VLDB 2026 Research / reviewers in the wild / expert
Zhenfeng Zhang
dblp:43/4074
· DBLP profile ↗
109ranked-venue papers
8as first author
36since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 75 · 5 first-author · 21 since 2021Applied, interdisciplinary, general and emerging computing · 12 · 1 first-author · 7 since 2021Systems, architecture and hardware · 5 · 2 since 2021Computer networks · 5 · 3 since 2021Databases, data management, data science and information retrieval · 3Theory of computation · 3 · 1 since 2021Software engineering, systems software and programming languages · 2Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Data Scaling Laws for Block-Sparse Training
Zhenfeng Zhang, Yunquan Zhang, Daning Cheng |
ICPR (4) | 2 |
| 2026 | Authorized multi-key fully homomorphic encryption scheme with compact ciphertext
Tanping Zhou, Hongjian Yang, Long Chen 0018, Zhenfeng Zhang |
Des. Codes Cryptogr. | 4 |
| 2026 | Analysis of key reuse security for Aigis.KEM
Ke Wang 0043, Haodong Jiang, Zhenfeng Zhang, Long Chen 0018, Huiqin Xie |
Theor. Comput. Sci. | 3 |
| 2025 | BFT-MS: Asynchronous BFT Protocol Using Bounded Memory
Yuan Lu 0001, Zhenfeng Zhang |
SecureComm (5) | 4 |
| 2025 | A Comprehensive Analysis of the AKMA+ ProtocolabstractWith the rapid advancement of 5G networks and the increasing demand for secure application access, the Authentication and Key Management for Applications (AKMA) framework was developed by the 3rd Generation Partnership Project (3GPP) to provide unified authentication and key management for diverse 5G services. In response to the security and privacy concerns identified in the current AKMA protocol, as outlined in 3GPP TR 33.835, Yang et al. proposed an enhanced, standard-compatible 5G AKMA protocol known as AKMA+ [14].This paper presents a comprehensive analysis of AKMA+, discovering two critical vulnerabilities: (1) the compromise of the AKMA Anchor Function (AAnF), which enables adversaries to impersonate legitimate users; and (2) the persistent storage of multiple anchor keys, which heightens the risk of key exposure. These vulnerabilities arise from the reliance on the authentication framework inherent in existing AKMA+ models. This architectural dependency introduces fundamental security risks that cannot be adequately mitigated through incremental modifications to the current design.Furthermore, we observe that AKMA+ faces challenges in aligning with the standard account-based authentication model, which is incompatible with existing user practices within information systems. Additionally, we find that providing account-based authentication functionality without compromising privacy poses significant difficulties1. Yueming Li, Zhenfeng Zhang |
TrustCom | 3 |
| 2025 | OSKR/OKAI: Systematic Optimization of Key Encapsulation Mechanisms from Module Lattice
Shiyu Shen 0001, Zhichuang Liang, Jieyu Zheng, Hanyu Wei, Yang Wang 0050, Zhenfeng Zhang, Yunlei Zhao |
J. Comput. Sci. Technol. | 8 |
| 2025 | $\mathsf {JUMBO}$JUMBO: Fully Asynchronous BFT Consensus Made Truly ScalableabstractRecent progresses in asynchronous Byzantine fault-tolerant (BFT) consensus, e.g.$\mathsf {Dumbo}\textrm {-}\mathsf {NG}$(CCS' 22) and$\mathsf {Tusk}$(EuroSys' 22), show promising performance through decoupling transaction dissemination and block agreement. However, when executed with a larger number$n$of nodes, like several hundreds, they would suffer from significant degradation in performance. Their dominating scalability bottleneck is the huge authenticator complexity: each node has to multicast$\mathcal {O}(n)$quorum certificates (QCs) and subsequently verify them for each block. This paper systematically investigates and resolves the above scalability issue. We first propose a signature-free asynchronous BFT consensus$\mathsf {FIN}\textrm {-}\mathsf {NG}$that adapts a recent signature-free asynchronous common subset protocol FIN (CCS' 23) into the state-of-the-art framework of concurrent broadcast and agreement. The liveness of$\mathsf {FIN}\textrm {-}\mathsf {NG}$relies on our non-trivial redesign of FIN's multi-valued validated Byzantine agreement towards achieving optimal quality.$\mathsf {FIN}\textrm {-}\mathsf {NG}$greatly improves the performance of FIN and already outperforms$\mathsf {Dumbo}\textrm {-}\mathsf {NG}$in most deployment settings. To further overcome the scalability limit of$\mathsf {FIN}\textrm {-}\mathsf {NG}$due to$\mathcal {O}(n^{3})$messages, we propose$\mathsf {JUMBO}$, a scalable instantiation of$\mathsf {Dumbo}\textrm {-}\mathsf {NG}$, with only$\mathcal {O}(n^{2})$complexities for both authenticators and messages. We use various aggregation and dispersal techniques for QCs to significantly reduce the authenticator complexity of original$\mathsf {Dumbo}\textrm {-}\mathsf {NG}$implementations by up to$\mathcal {O}(n^{2})$orders. Finally, we implement our designs in Golang and experimentally demonstrated their enhanced scalability with hundreds of Amazon's AWS instances.$\mathsf {JUMBO}$and FIN-NG significantly outperform the state-of-the-art in (nearly) all deployment settings. Especially, when$n\ge$196,$\mathsf {JUMBO}$can attain a throughput that is more than 4× that of FIN and$\mathsf {Dumbo}\textrm {-}\mathsf {NG}$. Yuan Lu 0001, Zhenliang Lu, Qiang Tang 0005, Zhenfeng Zhang |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | ThPlA: Threshold Passwordless Authentication Made Usable and ScalableabstractPasswordless user authentication schemes with FIDO as the standard have been widely deployed in web applications. Users use hardware tokens to store their identity credentials (i.e., signing keys) and implement strong authentication through a challenge-response mechanism, avoiding the security risks associated with traditional password-based authentication. Distributed Web services can greatly alleviate the system reliability problem caused by single points of failure, and thus have received increasing attention and research. In distributed systems, resources are distributed across multiple servers, and users must interact with them (or a subset of them in thresholding) to obtain network services. User authentication among the distributed (threshold) systems also poses a challenge: how to ensure security and ease of use at the same time? In particular, users need to authenticate to multiple servers when accessing distributed services, and in the case of using FIDO authentication, users need to authenticate to each server using challenge-response authentication, which will greatly reduce the user experience. In this work, we propose the concept namedThreshold Passwordless Authentication(ThPlA) to address this issue. ThPlA allows users to authenticate to at-of-nthresholding system. ThPlA is designed to be compatible with existing FIDO tokens and requires no extra hardware modifications; the user only needs to interact with the hardware token once during an authentication session; and on the service side, the servers do not need to communicate with each other. ThPlA is based on the component namedNon-interactive Threshold Nonce Generation(NI-ThNG), which extends the two-party challenge-response mechanism tot-of-nsettings. We provide a formal definition of ThPlA and NI-ThNG and give practical constructions. We also provide a performance evaluation of ThPlA and NI-ThNG, respectively. Our experimental results show that the schemes are efficient and practical for real-world applications, even in large-scale distributed systems. Qianwen Gao, Yuan Lu 0001, Kunpeng Bai, Zhenfeng Zhang, Yichi Tu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | MPC-in-the-Head Framework without Repetition and its Applications to the Lattice-based CryptographyabstractThe MPC-in-the-Head framework has been proposed as a solution for Non-Interactive Zero-Knowledge Arguments of Knowledge (NIZKAoK) due to its efficient proof generation. However, most existing NIZKAoK constructions using this approach require multiple MPC evaluations to achieve negligible soundness error, resulting in proof size and time that are asymptotically at least λ times the size of the circuit of the NP relation. In this paper, we propose a novel method to eliminate the need for repeated MPC evaluations, resulting in a NIZKAoK protocol for any NP relation that we call Diet. The proof size and time of Diet are asymptotically only polylogarithmic with respect to the size of the circuit C of the NP relation, but are independent of the security parameter λ. Hence, both the proof size and time can be significantly reduced.Moreover, Diet offers promising concrete efficiency for proving Learning With Errors (LWE) problems and its variants. Our solution provides significant advantages over other schemes in terms of both proof size and proof time, when considering both factors together. Specifically, Diet is a promising method for proving knowledge of secret keys for lattice-based key encapsulation mechanisms (KEMs) such as Frodo and Kyber, offering a practical solution to future post-quantum certificate management. For Kyber 512, our implementation achieves an online proof size of 83.65 kilobytes (KB) with a preprocessing overhead of 152.02KB. The implementation is highly efficient, with an online proof time of only 0.68 seconds and a preprocessing time of 0.81 seconds. Notably, our approach provides the first reported implementation of proving knowledge of secret keys for Kyber 512 using post-quantum primitives-based zero-knowledge proofs. Weihao Bai, Qianwen Gao, Zhenfeng Zhang |
