Jianwei Liu 0001

dblp:43/3771-1 · DBLP profile ↗
← Back
172ranked-venue papers
3as first author
104since 2021 · last 2026
0000-0003-2965-3518ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 73 · 2 first-author · 37 since 2021Computer networks · 41 · 33 since 2021Systems, architecture and hardware · 18 · 9 since 2021Applied, interdisciplinary, general and emerging computing · 17 · 13 since 2021Artificial intelligence and machine learning · 11 · 8 since 2021Databases, data management, data science and information retrieval · 9 · 7 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Theory of computation · 1
YearPublicationVenuePosition
2026 Soloist: Distributed SNARK for R1CS with Constant Proof Size
Zongyang Zhang, Jianwei Liu 0001
EUROCRYPT (7)6
2026 SAGE: Self-Reflective End-to-End Framework for Automated APT Investigation in 5G Networks
Yu Sun 0015, Gaojian Xiong, Jianwei Liu 0001
INFOCOM6
2026 A Secure and Efficient Handover Authentication and Key Agreement Protocol in Fog Computing
Yiran Han, Jianwei Liu 0001, Hua Guo 0001, Zongxiao Li, Shanyao Ren
SACMAT2
2026 Optimistic Asynchronous Dynamic-Committee Proactive Secret Sharing
Bin Hu 0001, Jianwei Liu 0001, Zhenliang Lu, Qiang Tang 0005, Zhuolun Xiang, Zongyang Zhang
SP2
2026 GoSSamer: Lightweight and Linear-Communication Asynchronous (Dynamic Proactive) Secret Sharing and the Applications
Xinxin Xing, Yizhong Liu, Boyang Liao, Jianwei Liu 0001, Bin Hu 0001, Xun Lin, Yuan Lu 0001, Tianwei Zhang 0004
SP4
2026 A Lightweight and Secure Extended Authentication and Key Agreement Protocol for Direct-to-Cell LEO Satellite Constellations
Yu Sun 0015, Gang Wang 0016, Jianwei Liu 0001
WCNC5
2026 ShadowClone: Scalable Decentralized Identity with Cross-Domain Anonymity and Accountable Traceability
abstract
Decentralized identity (DID) is a key infrastructure for Web3, granting users sovereign control over their private identity data. While existing DID systems like FADID-TT (WWW'25) realize anonymity and traceability within a single domain, the Web3 ecosystem is a multiverse of independent domains like DeFi, GameFi, and DAO. This multi-domain reality presents critical issues for current DID solutions. First, most existing solutions are built on the monolithic committee architecture, facing severe scalability bottlenecks as the committee size grows. Second, most existing solutions cannot offer strong cross-domain anonymity, where frequent cross-domain interaction inevitably exposes the user's privacy. Third, existing methods for tracing the identities of malicious users are inefficient.
Yizhong Liu, Zedan Zhao, Na Wang 0003, Haojun Tan, Jianwei Liu 0001
WWW6
2026 Xemis: Fair and Robust Privacy-Preserving Data Trading based on Distributed Noise Sharing
abstract
Privacy-preserving data trading allows data owners to sell data to consumers through a data trading web platform, the data market, without disclosing sensitive information in raw data. It enables legitimate data transmission and aggregation, facilitating large-scale data-driven model training. However, existing differential privacy-based approaches struggle to inject precisely calibrated noise in a trustworthy manner without revealing raw data to a third party, thus making them fail in achieving strong fairness and controllable privacy simultaneously, especially when facing malicious external adversaries or a corrupted data market.
Xinxin Xing, Yizhong Liu, Banghong Qin, Wangjie Qiu, Jianwei Liu 0001, Qianhong Wu, Willy Susilo, Robert H. Deng
WWW6
2026 An ultra-lightweight PUF and ASCON-based authentication and key agreement protocol for UAV-ground station and UAV-UAV communication
abstract
Abstract Unmanned aerial vehicles (UAVs) have been increasingly integrated into diverse domains such as environmental monitoring, intelligent transportation, border surveillance, and military reconnaissance, giving rise to the broader concept of the Internet of Drones (IoD). However, this rapid proliferation also underscores the urgent need for secure and efficient communication mechanisms, as UAVs typically operate over public channels that are highly vulnerable to various security and privacy threats. To address these issues, authentication and key agreement (AKA) protocols have been introduced to enhance secure communication. However, most of the existing AKA protocols either incur high computation cost due to complex cryptographic primitives, or fail to provide resilience against attacks such as replay, impersonation, and ephemeral secret leakage. In this paper, we propose an ultra-lightweight AKA protocol that integrates physical unclonable function (PUF) with the lightweight authenticated encryption with associated data (AEAD) primitive ASCON. The protocol supports UAV registration over open channels, achieves mutual authentication between UAV and ground station, and extends to secure UAV-UAV communication with the assistance of the ground station. A formal proof under the real-or-random (ROR) model demonstrates the semantic security of the proposed protocol, while informal analysis confirms robustness against diverse attacks. Comprehensive performance evaluation shows that the total computation cost of the proposed protocol is approximately 2.391 ms, which is the lowest among the compared schemes. Specifically, it reduces computation cost by up to 69.0% compared with representative IoD authentication protocols and remains approximately 10.9% lower than existing ultra-lightweight designs. These results demonstrate that the proposed protocol achieves a superior balance between security strength and resource efficiency, making it particularly suitable for resource-constrained IoD environments.
Hua Guo 0001, Jianwei Liu 0001, Yiran Han, Hutao Song
Cybersecur.3
2026 A resource-efficient authentication and key agreement protocol for smart grid
abstract
Abstract Smart grid (SG) facilitates our lives by providing more reliable electricity and enabling better integration of renewable energy sources. Currently, numerous authentication and key agreement (AKA) protocols have been proposed to secure SG communication. However, these solutions often result in considerable cost, making them inappropriate for resource-constrained SG environment. In this paper, we propose a secure and resource-efficient AKA protocol by employing lightweight cryptography primitives including authenticated encryption with associated data (AEAD) primitive ASCON, hash function and XOR operation. The ASCON primitive simultaneously provides data confidentiality, integrity and authenticity with low computation cost, making it suitable for employing in resource-constrained SG environment. The secret intermediate values in the protocol are designed as hash values that incorporate both long-term and short-term secrets, thereby providing enhanced security while further reducing cost. Moreover, a dynamic indexing method is deployed in the protocol to resist de-synchronization attack. The designed protocol performs secure mutual authentication and session key establishment between entities without relying on a central trusted authority. The proposed protocol is proven secure through rigorous security proof under the real-or-random model and formally verified by AVISPA tool. Theoretical performance analysis and simulation results indicate that the proposed protocol outperforms other related protocols due to its lightweight nature and adherence to all fundamental security attributes, making it suitable for deployment in smart grid environment.
Hua Guo 0001, Hutao Song, Yapeng Wu, Jianwei Liu 0001, Yiran Han
Cybersecur.5
2026 New permutation polynomials with coefficients 1 over finite fields and their compositional inverses
Hutao Song, Hua Guo 0001, Fengju Gao, Xiyong Zhang, Jianwei Liu 0001
Frontiers Comput. Sci.5
2026 CP-SuperSpartan: commit-and-prove SNARKs for customizable constraint systems
Zibo Zhou, Zongyang Zhang, Feng Hao 0001, Jianwei Liu 0001
Frontiers Comput. Sci.4
2026 Some Flaws of Authentication and Key Agreement Protocols Against Ephemeral Secret Leakage Attack for Smart Grid
abstract
The increasing complexity of the smart grid raises significant concerns regarding the security of smart grid communication. As a countermeasure, authentication and key agreement (AKA) protocol ensures the secure transmission of sensitive information between legitimate entities by achieving mutual authentication and establishing session keys. One of the most urgent and critical security threats in AKA protocol concerns ephemeral secret leakage (ESL) attack, due to its threat to session key secrecy. However, there remains a lack of systematic understanding of how to resist ESL attacks in smart grid environment. Therefore, we categorize the ESL attack into three different types, then conduct an in-depth analysis of their root causes and propose corresponding recommendations to mitigate it. To further illustrate the effectiveness of the recommendations, we design a secure and efficient AKA protocol based on elliptic curve cryptography accordingly. The proposed protocol is proven secure through rigorous security proof under the random oracle model and formally verified by AVISPA tool. Performance comparisons indicate that the proposed protocol outperforms other related protocols due to its lightweight nature and adherence to all fundamental security attributes, making it well-suited for deployment in resource-constrained smart grid environment.
Hua Guo 0001, Jianwei Liu 0001, Yiran Han, Hutao Song
IEEE Internet Things J.3
2026 SLAPE: Secure Lightweight Authentication for Privacy-Enhanced Federated Learning in Industrial Internet of Things
abstract
Federated learning (FL) has emerged as a promising technique in the Industrial Internet of Things (IIoT) by enabling distributed devices to collaboratively train models without sharing raw data. In FL, ensuring data privacy and secure authentication becomes essential due to the sensitivity of industrial data and the potential for adversarial attacks. This paper highlights a security flaw in a recently proposed FL authentication protocol designed for IIoT environments. Specifically, the scheme is analyzed to be susceptible to public-key replacement attacks. We propose a secure, lightweight authentication scheme for privacy-enhanced federated learning (SLAPE) to address vulnerabilities in participant registration, group key distribution, local data training, and aggregation processes. SLAPE leverages the Elliptic Curve Cryptography with the Chinese Remainder Theorem to support malicious group member traceability, revocation of compromised identities, and efficient batch verification of multiple messages. It effectively resists Type-I attacks that previous schemes could not, while also incorporating forward and backward security essential for IIoT applications. We rigorously demonstrate SLAPE’s resilience against prevalent threats through both formal and informal analyses. Our evaluation results indicate that SLAPE demonstrably enhances the security and privacy of existing schemes, with improvements in computational efficiency for both proof generation and verification, while keeping communication overhead relatively low.
Shanyao Ren, Jianwei Liu 0001, Chip-Hong Chang, Hanzhou Wang, Dongyu Li
IEEE Internet Things J.2
2026 HALO: Heterogeneous evaluation of arithmetic-and-logic circuit via unified homomorphic instruction set
Zian Zhao, Zhou Zhang 0016, Ran Mao, Song Bian 0001, Jianwei Liu 0001
J. Inf. Secur. Appl.5
2026 SMARC: A State-Repairing Multi-Agent Resilient Consensus Scheme
abstract
In this paper, we analyze a recent algorithm for resilient consensus control in distributed multi-agent systems. While effective in theory, its reliance on security in communication and strong connectivity assumptions limits its practicality in dynamic electronic and cyber-physical systems, such as embedded device networks and uncrewed platforms. To address these limitations, we propose a State-repairing Multi-agent Resilient Consensus (SMARC) scheme to eliminate the need for normal agents to collect trustworthy state values from a fixed bounded threshold of neighbors to achieve reliable consensus. The core innovation of SMARC is a decentralized state-repair mechanism, which enables agents to obtain additional information from their reachable sets to repair unavailable or corrupted state values of malicious or faulty agents, and autonomously adjust their convergence speed. Additionally, without negatively impacting the consensus performance, SMARC employs a noise-masked surface state to protect the initial states of agents from eavesdropping. This approach avoids extra storage and reduces computations without adhering to strict security prerequisites, making it more suitable for resource-constrained electronic systems compared to existing methods. Theoretical convergence and security proofs demonstrate that SMARC can successfully resist passive attacks while ensuring accurate convergence on multi-dimensional data. Most importantly, from small- to large-scale networks, SMARC achieves a three- to four-fold increase in convergence speed compared to the most competitive recent state-of-the-art resilient consensus algorithm in both passive and active attacks. A prototype electronic of a MAS was also built using six Raspberry Pi devices to validate its performance and robustness in practical environments.
Shanyao Ren, Chip-Hong Chang, Jianwei Liu 0001, Dongyu Li
IEEE Trans. Circuits Syst. I Regul. Pap.3
2026 EdgeGuard: Blockchain-Enhanced Secure Data Circulation via Aggregatable Distributed Key Generation
abstract
Data has become a critical driver of innovation in artificial intelligence and the evolution of 6G technologies. The explosive growth of data volume accelerates the convergence of cloud and edge computing, while simultaneously posing heightened challenges to data security and privacy. The emerging cloud-edge-device collaborative paradigm enables dynamic and large-scale data circulation across heterogeneous entities, exposing systems to complex threats such as malicious edge nodes and eavesdropping over untrusted communication channels. In response to these issues, we propose EdgeGuard, a secure and decentralized framework for cloud-edge-device data circulation. EdgeGuard is specifically designed for highly dynamic environments and ensures robust data confidentiality, integrity, traceability, and resilience against both malicious external attackers and compromised edge servers. To underpin its cryptographic foundation, we develop two core primitives. Specifically, we introduce an Aggregatable Publicly Verifiable Secret Sharing (APVSS) scheme that enables efficient sharing of field elements while supporting aggregation and public verifiability. Furthermore, we construct AggDKG, a distributed key generation (DKG) protocol. AggDKG achieves public verifiability and bias resistance with an expected total communication cost of${\mathcal {O}}(\kappa n^{3})$effectively overcoming the scalability limitations inherent in traditional complaint-based protocols. Collectively, these components form a comprehensive framework that strengthens secure and efficient data circulation in cloud-edge-device systems. Experimental data show that AggDKG delivers clear performance gains: across all tested scales, its total running time is only about 8%–65% of that of the DKG of Gurkan et al., and at$n=256$, it reduces per-node runtime by approximately 27% compared with the DKG of Gennaro et al. These results highlight EdgeGuard's superior scalability, lower latency, and stronger Byzantine resilience for secure large-scale deployments.
Boyang Liao, Jianwei Liu 0001, Xinxin Xing, Qianhong Wu, Willy Susilo, Robert H. Deng, Yizhong Liu
IEEE Trans. Dependable Secur. Comput.2
2026 VLMS: Verifiable Lattice-Based Encryption With Multi-Keyword Search in Cloud Storage
Na Wang 0003, Wen Zhou 0021, Jingjing Wang 0001, Junsong Fu 0001, Jianwei Liu 0001, Bharat K. Bhargava
IEEE Trans. Dependable Secur. Comput.5
2026 LIVA: A Multi-Agent LLM-Assisted System for IoT Vulnerability Analysis
abstract
IoT devices have become deeply integrated into our daily lives, making comprehensive security research on critical infrastructure devices increasingly important. Static analysis techniques, particularly those leveraging taint propagation, have demonstrated promise in identifying security vulnerabilities within these devices, effectively detecting critical vulnerabilities. However, current solutions often struggle with limitations in both detection efficiency and accuracy. To address these challenges, this paper introduces Liva, a novel static taint analysis tool designed for detecting web vulnerabilities in IoT devices. Liva employs a large language model (LLM) multi-agent approach for static binary taint analysis, primarily leveraging fine-tuned open-source models and commercial LLMs to improve source/sink identification and taint data analysis—areas where traditional methods often fall short—thereby enhancing overall analysis efficiency. LIVA's core analysis engine leverages a Qwen3-32B open-source model that has been fine-tuned using a dataset of 3,000 real-world device samples. This fine-tuned model achieves a 3 percentage point improvement in accuracy for identifying taint data propagation relationships compared to commercial LLMs, while also increasing average analysis efficiency by 5.5%. A comprehensive evaluation of Liva, conducted on a dataset of 64 devices from 11 vendors, revealed that it detected 309 and 349 more known vulnerabilities than the state-of-the-art solutions SaTC and Karonte, respectively, while simultaneously reducing false positive rates by 59.4% and 67.6%. Liva achieves a recall of 98.1% and a precision of 74.6%, with a 6.7× reduction in analysis time compared to the best-performing baseline. Furthermore, in the realm of zero-day vulnerability detection, Liva discovered 64 previously unknown vulnerabilities, 39 of which have since been assigned official CVE/CNVD identifiers.
Hao Peng 0001, Yanling Jiang, Jianwei Liu 0001, Hongbin Luo, Mingsheng Tang, Kun Zhang 0012
IEEE Trans. Dependable Secur. Comput.4
2026 SharBipole: Secure and Scalable Sharding Blockchain-Based Federated Learning Against Poisoning Attacks
abstract
Federated Learning (FL) enables collaborative model training across distributed devices while preserving data privacy. However, it faces critical security challenges, including centralization risks and poisoning attacks, which degrade robustness and scalability. Existing schemes struggle to simultaneously mitigate targeted and untargeted poisoning attacks, impose restrictive adversary ratio assumptions (poison ratio < 50%), and suffer from privacy-performance trade-offs. To address these limitations, we propose SharBipole, a decentralized FL scheme integrating sharding blockchain with a novel dual-metric defense mechanism, Bipole. SharBipole employs a Byzantine Fault Tolerant-enabled sharding architecture to eliminate single points of failure, reduce communication overhead, and enable parallel model aggregation. Meanwhile, the Bipole module defends against poisoning attacks using two adaptive similarity metrics to filter malicious updates dynamically. Reinforcement learning optimizes threshold adjustments, while noise-aware adaptive clipping balances privacy and model utility. Further, we give convergence analysis to prove the theoretical soundness and scalability of SharBipole. Lastly, extensive experimental evaluations demonstrate that SharBipole supports poison ratios exceeding 50% and improves throughput and latency. The model replacement attack with 60% adversaries is entirely ineffective against SharBipole, and the label-flipping attack achieves an attack success rate of only 2.344%. SharBipole establishes a scalable, secure, and privacy-preserving solution for distributed learning in massive environments.
