Zhe Xia

dblp:43/4169 · DBLP profile ↗
← Back
59ranked-venue papers
10as first author
31since 2021 · last 2026
0000-0003-4397-1248ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 26 · 9 first-author · 9 since 2021Computer networks · 11 · 8 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 6 since 2021Databases, data management, data science and information retrieval · 7 · 1 first-author · 4 since 2021Theory of computation · 3 · 1 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A practical blockchain-based vaccine supply management framework with verifiability and traceability
abstract
Abstract With increasing global demand for vaccines and the changing level of biotechnology, vaccines become an important force to promote the development of the global pharmaceutical market. Vaccine forms an important basis for human self-protection. At present, existing vaccine supply management is mostly established in a centralized manner with a central authority (CA) for assuring trust. This approach requires that a trusted CA be set up, and it incurs overhead costs in communications and storage in networks. At the same time, issues such as the authenticity, integrity, and privacy are still widespread in vaccine supply management. Therefore, it is crucial to study a vaccine supply management traceability scheme that can be supervised in a decentralized manner and whose data cannot be tampered with or forged. In view of the security and efficiency problems in the existing vaccine supply management traceability scheme, a practical blockchain-based vaccine supply management framework with verifiability and traceability is proposed in this paper. This architecture can solve the lack of centralization in the existing vaccine supply management and the problems of data falsification, tampering, and low work efficiency in the current vaccine supply supervision process. At the same time, aiming at the lack of efficiency and security of the existing signature schemes suitable for consortium chains, an improved SM2 digital signature algorithm based on key distribution authentication and modulo-free inverse operation is designed, which improves the signature efficiency and reliability in the signature verification process. Then, we design a new way to store vaccine production records, which can avoid the forgery and modification of production records by treating the production record of each production step as a separate piece of data. Based on the decentralized and traceable feature of the framework, it can well resolve the trust issue between consumers and the vaccine regulators. Consumers can be allowed to verify the authenticity of vaccine supply management process. In addition, the security analysis shows that the proposed framework meets all desired security requirements. Compared with similar solutions, the proposed scheme takes less computation and communication costs. Hence, our construction is more appropriate for practical vaccine supply management.
Lulu Ke, Ching-Fang Hsu 0001, Man Ho Au, Zhe Xia
Comput. J.4
2026 Leakage-Resilient Data Transmission Protocol With Multi-Receiver for Internet of Things
abstract
The Internet of Things (IoT) is transforming lives, making daily tasks more convenient and efficient than ever before. However, the true potential of IoT can only be realized if its nodes interact with robust security, ensuring that sensitive data and personal information remain protected. While many data transmission protocols have been proposed in recent years, most fail to deliver on their security promises in real-world scenarios. Adversaries can exploit vulnerabilities through sophisticated leakage attacks such as side channel attacks or cold boot attacks to compromise encryption keys and undermine system integrity. Without advanced, resilient protocols, the promise of IoT is put at serious risk. In addition, the corresponding protocols deployed in IoT should enjoy high computational efficiency, because the mobile terminals have weak computing power. Also, from the viewpoint of actual application, the proposed data transmission protocol should have wider universality and can be used in multiple scenarios of IoT. Therefore, to further address the above problems, we propose a general construction of a leakage-resilient data transmission protocol with multi-receiver from an identity-based hash proof system (IB-HPS) and identity-based signature (IBS) scheme. For our proposal, the unforgeability, anonymity, and confidentiality can be proved based on the security of the underlying cryptography tools. Compared with the existing protocols, our proposal has better performance, such as dynamic anonymity, leakage resilience, traceability, etc. Furthermore, to guarantee the highest levels of security and efficiency, we have developed a novel IB-HPS construction that offers continuous leakage resilience and perfect key updates. Alongside this, our new leakage-resilient IBS scheme delivers the computational efficiency essential for practical deployment in IoT networks, ensuring that security enhancements do not come at the expense of performance. Both performance analysis and security analysis show that our data transmission protocol is secure, efficient, and highly practical.