SP | 4 |
| 2024 | Committed-programming reductions: formalizations, implications and relations
Jiang Zhang 0001, Yu Yu 0001, Dengguo Feng, Shuqin Fan, Zhenfeng Zhang |
Sci. China Inf. Sci. | 5 |
| 2024 | Liveness Attacks On HotStuff: The Vulnerability Of Timer Doubling MechanismabstractAbstract Byzantine fault-tolerant (BFT) consensus protocols are essential in distributed computing. Most partially synchronous BFT protocols proceed in views and rely on a view synchronizer module to guarantee liveness by synchronizing honest replicas to the same view. HotStuff is a leading BFT consensus protocol known for achieving linear view change and optimistic responsiveness. To achieve these desirable properties, HotStuff relies on a candidate solution for the view synchronizer based on a recomposed timer doubling mechanism. However, a formal analysis of this mechanism is currently lacking. This paper delves into HotStuff with the recomposed timer doubling mechanism. To facilitate accurate analysis, we introduce a new specification for the view synchronizer, incorporating two paths for view switching as in HotStuff’s setting. Surprisingly, we observe that the adversary can disrupt the view synchronization and launch a liveness attack, stalling the confirmation process. Besides, the adversary can further recover or control the confirmation process at will. A repairment that retains the desirable feature of HotStuff is also presented. We simulate the liveness attack and the repairment, demonstrating their effectiveness. Specifically, the liveness attack can cause HotStuff’s throughput to drop and remain at 0. When equipped with our repairment, HotStuff can resist the attack and retain the throughput performance. Zhenfeng Zhang |
Comput. J. | 3 |
| 2024 | Key Reuse Attacks on Post-quantum Cryptosystems, RevisitedabstractAbstract The National Institute of Standards and Technology (NIST) has been working on standardization of post-quantum cryptography and is approaching the end of round-3 evaluation of algorithms. Key reuse security evaluation is an important part of algorithm evaluation. In order to evaluate the key reuse security of candidate IND-CPA PKEs, at Eurocrypt’19, B$\breve{\text{a}}$etu et al. proposed a classical key recovery under plaintext checking attack (KR-PCA) which can recover the reused secret keys by querying an oracle thousands of times. However, the method does not work for cryptosystems which shorten ciphertexts by rounding off the low bits, such as round-3 finalists Kyber and Saber. Subsequently, Dumittan and Vaudenay (ACNS’20) and Qin et al. (ASIACRYPT’21) came up with new effective methods, which require carefully constructed queries. In this paper, we propose an automatic method to recover the reused secret keys of IND-CPA PKEs in Kyber and Saber. Instead of constructing queries carefully, our method uses automated search combined with an optimized bruteforce. The effect and cost of the method depend on the specific parameters. In particular, we can recover the secret keys after thousands of queries in all parameter sets, which is comparable with the current best result. Ke Wang 0043, Zhenfeng Zhang, Haodong Jiang, Huiqin Xie, Lidong Han |
Comput. J. | 2 |
| 2024 | Generalized splitting-ring number theoretic transform
Zhichuang Liang, Yunlei Zhao, Zhenfeng Zhang |
Frontiers Comput. Sci. | 3 |
| 2024 | BSRA: Blockchain-Based Secure Remote Authentication Scheme for Fog-Enabled Internet of ThingsabstractThe insufficient trustworthiness of fog nodes in fog computing leads to new security and privacy problems in communication between entities. Existing authentication schemes rely on a trusted third party, or assume that fog nodes are trustworthy, or the authentication overhead is high, which is inconsistent with the characteristics of fog computing. To solve the problem of secure communication in the fog computing environment, we propose an efficient blockchain-based secure remote authentication protocol for the fog-enabled Internet of Things (BSRA). Specifically, blockchain is introduced to construct distributed trust for the fog computing environment. Only lightweight cryptographic primitives, such as physical unclonable functions (PUFs) and cryptographic hash functions, are exploited to design the authentication scheme. In addition, we use temporary identities and the authentication-piggybacking-synchronization to ensure the anonymity and effectiveness of the authentication scheme. We conduct security analysis to demonstrate that BSRA can provide guarantees against various known attacks. We also evaluate the performance of BSRA from several aspects, and the results show that BSRA is effective. Yimin Guo 0001, Zhenfeng Zhang, Yajun Guo, Ping Xiong 0001 |
IEEE Internet Things J. | 2 |
| 2024 | Lattice-Based Programmable Hash Functions and Applications
Zhenfeng Zhang |
J. Cryptol. | 3 |
| 2024 | Sidechains With Optimally Succinct ProofabstractSidechains have been widely used to improve the interoperability and scalability of blockchain systems. Despite several interesting sidechain constructions have been proposed in the literature, they suffer from the following downsides: (1) their designs do not easily support pluggable consensus mechanisms, and (2) their communication and storage costs for cross-chain operations are not yet optimized. In this work, we first propose Ge-Co, a generic sidechain construction to realize secure asset transfers between blockchains, supporting different consensus algorithms, such as Proof-of-Stake (PoS) and Proof-of-Work (PoW). Our design is built on top of the proposed voting committee selection approach and threshold signature schemes (TSS) and meanwhile, it achieves optimally succinct and constant proof size, only yielding lightweight communication and storage costs. Ge-Co works in the semi-adaptive corruption model. To provide stronger security, we further propose PoS-Co, a PoS-based sidechain construction in the fully-adaptive corruption model. PoS-Co is based on the proposed anonymous committee selection approach, and preserves optimally succinct proof. We also formally prove that Ge-Co can achieve the security properties of atomicity and timeliness. Finally, we develop a proof-of-concept (PoC) implementation for Ge-Co, and the results demonstrate that the design is efficient and practical. Lingyuan Yin, Jing Xu 0002, Kaitai Liang, Zhenfeng Zhang |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Post-quantum Security of Key Encapsulation Mechanism Against CCA Attacks with a Single Decapsulation Query
Haodong Jiang, Zhi Ma 0001, Zhenfeng Zhang |
ASIACRYPT (4) | 3 |
| 2023 | Bit Security Analysis of Lattice-Based KEMs Under Plaintext-Checking Attacks
Ruiqi Mi, Haodong Jiang, Zhenfeng Zhang |
SAC | 3 |
| 2023 | Two-Party Signing For ISO/IEC Digital Signature StandardsabstractAbstract Two-party signing can be used to provide a high level of key protection especially in the blockchain systems where the safety of money relies on the safety of the signing key. With a two-party signing protocol, the signing key is distributed among two devices, thus the funds are safe as long as one device remains uncorrupted. In this paper, we study the two-party signing protocols for all ISO/IEC signature standards. The mechanisms based on elliptic curve discrete logarithm in ISO/IEC can be divided into three types: Schnorr-type, Elliptic Curve Digital Signature Algorithm (ECDSA)-type and SM2-type. There have already been efficient two-party protocols based on Schnorr signature scheme which can be easily extended into all Schnorr-type standards. However, it is particularly hard to construct efficient distributed SM2-type and ECDSA-type protocols due to their nonlinear signing equations. In this paper, we present the first secure and efficient two-party protocol over SM2-type signature standard. We prove its security in the generic group model. We then construct a more efficient two-party ECDSA protocol that is secure in the generic group model and outperforms all previous works. Guofeng Tang, Zhenfeng Zhang |
Comput. J. | 2 |