ZiAn Jin, Dawei Li 0009, Jianwei Liu 0001, Hao Peng 0001, Qianhong Wu, Zhenyu Guan 0002, Willy Susilo, Robert H. Deng, Yizhong Liu
IEEE Trans. Inf. Forensics Secur.3
2026 Multi-Leader Byzantine Fault Tolerance in Blockchain: Performance and Security
Yizhong Liu, Mingzhe Zhai, Xun Lin, Chenhao Ying 0001, Zhenyu Guan 0002, Dawei Li 0009, Qianhong Wu, Jianwei Liu 0001, Willy Susilo, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.9
2026 An Efficient and Secure Authentication and Key Agreement Protocol for Multi-Device Scenarios in Fog Computing
abstract
The fog computing paradigm enables mobile users to seamlessly interact with crowds of nearby IoT devices for low-latency services. However, existing authentication and key agreement (AKA) protocols suffer from critical limitations in this mobile context. While existing AKA schemes are optimized for mobile edge environments, they incur substantial overhead in multi-device scenarios: they require repeated authentication for each device and generate distinct session keys per user-device pair, leading to high key management complexity at scale. Furthermore, traditional one-to-many protocols are unsuitable for distributed fog environments due to their reliance on trusted central nodes (e.g., gateways or servers) and incompatible communication models. To address these issues, this paper proposes an efficient and secure authentication protocol for fog computing that integrates elliptic curve cryptography with secret sharing. Our solution enables a user to authenticate an entire group of devices managed by a semi-trusted fog node (honest-but-curious) through a single protocol execution, effectively eliminating the authentication bottleneck caused by scaling devices. Formal security proof under the Real-Or-Random (ROR) model is provided, along with informal analysis, demonstrating the protocol ensures forward secrecy, user anonymity, and resistance to a comprehensive set of attacks, including ephemeral secret leakage, key compromise impersonation, and replay attacks. Performance analysis confirms the scheme maintains low communication and computational overhead while achieving comprehensive security.
Yiran Han, Jianwei Liu 0001, Hua Guo 0001, Zongxiao Li, Shanyao Ren
IEEE Trans. Mob. Comput.2
2026 Toward Trusted 6G Mobile Edge Computing: A Secure Batch Large Language Models Deployment Framework
Yu Sun 0015, Gaojian Xiong, Qinglin Song, Jianwei Liu 0001, Gang Wang 0016, Rui Wang 0183
IEEE Trans. Mob. Comput.5
2026 Secure Authentication and Encryption With Distributed Management for SAGIN via Signcryption and Sharding Blockchain
abstract
With the development of air transportation, Space-Air-Ground Integrated Network (SAGIN) are playing an increasingly important role in optimizing air traffic management and enhancing flight safety for billions of passengers and trillions dollars of aviation industry. As the key technology of SAGIN, the Automatic Dependent Surveillance-Broadcast (ADS-B) system is widely used due to its simple operation, low construction cost, and high information accuracy. However, the security problems in ADS-B system, including lack of identity authentication between all communication links, crucial information transmitted in plaintext, and susceptibility to the single point of failure, have been serious obstacle to its wide application. Existing solutions fail to account for the unique characteristics of ADS-B and SAGIN, leading to inadequate security and poor performance in these specialized contexts. Aiming to solve the above issues and provide security and scalability for ADS-B system, we conduct the following research. Firstly, an enhanced identity-based broadcast signcryption (e-IBBSC) scheme is designed to keep crucial information confidential and all messages authenticated simultaneously. Secondly, we propose an efficient batch message authentication method combined with the Merkle tree and proposed e-IBBSC, significantly improving the ADS-B message utilization ratio from 1.35% to 74.10%. Thirdly, we utilize the sharding blockchain and Byzantine fault tolerance protocol to design the first sharding-based distributed management system for SAGIN that realizes fault tolerance and scalability. Finally, after a detailed security analysis and comprehensive performance evaluation, we demonstrate that our solution can achieve all proposed system goals including security, scalability, and high performance of 1s flight transaction processing latency and 62KTPS throughput.
Yizhong Liu, Xuqi Huang, Runhua Xu, Jianwei Liu 0001, Qianhong Wu, Willy Susilo, Robert H. Deng
IEEE Trans. Netw.6
2026 A Multi-Semantic Scheme to Verifiable EHRs Retrieval for Cloud-Based Telemedicine
abstract
As the cornerstone of telemedicine, Electronic Health Records (EHRs) not only reduce clinical costs but also enable precision diagnostics. As medical institutions increasingly outsource EHRs to Cloud Service Providers (CSPs), dual challenges have emerged as critical issues: preserving patient privacy and enhancing the search experience for medical personnel. While multi-keyword searchable encryption has gained significant attention in the medical domain as a potential solution, existing schemes have significant limitations in both practicality and security. First, the growing number of medical institutions complicates the management of key and privileges. Second, the impoverished search semantics in existing query mechanisms severely degrades the clinical user experience, creating unacceptable operational bottlenecks in medical practice. Furthermore, excessive reliance on CSPs leads to ignoring situations where the returned results are incorrect, impacting the availability and security of the telemedicine system. To address these limitations, we propose a Verifiable Multi-Semantic Keyword Search scheme (VMSKS) for EHRs in cloud-based telemedicine. To resolve the security requirements arising from the increasing medical institutions, we innovatively design a more efficient dual Securek-Nearest Neighbor technique (SKNN) for key distribution. Meanwhile, fine-grained access control is implemented using access policy trees, ensuring the controllability of data access. This approach safeguards the privacy of EHRs. To support flexible EHR search for medical personnel, the prime Hadamard product encoding technique is exploited to provide queries that support multiple search semantics simultaneously. Given the potential unreliability of CSPs, VMSKS introduces a novel verification mechanism by constructing verification proofs during encryption, ensuring the authenticity and integrity of returned results. Theoretical analysis and experimental evaluation demonstrate the security and efficiency of VMSKS, respectively.
Na Wang 0003, Guizhen Chen, Jianwei Liu 0001, Junsong Fu 0001
IEEE Trans. Netw.3
2025 Realizing Corrupted-Shard Tolerance: A Sharding Blockchain with Preserving Global Resilience
abstract
Blockchain sharding is a promising approach to enhancing scalability by partitioning the network into smaller, parallel shards. However, existing sharding blockchains that rely on Byzantine fault tolerance protocols require large shard sizes to meet strict security thresholds, limiting scalability, while relaxing security parameters can lead to liveness and safety violations. In this work, we present Camael, a secure sharding blockchain that achieves corrupted-shard tolerance through effective detection and processing mechanisms for both liveness and safety violations. Specifically, fake liveness violations forged by malicious nodes are accurately detected via a two-phase reporting and confirmation mechanism, while concealed safety violations are efficiently identified using a lightweight snapshot mechanism. Furthermore, a state determination process ensures overall system consistency. Malicious nodes are precisely identified through a conviction mechanism, which enables the replacement of the targeted nodes and the reconfiguration of the shards. Notably, Camael ensures security while preserving a global fault tolerance of 1/3 and tolerating corrupted shards, with each shard accommodating up to 2/3 malicious nodes. Extensive experiments conducted on 2000 AWS EC2 nodes across 4 regions demonstrate that Camael improves throughput by 3.56 times compared to the baseline (Kronos, NDSS'25), achieving a throughput of 109.3 ktx/sec, while the violation processing requires only 1.64 sec.
Yizhong Liu, Andi Liu, Zhuocheng Pan, Jianwei Liu 0001, Song Bian 0001, Yuan Lu 0001, Zhenyu Guan 0002, Dawei Li 0009, Meikang Qiu
CCS5
2025 5GC-Fuzz: Finding Deep Stateful Vulnerabilities in 5G Core Network with Black-Box Fuzzing
Yu Sun 0015, Jianwei Liu 0001
INFOCOM6
2025 Kronos: A Secure and Generic Sharding Blockchain Consensus with Optimized Overhead
Yizhong Liu, Andi Liu, Yuan Lu 0001, Zhuocheng Pan, Yinuo Li, Jianwei Liu 0001, Song Bian 0001, Mauro Conti
NDSS6
2025 LoRO: Real-Time on-Device Secure Inference for LLMs via TEE-Based Low Rank Obfuscation
abstract
While Large Language Models (LLMs) have gained remarkable success, they are consistently at risk of being stolen when deployed on untrusted edge devices. As a solution, TEE-based secure inference has been proposed to protect valuable model property. However, we identify a statistical vulnerability in existing protection methods, and furtherly compromise their security guarantees by proposed Model Stealing Attack with Prior. To eliminate this vulnerability, LoRO is presented in this paper, which leverages dense mask to completely obfuscate parameters. LoRO includes two innovations: (1) Low Rank Mask, which uses low-rank factors to generate dense masks efficiently. The computing complexity in TEE is hence reduced by an exponential amount to achieve inference speed up, while providing robust model confidentiality. (2) Factors Multiplexing, which reuses several cornerstone factors to generate masks for all layers. Compared to one-mask-per-layer, the secure memory requirement is reduced from GB-level to tens of MB, hence avoiding the hundred-fold latency introduced by secure memory paging. Experimental results indicate that LoRO achieve a $0.94\times$ Model Stealing (MS) accuracy, while SOTA methods presents $3.37\times$ at least. The averaged inference latency of LoRO is only $1.49\times$, compared to the $112\times$ of TEE-shielded inference. Moreover, LoRO results no accuracy loss, and requires no re-training and structure modification. LoRO can solve the concerns regarding model thefts on edge devices in an efficient and secure manner, facilitating the wide edge application of LLMs.
Gaojian Xiong, Yu Sun 0015, Jianwei Liu 0001
NeurIPS5
2025 CHLOE: Loop Transformation over Fully Homomorphic Encryption via Multi-Level Vectorization and Control-Path Reduction
abstract
This work proposes a multi-level compiler framework to transform programs with loop structures to efficient algorithms over fully homomorphic encryption (FHE). We observe that, when loops operate over ciphertexts, it becomes extremely challenging to effectively interpret the control structures within the loop and construct operator cost models for the main body of the loop. Consequently, most existing compiler frameworks have inadequate support for programs involving non-trivial loops, undermining the expressiveness of programming over FHE. To achieve both efficient and general program execution over FHE, we propose CHLOE, a new compiler framework with multi-level control-flow analysis for the effective optimization of compound repetition control structures. We observe that loops over FHE can be classified into two categories depending on whether the loop condition is encrypted, namely, the transparent loops and the oblivious loops. For transparent loops, we can directly inspect the control structures and build operator cost models to apply FHE-specific loop segmentation and vectorization in a fine-grained manner. Meanwhile, for oblivious loops, we derive closed-form expressions and static analysis techniques to reduce the number of potential loop paths and conditional branches. In the experiment, we show that CHLOE can compile programs with complex loop structures into efficient executable codes over FHE, where the performance improvement ranges from 1.5× to 54× (up to 105× for programs containing oblivious loops) when compared to programs produced by the-state-of-the-art FHE compilers.
Song Bian 0001, Zian Zhao, Ruiyu Shen, Zhou Zhang 0016, Ran Mao, Dawei Li 0009, Yizhong Liu, Masaki Waga, Kohei Suenaga, Zhenyu Guan 0002, Jiafeng Hua, Yier Jin, Jianwei Liu 0001
SP13
2025 AirFRL: Topology-Aware Decentralized Federated Reinforcement Learning for UAV Networks
abstract
Machine learning (ML) enhanced unmanned aerial vehicle (UAV) networks are envisioned to facilitate extensive applications in next-generation wireless networks. Due to the privacy concern and communication overhead in cloud-centric ML, federated reinforcement learning (FRL) enables UAVs to collaboratively train a policy model without disclosing raw observation data. However, the model aggregator in centralized FRL architecture poses various potential threats such as a single point of failure and is inappropriate to distributed networks with unreliable links and nodes. In this paper, we propose AirFRL, a topology-aware decentralized federated reinforcement learning framework for UAV-enabled networks. In AirFRL, we consider the topology dynamics influenced by nodes' mobility and communication quality and its impact on AirFRL. To accelerate training process and guarantee the model performance, we also incorporate the model compression to lighten the local model and introduce the consensus distance and data correlation to reflect the discrepancy between local models and local data. Furthermore, we propose an efficient algorithm to decide the optimal neighbour node selection and model compression ratio. A case study and numerical results demonstrate that AirFRL can achieve linear training speedup and guarantee the learning performance for UAV-enabled networks.
Ziheng Tong, Jingjing Wang 0001, Jianrui Chen 0001, Xin Zhang 0039, Haohua Du, Jianwei Liu 0001
VTC2025-Spring6
2025 FLock: Robust and Privacy-Preserving Federated Learning based on Practical Blockchain State Channels
abstract
Federated Learning (FL) is a distributed machine learning paradigm that allows multiple clients to train models collaboratively without sharing local data. Numerous works have explored security and privacy protection in FL, as well as its integration with blockchain technology. However, existing FL works still face critical issues. i) It is difficult to achieving poisoning robustness and data privacy while ensuring high model accuracy. Malicious clients can launch poisoning attacks that degrade the global model. Besides, aggregators can infer private data from the gradients, causing privacy leakages. Existing privacy-preserving poisoning defense FL solutions suffer from decreased model accuracy and high computational overhead. ii) Blockchain-assisted FL records iterative gradient updates on-chain to prevent model tampering, yet existing schemes are not compatible with practical blockchains and incur high costs for maintaining the gradients on-chain. Besides, incentives are overlooked, where unfair reward distribution hinders the sustainable development of the FL community. In this work, we propose FLock, a robust and privacy-preserving FL scheme based on practical blockchain state channels. First, we propose a lightweight secure Multi-party Computation (MPC)-friendly robust aggregation method through quantization, median, and Hamming distance, which could resist poisoning attacks against up to <50% malicious clients. Besides, we propose communication-efficient Shamir's secret sharing-based MPC protocols to protect data privacy with high model accuracy. Second, we utilize blockchain off-chain state channels to achieve immutable model records and incentive distribution. FLock achieves cost-effective compatibility with practical cryptocurrency platforms, e.g. Ethereum, along with fair incentives, by merging the secure aggregation into a multi-party state channel. In addition, a pipelined Byzantine Fault-Tolerant (BFT) consensus is integrated where each aggregator can reconstruct the final aggregated results. Lastly, we implement FLock and the evaluation results demonstrate that FLock enhances robustness and privacy, while maintaining efficiency and high model accuracy. Even with 25 aggregators and 100 clients, FLock can complete one secure aggregation for ResNet in 2 minutes over a WAN. FLock successfully implements secure aggregation with such a large number of aggregators, thereby enhancing the fault tolerance of the aggregation.
Ye Dong, Yizhong Liu, Tingyu Fan, Dawei Li 0009, Zhenyu Guan 0002, Jianwei Liu 0001, Jianying Zhou 0001
WWW7
2025 Self-evolving detection of uncovered protocol attacks in 5GA and 6G NTNs
Tianbin Dang, Shuzheng Liu, Yangliu Hu, Jianwei Liu 0001
Sci. China Inf. Sci.7
2025 A Verifiable and Efficient Multi-Keyword Fuzzy Rank Search Scheme Over Encrypted Data With Privacy-Preserving
abstract
ABSTRACT Searchable Encryption (SE) enables searching over encrypted data. Exact keyword search is supported in most SE schemes, which achieve higher search accuracy but suffer from lower completeness due to the inability to handle similar expressions. To realize fuzzy keyword search, some schemes employ Bloom Filters (BFs), but these may incur high false positive rates and risk exposing the Bloom Filter's internal values to cloud servers (CS). Besides, most existing schemes ignore the fact that CS may engage in malicious behaviors (e.g., undercounting parameters or forging results). To address these issues, we propose an efficient and verifiable ranked fuzzy multi‐keyword search scheme based on BFs. We propose a Twin Bloom Filter (TBF) to conceal insertion positions and introduce random numbers to obfuscate uninserted bits. Search results are ranked using Term Frequency‐Inverse Document Frequency (TF‐IDF) scores to improve relevance. To ensure correctness and integrity, we employ Real Homomorphic Message Authentication Codes (RealHomMAC) and a random challenge technique, respectively. Security analysis proves that our scheme remains secure under both the known‐ciphertext model and the known‐background model. Theoretical and experimental performance analysis confirms that our scheme achieves efficient and accurate keyword search.
Fengyi Gao, Na Wang 0003, Jianwei Liu 0001, Zhiquan Liu 0001, Junsong Fu 0001, Lunzhi Deng
Concurr. Comput. Pract. Exp.3
2025 Efficient inner product arguments with sublogarithmic proof and sub-square-root verifier
abstract
Abstract Inner product arguments are core building blocks of numerous cryptographic primitives and therefore minimizing their complexity is a central goal in this research area. In this paper, we follow the work of Kim et al. (ASIACRYPT’22) and propose the first inner product argument having sublogarithmic communication complexity and sub-square-root verifier complexity simultaneously. We first devise a new subvector combination method for recursion and utilize an aggregated multi-exponentiation argument to prove some committed group elements are valid. We then modify the commitment keys in inner product arguments to be structured and reduce the verifier complexity by delegating the costly computations to the prover. Compared with the state-of-the-art inner product arguments, our protocol is highly competitive in terms of asymptotic complexity.
Zibo Zhou, Zongyang Zhang, Jianwei Liu 0001, Haifeng Qian
Cybersecur.3
2025 RCEAE: A Role Correlation-enhanced Model for Event Argument Extraction
Yiming Hei, Jiawei Sheng, Qian Li 0033, Jianwei Liu 0001, Yizhong Liu, Prayag Tiwari
Neurocomputing6
2025 An Efficient and Privacy-Preserving Range Retrieval Scheme for Location-Based Services
abstract
With the rapid development of positioning technology and mobile devices, location-based services (LBS) have witnessed extensive adoption. However, privacy leakage issues have become increasingly severe. Existing solutions often focus solely on protecting users’ location privacy while neglecting query privacy requirements, and further exhibit suboptimal retrieval efficiency when handling large-scale datasets. To comprehensively preserve user and server privacy while enhancing data retrieval efficiency, this paper proposes an efficient and privacy-preserving range retrieval scheme for location-based services (EPRL). The scheme proposes a Geohash-based query range generation algorithm, enabling users to generate query ranges according to their privacy requirements dynamically. To protect the user’s location privacy and query privacy, EPRL employs a ring signature policy. Furthermore, we innovatively design a Geohash-Trie Tree structure to store server data resources, effectively improving retrieval efficiency. Theoretical analysis and extensive experiments indicate that compared with other state-of-the-art LBS retrieval schemes, EPRL exhibits broader applicability, lower computational costs, and higher efficiency. When the number of ring signature users reaches 1,000, the total computational overhead of the scheme is approximately 5 seconds, merely one-fifth of that required by similar schemes.
