhao, Lingxiao Gong, Kuo-Hui Yeh |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2023 | Scalable and Revocable Attribute-Based Data Sharing With Short Revocation List for IIoTabstractThe cooperative works between connected smart devices in the Industrial Internet of Things (IIoT) have greatly made the growth in productivity and economics for the conventional industry. However, due to the introduction of the communication network, the budding IIoT also confronts the unprecedented cyber threats. To prevent the data from being intercepted by malicious intruders, we propose an efficient and fully secure data sharing work with a short revocation list (DS-SRL) for IIoT. The DS-SRL not only enables flexible access control to the massive data in IIoT but also provides a direct revocation approach for handling the potential issues of key disclosure and membership expiring in application scenarios. Particularly, compared with existing directly revocable ABE works, the revocation list in the DS-SRL scheme will keep constant size even with the increasing number of users. Thus, the consumption for computing and disseminating the revoke-related part of ciphertext are low. This resource-saving merit makes our DS-SRL scheme suitable for IIoT where the smart devices are weak in the ability of both processing and storage. The DS-SRL works without boundary such that the public parameters involved in the system require no predefinitions and can be dynamically adjusted after deployment. Furthermore, the proposed DS-SRL work is demonstrated to be fully secure under the decisional linear assumption. Hence, it owns high flexibility, scalability, and security, which are essential and desirable in real-life applications. Finally, the superior feasibility, efficiency, as well as effectiveness of our DS-SRL work are fairly confirmed by the detailed performance evaluation. Jun Feng 0007, Hu Xiong, Yang Xiang 0001, Kuo-Hui Yeh |
IEEE Internet Things J. | 2 |
| 2023 | Revocable and Unbounded Attribute-Based Encryption Scheme With Adaptive Security for Integrating Digital Twins in Internet of ThingsabstractInternet of Things (IoTs) has been a burgeoning field that transforms the ubiquitous objects to interconnected devices and intelligent system. Today, with the emerging of innovative technologies such as cloud computing, the IoT sector is in a race to leverage these novel technologies to achieve optimal performance. Naturally the Digital Twins (DTs) architecture acts as an indispensable intermediary bridge to couple the IoT domain with these lastest technologies together. However, a tremendous obstacle is that the current Revocable Attribute-Based Encryption (RABE) schemes applied in the DTs paradigm fail to balance the efficiency, security and scalability simultaneously. In this paper, we tackle this challenge by presenting an unbounded and efficient direct RABE scheme with adaptive security. Compared with the previous schemes in this domain, our approach achieves revocable and fine-grained access control efficiently by employing the arithmetic span program (ASP) as the access structure. In this way, the expensive bilinear pairing and exponentiation operations are reduced significantly. Moreover, the unbounded property is satisfied in our scheme since the parameters are not required to be predefined in the setup phase. At last, with the support of the Matrix Decisional Diffie-Hellman (MDDH) assumption, the proposed scheme is proved to achieve adaptive security by adopting dual system encryption methodology. Theoretical comparison and implementation results demonstrate our proposed scheme possesses prominent practicability, scalability and efficiency. Hu Xiong, Kuo-Hui Yeh |
IEEE J. Sel. Areas Commun. | 1 |
| 2023 | MSDP: multi-scheme privacy-preserving deep learning via differential privacyabstractAbstract Human activity recognition (HAR) generates a massive amount of the dataset from the Internet of Things (IoT) devices, to enable multiple data providers to jointly produce predictive models for medical diagnosis. That the accuracy of the models is greatly improved when trained on a large number of datasets from these data providers on the untrusted cloud server is very significant and raises privacy concerns. With the migration of a deep neural network (DNN) in the learning experience in HAR, we present a privacy-preserving DNN model known as Multi-Scheme Differential Privacy (MSDP) depending on the fusion of Secure Multi-party Computation (SMC) and 𝜖-differential privacy, making it very practical since existing proposals are unable to make all the fully homomorphic encryption multi-key which is very impracticable. MSDP inputs a secure multi-party alternative to the ReLU function to reduce the communication and computational cost at a minimal level. With the aid of experimental verification on the four of the most widely used human activity recognition datasets, MSDP demonstrates superior performance with very good generalization performance and is proven to be secure as compared with existing ultramodern models without breach of privacy. Kwabena Owusu-Agyemang, Zhen Qin 0002, Hu Xiong, Yao Liu 0019, Tianming Zhuang, Zhiguang Qin |
Pers. Ubiquitous Comput. | 3 |
| 2023 | Efficient Revocable Storage Attribute-based Encryption With Arithmetic Span Programs in Cloud-Assisted Internet of ThingsabstractRevocable storage and efficient description of the access policy are necessary to enhance the practicality of the attribute-based encryption (ABE) in real-life scenarios, such as cloud-assisted Internet of Things (IoT). Nevertheless, existing ABE works fail to balance the two vital factors. In this paper, we construct an efficient revocable storage ciphertext-policy attribute-based encryption with arithmetic span programs (RS-CPABE-ASP). The arithmetic span program (ASP) is elegantly utilized as the access structure to reduce the unnecessary cost for defining access policy. Combining the indirect revocation and the ciphertext update mechanism, our work prevents the revoked user unable to access the newly generated data and the old data that can be accessed before. As shown in the outsourced version of RS-CPABE-ASP, the costly part for users to decrypt the data can be outsourced to powerful cloud servers. In this way, users in our RS-CPABE-ASP are able to access their data in a more efficient way by merely one exponential operation. Finally, we carry out detailed theoretical analysis and experimental simulations to evaluate the performance of our work. The results fairly show that our proposed work is efficient and feasible in cloud-assisted IoT. Hu Xiong |
IEEE Trans. Cloud Comput. | 2 |