| 2023 | Interopera: An Efficient Cross-Chain Trading ProtocolabstractAbstract With the rapid development of blockchains, blockchain systems are moving on from a stand-alone manner to cross-chain interactions, and achieving interoperability is emerging as one of the essential features of blockchains. Unfortunately, existing mechanisms such as XCLAIM mostly focus on exchanging assets between two blockchains and it is slow and expensive to process each cross-chain trade among more than two blockchains as multiple transactions are required. In this paper, we present Interopera, a decentralized and efficient cross-chain trading protocol among two or more blockchains. Interopera atomically processes each cross-chain trade faster and more cheaply with fewer transactions by a two-phase lock/unlock process. Interopera also achieves efficient cross-chain communication by our presented Partitioned-FlyClient and Tx-FlyClient. Partitioned-FlyClient is based on FlyClient but more efficient with smaller proof size, reducing the storage and bandwidth overheads. Tx-FlyClient maintains efficiency even when cross-chain trades become frequent, instead of other mechanisms only being effective under low cross-chain trades volumes. We also develop a proof-of-concept implementation and the results demonstrate high efficiency of our protocol. Lingyuan Yin, Jing Xu 0002, Zhenfeng Zhang |
Comput. J. | 3 |
| 2023 | An optimisation for a two-round good-case latency protocolabstractAbstract Byzantine broadcast is a fundamental primitive in distributed computing. A highly efficient Byzantine broadcast protocol, motivated by the real‐world performance of practical state machine replication protocols, is increasingly needed. This article focuses on the state‐of‐the‐art partially synchronous Byzantine broadcast protocol proposed by Abraham et al. (PODC’21), which achieves optimal good‐case latency of two rounds and optimal resilience of n ≥ 5 f − 1 in this setting. Each step of the protocol is analysed, and then improved by cutting down the number of messages required to be collected and transmitted in the heaviest step of the protocol by about half , without adding any extra cost. This benefits from a new property, named “spread”, that we identify and extract from the original protocol. It helps us to eliminate non‐essential work in its view‐change procedure. The authors also show that no further reduction is possible without violating security. A prototype is implemented and the performances of improved and original protocols are evaluated in the same environment. The results show that our improvement can achieve about 50% lower communication cost and 40% shorter latency at a scale of 100 replicas. The latency gap becomes wider as the scale further increases. Zhenfeng Zhang, Weiyu Jiang, Xiaoman Shawn Li, Jiang Han |
IET Inf. Secur. | 2 |
| 2023 | Illu-NASNet: unsupervised illumination estimation based on dense spatio-temporal smoothness
Zhenfeng Zhang, Chuhua Huang, Renjing Huang |
Multim. Syst. | 1 |
| 2023 | Escaping From Consensus: Instantly Redactable Blockchain Protocols in Permissionless SettingabstractBlockchain technologies have drawn a lot of attentions, and its immutability is paramount to applications requiring persistent records. However, tremendous real-world incidents have exposed the harm of strict immutability, such as the illicit data stored on Bitcoin and the loss of millions of dollars in vulnerable smart contracts. Moreover, “Right to be Forgotten” has been imposed in new General Data Protection Regulation (GDPR) of European Union, which is incompatible with blockchain's immutability. Therefore, it is imperative to design efficient redactable blockchain in a controlled way. In this paper, we present a generic design of redactable blockchain protocols in the permissionless setting, applied to both proof-of-stake and proof-of-work blockchains. Our protocol can (1) maintain the same adversary bound requirement as the underlying blockchain, (2) support various network environments, (3) offer public verifiability for any redaction, and (4) achieve instant redaction, even only within one slot in the best case, which is desirable for redacting harmful data. Furthermore, we define the first ideal protocol of redactable blockchain and conduct security analysis following the language of universal composition. Finally, we develop a proof-of-concept implementation showing that the overhead remains minimal for both online and re-spawning nodes, which demonstrates the high efficiency of our design. Xinyu Li 0002, Jing Xu 0002, Lingyuan Yin, Yuan Lu 0001, Qiang Tang 0005, Zhenfeng Zhang |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2023 | Practical Algorithm Substitution Attacks on Real-World Public-Key CryptosystemsabstractThe revelations about massive surveillance have created significant interest in algorithm substitution attack (ASA), where an honest implementation of a cryptographic primitive is replaced by a subverted one which can help “big brother" to break cryptographic security while generating output indistinguishable from the honest output. The current known ASAs on public-key cryptography are either dedicated for a type of concrete constructions with specific internal, or restrictive when applying to the real-word cryptographic standards (Ateniese et al., ACM CCS’15; Russell et al., ACM CCS’17; Chen et al., ASIACRYPT’20). In this paper, we first present a practical undetectable substitution for a general randomized algorithm with certain structure such that the randomness can be revealed to the big brother. Then, instantiating this randomized algorithm, we present a series of ASAs on core primitives in public-key cryptography including public-key encryption, key encapsulation mechanism, key exchange, and digital signature. In particular, our ASAs are universal in the sense that they do not rely on the internal description of the underlying cryptographic algorithm. Moreover, our ASAs are also practical since they can affect not only the widely deployed cryptographic standards, but also the ongoing NIST post-quantum standards. Haodong Jiang, Jiang Han, Zhenfeng Zhang, Zhi Ma 0001, Hong Wang 0027 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Efficient Lattice-Based Threshold Signatures With Functional InterchangeabilityabstractA threshold signature scheme distributes the ability to generate signatures through distributed key generation and signing protocols. A threshold signature scheme should be functionally interchangeable, meaning that a signature produced by a threshold scheme should be verifiable by the same algorithm used for non-threshold signatures. To resist future attacks from quantum adversaries, lattice-based threshold signatures are desirable. However, the performance of existing lattice-based threshold signing protocols is still far from practical. This paper presents the first lattice-basedt-out-of-nthreshold signature scheme with functional interchangeability that has been implemented. To build ant-out-of-naccess structure for arbitraryt≤n, we first present a novelt-out-of-nversion of the SPDZ MPC protocol. For high concrete efficiency, we avoid using the MPC protocol to evaluate hash operations. Moreover, we design an efficient distributed rejection sampling protocol. As a consequence, the online phase of our distributed signing protocol takes only 0.5 seconds in the two-party setting and 7.3 seconds in the 12-party setting according to our implementation. As a byproduct, our scheme also presents a periodic key refreshment mechanism and offers proactive security. Guofeng Tang, Long Chen 0018, Zhenfeng Zhang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | Dumbo-NG: Fast Asynchronous BFT Consensus with Throughput-Oblivious LatencyabstractDespite recent progresses of practical asynchronous Byzantine-fault tolerant (BFT) consensus, the state-of-the-art designs still suffer from suboptimal performance. Particularly, to obtain maximum throughput, most existing protocols \rev with guaranteed linear amortized communication complexity require each participating node to broadcast a huge batch of transactions, which dramatically sacrifices latency. Worse still, the ƒ slowest nodes' broadcasts might never be agreed to output and thus can be censored (where ƒ is the number of faults). Implementable mitigation to the threat either uses computationally costly threshold encryption or incurs communication blow-up by letting the honest nodes to broadcast redundant transactions, thus causing further efficiency issues. Yingzi Gao, Yuan Lu 0001, Zhenliang Lu, Qiang Tang 0005, Jing Xu 0002, Zhenfeng Zhang |
CCS | 6 |