Haojia Qi, Guobiao He, Na Wang 0003, Jianwei Liu 0001, Junsong Fu 0001, Zhiquan Liu 0001
IEEE Internet Things J.4
2025 Quantum-Resistant Sharding Blockchain and Its Application in Secure Data Transmission
abstract
With the approach of the quantum era, public key cryptography (PKC) faces risks, which also presents challenges to blockchain technologies that utilize PKC as a core component. Sharding blockchain is a promising way to realize scalability, yet current research does not consider quantum-resistant sharding blockchains as it is non-trivial to design cross-shard communication and transaction processing method without PKC. Besides, blockchain enables reliability in data transmission and unbreakable communication while current schemes suffer from high overhead and low throughput. In this paper, we propose a quantum-resistant sharding blockchain (QRShar) and a secure data transmission scheme (QRDT) to fill the above gap. Firstly, we design a secure and efficient cross-shard communication pattern utilizing hash-based message authentication code (HMAC) and erasure code to reduce the transmission load and achieve high efficiency. Secondly, we propose the a quantum-resistant sharding blockchain utilizing optimized cross-shard transaction processing method to decrease the consensus execution frequency. Thirdly, we introduce a quantum-resistant key agreement protocol through the verifiable secret sharing on cryptographic hash function and we also offer a data transmission scheme to realize efficient QRDT. Furthermore, we conduct security analysis and performance evaluations for our schemes. The results show that the QRShar throughput can reach up to 34 KTPS and the latency stays below 2 seconds. The key agreement latency is just 43ms.
Yizhong Liu, Xun Lin, Zhenyu Guan 0002, Dawei Li 0009, Jianwei Liu 0001, Qianhong Wu, Willy Susilo, Robert H. Deng
IEEE J. Sel. Areas Commun.6
2025 Privacy-preserving Multiple Sequence Alignment Scheme for Long Gene Sequence
abstract
Gene Multiple Sequence Alignment is crucial for genomic data analysis, forming the basis for studying its biological significance. The digitization of genomic data allows collaborative analysis on cloud platforms, improving the efficiency and precision of genomic research. However, gene sequences contain sensitive information, posing a risk of privacy leakage with unauthorized access. Balancing privacy, accuracy, and efficiency in multiple sequence alignment for long gene sequences remains a challenge. In this paper, we propose a distributed privacy-preserving multiple sequence alignment scheme for long sequences based on secure multi-party computation. Our scheme includes a method for segmenting long sequences to achieve partially distributed computing and a privacy-preserving method for calculating edit distance among subsequences using secret sharing. The scheme consists of a distributed computing phase and an aggregate computing phase, optimizing efficiency by dropping repeated subsequences alignment. Our proposed scheme achieves accurate and efficient privacy-preserving alignment for long gene sequences.
Yatong Jiang, Tao Shang 0002, Jianwei Liu 0001
Proc. Priv. Enhancing Technol.3
2025 Efficient dynamic-committee BFT consensus based on HotStuff
Zongyang Zhang, Bin Hu 0001, Jianwei Liu 0001
Peer Peer Netw. Appl.5
2025 LOGO-Based Intellectual Property Right Protection Scheme for GANs on FPGA
abstract
In recent years, Generative Adversarial Networks (GANs) have become essential tools in artificial intelligence research. Field Programmable Gate Arrays (FPGAs) offer remarkable flexibility, high performance, and energy efficiency for deploying GANs. However, the open and reprogrammable architecture of FPGAs, despite its advantages, introduces risks of unauthorized access and reverse engineering. To address this challenge, this paper presents a novel approach integrating Physical Unclonable Functions (PUFs) and logos to protect the Intellectual Property Rights (IPR) of GANs. Our method establishes a closed-loop conversion process where logos are transformed into PUF responses, generating unique identities fed into the GAN to reproduce the original logo. By embedding PUF response information into latent vectors, the generator produces images with embedded logos. Thanks to the uniqueness of PUF, a robust binding of the logo, FPGA, and GANs' IPR is implemented, allowing verification of the IPR with the assistance of a unique FPGA fingerprint, even when a publicly available logo is used. Experimental results show that embedding the logo does not change the performance of the original GANs, and the logo detection rate exceeds 90%. At the same time, the scheme can effectively resist brute force, fine-tuning and pruning attacks.
Dawei Li 0009, Yangkun Ren, Di Liu 0019, Song Bian 0001, Zhenyu Guan 0002, Willy Susilo, Jianwei Liu 0001, Qianhong Wu
IEEE Trans. Dependable Secur. Comput.7
2025 Dissecting Blockchain Network Partitioning Attacks and Novel Defense for Bitcoin and Ethereum
abstract
Cryptocurrencies and permissionless blockchains allow nodes from all over the world to join, and their rapid development has created enormous blockchain networks with nodes spanning the globe. Blockchain network partitioning attacks split the network into separate node groups through disrupting communication, causing information inconsistency, and facilitating malicious behaviors like double-spending and selfish mining, threatening the blockchain security. Existing research primarily studies concrete partitioning attack methods. However, it is hard to analyze practical post-attack security and efficiency impacts on blockchains and design effective countermeasures. This paper studies practical network partitioning attacks’ impacts on existing proof-of-work-based (Bitcoin) and proof-of-stake-based (Ethereum) permissionless blockchains. We theoretically analyze and experimentally confirm the adverse effects of network partitioning on blockchain performance and security. Network partitioning will cause blockchain throughput to plummet, and cause block generation delay to increase rapidly. In our experiments on Ethereum 2.0, when the bandwidth between the partitioned networks is lower than 768 Kbps, the throughput begins to plummet precipitously until it ultimately falls to 0. What’s worse, network partitioning will significantly increase the success rate of double-spending. In our experiments on Bitcoin, when the bandwidth between the partitioned networks is less than 256 Kbps, the success rate of double-spending reaches 50%. To solve the above issues, we propose countermeasures leveraging a freezing threshold to safeguard the security of permissionless blockchains and resist double-spending attacks. We experimentally validate that the countermeasures enhance the resistance of permissionless blockchains to network partitioning attacks. It reduces the probability of double-spending in partitioned networks, thereby ensuring security and reliability.
Dawei Li 0009, Yizhong Liu, Jianwei Liu 0001, Zhenyu Guan 0002, Qianhong Wu, Jianying Zhou 0001, Willy Susilo
IEEE Trans. Inf. Forensics Secur.5
2025 Bitcoin-Compatible Privacy-Preserving Multi-Party Payment Channels Supporting Variable Amounts
abstract
Blockchain and cryptocurrencies are developing rapidly, and the scalability issue has become a constraint on their practical application and development. Off-chain payment channel is an effective solution to the scalability problem of blockchain. Currently, various payment channel protocols have been proposed. However, privacy issues are vital in payment channels. Existing works that consider privacy issues mainly focus on payment channel networks and payment channel hubs, while there is little work on two-party and multi-party channels. In addition, many existing payment channel works that consider privacy protection fix the transaction amounts to ensure the hiding of payment relationships or rely on smart contracts, which will hinder the practical application of payment channels. In this work, we propose a two-party privacy-preserving payment channel protocol that is compatible with Bitcoin (TBPChannel), achieving value privacy and unlinkability, while supporting variable transaction amounts. On this basis, we propose a privacy-preserving multi-party payment channel protocol (MBPChannel), which removes the role of untrusted operators in previous multi-party settings and further achieves robustness. We formally model the protocols in the universal composability framework and prove the security. Finally, we implement the protocols and provide a performance evaluation. The results demonstrate the scalability and practicality of our protocols. Compared to current protocols, even though we use privacy-preserving methods, our protocols are still efficient and applicable in practice.
Dawei Li 0009, Yizhong Liu, Jianwei Liu 0001, Qianhong Wu, Jianying Zhou 0001, Willy Susilo
IEEE Trans. Inf. Forensics Secur.5
2025 Enhancing the Security of One-Tap Authentication Services via Dynamic Application Identification
abstract
The One-Tap Authentication (OTAuth) service enables users to quickly log in or sign up for app accounts using their phone number. OTAuth provides a more secure and convenient alternative to password-based and Short Message Service (SMS)-based authentication schemes. Consequently, the OTAuth service has been adopted by numerous Mobile Network Operators (MNOs) worldwide. However, a high severity vulnerability remains unaddressed in the OTAuth service, which allows an attacker to access a victim’s various app accounts, posing a significant risk to user privacy and data security. In this paper, we present LoadShow, which, to the best of our knowledge, is the first security-enhanced OTAuth scheme to address this vulnerability. We propose a novel dynamic application identification technique that aims to address the root cause of this vulnerability, i.e., the inability of MNOs to distinguish between different applications on the same device. Specifically, application identification is based on the hardware load side-channel and captures the unique CPU and GPU load characteristics of applications through the sequence of timing values of fingerprinting functions. We evaluate the effectiveness of LoadShow by accuracy, False Positive Rate (FPR), and True Positive Rate (TPR). We also evaluate its multi-platform compatibility on devices with different architectures and models. LoadShow achieves over 90% accuracy, with a TPR exceeding 90% and an FPR below 1%. The evaluation results demonstrate LoadShow’s capability to effectively differentiate between applications on a device, defend against app impersonation attacks, and reliably identify legitimate applications.
Di Liu 0019, Dawei Li 0009, Ruinan Hu, Jianwei Liu 0001, Song Bian 0001, Xuhua Ding, Yizhong Liu, Zhenyu Guan 0002
IEEE Trans. Inf. Forensics Secur.6
2025 An Efficient and Secure Spatial Keyword Ciphertext Retrieval Scheme Based on Cloud-Fog Collaboration
abstract
Location-Based Services are increasingly common in our lives. In order to reduce user overhead, the data owner stores the location information and text data on the cloud server, and the user completes the retrieval task with the help of the fog server. To protect the privacy of outsourced data, many secure spatial keyword retrieval schemes have been proposed. Most schemes use R-tree indexes to improve the efficiency of ciphertext retrieval, but the encrypted R-tree index is hard to update. Moreover, some indexes based on order-preserving encryption are vulnerable to frequency-revealing attacks. So how to balance efficiency and security is a problem. To solve the above problems, we propose an efficient and secure spatial keyword ciphertext retrieval scheme based on cloud-fog collaboration. First, we innovatively design the SK-tree. The Geohash algorithm and Simhash algorithm are used in SK-tree to compress information, achieving efficient retrieval. Secondly, our retrieval tree has the function of fuzzy order preservation, which can better hide the correspondence between plaintext and ciphertext compared to traditional index-based order-preserving encryption schemes. In addition, we design a cloud-fog-user interaction scheme for attribute-based encryption that can hide access control policies, which reduces the computational overhead for the user side. Finally, we prove through theoretical analysis that our scheme ensures cloud data security and query trap information privacy. We compare our scheme with others through simulation experiments to demonstrate its superiority in efficiency.
Na Wang 0003, Junsong Fu 0001, Lunzhi Deng, Jianwei Liu 0001
IEEE Trans. Inf. Forensics Secur.5
2025 GIIE: A Graph-based News Recommendation Model with Intrinsic Interest Enhancement
abstract
News recommendation aims to offer potentially interesting news items to a specific user, guided by his historical browsing behaviors. Existing methods failed to effectively address the knowledge sparsity issue that the user may have sparse behaviors and the news may own sparse features. To address the problem, we propose a graph-based news recommendation model with intrinsic interest enhancement, named GIIE , leveraging intrinsic interests and neighbor information to enhance the representation of sparse users and news. Concretely, to fully take advantage of the intrinsic interests, we design an interest encoder based on an interest-type graph with a learnable structure and explore the interest embeddings from news types. Then, we inject the obtained interest embeddings into news and represent the user by aggregating the clicked news under the same interest and across different interests sequentially. These interests can build a bridge between users so users with sparse behaviors can implicitly share knowledge with other users, thereby enhancing their representation. To properly introduce the neighbor knowledge, we propose a graph-based neighbor enhancing mechanism. First, we design a news relation graph and a user relation graph in encoders. Then, based on these graphs, we take the attention module to aggregate additional knowledge from neighbors, enhancing sparse news and user representations. To avoid feature ambiguity, we adopt a way to represent the current item (user and news) and its neighbors separately and then do adaptive aggregation. We evaluate GIIE on the public news recommendation datasets MIND-Large and MIND-Small. Experimental results show that our model can solve the knowledge-sparse problem and outperforms current state-of-the-art models in four indicators.
Yiming Hei, Jianwei Liu 0001, Zhengtao Yu 0001
Trans. Recomm. Syst.2
2025 A Privacy-Preserving IoT Data Access Control Scheme for Cloud-Edge Computing
abstract
In Internet of Things(IoT), the combination of cloud computing and edge computing becomes a new computing paradigm to provide users with low-latency data services. However, for the limited resource, high dynamic, and wide distributed characteristics of IoT devices, it becomes a great challenge to realize the universal application of edge servers and the cloud-edge computing allocation. Meanwhile, most of the schemes ignore the leakage of data access pattern privacy when accessing data. Therefore, in this paper, we propose a privacy-preserving access control scheme for IoT data. Based on the cloud-edge-end framework, we design a pervasive edge computing protocol, which allows well-resourced devices to become edge servers at suitable geographic locations and users to outsource and access IoT data through the nearest edge server. It increases the flexibility of the cloud-edge collaborative system as well as the efficiency of data processing. Users do not need to interact beyond the network edge to enjoy the data services. Furthermore, a novel attribute-based encryption scheme is designed based on a modified Lightweight Secret Sharing Scheme to optimize computing task allocation and reduce the computation burden on end devices, without attribute information leakage. In addition, we also design a Transform algorithm and a Cloud-edge Interaction protocol to hide access pattern privacy efficiently. We analyze the feasibility of the scheme and demonstrate that the scheme is semantically secure and conceals access pattern privacy. Simulation experiments based on real IoT data show that the scheme is efficient and suitable for IoT scenarios.
Jingjing Wang 0001, Na Wang 0003, Wen Zhou 0021, Jianwei Liu 0001, Junsong Fu 0001, Lunzhi Deng
IEEE Trans. Parallel Distributed Syst.4
2025 A Lightweight and Fine-Grained Ciphertext Search Scheme for Big Data Assisted by Proxy Servers
abstract
In big data scenarios, the data volume is enormous. Data computation and storage in distributed manner with more efficient algorithms is promising. However, most current ciphertext search schemes are designed for the centralized cloud computing platforms and they are inefficient and inapplicable in big data scenarios. A proxy server based system is a cloud computing extension. This new pattern moves some of the data storage and computation burden from end users to the edge servers and it greatly decrease the resource costs of data users. In this paper, we propose a searchable encryption scheme assisted by cloud computing and proxy servers for big data, which can accomplish Lightweight Fine-grained access control and Efficient multi-keyword top-k ciphertext Search synchronously (LFES). To cope with all types of data, we design an innovative fine-grained access control mechanism based on attribute-based encryption and key distribution protocol. Thus, the scheme only allows users with licensed attributes to access data efficiently. Then, a public key searchable encryption scheme is proposed based on privacy Protection Set Intersection (PSI) and the proxy server model. Our scheme greatly reduces the computation burden on end-users and improves retrieval efficiency. Meanwhile, to prevent tampering with stored ciphertexts, a practical data integrity audit mechanism is also designed. Security analysis illustrates that the LFES can resist Chosen Keyword Attack (CKA) and Keyword Guessing Attack (KGA). Finally, the simulation shows that the LFES is efficient and feasible in practice.
Na Wang 0003, Kaifa Zheng, Wen Zhou 0021, Jianwei Liu 0001, Lunzhi Deng, Junsong Fu 0001
IEEE Trans. Parallel Distributed Syst.4
2024 GroupCover: A Secure, Efficient and Scalable Inference Framework for On-device Model Protection based on TEEs
abstract
Due to the high cost of training DNN models, how to protect the intellectual property of DNN models, especially when the models are deployed to users’ devices, is becoming an important topic. One practical solution is to use Trusted Execution Environments (TEEs) and researchers have proposed various model obfuscation solutions to make full use of the high-security guarantee of TEEs and the high performance of collocated GPUs. In this paper, we first identify a common vulnerability, namely the fragility of randomness, that is shared by existing TEE-based model obfuscation solutions. This vulnerability benefits model-stealing attacks and allows the adversary to recover about 97% of the secret model. To improve the security of TEE-shielded DNN models, we further propose a new model obfuscation approach GroupCover, which uses sufficient randomization and mutual covering obfuscation to protect model weights. Experimental results demonstrate that GroupCover can achieve a comparable security level as the upper-bound (black-box protection), which is remarkably over 3x compared with existing solutions. Besides, GroupCover introduces 19% overhead and negligible accuracy loss compared to model unprotected scheme.
Na Wang 0003, Jianwei Liu 0001
ICML6
2024 HEIR: A Unified Representation for Cross-Scheme Compilation of Fully Homomorphic Computation
Song Bian 0001, Zian Zhao, Zhou Zhang 0016, Ran Mao, Kohei Suenaga, Yier Jin, Zhenyu Guan 0002, Jianwei Liu 0001
NDSS8
2024 HWMP-based secure communication of multi-agent systems
Shanyao Ren, Jianwei Liu 0001, Shuzhi Sam Ge, Dongyu Li
Ad Hoc Networks2
2024 The blockchain-based privacy-preserving searchable attribute-based encryption scheme for federated learning model in IoMT
abstract
Abstract Federated learning enables training healthcare diagnostic models across multiple decentralized devices containing local private health data samples, without transferring data to a central server, providing privacy‐preserving services for healthcare professionals. However, for a model of a specific field, some medical data from non‐target participants may be included in model training, compromising model accuracy. Moreover, diagnostic queries for healthcare models stored in cloud servers may result in the leakage of the privacy of healthcare participants and the parameters of models. Furthermore, the records of model searching and usage could be tracked causing privacy disclosure risk. To address these issues, we propose a blockchain‐based privacy‐preserving searchable attribute‐based encryption scheme for the diagnostic model federated learning in the Internet of Medical Things (BSAEM‐FL). We first adopt fine‐grained model trainer participation policies for federated learning, using the attribute‐based encryption (ABE) mechanism, to realize model accuracy and local data privacy. Then, We employ searchable encryption technology for model training and usage to protect the security of models stored in the cloud server. Blockchain is utilized to implement distributed healthcare models' keyword‐based search and model users' attribute‐based authentication. Lastly, we transfer most of the computational overhead of user terminals in model searching and decryption to edge nodes, achieving lightweight computation of IoMT terminals. The security analysis proves the security of the proposed healthcare scheme. The performance evaluation indicates our scheme is of better feasibility, efficiency, and decentralization.