| 2023 | Share Your Data Carefree: An Efficient, Scalable and Privacy-Preserving Data Sharing Service in Cloud ComputingabstractBenefiting from the powerful computing and storage capabilities of cloud services, data sharing in the cloud has been permeated across various applications including social networks, e-health and crowdsourcing transportation system. Intuitively, outsourcing data to untrusted cloud commonly raises concerns about data privacy breaches. To combat this, one approach is exploiting Broadcast Based Searchable Encryption (BBSE) for secure data sharing. Nevertheless, the latest proposed BBSE is still defective in either security or efficiency. In this article, we propose ESPD, an Efficient, Scalable and Privacy-preserving Data sharing framework over encrypted cloud dataset. Different from previous works, ESPD supports sharing target data to multiple users with distinct secret keys, and keeps a constant ciphertext length with the changes of the amount of system users. This feature significantly improves search efficiency and makes ESPD scalable in real-world scenarios. We show a formal analysis to prove the security of ESPD in terms of file privacy, keyword privacy and trapdoor privacy. Also, extensive experiments on real-world dataset are conducted to indicate the desirable performance of ESPD compared to other similar schemes. Jianfei Sun, Guowen Xu, Tianwei Zhang 0004, Hu Xiong, Hongwei Li 0001, Robert H. Deng |
IEEE Trans. Cloud Comput. | 4 |
| 2023 | Expressive Data Sharing and Self-Controlled Fine-Grained Data Deletion in Cloud-Assisted IoTabstractExpressive data sharing and efficient data deletion are essential to drive the development of cloud-assisted IoT. But insecure transmission and the vulnerability of the cloud server may cause potential threats to IoT data, attribute-based encryption (ABE) is widely applied to ensure data confidentially. Nonetheless, the potential data exposure caused by the compromised long-term key and the contradiction between conventional access structures in ABE and the various demands of data owners are still two huge challenges. To overcome these challenges, this article designs an unbounded and puncturable ciphertext-policy ABE with arithmetic span program ($\mathcal {UP}$-$\mathcal {CP}$-$\mathcal {ABE}$-$\mathcal {ASP}$) scheme and presents an expressive data sharing and self-controlled fine-grained data deletion solution in cloud-assisted IoT, which allows data owners to efficiently encrypt and share data with various computable access policies, but also enables data owners and data users to independently delete specific data stored in the cloud. The designed$\mathcal {UP}$-$\mathcal {CP}$-$\mathcal {ABE}$-$\mathcal {ASP}$leverages unbounded ABE and puncturable encryption to support the flexible update of system parameters and the deletion of specific data. Also, the arithmetic span program access structure is combined to realize expressive data sharing. Moreover, the$\mathcal {UP}$-$\mathcal {CP}$-$\mathcal {ABE}$-$\mathcal {ASP}$is adaptively secure in the standard model, and comprehensive performance evaluations demonstrate its practicability and scalability in cloud-assisted IoT. Qian Mei, Hu Xiong |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | FABRIC: Fast and Secure Unbounded Cross-System Encrypted Data Sharing in Cloud ComputingabstractExisting proxy re-encryption (PRE) schemes to secure cloud data sharing raise challenges such as supporting the heterogeneous system efficiently and achieving the unbounded feature. To address this problem, we proposed a fast and secure unbounded cross-domain proxy re-encryption scheme, named FABRIC, which enables the delegator to authorize the semi-trusted cloud server to convert one ciphertext of an identity-based encryption (IBE) scheme to another ciphertext of an attribute-based encryption (ABE) scheme. As the first scheme to achieve the feature mentioned above, FABRIC not only enjoys constant computation overhead in the encryption, decryption, and re-encryption phases when the quantity of attributes increases, but is also unbounded such that the new attributes or roles could be adopted into the system anytime. Furthermore, FABRIC achieves adaptive security under the decisional linear assumption (DLIN). Eventually, detailed theoretical and experimental analysis proved that FABRIC enjoys excellent performance in efficiency and practicality in the cloud computing scenario. Ting Yao 0002, Hu Xiong, Kaitai Liang |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Attribute-Based Data Sharing Scheme With Flexible Search Functionality for Cloud-Assisted Autonomous Transportation SystemabstractThe existing group public key encryption with equality test schemes could only support one-to-one data sharing and are not suitable for cloud-assisted autonomous transportation systems, which demand one-to-many data sharing. To tackle this problem efficiently, in this article, we put forward the group-attribute-based encryption with equality test (G-ABEET) scheme. The presented G-ABEET allows sensors equipped in vehicles to encrypt traffic data with an expressive access policy before sharing it. Only users with attributes required by the access policy ought to access the shared ciphertexts, thus achieving selective one-to-many data sharing. Meanwhile, the authorized cloud server could provide group users with equality tests over the ciphertexts, realizing ciphertext search ability. Furthermore, with the group mechanism, the G-ABEET scheme could resist offline message recovery attacks. Besides, in the standard model, we give rigorous security proof of the G-ABEET construction. The feasibility and efficiency of G-ABEET are demonstrated by experimental simulations. Hu Xiong, Hanxiao Wang 0002, Weizhi Meng 0001, Kuo-Hui Yeh |
IEEE Trans. Ind. Informatics | 1 |
| 2022 | Network Intrusion Detection Based on Hybrid Neural Network
Guofeng He, Qing Lu 0006, Guangqiang Yin, Hu Xiong |
WASA (2) | 4 |
| 2022 | Secure and Authenticated Data Access and Sharing Model for Smart Wearable SystemsabstractContrary to the public cloud storage services that impose users to accept the security restrictions delivered by the service provider, users in the private cloud benefit from self-managed, authenticated data access services. However, this may lead to security issues. A critical challenge is the provision of secure and authenticated data storage for the data owner. Moreover, the data owner should be able to access the stored data and share it with others in a controlled manner. In this article, a secure and authenticated data storage, access, and sharing model is proposed for private cloud storage, which has three components. The data storage component provides the user with secure storage of information. The data-sharing component enables sharing the stored data under the control of the data owner. The data access component enables authenticated access to the cloud storage. The security analysis demonstrates that the model is secure against various attacks. The scheme is validated to be secure via the Scyther tool, BAN Logic, and in Random Oracle Model. The performance analysis regarding the computation and communication cost via simulation in OMNeT++ show that it obtains the required security goals and efficiency of computation and communication, compared to the related methods. Haleh Amintoosi, Mahdi Nikooghadam, Saru Kumari, Jun Feng 0007, Hu Xiong, Sachin Kumar 0002, Joel J. P. C. Rodrigues |