Yanwei Zhou, Zirui Qiao, Bo Yang 0003, Zhe Xia, Mingwu Zhang
IEEE Trans. Dependable Secur. Comput.4
2025 DVSTdetector: Dual-View Spatio-Temporal Representation Learning for Intrusion Detection in Industrial Control System
abstract
Industrial Control Systems (ICS) serve as the backbone of critical infrastructures, controlling and automating the stable operation of industrial processes. With the progressive integration of industrial processes and Information Technology (IT), ICS have evolved from closed, isolated systems to open, interconnected networks. This evolution has significantly expanded attack surfaces and increased security vulnerabilities, making ICS more susceptible to cyber attacks. Intrusion Detection Systems (IDS), particularly those based on deep learning that can learn spatio-temporal features from raw network traffic, are the most effective methods for protecting ICS. However, most existing DL-based IDS adopt a Traditional Spatio-Temporal Feature (TSTF) view for representation learning, which often ignores the unique characteristics of industrial protocols and ICS communication patterns, and loses important fine-grained discriminative information. As a result, the detection models perform poorer with higher false negatives and false positives when applied in ICS. To overcome the above issue, we propose a novel Segment-Based Spatio-Temporal Feature (SSTF) view, which leverages temporal dependencies among the same segments in different packets within a flow and spatial correlations between different segments. Additionally, we introduce a dual-view intrusion detection framework-DVSTdetector, that integrates both the TSTF and SSTF views and employs two workflows to promote better representation learning from both global and local perspectives in parallel, obtaining more robust spatiotemporal features. A publicly available dataset (WDT) and a private dataset (XLP) are used to evaluate our approach. The experimental results demonstrate its effectiveness and superiority, outperforming six state-of-the-art approaches and achieving high performance across six metrics: Accuracy ($99.35 \%$, 99.87%), Precision (99.28%, 99.93%), Recall (98.52%, 99.90%), F1-score ($\mathbf{9 8. 9 0 \%, ~} \mathbf{9 9. 9 1 \%}$), AUC-ROC ($\mathbf{9 9. 1 1 \%, ~ 9 9. 8 4 \%), ~ a n d ~ a ~ l o w ~ F a l s e ~}$ Positive Rate ($\mathbf{0. 2 9 \%, ~} \mathbf{0. 2 1 \%}$).
Qianrong Zheng, Zhe Xia, Junwei Zhou 0002, Jianwen Xiang
ISSRE4
2025 A novel construction of certificateless aggregate signcryption scheme for smart healthcare
Xianxiang Liu, Yanwei Zhou, Yasi Zhu, Zhe Xia
Expert Syst. Appl.4
2024 Extremely Lightweight Constant-Round Membership-Authenticated Group Key Establishment for Resource-Constrained Smart Environments toward 5G
abstract
Abstract With rapid development of next-generation mobile networks and communications (5G networks), group-oriented applications in resource-constrained smart environments (RSEs), such as smart homes and smart classrooms, have attracted great attentions. Due to the insecure communications between resource-constrained devices, secure group communications in RSE toward 5G face many challenges. In RSE toward 5G, lightweight communications and low computational overheads are crucial. Besides, the private tokens used to generate the group key are expected to be reused multiple times. However, the conventional frameworks for secure group communications cannot meet these requirements. A practical construction of extremely lightweight constant-round membership authenticated group key establishment framework is proposed in this paper for RSE toward 5G, which not only implements identity authentication among the members and group key establishment but also ensures extremely lightweight computation and communication costs by each group member. In our proposed scheme, the increase in the number of group members will not lead to a linear or logarithmic increase in the communication and calculation costs at the member side. Our framework also resists external and internal attacks and meets all the desirable security features. In this framework, the privacy of tokens can be well protected, so that they can be reused for multiple times. Therefore, our scheme significantly reduces the costs of communication and calculation, and it is more efficient compared with the related schemes in the literature. This proposal is fairly suitable for lightweight membership authentication and group key establishment in RSE toward 5G.
Ching-Fang Hsu 0001, Zhe Xia, Tianshu Cheng, Lein Harn
Comput. J.2
2024 PRLAP-IoD: A PUF-based Robust and Lightweight Authentication Protocol for Internet of Drones
Ching-Fang Hsu 0001, Man Ho Au, Lein Harn, Jianqun Cui, Zhe Xia, Zhuo Zhao
Comput. Networks6
2024 Lightweight ring-neighbor-based user authentication and group-key agreement for internet of drones
abstract
Abstract As mobile internet and Internet of Things technologies continue to advance, the application scenarios of peer-to-peer Internet of Drones (IoD) are becoming increasingly diverse. However, the development of IoD also faces significant challenges, such as security, privacy protection, and limited computing power, which require technological innovation to overcome. For group secure communication, it is necessary to provide two basic services, user authentication and group key agreement. Due to the limited storage of IoD devices, group key negotiation requires lightweight calculations, and conventional schemes cannot satisfy the requirements of group communication in the IoD. To this end, a new lightweight communication scheme based on ring neighbors is presented in this paper for IoD, which not only realizes the identity verification of user and group key negotiation, but also improves computational efficiency on each group member side. A detailed security analysis substantiates that the designed scheme is capable of withstanding attacks from both internal and external adversaries while satisfying all defined security requirements. More importantly, in our proposal, the computational cost on the user side remains unaffected by the variability of the number of members participating in group communication, as members communicate in a non-interactive manner through broadcasting. As a result, the protocol proposed in this article demonstrates lower computational and communication costs in comparison to other cryptographic schemes. Hence, this proposal presents a more appealing approach to lightweight group key agreement protocol with user authentication for application in the IoD.