Ziyu Zhou 0002, Na Wang 0003, Jianwei Liu 0001, Junsong Fu 0001, Lunzhi Deng
Concurr. Comput. Pract. Exp.3
2024 An Enhanced Multifactor Authentication and Key Agreement Protocol in Industrial Internet of Things
abstract
The Industrial Internet of Things (IIoT) is the application of the Internet of Things (IoT) in the industrial field. IIoT allows users to remotely access industrial equipment and the data in it, which also brings certain challenges to the security of industrial data. Authentication and key agreement protocols are very effective security technologies in the matter of protecting industrial data. There is a large amount of research work on authentication protocols in IIoT, but most of the protocols have security weaknesses. Recently, Rafique et al. proposed a multi-factor protocol in IIoT that can accomplish authentication and session key establishment through a gateway. Rafique et al. claimed that their protocol is secure, unfortunately, we carefully analyze the protocol of Rafique et al. and find some security flaws, i.e., it is vulnerable to insider attack and known session-specific temporary information (KSSTI) attack, and unable to provide forward security. We explore the factors of insecurity and propose an enhanced multi-factor secure authentication and key agreement protocol in IIoT. The new protocol improves the security of the protocol while using only symmetric cryptography, hash function, and XOR operation. Formal security analysis and informal security discussions demonstrate that the new protocol is resistant to a variety of known attacks. After performance analysis, our protocol has lower computational cost, and increases no significant communication cost, while providing more secure and robust properties.
Yiran Han, Hua Guo 0001, Jianwei Liu 0001, Brou Bernard Ehui, Yapeng Wu
IEEE Internet Things J.3
2024 SS-DID: A Secure and Scalable Web3 Decentralized Identity Utilizing Multilayer Sharding Blockchain
abstract
Web3 is a revolutionary Internet paradigm that focusing decentralization, user empowerment, and intelligence. One of its key technologies is decentralized identity (DID), which has gained significant attention recently. However, existing DID solutions are not scalable enough to be compatible with the large-scale identity node applications required by Web3 across various fields. To overcome this challenge, we propose the first multi-layer Web3 DID architecture utilizing sharding blockchain, which provides management, scalability, and compatibility. This architecture leverages leader shards and the main chain to establish trust, while regular shards manage DID-related transactions. Specific system processes and query optimizations are also given. Besides, formal security analysis and comprehensive simulation evaluations have demonstrated that the architecture can achieve all proposed security and performance goals, including low latency of down to 2 seconds and high throughput of up to 90KTPS.
Yizhong Liu, Zedan Zhao, Jianwei Liu 0001, Xun Lin, Qianhong Wu, Willy Susilo
IEEE Internet Things J.4
2024 SmartTracer: Anomaly-Driven Provenance Analysis Based on Device Correlation in Smart Home Systems
abstract
As a typical application of the Internet of Things (IoT), smart home systems facilitate home setup where appliances and devices can be controlled automatically and remotely from anywhere with an Internet connection. Devices within a smart home system are usually correlated according to the automation rules/programs preconfigured by system owners. However, attackers can exploit these complex correlations among devices to conduct indirect attacks, making it challenging for owners to locate the root cause of a security incident and identify compromised devices. In this article, we propose SmartTracer, an anomaly-driven provenance analysis approach based on interdevice correlation extraction and tracing. Specifically, we extract correlations from the smart home system’s automation setup and physical interaction configuration. We define a unified dependency graph to describe the event causality among devices based on the event correlation and device run-time states. We then present an identification algorithm to profile trigger-action sequences from the abnormal run-time dependency graph and identify root cause nodes of anomalies. We prototype our approach and evaluate it on a self-developed testbed. The experiment results show that SmartTracer effectively provides a complete and precise provenance analysis for attacks exploited by the execution chains of automation. SmartTracer can generate a dependency graph for around 100 automation rules in 0.03 s and identify anomalies within 0.14 s.
Qixiao Lin, Shishi Zhu, Liran Ma, Jianwei Liu 0001
IEEE Internet Things J.5
2024 Provable Secure Anonymous Device Authentication Protocol in IoT Environment
abstract
The inherent massive heterogeneous devices and open channels in the Internet of Things (IoT) present significant challenges for identity authentication between devices and cloud servers. For this issue, reliable protocols ensure the legality of participants and act as a crucial method to provide security for authentication. In previous research, schemes devised by researchers exhibit certain security vulnerabilities, making it challenging to withstand comprehensive network attacks, e.g., stolen device attacks, replay attacks, impersonation, etc. Additionally, some protocols have complex interaction processes, which incur significant computational redundancy and resource loss. Motivated by this, this article proposes an anonymous and certificateless lightweight authentication protocol (ACLAP) for device-to-server and device-to-device based on elliptic curve cryptography. It improves the communication quality between devices and cloud servers and solves the security risks in authentication. In the scheme, we utilize device users’ passwords and biometric features as verification credentials without storing any trusted proofs on the cloud server. We address the issue of resource consumption caused by numerous devices in the IoT environment. From formal security analysis and comparisons with other works, our protocol has preferable security performance and effectively saves communication resources for authentication. Simulation results demonstrate the feasibility and practical significance of the scheme.
Shanyao Ren, Yizhong Liu, Beiyuan Yu, Jianwei Liu 0001, Dongyu Li
IEEE Internet Things J.4
2024 Client-Side Gradient Inversion Attack in Federated Learning Using Secure Aggregation
abstract
As a privacy-preserving enhancement to the Federated Learning (FL) framework, Secure Aggregation (SA) enables multiparty summation without any party needing to reveal their updates to the aggregator in Internet of Things applications. However, conventional threat model underestimates the potential inversion attacks on aggregated gradients from an honest-but-curious client, due to the considering information loss caused by SA. This study for the first time, demonstrates the gradient inversion attack against SA schemes in which gradients are quantized and aggregated. Then an enhanced gradient inversion from client side is proposed to address two roadblocks caused by SA, i.e., aggregation information loss and quantization rounding error. To countermeasure the information loss, we utilize class-wise representation matching to achieve category-level decomposition. This relies on a prior restoration of the class-wise representations and instance-wise labels, whose numerical accuracy is cyclically calibrated through prior-based offset estimation. Since cryptographic operators involved in SA schemes usually operates in the integer domain, gradient quantization is introduced. Regarding the rounding errors from gradient quantization, quantization-aware gradient matching is presented to align with a more precise optimization objective. Extensive experiments demonstrate that a semi-honest client is sufficient to infer sensitive data from the aggregated gradients after even 8-bit quantization. Moreover, a defense scheme based on 1-bit gradient quantization is proposed. The new attack from client side in SA-based FL urges the community to take necessary defensive measures.
Yu Sun 0015, Kailang Ma, Jianwei Liu 0001
IEEE Internet Things J.6
2024 Blockchain-Based Trustworthy and Efficient Hierarchical Federated Learning for UAV-Enabled IoT Networks
abstract
Unmanned aerial vehicles (UAVs) empowered Internet of things (IoT) networks have emerged as a burgeoning paradigm in the era of 6G. However, due to substantial data volume and privacy concerns, the conventional UAV backhaul to cloud center framework is not applicable to various latency and privacy-sensitive applications. Therefore, we propose a blockchain-based hierarchical federated learning (FL) framework for UAV-enabled IoT networks. Specifically, we utilize the total data distance-aware device association to mitigate model impairment arising from imbalanced data distribution. Besides, we introduce a lightweight blockchain into FL to tackle the trust deficit caused in decentralized global model aggregation. Furthermore, we design an optimization framework that jointly orchestrating device association, wireless resource allocation, and UAV deployment, aiming at a balance between the learning latency and model accuracy. To address the formulated optimization problem, we proposed a two-stage algorithm that integrates both greedy strategy and soft actor-critic algorithm. Extensive experiments show that our proposed scheme outperforms contemporary relative to state-of-the-art alternatives.
Ziheng Tong, Jingjing Wang 0001, Xiangwang Hou, Jianrui Chen 0001, Zihan Jiao 0001, Jianwei Liu 0001
IEEE Internet Things J.6
2024 TaP2-CSS: A Trustworthy and Privacy-Preserving Cooperative Spectrum Sensing Solution Based on Blockchain
abstract
In cognitive radio networks, cooperative spectrum sensing (CSS) is a key approach to effectively discover spectrum opportunities for secondary users. However, due to the presence of malicious nodes, CSS faces significant challenges in the trust issue of sensing results caused by spectrum sensing data falsification and the privacy leakage of sensing nodes. In this article, we develop a trustworthy and privacy-preserving CSS solution based on blockchain, TaP2-CSS. It achieves the transparency and trustworthiness in exchanging and fusing sensing reports and preserves privacy of sensing nodes. More specifically, a fusion scheme is proposed to realize the high defense capability against the spectrum sensing falsification attack launched by lurking and persistent malicious nodes. Furthermore, to address privacy threats of sensing nodes, we propose a privacy-preserving sensing scheme based on dynamic sensing time for resource-constrained sensing nodes. It effectively limits the location information leaked by sensing reports without the need for complex cryptographic computation and protocol interaction. Comprehensive evaluation and comparison show that the proposed solution achieves high sensing accuracy in the presence of malicious nodes while preserving the privacy of sensing nodes.
Qianyun Zhang 0001, Weihao Zeng 0001, Zhijin Qin, Yun Lin 0005, Zhenyu Guan 0002, Jianwei Liu 0001
IEEE Internet Things J.6
2024 BFL-SA: Blockchain-based federated learning via enhanced secure aggregation
Yizhong Liu, Zixiao Jia, Zixu Jiang, Xun Lin, Jianwei Liu 0001, Qianhong Wu, Willy Susilo
J. Syst. Archit.5
2024 Decomposition and recombination. A soft cascade model for event detection
Yiming Hei, Jiawei Sheng, Qian Li 0033, Jianwei Liu 0001
Knowl. Based Syst.6
2024 A Lightweight Privacy-Preserving Ciphertext Retrieval Scheme Based on Edge Computing
abstract
With the rapid development of cloud computing and Internet of Things (IoT) technologies, large amounts of data collected from IoT devices are encrypted and outsourced to cloud servers for storage and sharing. However, traditional ciphertext retrieval schemes impose high computation and storage overhead on end users. Meanwhile, IoT devices with limited resources are difficult to adapt to large amounts of data computation and transmission, which leads to transmission delay and poor user experience. In this article, we propose a lightweight privacy-preserving ciphertext retrieval scheme based on edge computing (LPCR) by extending searchable encryption (SE) and ciphertext policy attribute-based encryption (CP-ABE) techniques. First, to avoid network delay and paralysis, we introduce edge servers into LPCR and design a collaboration mechanism between the user side and the edge servers. The user side only needs to accomplish lightweight computation and storage tasks, which greatly reduces their resource consumption. Second, we extend the basic ciphertext policy attribute-based keyword search (CP-ABKS) technique and design the Linear Secret Sharing Scheme (LSSS) access control algorithm with attribute values to hide access policies and attributes. In addition, to improve the retrieval accuracy, the document indexes and query trapdoors are set up by conjunctive keywords to help the cloud server locate exactly the data that the user wishes to query. Formal security analysis verifies that LPCR can achieve the security of chosen plaintext attack (CPA) and chosen keyword attack (CKA), and resist collusion attack. Simulation experiments prove that LPCR is lightweight and feasible.
Na Wang 0003, Wen Zhou 0021, Qingyun Han, Jianwei Liu 0001, Weilue Liao, Junsong Fu 0001
IEEE Trans. Cloud Comput.4
2024 CPAKA: Mutual Authentication and Key Agreement Scheme Based on Conditional PUF in Space-Air-Ground Integrated Network
abstract
The space-air-ground integrated network (SAGIN) has a stringent demand on the efficiency of authentication protocols deployed in the devices that have been launched into the air and space. In this paper, we define the concept of the security model of conditional physical unclonable function (CPUF) that guarantees the security of the protocol while allowing the use of PUFs that can be modeled. We then propose a CPUF-based authentication and key agreement (AKA) scheme, named CPAKA, that addresses the challenges of device key leakage and inefficient authentication in resource-asymmetric environments. The CPAKA scheme embeds PUFs in weak nodes and deploys prediction models corresponding to the PUFs in strong nodes, eliminating the need to store challenge-response pairs or perform complex calculations. We formally prove the protocol's security under the decisional uniqueness assumption of CPUF and the universal composability framework, and we analyze its secrecy and authentication properties using the Tamarin prover. We also implement an Arbiter PUF on the ZYNQ-7020 FPGA, verify its accuracy through experiments, and show that CPAKA is secure, efficient, and suitable for SAGIN. Our CPAKA scheme greatly reduces computing and storage costs while improving authentication efficiency compared to traditional schemes.
Dawei Li 0009, Di Liu 0019, Yangkun Ren, Yu Sun 0015, Zhenyu Guan 0002, Qianhong Wu, Jiankun Hu, Jianwei Liu 0001
IEEE Trans. Dependable Secur. Comput.8
2024 Secure and Efficient Similarity Retrieval in Cloud Computing Based on Homomorphic Encryption
abstract
With the rapid development of cloud computing, massive amounts of data are uploaded to cloud servers for storage. For privacy protection, sensitive data should be encrypted before outsourcing, and ciphertext retrieval technologies based on similarity come into being. In cloud computing with massive data, the efficiency and accuracy of retrieval are crucial. However, most of the current similarity retrieval schemes do not perform well in these two aspects. Therefore, we propose SESR scheme, a secure and efficient similarity retrieval scheme based on homomorphic encryption. Firstly, we use Hamming distance to calculate the similarity between the feature vector of the data and query vector from the data user. Secondly, the homomorphic encryption algorithm is used to encrypt data to protect data privacy. Furthermore, we creatively design a BK-KD tree structure that hierarchically implements similarity search and fine-grained access control, thereby speeding up the retrieval efficiency. In addition, we design a two-cloud-server cooperative retrieval model and a message authentication scheme, which ensure access pattern privacy security and the integrity of the transmitted data simultaneously. We also propose an improved SESR scheme. In this scheme, we use Simhash algorithm to generate feature vectors and query vectors, which reduces storage overhead. Finally, the security of SESR is formally proved and the simulation results show the efficiency and accuracy of the retrieval scheme.
Na Wang 0003, Wen Zhou 0021, Jingjing Wang 0001, Junsong Fu 0001, Jianwei Liu 0001
IEEE Trans. Inf. Forensics Secur.6
2024 A Security-Enhanced Authentication and Key Agreement Protocol in Smart Grid
abstract
With the enablement of Internet of Things technology, the electrical grid is currently undergoing a drastic revolution, which is known as smart grid. Since massive sensitive data and control commands transmitted via public channels, the smart grid is challenged by various cyber threats. Authenticated key agreement protocols in smart grid effectively ensure the confidentiality and authentication of communication through mutual authentication and establishing session keys. In this article, we review the existing elliptic curve cryptography (ECC)-based authentication and key agreement protocols in smart gird and perform a security analysis of Hu et al.’s protocol. We exhibit that the protocol fails to resist key compromise impersonation (KCI) attack and cannot provide untraceability. Furthermore, we propose a security-enhanced authentication and key agreement protocol based on ECC, which performs registration, authentication, and key agreement phases over public channels to enable mutual authentication and to establish session keys. The protocol is also proved to be security-enhanced by formal proof and informal analysis. The performance analysis results demonstrate that the proposed protocol is comparable to other existing protocols while achieving enhanced security. Therefore, the protocol satisfies the deployment requirements for resource-constrained smart grid.
Yapeng Wu, Hua Guo 0001, Yiran Han, Jianwei Liu 0001
IEEE Trans. Ind. Informatics5
2024 Hawk: Rapid Android Malware Detection Through Heterogeneous Graph Attention Networks
abstract
Android is undergoing unprecedented malicious threats daily, but the existing methods for malware detection often fail to cope with evolving camouflage in malware. To address this issue, we present Hawk, a new malware detection framework for evolutionary Android applications. We model Android entities and behavioral relationships as a heterogeneous information network (HIN), exploiting its rich semantic meta-structures for specifying implicit higher order relationships. An incremental learning model is created to handle the applications that manifest dynamically, without the need for reconstructing the whole HIN and the subsequent embedding model. The model can pinpoint rapidly the proximity between a new application and existing in-sample applications and aggregate their numerical embeddings under various semantics. Our experiments examine more than 80 860 malicious and 100 375 benign applications developed over a period of seven years, showing that Hawk achieves the highest detection accuracy against baselines and takes only 3.5 ms on average to detect an out-of-sample application, with the accelerated training time of 50× faster than the existing approach.
Yiming Hei, Renyu Yang, Hao Peng 0001, Jianwei Liu 0001, Hong Liu 0006, Jie Xu 0007, Lichao Sun 0001
IEEE Trans. Neural Networks Learn. Syst.6
2024 UAV-Assisted Covert Federated Learning Over mmWave Massive MIMO
abstract
Unmanned aerial vehicles (UAVs) associated with federated learning (FL) have been deemed as a prospective framework by utilizing private data generated in the edge devices. However, despite various privacy-preserving and cryptography technologies adopted at the data level, FL still faces a range of security threats to raw data considering the broadcast nature of wireless channel. In this paper, to facilitate the communication-efficiency and privacy-preservation capability, we propose a UAV-enhanced covert federated learning architecture over mmWave massive multiple input multiple output (MIMO) channel, where we harness the covert communication technique in FL in order to avoid eavesdropping of illegal wardens. To achieve a trade-off between the security performance and training cost, we formulate a joint optimization problem involving the UAV’s trajectory, transmitting power, analog beamforming, and the required accuracy of FL. Furthermore, we propose the multi-agent deep deterministic policy gradient (MADDPG) algorithm to solve the above-mentioned problem. Numerous simulations have been performed to demonstrate both the effectiveness and convergence of the proposed algorithm.