| 2022 | Efficient Asynchronous Byzantine Agreement without Private SetupsabstractEfficient asynchronous Byzantine agreement (BA) protocols were mostly studied with private setups, e.g., pre-setup threshold cryptosystem. Challenges remain to reduce the large communication in the absence of such setups. Recently, Abraham et al. (PODC’21) presented the first asynchronous validated BA (VBA) with expected $\mathcal{O}$(n3) messages and $\mathcal{O}$ (1) rounds, relying on only public key infrastructure (PKI) setup, but the design still costs $\mathcal{O}$ (λn3logn) bits. Here n is the number of parties, and λ is a cryptographic security parameter.In this paper, we reduce the communication of private-setup free asynchronous BA to expected $\mathcal{O}$(λn3) bits. At the core of our design, we give a systematic treatment of common randomness protocols in the asynchronous network, and proceed as:•We give an efficient reasonably fair common coin protocol in the asynchronous setting with only PKI setup. It costs only $\mathcal{O}$ (λn3) bit and $\mathcal{O}$(1) rounds, and ensures that with at least 1/3 probability, all honest parties can output a common bit that is as if randomly flipped. This directly renders more efficient private-setup free asynchronous binary agreement (ABA) with expected $\mathcal{O}$(λn3) bits and $\mathcal{O}$(1) rounds.•Then, we lift our common coin to attain perfect agreement by using a single ABA. This gives us a reasonably fair random leader election protocol with expected $\mathcal{O}$(λn3) communication and expected constant rounds. It is pluggable in all existing VBA protocols (e.g., Cachin et al., CRYPTO’01; Abraham et al., PODC’19; Lu et al., PODC’20) to remove the needed private setup or distributed key generation (DKG). As such, the communication of private-setup free VBA is reduced to expected $\mathcal{O}$(λn3) bits while preserving fast termination in expected $\mathcal{O}$(1) rounds. Moreover, our result paves a generic path to private-setup free asynchronous BA protocols, as it is not restricted to merely improve Abraham et al.’s specific VBA protocol (PODC’21).Our results and techniques could be found useful and interesting for a broad array of applications such as asynchronous DKG and DKG-free asynchronous random beacon that is friendly for dynamic participation and reconfiguration. Yingzi Gao, Yuan Lu 0001, Zhenliang Lu, Qiang Tang 0005, Jing Xu 0002, Zhenfeng Zhang |
ICDCS | 6 |
| 2022 | Leopard: Towards High Throughput-Preserving BFT for Large-scale SystemsabstractWith the emergence of large-scale decentralized applications, a scalable and efficient Byzantine Fault Tolerant (BFT) protocol of hundreds of replicas is desirable. Although the throughput of existing leader-based BFT protocols has reached a high level of 105requests per second for a small scale of replicas, it drops significantly when the scale increases.This paper focuses on preserving high throughput as the BFT protocol’s scale is increasing. We identify and analyze a major bottleneck to leader-based BFT protocols due to the excessive workload of the leader at large scales. A new metric of scaling factor is defined to capture whether a BFT protocol will get stuck when the scale gets larger, which can be used to measure the performance of throughput and scalability of BFT protocols. We propose "Leopard", the first leader-based BFT protocol that scales to multiple hundreds of replicas, and more importantly, preserves high throughput. We remove the bottleneck by introducing a technique of achieving the ideal constant scaling factor, which takes full advantage of the idle resource and balances the workload of the leader among all replicas. We implemented Leopard and evaluated its performance compared to HotStuff, a state-of-the-art leader-based BFT protocol. We ran extensive experiments with up to 600 replicas. The results show that Leopard achieves significant throughput improvements. In particular, the throughput of Leopard remains at a high level of 105when the scale is 600. It achieves a 5× throughput over HotStuff when the scale is 300, and the gap becomes wider as the scale further increases. Qiang Tang 0005, Zhenfeng Zhang, Zhiyang Zhao |
ICDCS | 4 |
| 2022 | Speeding Dumbo: Pushing Asynchronous BFT Closer to Practice
Bingyong Guo, Yuan Lu 0001, Zhenliang Lu, Qiang Tang 0005, Jing Xu 0002, Zhenfeng Zhang |
NDSS | 6 |
| 2022 | SecFHome: Secure remote authentication in fog-enabled smart home environment
Yimin Guo 0001, Zhenfeng Zhang, Yajun Guo |
Comput. Networks | 2 |
| 2022 | Anonymous Authenticated Key Agreement and Group Proof Protocol for Wearable ComputingabstractWearable computing has been used in a wide range of applications. But wearable computing often suffers from various security and privacy issues. To solve these issues, many effective authentication schemes have been proposed. However, most of the existing schemes are vulnerable to various known attacks (such as desynchronization attack, privileged-insider attack, and anonymity attack), or require high computation and communication costs, and are not suitable for resource-constrained wearable devices, or simultaneous verification of multiple wearable devices is not supported. Therefore, in this paper, we propose a new anonymous authentication and group proof protocol for wearable computing, which achieves mutual authentication between the wearable device and user and between user and cloud server, and generates a group proof for multiple wearable devices. Further, we extend the Real-Or-Random (ROR) model to support anonymity and group proof, and formally prove that the proposed scheme is provably secure under the extended security model. In addition, the informal security analysis is demonstrated that the proposed scheme is more resilient against known attacks. Finally, compared with some existing schemes, the proposed scheme offers more functionality features and requires less communication and computation costs. Yimin Guo 0001, Zhenfeng Zhang, Yajun Guo |
IEEE Trans. Mob. Comput. | 2 |
| 2021 | On the Non-tightness of Measurement-Based Reductions for Key Encapsulation Mechanism in the Quantum Random Oracle Model
Haodong Jiang, Zhenfeng Zhang, Zhi Ma 0001 |
ASIACRYPT (1) | 2 |
| 2021 | Privacy-Preserving and Standard-Compatible AKA Protocol for 5G
Zhenfeng Zhang, Yongquan Xie |
USENIX Security Symposium | 2 |
| 2021 | Superword: A honeyword system for achieving higher security goals
Yimin Guo 0001, Zhenfeng Zhang, Yajun Guo |
Comput. Secur. | 2 |
| 2021 | Accountable Proxy Re-Encryption for Secure Data SharingabstractProxy re-encryption (PRE) provides a promising solution for encrypted data sharing in public cloud. When data owner Alice is going to share her encrypted data with data consumer Bob, Alice generates a re-encryption key and sends it to the cloud server (proxy); by using it, the proxy can transform Alice's ciphertexts into Bob's without learning anything about the underlying plaintexts. Despite that existing PRE schemes can prevent the proxy from recovering Alice's secret key by collusion attacks with Bob, due to the inherent functionality of PRE, it is inevitable that the proxy and Bob together are capable to gain and distribute Alices decryption capabilities. Even worse, the malicious proxy can deny that it has leaked the decryption capabilities and has very little risk of getting caught. To tackle this problem, we introduce the concept of Accountable Proxy Re-Encryption (APRE), whereby if the proxy is accused to abuse the re-encryption key for distributing Alice's decryption capability, a judge algorithm can decide whether it is innocent or not. We then present a non-interactive APRE scheme and prove its CPA security and accountability under DBDH assumption in the standard model. Finally, we show how to extend it to a CCA secure one. Zhenfeng Zhang, Jing Xu 0002, Ningyu An, Xiao Lan |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Direct Anonymous Attestation With Optimal TPM Signing EfficiencyabstractDirect Anonymous Attestation (DAA) is an anonymous signature scheme, which allows the Trusted Platform Module (TPM), a small chip embedded in a host computer, to attest to the state of the host system, while preserving the privacy of the user. DAA provides two signature modes: fully anonymous signatures and pseudonymous signatures. One main goal of designing DAA schemes is to reduce the TPM signing workload as much as possible, as the TPM has only limited resources. In an optimal DAA scheme, the signing workload on the TPM will be no more than that required for a normal signature like ECSchnorr. To date, no scheme has achieved the optimal signing efficiency for both signature modes. In this paper, we propose the first DAA scheme which achieves the optimal TPM signing efficiency for both signature modes. In this scheme, the TPM takes only a single exponentiation to generate a signature, and this single exponentiation can be pre-computed. Our scheme can be implemented using the existing TPM 2.0 commands, and thus is compatible with the TPM 2.0 specification. We benchmarked the TPM 2.0 commands needed for three DAA use cases on an Infineon TPM 2.0 chip, and also implemented the host signing and verification algorithm for our DAA scheme on a laptop with 1.80GHz Intel Core i7-8550U CPU. Our experimental results show that our DAA scheme obtains a total signing time of about 144 ms for either signature mode, while with pre-computation we can obtain a signing time of about 65 ms. Based on our benchmark results for the pseudonymous signature mode, our scheme is roughly$2\times $(resp.,$5\times $) faster than the existing DAA schemes supported by TPM 2.0 in terms of total (resp., online) signing efficiency. Kang Yang 0002, Liqun Chen 0002, Zhenfeng Zhang, Christopher J. P. Newton, Bo Yang 0003, Li Xi |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | Dumbo: Faster Asynchronous BFT ProtocolsabstractHoneyBadgerBFT, proposed by Miller et al. [34] as the first practical asynchronous atomic broadcast protocol, demonstrated impressive performance. The core of HoneyBadgerBFT (HB-BFT) is to achieve batching consensus using asynchronous common subset protocol (ACS) of Ben-Or et al., constituted with n reliable broadcast protocol (RBC) to have each node propose its input, followed by n asynchronous binary agreement protocol (ABA) to make a decision for each proposed value (n is the total number of nodes). Bingyong Guo, Zhenliang Lu, Qiang Tang 0005, Jing Xu 0002, Zhenfeng Zhang |