Zhuo Zhao, Ching-Fang Hsu 0001, Lein Harn, Zhe Xia
Cybersecur.4
2024 An Efficient and Secure Lightweight Certificateless Hybrid Signcryption Scheme
abstract
With the limited resources of the Internet of Things (IoT), security and efficiency have become a challenge. The hybrid signcryption scheme is a proper method to ensure data security and integrity. Recently, through continuous and in-depth research, the signcryption scheme has made many achievements, but there are still some problems. Most proposals use bilinear mapping, which reduces computational efficiency. It brings a heavy burden to the resource-constrained IoT. And many constructions cannot meet the claimed security, causing the leakage of private messages. Therefore, we propose a lightweight certificateless hybrid signcryption (CLHS) scheme with better performance and higher security to solve the above problems. First, we have reduced storage pressure and improved computational efficiency by using certificateless public-key cryptography and elliptic curves instead of bilinear maps to construct a signcryption scheme, and the construction is lightweight. At the same time, to securely transmit messages of different lengths, we employ a hybrid signcryption scheme. Through formal security proof, efficiency, and performance analysis, our proposal has the security requirements of confidentiality and unforgeability and has better computational efficiency and security performance. Finally, we propose a secure data transmission protocol based on our CLHS scheme in Smart Grid, which inherits the advantages of high computational efficiency and better security of the underlying CLHS scheme.
Yanwei Zhou, Bo Yang 0003, Zhe Xia, Mingwu Zhang
IEEE Internet Things J.4
2024 An Anonymous and Efficient Certificate-Based Identity Authentication Protocol for VANET
abstract
In recent years, the development of Internet of Things technology has led to a surge in interest in the vehicular ad hoc network (VANET), which has greatly improved travel efficiency and facilitated vehicle data sharing. To ensure the privacy and security of both vehicles and personnel, researchers have proposed various measures for securing VANET systems. Recently, certificate-based aggregate signature (CBAS) schemes have been proposed to design an identity authentication protocol for the VANET to prevent tampering and corruption of private vehicle data. In this study, we conduct a security analysis of the previous CBAS scheme by presenting a security attack. Afterward, we propose a novel and concrete construction of the CBAS scheme that offers improved performance for VANET, which can enhance protection in the VANET scenario. We also demonstrate its security based on standard cryptographic assumptions. Comparative results from theoretical analysis and experimental evaluation illustrate the practicality of our proposed scheme. Similarly, the identity authentication protocol created based on the above CBAS scheme has the properties of dynamic anonymity, mutual identity authentication, unforgeability.
Zirui Qiao, Yanwei Zhou, Qiliang Yang, Zhe Xia, Bo Yang 0003, Mingwu Zhang
IEEE Internet Things J.5
2024 An efficient and secure certificateless aggregate signature scheme
Ran Xu 0012, Yanwei Zhou, Qiliang Yang, Kunwei Yang, Bo Yang 0003, Zhe Xia
J. Syst. Archit.7
2023 Multiple Blind Signature for e-Voting and e-Cash
abstract
Abstract In this paper, we propose a new cryptographic primitive, called multiple blind signature (MBS), which is designed based on the integration of both normal blind signature scheme and dual signature. The major difference between a normal blind signature and an MBS is that using a normal blind signature, only one message, $m$, can be verified, but using an MBS, any subset, ${M}^{\prime }$, of multiple messages in a set, $M$, where ${M}^{\prime}{\subseteq} M$, can be verified. With this additional property, we will show that MBS is especially suitable for e-voting and e-cash applications. In other words, we classify these processes in two applications into two phases, on-line and off-line phases. One unique property of this design is that most time-consuming computation and interaction can be performed in advance in off-line phase. There is no cost of computation and interaction in the online phase.
Lein Harn, Ching-Fang Hsu 0001, Zhe Xia
Comput. J.3
2023 Construction of Lightweight Authenticated Joint Arithmetic Computation for 5G IoT Networks
abstract
Abstract The next generation of Internet of Things (IoT) networks and mobile communications (5G IoT networks) has the particularity of being heterogeneous, therefore, it has very strong ability to compute, store, etc. Group-oriented applications demonstrate its potential ability in 5G IoT networks. One of the main challenges for secure group-oriented applications (SGA) in 5G IoT networks is how to secure communication and computation among these heterogeneous devices. Conventional protocols are not suitable for SGA in 5G IoT networks since multiparty joint computation in this environment requires lightweight communication and computation overhead. Furthermore, the primary task of SGA is to securely transmit various types of jointly computing data. Hence, membership authentication and secure multiparty joint arithmetic computation become two fundamental security services in SGA for 5G IoT networks. The membership authentication allows communication entities to authenticate their communication partners and the multiparty joint computations allow a secret output to be shared among all communication entities. The multiparty joint computation result can be used to protect exchange information in the communication or be used as a result that all users jointly compute by using their secret inputs. A novel construction of computation/communications-efficient membership authenticated joint arithmetic computation is proposed in this paper for 5G IoT networks, which not only integrates the function of membership authentication and joint arithmetic computation but also realizes both computation and communication efficiency on each group member side. Our protocol is secure against inside attackers and outside attackers, and also meets all the described security goals. Meanwhile, in this construction the privacy of tokens can be well protected so tokens can be reused multiple times. This proposal is noninteractive and can be easily extended to joint arithmetic computation with any number of inputs. Hence, our design has more attraction for lightweight membership authenticated joint arithmetic computation in 5G IoT networks.