Ziheng Tong, Jingjing Wang 0001, Xiangwang Hou, Chunxiao Jiang, Jianwei Liu 0001
IEEE Trans. Wirel. Commun.5
2023 Instance-wise Batch Label Restoration via Gradients in Federated Learning
Kailang Ma, Yu Sun 0015, Dawei Li 0009, Zhenyu Guan 0002, Jianwei Liu 0001
ICLR6
2023 FPHammer: A Device Identification Framework based on DRAM Fingerprinting
abstract
The device fingerprinting technique extracts fingerprints based on the hardware characteristics of the device to identify the device. The primary goal of device fingerprinting is to accurately and uniquely identify a device, which requires the generated device fingerprints to have good stability to achieve long-term tracking of the target device. However, the fingerprints generated by some existing fingerprinting technologies are not stable enough or change frequently, making it impossible to track the target device for a long time. In this paper, we present FPHammer, a novel DRAM-based fingerprinting technique. The device fingerprint generated by our technique has high stability and can be used to track the device for a long time. We leverage the Rowhammer technique to repeatedly and quickly access a row in DRAM to get bit flips in its adjacent row. We then construct a physical fingerprint of the device based on the locations of the collected bit flips. The evaluation results of the uniqueness and reliability of the physical fingerprint show that it can be used to distinguish devices with the same hardware and software configuration. The experimental results on device identification demonstrate that the physical fingerprints engendered by our innovative technique are inherently linked to the entirety of the device rather than just the DRAM module. Even if the device modifies software-level parameters such as MAC address and IP address or even reinstalls the operating system, we can accurately identify the target device. This demonstrates that FPHammer can generate stable fingerprints that are not affected by software layer parameters.
Dawei Li 0009, Di Liu 0019, Yangkun Ren, Yu Sun 0015, Zhenyu Guan 0002, Qianhong Wu, Jianwei Liu 0001
TrustCom8
2023 A novel two-factor multi-gateway authentication protocol for WSNs
Chen Chen 0094, Hua Guo 0001, Yapeng Wu, Jianwei Liu 0001
Ad Hoc Networks5
2023 Anti-Jamming Strategy for Satellite Internet of Things: Beam Switching and Optimization
abstract
Recently, the satellite network is emerged to guarantee the demand of seamless connectivity of Internet of Things (IoT) devices, which can provide services for IoT devices at anytime and anywhere. However, the satellite suffers from jamming attack due to its highly exposed satellite-ground links and spot-beams, which may cause severe security problems. In order to combat the jamming attack, we first analyze the performance of Satellite IoT (SIoT) in terms of the transmission rate. Then, we propose an anti-jamming strategy for SIoT by using the technique of beam switching, where a suitable satellite that offers sufficient spatial diversity can be chosen to swap the coverage with the attacked satellite. To this end, the coverage relationship between satellites and ground cells is investigated using the game theory and the satellite beam angle is further optimized to maximize the sum transmission rate of satellite clusters. Simulation results show that the proposed strategy can provide high achievable transmission rate for SIoT networks when jamming attacks happen.
Rui Han 0002, Meiqi Liu, Jiaxing Wang 0004, Lin Bai 0001, Jianwei Liu 0001
IEEE Internet Things J.5
2023 Decentralized IoT Resource Monitoring and Scheduling Framework Based on Blockchain
abstract
With the continuous advancement of edge intelligence, edge servers undertake more and more intelligent computing tasks. Nowadays, there are a large number of IoT devices in the network in idle state. For instance, the mining process for consensus of miners in blockchain such as Bitcoin causes a waste of computing resources and energy. A natural question arises: can we couple the idle computing resources of network devices to continuously and credibly share the burden of edge intelligent computing tasks in a secure manner? The answer of this paper is yes. We propose a blockchain-based IoT resource monitoring and scheduling framework that supports resource management and trusted edge computing. We analyze the security threats in all phases of distributed edge computing, and utilize the trusted computing and public verifiability features of blockchain to ensure reliability and fairness in the trusted measurement of device computing power, the decomposition of intelligent computing tasks, the matching of task and computing power, and the verification of computing result. Finally, we implement a simulation on the edge network by performing distributed machine learning task for weather prediction, and the simulation results demonstrate the availability of our scheme.
Dawei Li 0009, Qinjun Wan, Zhenyu Guan 0002, Yu Sun 0015, Qianhong Wu, Jiankun Hu, Jianwei Liu 0001
IEEE Internet Things J.8
2023 Privacy-Preserving Cross-Silo Federated Learning Atop Blockchain for IoT
abstract
Cross-silo federated learning (FL) is promising in facilitating data collaboration across various organizations, which greatly alleviates the information silo problem in industries and promotes the data intelligence of Internet of Things. With the advances of decentralized FL, the higher requirements of trust and privacy are put forward. Traditional FL heavily relies on a central coordinating server, which suffers from single points of failure and lacks trust in the correctness of aggregation results. What is more, the intrinsic privacy issues of FL have aroused public attention, such as gradient inversion attack in local gradients. However, the privacy of quantized gradients remains serious and lacks attention, especially the most extremely 1-bit quantization in sign-based FL. In this article, we demonstrate the potential privacy risk in sign-based FL by presenting a new gradient inversion attack, which successfully restores the original data from sign-based quantized gradients. And then we tackle the above two challenges via constructing a self-aggregation privacy-preserving FL atop blockchain, which takes advantage of a variant of ElGamal encryption to protect the privacy of local sign-based quantized gradients, and leverages the smart contract to achieve secure self-aggregation for participants without involving a centralized server. Moreover, we analyze that the proposed protocol achieves privacy and public verifiability. Finally, we evaluate the performance of the proposed protocol with a real deep learning model, and the results show that our protocol is resilient against gradient inversion attack in a decentralized environment without sacrificing learning accuracy.
Yu Sun 0015, Yong Yu 0002, Dawei Li 0009, Zhenyu Guan 0002, Jianwei Liu 0001
IEEE Internet Things J.6
2023 Multiuser Personalized Ciphertext Retrieval Scheme Based on Deep Learning
abstract
With the rapid development of cloud computing technology and Internet of Things (IoT), enterprises and organizations tend to outsource local data to cloud servers and use searchable encryption (SE) technology to access and search encrypted data. However, the existing symmetric SE (SSE) schemes pay less attention to multiuser environments and users’ interest, which cause poor experience to users. In this article, we propose a multiuser personalized ciphertext search scheme (MPCS) by extending deep learning technology and SSE technology, which can achieve personalized retrieval and multiuser retrieval at the same time. MPCS achieves secure transmission of document keys and fine-grained access control by combining matrix decomposition and ciphertext policy attribute-based encryption (CP-ABE) technology, which assigns different private keys to each authorized user in the system and allows setting different access rights for different users. Second, we build an interest model for different users and design a user query update algorithm based on the attention mechanism to provide personalized ranking results, which improves the retrieval experience of users. In addition, the computation overhead of MPCS is lightweight, the size of ciphertext and key will not increase linearly with the number of attribute values, and MPCS supports lightweight document updates, which greatly reduces the computation overhead of the system. Formal security analysis verifies the security of MPCS, and simulation experiments on real data sets show that MPCS is feasible and efficient in practice.
Na Wang 0003, Qingyun Han, Junsong Fu 0001, Jianwei Liu 0001
IEEE Internet Things J.4
2023 Defending against model extraction attacks with physical unclonable function
Dawei Li 0009, Di Liu 0019, Yangkun Ren, Jieyu Su, Jianwei Liu 0001
Inf. Sci.6
2023 Secure Counting Query Protocol for Genomic Data
Yatong Jiang, Tao Shang 0002, Jianwei Liu 0001
IEEE ACM Trans. Comput. Biol. Bioinform.3
2023 A Flexible Sharding Blockchain Protocol Based on Cross-Shard Byzantine Fault Tolerance
abstract
Sharding technology is crucial to achieve decentralization, scalability, and security simultaneously. However, existing sharding blockchain schemes suffer from high cross-shard transaction processing latency, low parallelism, incomplete cross-shard views of shard members, centralized reconfiguration, high overhead of randomness generation, and lack of formalized protocol design and security proofs. This paper proposes a flexible sharding (FS) blockchain protocol. First, a cross-shard Byzantine fault tolerance (CSBFT) protocol is designed to cut down confirmation delays when processing cross-shard transactions. Second, we utilize multiple parallel CSBFT where each node acts not only as a leader but also as multiple ordinary members to break through the performance bottleneck caused by a leader’s bandwidth and computing power, improving the system parallelism. Third, a cross-shard transaction censorship attack is proposed, and a cross-shard view-change mechanism is designed to defend against it. Fourth, a secure and truly decentralized shard reconfiguration method combining proof-of-work, proof-of-possession, and intra-shard BFT is designed. Fifth, we utilize a formal protocol design method and give strict security proof for each protocol. Finally, we evaluate FS from both theoretical and practical perspectives. FS is proven to have lower communication and computation complexity and achieve considerable performance.
Yizhong Liu, Xinxin Xing, Haosu Cheng, Dawei Li 0009, Zhenyu Guan 0002, Jianwei Liu 0001, Qianhong Wu
IEEE Trans. Inf. Forensics Secur.6
2023 Lightweight and Secure Data Transmission Scheme Against Malicious Nodes in Heterogeneous Wireless Sensor Networks
abstract
With the continuous development of sensor technology, more and more users hope to monitor and collect information in a certain area safely and efficiently by deploying heterogeneous wireless sensor networks (HWSNs). However, nodes in HWSNs have limited capabilities, which leads to many security challenges. Existing data transmission schemes in HWSNs take measures to resist these security threats, which aggravate the node computation overhead and increase the network energy consumption. This paper proposes a Lightweight and Secure Data Transmission (LSDT) scheme against malicious nodes in heterogeneous wireless sensor networks. Firstly, considering node capabilities limitations in HWSNs, we design a lightweight secret sharing scheme based on XOR operation, which maps data to multiple shares and makes it convenient to transmit shares separately to the sink node via multiple paths. While guaranteeing data security, this scheme can greatly reduce the computation overhead of nodes compared with traditional secret sharing schemes. Further, during the delivery of shares, the network may be attacked by malicious nodes, causing the interruption of message transmission. Therefore, we design a malicious node detection and feedback mechanism, which can quickly respond to malicious node attacks and update the reputation degree of malicious nodes. Finally, we propose a routing selection scheme based on reference path which comprehensively considers the energy and reputation degree of heterogeneous nodes. It makes message transmission bypass malicious nodes while achieving network energy load balance, significantly extending the network lifetime. The security analysis proves that our scheme guarantees the security of data transmission. Theoretical analysis and experiments show that our scheme has significant advantages over the existing HWSNs data transmission schemes in terms of network lifetime extension and malicious node resistance.
Na Wang 0003, Shancheng Zhang, Jiawen Qiao, Junsong Fu 0001, Jianwei Liu 0001, Bharat K. Bhargava
IEEE Trans. Inf. Forensics Secur.6
2023 Block-Based Privacy-Preserving Healthcare Data Ranked Retrieval in Encrypted Cloud File Systems
abstract
The Internet of Medical Things (IoMT) is an important application of the Internet of Things in health care. In IoMT, efficiency and user privacy are crucial for cloud storage and retrieval of healthcare data documents. Existing schemes, however, often suffer from inefficient retrieval and increased risk of privacy disclosure when dealing with massive data. We propose here a new Efficient Encrypted Parallel Ranking (EEPR) search system, block-based and privacy-preserved, for encrypted cloud healthcare data. We design a parallel binary search tree structure in block and propose a parallel retrieval algorithm adaptable to such a structure. A quantitative analysis through the information retention index shows that our scheme demonstrates better search performance. In addition, feature vectors generated from our scheme are difficult to be reversely analyzed due to unexplainability, enhancing privacy protection for patients and researchers. A formal security analysis shows that our EEPR scheme is resistable to known background attack, and yields a lower time complexity and significantly improves search efficiency as well as accuracy over existing schemes.
Na Wang 0003, Shancheng Zhang, Junsong Fu 0001, Jianwei Liu 0001, Ruijin Wang
IEEE J. Biomed. Health Informatics5
2023 Intelligent and Fair IoV Charging Service Based on Blockchain With Cross-Area Consensus
abstract
The emergence of electric vehicles promotes the development of Internet of Vehicle (IoV). However, there are a series of security problems to be solved in the IoV. Firstly, how to allow vehicle users to find the nearest non-queuing charging pile without detours is a challenge. Secondly, applications in the IoV are delay-sensitive, while high communication delays caused by security mechanisms would bring serious consequences to vehicles. Thirdly, the verifiability and fairness between charging and payment are difficult to be guaranteed. Aiming at the efficiency and security problems of the charging service in the IoV, this paper proposes a blockchain-based intelligent and fair IoV charging service system. According to the multi-factor constraints between vehicles and charging piles, a multi-factor IoV branch and bound algorithm is proposed to intelligently recommend charging piles for vehicles and maximize the overall energy saving. We propose the cross-area consensus protocol to achieve low latency in vehicle communication. In addition, we ensure the fairness between charging and payment through a payment channel protocol based on verifiable encrypted signatures. Finally, we implement the proposed scheme, and we put the project prototype on an open source platform is available at:https://github.com/chenruonan/blockchain-based-intelligent-and-fair-IoV-charging-service-protocol. The experimental results demonstrate the low latency and energy-saving advantages of our proposal. When the payment is executed 250 times, the delay of our proposal is only 1.54% of the normal on-chain payment time.
Dawei Li 0009, Qinjun Wan, Zhenyu Guan 0002, Shizhong Li, Jieyu Su, Jianwei Liu 0001
IEEE Trans. Intell. Transp. Syst.8
2023 Secure and Distributed IoT Data Storage in Clouds Based on Secret Sharing and Collaborative Blockchain
abstract
With the rapid development of 5G/6G, most Internet of Things (IoT) devices will embrace wireless connection in the near future. A public concern is how to securely organize, store and retrieve data generated from IoT devices. Many cloud-based IoT data storage schemes have been proposed recently. However, for an untrusted or vulnerable cloud server, the stored IoT data can be easily accessed, modified and even destroyed given that the IoT data are stored in total centralization. Moreover, the servers in a cloud are generally homogeneous and thus vulnerable to attacks. For improvements, we design a novel framework for secure and efficient IoT data storage based on secret sharing and a collaborative blockchain. First, an ultra-lightweight secret sharing algorithm is designed to map original messages generated by IoT devices to a set of shorter message shares. Second, all the shares of IoT messages are separately delivered to different clouds for storage. To guarantee the security of shares, the delivery is notarized on a proposed blockchain. Specifically, both hash values of the shares and their information of location are embedded in blocks which are then chained to form a blockchain. Third, we create a balanced index structure about the shares for each cloud storage node based on the information in the blockchain, and we also propose a depth-first data search algorithm to improve IoT data retrieval efficiency. Theoretical analysis and simulation results illustrate that our scheme can store and retrieve the IoT data securely and efficiently.
Na Wang 0003, Junsong Fu 0001, Shancheng Zhang, Jiawen Qiao, Jianwei Liu 0001, Bharat K. Bhargava
IEEE/ACM Trans. Netw.6
2023 Secure Gene Sequence Alignment Based on Garbled Circuit
abstract
With the development of bioinformatics technology, there is an increasing demand for gene sequence alignment. Gene sequence alignment can determine the homology between sequences and plays an increasingly prominent role in the traceback of species, the construction of phylogenetic trees and the diagnosis of human diseases. So far, gene sequence alignment schemes usually do not consider the privacy of participants, which could cause the disclosure of sensitive information, thus there is an urgent need for secure gene sequence alignment schemes. In this paper, we model genomic data from the perspective of privacy protection. On this basis, we design a scheme of gene sequence alignment for the analysis of homologous genopathy. Genopathy private query is realized by adding redundant query conditions, and secure gene sequence alignment is realized by using garbled circuit. And we propose merging truth table to implement a garbled equality gate circuit that only needs to send ciphertext once. The times of encryption and decryption reduced to a third of the general garbled equality gate circuit. Consequently, the scheme can protect the data privacy, query privacy and output privacy of both participants and has better practicability.
Yatong Jiang, Tao Shang 0002, Jianwei Liu 0001
IEEE Trans. Serv. Comput.3
2022 PUF-Based Intellectual Property Protection for CNN Model
Dawei Li 0009, Yangkun Ren, Di Liu 0019, Zhenyu Guan 0002, Qianyun Zhang 0001, Jianwei Liu 0001
KSEM (3)7
2022 Quantitative Risk Assessment of Threats on SCADA Systems Using Attack Countermeasure Tree
abstract
SCADA systems are one of the critical infrastructures and face many security threats. Attackers can control SCADA systems through network attacks, destroying the normal operation of the power system. It is important to conduct a risk assessment of security threats on SCADA systems. However, existing models for risk assessment using attack trees mainly focus on describing possible intrusions rather than the interaction between threats and defenses. In this paper, we comprehensively consider intrusion likelihood and defense capability and propose a quantitative risk assessment model of security threats based on attack countermeasure tree (ACT). Each leaf node in ACT contains two attributes: exploitable vulnerabilities and defense countermeasures. An attack scenario can be constructed by means of traversing the leaf nodes. We set up six indicators to evaluate the impact of security threats in attack scenarios according to NISTIR 7628 standard. Experimental results show the attack probability of security threats and high-risk attack scenarios in SCADA systems. We can improve defense countermeasures to protect against security threats corresponding to high-risk scenarios. In addition, the model can continually update risk assessments based on the implementation of the system’s defensive countermeasures.