CCS | 5 |
| 2020 | Modular Security Analysis of OAuth 2.0 in the Three-Party SettingabstractOAuth 2.0 is one of the most widely used Internet protocols for authorization/single sign-on (SSO) and is also the foundation of the new SSO protocol OpenID Connect. Due to its complexity and its flexibility, it is difficult to comprehensively analyze the security of the OAuth 2.0 standard, yet it is critical to obtain practical security guarantees for OAuth 2.0. In this paper, we present the first computationally sound security analysis of OAuth 2.0. First, we introduce a new primitive, the three-party authenticated secret distribution (3P-ASD for short) protocol, which plays the role of issuing the secret and captures the token issue process of OAuth 2.0. As far as we know, this is the first attempt to formally abstract the authorization technology into a general primitive and then define its security. Then, we present a sufficiently rich three-party security model for OAuth protocols, covering all kinds of authorization flows, providing reasonably strong security guarantees and moreover capturing various web features. To confirm the soundness of our model, we also identify the known attacks against OAuth 2.0 in the model. Furthermore, we prove that two main modes of OAuth 2.0 can achieve our desired security by abstracting the token issue process into a 3P-ASD protocol. Our analysis is not only modular which can reflect the compositional nature of OAuth 2.0, but also fine-grained which can evaluate how the intermediate parameters affect the final security of OAuth 2.0. Xinyu Li 0002, Jing Xu 0002, Zhenfeng Zhang, Xiao Lan |
EuroS&P | 3 |
| 2020 | Strong Authentication without Temper-Resistant Hardware and Application to Federated Identities
Zhenfeng Zhang, Kang Yang 0002 |
NDSS | 1 |
| 2020 | Key Recovery Under Plaintext Checking Attack on LAC
Ke Wang 0043, Zhenfeng Zhang, Haodong Jiang |
ProvSec | 2 |
| 2020 | Security of Two NIST Candidates in the Presence of Randomness Reuse
Ke Wang 0043, Zhenfeng Zhang, Haodong Jiang |
ProvSec | 2 |
| 2020 | Improved lattice-based CCA2-secure PKE in the standard model
Jiang Zhang 0001, Yu Yu 0001, Shuqin Fan, Zhenfeng Zhang |
Sci. China Inf. Sci. | 4 |
| 2020 | Nudging personalized password policies by understanding users' personality
Yimin Guo 0001, Zhenfeng Zhang, Yajun Guo |
Comput. Secur. | 2 |
| 2020 | Corrigendum to "Breaking the binding: Attacks on the Merkle approach to prove liabilities and its applications" [Computers & Security, Volume 87, 2019, 101585]
Zhenfeng Zhang |
Comput. Secur. | 2 |
| 2020 | Corrigendum to "LPSE: Lightweight password-strength estimation for password meters" [Computers & Security, Volume 73, 2018, Pages 507-518]
Yimin Guo 0001, Zhenfeng Zhang |
Comput. Secur. | 2 |
| 2020 | Corrigendum to "Optiwords: A new password policy for creating memorable and strong password" [Computers & Security, Volume 85, 2019, Pages 423-435]
Yimin Guo 0001, Zhenfeng Zhang, Yajun Guo |
Comput. Secur. | 2 |
| 2020 | Puncturable Signatures and Applications in Proof-of-Stake Blockchain ProtocolsabstractProof-of-stake blockchain protocols are becoming one of the most promising alternatives to the energy-consuming proof-of-work protocols. However, one particularly critical threat in the PoS setting is the well-known long-range attacks caused by secret key leakage (LRSL attack). Specifically, an adversary can attempt to control/compromise accounts possessing substantial stake at some past moment such that double-spend or erase past transactions, violating the fundamental persistence property of blockchain. Puncturable signatures provide a satisfying solution to construct practical proof-of-stake blockchain resilient to LRSL attack, despite of the fact that existent constructions are not efficient enough for practical deployments. In this paper, we provide an in-depth study of puncturable signatures and explore its applications in the proof-of-stake blockchain. We formalize a security model that allows the adversary for adaptive signing and puncturing queries, and show a construction with efficient puncturing operations based on the Bloom filter data structure and strong Diffie-Hellman assumption. The puncturing functionality we desire is for a particular part of message, like prefix, instead of the whole message. Furthermore, we use puncturable signatures to construct practical proof-of-stake blockchain protocols that are resilient to LRSL attack, while previously the forward-secure signature is used to immunize this attack. We implement our scheme and provide experimental results showing that in comparison with the forward-secure signature, our construction performs substantially better on signature size, signing and verification efficiency, significantly on key update efficiency. Xinyu Li 0002, Jing Xu 0002, Xiong Fan, Zhenfeng Zhang |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2019 | Generic Traceable Proxy Re-encryption and Accountable Extension in Consensus Network
Zhenfeng Zhang, Jing Xu 0002, Mingyuan Xia 0003 |
ESORICS (1) | 2 |
| 2019 | Sum-Rate Maximization for D2D and Cellular Hybrid Networks Enhanced by NOMAabstractNon-Orthogonal Multiple Access (NOMA) has recently been conceived as a promising technology for the fifth-generation mobile communication system. In this paper, we apply NOMA into the device-to-device (D2D) and cellular hybrid networks to improve the data rate of the D2D links. Specifically, we formulate a D2D transmission rate maximization problem by jointly considering user pairing and power control under the constraints of the decoding threshold of cellular users. To solve the formulated problem, we first analyze the optimal transmission power of the D2D users. According to the obtained power control strategy, the user pairing problem is transformed into a bipartite graph matching problem, which can be solved optimally by the Hungarian algorithm. Simulation results demonstrate that our algorithm outperforms the existing schemes in terms of data rate. Daosen Zhai, Ruonan Zhang 0001, Zhenfeng Zhang |
HPSR | 4 |
| 2019 | Deep Neural Network based Channel Allocation for Interference-Limited Wireless NetworksabstractCooperative communication in wireless networks has received much attention in both academia and industry. How to effectively allocate and schedule radio resources to improve system performance becomes an important issue of cooperative communication. This paper mainly studies the ultra-low complexity wireless channel allocation algorithm for interference-limited networks. Firstly, we use the traditional sequential convex approximation (SCA) technique to design the channel allocation algorithm. Then, we utilize the characteristics of deep neural network (DNN) that can approximate a complex function with multiple layers of mapping to approximate the SCA-based algorithm. Based on DNN, we design an ultra-low complexity algorithm. Simulation results indicate that the DNN-based algorithm can achieve good performance with ultra-low computation time, which is a feature for practical application. Zhenfeng Zhang, Daosen Zhai, Ruonan Zhang 0001 |
HPSR | 1 |
| 2019 | User Connectivity Maximization for D2D and Cellular Hybrid Networks with Non-Orthogonal Multiple AccessabstractNon-orthogonal multiple access (NOMA) and device-to-device (D2D) are two key technologies of the fifth-generation wireless networks. In this paper, we propose a new D2D-and-NOMA integrated framework, where the D2D users (DUEs) can reuse the spectrum of the cellular users (CUEs) in four NOMA-aided spectrum-sharing modes. In order to fully exploit the potential of the proposed framework, we jointly optimize user pairing and power control to maximize the number of accessed D2D links and meanwhile reduce the total power consumption under the constraints of the decoding thresholds of the DUEs and CUEs. We first analytically obtain the optimal transmission power for each DUE-CUE pair. Then, based on the power control policy, we reformulate the user pairing problem as a min-cost max-flow problem in graph theory and solve it efficiently. Specifically, our proposed algorithm can solve the formulated problem optimally with low complexity. Finally, simulation results indicate that our algorithm can significantly improve the number of accessed D2D links and reduce the power consumption in comparison with the other schemes. Daosen Zhai, Ruonan Zhang 0001, Zhenfeng Zhang, Dawei Wang 0001 |
PIMRC | 4 |
| 2019 | Tighter Security Proofs for Generic Key Encapsulation Mechanism in the Quantum Random Oracle Model
Haodong Jiang, Zhenfeng Zhang, Zhi Ma 0001 |
PQCrypto | 2 |