Ching-Fang Hsu 0001, Lein Harn, Zhe Xia, Jianqun Cui, Jingxue Chen
Comput. J.3
2023 Leakage-resilient identity-based cryptography from minimal assumptions
Yanwei Zhou, Bo Yang 0003, Zirui Qiao, Zhe Xia, Mingwu Zhang, Yi Mu 0001
Des. Codes Cryptogr.4
2023 Comments on 'Chinese Remainder Theorem-based centralised group key management for secure multicast communication'
abstract
Abstract To ensure private message exchange among the group members, it is desirable to construct secure and efficient group key management schemes. Moreover, these schemes are more versatile if they could support dynamic join or leave of group members. In IET Information Security 2014, Vijayakumar et al. have introduced such a group key management scheme with lightweight overheads in both computation and communication. And this scheme has been used as a building block in many cryptographic protocols afterwards. In this paper, the authors demonstrate that Vijayakumar's scheme suffers some potential security weaknesses. First, after participating in the group communications for some sessions, a group member may still be able to obtain the group key after it leaves the group, and this violates the claimed security property of forward secrecy. Second, some colluding group members may derive another group member's long term secret key, and obviously, this has more serious consequences. One of the main reasons for the existence of these attacks is that the security analyses in Vijayakumar's scheme are informal and they cannot cover the dynamic environment. To address this issue, the authors’ suggestion is that heuristic arguments of security are not adequate in the design of cryptographic protocols, but formal security definitions and proofs are required.
Zhe Xia, Fuyou Miao 0001
IET Inf. Secur.1
2023 An Efficient Identity Authentication Scheme With Dynamic Anonymity for VANETs
abstract
Nowadays, as an essential technique for intelligent transportation, vehicular ad hoc networks (VANETs) has significantly improved people’s travel experience, providing richer, and smarter services for vehicles while ensuring driver safety. However, considering that VANETs are complex, some security challenges still remain, including but not restricted to privacy preserving of vehicles, authentication of messages, limited resources in computational power, and network bandwidth. To address these issues, many privacy-preserving identity authentication schemes for VANETs have been proposed recently. However, these schemes still suffer some limitations. First, their computational overheads are heavy due to the complex calculations. Second, some schemes are vulnerable to various security weaknesses, unable to resist normal attacks. Third, in some schemes, the same pseudonym keeps unchanged and it is linked to the corresponding private key of user. The consequence is that if the user wants to change its pseudonym, the corresponding private key must be changed. In order to further solve the above problems, we propose a novel privacy-preserving identity authentication protocol based on the certificateless aggregate signature scheme, allowing the user to generate a fuzzy identity to hide her real identity, and the private key can be kept unchanged even if the corresponding pseudonym is updated. Furthermore, to achieve efficiency in computation, bilinear mapping is avoided in our proposed scheme. We prove that our protocol satisfies unforgeability in the random oracle based on a classic complexity assumption. Finally, the security and efficiency analyses demonstrate that our construction enjoys more security features and better performance compared with the existing schemes.
Yanwei Zhou, Zirui Qiao, Zhe Xia, Bo Yang 0003, Mingwu Zhang, Wenzheng Zhang 0001
IEEE Internet Things J.4
2023 An Anonymous and Efficient Multimessage and Multireceiver Certificateless Signcryption Scheme for VANET
abstract
In future intelligent transportation systems, vehicular ad hoc network (VANET) is a popular application. They provide early warning of dangers through wireless communication to improve road safety. Therefore, we should protect messages from leakage and changes during transmission. To ensure the security issues in the communication process, we propose a secure and effective certificateless signcryption scheme with multiple messages and multiple receivers and prove its confidentiality and unforgeability based on the hardness of the discrete logarithm problem and the computational Diffie Hellman problem. Our scheme implements the signature and encryption of multiple messages for different receivers and achieves anonymity for the receiver. Based on our signcryption scheme, we design an identity authentication and key agreement protocol applying the construction in VANET. In addition, we also point out that through comprehensive performance analysis, our proposal has higher security and efficiency of computation and communication compared to other signcryption constructions.