Xueqin Gao, Tao Shang 0002, Jianwei Liu 0001
PST4
2022 CLTracer: A Cross-Ledger Tracing framework based on address relationships
Zongyang Zhang, Jiayuan Yin, Bin Hu 0001, Qianhong Wu, Jianwei Liu 0001
Comput. Secur.7
2022 Practical AgentChain: A compatible cross-chain exchange system
Yiming Hei, Dawei Li 0009, Chi Zhang 0073, Jianwei Liu 0001, Yizhong Liu, Qianhong Wu
Future Gener. Comput. Syst.4
2022 Cryptanalysis of a white-box SM4 implementation based on collision attack
abstract
Abstract White‐box cryptography is to primarily protect the key of a cipher from being extracted in a white‐box scenario, where an adversary has full access to the execution environment of software implementation. Since the introduction of white‐box cryptography, a number of white‐box implementations of the Chinese SM4 block cipher standard have been proposed, and all of them have been attacked based on Billet et al.’s attack. In this study, we show that collision‐based attack can work more efficiently on Shi et al.’s white‐box SM4 implementation than the previously published attacks, by devising an attack with a time complexity of , significantly reducing the previously known time complexity of to a very practical level. Our attack can also be similarly applied to some other white‐box SM4 implementations.
Rusi Wang, Hua Guo 0001, Jiqiang Lu, Jianwei Liu 0001
IET Inf. Secur.4
2022 An efficient multikeyword fuzzy ciphertext retrieval scheme based on distributed transmission for Internet of Things
abstract
As traditional computing and cloud computing integrate, the Internet of Things (IoT) has evolved into a layered and cloud-network-edge-end architecture. However, most searchable encryption models still use triples, in which hierarchical structures are neglected, and insecure intermediate nodes are exposed to external environment. Meanwhile, mainstream schemes adopting accurate retrieval are incompatible with IoT end users' features of differentiation. To address these issues, we innovatively design an efficient and credible search model with an accurate multikeyword fuzzy ciphertext retrieval scheme in the context of IoT. First, based on network coding and key sharing, data are grouped, encoded, and transmitted in parallel to the receiver node through middle-layer nodes, with high efficiency and reliability. Second, to realize fuzzy retrieval of IoT, edit distance is selected as the standard of difference between keywords, and then document index vector and query vector are created based on locality sensitive hashing (LSH) and Bloom Filter. Furthermore, to improve the traditional scheme, query keywords are split into multiple single-word forms, inner products between each trapdoor of single word and encryption index vector are calculated, respectively, for the sum of each inner product and thus top $\mathrm{top}$ - k $k$ sorting search. Ultimately, feasibility, safety, and efficiency of our improved scheme are verified by security analysis, while simulation results support that our scheme has better accuracy and efficiency.
Kaifa Zheng, Na Wang 0003, Jianwei Liu 0001, Shancheng Zhang, Qingyun Han, Ruijin Wang, Junsong Fu 0001
Int. J. Intell. Syst.3
2022 Blockchain-based authentication for IIoT devices with PUF
Dawei Li 0009, Di Liu 0019, Yingxian Song, Yangkun Ren, Zhenyu Guan 0002, Yu Sun 0015, Jianwei Liu 0001
J. Syst. Archit.8
2022 Variational Inference Based Sparse Signal Detection for Next Generation Multiple Access
abstract
The next generation multiple access (NGMA) schemes are considered to support massive access for a large number of devices, which motivates us to develop a low-complexity approach for next generation systems. Since the generalized spatial modulation (SM) can be adopted to the system, a number of compressive sensing (CS) reconstruction algorithms are deployed for the detection of sparse signals, while the complexity of CS-based approaches is proportional to the number of antennas. In order to decrease the complexity, we propose a two-stage approach to detect sparse signals, where the received signals are divided into groups. Then, the activity variables of aggregated signals are decided and the sparse signal detection is carried out at the signals belonging to active groups. During the activity variable detection, the variational inference algorithm is applied to determine the activity variables. Moreover, in order to analyze the performance of activity variable detection, the$J$-divergence is proposed to measure the distance between the distributions, while the approximate expression of$J$-divergence is derived. Simulation results show that the proposed approach is able to provide good detection performance with low complexity. In addition, the$J$-divergence is confirmed to be useful as an evaluation metric to measure the detection performance.
Rui Han 0002, Lin Bai 0001, Weizheng Zhang 0002, Jianwei Liu 0001, Jinho Choi 0001, Wei Zhang 0001
IEEE J. Sel. Areas Commun.4
2022 SSHC: A Secure and Scalable Hybrid Consensus Protocol for Sharding Blockchains With a Formal Security Framework
abstract
Sharding blockchains are proposed to solve the scalability problem while maintaining security and decentralization. However, there are still many issues to be solved. First, the member selection and assignment process are not strictly analyzed, which might lead to an increase in the adversary proportion. Second, current intra-shard consensus algorithms are inefficient. Besides, cross-shard transaction processing costs expensive system overhead. Moreover, there is a lack of a formal security framework. In this article, we propose a secure and scalable hybrid consensus (SSHC). First, we propose a fair sharding selection scheme to select committee members, including mining processes and member lists confirmation by a reference committee. Second, a pipelined Byzantine fault tolerance for intra-shard consensus is designed, combining the pipelined technology with threshold signatures. Third, we propose a responsive sharding transaction batch processing mechanism to handle cross-shard transactions, which reduces the number of calls to Byzantine fault tolerance algorithms. Fourth, a secure committee reconfiguration method is designed to update shard members efficiently. Furthermore, we employ a formal security framework to design and analyze a sharding blockchain. For an adversary whose computational power fraction is less than$1/3$, by reasonably setting a corruption parameter and other related parameters, SSHC is proved to achieve consistency and liveness.
Yizhong Liu, Jianwei Liu 0001, Qianhong Wu, Yiming Hei, Ziyu Zhou 0002
IEEE Trans. Dependable Secur. Comput.2
2022 Age of Information Aware UAV Deployment for Intelligent Transportation Systems
abstract
The intelligent transportation has been extensively investigated as an enabling technology for ubiquitous data processing and content sharing among vehicles and terrestrial infrastructures. In intelligent transportation systems, numerous vehicles and infrastructures are connected for information and data sharing to enable different operations. Since there are some urban areas that face the traffic congestion or cannot be well served, space-air-ground integrated networks (SAGIN) can be carried out to provide continuous network connectivity for vehicles. In particular, unmanned aerial vehicles (UAVs) are deployed as data collectors to receive data packets from vehicles due to the advantages of high mobility and low operating cost. It is noteworthy that the information freshness is critical to enable services for timely decision, e.g., autonomous driving and accident prevention. In this paper, we develop UAV-aided intelligent transportation systems to enhance the usage of vehicular networks and support low latency vehicular services, where the concept of age-of-information (AoI) is adopted to measure the freshness of data packets of vehicles. Then, the performance of UAV-aided intelligent transportation systems is analyzed in terms of the average AoI. In addition, the deployment of multiple UAVs is optimized to minimize the average peak AoI according to the traffic intensity of vehicles under seamless coverage, finite queue, and coverage probability constraints. To this end, the deployment optimization problem is formulated as a multi-constrained non-convex optimization problem and solved by considering each soft constraint separately. Simulation results show that our proposed system can provide timely data transmission.
Rui Han 0002, Yongqing Wen, Lin Bai 0001, Jianwei Liu 0001, Jinho Choi 0001
IEEE Trans. Intell. Transp. Syst.4
2021 A Secure Cross-Shard View-Change Protocol for Sharding Blockchains
Yizhong Liu, Jianwei Liu 0001, Yiming Hei, Yu Xia 0013, Qianhong Wu
ACISP2
2021 Redactable Transactions in Consortium Blockchain: Controlled by Multi-authority CP-ABE
Zongyang Zhang, Tong Li 0018, Jianwei Liu 0001
ACISP4
2021 UC-Secure Cryptographic Reverse Firewall-Guarding Corrupted Systems with the Minimum Trusted Module
Jianwei Liu 0001, Zongyang Zhang, Yanting Zhang 0002
Inscrypt2
2021 WADS: A Webshell Attack Defender Assisted by Software-Defined Networks
Beiyuan Yu, Jianwei Liu 0001, Ziyu Zhou 0002
ISPEC2
2021 Differential identifiability clustering algorithms for big data analysis
Tao Shang 0002, Xujie Ren, Jianwei Liu 0001
Sci. China Inf. Sci.4
2021 Making MA-ABE fully accountable: A blockchain-based approach for secure digital right management
Yiming Hei, Jianwei Liu 0001, Hanwen Feng 0001, Dawei Li 0009, Yizhong Liu, Qianhong Wu
Comput. Networks2
2021 Traceable ring signatures: general framework and post-quantum security
Hanwen Feng 0001, Jianwei Liu 0001, Dawei Li 0009, Ya-Nan Li 0007, Qianhong Wu
Des. Codes Cryptogr.2
2021 A Novel Lightweight Authentication Protocol for Emergency Vehicle Avoidance in VANETs
abstract
The delay of vehicle emergency has led to many serious consequences. A series of studies has been carried out in the field of information security in vehicularad hocnetworks (VANETs). However, open issues such as the authentication of emergency vehicle (EV) avoidance are remaining unsolved. In this article, we propose a novel lightweight authentication protocol to avoid EVs in VANETs. In our protocol, after completing the first mutual authentication with the nearest roadside unit (RSU), EV can complete the mutual identity authentication with the subsequent RSUs without repeating cumbersome calculations. Additionally, EV is required to verify the legitimacy of the driver’s identity when starting to avoid some illegal driving behavior. The RSUs will broadcast avoidance information to ordinary vehicles in their jurisdiction to remind them to clear a temporary emergency lane for EVs in advance. With temporary emergency lanes, emergent mission delays due to traffic congestion could be reduced. The security analysis and efficient analysis prove that our protocol is practical and efficient against attacks, such as impersonation attacks, device theft attacks, reputation attacks, etc.
Chen Wang 0015, Jian Shen 0001, Jianwei Liu 0001, Pandi Vijayakumar, Neeraj Kumar 0001
IEEE Internet Things J.4
2021 Age of Information and Performance Analysis for UAV-Aided IoT Systems
abstract
In the Internet of Things (IoT), numerous IoT devices are deployed for environment sensing, information collecting, and data transmitting to enable different operations, including patrol monitor, industrial automation, and system control. Considering the limited power and computation capability of IoT devices, mobile-edge computing (MEC) is applied to enhance the usage of IoT. Since unmanned aerial vehicles (UAVs) can be used as MEC servers, they become an efficient means to collect data packets and assist computation. In this article, we develop UAV-aided IoT systems, where the performance of data collection is analyzed in terms of packet loss rate and data quantity using a Markov chain. Then, in order to meet the diverse service requirements, the computation frequency of UAV is designed according to the preference coefficients of the cost on energy and time consumption. Finally, the system Age of Information (AoI) is considered to define the freshness of data packets, where the models of single-IoT device and multi-IoT devices with first-come–first-served (FCFS) principle and M/M/1 queuing are analyzed. The simulation results show that the proposed system is able to provide robust data collection and efficient computation for IoT devices.
Rui Han 0002, Jiaxing Wang 0004, Lin Bai 0001, Jianwei Liu 0001, Jinho Choi 0001
IEEE Internet Things J.4
2021 UAV-Aided Backscatter Communications: Performance Analysis and Trajectory Optimization
abstract
In 5G massive machine-type communication (mMTC), power-limited or battery-free parasite devices such as radio frequency identification (RFID) tags, can use the transmitted signals from host devices as ambient signals for backscatter communications to send information to a base station (BS). Unmanned aerial vehicles (UAVs) can be employed as host devices to help transmissions of parasite devices due to the advantages of high mobility and low operating cost. In this paper, we propose a signal detection approach based on the central limit theorem to detect the presence of parasite devices and separate parasite signals from host signals. Then, closed-form expressions for the probability of error detection and the bit error rate (BER) are derived. Moreover, the trajectory planning of multiple UAVs is optimized with the consideration of minimizing the energy consumption of UAV swarms to serve parasite devices. Theoretical and simulation results show that our proposed method provides good detection performance for parasite devices. It also shows that the trajectory planning of multiple UAVs is optimized.
Rui Han 0002, Lin Bai 0001, Yongqing Wen, Jianwei Liu 0001, Jinho Choi 0001, Wei Zhang 0001
IEEE J. Sel. Areas Commun.4
2021 Themis: An accountable blockchain-based P2P cloud storage scheme
Yiming Hei, Yizhong Liu, Dawei Li 0009, Jianwei Liu 0001, Qianhong Wu
Peer-to-Peer Netw. Appl.4
2021 Identity-Based Dynamic Data Auditing for Big Data Storage
abstract
Identity-based remote data auditing schemes can verify data integrity and provide a simple identity authentication and management for multiple users. However, prior works on identity-based remote data auditing lack the support of dynamic operations. In these schemes, tag generation is linked to the index of data block, which is related to update operations such as modification, insertion and deletion. If users perform dynamic operations on a data block, the tags of all subsequent blocks need to be modified. It means that if users want to update data on a big data platform, they have to download the whole file, update the file and send the updated file to the big data platform. Such pattern will bring huge communication overhead. In this paper, we propose an identity-based dynamic data auditing scheme which supports dynamic data operations, including modification, insertion and deletion. As far as we know, there is still no other identity-based data auditing scheme that supports dynamic operations. In particular, to achieve efficient dynamic operations, we use the data structure of Merkle hash tree for block tag authentication, which helps update data with integrity assurance. Analyses of security and performance show that the proposed scheme is efficient and secure.
Tao Shang 0002, Xingyue Chen, Jianwei Liu 0001, Xinxi Lu
IEEE Trans. Big Data4
2020 A Blockchain-Based Resource Supervision Scheme for Edge Devices Under Cloud-Fog-End Computing Models
Tongchen Wang, Jianwei Liu 0001, Dawei Li 0009, Qianhong Wu
ACISP2
2020 Traceable Ring Signatures with Post-quantum Security
Hanwen Feng 0001, Jianwei Liu 0001, Qianhong Wu, Ya-Nan Li 0007
CT-RSA2
2020 An Attack-Immune Trusted Architecture for Supervisory Intelligent Terminal
Dongxu Cheng, Jianwei Liu 0001, Zhenyu Guan 0002, Jiale Hu
ICA3PP (3)2
2020 FleetChain: A Secure Scalable and Responsive Blockchain Achieving Optimal Sharding
Yizhong Liu, Jianwei Liu 0001, Dawei Li 0009, Qianhong Wu
ICA3PP (3)2
2020 Cross-shard Transaction Processing in Sharding Blockchains
Yizhong Liu, Jianwei Liu 0001, Jiayuan Yin, Qianhong Wu
ICA3PP (3)2
2020 Measurement-Device-Independent QKD Based on Orbital Angular Momentum with Dual Detectors
abstract
Orbital angular momentum (OAM) has the characteristics of high dimension and rotational symmetry. Quantum key distribution (QKD) schemes using OAM can carry more quantum information, improve the transmission capacity of information and reduce the errors caused by reference frame calibration errors. In this paper, we propose a measurement-device-independent QKD scheme based on OAM with dual detectors. On the basis of the measurement-device-independent QKD protocol, we use OAMs to encode the key information and then send them to a third-party measurement device. In the process of measurement, we adopt the dual-detector theory to improve key generation rate and transmission distance. Simulation analyses show that the secure transmission distance of our scheme can reach 140 km, which is about 30km more than the scheme using single detector.
Hai-Zheng Sun, Tao Shang 0002, Jianwei Liu 0001
IWCMC3
2020 Quantum Homomorphic Encryption Based on Quantum Obfuscation
abstract
Homomorphic encryption enables computation on encrypted data while maintaining secrecy. This leads to an important open question whether quantum computation can be delegated and verified in a non-interactive manner or not. In this paper, we affirmatively answer this question by constructing the quantum homomorphic encryption scheme with quantum obfuscation. It takes advantage of the interchangeability of the unitary operator, and exchanges the evaluation operator and the encryption operator by means of equivalent multiplication to complete homomorphic encryption. The correctness of the proposed scheme is proved theoretically. The evaluator does not know the decryption key and does not require a regular interaction with a user. Because of key transmission after quantum obfuscation, the encrypting party and the decrypting party can be different users. The output state has the property of complete mixture, which guarantees the scheme security. Moreover, the security level of the quantum homomorphic encryption scheme depends on quantum obfuscation and encryption operators.
Yuanjing Zhang, Jianwei Liu 0001, Tao Shang 0002
IWCMC2
2020 A Secure Shard Reconfiguration Protocol for Sharding Blockchains Without a Randomness
abstract
In permissionless blockchains, due to the corruption attack of an adversary, nodes participating the protocol need to be updated regularly. In the process of node selection and committee reconfiguration, there may exist some problems. First, a complicated secure randomness generation protocol is in need. Besides, an adversary might obtain a mining puzzle in advance and start mining in ahead of honest nodes. Moreover, an adversary usually has an advantage of network delay. In order to solve the above problems, we conduct the following research. Firstly, we propose a PoW solution withhold attack against PoW-based member selection methods. An adversary might withhold his mining results in an epoch to obtain the mining puzzle of the next epoch in advance of honest nodes. Secondly, a secure shard reconfiguration protocol is designed, which does not rely on any complicated randomness generation protocol. Our shard reconfiguration protocol is proved rigorously to be secure, which means that in each selected committee, the honest node fraction exceeds a predefined target value. Thirdly, we implement our shard reconfiguration protocol. By carefully setting related system parameters, our protocol could be applied easily to most sharding blockchains. To our best knowledge, the shard reconfiguration protocol proposed in this paper is the first protocol that could safely implement node selection and committee reconfiguration of a sharding blockchain without using a secure randomness, which greatly reduces the communication and time overhead caused by the generation of a randomness.