IEEE Internet Things J. | 5 |
| 2022 | Unbounded and Efficient Revocable Attribute-Based Encryption With Adaptive Security for Cloud-Assisted Internet of ThingsabstractExisting attribute-based encryption (ABE) schemes with revocation to secure the cloud-assisted Internet of Things (IoTs) raise challenges, such as eliminating the need for predefined public parameters in system initialization, performing the encryption and decryption operations efficiently, and achieving adaptive security under standard security assumption. In this article, we address these challenges by proposing an unbounded and efficient revocable ABE scheme with adaptive security for cloud-assisted IoTs. Distinct from the previous approaches in this field, our scheme not only efficiently realizes access control over encrypted data in a fine-grained and revocable way but also is proved to be adaptively secure under standard decision linear assumption. Meanwhile, the parameters do not need to be predefined in the system initialization and thus, our scheme satisfies the unbounded property. Moreover, the monotonic span program (MSP) is elegantly utilized as the access structure to reduce the number of bilinear pairing and exponentiation operations for encryption and decryption. Theoretical performance analysis and experiment evaluation disclose that our proposed scheme owns outstanding feasibility, efficiency, and effectiveness. Hu Xiong, Shui Yu 0001 |
IEEE Internet Things J. | 1 |
| 2022 | Burn After Reading: Adaptively Secure Puncturable Identity-Based Proxy Re-Encryption Scheme for Securing Group MessageabstractPuncturable proxy re-encryption (PPRE) is envisioned to provide secure access control delegation and fine-grained forward security for asynchronous group messaging systems. Nevertheless, the existing PPRE scheme not only suffers from the burden of certificate management but also merely achieves selective security based on the nonstandard assumption. In this article, a puncturable identity-based PRE (P-IB-PRE) scheme is proposed to efficiently protect the security and privacy of the group message. The proposed scheme introduces a message server as the proxy to transform ciphertext for each participant in the group; thus, the heavy computation overhead is delegated to the message server with abundant resources. Most importantly, our scheme enables the recipient to revoke its private key’s decryption capability of the specific messages without affecting other messages. Moreover, the identity-based mechanism eliminates the burden of certificate management as well as improves efficiency. The proposed scheme achieves adaptive security under the standard decisional bilinear Diffie–Hellman (DBDH) assumption. Eventually, theoretical and experimental analyses demonstrate that the proposed scheme has an excellent performance in efficiency and practicality. Hu Xiong, Zhida Zhou, Zetong Zhao, Saru Kumari |
IEEE Internet Things J. | 1 |
| 2022 | A Survey of Public-Key Encryption With Search Functionality for Cloud-Assisted IoTabstractNowadays, Internet of Things (IoT) is an attractive system to provide broad connectivity of a wide range of applications, and clouds are natural promoters. Cloud-assisted IoT combines the advantages of cloud computing and IoT, which is able to collect data from the real world and maximizes the value of the collected data by the means of data sharing and data analysis. Meanwhile, secure and convenient data retrieval in cloud servers becomes an important requirement for both enterprises and individual users. Public-key encryption with search functionality (shorten as PKE-SF) is a widely used cryptographic technique that allows users to retrieve encrypted data without decryption. PKE-SF mainly contains the primitives of public-key encryption with keyword search (PKE-KS), public-key encryption with equality test (PKE-ET), and plaintext-checkable encryption (PCE). In light of the overwhelming variety and multitude of PKE-SF schemes, this survey presents these schemes from different perspectives to provide better comprehension for beginners and advanced researchers. More concretely, this survey concentrates on the state of the art of PKE-SF by analyzing the design rationale, examining the framework and security model, and assessing the existing schemes in accordance with theoretic efficiency, security properties, and experimental performance. Furthermore, we discuss the extensions of traditional PKE-SF schemes which feature with the access control delegation, conjunctive keyword search, certificate-free, and offline keyword guessing attack resilience. Finally, we point out some promising directions for readers. Hu Xiong, Tianang Yao, Hanxiao Wang 0002, Jun Feng 0007, Shui Yu 0001 |
IEEE Internet Things J. | 1 |
| 2022 | A survey on Attribute-Based Signatures
Prince Silas Kwesi Oberko, Victor-Hillary Kofi Setornyo Obeng, Hu Xiong, Saru Kumari |
J. Syst. Archit. | 3 |
| 2022 | Proxy-based public-key cryptosystem for secure and efficient IoT-based cloud data sharing in the smart city
Negalign Wake Hundera, Chuanjie Jin, Dagmawit Mesfin Geressu, Muhammad Umar Aftab, Oluwasanmi Ariyo Olanrewaju, Hu Xiong |
Multim. Tools Appl. | 6 |
| 2022 | Revocable Identity-Based Access Control for Big Data with Verifiable Outsourced ComputingabstractTo be able to leverage big data to achieve enhanced strategic insight, process optimization and make informed decision, we need to be an efficient access control mechanism for ensuring end-to-end security of such information asset. Signcryption is one of several promising techniques to simultaneously achieve big data confidentiality and authenticity. However, signcryption suffers from the limitation of not being able to revoke users from a large-scale system efficiently. We put forward, in this paper, thefirstidentity-based (ID-based) signcryption scheme with efficient revocation as well as the feature to outsource unsigncryption to enable secure big data communications between data collectors and data analytical system(s). Our scheme is designed to achieve end-to-end confidentiality, authentication, non-repudiation, and integrity simultaneously, while providing scalable revocation functionality such that the overhead demanded by the private key generator (PKG) in the key-update phase only increases logarithmically based on the cardiality of users. Although in our scheme the majority of the unsigncryption tasks are outsourced to an untrusted cloud server, this approach does not affect the security of the proposed scheme. We then prove the security of our scheme, as well as demonstrating its utility using simulations. Hu Xiong, Kim-Kwang Raymond Choo, Athanasios V. Vasilakos |