Yanwei Zhou, Ran Xu 0012, Zirui Qiao, Bo Yang 0003, Zhe Xia, Mingwu Zhang
IEEE Internet Things J.5
2023 Public-key encryption scheme with optimal continuous leakage resilience
Yanwei Zhou, Ran Xu 0012, Wenzheng Zhang 0001, Zhe Xia, Bo Yang 0003, Meijuan Huang
Inf. Process. Lett.4
2023 Ideal dynamic threshold Multi-secret data sharing in smart environments for sustainable cities
Ching-Fang Hsu 0001, Zhe Xia, Lein Harn, Man Ho Au, Jianqun Cui, Zhuo Zhao
Inf. Sci.2
2023 Quorum controlled homomorphic re-encryption for privacy preserving computations in the cloud
Zhe Xia, Qiliang Yang, Zirui Qiao
Inf. Sci.1
2023 A verifiable and privacy-preserving cloud mining pool selection scheme in blockchain of things
Mingwu Zhang, Gang Shen 0003, Zhe Xia, Yuntao Wang 0002
Inf. Sci.4
2023 Simple and efficient threshold changeable secret sharing
Lein Harn, Ching-Fang Hsu 0001, Zhe Xia, Shuchang Zeng, Fengling Pang
J. Inf. Secur. Appl.3
2023 A Privacy-Preserving and Verifiable Statistical Analysis Scheme for an E-Commerce Platform
abstract
To know the most recent market conditions, an e-commerce platform needs to be aware of the sales situation of its sellers’ commodities. The most recent market conditions can help to forecast future market trends and develop policies to guide sellers in reasonably allocating their inventory proportion. Statistical analysis is a fundamental approach to studying the sales situation. However, the sales data of an e-commerce platform usually has a significant volume. Therefore, outsourcing statistical analysis to cloud servers is an effective method. Nevertheless, sellers do not want their sales data leaked to anyone or any other organization. Moreover, in many circumstances, we cannot fully trust cloud servers. Thus, we need to utilize cryptographic or non-cryptographic tools to realize the above outsourcing. Secret sharing is a lightweight and powerful non-cryptographic tool to realize privacy-preserving data analysis. However, it needs secure channels to distribute secret shares. On the other hand, homomorphic encryption is a powerful cryptographic tool for designing privacy-preserving data analysis schemes. Nevertheless, these schemes usually do not allow the entity that holds the decryption key to collude with other entities. We propose a privacy-preserving and verifiable statistical analysis scheme for an e-commerce platform that combines a threshold secret sharing scheme with a verifiable threshold homomorphic encryption scheme. Our solution’s demand for secure channels is reduced by 40% ~ 60% compared with a traditional threshold secret sharing scheme, thanking the designed novel distribution model for delivering secret shares. Furthermore, our solution has a stronger ability to resist collusive attacks, keep sales data private from any entity, and ensure that the platform can only obtain the analysis results with the help of some cloud servers, alleviating the single point of trust. And meanwhile, the novel distributed model makes our solution enjoy better robustness and fault tolerance. The proposed solution is validated through security analyses, performance evaluations, and comparison analyses.
Hua Shen 0002, Ge Wu 0001, Zhe Xia, Willy Susilo, Mingwu Zhang
IEEE Trans. Inf. Forensics Secur.3
2022 CBSDI: Cross-Architecture Binary Code Similarity Detection based on Index Table
abstract
Binary code similarity detection for cross-platform is widely used in plagiarism detection, malware detection and vulnerability search, aiming to detect whether two binary functions over different platforms are similar. Existing cross-architecture approaches mainly rely on the approximate matching calculation of complex high-dimensional features, such as graph, which are inevitably slow and unsuitable for large-scale applications. To solve this problem, we propose a novel approach based on index table called CBSDI, improving efficiency by screening a batch of mismatched functions before similarity detection. We select three features and compare them across architectures to select the most appropriate one to construct the index table, and this table can be embedded in other tools. The evaluation shows that the index table can roughly cut the computational costs in half when there are few errors. Moreover, compared with the related works in the literature, our proposed approach can improve not only the efficiency but also the accuracy.
Longmin Deng, Dongdong Zhao 0001, Junwei Zhou 0002, Zhe Xia, Jianwen Xiang
QRS4
2022 A novel threshold changeable secret sharing scheme
Lein Harn, Ching-Fang Hsu 0001, Zhe Xia
Frontiers Comput. Sci.3
2022 A distributed privacy-preserving data aggregation scheme for smart grid with fine-grained access control
Wenzheng Zhang 0001, Zhe Xia
J. Inf. Secur. Appl.3
2021 Novel Public-Key Encryption with Continuous Leakage Amplification
abstract
Abstract Leakage of private information, such as the secret keys, has become a threat to the security of computing systems. It has become a common requirement that cryptographic schemes should withstand various leakage attacks, including the continuous leakage attacks. Although some research progresses have been made toward this area, there are still some unsolved issues. In the literature, the public-key encryption (PKE) constructions with (continuous) leakage resilience normally require the upper bound of leakage to be fixed. However, in many real-world applications, this requirement cannot provide sufficient protection against leakage attacks. In order to mitigate these problems, this paper demonstrates how to design a leakage amplified PKE scheme with continuous leakage resilience and chosen-plaintext attacks security. In our proposed PKE scheme, the leakage parameter can have an arbitrary length. Moreover, the length of permitted leakage in our scheme can be flexibly adjusted according to the leakage requirements of application environment. Its security is formally proved under the classic static assumption.