Yizhong Liu, Jianwei Liu 0001, Yiming Hei, Qianhong Wu
TrustCom2
2020 A fair selection protocol for committee-based permissionless blockchains
Yizhong Liu, Jianwei Liu 0001, Zongyang Zhang
Comput. Secur.2
2020 Dynamic data auditing scheme for big data storage
Xingyue Chen, Tao Shang 0002, Jianwei Liu 0001, Zhenyu Guan 0002
Frontiers Comput. Sci.4
2020 ECDSA weak randomness in Bitcoin
Ziyu Wang 0009, Zongyang Zhang, Jiaming Piao, Jianwei Liu 0001
Future Gener. Comput. Syst.5
2020 More realistic analysis of mass surveillance - security in multi-surveillant settings
abstract
The PRISM made the research of cryptography against subversion attacks flourish these years. In a subversion attack, surveillants can compromise the security of users’ systems by subverting implementations of cryptographic algorithms. While the scenario of a single‐surveillant has been researched by several works, the multi‐surveillant setting attracted less consideration. The authors have initialised this notion in previous work but assumed the surveillants to be completely isolated. In this study, the authors follow this idea and consider more realistic scenarios of the multi‐surveillant subversion, where surveillants are able to have limited communications. They propose the notions of queryable adversaries and conversational adversaries. In the first setting, adversaries can verify whether output is produced by a subverted implementation from others; in the latter setting, adversaries can have arbitrary conversations with each other without leaking their backdoors. Under the framework of ‘amalgamation and decomposition’, they design randomness generators that are secure against queryable adversaries and conversational adversaries, respectively, by adopting implementations from different sources intentionally. Based on the secure randomness generators, they construct symmetric encryption schemes that match the corresponding security definitions.
Jianwei Liu 0001, Zongyang Zhang
IET Inf. Secur.2
2020 Random Access and Detection Performance of Internet of Things for Smart Ocean
abstract
Over the last decade, the Internet of Things (IoT) has been employed as an enabling technology for the smart ocean. As one of the key technologies in the IoT, machine-type communication (MTC) has been considered to support devices' connectivity. In the MTC, random access is introduced for devices to share a common access channel during the packet transmission with low signaling overhead. However, the collision caused by the presence of multiple devices is inevitable. Since maritime sensors have limited energy sources, in this article, we propose a relay-aided random access (RARA) scheme for the smart ocean, where retransmissions are carried out by maritime buoys with the relay function, to deal with collisions. In the RARA scheme, a base station (BS) is able to recover multiple collided signal packets simultaneously by using multiuser detection with multiple copies of collided signals forwarded by buoy nodes. As a result, our proposed scheme becomes energy efficient and reliable to be suitable for the smart ocean. Theoretical and simulation results show that a high throughput and a low outage probability can be achieved with a large number of buoy nodes.
Lin Bai 0001, Rui Han 0002, Jianwei Liu 0001, Jinho Choi 0001, Wei Zhang 0001
IEEE Internet Things J.3
2020 Watchdog: Detecting Ultrasonic-Based Inaudible Voice Attacks to Smart Home Systems
abstract
Internet of Things is a critical infrastructure component as well as an enabling technology to support the fast-developing cross-region, cross-application, and diversified collaborative smart city services that require systematic cooperation among multiple smart city systems. Speech recognition-based voice controllable systems become one of the most popular interfaces in smart devices. However, it has been proved that attackers can hide their voice commands via modulating them on ultrasonic carriers and carry out inaudible voice attacks to manipulate voice controllable devices (e.g., mobile phone) unnoticeably. Although there are defense suggestions to enhance the hardware or add new modules of microphones, it is impractical to change the hardware design of all voice-controllable devices developed by different manufactures. In this article, we validate the effectiveness of ultrasonic-based inaudible voice attacks to voice-controllable smart home devices and propose a signal-processing-based hidden voice attack detection approach. Our approach uses an independent device that deploys a two-step lightweight detecting algorithm to identify the attack signals. We simulate our algorithm and make a prototype implementation of the proposed approach. The simulation results illustrate the correctness of the detection algorithm and the experiments show that our approach can detect the ultrasonic-based inaudible voice attack effectively.
Shishi Zhu, Xuan Dai, Qixiao Lin, Jianwei Liu 0001
IEEE Internet Things J.5
2020 Spatial temporal incidence dynamic graph neural networks for traffic flow forecasting
Hao Peng 0001, Bowen Du 0001, Md. Zakirul Alam Bhuiyan, Hongyuan Ma, Jianwei Liu 0001, Linfeng Du, Senzhang Wang, Philip S. Yu
Inf. Sci.6
2020 An inaudible voice attack to context-based device authentication in smart IoT systems
Shishi Zhu, Jianwei Liu 0001
J. Syst. Archit.3
2020 Air-to-Ground Wireless Links for High-Speed UAVs
abstract
As unmanned aerial vehicles (UAVs) are becoming more popular and the demand for wireless links for UAVs is increasing, it is crucial to develop air-to-ground (A2G) wireless links for high-speed UAVs. Suffering from the high mobility and limitation of transmission power of UAVs, A2G wireless links become unstable to provide high quality communication services. In this paper, we design robust A2G wireless links for high speed UAVs, where conjunct power control is developed together with switched beamforming to maximize the power efficiency and minimize the fluctuation of A2G wireless links of millimeter wave (mmWave) signal transmission. We first present channel models for A2G wireless links of high-speed UAVs, which can be virtually seen as multiple-input multiple-output (MIMO) channels. To maximize the power efficiency, a conjunct power control problem is formulated to allocate powers for wireless links between antenna arrays on UAVs and access points (APs). For switched beamforming, beamformers are designed to provide a certain time-invariant signal-to-interference-plus-noise ratio (SINR) to minimize the SINR fluctuation of A2G wireless links. From theoretical analysis and numerical results, it is shown that the proposed architecture is able to provide robust and high quality A2G wireless links for high-speed UAV communication systems.
Lin Bai 0001, Rui Han 0002, Jianwei Liu 0001, Jinho Choi 0001, Wei Zhang 0001
IEEE J. Sel. Areas Commun.3
2020 Cognitive AODV routing protocol with novel channel-route failure detection
Abdur Rashid Sangi, Mohammed Saeed Alkatheiri, Satish Anamalamudi, Jianwei Liu 0001
Multim. Tools Appl.4
2020 Secure Outsourced Medical Data against Unexpected Leakage with Flexible Access Control in a Cloud Storage System
abstract
The application of cloud storage system has been deployed widely in recent years. A lot of electronic medical records (EMRs) are collected and uploaded to the cloud for scalable sharing among the authority users. It is necessary to guarantee the confidentiality of EMRs and the privacy of EMR owners. To achieve this target, we summarize a series of attack behaviors in the cloud storage system and present the security model against many types of unexpected privacy leakage. Privacy of unassailed EMRs is guaranteed in this model, and the influence of privacy leakage is controlled in a certain scope. We also propose a role-based access control scheme to achieve flexible access control on these private EMRs. One can access medical records only if his/her role satisfies the defined access policy, which implies a fine-grained access control. Theoretical and experimental analyses show the efficiency of our scheme in terms of computation and communication.
Xingguang Zhou, Jianwei Liu 0001, Zongyang Zhang, Qianhong Wu
Secur. Commun. Networks2
2019 Security Against Subversion in a Multi-surveillant Setting
Jianwei Liu 0001, Zongyang Zhang
ACISP2
2019 A Combined Micro-block Chain Truncation Attack on Bitcoin-NG
Ziyu Wang 0009, Jianwei Liu 0001, Zongyang Zhang, Yanting Zhang 0002, Jiayuan Yin, Wenmao Liu
ACISP2
2019 A Trustworthiness-Based Time-Efficient V2I Authentication Scheme for VANETs
Chen Wang 0015, Jian Shen 0001, Jianwei Liu 0001
BlockSys4
2019 Secure Stern Signatures in Quantum Random Oracle Model
Hanwen Feng 0001, Jianwei Liu 0001, Qianhong Wu
ISC2
2019 Achieving liability in anonymous communication: Auditing and tracing
Haibin Zheng, Qianhong Wu, Zhenyu Guan 0002, Shuangyu He, Jianwei Liu 0001
Comput. Commun.6
2019 An analytic evaluation for the impact of uncle blocks by selfish and stubborn mining in an imperfect Ethereum network
Ziyu Wang 0009, Jianwei Liu 0001, Qianhong Wu, Yanting Zhang 0002, Ziyu Zhou 0002
Comput. Secur.2
2019 DA&FD-Deadline-Aware and Flow Duration-Based Rate Control for Mixed Flows in DCNs
abstract
Data center has become an important facility for hosting various applications. For data center networks, deadline missing rate and average flow completion time are two main metrics for the performance of applications. In this paper, we find deadline-aware methods can only reduce the percentage of flows missing deadline, while flowsize-aware and information-cumulative methods can only optimize the average flow completion time. However, traffic in data center is the mixture of various flows and focusing on the single goal is not enough. We advocate to incorporate deadline and flow duration time into flow rate control. Then we design DA&FD (Deadline-Aware and Flow Duration) based rate control mechanism and analyze its performance in theory. At last, we evaluate DA&FD under different topologies, real world traffic and load scenarios, both by simulation and in real testbed. Our results show that DA&FD performs close to D2TCP and about 15%, 25%, 30%, 35% better than Ameon, L2DCT, Karuna, DCTCP on deadline missing rate. For average FCT, the performance of DA&FD is similar to L2DCT and compared with Ameon, D2TCP, Karuna, DCTCP, DA&FD can reduce average FCT by 10%, 15%, 20%, 25%.
Han Zhang 0009, Haijun Geng, Xia Yin 0001, Xingang Shi, Qianhong Wu, Jianwei Liu 0001
IEEE/ACM Trans. Netw.8
2019 Efficient Scheduling of Weighted Coflows in Data Centers
abstract
Traditional network resource management mechanisms are mainly flow or packet based. Recently, coflow has been proposed as a new abstraction to capture the communication patterns in a rich set of data parallel applications in data centers. Coflows effectively model the application-level semantics of network resource usage, so high-level optimization goals, such as reducing the transfer latency of applications, can be better achieved by taking coflows as the basic elements in network resource allocation or scheduling. Although efficient coflow scheduling methods have been studied, in this paper, we advocate to schedule weighted coflows as a further step in this direction, where weights are used to express the importances or priorities of different coflows or their corresponding applications. We propose the Weighted Coflow Completion Time (WCCT) minimization problem and a (2-2/n+1)-approximate optimal offline algorithm, where n is the concurrent number of coflows. We then design an information-agnostic online algorithm named IAOA to dynamically schedule coflows according to their weights and the instantaneous network condition. We also design and implement a coflow scheduling system named FlyTransfer, which can use the online algorithm as its scheduling method. We test the performance of FlyTransfer by trace-driven simulations as well as real deployment in openstack. Our evaluation results show that, compared to the latest information-agnostic coflow scheduling algorithms, FlyTransfer can reduce more than 40 percent of the WCCT, and more than 30 percent of the completion time for coflows with above-the-average level of importance. It even outperforms the most efficient clairvoyant coflow scheduling method by reducing around 30 percent WCCT, and 25- 30 percent of the completion time for coflows with above-the-average importance, respectively.
Han Zhang 0009, Xingang Shi, Xia Yin 0001, Haijun Geng, Qianhong Wu, Jianwei Liu 0001
IEEE Trans. Parallel Distributed Syst.8
2018 Revisiting the Incentive Mechanism of Bitcoin-NG
Jiayuan Yin, Changren Wang, Zongyang Zhang, Jianwei Liu 0001
ACISP4
2018 Linkable Group Signature for Auditing Anonymous Communication
Haibin Zheng, Qianhong Wu, Lin Zhong 0003, Shuangyu He, Jianwei Liu 0001
ACISP6
2018 Auditable Hierarchy-Private Public-Key Encryption
Lin Zhong 0003, Qianhong Wu, Haibin Zheng, Jianwei Liu 0001
ACISP5
2018 Multi-authority Fast Data Cloud-Outsourcing for Mobile Devices
Yanting Zhang 0002, Jianwei Liu 0001, Zongyang Zhang
ISC2
2018 OSCO: An Open Security-Enhanced Compatible OpenFlow Platform
Haosu Cheng, Jianwei Liu 0001, Jie Chen 0038
WASA2
2018 Lightweight and Manageable Digital Evidence Preservation System on Bitcoin
Qianhong Wu, Qin Wang 0008, Jianwei Liu 0001, Zhenyu Guan 0002
J. Comput. Sci. Technol.5
2018 A Compatible OpenFlow Platform for Enabling Security Enhancement in SDN
abstract
Software-defined networking (SDN) is a representative next generation network architecture, which allows network administrators to programmatically initialize, control, change, and manage network behavior dynamically via open interfaces. SDN is widely adopted in systems like 5G mobile networks and cyber-physical systems (CPS). However, SDN brings new security problems, e.g., controller hijacking, black-hole, and unauthorized data modification. Traditional firewall or IDS based solutions cannot fix these challenges. It is also undesirable to develop security mechanisms in such an ad hoc manner, which may cause security conflict during the deployment procedure. In this paper, we propose OSCO (Open Security-enhanced Compatible OpenFlow) platform, a unified, lightweight platform to enhance the security property and facilitate the security configuration and evaluation. The proposed platform supports highly configurable cryptographic algorithm modules, security protocols, flexible hardware extensions, and virtualized SDN networks. We prototyped our platform based on the Raspberry Pi Single Board Computer (SBC) hardware and presented a case study for switch port security enhancement. We systematically evaluated critical security modules, which include 4 hash functions, 8 stream/block ciphers, 4 public-key cryptosystems, and key exchange protocols. The experiment results show that our platform performs those security modules and SDN network functions with relatively low computational (extra 2.5% system overhead when performing AES-256 and SHA-256 functions) and networking performance overheads (73.7 Mb/s TCP and 81.2Mb/s UDP transmission speeds in 100Mb/s network settings).
Haosu Cheng, Jianwei Liu 0001, Jie Chen 0038, Jingdong Bian
Secur. Commun. Networks2
2018 Efficient subtree-based encryption for fuzzy-entity data sharing
Jianwei Liu 0001, Qianhong Wu, David Naccache, Houda Ferradi
Soft Comput.2
2017 Predicate Fully Homomorphic Encryption: Achieving Fine-Grained Access Control over Manipulable Ciphertext
Hanwen Feng 0001, Jianwei Liu 0001, Qianhong Wu
Inscrypt2
2017 Provably Secure Self-Extractable Encryption
Qianhong Wu, Jianwei Liu 0001, Fu Xiao 0001
ProvSec4
2017 Auditing Revocable Privacy-Preserving Access Control for EHRs in Clouds
abstract
Electronic Health Record (EHR) systems bring an abundance of convenience for telediagnosis, medical data sharing and management. A main obstacle for wide adoption of EHR systems is due to the privacy concerns of patients. In this work, we propose a role-based access control (RBAC) scheme for EHR systems to secure private EHRs. In our RBAC, there are two main types of roles, namely independent patients and hierarchically organized medical staffs. A patient is identified by his/her identity, and a medical staff is recognized by his/her role in the medical institute. A user can comprehend an EHR only if he/she satisfies the access policy associated with this EHR, which implies a fine-grained access control. A public auditor is employed to verify whether the EHR is correctly encapsulated with the specified access policy, which provides an a priori approach to find fraudulent EHRs and reduce potential medical disputes. Moreover, our RBAC enforces a forward revocation mechanism. A revoked user cannot access the future EHRs even if his/her previous role satisfies the access policy. These security properties are formally proven under well-established assumptions. Theoretical and experimental analyses show the efficiency of our RBAC in terms of communication and computation.
Jianwei Liu 0001, Qianhong Wu
Comput. J.3
2017 Co-Check: Collaborative Outsourced Data Auditing in Multicloud Environment
abstract
With the increasing demand for ubiquitous connectivity, wireless technology has significantly improved our daily lives. Meanwhile, together with cloud-computing technology (e.g., cloud storage services and big data processing), new wireless networking technology becomes the foundation infrastructure of emerging communication networks. Particularly, cloud storage has been widely used in services, such as data outsourcing and resource sharing, among the heterogeneous wireless environments because of its convenience, low cost, and flexibility. However, users/clients lose the physical control of their data after outsourcing. Consequently, ensuring the integrity of the outsourced data becomes an important security requirement of cloud storage applications. In this paper, we present Co-Check, a collaborative multicloud data integrity audition scheme, which is based on BLS (Boneh-Lynn-Shacham) signature and homomorphic tags. According to the proposed scheme, clients can audit their outsourced data in a one-round challenge-response interaction with low performance overhead. Our scheme also supports dynamic data maintenance. The theoretical analysis and experiment results illustrate that our scheme is provably secure and efficient.
Wenqian Tian, Hanjun Ma, Jingdong Bian, Jianwei Liu 0001, Jianhong Zhang 0001
Secur. Commun. Networks7
2017 A position-aware Merkle tree for dynamic cloud data integrity verification
Qianhong Wu, Jianwei Liu 0001
Soft Comput.6
2017 Secure joint Bitcoin trading with partially blind fuzzy signatures
Qianhong Wu, Xiuwen Zhou, Jiankun Hu, Jianwei Liu 0001, Yong Ding 0005
Soft Comput.5
2016 Accelerating Oblivious Transfer with Batch Multi-exponentiation
Qianhong Wu, Jianwei Liu 0001, Xinyi Huang 0001
ACISP (1)4
2016 Anonymous Role-Based Access Control on E-Health Records
abstract
Electronic Health Record (EHR) system facilitates us a lot for health record management. Privacy risk of patients' records is the dominating obstacle in the widely deployed EHRs. Role-based access control (RBAC) schemes offer an access control on EHRs according to one's role. Only the medical staff with roles satisfying the specified access policies can read EHRs. In existing schemes, attackers can link patients' identities to their doctors. Therefore, the classification of patients' diseases are leaked without actually knowing patients' EHRs. To address this problem, we present an anonymous RBAC scheme. Not only it achieves flexible access control, but also realizes privacy-preserving for individuals. Moreover, our scheme maintains the property of constant size for the encapsulated EHRs. The proposed security models with semantic security and anonymity can be proven under decisional bilinear group assumptions. Besides, we provide an approach for EHR owners to search out their targeted EHR in the anonymous system. For better user experience, we apply "online/offline" approach to speed up data processing in our scheme. Experimental results show that the time consumption for key generation and EHR encapsulation can be done in milliseconds.