| 2019 | Non-transferable Proxy Re-encryptionabstractThe traditional security notion of proxy re-encryption (PRE) focuses on preventing the proxy learning anything about the encrypted messages. However, such a basic security requirement is clearly not enough for scenarios where the proxy can collude with Bob. A desirable security goal is, therefore, to prevent a malicious proxy colluding with Bob to re-delegate Alice’s decryption right. In 2005, Ateniese et al. first proposed this intriguing problem called non-transferability, in the sense that the only way for Bob to transfer Alice’s decryption capability is to expose his own secret key. However, no solutions have achieved this property. In this paper, we positively resolve this open problem. In particular, we give the first construction of non-transferable PRE where the attacker is allowed to obtain one pair of keys consisting of Bob’s secret key and the corresponding re-encryption key. Using indistinguishability obfuscation and k-unforgeable authentication as main tools, our scheme is provably secure in the standard model. The essential idea behind our approach is to allow Bob’s secret key to be evoked in the process of decrypting Alice’s ciphertext while hiding the fact that only Bob could decrypt it by the obfuscated program. In addition, we also show a negative result: a CPA secure PRE scheme with ‘error-freeness’ property cannot be non-transferable. Zhenfeng Zhang, Jing Xu 0002, Ningyu An |
Comput. J. | 2 |
| 2019 | Optiwords: A new password policy for creating memorable and strong passwords
Yimin Guo 0001, Zhenfeng Zhang, Yajun Guo |
Comput. Secur. | 2 |
| 2019 | Breaking the binding: Attacks on the Merkle approach to prove liabilities and its applications
Zhenfeng Zhang |
Comput. Secur. | 2 |
| 2019 | Investigating the Multi-Ciphersuite and Backwards-Compatibility Security of the Upcoming TLS 1.3abstractTransport Layer Security (TLS) is one of the most widely used Internet protocols for secure communications. TLS 1.3, the next-generation protocol, is currently under development, with the latest candidate being draft-18. For flexibility and compatibility, TLS supports various ciphersuites and offers configurable selection of multiple protocol versions, which unfortunately opens the door to practical attacks. For example, although TLS 1.3 is now proven secure separately, coexisting with previous versions may be subject to backwards compatibility attacks. In this paper, we present a formal treatment of the multi-ciphersuite and backwards-compatibility security of TLS 1.3 (specifically, draft-18). We introduce a multi-stage security model, covering all known kinds of compositional interactions (w.r.t. ciphersuites and protocol versions) and reasonably strong security notions. Then we dissect the cross-ciphersuite attack regarding TLS 1.2 in our model, and show that the TLS 1.3 handshake protocol satisfies the multi-ciphersuite security, highlighting the strict necessity of including more information in the signature. Furthermore, we demonstrate how the backwards compatibility attack by Jager et al. can be identified owing to our model, and prove that the handshake protocol can achieve our desired strong security if certain countermeasures are adopted. Our treatment is also applicable to analyzing other protocols. Xiao Lan, Jing Xu 0002, Zhenfeng Zhang, Wen Tao Zhu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2018 | Fast Lottery-Based Micropayments for Decentralized Currencies
Zhenfeng Zhang |
ACISP | 2 |
| 2018 | On the Hardness of the Computational Ring-LWR Problem and Its Applications
Long Chen 0018, Zhenfeng Zhang, Zhenfei Zhang |
ASIACRYPT (1) | 2 |
| 2018 | IND-CCA-Secure Key Encapsulation Mechanism in the Quantum Random Oracle Model, Revisited
Haodong Jiang, Zhenfeng Zhang, Long Chen 0018, Hong Wang 0027, Zhi Ma 0001 |
CRYPTO (3) | 2 |
| 2018 | LPSE: Lightweight password-strength estimation for password meters
Yimin Guo 0001, Zhenfeng Zhang |
Comput. Secur. | 2 |
| 2018 | Protect white-box AES to resist table composition attacksabstractWhite‐box cryptography protects cryptographic software in a white‐box attack context (WBAC), where the dynamic execution of the cryptographic software is under full control of an adversary. Protecting AES in the white‐box setting attracted many scientists and engineers, and several solutions emerged. However, almost all these solutions have been badly broken by various efficient white‐box attacks, which target compositions of key‐embedding lookup tables. In 2014, Luo, Lai, and You proposed a new WBAC‐oriented AES implementation, and claimed that their implementation is secure against both Billet et al . 's attack and De Mulder et al . 's attack. In this study, based on the existing table‐composition‐targeting cryptanalysis techniques, the authors show that the secret key of the Luo–Lai–You (LLY) implementation can be recovered with a time complexity of about 2 44 . Furthermore, the authors propose a new white‐box AES implementation based on table lookups, which is shown to be resistant against the existing table‐composition‐targeting white‐box attacks. The authors, key‐embedding tables are obfuscated with large affine mappings, which cannot be cancelled out by table compositions of the existing cryptanalysis techniques. Although their implementation requires twice as much memory as the LLY WBAES to store the tables, its speed is about 63 times of the latter. Kunpeng Bai, Chuankun Wu, Zhenfeng Zhang |
IET Inf. Secur. | 3 |
| 2017 | Fast Multi-dimensional Range Queries on Encrypted Cloud Databases
Jialin Chi, Cheng Hong 0001, Min Zhang 0043, Zhenfeng Zhang |
DASFAA (1) | 4 |
| 2017 | The De-anonymization Method Based on User Spatio-Temporal Mobility Trace
Yanyan Fu, Zhenfeng Zhang |
ICICS | 4 |
| 2017 | Bootstrapping Fully Homomorphic Encryption with Ring Plaintexts Within Polynomial Noise
Long Chen 0018, Zhenfeng Zhang |
ProvSec | 2 |
| 2017 | Batched Multi-hop Multi-key FHE from Ring-LWE with Compact Ciphertext Extension
Long Chen 0018, Zhenfeng Zhang |
TCC (2) | 2 |
| 2017 | Universally composable anonymous password authenticated key exchange
Xuexian Hu, Jiang Zhang 0001, Zhenfeng Zhang, Jing Xu 0002 |
Sci. China Inf. Sci. | 3 |
| 2017 | Towards Secure Data Distribution Systems in Mobile Cloud ComputingabstractThough the electronic technologies have undergone fast developments in recent years, mobile devices such as smartphones are still comparatively weak in contrast to desktops in terms of computational capability, storage, etc., and are not able to meet the increasing demands from mobile users. By integrating mobile computing and cloud computing, mobile cloud computing (MCC) greatly extends the boundary of the mobile applications, but it also inherits many challenges in cloud computing, e.g., data privacy and data integrity. In this paper, we leverage several cryptographic primitives such as a new type-based proxy re-encryption to design a secure and efficient data distribution system in MCC, which provides data privacy, data integrity, data authentication, and flexible data distribution with access control. Compared to traditional cloud-based data storage systems, our system is a lightweight and easily deployable solution for mobile users in MCC since no trusted third parties are involved and each mobile user only has to keep short secret keys consisting of three group elements for all cryptographic operations. Finally, we present extensive performance analysis and empirical studies to demonstrate the security, scalability, and efficiency of our proposed system. Jiang Zhang 0001, Zhenfeng Zhang |
IEEE Trans. Mob. Comput. | 2 |
| 2016 | Practical Anonymous Password Authentication and TLS with Anonymous Client AuthenticationabstractAnonymous authentication allows one to authenticate herself without revealing her identity, and becomes an important technique for constructing privacy-preserving Internet connections. Anonymous password authentication is highly desirable as it enables a client to authenticate herself by a human-memorable password while preserving her privacy. In this paper, we introduce a novel approach for designing anonymous password-authenticated key exchange (APAKE) protocols using algebraic message authentication codes (MACs), where an algebraic MAC wrapped by a password is used by a client for anonymous authentication, and a server issues algebraic MACs to clients and acts as the verifier of login protocols. Our APAKE construction is secure provided that the algebraic MAC is strongly existentially unforgeable under random message and chosen verification queries attack (suf-rmva), weak pseudorandom and tag-randomization simulatable, and has simulation-sound extractable non-interactive zero-knowledge proofs (SE-NIZKs). To design practical APAKE protocols, we instantiate an algebraic MAC based on the q-SDH assumption which satisfies all the required properties, and construct credential presentation algorithms for the MAC which have optimal efficiency for a randomize-then-prove paradigm. Based on the algebraic MAC, we instantiate a highly practical APAKE protocol and denote it by APAKE, which is much more efficient than the mechanisms specified by ISO/IEC 20009-4. An efficient revocation mechanism for APAKE is also proposed. Zhenfeng Zhang, Kang Yang 0002, Xuexian Hu |