IEEE Trans. Big Data | 1 |
| 2022 | Conditional Privacy-Preserving Authentication Protocol With Dynamic Membership Updating for VANETsabstractExisting conditional anonymous authentication protocols to secure the group communication in VANETs (Vehicular Ad hoc Networks) render challenges such as dynamically updating membership in a domain and achieving vehicle user’s privacy preservation. This article elegantly addresses these challenges by proposing a novel conditional privacy-preserving authentication with dynamic membership for VANETs depending on chinese remainder theorem (CRT). Specifically, the CRT is utilized by a trusted authority to securely disseminate a domain key for the authorized vehicles in the same domain, where each vehicle in this domain is able to obtain the domain key by only performing one modulo division operation in case of domain key updating. Distinct from the previous works in this field, our proposed protocol not only achieves message authentication, anonymity and conditional privacy-preserving, but also provides forward security and backward security of vehicles. Theoretical analysis and experiment simulation demonstrate that the proposed protocol is provably secure and highly feasible. Hu Xiong, Qian Mei, Yanan Zhao 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | On the Design of Blockchain-Based ECDSA With Fault-Tolerant Batch Verification Protocol for Blockchain-Enabled IoMTabstractThe blockchain-enabled internet of medical things (IoMT) is an emerging paradigm that could provide strong trust establishment and ensure the traceability of data sharing in the IoMT networks. One of the fundamental building blocks for Blockchain is Elliptic Curve Digital Signature Algorithm (ECDSA). Nevertheless, when processing a large number of transactions, the verification of multiple signatures will incur cumbersome overhead to the nodes in Blockchain. Although batch verification is able to provide a promising approach that verifies multiple signatures simultaneously and efficiently, the upper bound of batch size is limited to small-scale and the efficiency will drop rapidly as the batch size grows in the state-of-the-art ECDSA batch schemes. Meanwhile, most of the existing researches only focus on improving the efficiency of batch verification algorithms in various cryptosystem while ignoring the identification of invalid signatures, which could cause severe performance degradation when the batch verification fails. Motivated by these observations, this paper proposes an efficient and large-scale batch verification scheme with group testing technology based on ECDSA. The application of the presented protocols in Bitcoin and Hyperledger Fabric has been analyzed as supportive and effective. When the batch verification returns a false result, we utilize group testing technology to improve the efficiency of identifying invalid signatures. Comprehensive simulation results demonstrate that our protocol outperforms the related ECDSA batch verification schemes. Hu Xiong, Chuanjie Jin, Mamoun Alazab, Kuo-Hui Yeh, Hanxiao Wang 0002, G. Thippa Reddy, Weizheng Wang 0001, Chunhua Su |
IEEE J. Biomed. Health Informatics | 1 |
| 2022 | Cryptographic Solutions for Cloud Storage: Challenges and Research OpportunitiesabstractWhile cloud computing is relatively mature and its potential benefits well understood by individual, industry and government consumers, a number of security and privacy concerns remain. Unsurprisingly, designing cryptographic solutions to ensure the security of cloud services and the privacy of data outsourced to the cloud remains an ongoing research area. This paper provides a critique of the wide range of cryptographic schemes designed for securing sensitive data in the cloud computing environment, as well as outlining the research opportunities in the use of cryptographic techniques in cloud computing. Lei Zhang 0009, Hu Xiong, Qiong Huang 0001, Jiguo Li 0001, Kim-Kwang Raymond Choo, Jiangtao Li 0003 |
IEEE Trans. Serv. Comput. | 2 |
| 2021 | Certificate-Based Parallel Key-Insulated Aggregate Signature Against Fully Chosen Key Attacks for Industrial Internet of ThingsabstractWith the emergence of the Industrial Internet of Things (IIoT), numerous operations based on smart devices contribute to producing the convenience and comfortable applications for individuals and organizations. Considering the untrusted feature of the communication channels in IIoT, it is essential to ensure the authentication and incontestableness of the messages transmitted in the IIoT. In this article, we first proposed a certificate-based parallel key-insulated aggregate signature (CB-PKIAS), which can resist the fully chosen-key attacks. Concretely, the adversary who can obtain the private keys of all signers in the system is able to forge a valid aggregate signature by using the invalid single signature. Furthermore, our scheme inherits the merits of certificate based and key insulated to avoid the certificate management problem, key-escrow problems, as well as the key exposures simultaneously. In addition, the rigorous analysis and the concrete simulation experiment demonstrated that our proposed scheme is secure under the random oracle and more suitable for the IIoT environment. Yingzhe Hou, Hu Xiong, Saru Kumari |
IEEE Internet Things J. | 2 |
| 2021 | Heterogeneous Signcryption With Equality Test for IIoT EnvironmentabstractThe existing signcryption schemes with equality testing are aimed at a sole cryptosystem and not suitable for the sophisticated heterogeneous network of Industrial Internet of Things (IIoT). To deal with this challenge, we propose a heterogeneous signcryption scheme with equality test (HSC-ET) in this article. This scheme enables a sensor in public key infrastructure (PKI) to execute data encryption and deliver it to the semitrusted entity (cloud server). When a user in an identity-based cryptosystem (IBC) intends to search for some data stored on the cloud server. The delegated cloud server executes tests on ciphertexts for determining whether the same underlying plaintext exists between two ciphertexts. These two ciphertexts can be one signcrypted ciphertext and one encrypted ciphertext, or both encrypted/signcrypted ciphertext, thus achieving a flexible search to the ciphertext. HSC-ET is demonstrated to be secure by the rigorous and detailed analysis. The experimental simulation and analysis results show the efficiency of our scheme. Hu Xiong, Yanan Zhao 0002, Yingzhe Hou, Chuanjie Jin, Saru Kumari |
IEEE Internet Things J. | 1 |