Zirui Qiao, Qiliang Yang, Yanwei Zhou, Zhe Xia, Mingwu Zhang
Comput. J.4
2021 Novel generic construction of leakage-resilient PKE scheme with CCA security
Yanwei Zhou, Bo Yang 0003, Zhe Xia, Mingwu Zhang, Yi Mu 0001
Des. Codes Cryptogr.3
2021 Non-interactive integrated membership authentication and group arithmetic computation output for 5G sensor networks
abstract
Abstract Group‐oriented applications show its potential ability in the next generation of wireless sensor networks (5G WSNs), which have the particularity of being heterogeneous and so have different capabilities in terms of storage, computing, communicating and energy. One of the main challenges for secure group‐oriented applications (SGA) in 5G WSNs is how to secure communication between these heterogeneous devices. Conventional protocols are not suitable for SGA in 5G sensor networks since multiparty output establishment in this environment requires lightweight communication and computation overhead, further the primary task of SGA in 5G WSNs is to securely transmit various types of jointly computing data. Hence, membership authentication and multiparty output for arithmetic computations become two fundamental and necessary security services in SGA for 5G WSNs. In this paper we propose a novel design of non‐interactive integrated membership authenticated multiparty output for arithmetic computations in 5G sensor networks, which embeds the function of membership authentication and multiparty output for arithmetic computations. Since any arithmetic computation function is composed of multiple additions and multiplications, our result serves as a general method for multiparty computation output in SGA. This design is more suitable for lightweight membership authenticated multiparty arithmetic computations output in 5G sensor networks.
Ching-Fang Hsu 0001, Lein Harn, Zhe Xia, Maoyuan Zhang, Zhuo Zhao
IET Commun.3
2021 Design of ideal secret sharing based on new results on representable quadripartite matroids
Ching-Fang Hsu 0001, Lein Harn, Zhe Xia, Maoyuan Zhang, Quanrun Li
J. Inf. Secur. Appl.3
2021 Non-interactive secure multi-party arithmetic computations with confidentiality for P2P networks
Lein Harn, Zhe Xia, Ching-Fang Hsu 0001
Peer-to-Peer Netw. Appl.2
2021 Lightweight and flexible key distribution schemes for secure group communications
Lein Harn, Ching-Fang Hsu 0001, Zhe Xia
Wirel. Networks3
2020 Improvement of Attribute-Based Encryption Using Blakley Secret Sharing
Zhe Xia, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang, Yi Mu 0001
ACISP1
2020 Continuous Leakage-Resilient Certificate-Based Encryption Scheme Without Bilinear Pairings
abstract
Abstract Recently, much attention has been focused on designing provably secure cryptographic primitives in the presence of key leakage, even the continuous leakage attacks. However, several constructions on the (continuous) leakage-resilient certificate-based encryption (CBE) scheme were proposed based on the bilinear pairings, and the corresponding computational efficiency is lower. Also, the leakage on the master secret key is omitted in the previous constructions. In this paper, to further achieve the better performance, a new construction method of continuous leakage-resilient CBE scheme without bilinear pairings is proposed, and the chosen-ciphertext attacks security of designed scheme is proved based on the hardness of the classic decisional Diffie–Hellman assumption. The performance analysis shows that our method not only can obtain higher computational efficiency but also enjoys better security performances, such as the leakage parameter of secret key of user has the constant size, and an adversary cannot obtain any leakage on the secret key of user from the corresponding given ciphertext etc. The advantage is that our proposal allows leakage attacks of multiple keys, i.e. continuous leakage resilience of the secret key of user and bounded leakage resilience of the master secret key. Additionally, to provide the leakage resilience for the cloud computing, a novel data access control scheme for cloud storage service is proposed from our continuous leakage-resilient CBE scheme, which can keep its claimed security in the leakage seting.
Yanwei Zhou, Bo Yang 0003, Tao Wang 0039, Zhe Xia, Hong-xia Hou
Comput. J.4
2020 Lightweight group key distribution schemes based on pre-shared pairwise keys
abstract
In a secure communication, a one‐time session key is needed to be shared among all participants. Most well‐known key distribution schemes, such as Diffie–Hellman public‐key key distribution scheme invented in 1976 and quantum key distribution scheme invented in 1984 (also called the BB84 scheme), can only allow two users to share a key in conventional one‐to‐one communications. There are many research papers in the literature to propose group key distribution schemes for multiple participants in modern group communications. In this study, the authors propose lightweight group key distributions using pre‐shared pairwise keys. The authors first propose a three‐party group key distribution scheme. They then extend the basic three‐party scheme to establish a group key for a large size of group communications. The proposed generalised schemes can be based to any type of pairwise key distribution schemes, e.g. either quantum or non‐quantum. Moreover, both generalised multi‐party group key distribution schemes are lightweight. The main operations in the proposed schemes are key comparison between two or more than two keys (i.e. logic XOR operation) and the computation of key derivation functions.