CCS | 1 |
| 2016 | UC-secure Two-Server Password-Based Authentication Protocol and Its ApplicationsabstractA two-server password-based authentication (2PA) protocol is a special kind of authentication primitive that provides additional protection for the user's password. Through a 2PA protocol, a user can distribute his low-entropy password between two authentication servers in the initialization phase and authenticate himself merely via a matching password in the login phase. No single server can learn any information about the user's password, nor impersonate the legitimate user to authenticate to the honest server. In this paper, we first formulate and realize the security definition of two-server password-based authentication in the well-known universal composability (UC) framework, which thus provides desirable properties such as composable security. We show that our construction is suitable for the asymmetric communication model in which one server acts as the front-end server interacting directly with the user and the other stays backstage. Lin Zhang 0019, Zhenfeng Zhang, Xuexian Hu |
AsiaCCS | 2 |
| 2016 | One-Round Cross-Domain Group Key Exchange Protocol in the Standard Model
Xiao Lan, Jing Xu 0002, Zhenfeng Zhang |
Inscrypt | 4 |
| 2016 | Programmable Hash Functions from Lattices: Short Signatures and IBEs with Small Key Sizes
Jiang Zhang 0001, Yu Chen 0003, Zhenfeng Zhang |
CRYPTO (3) | 3 |
| 2016 | AEP-M: Practical Anonymous E-Payment for Mobile Devices Using ARM TrustZone and Divisible E-Cash
Bo Yang 0003, Kang Yang 0002, Zhenfeng Zhang, Dengguo Feng |
ISC | 3 |
| 2016 | Multiple Handshakes Security of TLS 1.3 CandidatesabstractThe Transport Layer Security (TLS) protocol is by far the most widely deployed protocol for securing communications and the Internet Engineering Task Force (IETF) is currently developing TLS 1.3 as the next-generation TLS protocol. The TLS standard features multiple modes of handshake protocols and supports many combinational running of successive TLS handshakes over multiple connections. Although each handshake mode is now well-understood in isolation, their composition in TLS 1.2 remains problematic, and yet it is critical to obtain practical security guarantees for TLS. In this paper, we present the first formal treatment of multiple handshakes protocols of TLS 1.3 candidates. First, we introduce a multi-level&stage security model, an adaptation of the BellareRogaway authenticated key exchange model, covering all kinds of compositional interactions between different TLS handshake modes and providing reasonably strong security guarantees. Next, we prove that candidate handshakes of TLS 1.3 draft meet our strong notion of multiple handshakes security. Our results confirm the soundness of TLS 1.3 security protection design. Such a multi-level&stage approach is convenient for analyzing the compositional design of the candidates with different session modes, as they establish dependencies of multiple sessions. We also identify the triple handshake attack of Bhargavan et al. on TLS 1.2 within our multiple handshakes security model. We show generically that the proposed fixes (RFC 7627) for TLS 1.2 offer good protection against multiple handshakes attacks. Xinyu Li 0002, Jing Xu 0002, Zhenfeng Zhang, Dengguo Feng, Honggang Hu |
IEEE Symposium on Security and Privacy | 3 |
| 2016 | Security analysis of a privacy-preserving decentralized ciphertext-policy attribute-based encryption schemeabstractSummary As it does not require a central authority or the cooperation among multiple authorities, decentralized attribute‐based encryption is an efficient and flexible multi‐authority attribute‐based encryption system. In most existing multi‐authority attribute‐based encryption schemes, a global identifier (GID) is introduced to act as the linchpin to resist collusion attacks. Because GID as well as some sensitive attributes used to apply for secret keys will lead to the compromise of user's privacy, some schemes towards solving these privacy issues have been proposed. Nevertheless, only the privacy of GID was considered in prior works. Recently in ESORICS 2014, Han et al. put forward a privacy‐preserving decentralized ciphertext‐policy attribute‐based encryption scheme in the standard model to address the additive privacy of attributes. In their work, a privacy‐preserving key extract protocol is presented to protect both user's identifier and attributes. In this paper, we point out the security weakness of the scheme of Han et al. We present a collusion attack on their basic decentralized ciphertext‐policy attribute‐based encryption scheme and additionally show that the privacy protection of attributes in their privacy‐preserving key extract protocol cannot be provided. Copyright © 2015 John Wiley & Sons, Ltd. Minqian Wang, Zhenfeng Zhang |
Concurr. Comput. Pract. Exp. | 2 |
| 2016 | Generic constructions of integrated PKE and PEKS
Yu Chen 0003, Jiang Zhang 0001, Dongdai Lin, Zhenfeng Zhang |
Des. Codes Cryptogr. | 4 |
| 2016 | Authenticated key exchange with entities from different settings and varied groupsabstractAbstract Authenticated key exchange (AKE) is a very important primitive in cryptography. In the last decades, many AKE protocols appeared either in the certificate‐based (cert‐based) setting or in the identity‐based (id‐based) setting. In real applications, entities from different settings may also have the requirement to communicate with each other. Several papers have concentrated on supporting either multiple certification authorities or multiple key generation centers, but very few have considered the interoperability between the two settings. Furthermore, existing approaches are still inadequate in supporting parameters from different algebraic groups. In this paper, we consider AKE protocols integrating cert‐based and id‐based settings with varied groups. Based on two extract algorithms for id‐based entities, we present two AKE protocols where one entity is cert‐based and the other is id‐based, and the parameters of both entities come from different groups. An extended AKE security model of Chatterjee et al. and Ustaoǧlu [1, 2] is proposed to support multiple certification authorities and multiple key generation centers in which the proposed protocols are proved to be secure. Other variant protocols are also presented. Then, extensions to support forward secrecy and resistance to leakage of both ephemeral keys are provided. Finally, we present a more efficient integrating protocol than existing constructions for users who use the same group. Copyright © 2013 John Wiley & Sons, Ltd. Yanfei Guo, Zhenfeng Zhang |
Secur. Commun. Networks | 2 |
| 2016 | Superpixel-Based Segmentation for 3D Prostate MR ImagesabstractThis paper proposes a method for segmenting the prostate on magnetic resonance (MR) images. A superpixel-based 3D graph cut algorithm is proposed to obtain the prostate surface. Instead of pixels, superpixels are considered as the basic processing units to construct a 3D superpixel-based graph. The superpixels are labeled as the prostate or background by minimizing an energy function using graph cut based on the 3D superpixel-based graph. To construct the energy function, we proposed a superpixel-based shape data term, an appearance data term, and two superpixel-based smoothness terms. The proposed superpixel-based terms provide the effectiveness and robustness for the segmentation of the prostate. The segmentation result of graph cuts is used as an initialization of a 3D active contour model to overcome the drawback of the graph cut. The result of 3D active contour model is then used to update the shape model and appearance model of the graph cut. Iterations of the 3D graph cut and 3D active contour model have the ability to jump out of local minima and obtain a smooth prostate surface. On our 43 MR volumes, the proposed method yields a mean Dice ratio of 89.3 ±1.9%. On PROMISE12 test data set, our method was ranked at the second place; the mean Dice ratio and standard deviation is 87.0±3.2%. The experimental results show that the proposed method outperforms several state-of-the-art prostate MRI segmentation methods. Zhenfeng Zhang, Baowei Fei |
IEEE Trans. Medical Imaging | 3 |
| 2015 | Round-Optimal Password-Based Group Key Exchange Protocols in the Standard Model
Jing Xu 0002, Xuexian Hu, Zhenfeng Zhang |
ACNS | 3 |
| 2015 | Authenticated Key Exchange from Ideal Lattices
Jiang Zhang 0001, Zhenfeng Zhang, Jintai Ding, Michael Snook, Özgür Dagdelen |
EUROCRYPT (2) | 2 |
| 2015 | Privacy-Enhancing Range Query Processing over Encrypted Cloud Databases
Jialin Chi, Cheng Hong 0001, Min Zhang 0043, Zhenfeng Zhang |
WISE (2) | 4 |