| 2021 | Efficient access control with traceability and user revocation in IoTabstractAbstract With the universality and availability of Internet of Things (IoT), data privacy protection in IoT has become a hot issue. As a branch of attribute-based encryption (ABE), ciphertext policy attribute-based encryption (CP-ABE) is widely used in IoT to offer flexible one-to-many encryption. However, in IoT, different mobile devices share messages collected, transmission of large amounts of data brings huge burdens to mobile devices. Efficiency is a bottleneck which restricts the wide application and adoption of CP-ABE in Internet of things. Besides, the decryption key in CP-ABE is shared by multiple users with the same attribute, once the key disclosure occurs, it is non-trivial for the system to tell who maliciously leaked the key. Moreover, if the malicious mobile device is not revoked in time, more security threats will be brought to the system. These problems hinder the application of CP-ABE in IoT. Motivated by the actual need, a scheme called traceable and revocable ciphertext policy attribute-based encryption scheme with constant-size ciphertext and key is proposed in this paper. Compared with the existing schemes, our proposed scheme has the following advantages: (1) Malicious users can be traced; (2) Users exiting the system and misbehaving users are revoked in time, so that they no longer have access to the encrypted data stored in the cloud server; (3) Constant-size ciphertext and key not only improve the efficiency of transmission, but also greatly reduce the time spent on decryption operation; (4) The storage overhead for traceability is constant. Finally, the formal security proof and experiment has been conducted to demonstrate the feasibility of our scheme. Wei Zhang 0205, Hu Xiong, Zhiguang Qin, Kuo-Hui Yeh |
Multim. Tools Appl. | 3 |
| 2021 | Comment on "Achieving Secure, Universal, and Fine-Grained Query Results Verification for Secure Search Scheme Over Encrypted Cloud Data"abstractRecently in IEEE Transactions on Cloud Computing (TCC), Yinet al.[5]designed a fine-grained query verification mechanism where a novel certificateless short signature scheme is proposed for validating the data of encrypted query results. Despite the authors alleged that their scheme achieves the existential unforgeability to ensure the authenticity of verification objects, we found that this scheme fails to resist the forgery attack. Specifically, through launching the concrete attacks, a malicious adversary can forge a signature on any verification object without being detected. Zhiguang Qin, Yan Wu 0014, Hu Xiong |
IEEE Trans. Cloud Comput. | 3 |
| 2021 | On the Security of Privacy-Preserving Attribute-Based Keyword Search in Shared Multi-Owner SettingabstractRecently in the IEEE Transactions on Dependable and Secure Computing (doi: 10.1109/TDSC.2019.28976752019), Miao et al. proposed a novel construction of Privacy-Preserving Attribute-Based Keyword Search in Shared Multi-owner Setting (ABKS-SM), which can delegate keyword search tasks to cloud server provider (CSP) without revealing any useful information. Although the authors claimed that the offline keyword guessing attacks can be resisted in ABKS-SM scheme, we show that this scheme indeed suffers from four types of offline keyword guessing attacks and hence fails to gain the claimed security property, which is an important goal to be achieved in searchable encryption schemes. Specifically, given the concrete attacks, we demonstrate that the underlying keyword information can be extracted from both encrypted keyword indexes and trapdoors by any malicious user and any adversarial CSP. We hope that the similar security vulnerabilities could be avoided in the future design of related searchable encryption schemes. Jianfei Sun, Hu Xiong, Xuyun Nie, Yinghui Zhang 0002, Pengfei Wu 0003 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | A Fuzzy Authentication System Based on Neural Network Learning and Extreme Value StatisticsabstractInternet-connected smart devices in, on, and around us, (e.g., embedded devices, wearable devices, and smart sensors) can collect human biometric features and facilitate identity authentication. Existing approaches are mainly based on pattern recognition and machine learning algorithms, which may not be capable of processing uncertain user information. Thus, focusing on the uncertainty of users' identity, this article proposes a fuzzy authentication system based on neural network and extreme value analysis. Specifically, we utilize biometric gait information of human body recognition. Our proposed authentication system is designed to implicitly authenticate users based on their gait, and can detect uncertain users and reject the authentication of unknown users. The performance is evaluated using an open dataset of 153 volunteers, where we manage to achieve a recognition accuracy rate of 98.4% and an error rate of unauthorized users at 6%. Zhen Qin 0002, Gu Huang, Hu Xiong, Zhiguang Qin, Kim-Kwang Raymond Choo |
IEEE Trans. Fuzzy Syst. | 3 |
| 2021 | Equality test with an anonymous authorization in cloud computing
Hisham Abdalla, Hu Xiong, Abubaker Wahaballa, Mohammed Ramadan, Zhiguang Qin |
Wirel. Networks | 2 |
| 2020 | An enhanced authentication protocol for client server environment
Muhammad Asad Saleem, Shafiq Ahmed, Khalid Mahmood 0002, Saru Kumari, Hu Xiong |
Frontiers Comput. Sci. | 5 |
| 2020 | Comments on "Toward Secure and Provable Authentication for Internet of Things: Realizing Industry 4.0"abstractInternet of Things (IoT) is the next era of communication networks. The concept of IoT is that everything within the global communication network is interconnected and accessible. Since IoT has various applications, including Industry 4.0. Therefore, upcoming and existing IoT applications are highly auspicious to enhance the level of automation, efficiency, and comfort for the users. However, to a certain extent, there are numerous challenges while deploying IoT devices in the Industry 4.0, like IoT devices are assumed to have inadequate resources to support security solutions. Therefore, in order to protect the communication environment, an efficient and lightweight security solution is needed. Recently, on the basis of a hierarchical approach, Garget al.presented a lightweight, robust key agreement, and provably secure authentication protocol for the IoT environment. Their introduced protocol relies on lightweight operations, including XOR operation, concatenation, hash function, physically unclonable function (PUF), and elliptic curve cryptography. However, in this comment, we point out the security loopholes of Garget al.’s protocol and show that it is vulnerable to the IoT-node impersonation attack. Moreover, it has irrelevant generation and usage of some parameters. Therefore, we put forward some valuable suggestions for attack resilience. Muhammad Arslan Akram, Khalid Mahmood 0002, Saru Kumari, Hu Xiong |
IEEE Internet Things J. | 4 |