Lein Harn, Ching-Fang Hsu 0001, Zhe Xia
IET Commun.3
2020 A generic construction of CCA-secure deterministic encryption
Meijuan Huang, Bo Yang 0003, Yi Zhao 0011, Xin Wang 0058, Yanwei Zhou, Zhe Xia
Inf. Process. Lett.6
2020 Secret sharing with secure secret reconstruction
Lein Harn, Zhe Xia, Ching-Fang Hsu 0001, Yi-Ning Liu 0002
Inf. Sci.2
2020 An efficient aggregation scheme resisting on malicious data mining attacks for smart grid
Hua Shen 0002, Zhe Xia, Mingwu Zhang
Inf. Sci.3
2020 Cryptanalysis and Improvement of a Group Authentication Scheme with Multiple Trials and Multiple Authentications
abstract
Authentication is one of the most fundamental services in cryptography and information security. Compared with the traditional authentication methods, group authentication allows a group of users to be authenticated at once rather than authenticating each of these users individually. Therefore, it is more desirable in the group oriented environment, such as multicast/conference communications. In this paper, we first demonstrate that a recent group authentication scheme by Chien (Security and Communication Networks, 2017) suffers some security flaws, i.e. an adversary in the asynchronous communication model can pretend to be a legitimate group member without being detected. We then use the Anonymous Veto Networks (AV-net) to patch Chien’s scheme, so that its security can be rigorously proved in a well-defined security model.
Zhe Xia, Yining Liu 0001, Ching-Fang Hsu 0001, Chin-Chen Chang 0001
Secur. Commun. Networks1
2020 Identity-based encryption with leakage-amplified chosen-ciphertext attacks security
Yanwei Zhou, Bo Yang 0003, Zhe Xia, Mingwu Zhang, Yi Mu 0001
Theor. Comput. Sci.3
2019 Provably Secure Group Authentication in the Asynchronous Communication Model
Zhe Xia, Lein Harn, Bo Yang 0003, Mingwu Zhang, Yi Mu 0001, Willy Susilo, Weizhi Meng 0001
ICICS1
2019 Cryptanalysis of Raindrop and FBC
Bingqing Ren, Jiageng Chen, Xiushu Jin, Zhe Xia, Kaitai Liang
NSS5
2019 Provably Secure Proactive Secret Sharing Without the Adjacent Assumption
Zhe Xia, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang, Hua Shen 0002, Yi Mu 0001
ProvSec1
2019 Privacy-preserving raw data collection without a trusted authority for IoT
Yi-Ning Liu 0002, Yan-Ping Wang, Xiao-Fen Wang, Zhe Xia, Jingfang Xu
Comput. Networks4
2019 A secure data sharing scheme with cheating detection based on Chaum-Pedersen protocol for cloud storage
abstract
With the development of cloud computing technology, data can be outsourced to the cloud and conveniently shared among users. However, in many circumstances, users may have concerns about the reliability and integrity of their data. It is crucial to provide data sharing services that satisfy these security requirements. We introduce a reliable and secure data sharing scheme, using the threshold secret sharing technique and the Chaum-Pedersen zero-knowledge proof. The proposed scheme is not only effective and flexible, but also able to achieve the semantic security property. Moreover, our scheme is capable of ensuring accountability of users’ decryption keys as well as cheater identification if some users behave dishonestly. The efficiency analysis shows that the proposed scheme has a better performance in terms of computational cost, compared with the related work. It is particularly suitable for application to protect users’ medical insurance data over the cloud.
Xin Wang 0058, Bo Yang 0003, Zhe Xia, Hong-xia Hou
Frontiers Inf. Technol. Electron. Eng.3
2019 An alternative approach to public cloud data auditing supporting data dynamics
Tao Wang 0039, Bo Yang 0003, Yong Yu 0002, Guoyong Qiu, Zhe Xia
Soft Comput.6
2018 Verifiable Secret Sharing Based on Hyperplane Geometry with Its Applications to Optimal Resilient Proactive Cryptosystems
Zhe Xia, Liuying Sun, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang
ACISP1
2018 Privacy-Preserving Data Collection for Mobile Phone Sensing Tasks
Yi-Ning Liu 0002, Yan-Ping Wang, Xiao-Fen Wang, Zhe Xia, Jingfang Xu
ISPEC4
2018 An Efficient and Provably Secure Private Polynomial Evaluation Scheme
Zhe Xia, Bo Yang 0003, Mingwu Zhang, Yi Mu 0001
ISPEC1
2018 Continuous leakage-resilient access control for wireless sensor networks
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001, Zhe Xia
Ad Hoc Networks4
2018 Framework for practical and receipt-free remote voting
abstract
Remote voting allows the voters to cast their votes remotely at their convenience, and it is desirable in many circumstances. In the literature, a number of verifiable remote voting schemes have been introduced recently. However, some of these schemes are only suitable for the low coercion environment. Since without the receipt‐freeness guarantee, voters can be coerced or bribed to vote the candidate favoured by adversaries. Some other schemes provide a very high level of security assurance, e.g. coercion resistance, but these schemes are normally very complex, and ordinary voters are required to perform complicated crypto calculations. In this study, the authors introduce a generic framework for practical and receipt‐free remote voting. In their proposed scheme, voters do not need to have special knowledge or use any trusted device to cast their votes, and meanwhile, they cannot prove to the others how they have voted.