Xingguang Zhou, Jianwei Liu 0001, Qianhong Wu
AsiaCCS2
2016 Online/Offline Public-Index Predicate Encryption for Fine-Grained Mobile Access Control
Jianwei Liu 0001, Qianhong Wu, Kaitai Liang
ESORICS (2)2
2016 Efficient group key management for secure big data in predictable large-scale networks
abstract
Summary It is challenging to secure group communications among large‐scale networks due to their network scale. We observe that in many large‐scale networks, the scale of actual group communication is nevertheless predicable and not very large. For instance, although the entire social network (e.g., Facebook) may have billions of users, the members in a concrete group are usually about tens to hundreds. We manage to secure group communication in such scenarios with efficient group management protocols. Technically, we achieve this goal by using a novel dual‐ring approach in which two rings of nodes are established, one active and one dummy. When some nodes leave, the remaining nodes can replace these nodes with dummy nodes, minimizing the required communications and computations after the protocol is set up and thus providing significant advantage over existing group key management protocols. Formal security arguments show that our protocols are secure under standard computational assumptions. Thorough analysis confirms that our protocols are efficient in computation and communication. Copyright © 2015 John Wiley & Sons, Ltd.
Shuangyu He, Qianhong Wu, Jianwei Liu 0001
Concurr. Comput. Pract. Exp.4
2016 Batch Public Key Cryptosystem with batch multi-exponentiation
Qianhong Wu, Jiankun Hu, Jianwei Liu 0001, Yong Ding 0005
Future Gener. Comput. Syst.6
2016 Identity-based proxy re-encryption version 2: Making mobile access easy in cloud
Yunya Zhou, Qianhong Wu, Jianwei Liu 0001, Yong Ding 0005
Future Gener. Comput. Syst.5
2016 SAKE: scalable authenticated key exchange for mobile e-health networks
abstract
Abstract Mobile e‐Health Network (MHN) is an emerging cloud‐aided networking application across the entire range of functions involved in e‐Health systems. It is important to establish secure channels between users because the data transmitted in MHNs are private, for example, personal electronic healthcare records. It is of great significance to employ key management mechanism and encrypt the data before transmitting in MHNs. However, secure key management is challenging in MHNs because of its highly dynamic and large‐scale nature. In this paper, we first model MHNs and formalize a hierarchical network architecture mirroring the administrative hierarchy and dynamic autonomy in MHNs in the real world. We next present a virtual MHN architecture with only three levels yet suitable to realistic MHNs with arbitrary hierarchical levels. By exploiting the virtual architecture, we propose an efficient authenticated key exchange framework to secure MHNs. We realize a scalable authenticated key exchange scheme with a dedicated variant of a recent hierarchical identity‐based signature and the well‐known Diffie–Hellman key exchange protocol. Theoretical analyses and experimental results show that scalable authenticated key exchange is secure and scalable and hence is practical to secure MHNs. Copyright © 2015 John Wiley & Sons, Ltd.
Jianwei Liu 0001, Qianhong Wu, Willy Susilo
Secur. Commun. Networks2
2016 Large-Scale MIMO Detection Using MCMC Approach With Blockwise Sampling
abstract
In this paper, a low-complexity approach for the large-scale (underdetermined) multiple-input multiple-output (MIMO) detection is proposed using the Markov chain Monte Carlo (MCMC) algorithm in conjunction with blockwise sampling. Klein's algorithm is employed in each sub-system to draw multidimensional samples for an MCMC detector in iterative detection and decoding (IDD). From analysis, we find that the lattice reduction (LR) technique cannot improve the performance of the proposed MCMC-based approach under low-correlated channel environment. In addition, due to blockwise sampling, the proposed method exhibits a faster convergence speed when running a Markov chain and provides a near-optimal performance for the detection of underdetermined MIMO systems. Complexity analysis and simulation results show that the proposed approach outperforms the conventional LR-based Klein randomized successive interference cancellation (SIC) detection with a relatively low complexity.
Lin Bai 0001, Tian Li 0001, Jianwei Liu 0001, Jinho Choi 0001
IEEE Trans. Commun.3
2015 PERM-GUARD: Authenticating the Validity of Flow Rules in Software Defined Networking
abstract
Software Defined Networking (SDN) is one of the typical flow-rule-driven networks. In SDN, a centralized controller dictates the network behavior and configures network devices with many flow rules, and the validity and consistency of flow rules could guarantee the normal operations in SDN. Therefore, SDN requires a secure and efficient mechanism to manage and authenticate flow rules between the application layer and the control layer. In this paper, our target problem is to authenticate the validity of flow rules in SDN. We analyze the mechanisms to generate and insert flow rules in SDN respectively, and present PERM-GUARD, a fine-grained flow rule production-permission authentication scheme. PERM-GUARD employs a new permission authentication model and introduces an identity-based signature scheme to ensure that the controller can verify the validity of flow rules. We conduct theoretical analysis and evaluate our approach by simulation. The results demonstrate that PERM-GUARD can efficiently identify and reject fake flow rules generated by unregistered applications. Meanwhile, our approach can also effectively filter unauthorized flow rules created by valid applications.
Jianwei Liu 0001, Jie Chen 0038
CSCloud2
2015 Batch Blind Signatures on Elliptic Curves
Qianhong Wu, Jianwei Liu 0001
ISPEC5
2015 Non-interactive Revocable Identity-Based Access Control over e-Healthcare Records
Yunya Zhou, Jianwei Liu 0001, Lei Zhang 0009
ISPEC2
2015 Further ideal multipartite access structures from integer polymatroids
Qianhong Wu, Duncan S. Wong, Yi Mu 0001, Jianwei Liu 0001
Sci. China Inf. Sci.6
2015 Practical (fully) distributed signatures provably secure in the standard model
Duncan S. Wong, Qianhong Wu, Sherman S. M. Chow, Jianwei Liu 0001, Yong Ding 0005
Theor. Comput. Sci.6
2014 Hierarchical Identity-Based Broadcast Encryption
Jianwei Liu 0001, Qianhong Wu
ACISP2
2014 Practical Distributed Signatures in the Standard Model
Duncan S. Wong, Qianhong Wu, Sherman S. M. Chow, Jianwei Liu 0001
CT-RSA6
2014 Practical Direct Chosen Ciphertext Secure Key-Policy Attribute-Based Encryption with Public Ciphertext Test
Jianwei Liu 0001, Qianhong Wu, Yunya Zhou
ESORICS (2)2
2014 Provably Secure Certificateless Authenticated Asymmetric Group Key Agreement
Lei Zhang 0009, Qianhong Wu, Jianwei Liu 0001, Wenchang Shi
ISPEC5
2014 Hierarchical Solution for Access Control and Authentication in Software Defined Networks
Shuangyu He, Jianwei Liu 0001, Jie Chen 0038
NSS2
2014 Ciphertext-policy hierarchical attribute-based encryption with short ciphertexts
Qianhong Wu, Josep Domingo-Ferrer, Lei Zhang 0009, Jianwei Liu 0001, Wenchang Shi
Inf. Sci.6
2013 A Generic Construction of Proxy Signatures from Certificateless Signatures
abstract
The primitive of proxy signatures allows the original signer to delegate proxy signers to sign on messages on behalf of the original signer. It has found numerous applications in distributed computing scenarios where delegation of signing rights is common. Certificate less public key cryptography eliminates the complicated certificates in traditional public key cryptosystems without suffering from the key escrow problem in identity-based public key cryptography. In this paper, we reveal the relationship between the two important primitives of proxy signatures and certificate less signatures and present a generic conversion from the latter to the former. Following the generic transformation, we propose an efficient proxy signature scheme with a recent certificate less signature scheme.
Lei Zhang 0009, Qianhong Wu, Josep Domingo-Ferrer, Jianwei Liu 0001, Ruiying Du
AINA6
2013 Light Weight Network Coding Based Key Distribution Scheme for MANETs
Jianwei Liu 0001, Abdur Rashid Sangi, Ruiying Du, Qianhong Wu
NSS1
2013 Identity-Based Dynamic Authenticated Group Key Agreement Protocol for Space Information Network
Kefei Mao, Jianwei Liu 0001
NSS3
2012 Security and privacy in emerging information technologies
abstract
Advances in communication and information technologies including pervasive computer applications, rapid deployments of new wireless networks like 3G, Wifi, WiMAX and their tight coupling to the Internet, have revolutionised our society and really changed every aspect of our lives through a variety of new applications. The rapidly evolving technologies have become ubiquitous, for example, allowing people to stay connected anywhere, anytime via social media services accessed by smartphones, such as Facebook and Twitter. While we experience tremendous benefits from adopting the new technologies, we also continue to face challenges and the biggest challenge is always: how to address security and privacy issues, which may be caused by new technology adoption. This special issue consists of seven papers addressing the security and privacy issues in emerging information technologies such as delay tolerant networking, vehicular communication systems and smartphones and mobile devices. In the first paper, D. Damopoulos, S.A. Menesidou, G. Kambourakis, M. Papadaki, N. Clarke and S. Gritzalis present an evaluation study of anomaly-based IDS for mobile devices using machine learning classifiers. A dataset consisting of iPhone users data log files has been created and various classification and validation methods have been evaluated to assess their effectiveness in detecting misuses. The experimental procedure includes and cross-evaluates four machine learning algorithms (i.e. Bayesian Networks, Radial Basis Function, K-Nearest Neighbours and Random Forest), which classify the behaviour of the end-user in terms of Telephone calls, SMS and Web browsing history. The results acquired are very promising, showing the ability of at least one classifier to detect intrusions with a high True Positive Rate of 99.8%. The second paper, “User Identification and Anonymization in 802.11 Wireless LANs” by D. Xu, Y. Wang, X. Shi, and X. Yin, deals with privacy issues for 802.11 Wireless LAN users. It first proposes a new 802.11 user identification approach through enhanced feature selection and generation. Then, it further studies how to provide user anonymity by introducing a set of 802.11 user anonymisation approaches based on bogus traffic injection. Accountability is a very important topic for computer and networking systems, and a key to achieve accountability is a better logging system, which can capture not only the activities but also their relationships. The third paper, “Accountability using Flow-net: Design, Implementation, and Performance Evaluation” by Y. Xiao, K. Meng and D. Takahashi extends the flow-net methodology, which is a logging mechanism for accountability previously proposed by the authors, and presents its design and implementation in wireless networks. They also evaluate the performance of flow-net and compare it to that of audit log files. The fourth paper, “Modelling Security Message Propagation in Delay Tolerant Networks ” by Z. Jia, S. Li, H. Peng, Y. Yang and S. Guo, proposes a security message propagation model for delay tolerant networks formed by vehicles on the road. The goal of the paper is to evaluate how many public keys should be maintained by each node in order to achieve fast message propagation while single hop authentication scheme is used. Network coding provides an excellent solution to maximise throughput in various networks. Because of its simplicity and high efficiency, the idea of network coding can also be used for designing lightweight key distribution schemes for wireless ad hoc network. The fifth paper, “A key distribution scheme using network coding for mobile ad hoc network” by J. Liu, R. Du, J. Chen and K. He, presents a key distribution scheme that exploits the inherent security properties of network coding. The new scheme relies on simple XOR network coding operations to provide data confidentiality and as well use message authentication codes to guarantee the integrity of the distributed keys. Recently, vehicular ad-hoc network (VANET) has emerged as a promising approach to increasing road safety and efficiency. However, the attractive features of VANET inevitably incur higher risks for abuse if we do not take into account security and privacy considerations before the wide deployment of such network. It would jeopardise the public safety and become the main barrier to the acceptance of such a new technology. The last two papers focus on the security and privacy issues in VANETs. In the sixth paper, “LPA: A New Location-based Privacy-preserving Authentication Protocol in VANET” by X. Xue and J. Ding, a novel location-based authentication protocol for conditional privacy preservation in VANETs is proposed. By utilising location information and layered security scheme, the large storage overhead problem in anonymous certificates-based protocols and the long verification time problem in group signature-based protocols are solved. The seventh paper, “An Efficient Distributed Key Management Scheme for Group Signature based Anonymous Authentication in VANET” by Y. Sun, Z. Feng, Q. Hu and J. Su, proposes a distributed key management (DKM) scheme based on Group Signature for anonymous authentication in VANETs. The goal of the paper is to prevent vehicles from leaking the value of the updated group secret key to the regional group manager during the group key updating process. Subsequently, it can avoid the buck-passing between vehicles and regional group managers when the malicious messages are detected. In closing, we would like to thank all the authors who have submitted their research work to this special issue. We would also like to acknowledge the contribution of many experts in the field who have participated in the review process and provided helpful suggestions to the authors on improving the content and presentation of the papers. We would also like to express our gratitude to the Editor-in-Chief, Dr. Hsiao-Hwa Chen for his support and help in bringing forward this special issue. We hope you will enjoy the papers in this collection. Prof. Xiaodong Lin received the Ph.D. degree in information engineering from Beijing University of Posts and Telecommunications, Beijing, China, in 1998 and the Ph.D. degree (with Outstanding Achievement in Graduate Studies Award) in electrical and computer engineering from the University of Waterloo, Waterloo, ON, Canada, in 2008. He is currently an assistant professor of information security with the Faculty of Business and Information Technology, University of Ontario Institute of Technology, Oshawa, ON, Canada. His research interests include wireless network security, computer forensics, software security, and applied cryptography. Dr. Lin was the recipient of a Natural Sciences and Engineering Research Council of Canada (NSERC) Canada Graduate Scholarships (CGS) Doctoral and the Best Paper Awards of the 18th International Conference on Computer Communications and Networks (ICCCN 2009), the 5th International Conference on Body Area Networks (BodyNets 2010), the 3rd International Conference on Forensic Applications and Techniques in Telecommunications, Information and Multimedia (e-Forensics 2010), and IEEE International Conference on communications (ICC 2007). He is a member of IEEE. Prof. Jianwei Liu received his Ph.D. in communication engineering from Xidian University, China in 1998, and his B.S. and M.S. degrees in electronic engineering from Shandong University, China in 1985 and 1988. He is currently a professor and vice dean of School of Electronic and Information Engineering of Beihang University. His current research interests include the security of wireless and mobile communication network and computer network. He is a senior member of the Chinese Institute of Electronics and director of the Chinese Association for Cryptologic Research. Prof. Stefanos Gritzalis is a Professor at the Dept. of Information and Communication Systems Engineering, University of the Aegean, Greece and the Director of the Lab. of Information and Communication Systems Security. He also serves as the Special Secretary at the Greek Ministry of Administrative Reform and Electronic Governance. He holds a BSc in Physics, an MSc in Electronic Automation, and a PhD in Information and Communications Security from the Dept. of Informatics and Telecommunications, University of Athens, Greece. He has been involved in several national and EU funded R&D projects. His published scientific work includes 30 books or book chapters, 90 journals and more than 120 international refereed conference and workshop papers. The focus of these publications is on Information and Communications Security and Privacy. His most highly cited papers have more than 1,000 citations. He has been involved in more than 30 international conferences and workshops as General Chair or Program Committee Chair. He has served on more than 230 Program Committees of international conferences and workshops. He is an Editor-in-Chief or Editor or Editorial Board member for 15 journals. He has supervised 10 PhD dissertations. He was an elected Member of the Board (Secretary General, Treasurer) of the Greek Computer Society. His professional experience includes senior consulting and researcher positions in a number of private and public institutions. He is a Member of the ACM, and the IEEE.
Xiaodong Lin 0001, Jianwei Liu 0001, Stefanos Gritzalis
Secur. Commun. Networks2
2012 A key distribution scheme using network coding for mobile ad hoc network
abstract
ABSTRACT Network coding offers an excellent solution for maximizing throughput in various networks. Because of its simplicity and high efficiency, the idea of network coding can also be used for designing lightweight key distribution schemes for wireless ad hoc network. This paper presents a key distribution scheme that exploits the inherent security properties of network coding. The new scheme relies on simple XOR network coding operations to provide data confidentiality and uses message authentication codes to guarantee the integrity of the distributed keys. We also show that our scheme can resist a series of attacks in wireless ad hoc network and has better performance compared with previous schemes proposed in the literature. Copyright © 2011 John Wiley & Sons, Ltd.
Jianwei Liu 0001, Ruiying Du, Jing Chen 0003, Kun He 0008
Secur. Commun. Networks1
2010 A Probabilistic Approach for Improving TCP Fairness across Multiple Contending WLANs
abstract
Contention among multiple nearby WLANs in urban areas may cause severe TCP unfairness, where some TCP flows can achieve very high throughput at the expense of starving others. This unfairness results from the fact that different physical nodes conveying TCP flows at a wireless bottleneck may have different channel observations and consequently they may provide inconsistent feedbacks to the TCP sources. Existing solutions to this problem try to synchronize channel observations of contending nodes by exchanging control messages among them. They rely on the assumption that these nodes are within each other''s transmission range, which however may not always hold. In this paper, we propose a new approach, called Wireless Probabilistic Drop (WPD), to improve TCP fairness without requiring direct communication among nodes. In WPD, when a node detects congestion, it probabilistically chooses to either drop some packets to resolve the congestion, or aggressively spread the congestion signal to other contending nodes. Each node makes the choice with a probability that is proportional to its flow rate. Henceforth, high-rate flows tend to perform rate reduction more often, and low-rate flows are more likely to increase their flow rates. Eventually, all flows passing the bottleneck are expected to get a fair share of the channel bandwidth. Extensive simulations in ns-2 demonstrate that WPD can significantly improve fairness among TCP flows across multiple contending WLANs.
Ming Zhang 0028, S. M. Iftekharul Alam, Shigang Chen, Jianwei Liu 0001
GLOBECOM4
2010 Shorter Verifier-Local Revocation Group Signature with Backward Unlinkability
Lingbo Wei, Jianwei Liu 0001
Pairing2
2007 A Key Management and Authentication Model for Ad hoc Network
abstract
A key management and authentication model is proposed based on elliptic curve combined public key scheme and threshold cryptosystem. In the initialization phase, a trusted authentication centre is needed, while in the operation phase, the key update, revocation, and the shared private-seed-key matrix update are self-organized. Based on the model, an authentication and key agreement protocol without public key transfer and certificate support is proposed. Compared with the certificate-based and the identity-based models, the new model is more suitable for the privacy and authentication in secure ad hoc network.
Jianwei Liu 0001, Keqiang Guo
PIMRC1