| 2020 | Lightweight and Privacy-Aware Fine-Grained Access Control for IoT-Oriented Smart HealthabstractWith the booming of Internet of Things (IoT), smart health (s-health) is becoming an emerging and attractive paradigm. It can provide an accurate prediction of various diseases and improve the quality of healthcare. Nevertheless, data security and user privacy concerns still remain issues to be addressed. As a high potential and prospective solution to secure IoT-oriented s-health applications, ciphertext policy attribute-based encryption (CP-ABE) schemes raise challenges, such as heavy overhead and attribute privacy of the end users. To resolve these drawbacks, an optimized vector transformation approach is first proposed to efficiently transform the access policy and user attribute set into respective vectors of shorter length while other approaches result in redundant and longer vectors. Our transformation approach can greatly relieve the costly overheard of key generation, encryption, and decryption phases. Then, based on the transformation approach and the offline/online computation technology, we propose a lightweight policy-hiding CP-ABE scheme for the IoT-oriented s-health application. With our proposed scheme, data users in the s-health system can perform lightweight encryption and decryption without leaking any sensitive privacy about the attributes of the user. Finally, the formal security analysis, the theoretic performance evaluation and experiment results indicate that the solution is secure and efficient. Jianfei Sun, Hu Xiong, Ximeng Liu, Yinghui Zhang 0002, Xuyun Nie, Robert H. Deng |
IEEE Internet Things J. | 2 |
| 2020 | Efficient and Privacy-Preserving Authentication Protocol for Heterogeneous Systems in IIoTabstractThe Industrial Internet of Things (IIoT) is expected to provide a promising opportunity to revolutionize the production operation of the existing industrial systems by leveraging smart devices. Due to the untrusted nature of communication channels, ensuring data authenticity is a critical challenge. Besides, devices' privacy and communication heterogeneity raise crucial concerns about the IIoT applications since the existing authentication protocols for the IIoT environment face the potential threats of privacy leakage and cannot achieve secure communication between heterogeneous industrial systems. To address these challenges, this article proposes an efficient privacy-preserving authentication protocol for heterogeneous systems in IIoT using proxy resignature. The presented protocol not only provides heterogeneous communication between ID-based and certificateless-based cryptosystems but also achieves various security requirements. The security of our protocol has been proven based on the extended Computational Diffie-Hellman (eCDH) assumption in the random oracle model. The experimental simulation demonstrates that our protocol is feasible for the IIoT-based environment. Hu Xiong, Yan Wu 0014, Chuanjie Jin, Saru Kumari |
IEEE Internet Things J. | 1 |
| 2020 | Mobile access and flexible search over encrypted cloud data in heterogeneous systems
Jianfei Sun, Hu Xiong |
Inf. Sci. | 2 |
| 2020 | A secure and efficient certificateless batch verification scheme with invalid signature identification for the internet of things
Hu Xiong, Yan Wu 0014, Chunhua Su, Kuo-Hui Yeh |
J. Inf. Secur. Appl. | 1 |
| 2020 | A Robust user authentication protocol with privacy-preserving for roaming service in mobility environments
Shashidhara, Sriramulu Bojjagani, Anup Kumar Maurya, Saru Kumari, Hu Xiong |
Peer-to-Peer Netw. Appl. | 5 |
| 2020 | Server-Aided Attribute-Based Signature Supporting Expressive Access Structures for Industrial Internet of ThingsabstractExisting server-aided attribute-based signature (SA-ABS) to secure industrial Internet of Things (IIoT)-oriented applications raise challenges such as achieving collusion attack resilience and realizing expressive linear secret-sharing scheme (LSSS) access structures. In this paper, we positively address these challenges by proposing a novel SA-ABS for IIoT. Distinct from the existing works in this field, our SA-ABS protocol not only allows to delegate the heavy calculation in both signature generation and verification to a third-party server, but also resists the collusion attack and realizes expressive LSSS access structures. The formal proof about the unforgeability of the proposed SA-ABS has been given on the basis of the standard model. Theoretical analysis as well as experimental simulation reveal the fact that the proposed SA-ABS is feasible and efficient. Hu Xiong, Yangyang Bao, Xuyun Nie, Yakubu Issifu Asoor |
IEEE Trans. Ind. Informatics | 1 |
| 2019 | Partially policy-hidden attribute-based broadcast encryption with secure delegation in edge computing
Hu Xiong, Yanan Zhao 0002, Kuo-Hui Yeh |
Future Gener. Comput. Syst. | 1 |
| 2018 | Comments on "A secure anti-collusion data sharing scheme for dynamic groups in the cloud"
Jianfei Sun, Hu Xiong, Zhiguang Qin |
Inf. Process. Lett. | 4 |
| 2018 | Privacy-Preserving Data Aggregation Protocol for Fog Computing-Assisted Vehicle-to-Infrastructure ScenarioabstractVehicle-to-infrastructure (V2I) communication enables moving vehicles to upload real-time data about road surface situation to the Internet via fixed roadside units (RSU). Thanks to the resource restriction of mobile vehicles, fog computation-enhanced V2I communication scenario has received increasing attention recently. However, how to aggregate the sensed data from vehicles securely and efficiently still remains open to the V2I communication scenario. In this paper, a light-weight and anonymous aggregation protocol is proposed for the fog computing-based V2I communication scenario. With the proposed protocol, the data collected by the vehicles can be efficiently obtained by the RSU in a privacy-preserving manner. Particularly, we first suggest a certificateless aggregate signcryption (CL-A-SC) scheme and prove its security in the random oracle model. The suggested CL-A-SC scheme, which is of independent interest, can achieve the merits of certificateless cryptography and signcryption scheme simultaneously. Then we put forward the anonymous aggregation protocol for V2I communication scenario as one extension of the suggested CL-A-SC scheme. Security analysis demonstrates that the proposed aggregation protocol achieves desirable security properties. The performance comparison shows that the proposed protocol significantly reduces the computation and communication overhead compared with the up-to-date protocols in this field. Zhenyu Lu 0005, Hu Xiong |
Secur. Commun. Networks | 3 |
| 2017 | Comments on "Circuit ciphertext-policy attribute-based hybrid encryption with verifiable delegation"
Hu Xiong, Jianfei Sun |
Inf. Process. Lett. | 1 |