Zhe Xia, Zheng Tong, Chin-Chen Chang 0001
IET Inf. Secur.1
2018 Updatable Identity-Based Hash Proof System Based on Lattices and Its Application to Leakage-Resilient Public-Key Encryption Schemes
Qiqi Lai, Bo Yang 0003, Yong Yu 0002, Zhe Xia, Yanwei Zhou, Yuan Chen 0008
J. Comput. Sci. Technol.4
2018 A Cheating Detectable Privacy-Preserving Data Sharing Scheme for Cloud Computing
abstract
Cloud computing provides a new, attractive paradigm for the effective sharing of storage and computing resources among global consumers. More and more enterprises have begun to enter the field of cloud computing and storing data in the cloud to facilitate the sharing data among users. However, in many cases, users may be concerned about data privacy, trust, and integrity. It is challenging to provide data sharing services without sacrificing these security requirements. In this paper, a data sharing scheme of reliable, secure, and privacy protection based on general access structure is introduced. The proposed scheme is not only effective and flexible, but also is capable of protecting privacy for the cloud owner, supporting data sharing under supervision, enabling accountability of users’ decryption keys, and identifying cheaters if some users behave dishonestly. Security analysis and efficiency analysis demonstrate that our proposed scheme has better performance in computational costs compared with most related works. The scheme is versatile to be used in various environments. For example, it is particularly suitable to be employed to protect personal health data and medical diagnostic data in information medical environment.
Xin Wang 0058, Bo Yang 0003, Zhe Xia, Yanqi Zhao, Huifang Yu 0001
Secur. Commun. Networks3
2017 A secure data backup scheme using multi-factor authentication
abstract
Sensitive data stored in laptops or other mobile devices can easily be lost, stolen, misplaced or corrupted, the remote backup storage technique is used to address these issues; however, the backup server could not be fully trusted, the data should be encrypted in advance. Although the key is more easily protected due to the smaller size compared with the backup data, it is still impossible for ordinary human to remember. A user‐centred design data backup scheme is proposed using multi‐factor authentication. The user firstly selects a symmetrical key and divides it into three shares, then destroys the key. The key can easily be reconstructed by combining the shares stored in the user's smart card and the laptop. Even if the smart card or laptop is lost, the key can still be recovered with the password and biometrics. The proposed scheme not only achieves the required security goals but also is more robust and practical.
Yi-Ning Liu 0002, Liang Chang 0003, Zhe Xia, Debiao He, Chi Cheng 0003
IET Inf. Secur.4
2017 Special issue on Secure Computation on Encrypted Data
Jiageng Chen, Debiao He, Chunhua Su, Zhe Xia
J. Inf. Secur. Appl.4
2017 How to Share Secret Efficiently over Networks
abstract
In a secret-sharing scheme, the secret is shared among a set of shareholders, and it can be reconstructed if a quorum of these shareholders work together by releasing their secret shares. However, in many applications, it is undesirable for nonshareholders to learn the secret. In these cases, pairwise secure channels are needed among shareholders to exchange the shares. In other words, a shared key needs to be established between every pair of shareholders. But employing an additional key establishment protocol may make the secret-sharing schemes significantly more complicated. To solve this problem, we introduce a new type of secret-sharing, calledprotected secret-sharing(PSS), in which the shares possessed by shareholders not only can be used to reconstruct the original secret but also can be used to establish the shared keys between every pair of shareholders. Therefore, in the secret reconstruction phase, the recovered secret is only available to shareholders but not to nonshareholders. In this paper, an information theoretically secure PSS scheme is proposed, its security properties are analyzed, and its computational complexity is evaluated. Moreover, our proposed PSS scheme also can be applied to threshold cryptosystems to prevent nonshareholders from learning the output of the protocols.
Lein Harn, Ching-Fang Hsu 0001, Zhe Xia, Junwei Zhou 0002
Secur. Commun. Networks3
2016 Provably Secure Threshold Paillier Encryption Based on Hyperplane Geometry
Zhe Xia, Xiaoyun Yang, Debiao He
ACISP (2)1
2016 Editorial: Special issue on security and dependability of internet of things
Ning Wang 0001, Zhe Xia, Jianwen Xiang
J. Inf. Secur. Appl.2
2014 Countering Ballot Stuffing and Incorporating Eligibility Verifiability in Helios
Sriramkrishnan Srinivasan, Chris Culnane, James Heather, Steve A. Schneider, Zhe Xia
NSS5
2009 Prêt à voter: a voter-verifiable voting system
abstract
¿¿¿¿¿¿Pre¿t a¿ Voter provides a practical approach to end-to-end verifiable elections with a simple, familiar voter-experience. It assures a high degree of transparency while preserving secrecy of the ballot. Assurance arises from the auditability of the election itself, rather than the need to place trust in the system components. The original idea has undergone several revisions and enhancements since its inception in 2004, driven by the identification of threats, the availability of improved cryptographic primitives, and the desire to make the scheme as flexible as possible. This paper presents the key elements of the approach and describes the evolution of the design and their suitability in various contexts. We also describe the voter experience, and the security properties that the schemes provide.
Peter Y. A. Ryan, David Bismark, James Heather, Steve A. Schneider, Zhe Xia
IEEE Trans. Inf. Forensics Secur.5