| 2015 | Secure and efficient data-sharing in cloudsabstractSummary With the rapid development of cloud computing, cloud storage has become a cost‐effective solution for many users with the demand of data storage. However, there are still two main concerns for users with sensitive/private data: (1) Is it secure to store private data in public cloud storages? (2) Is there an efficient way to share private data with other specified users? In the past years, several papers in the literature have used proxy re‐encryption (PRE) to address these two concerns, where the efficiency of the underlying PRE scheme is usually a bottleneck of the overall performance of cloud storages. In this paper, we dedicate to design a secure and practical PRE scheme for cloud‐based data‐sharing. First, we discuss a ‘pitfall’ in the security proof of several existing PREs. Then, we give a general framework for proving the chosen ciphertext attacks (CCA) security of single‐hop unidirectional PRE schemes. Finally, we propose a practical PRE scheme that is proven secure against CCA under the computational Diffie–Hellman problem in the random oracle model. We evaluate the performance of our PRE scheme both in theoretical comparisons with related schemes and in implementations at several security levels. The results indicate that our scheme can be practical in cloud‐based data‐sharing. Copyright © 2014 John Wiley & Sons, Ltd. Jiang Zhang 0001, Zhenfeng Zhang |
Concurr. Comput. Pract. Exp. | 2 |
| 2014 | Black-Box Separations for One-More (Static) CDH and Its Generalization
Jiang Zhang 0001, Zhenfeng Zhang, Yu Chen 0003, Yanfei Guo, Zongyang Zhang |
ASIACRYPT (2) | 2 |
| 2014 | Proxy Re-encryption with Unforgeable Re-encryption Keys
Zhenfeng Zhang, Jiang Zhang 0001 |
CANS | 2 |
| 2014 | Security Analysis of EMV Channel Establishment Protocol in An Enhanced Security Model
Yanfei Guo, Zhenfeng Zhang, Jiang Zhang 0001, Xuexian Hu |
ICICS | 2 |
| 2014 | PRE: Stronger security notions and efficient construction with non-interactive opening
Jiang Zhang 0001, Zhenfeng Zhang, Yu Chen 0003 |
Theor. Comput. Sci. | 2 |
| 2013 | Fully Secure Attribute-Based Systems with Short Ciphertexts/Signatures and Threshold Access Structures
Jie Chen 0021, Hoon Wei Lim, Zhenfeng Zhang, Dengguo Feng, San Ling, Huaxiong Wang |
CT-RSA | 4 |
| 2013 | Towards a Secure Certificateless Proxy Re-Encryption Scheme
Zhenfeng Zhang, Jiang Zhang 0001 |
ProvSec | 2 |
| 2013 | Security Analysis of a Privacy-Preserving Decentralized Key-Policy Attribute-Based Encryption SchemeabstractIn a decentralized attribute-based encryption (ABE) system, any party can act as an authority by creating a public key and issuing private keys to different users that reflect their attributes without any collaboration. Such an ABE scheme can eliminate the burden of heavy communication and collaborative computation in the setup phase of multiauthority ABE schemes, thus is considered more preferable. Recently in IEEE Transactions Parallel Distributed Systems, Han et al. proposed an interesting privacy-preserving decentralized key-policy ABE scheme, which was claimed to achieve better privacy for users and to be provably secure in the standard model. However, after carefully revisiting the scheme, we conclude that their scheme cannot resist the collusion attacks, hence fails to meet the basic security definitions of the ABE system. Aijun Ge 0001, Jiang Zhang 0001, Rui Zhang 0002, Chuangui Ma, Zhenfeng Zhang |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2012 | Threshold Ciphertext Policy Attribute-Based Encryption with Constant Size Ciphertexts
Aijun Ge 0001, Rui Zhang 0002, Chuangui Ma, Zhenfeng Zhang |
ACISP | 5 |
| 2012 | Ciphertext policy attribute-based encryption from latticesabstractSahai and Waters [6] proposed Attribute-Based Encryption (ABE) as a new paradigm of encryption algorithms that allow the sender to set a policy describing who can decrypt a particular ciphertext. In this paper, we first propose a ciphertext policy attribute-based encryption (CP-ABE) scheme from lattices, which supports flexible threshold access policies on literal (or boolean) attributes. Then we extend it to support multi-valued attributes without increasing the public key and ciphertext size. Our scheme's master secret key has only one matrix despite of the number of the system's attributes. The security of our schemes is based on the worst-case hardness on lattices. Jiang Zhang 0001, Zhenfeng Zhang, Aijun Ge 0001 |
AsiaCCS | 2 |
| 2012 | Combined Public-Key Schemes: The Case of ABE and ABS
Jie Chen 0021, Hoon Wei Lim, Zhenfeng Zhang, Dengguo Feng |
ProvSec | 4 |
| 2012 | Fully Secure Doubly-Spatial Encryption under Simple Assumptions
Zhenfeng Zhang, Dengguo Feng |
ProvSec | 2 |
| 2012 | Authenticated Key Exchange with Entities from Different Settings and Varied Groups
Yanfei Guo, Zhenfeng Zhang |
ProvSec | 2 |
| 2012 | Attribute-based signature scheme with constant size signature in the standard modelabstractIn this study, the authors propose a new efficient attribute-based signature (ABS) scheme. This scheme achieves existential unforgeability against selective predicate attack and attributes signer privacy in the standard model. The signature scheme only needs three pairing operations, and the signature size is constant, regardless of the number of attributes. Compared with other existing schemes, this construction provides better efficiency in terms of the computational cost and communication cost. To the best of author's knowledge, this is the first ABS scheme that can achieve constant signature size and constant number of pairing operations. In addition, after the analysis of Wang and Chen's attribute-based ring signature scheme, the authors show that their scheme is incorrect. Aijun Ge 0001, Chuangui Ma Ma, Zhenfeng Zhang |
IET Inf. Secur. | 3 |
| 2012 | Gateway-oriented password-authenticated key exchange protocol in the standard model
Fushan Wei, Zhenfeng Zhang, Chuangui Ma |
J. Syst. Softw. | 2 |
| 2012 | Corrigendum to "Gateway-oriented password-authenticated key exchange protocol in the standard model" [J. Syst. Softw. 85 (March (3)) (2012) 760-768]
Fushan Wei, Zhenfeng Zhang, Chuangui Ma |
J. Syst. Softw. | 2 |
| 2011 | A Generic Construction from Selective-IBE to Public-Key Encryption with Non-interactive Opening
Jiang Zhang 0001, Rui Zhang 0002, Zhenfeng Zhang |
Inscrypt | 4 |
| 2011 | A Ciphertext Policy Attribute-Based Encryption Scheme without Pairings
Jiang Zhang 0001, Zhenfeng Zhang |
Inscrypt | 2 |
| 2011 | Efficient Ciphertext Policy Attribute-Based Encryption with Constant-Size Ciphertext and Constant Computation-Cost
Zhenfeng Zhang, Dengguo Feng |
ProvSec | 2 |
| 2011 | Gateway-Oriented Password-Authenticated Key Exchange Protocol with Stronger Security
Fushan Wei, Chuangui Ma, Zhenfeng Zhang |
ProvSec | 3 |
| 2010 | Attribute-Based Conditional Proxy Re-Encryption with Chosen-Ciphertext SecurityabstractProxy re-encryption is a cryptographic primitive which enables a ciphertext encrypted under a delegator's public key to be translated into a ciphertext of a delegatee by a semi-trusted proxy. Conditional proxy re-encryption (CPRE) is a variant of proxy re-encryption which allows the delegator to control the delegation of decryption rights with certain conditional value. The existing CPRE schemes left an open problem about how to construct CCA-secure CPRE schemes supporting Boolean predicates over conditions. In this paper, we propose attribute-based CPRE (AB-CPRE) in which the delegator could implement attributed-based control on the delegation of decryption rights by setting conditions in the form of access structure and attribute set. AB-CPRE is suitable for applications where fine-grained control of the decryption delegation is necessary. We formalize definitions and security notions for AB-CPRE and prove that the proposed scheme is chosen-ciphertext secure under the 3-Quotient Decision Bilinear Diffie-Hellman (3-QDBDH) assumption. Dengguo Feng, Zhenfeng Zhang |
GLOBECOM | 3 |
| 2009 | Certificateless Threshold Ring Signature
Shuang Chang, Duncan S. Wong, Yi Mu 0001, Zhenfeng Zhang |
Inf. Sci. | 4 |
| 2007 | Certificateless signature: a new security model and an improved generic construction
Bessie C. Hu, Duncan S. Wong, Zhenfeng Zhang, Xiaotie Deng |
Des. Codes Cryptogr. | 3 |
| 2006 | Key Replacement Attack Against a Generic Construction of Certificateless Signature
Bessie C. Hu, Duncan S. Wong, Zhenfeng Zhang, Xiaotie Deng |
ACISP | 3 |
| 2006 | Certificateless Public-Key Signature: Security Model and Efficient Construction
Zhenfeng Zhang, Duncan S. Wong, Jing Xu 0002, Dengguo Feng |
ACNS | 1 |
| 2005 | ID-Based Aggregate Signatures from Bilinear Pairings
Jing Xu 0002, Zhenfeng Zhang, Dengguo Feng |
CANS | 2 |
| 2005 | Efficient Identity-Based Protocol for Fair Certified E-mail Delivery
Zhenfeng Zhang, Jing Xu 0002, Dengguo Feng |
CANS | 1 |
| 2005 | Efficient ID-Based Optimistic Fair Exchange with Provable Security
Zhenfeng Zhang, Dengguo Feng, Jing Xu 0002, Yongbin Zhou |
ICICS | 1 |
| 2002 | Cryptanalysis on AW digital signature scheme based on error-correcting codes
Zhenfeng Zhang, Dengguo Feng, Zongduo Dai |
Sci. China Ser. F Inf. Sci. | 1 |