| 2017 | Comments on "Verifiable and Exculpable Outsourced Attribute-Based Encryption for Access Control in Cloud Computing"abstractRecently in IEEE Transactions on Dependable and Secure Computing (TDSC) (doi: 10.1109/TDSC.2015.2499755), Ma et al. proposed a new construction of attribute-based encryption (ABE) which can outsource the complicated encryption task to Encryption Service Provider (ESP) in a verifiable manner. Despite the authors claimed that the results of the outsourced encryption can be checked by the user, we show that Ma et al.'s proposal fails to provide the verifiability property for outsourced encryption, the most essential security goal that a verifiable computation scheme should achieve. Specifically, by giving concrete attacks, we demonstrate that the ESP can return forged intermediate ciphertext to the user without being detected. Hu Xiong, Jianfei Sun |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2016 | On the security of two identity-based signature schemes based on pairings
Zhen Qin 0002, Chen Yuan 0002, Hu Xiong |
Inf. Process. Lett. | 4 |
| 2016 | Fuzzy certificateless signatureabstractAccording to the inspirations from history, we introduce a new cryptography primitive called fuzzy certificateless signature, which not only eliminates the key escrow problem inherently existed in fuzzy identity-based signature but also possesses the error tolerance property of fuzzy identity-based signature that allows for a set of attributes ω to verify a signature produced with a private key for an identity ω′ if and only if the distance between the two identities ω and ω′ is within a certain threshold. In this paper, the concept of fuzzy certificateless signature is first proposed, and then, the syntax and security model of fuzzy certificateless signature are formally defined. In the next step, so far, the first concrete fuzzy certificateless signature scheme is proposed, which may be practicably implemented in biometric identification. In addition, a formal security proof is provided, so as to demonstrate that in the random oracle model, our newly proposed scheme is existentially unforgeable against Types I and II chosen message attacks formalized in the security model under the computational Diffie–Hellman assumption. Copyright © 2016 John Wiley & Sons, Ltd. Liangliang Wang 0001, Junzuo Lai, Hu Xiong, Kefei Chen, Yu Long 0001 |
Secur. Commun. Networks | 3 |
| 2015 | Cubic Unbalance Oil and Vinegar Signature Scheme
Xuyun Nie, Hu Xiong |
Inscrypt | 3 |
| 2015 | Revocable and Scalable Certificateless Remote Authentication Protocol With Anonymity for Wireless Body Area NetworksabstractTo ensure the security and privacy of the patient's health status in the wireless body area networks (WBANs), it is critical to secure the extra-body communication between the smart portable device held by the WBAN client and the application providers, such as the hospital, physician or medical staff. Based on certificateless cryptography, this paper proposes a remote authentication protocol featured with nonrepudiation, client anonymity, key escrow resistance, and revocability for extra-body communication in the WBANs. First, we present a certificateless encryption scheme and a certificateless signature scheme with efficient revocation against short-term key exposure, which we believe are of independent interest. Then, a certificateless anonymous remote authentication with revocation is constructed by incorporating the proposed encryption scheme and signature scheme. Our revocation mechanism is highly scalable, which is especially suitable for the large-scale WBANs, in the sense that the key-update overhead on the side of trusted party increased logarithmically in the number of users. As far as we know, this is the first time considering the revocation functionality of anonymous remote authentication for the WBANs. Both theoretic analysis and experimental simulations show that the proposed authentication protocol is provably secure in the random oracle model and highly practical. Hu Xiong, Zhiguang Qin |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2014 | Analysis and improvement of a provable secure fuzzy identity-based signature scheme
Hu Xiong, Guobin Zhu, Zhiguang Qin |
Sci. China Inf. Sci. | 1 |
| 2014 | Certificate-free ad hoc anonymous authentication
Zhiguang Qin, Hu Xiong, Guobin Zhu, Zhong Chen 0001 |
Inf. Sci. | 2 |
| 2014 | Cost-Effective Scalable and Anonymous Certificateless Remote Authentication ProtocolabstractExisting anonymous remote authentication protocols to secure wireless body area networks (WBANs) raise challenges such as eliminating the need for distributing clients' account information to the application providers and achieving forward security. This paper efficiently addresses these challenges by devising a scalable certificateless remote authentication protocol with anonymity and forward security for WBANs. Different from the previous protocols in this field, our protocol not only provides mutual authentication, session key establishment, anonymity, unlinkability, and nonrepudiation, but also achieves forward security, key escrow resilience, and scalability. Performance evaluation demonstrates that compared with the most efficient ID-based remote anonymous authentication protocol, our protocol reduces at least 52.6% and 17.6% of the overall running time and communication overhead, respectively, and the reduction in the computation cost and communication overhead achieves at least 73.8% and 55.8%, respectively, compared with up-to-date certificateless remote authentication protocol with anonymity. Hu Xiong |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2013 | Finding and fixing vulnerabilities in several three-party password authenticated key exchange protocols without server public keys
Hu Xiong, Zhi Guan, Zhong Chen 0001 |
Inf. Sci. | 1 |
| 2013 | An efficient certificateless aggregate signature with constant pairing computations
Hu Xiong, Zhi Guan, Zhong Chen 0001, Fagen Li |
Inf. Sci. | 1 |
| 2013 | Certificateless threshold signature secure in the standard model
Hu Xiong, Fagen Li, Zhiguang Qin |
Inf. Sci. | 1 |
| 2013 | New identity-based three-party authenticated key agreement protocol with provable security
Hu Xiong, Zhong Chen 0001, Fagen Li |
J. Netw. Comput. Appl. | 1 |
| 2012 | Bidder-anonymous English auction protocol based on revocable ring signature
Hu Xiong, Zhong Chen 0001, Fagen Li |
Expert Syst. Appl. | 1 |
| 2012 | Cryptanalysis and improvements of an anonymous multi-receiver identity-based encryption schemeabstractIn 2010, Fan et al. presented an anonymous multi-receiver identity-based encryption scheme where they adopt Lagrange interpolating polynomial mechanism. They showed that their scheme makes it impossible for an attacker or any other message receiver to derive the identity of a message receiver such that the privacy of every receiver can be guaranteed. They also formally showed that every receiver in the proposed scheme is anonymous to any other receiver. In this work, the authors study the security of Fan et al.'s anonymous multi-receiver identity-based encryption scheme. It is regretful that they found their scheme is insecure. Every receiver in Fan et al.'s scheme is not anonymous to any other receiver. The authors showed that simple protocol changes can fix these weaknesses and render Fan et al.'s scheme. The improved scheme is proved to satisfy the confidentiality and receiver anonymity in the random oracle. Huaqun Wang, Yi-Chun Zhang, Hu Xiong |
IET Inf. Secur. | 3 |
| 2012 | Efficient privacy-preserving authentication protocol for vehicular communications with trustworthyabstractABSTRACT In this paper, we introduce an efficient and trustworthy conditional privacy‐preserving communication protocol for VANETs based on proxy re‐signature. The proposed protocol is characterized by the trusted authority (TA) designating the roadside units to translate signatures computed by the on‐board units into one that are valid with respect to TA's public key. In addition, the proposed protocol offers both a priori and a posteriori countermeasures: it can not only provide fast anonymous authentication and privacy tracking, but also guarantee message trustworthiness for vehicle‐to‐vehicle communications. Furthermore, it reduces the communication overhead and offers fast message authentication and low storage requirements. We use extensive analysis to demonstrate the merits of the proposed protocol and to contrast it with previously proposed solutions. Copyright © 2012 John Wiley & Sons, Ltd. Hu Xiong, Zhong Chen 0001, Fagen Li |
Secur. Commun. Networks | 1 |
| 2011 | Need for Symmetry: Addressing Privacy Risks in Online Social NetworksabstractPrivate attributes of Online Social Network (OSN) users can be inferred from other information (which is usually from users' friends and group information). To address this, social networking sites allow users to hide their friend lists and group lists, so that general public cannot see them. However, if a user doesn't make his friend list public, but his friends have public friend list where we can find him, we can do reverse lookup to extend the friend lists of the user. Furthermore, many social networks allow non-group members to list the members of public groups (e.g., Face book). These are strong violations of OSN users' privacy, and can be considered as privacy risks caused by the asymmetric configuration of settings in OSNs. In this paper we present the privacy risks due to the lack of symmetric configurations, which exist in most of the OSNs. To make our idea more clear, we propose a inference attack and show that it can be used to infer users' private information, even users already made their friend list private. We theoretically analyze the risk of proposed privacy issues, and evaluate the risk using experiments based on real-world OSN data. We show that it is not sufficient to only disable friend list and group list to guarantee privacy, and propose methods to mitigate these privacy issues. Cong Tang, Hu Xiong, Tao Yang 0015, Jian-bin Hu, Qingni Shen, Zhong Chen 0001 |
AINA | 3 |
| 2011 | A Traceable Certificateless Threshold Proxy Signature Scheme from Bilinear Pairings
Tao Yang 0015, Hu Xiong, Jian-bin Hu, Biao Xiao, Zhong Chen 0001 |
APWeb | 2 |
| 2011 | Mobile Browser as a Second Factor for Web AuthenticationabstractPeople's increasingly relying on web applications to manage their digital assets makes web authentication a critical security issue. As most websites today still authenticate a user with only username and password, the authentication credentials can be easily compromised in a vulnerable browsing environment without the owner's notice. Considering the browsing in mobile devices is more secure than personal computers, in this paper we explore the One-Time Password web application running inside mobile browsers as a second authentication factor for high value websites in hostile browsing environments. We discuss the security and efficiency of this authentication method from both theory and practice. An implementation with performance evaluation is also provided to prove our concept. Zhi Guan, Hu Xiong, Suke Li, Zhong Chen 0001 |
ISPA | 2 |
| 2011 | Toward Pairing-Free Certificateless Authenticated Key Exchanges
Hu Xiong, Qianhong Wu, Zhong Chen 0001 |
ISC | 1 |
| 2011 | Cryptanalysis of an Identity Based Signcryption without Random OraclesabstractSigncryption is a cryptographic primitive that performs digital signature and public key encryption simultaneously, at lower computational costs and communication overhead than signing and encrypting separately. Recently, Yu et al. proposed an identity based signcryption scheme with a claimed proof of security. We show that their scheme is not secure even against a chosen-plaintext attack. Hu Xiong, Zhiguang Qin, Fagen Li |
Fundam. Informaticae | 1 |
| 2010 | Efficient and Spontaneous Privacy-Preserving Protocol for Secure Vehicular CommunicationabstractThis paper introduces an efficient and spontaneous privacy-preserving protocol for vehicular ad-hoc networks based on revocable ring signature. The proposed protocol has three appealing characteristics: First, it offers conditional privacy-preservation: while a receiver can verify that a message issuer is an authorized participant in the system only a trusted authority can reveal the true identity of a message sender. Second, it is spontaneous: safety messages can be authenticated locally, without support from the roadside units or contacting other vehicles. Third, it is efficient: it offers fast message authentication and verification, cost-effective identity tracking in case of a dispute, and has low storage requirements. We use extensive analysis to demonstrate the merits of the proposed protocol and to compare it with previously proposed solutions. Hu Xiong, Konstantin Beznosov, Zhiguang Qin, Matei Ripeanu |
ICC | 1 |
| 2008 | An Improved Certificateless Signature Scheme Secure in the Standard Model
Hu Xiong, Zhiguang Qin, Fagen Li |
Fundam. Informaticae | 1 |
| 2007 | First results of GNSS-R coastal experiment in ChinaabstractWe report on the first time of GNSS-Reflection (GNSS-R) coastal experiment in Fujian province in the southeast of China. The experimental campaign began in September 2006 and the succeeding observation was kept until March 2007. Through the ocean reflected event recorded by the Oceanpal instruments, the direct and reflected correlation waveforms were obtained. We retrieved the Significant Wave Height (SWH) and Sea Surface Height (SSH) with these data. Then a method to compute the wave speed and direction by the delay of the autocorrelation waveforms was proposed. We present primary results here. With the continual measurements, we also studied the semidiurnal tides and paid our attention to the variations of amplitudes and phases of the tides. At last we present some problems occurred in this experiment and discussed the possible treatments to make the observing technique available in the seacoast of China. Zhang Xunxie, Shao Lianjun, Sun Qiang, Hu Xiong, Giulio Ruffini, D. Stephen, François Soulat |
IGARSS | 5 |